Categories
Great Women in Compliance

Great Women in Compliance – The Compliance Pre-Mortem: Together We Can Do Hard Things Well with Jonathan Aronie

This GWIC episode features a “Great Gentleman in Compliance,” Jonathan Aronie, a leading expert in government investigations and organizational integrity at Sheppard Mullin. Jonathan joins GWIC co-host Hemma Lomax to discuss his career journey, the innovative compliance tool known as the compliance pre-mortem, and the importance of proactive measures in compliance and governance. He also emphasizes the significance of active bystander intervention programs, derived from law enforcement, as highly effective tools for preventing misconduct in organizations. Additionally, Jonathan offers insights into the challenges and benefits of compliance programs, highlighting the need for continuous improvement and strategic empathy in these efforts.

  • The Psychology of Preventative Compliance
  • The ROI of Compliance and Integrity
  • The Concept of Pre-Mortem in Compliance
  • Common Risks and Blind Spots in Compliance
  • Active Bystander Programs vs. Compliance Hotlines
  • Lessons in Compliance and Culture from Policing
  • Building Continuous Improvement Frameworks
 

Biography

Jonathan Aronie is a partner in and the former leader of the firm’s Governmental Practice, resident in Washington, DC. Jonathan is also a founding member and current leader of the firm’s Organizational Integrity Group, a cross-disciplinary team of litigators, regulatory specialists, federal monitors, and ex-prosecutors with extensive experience helping organizations prevent and defend against challenges to their organizational integrity. 

Areas of Practice

Jonathan counsels and represents large and small businesses in some of the country’s most prominent classified and unclassified government contract matters, including bid protests, claims, self-disclosures, internal investigations, Department of Justice investigations, and False Claims Act investigations. As the leader of the firm’s Organizational Integrity Group, Jonathan also dedicates significant time to working with clients to identify and mitigate known and unknown risks before they become problems.

Jonathan’s experience includes litigating under the qui tam provisions of the False Claims Act, conducting early risk-based “legal pre-mortems,” developing and implementing corporate compliance programs, conducting internal investigations (proactive and defensive), and providing advice on the FAR Mandatory Disclosure Rule as well as a variety of federal regulatory and statutory matters. He frequently represents clients before the DOJ, the Government Accountability Office, the General Services Administration, and other defense and civilian agencies. Additionally, Jonathan is cleared at the highest levels and counsels and defends clients in classified matters.

Jonathan has authored more than 100 articles and co-authored what is regarded by many as the leading treatise on the GSA Multiple Award Schedule Program, published by Thomson Reuters. He is a regular speaker at national and international forums, as well as CLE programs, including government-sponsored symposia. He is a regular presenter at Coalition for Government Contracting programs and served on the ABA Task Force that drafted guidance regarding the FAR Mandatory Disclosure Rule.

https://www.sheppardmullin.com/jaronie

Resources

Sheppard Mullin’s Organizational Integrity Group

Active Bystandership for Law Enforcement

Everyone Benefits When An Ethics & Compliance Program Is Integrated Throughout An Organization. By: Jonathan Aronie,

Jonathan Aronie on LinkedIn

Categories
Blog

The Compliance Guide to Designed Intelligence: Part 2 – Rethinking Governance for the Age of AI

Yesterday, I began a two-part review of the article “What Is a Designed Intelligence Environment?” in which authors Michael Schrage and David Kiron examine how enterprises must rethink their intelligence and compliance strategies to survive and thrive in the new world of AI-rich operations. I found their insights for compliance professionals both practical and transformative. Previously, we considered what is Designed Intelligence. Tomorrow, we take a deeper dive into what it means for compliance.

For decades, we have approached compliance through policies, procedures, and periodic reviews, trusting that careful planning and diligent oversight would guide us through the challenges of regulatory change and operational risk. However, the rise of artificial intelligence has forever altered this equation. Now, the decisions that shape our organizations are made not just by people, but by increasingly autonomous machines and systems that learn, adapt, and interact in ways that can outpace human comprehension.

This new reality demands a new approach to compliance, one that goes beyond enforcing existing rules and begins to architect the very environments in which human and machine intelligence operate. The article “What Is a Designed Intelligence Environment? ” offers a timely and robust framework for this challenge. Rather than treat AI as just another tool in the compliance toolbox, it urges us to rethink how knowledge, reasoning, and governance are structured across the enterprise. For the compliance professional, this shift is as profound as it is practical: our mission is no longer to control risk but to orchestrate intelligence itself.

Five Key Takeaways for the Compliance Professional

1. Observability Over Prediction: Embrace Real-Time Monitoring

Traditional compliance programs often rely on the classic cycle of predict, plan, execute, and measure. However, as the article emphasizes, Stephen Wolfram’s principle of computational irreducibility suggests that in highly complex, AI-rich environments, outcomes cannot be predicted; they must be observed as they occur. This is not a theoretical point; rather, it is a practical call to action for compliance.

In a world where both human and machine agents make critical decisions, compliance leaders need to build systems that provide real-time visibility into these interactions. The case of the pharmaceutical R&D pipeline illustrates this vividly: instead of forcing premature rankings of drug candidates, the company built a computational observatory, allowing emergent patterns to drive decision-making. For compliance, this means investing in tools and processes that enable continuous monitoring, immediate detection of anomalies, and dynamic feedback loops, moving from static after-the-fact audits to active, ongoing oversight.

