Categories
Adventures in Compliance

Adventures in Compliance: The Novels – The Hound of the Baskervilles: Uncovering Compliance – Lessons from The Hound of the Baskervilles

In this new season of Adventures in Compliance, host Tom Fox takes a deep dive into the Sherlock Holmes novels. Over this season Tom will take a deep dive into each novel over a four part series. The four novels we will consider from the ethics and compliance perspective are A Study in Scarlet, The Sign of Four, The Hound of the Baskervilles and The Valley of Fear. For the month of July we are considering lessons from The Hound of the Baskervilles.

Fiona and Timothy are back to extract five key compliance lessons from the story, including combating complacency, effective data use, maintaining objectivity, transparent communication, and ethical culture. These principles, drawn from a Victorian mystery, prove profoundly relevant for modern corporate compliance.

Highlights include:

  • Overview of Compliance Lessons from Sherlock Holmes
  • Lesson 1: Avoiding Complacency
  • Lesson 2: Power of Effective Data and Evidence
  • Lesson 3: Independence and Objectivity
  • Lesson 4: Transparent Communication and Reporting
  • Lesson 5: Importance of Culture and Ethics

Resources:

The New Annotated Sherlock Holmes

Sherlock Holmes FAQ by Dave Thompson

Sherlock Holmes, The Novels, with an introduction by Michael Dirda

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

COSO’s Corporate Governance Framework: What It Means for Compliance

For decades, COSO has been the gold standard in internal controls and enterprise risk management. But with the release of its new Corporate Governance Framework (CGF), now open as a Public Exposure Draft, COSO has thrown down the gauntlet to the compliance profession. This isn’t just a governance checklist. It is a call to action: step up, shape governance, and lead your organization into the future.

After exploring each of the six CGF Components in depth, I wanted to conclude this series by bringing it all together. What does the new COSO framework mean for compliance professionals? How should you adjust your strategy, your conversations with the board, and your daily work? Here are the big lessons and the practical next steps.

1. The Big Picture: A New Era for Governance and Compliance

The COSO CGF is a principles-based, integrated system designed to make governance everyone’s business, not just the sole responsibility of a Board of Directors. The six Components—Oversight, Strategy, Culture, People, Communication, and Resilience, each include key Principles with practical Points of Focus and leading-edge considerations. This is not a compliance framework by name, but it is a governance framework that places compliance at the heart of value creation, accountability, and enterprise resilience.

Compliance Takeaway: The CGF is arriving at a moment of regulatory complexity, stakeholder activism, and reputational volatility. Boards and management face evolving risks from AI, cyber, and ESG while being held to standards of transparency and trust by investors, employees, and society itself. If you’re a compliance leader, COSO just handed you the blueprint for embedding compliance deeper than ever before.

2. Oversight: Compliance’s Seat at the Table

Effective governance starts with the board, but it extends through management to every level of the organization. Oversight is about structure, independence, and accountability across board composition, executive delegation, and shareholder engagement. Do not be a bystander in governance; be a builder. Propose committee enhancements, brief leadership on independence and risk, and ensure compliance is on the board’s standing agenda. Your role is to clarify escalation protocols, support board effectiveness, and ensure oversight extends beyond mere numbers to encompass culture and ethical tone.

Compliance Takeaway: Start benchmarking your BOD structure and practices against COSO’s principles. Bring data to governance discussions and push for compliance metrics and risk topics to be regular board agenda items.

3. Strategy: From Afterthought to Co-Pilot

Strategy is no longer a C-suite sandbox. COSO makes clear: the board must oversee strategy, management must align it with purpose, and compliance must be at the table from planning to performance review. Step into the strategic conversation early. Embed compliance considerations into scenario planning, risk assessment, and incentive design. Move beyond being a “fixer” after decisions are made. You are now a co-pilot in shaping resilient, risk-aware, and stakeholder-driven strategy.