2. Semantic Formalization: Make Compliance Computable

If your compliance program still relies on lengthy policy manuals and inconsistent training, it’s time to elevate it. The article introduces the concept of semantic formalization, defining key business and compliance concepts in a manner that enables both humans and machines to execute and reason with them. This isn’t just data management; it’s about ensuring every stakeholder and system shares a common, computable language for compliance.

For example, a multinational retailer struggling with customer experience (CX) consistency turned things around by building a semantic kernel, a shared ontology for complaints, resolutions, and metrics. Compliance teams must similarly formalize definitions for key terms, including risk, conflict of interest, and reporting obligations. This creates a foundation where both human and AI agents can interpret and act on compliance requirements, ensuring consistency, auditability, and scalability.

3. Translate Between Multiple Realities

Every department, human expert, and AI system in your organization “computes” reality differently. Financial models assess risk through simulations, operations utilize failure analysis, and AI identifies statistical correlations. The article’s exploration of real space, the idea that these are not just different perspectives but fundamentally different computational rule sets, changes the compliance game.

Instead of forcing alignment through top-down mandates, compliance officers must become expert translators and orchestrators of change. The aerospace design review case proves the point: rather than punishing disagreement between engineers and AI, leadership created a real mediator, mapping and reconciling the underlying rules of each party. Compliance professionals should develop frameworks and protocols to make these internal logics explicit, resolve conflicts, and coordinate decision-making without imposing artificial consensus.

4. Do Not Simply Deploy Smarter Tools, But Architect Intelligence Environments

Throwing advanced AI or analytics at compliance problems is not enough. The article argues forcefully that intelligence, whether human or machine, must be designed into the very infrastructure of the enterprise. Most organizations still treat intelligence as an emergent property of tools, rather than an intentional product of environment design.

For compliance, this means working proactively with IT, legal, and operational leaders to design systems where intelligence (learning, reasoning, and adaptation) is orchestrated by default. Real-time observability, semantic formalization, and rule-based mediation must be built into the core of your compliance framework, not added as afterthoughts. This approach enables faster, higher-quality decisions, reduces systemic risk, and enhances organizational agility.

5. From Enforcer to Orchestrator: Redefine the Compliance Role

The most important takeaway is the redefinition of what it means to be a compliance professional in the era of AI. The future of compliance is not just about enforcing standards and conducting audits; it is about orchestrating intelligence across human and machine systems. This means guiding the translation between different rules and perspectives, architecting environments for safe collaboration, and ensuring ethical execution in a world of real-time, adaptive agents.

Compliance officers must expand their skill sets by learning the basics of AI, systems engineering, and data science, developing fluency in semantic modeling, and building cross-functional relationships with technology and business leaders. By leading the design of intelligence environments, compliance professionals can become strategic partners in innovation, not just gatekeepers of risk.

As we enter a new era defined by AI, the compliance profession finds itself at a crossroads. The systems we govern are no longer straightforward, linear, or purely human—they are dynamic, adaptive, and built from the collaboration between people and machines. The article “What Is a Designed Intelligence Environment? ” makes clear that our old tools—checklists, policy manuals, and after-the-fact audits—are no longer sufficient for the task ahead. Instead, we must build environments where intelligence itself is orchestrated, monitored, and governed by design.

This transformation is not about abandoning the core values of compliance, integrity, transparency, and accountability; it is about embracing new methods to uphold them in a complex world. We must shift from prediction to observability, from description to formalization, and from enforcement to orchestration. We must learn to translate and mediate between diverse ways of thinking and design infrastructures that enable human and machine intelligence to flourish safely and ethically.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Rethinking Corporate AI Governance Through Design Intelligence

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today we consider how enterprises must rethink their compliance strategies to survive and thrive in the new world of AI-rich operations.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition which was recently released by LexisNexis. It is available here.

Categories
Innovation in Compliance

Innovation in Compliance – The Power of Accountability and Team Culture with Gina Cotner

Innovation comes in many areas, and compliance professionals need to be ready for it and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this engaging episode, Tom Fox sits down with Gina Cotner, the founder and CEO & Founder of Athena Executive Services, to explore the importance of team culture and accountability in corporate settings.

Cotner delves into her professional background and the organic development of a strong team culture at Athena. She emphasizes the critical role of accountability as a cultural standard and provides actionable insights for leaders on how to instill this within their organizations. Key takeaways include the significance of consistency, the balance between compassion and accountability, and the role of follow-up as a leadership tool. With real-world examples and practical advice, Cotner provides a comprehensive guide to building and maintaining a high-performing, accountable team.

Key highlights:

  • Gina Cotner’s Professional Background
  • The Importance of Team Culture
  • Accountability in High-Performing Teams
  • Misunderstandings About Accountability
  • Building a Culture of Accountability
  • Consistency and Psychological Safety
  • Follow-Up as a Leadership Tool
  • Compassion in Leadership

Resources:

Follow Athena Executive Services on:

Company’s Website

LinkedIn

Instagram

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

How Generative AI is Transforming Business and Compliance in 2025

One thing I have learned from the digital age is that to stay ahead, we must stay informed and proactive about how new technologies impact corporate governance, ethics, and operational compliance. In this context, generative AI (Gen AI) is no longer a futuristic concept; it is embedded deeply in our everyday activities. Marc Zao-Sanders’ article in Harvard Business Review (HBR), “How People Are Really Using Gen AI in 2025,” presents an excellent opportunity to reflect on how these developments impact compliance, governance, and risk management.