Compliance Takeaway: Map your organization’s strategic plan to the four COSO strategy principles: purpose, development, execution, and measurement. Create or enhance compliance dashboards with ethical and cultural KPIs, and ensure the board is briefed on them.

4. Culture: From Soft Topic to Measurable Mandate

Culture is not simply a poster on the wall; rather, it is how people behave when nobody is watching. The CGF calls for boards to own culture oversight, with management embedding values in every business process, from hiring to crisis response. Culture is now measurable, manageable, and mission-critical. Create culture dashboards, integrate ethics into leadership assessments, and bring employee sentiment to the board. Remember, misaligned culture leads to misconduct, and compliance has the data to prove it.

Compliance Takeaway: Launch a culture governance program with clear metrics (hotline use, training engagement, exit interview themes). Schedule regular board updates and recommend third-party culture assessments every few years.

5. People: Talent Is Governance in Action

People make or break both strategy and culture. COSO’s People Component focuses on workforce planning, succession, compensation, and development, with the board responsible for oversight of the front line—partner with HR on leadership development, succession planning, and ethics in incentives. Review onboarding and offboarding for compliance moments of truth, and advocate for ethics questions in performance reviews. Do not simply check the HR box; bring a compliance risk lens to every talent conversation.

Compliance Takeaway: Review how people-related risks (succession gaps, compensation misalignment) are addressed in board and committee agendas. Propose ethics- and compliance-driven enhancements to talent processes, and pilot 360-degree reviews for key leaders.

6. Communication: Governance’s Nervous System

Communication is not simply about reporting; rather, it is the way governance breathes. The CGF emphasizes trustworthy data, technology enablement, escalation protocols, and stakeholder engagement. Ensure your GRC systems provide real-time, accurate insights. If your compliance program runs on spreadsheets, it’s time for an upgrade. Push for integrated platforms, streamlined reporting, and regular “lookback” exercises after incidents.

Compliance Takeaway: Lead a review of your communication tools and escalation pathways. Bring technology-enabled dashboards to executive and board meetings, combining compliance, risk, and culture indicators for holistic governance oversight.

7. Resilience: From Compliance Cost Center to Value Enabler

Resilience is the ability to anticipate, withstand, and adapt to disruption. The Resilience Component weaves together risk, compliance, internal control, and continuous monitoring and positions compliance as a pillar of enterprise stability. Expand your oversight of internal controls beyond financials—leverage technology to automate high-risk monitoring. Lead post-incident reviews that turn mistakes into governance muscle. Compliance is not just about “bouncing back” from crisis; it is about building systems that don’t break in the first place.

Compliance Takeaway: Map compliance risks to strategic objectives and ensure alignment with enterprise risk management (ERM). Use predictive analytics to flag emerging cultural or ethical risks and brief the board on how compliance is driving not just compliance but resilience.

What Makes COSO’s CGF Different—and What You Should Do Now

Cross-functional by design. Each Component connects with others—culture shapes strategy, people enable resilience, and communication powers oversight.

Principle-based, not prescriptive. The framework is adaptable across industries and geographies. It is not about ticking boxes but building a system that fits your organization.

Tech-forward and future-focused. AI, data, and technology are built in from the start, not an afterthought.

Final Takeaways for Compliance Professionals:

  • Engage early and often: Do not wait for the board to call you. Proactively map your program to the CGF’s Components.
  • Benchmark and build: Use the framework as a lens to spot gaps, propose improvements, and advocate for compliance in new domains (talent, tech, ESG).
  • Educate and evangelize: Socialize the CGF across the C-suite, HR, IT, and risk. Make compliance the bridge that connects governance with value creation.

Closing Thoughts: A Call to Action

The new COSO Corporate Governance Framework is a leadership manual for the modern compliance professional. It challenges us to see compliance as more than defense; it is the engine of long-term value, trust, and resilience.

If you are ready to move from risk mitigator to governance architect, COSO just handed you the playbook. Now’s the time to roll up your sleeves, engage with the board, and help build a governance system that will stand the test of disruption, scrutiny, and change.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Design-Centric Internal Controls

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at design-centric controls that lay the groundwork for effective internal controls.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 40 – Prime Directive Decisions: Ethics in Action from Star Trek’s “Friday’s Child”

Star Trek has always been about more than adventure. It is often a mirror for our ethical challenges, especially for those tasked with steering organizations through the tricky space of corporate compliance. The original series episode “Friday’s Child” offers a compelling look at negotiation, trust, and ethics under fire. While set on the distant planet Capella IV, the dilemmas faced by Captain Kirk and his crew echo those in today’s boardrooms and compliance departments. Today, we set our phasers to “learn” and beam down five ethical lessons for compliance professionals, each tied to a defining scene from this classic episode.

Lesson 1: Respect Local Customs—Even When They Conflict With Your Own Values

Illustrated By: Upon arrival on Capella IV, Kirk and his landing party encounter the fiercely traditional Capellan society. The Capellans’ customs, particularly their views on leadership and the role of women, are in stark contrast to those of the Federation. Kirk and Dr. McCoy are forced to tread carefully, knowing that any misstep could lead to violence or destroy negotiations.

Compliance Lesson: Operating globally means working in environments where local laws and customs may clash with your organization’s values or home-country regulations. Compliance professionals must develop cultural intelligence and adapt without compromising core ethical standards. Kirk’s diplomacy demonstrates the importance of engaging with local practices respectfully, seeking understanding before judgment.

Provide training for teams working abroad, focusing on cultural sensitivity and practical ways to address conflicts between local customs and organizational policies. Create protocols for escalating issues when legal or ethical lines are at risk of being crossed.

Lesson 2: Integrity in Negotiation Is Non-Negotiable

Illustrated By: As the Federation seeks mining rights on Capella IV, the Klingons arrive to negotiate with the Capellans, bringing duplicity and manipulation. The Klingon emissary, Kras, offers bribes and deceit, but Kirk insists on transparency—even when it puts the mission at risk.

Compliance Lesson: Negotiations, whether with third parties or regulators, test ethical boundaries. While competitors may take shortcuts or resort to unethical tactics, a compliance-driven organization must prioritize integrity. Kirk’s refusal to engage in deception sets a tone of ethical leadership that earns the grudging respect of the Capellans.

Embed ethics in your negotiation strategy. Establish clear boundaries and a code of conduct for employees and third parties, making it clear that winning at any cost is not acceptable. Regularly audit negotiations for compliance with both law and company values.

Lesson 3: Protect the Vulnerable—Even When It’s Not Easy

Illustrated By: After the assassination of Akaar, the Capellan leader, his pregnant widow, Eleen, becomes the target of violence. Federation protocol would have Kirk and his team withdraw, but McCoy and Kirk insist on protecting Eleen and her unborn child, risking their safety and the mission.

Compliance Lesson: Organizations must safeguard those in vulnerable positions—whether whistleblowers, employees facing retaliation, or communities impacted by business decisions. The true ethical test is what you do when protecting the vulnerable is inconvenient, costly, or unpopular.

Establish robust whistleblower protection programs, anti-retaliation measures, and processes for identifying at-risk individuals or groups. Make it clear that ethical obligations to protect the vulnerable are not optional, but a core part of your compliance mission.

Lesson 4: Ethical Courage Means Making Unpopular Decisions

Illustrated By: When Eleen, following Capellan law, insists that she does not want her child, McCoy faces a stark ethical dilemma. He risks offending her and violating local tradition by insisting on the child’s birth, believing it to be in her and the child’s best interests. Ultimately, his actions save both Eleen and her child, who becomes the new heir.

Compliance Lesson: There are moments when ethical behavior demands standing alone, challenging consensus, or confronting deeply ingrained practices. McCoy’s “tough love” illustrates the courage required to make the right decision, even when it’s not the popular one.