Zao-Sanders highlights a critical shift in how generative AI is utilized: from purely technical assistance towards significantly more personal and emotive applications. With “Therapy/Companionship,” “Organizing my life,” and “Finding purpose” emerging as the top three use cases, it’s clear that users seek emotional and organizational support, demonstrating Gen AI’s versatility beyond traditional technological roles.

Compliance professionals must recognize that as AI increasingly becomes integral to both professional services and personal well-being, the accompanying risk and compliance implications magnify exponentially. The nature of these interactions, often intimate or deeply personal, demands robust data privacy protections and stringent ethical governance frameworks. Businesses integrating these technologies need precise, transparent policies and effective oversight mechanisms to mitigate new compliance risks.

Implications for Compliance Professionals

Enhanced Data Privacy and Ethical Considerations

Zao-Sanders emphasizes the rising prominence of personal and professional support through Gen AI, especially in areas such as AI-based therapy, emotional companionship, and life organization. As users entrust AI with highly sensitive personal data, compliance professionals face increased responsibilities regarding data privacy, security, and the ethical use of data. This scenario elevates the stakes considerably. He notes, “data safety is not a concern when your health is deteriorating,” highlighting users’ willingness to sacrifice privacy for crucial emotional or medical support. Such conditions can quickly lead to ethical and compliance vulnerabilities if businesses fail to manage and protect sensitive user data rigorously.

Organizations must reinforce their compliance strategies to manage ethical risks inherent in AI-human interactions. As Zao-Sanders indicates, professional services, including medical, legal, and financial advisement, are increasingly relying on generative AI, pushing regulatory boundaries. Notably, EY’s deployment of 150 AI agents specifically for tax-related tasks highlights the profound impact of generative AI on professional services, adding layers of complexity to compliance strategies.

Regulatory Response and Enforcement Trends

The article briefly touches on the growing regulatory scrutiny that Gen AI is attracting globally, noting explicitly that governments are “taking more emphatic and explicit positions” due to heightened stakes surrounding AI technology. For compliance professionals, this should serve as a clarion call: regulatory oversight is intensifying. Preparing for audits, demonstrating compliance, and actively engaging with regulatory developments will be essential. The rapid pace of AI adoption necessitates an agile and proactive approach to compliance management that anticipates, rather than merely reacts to, regulatory shifts.

Balancing AI Dependence with Human Oversight

A striking tension highlighted in the article is the debate over the impact of generative AI on human cognitive abilities, decision-making, and ethical judgment. Users express genuine concern about becoming overly reliant on AI, which could erode their ability to think critically and make independent, ethical decisions.

This reliance poses significant implications for compliance officers charged with safeguarding ethical decision-making. Effective compliance programs must emphasize human oversight, cultivating a culture where AI supports rather than supplants human judgment. Investing in AI literacy among employees can mitigate potential over-reliance, fostering an environment where staff understand both the capabilities and limitations of AI.

Compliance in AI-Driven Professional Services

Zao-Sanders illustrates how AI integration into professional tasks is increasingly sophisticated. For instance, the transformation underway at EY, training employees extensively in generative AI, reflects broader industry trends. Compliance officers must respond to these developments by establishing clear standards and compliance checkpoints. It is crucial to determine whether AI outputs meet professional standards, remain unbiased, and do not inadvertently violate regulatory obligations.

Given AI’s pervasive integration into professional judgments (such as tax preparation, legal advice, and medical diagnosis), the accuracy and regulatory compliance of AI-driven outputs become paramount. Compliance programs must integrate AI auditability, accountability, and transparency deeply into corporate governance frameworks.

Practical Compliance Steps in the Gen AI Era

1. Proactive Policy Development and Training

Develop clear policies that outline the acceptable use of generative AI, including specific guidelines on data handling, ethical considerations, and regulatory obligations. Embed these policies into your organization’s culture through rigorous training and communication strategies.

2. Rigorous Risk Assessment and Ongoing Monitoring

Gen AI compliance must adopt continuous monitoring. Regular risk assessments and periodic audits of AI systems will promptly detect and rectify issues. Compliance officers should remain actively involved in assessing new AI technologies for ethical, privacy, and regulatory considerations before full-scale implementation.

3. Transparent Data Practices

Given the heightened public sensitivity to data privacy concerns, as noted by Zao-Sanders’ mention of users’ concerns around data privacy and their cynicism toward Big Tech, companies must prioritize transparent data practices. Clear communication about data usage, consent, and protection measures will foster trust and reduce compliance risks.

4. Ethical AI Governance Frameworks

Design and deploy ethical AI governance frameworks that address algorithmic fairness, transparency, and accountability, ensuring responsible use of AI. These frameworks ensure generative AI tools are deployed responsibly and ethically, aligning with stakeholder expectations and regulatory standards.

5. Encourage Human-AI Collaboration

Foster a balanced approach between AI-driven solutions and human judgment. Reinforce the importance of human oversight to ensure compliance, accuracy, and ethical decision-making, thus minimizing over-dependence on AI.

Looking Ahead—The Compliance Imperative in the Gen AI Landscape

As we approach a future increasingly defined by AI integration, compliance professionals have a unique opportunity to lead their organizations proactively. Understanding and managing the compliance and ethical dimensions of Gen AI is now critical, not optional. The risks and opportunities outlined in Zao-Sanders’ article underscore the urgent need for a strategic, well-informed approach to integrating generative AI into corporate compliance frameworks.