Lesson 5: Transparency and Communication Build Trust in Crisis

Illustrated By: As Kirk, Spock, McCoy, and Eleen flee from the Capellans and Klingons, success depends on clear, honest communication. Kirk keeps his crew and even Eleen informed at every stage, which allows them to adapt quickly and survive the dangers they face together.

Compliance Lesson: During crises, be it a compliance investigation, regulatory challenge, or public scandal, transparency and timely communication are critical. Hiding information, even with good intentions, breeds suspicion and undermines trust. Kirk’s example shows that open communication is not a luxury but a necessity, especially under pressure.

Prepare crisis communication protocols in advance. Train leaders to communicate openly, honestly, and quickly during emergencies. Ensure employees know how, when, and where to report issues, and how updates will be provided as matters evolve.

Final ComplianceLog Reflections

“Friday’s Child” may be set on a planet of warriors, but its ethical lessons are universal. For compliance professionals, the episode is a case study in what it means to lead ethically when stakes are high, the rules are unclear, and the path is fraught with danger.

From respecting local customs to standing up for the vulnerable, even at great personal or professional cost, the crew of the Enterprise demonstrates that ethics is not a luxury, but the core of mission success. The compliance officer’s role is not unlike Kirk’s: to navigate complexity, negotiate with integrity, protect those at risk, summon courage in the face of unpopularity, and build trust through transparency.

In a world where every new market brings new challenges and every crisis tests our character, “Friday’s Child” offers this timeless guidance: set your course by your values, and let ethical leadership be your prime directive.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

COSO’s Corporate Governance Framework: Component 6 – Resilience

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 6—Resilience. In today’s volatile business climate, one thing is sure: disruption is no longer the exception; it has become the norm. Whether it’s a cybersecurity incident, regulatory upheaval, geopolitical instability, or reputational crisis, the organizations that thrive are those that can bend without breaking. That’s why Component 6 – Resilience in the COSO Corporate Governance Framework (CGF) is more than timely; it may well be foundational.

For the compliance professional, resilience isn’t just about bouncing back—it’s about designing governance systems that withstand, anticipate, and even leverage disruption. The CGF reframes resilience as an integrated model that weaves together risk management, compliance, internal control, and continuous monitoring. This final Component of the framework is where compliance moves from policy enforcement to value creation. It is where compliance becomes a partner in operational continuity, strategic foresight, and cultural durability.

What Is the Resilience Component?

COSO defines resilience as the ability to withstand disruption, adapt to change, seize opportunity, and sustain long-term value. It is not reactive firefighting but rather about proactive design. This Component is structured around four principles:

  1. Manage and Oversee Risks and Opportunities
  2. Manage Compliance Responsibilities
  3. Establish and Evaluate Internal Control
  4. Monitor Governance Effectiveness

These principles span strategic, operational, and cultural dimensions of governance, reinforcing that a single function doesn’t own resilience. It’s built collaboratively across the board, executive leadership, internal audit, risk, and yes, compliance.

Why Resilience Belongs to Compliance

Compliance has continuously operated at the intersection of policy, people, and process. But in the Framework view, compliance is a key architect of resilience. Why? Because of the following:

  • Compliance sees how risks evolve across geographies, regulations, and business lines.
  • Compliance manages escalation, remediation, and accountability processes.
  • Compliance helps define the thresholds for risk acceptance and control failure.
  • Compliance monitors ethics and behavior—early indicators of cultural cracks.
  • Compliance is a trusted communicator in times of crisis.

The Resilience Component is our invitation to lead not just to prevent harm, but to build strength.

Five Key Lessons for Compliance Professionals

Lesson 1: Governance Without Risk Integration Is Incomplete

Principle 21: Manage and Oversee Risks and Opportunities

Executive management, with board oversight, must establish a structured, dynamic risk management process that aligns strategy, performance, and risk appetite. The board must allocate oversight of risk areas across committees while maintaining integrated ownership of enterprise-level risks.