Compliance professionals should view this moment as an opportunity to demonstrate thought leadership, to guide ethical AI adoption, and to establish robust frameworks that enable businesses to thrive responsibly. By proactively addressing the compliance and moral challenges presented by generative AI, we not only fulfill our professional obligations but also position our organizations as ethical, forward-thinking leaders in the digital age. The compliance journey ahead is demanding, but equally, it offers profound opportunities to influence and shape a responsible, compliant, and ethically robust AI-driven future.

Categories
Blog

Integrity Under Fire: Key Compliance Lessons from the Suzanne Ballek SEC Enforcement Action

In the realm of corporate compliance, integrity is a foundational principle. It underscores the effectiveness of every compliance program, defines the culture of an organization, and acts as a safeguard against misconduct. When integrity is compromised, compliance programs crumble. The recent administrative proceeding by the Securities and Exchange Commission (SEC) against Suzanne Ballek, the former Chief Compliance Officer (CCO) of an SEC-registered investment adviser (“Adviser A”), underscores this critical truth. (The Ballek Order) The SEC’s findings and resulting sanctions offer vital lessons for compliance professionals. Today, we examine what happens when a CCO goes awry and identify the essential lessons that every compliance professional should adopt.

Overview

Suzanne Ballek served as Vice President and CCO for Adviser A, an investment adviser that managed approximately $249 million in assets. The heart of the SEC’s action was that Ballek falsified and manipulated compliance records requested during an SEC examination. Specifically, she altered pre-clearance trading forms, backdated signatures, completed missing entries, and even created new forms without authorization, all to give the false appearance of compliance with the company’s trading pre-clearance policy.

Ultimately, Ballek’s actions violated Sections 204(a) and 206(4) of the Investment Advisers Act of 1940, prompting the SEC to impose a cease-and-desist order, a three-year prohibition on her acting in any compliance capacity, and a $40,000 civil penalty.

Compliance Lessons from the Ballek Administrative Order

Ballek presents several significant lessons for compliance professionals. Here are the top takeaways:

1. Integrity Must Guide Compliance Efforts

Compliance officers are custodians of organizational integrity. The Ballek Order emphasizes the importance of maintaining honest and accurate compliance documentation and record-keeping practices. Integrity is non-negotiable. Even under pressure from internal or external examinations, compliance professionals must resist any impulse to alter or falsify records. Ballek’s lapse serves as a stark reminder of how rapidly ethical transgressions can escalate, creating compliance risks that undermine entire organizations.

2. Maintain True and Accurate Records

The case highlights the importance of accurate record-keeping, a core responsibility codified in the Investment Advisers Act and Rule 204A-1. Adviser A was required to maintain true and accurate records of its pre-clearance trading activities. Instead, Ballek engaged in backdating, altering dates, filling out missing fields after the fact, and fabricating records entirely. Compliance officers must establish clear documentation procedures, train employees on those expectations, and conduct regular internal audits to ensure accurate records and immediate corrections of any identified discrepancies.

3. Implement Robust Policies and Procedures

Having written policies is essential, but they must be diligently and consistently followed. Adviser A had policies requiring prior approval of trades by access persons and mandated record retention for six years. However, these policies were consistently violated in practice. The Ballek Order emphasizes that maintaining a façade of compliance, particularly through document falsification, is insufficient. Compliance programs must include proactive monitoring and periodic testing of policies and procedures to ensure ongoing effectiveness and efficacy. Compliance officers need to embed policies into daily operational practices rather than treating them as mere formalities or check-the-box requirements.

4. Transparency During Regulatory Examinations

The SEC views transparency and honesty during examinations as fundamental compliance obligations. Ballek misrepresented the truth by submitting falsified documents and subsequently misleading examiners. Providing accurate, unaltered documentation to regulators is crucial. If errors or gaps in records are found, they should be openly disclosed, accompanied by a clear action plan to rectify deficiencies. Transparency with regulatory bodies builds credibility and can mitigate potential enforcement actions. Conversely, a lack of transparency can significantly exacerbate penalties and sanctions, as seen in this enforcement action.

5. Leadership Must Exemplify Compliance

Every compliance officer must embody the principles of compliance, acting as a model for the rest of the organization. In this case, the failure originated from the CCO herself, the person responsible for enforcing adherence to compliance norms. Compliance officers must exhibit behaviors they wish to see across the organization. When compliance leadership itself falters, the damage to organizational culture and employee confidence is profound and challenging to repair.

6. Beware of Slippery Slopes

Lawyers are familiar with the gradual escalation from minor oversights to serious misconduct, a phenomenon known as the slippery slope. Ballek’s missteps likely started small but eventually ballooned into substantial and systematic falsification. Compliance professionals must remain vigilant for early indicators of lax procedures or ethical compromises and address them immediately. Regular ethical training, scenario-based exercises, and creating a culture that encourages speaking up when irregularities arise can help organizations stay ahead of this slippery slope.

7. Prompt and Accurate Internal Reporting

The Ballek Order matter emphasizes the importance of encouraging honest internal reporting. Compliance professionals should foster a culture that encourages employees to report compliance concerns or failures without fear of retribution or retaliation. Effective internal reporting mechanisms and whistleblower protections enable organizations to identify and address issues before they escalate into regulatory violations. If Adviser A had promoted more robust internal communication around compliance deviations, this unfortunate event might have been avoided entirely.