Compliance Tip: Engage with your risk management function to ensure your compliance risks, such as regulatory enforcement, third-party integrity, and misconduct, are embedded in enterprise risk registers and heatmaps. Use scenario planning to show how legal and compliance risks could disrupt strategic objectives. Partner with the CRO to lead cross-functional risk workshops that consider both downside risk and upside opportunity (e.g., entering new markets with strong compliance advantages).

Lesson 2: Compliance Is Not a Silo—It’s a System

Principle 22: Manage Compliance Responsibilities

Compliance must be embedded across the enterprise, with clear ownership, independent oversight, robust policies, and responsive change management. The CCO must have the authority, access, and independence to lead an effective compliance program that evolves with risk.

Compliance Tip: Ensure your program includes both centralized compliance (for policy and strategy) and decentralized compliance partners (within functions or geographies). Consistency is key, but so is contextualization. Build a compliance change management protocol that activates when laws shift or operations expand. This should include regulatory horizon scanning, impact assessments, stakeholder training, and updated controls. Resilience depends on staying current, not compliant with yesterday’s standards.

Lesson 3: Internal Control Is Not Just Finance—It’s Enterprise Resilience

Principle 23: Establish and Evaluate Internal Control

Internal controls must support the achievement of operational, reporting, and compliance objectives. Executive management must align controls with ethics, legal obligations, and the entity’s risk profile, and boards must oversee their design and effectiveness.

Compliance Tip: Expand your oversight of controls beyond SOX and financial reporting. Review controls around conflicts of interest, data protection, anti-corruption, and third-party oversight. Collaborate with internal audit and risk to integrate compliance controls into enterprise-wide control frameworks and control testing cycles. Use this alignment to identify duplication, streamline assurance, and enhance board visibility.

Lesson 4: Monitoring Isn’t About Activity—It’s About Insight

Principle 24: Monitor Governance Effectiveness

Governance must be continuously monitored, not just audited periodically. This includes reviewing trends, stakeholder expectations, and gaps in policy or performance. Both the board and management should receive real-time insights on culture, compliance, and risk exposure.

Compliance Tip: Build dashboards that combine hard compliance metrics (e.g., training rates, hotline activity) with qualitative indicators (e.g., engagement survey results, tone-at-the-top assessments). Present these to executive leadership as part of quarterly reporting. Lead a governance “lookback” exercise after key incidents, such as investigations, regulatory inquiries, or market shifts. What worked? What broke down? What signals were missed? This practice turns mistakes into muscle.

Lesson 5: Technology Is a Force Multiplier—Use It to Scale Resilience

COSO highlights the power of technology, like GRC systems, data analytics, and artificial intelligence, to drive smarter, faster governance. Resilience requires visibility and agility, which technology can deliver when thoughtfully deployed.

Compliance Tip: Leverage tech to automate monitoring of high-risk processes, such as gifts & hospitality, vendor onboarding, or export controls. Use exception alerts to flag potential issues before they escalate—pilot predictive analytics for culture and ethics risk. Combine internal data (e.g., survey responses, exit interviews, training patterns) with external signals (e.g., Glassdoor, whistleblower trends) to identify emerging hotspots. That’s how resilient organizations get ahead of reputation-damaging crises.

Building a Resilience-Driven Compliance Program

Use COSO’s Resilience Component as the blueprint for a more integrated, forward-looking compliance program. Here’s how to begin:

  • Risk Integration: Map compliance risks to strategic objectives and ensure alignment with ERM.
  • Compliance Ownership: Assign roles and responsibilities at all levels, with a clear reporting line to the board.
  • Controls Framework: Ensure compliance controls are part of your internal control evaluation process, not isolated.
  • Technology Enablement: Deploy automation and analytics to monitor, report, and adapt.
  • Monitoring Infrastructure: Create a system for real-time visibility and feedback across all six COSO governance components.

This is not simply about regulatory defense. It’s about strategic readiness and stakeholder trust.

What Boards Need to Hear from Compliance

Bring these messages to your next governance, audit, or risk committee meeting:

  • Resilience is the outcome of integrated governance, compliance, risk, internal control, and culture that must work together.
  • Compliance is a strategic partner in managing disruption, not just avoiding penalties.
  • The board should regularly review compliance monitoring dashboards alongside risk and financial data.
  • The compliance function must be properly resourced and independent to support resilience.
  • Resilience is not just bouncing back; it is about designing systems that do not fold under pressure.

When boards see compliance as an enabler of value, not just a cost center, they make better decisions and support stronger programs.

Final Thoughts: Resilience Is the Future of Compliance

The COSO Resilience Component confirms what many of us have been saying for years: compliance must evolve from a reactive function to a proactive pillar of enterprise stability.

Do not simply write the policy. Build the process. Don’t just monitor conduct. Predict behavior. Don’t just advise in hindsight. Prepare with foresight. Because in governance, resilience isn’t a buzzword; it is a business model. And compliance is right at the center of making it real.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Internal Control Improvement

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at internal control override. It’s not necessarily bad, but it may indicate that your controls need improvement.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Blog

COSO’s Corporate Governance Framework: Component 5 – Communication

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 5—Communication. Suppose culture is the heart of an organization, and people are its muscle. In that case, communication is the circulatory system, carrying oxygen (information), nutrients (values), and antibodies (escalations and feedback) to every part of the governance body.

Most assuredly, it is not a side note. Communication is a core governance function, equally as critical as oversight, strategy, and culture. This component affirms something that compliance professionals have long known: poor communication creates risk, while effective communication fosters trust, resilience, and accountability. The Framework lays out a comprehensive roadmap for governing the quality, flow, and purpose of information both inside and outside the enterprise. It addresses communication as both a technical capability and a leadership responsibility, making it a perfect area for compliance professionals to lead from the front.

Today, we examine what Component 5 encompasses and identify five actionable lessons for compliance professionals who are ready to champion the communication function in governance.

What Does the Communication Component Cover?

COSO organizes this component around four principles:

  1. Commit to Information Quality
  2. Engage Stakeholders Strategically
  3. Communicate Effectively with Internal Stakeholders
  4. Communicate Effectively with External Stakeholders

Taken together, these principles stress that communication is strategic, multidirectional, and accountable. It is not just about what is said; rather, it is about who says it, how it is said, where it flows, and whether the message enables ethical decision-making, risk awareness, and stakeholder engagement.

Why Communication Matters to Compliance

For compliance professionals, communication is both a tool and a test. How we communicate policies, processes, and expectations shapes how employees behave. How the board receives information determines the quality of its decisions. How stakeholders perceive our transparency defines our license to operate.

More than ever, regulators, investors, and employees demand not just disclosure but meaningful, timely, and values-driven communication. That means compliance must go beyond the whistleblower hotline and annual training; we must build communication systems that enable governance excellence.

Five Key Lessons for Compliance Professionals

Lesson 1: Information Quality Is a Governance Issue—Own the Integrity of the Message

Principle 17: Commit to Information Quality

Boards and management must ensure that all internal and external information is accurate, complete, timely, and relevant to the decisions being made. This includes maintaining systems and controls to validate data and eliminate ambiguity in terminology.

Compliance Tip: Perform a communication audit of compliance reporting. Are your dashboards jargon-heavy or decision-ready? Do your risk reports help the board prioritize issues or confuse the message? Work with IT, internal audit, and risk to deploy governance, risk, and compliance (GRC) platforms that centralize and standardize your reporting. Use these tools not just to track activities but to tell a governance story.

Lesson 2: Stakeholder Engagement Is Risk Management—Make Communication Strategic

Principle 18: Engage Stakeholders Strategically

Executive management must identify key internal and external stakeholders and ensure that appropriate channels exist to share information, solicit feedback, and address concerns. This includes employees, investors, regulators, customers, suppliers, and communities.