8. Ensure Segregation of Compliance Duties

One significant issue highlighted by this case is the risk associated with concentrating compliance oversight and documentation responsibilities within one individual. To safeguard against record alteration and concealment, organizations should institute checks and balances, including periodic independent reviews and segregation of compliance duties. Compliance tasks should never be assigned solely to a single individual. This practice fosters accountability, mitigates fraud risk, and promotes a culture of healthy compliance.

9. Understand Consequences of Non-Compliance

The SEC’s enforcement action illustrates severe professional and financial consequences. Beyond monetary penalties, reputational damage and restrictions on future employment in compliance roles serve as powerful deterrents. Compliance professionals must ensure the entire organization, from executives to entry-level employees, fully understands these potential ramifications. Periodic compliance training emphasizing the severity of regulatory penalties and personal liability should reinforce adherence to rules and ethical standards.

10. Continuously Improve and Adapt Compliance Practices

Finally, the compliance function must be adaptive and responsive to evolving regulatory requirements and risks. Continuous improvement of compliance practices, through regular assessments and the incorporation of lessons from regulatory actions such as the Ballek order, helps maintain a proactive stance. Updating policies, strengthening internal controls, and enhancing compliance monitoring based on enforcement insights will help safeguard organizations from similar incidents in the future.

The SEC’s administrative order against Suzanne Ballek serves as a wake-up call for compliance professionals everywhere. It provides a poignant example of how ethical lapses, particularly from compliance leaders, can devastate an organization. By internalizing and applying these ten compliance lessons, organizations can reinforce integrity, build robust compliance frameworks, and protect themselves against regulatory actions.

In the world of compliance, integrity is not optional; it is the cornerstone of everything we do. Remembering this truth, compliance professionals must lead the charge toward uncompromising ethical standards. Only then can true compliance be achieved, fostering sustainable corporate growth and credibility.

Categories
Blog

Rewarding Integrity: Five Lessons from the DOJ – USPS Whistleblower MOU

As compliance professionals, we stand at the forefront of integrity, transparency, and accountability within our organizations. Recently, an important document has emerged from the Antitrust Division of the United States Department of Justice (Antitrust Division), the United States Postal Service (USPS), and the United States Postal Service Office of Inspector General (USPS OIG)—the Memorandum of Understanding (MOU) regarding the Whistleblower Rewards Program. This MOU represents a significant advancement in promoting corporate transparency, encouraging ethical behavior, and strengthening the reporting channels for criminal antitrust violations.

Understanding the MOU

The MOU is a collaborative agreement among the Antitrust Division of the DOJ, the USPS, and the USPS OIG, designed to establish and operationalize a Whistleblower Rewards Program. The overarching purpose is to incentivize whistleblowers to step forward and report credible and substantial evidence of criminal violations, especially those related to antitrust activities that directly impact the Postal Service’s operations or revenues.

Specifically, this program addresses serious federal criminal offenses, including price fixing, bid rigging, market allocation, and other forms of economic collusion, as well as associated fraud schemes that undermine the integrity of government procurement processes. The initiative reflects a comprehensive and coordinated effort among the Antitrust Division, the USPS, and the USPS OIG to foster accountability and transparency in federal contracts, procurements, and market practices.

A critical component of this MOU is the articulated process for whistleblower engagement and eligibility for rewards. Whistleblowers are encouraged to voluntarily submit original information, which must be specific, credible, timely, and previously unknown to any of the enforcement authorities. Once submitted, this information undergoes a rigorous review by the Antitrust Division, which evaluates its validity, specificity, and potential impact. If the initial assessment finds merit, the information is forwarded to the USPS Inspection Service (USPIS), which determines its relevance to the Postal Service’s operations or finances.

A distinctive feature of the Whistleblower Rewards Program, as detailed in the MOU, is the financial incentive offered to successful whistleblowers. Individuals whose reports lead directly to a criminal prosecution, conviction, deferred prosecution agreement, or non-prosecution agreement resulting in a monetary fine or recovery of at least $1 million may receive financial rewards ranging from 15% to 30% of the collected fine. This explicit reward structure serves to underscore the commitment of federal authorities to rewarding transparency, integrity, and courageous reporting of wrongdoing, providing a clear incentive for ethical action within organizations.

By outlining clear processes, defined roles, specific reporting criteria, and attractive financial incentives, this MOU establishes a strong blueprint for enhancing corporate and governmental compliance efforts, underscoring the critical role whistleblowers play in upholding economic integrity and ethical business conduct.

Five Key Takeaways for the Compliance Professional

1. Embrace Proactive Whistleblower Policies

A primary lesson from this MOU is the importance of proactively establishing robust whistleblower frameworks within your organization. This program demonstrates how structured whistleblower initiatives, backed by clear protocols and monetary incentives, significantly bolster compliance efforts. Organizations should similarly adopt proactive approaches, ensuring their whistleblower programs are transparent, well-publicized, and accessible to all employees and stakeholders. Always remember that 80% of all reported whistleblowers either attempt or do report internally. It is the remaining 20% who go to the government.

2. Original Information and Clear Reporting Channels

Compliance programs must ensure clarity around what constitutes “original information,” as defined by this MOU. Information must be independently obtained, credible, specific, and previously unknown to the enforcement authorities. Clear communication channels and robust internal reporting mechanisms are essential for employees to feel confident in sharing valuable insights, thus fostering an internal culture of integrity and vigilance.

3. Integration with Law Enforcement

Another critical takeaway is the integration and alignment of organizational compliance with external law enforcement agencies. By closely coordinating with entities such as the DOJ Antitrust Division, organizations not only enhance their compliance measures but also demonstrate their commitment to lawful operations and proactive detection of violations. Regular dialogue and clear lines of communication with regulatory and enforcement authorities can ensure alignment and swift action on identified risks.

4. Transparency in Award Determination

The MOU emphasizes transparency and fairness in the distribution of rewards. Rewards are stipulated to range from 15% to 30% of the collected criminal fines, promoting trust and clarity among potential whistleblowers. Compliance professionals must adopt a similarly transparent approach within internal reward and recognition structures, clearly communicating criteria, processes, and the rationale behind award decisions. Transparency fosters trust, boosts morale, and encourages active participation in compliance initiatives.

5. Limitations and Conditions for Whistleblowers

Understanding the MOU’s explicit exclusions and conditions is essential. Individuals excluded from whistleblower eligibility include those who instigated the violation, those with privileged or confidential compliance responsibilities, and those employed by law enforcement or regulatory bodies. Compliance professionals must delineate roles and responsibilities within their organizations, ensuring all team members understand their obligations, the nature of confidential and privileged information, and the boundaries of reporting mechanisms.

Final Thoughts

This Whistleblower Rewards Program MOU is a robust model for fostering a compliance culture and encouraging ethical conduct within corporations. By providing clear incentives, establishing transparent processes, and maintaining close collaboration with regulatory bodies, this program sets a high standard for organizations across industries.

As compliance leaders, it is our responsibility to champion these principles within our organizations, advocating for stronger whistleblower protections, clearer reporting channels, and greater collaboration with external oversight authorities. Only by doing so can we build resilient, transparent, and ethically robust organizations prepared to face tomorrow’s compliance challenges head-on.

Categories
Blog

Operationalizing AI for Compliance: Turning Potential into Practice

If you have spent any time around corporate compliance in the past several months, you have undoubtedly heard a great deal about artificial intelligence (AI). It is promised as a game changer, touted as the next big thing, and often presented with buzzwords that sound more like science fiction than practical business tools. Indeed, I wrote a book about its promise, Upping Your Game. However, compliance professionals consistently face one crucial question: How can we operationalize AI effectively within our compliance functions?

I used this title, as I have long advocated Operationalizing Compliance. Indeed, in 2016, I published a book with just that title. Therefore, in today’s blog, we will explore precisely that: how compliance leaders can strategically integrate AI solutions into existing compliance frameworks, drive effectiveness, and transform potential into sustainable value.

Understanding AI’s Value Proposition for Compliance

Operationalizing AI begins with recognizing why AI matters in the context of compliance. Fundamentally, compliance is about managing risk through monitoring, detection, investigation, and remediation. AI excels in these core compliance activities due to its ability to process massive volumes of data rapidly, identify patterns that humans may miss, and provide predictive insights.

AI, in short, enhances your compliance team’s ability to stay ahead of risk, transforming reactive processes into proactive strategies. Consider the traditional compliance approach to monitoring. Usually reliant on sampling and periodic audits, it can leave gaps for misconduct to slip through. AI-driven continuous monitoring solutions eliminate these gaps, spotting anomalies in real-time and flagging them immediately for action.

Yet, for all its promise, AI is not a “plug and play” solution. To operationalize AI, compliance teams must approach it methodically, intentionally, and with transparent governance in place.

Step 1: Define Your Objectives Clearly

The first step in operationalizing AI for compliance is clarity of purpose. Compliance leaders must define the specific outcomes they hope to achieve through AI. Ask yourself, “What problem are we trying to solve, and why is AI a suitable solution?”

Objectives may include:

  • Real-time detection of suspicious financial transactions.
  • Automated due diligence on third-party vendors.
  • Predictive analytics to flag high-risk regions or business units.
  • Enhanced hotline management through AI-powered triage.

Articulated objectives become the roadmap guiding your AI initiative, helping you select appropriate tools and measure success effectively.

Step 2: Data Readiness and Integration

Next, compliance professionals must tackle a critical operational requirement: data readiness. AI thrives on data; thus, operationalizing AI depends on ensuring your data is accessible, reliable, secure, and comprehensive.

Data silos present a significant challenge. Compliance functions often manage fragmented data from HR systems, financial databases, third-party diligence platforms, and internal reporting channels. Integrating these data streams into a unified compliance data lake or repository is a foundational step.

A successful integration strategy includes:

  • Conducting a data inventory and assessing data quality.
  • Standardizing data formats across various systems.
  • Implementing robust data governance practices ensures the accuracy and integrity of data.

Addressing these integration challenges upfront ensures your AI compliance solutions have high-quality fuel to drive accurate and valuable insights.

Step 3: Choose the Right AI Technology Partners and Tools

There’s no shortage of AI vendors promising solutions tailored for compliance needs. But choosing the right partner requires thorough due diligence, evaluating both technological capability and ethical alignment.

Compliance leaders should look for partners with:

  • Demonstrable experience in corporate compliance and regulatory environments.
  • Transparent and auditable AI algorithms to ensure explainability.
  • Robust data privacy and cybersecurity frameworks.
  • Scalable solutions that evolve with regulatory demands and business needs.

Furthermore, compliance professionals should carefully pilot and test AI solutions before implementing them on a full scale. Start small by piloting the solution within a specific compliance area, such as third-party due diligence or fraud detection, and expand gradually based on proven outcomes and clear metrics.

Step 4: Build AI Ethics into Your Compliance Framework

Operationalizing AI comes with significant ethical implications, particularly regarding bias, transparency, and accountability. Compliance officers play a pivotal role in ensuring that AI systems align with a company’s values, ethics, and regulatory expectations.

An ethical AI framework includes:

  • Regular algorithmic auditing to detect and mitigate bias.
  • Transparent processes that allow for the explainability of AI-driven decisions.
  • Mechanisms to oversee and correct AI systems continuously.

AI ethics isn’t an add-on; rather, it is integral to operationalizing AI responsibly. Compliance teams should be at the forefront of this conversation, partnering with data scientists and technology leaders to integrate ethical oversight into AI deployment from the outset.

Step 5: Training, Culture, and Change Management

Operationalizing AI also means preparing your team and organization to adapt to new ways of working. AI is not a replacement for compliance professionals; it’s a tool to augment their expertise. However, integrating AI successfully demands a culture receptive to technology-driven change.

Compliance leaders must focus on:

  • Continuous AI literacy training to ensure that compliance teams understand how to interact effectively with AI tools.
  • Establishing clear communication channels explaining AI’s role, scope, and limitations.
  • Encouraging a culture of curiosity and innovation within compliance teams, reinforcing that AI enables them to perform their roles more effectively, not replace them.

Managing organizational change proactively reduces resistance, fosters engagement, and ensures your compliance team leverages AI’s full potential.

Step 6: Establish Metrics and Measure Impact

Operationalizing AI requires rigorous performance monitoring. Compliance professionals must establish clear benchmarks and metrics to assess the effectiveness of AI continually. Typical metrics could include:

  • Reduction in false positives during transaction monitoring.
  • Improvements in detection accuracy and timeliness.
  • Reduction in compliance breaches and associated remediation costs.
  • Increased efficiency in compliance investigation processes.

These metrics provide tangible evidence of AI’s impact, allowing compliance leaders to make data-driven decisions about expanding or adjusting their AI initiatives.

Step 7: Continuous Improvement and Adaptation

Finally, operationalizing AI is not a one-time event but an ongoing cycle of continuous improvement. AI models and technologies evolve rapidly, as do regulatory environments and compliance risks. Regularly revisiting your AI strategy ensures continued alignment with organizational needs and compliance objectives.

Embrace a feedback loop approach:

  • Regularly solicit feedback from users about the AI tool’s effectiveness.
  • Stay informed about regulatory changes that may impact AI compliance practices.
  • Update algorithms and recalibrate models to maintain accuracy and relevance.

A compliance function committed to continuous learning, adaptation, and iteration is best positioned to reap long-term benefits from AI.

Turning AI from Concept to Compliance Reality (Operationalizing AI)

Operationalizing AI for compliance is not merely about adopting cutting-edge technology; it is about strategic integration, ethical oversight, proactive training, and continuous improvement. When compliance leaders approach AI thoughtfully, methodically, and responsibly, the result is transformative, turning AI’s promise into a practical reality that enhances compliance effectiveness, risk mitigation, and organizational integrity.

As compliance professionals, we stand at an exciting crossroads. AI has moved beyond theoretical potential; it is a tangible, operational reality. By clearly defining objectives, managing data effectively, choosing the right partners, embedding ethics, preparing our teams, and committing to continuous improvement, compliance can lead the way in responsibly harnessing AI’s power.

The AI revolution in compliance is here. The question is not whether compliance teams can operationalize AI but how effectively and ethically they can do so. The answer lies in the strategic, thoughtful, and deliberate steps we take today.

Categories
Blog

Chasing Shadows: Five Compliance Lessons from the Hound of the Baskervilles

The Hound of the Baskervilles,” penned by Sir Arthur Conan Doyle, is not only the most famous Sherlock Holmes story and a riveting detective tale but also presents timeless lessons in compliance applicable to corporate governance and risk management. Through its intricate plot and detailed character portrayals, the novel underscores several critical principles that every compliance professional should heed.

The story itself blends mystery, suspense, and supernatural elements. Sherlock Holmes and Dr. Watson investigate Sir Charles Baskerville’s mysterious death on the eerie Devonshire moors, connected to a legendary demonic hound curse. Holmes sends Watson with his heir, Sir Henry Baskerville, to the estate, where suspicious servants, an escaped convict, and peculiar neighbors—the Stapletons—heighten tensions. Watson’s observations reveal Jack Stapleton’s instability and jealousy over Sir Henry’s attention to Beryl Stapleton. Secretly investigating, Holmes identifies Stapleton as a Baskerville relative plotting Sir Henry’s death to claim the inheritance. Stapleton’s deception includes staging supernatural events to exploit local superstition. In the climax, Stapleton releases a phosphorus-painted hound to kill Sir Henry, but Holmes and Watson intervene, killing the beast. Stapleton flees, presumed dead in the Grimpen Mire. Holmes’s rational deductions triumph, dismissing supernatural fears and reinforcing logic and reason. Watson’s meticulous work is instrumental, showcasing his courage and skill. The novel concludes by affirming reason over superstition, demonstrating the dangers of irrational fear.

Here are five key compliance lessons derived from specific events within this classic tale.

Lesson 1: Avoiding Complacency in Risk Assessment

The initial approach to the mystery of Sir Charles Baskerville’s death illustrates a critical lesson in risk assessment: the importance of maintaining vigilance. Dr. Mortimer initially attributes the death to supernatural causes, influenced by local legends of a family curse. Sherlock Holmes immediately challenges this complacency, emphasizing the need for rational investigation over reliance on myths or unexamined assumptions. Holmes insists on examining evidence logically rather than accepting straightforward, sensational explanations.

Compliance professionals must similarly avoid complacency. It is easy for an organization to rely on historical assumptions or superficial risk assessments. However, genuine vigilance requires continuous questioning and reevaluation of all potential threats. By regularly revisiting risk assessments and remaining skeptical of conventional wisdom, compliance teams can better anticipate, mitigate, and respond to potential compliance failures before they escalate into significant issues.

Lesson 2: Effective Use of Data and Evidence

Throughout “The Hound of the Baskervilles,” Holmes’s meticulous use of evidence exemplifies the necessity of thorough documentation and analysis in achieving effective compliance outcomes. One key example is Holmes’s careful examination of Sir Henry Baskerville’s stolen boots. Holmes correctly deduces that the shoes were stolen to provide the hound with Sir Henry’s scent. This attention to minute detail and systematic analysis underscores the importance of robust documentation and record-keeping.

Compliance professionals should similarly prioritize precise data collection, rigorous documentation, and evidence-based decision-making. Proper documentation provides transparency, facilitates effective audits, and ensures clarity when addressing compliance issues or regulatory inquiries. By fostering a culture where data-driven decision-making is standard practice, organizations can strengthen their compliance programs and more effectively prevent violations.

Lesson 3: Maintaining Independence and Objectivity

A pivotal moment in the novel occurs when Holmes secretly arrives on the moor, independent of Watson’s investigation. Holmes understands the importance of maintaining independence to gather unbiased information. By conducting a parallel investigation that is free from local biases and personal relationships, Holmes preserves objectivity and ultimately identifies the true culprit, Jack Stapleton.

For compliance professionals, maintaining independence and objectivity is equally vital. Conflicts of interest can obscure judgment and compromise investigations. Compliance officers must be empowered to act independently, free from undue influence, to ensure the integrity of their findings and recommendations. Establishing clear reporting structures and supporting unbiased investigative procedures can significantly enhance an organization’s overall compliance effectiveness.

Lesson 4: Transparent Communication and Reporting

Transparency is repeatedly highlighted as essential throughout Conan Doyle’s narrative. Watson’s regular and detailed correspondence with Holmes exemplifies clear, transparent reporting. Watson meticulously records his observations, suspicions, and interactions, ensuring Holmes remains informed of developments in real time. This ongoing communication proves instrumental in Holmes’s eventual successful intervention.

In the realm of corporate compliance, transparent communication and reporting are equally critical. Employees must feel encouraged and supported in reporting suspicious activities or compliance concerns without fear of retaliation or retribution. Implementing precise and accessible reporting mechanisms, while ensuring open lines of communication, fosters a culture that is compliant-friendly. This transparency enables compliance teams to detect and address issues promptly, thereby reducing organizational exposure to risk and promoting an ethical business environment.

Lesson 5: Importance of Culture and Ethics

The actions and eventual downfall of Jack Stapleton underscore a profound lesson in compliance regarding organizational culture and ethics. Stapleton manipulates local fears and exploits the legend of the supernatural hound to facilitate his criminal plans. His unethical behavior, driven by greed and a disregard for human life, ultimately led to his ruin.

Organizations must prioritize building and maintaining a strong ethical culture. Leadership should exemplify ethical behavior, clearly communicate expectations, and swiftly address unethical actions. Regular training and communication regarding ethical standards reinforce an organization’s values and expectations. By cultivating a robust ethical culture, organizations not only reduce the likelihood of compliance violations but also enhance their reputation and long-term sustainability.

The Hound of the Baskervilles” offers rich insights for compliance professionals. Avoiding complacency, emphasizing evidence-based decision-making, maintaining independence, ensuring transparent communication, and fostering a robust ethical culture are foundational principles that are vividly highlighted throughout Conan Doyle’s timeless narrative. These lessons, illustrated through specific events and character decisions within the story, remain deeply relevant in guiding modern corporate compliance practices.

Categories
Innovation in Compliance

Innovation in Compliance – Allison Lagosh on Proactive Compliance Planning for Regulatory Changes

Innovation is present in many areas, and compliance professionals must not only be prepared for it but also actively embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with Allison Lagosh, Head of Compliance at Saifr.ai, to discuss the current and future landscape of regulatory compliance.

With over two decades of experience in asset management, compliance, and regulatory affairs, Lagosh anticipates a pivotal shift towards AI and cryptocurrency regulations. She predicts a lighter enforcement landscape but stresses the importance of a conservative, informed approach to compliance, encouraging firms to future-proof their programs by staying abreast of regulatory changes and engaging in cross-team collaboration. Her insights, shared on platforms like the “Innovation in Compliance” podcast, highlight the necessity of strong leadership support and continuous learning to effectively navigate the dynamic regulatory environment, particularly in the realm of emerging technologies.

Key highlights:

  • Regulatory Futurism: AI and Crypto Compliance
  • “Colorado’s Groundbreaking AI Safety Legislation”
  • Proactive Compliance Planning for Regulatory Changes
  • Navigating Compliance Uncertainties with AI Integration
  • Regulatory Insights on Safer.AI Website

Resources:

Allison Lagosh on LinkedIn

Saifr.ai

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Check out my latest book, Upping Your Game—How Compliance and Risk Management Move to 2023 and Beyond, available from Amazon.com.

Innovation in Compliance was recently honored as the number 4 podcast in Risk Management by 1,000,000 Podcasts.