Compliance Tip: Map your stakeholder communication channels, including the messages sent to whom, when, and through which medium. Identify gaps where feedback isn’t captured or transparency is lacking. Lead a quarterly cross-functional stakeholder forum with representatives from legal, ESG, investor relations, operations, and compliance. Use it to review messaging consistency, flag potential disconnects, and align on communication strategy for high-impact governance topics.

Lesson 3: Internal Communication Must Flow in All Directions—Not Just Top-Down

Principle 19: Communicate Effectively with Internal Stakeholders

Effective communication within the entity must support timely, secure, and informed decision-making across all departments and levels. It must include not only top-down directives, but also cross-functional collaboration and bottom-up feedback.

Compliance Tip: Evaluate whether your policies and training materials are accessible and understandable to frontline employees. Simplify complex legal language. Reinforce messaging across multiple touchpoints, not just once a year. Establish a compliance “listening architecture.” This could include monthly manager check-ins, anonymous digital suggestion boxes, and cultural pulse surveys. Use the insights to adapt your messaging, identify unspoken risks, and refine your program in real-time.

Lesson 4: External Communication Requires Guardrails—Balance Transparency and Confidentiality

Principle 20: Communicate Effectively with External Stakeholders

Boards and executive management must govern external communications with care, thereby ensuring transparency while protecting sensitive information and aligning with legal, regulatory, and reputational considerations. This includes formal disclosures, media engagement, investor briefings, and even social media interactions.

Compliance Tip: Coordinate with legal, investor relations, and public affairs to ensure external compliance disclosures (e.g., investigations, regulatory actions, ESG updates) are accurate and strategically timed. Recommend creating or expanding the entity’s disclosure committee beyond financial reporting. Include ethics, cybersecurity, and ESG in its scope. This ensures consistent governance over all public-facing statements, not just 10-Ks and earnings calls.

Lesson 5: Escalation Protocols and Whistleblower Systems Are Core Communication Channels

COSO stresses that communication is not simply about planned messaging, but it is about creating pathways for critical issues to reach decision-makers quickly. That includes whistleblower programs, hotline escalation, and crisis protocols that support real-time visibility and accountability.

Compliance Tip: Review your escalation policy. Is it clear when, how, and to whom an issue must be reported? Is there redundancy if a leader is implicated? Does the board know what “red lines” exist? Include whistleblower trends and escalation effectiveness as standing items in your board or audit committee materials. Go beyond volume and share insights about culture, responsiveness, and process quality. That’s how you earn board confidence and budget support.

Building a Governance Communication Program

To operationalize COSO’s Communication Component, compliance leaders should help lead the development of an integrated governance communication program with the following features:

  • Message alignment across all internal and external platforms;
  • Defined roles for who speaks, who approves, and who responds;
  • Feedback mechanisms like surveys, listening sessions, and open-door policies;
  • Secure reporting systems that support anonymity and protect whistleblowers; and
  • Crisis playbooks that define escalation paths, communications teams, and messaging protocols.

The goal? To ensure that communication is not just noise, but a narrative that guides behavior, enables decisions, and builds trust with all stakeholders.

What Boards Need to Hear from Compliance

Here’s what to communicate to your board:

  • The quality of governance depends on the quality of information.
  • Misaligned or confusing communication creates regulatory and reputational risk.
  • Stakeholders expect timely, truthful, and values-aligned information, not just compliance.
  • Compliance has a unique view into cross-functional communication gaps and whistleblower data.
  • The board should actively monitor communication systems and protocols, just as it does financial reporting.

When the board understands that communication is a control, not just a convenience, they will begin to ask better questions and set higher expectations.

Final Thoughts: Communication Is Governance in Motion

To determine whether your governance program is effective, listen to what people say and, equally importantly, what they do not. COSO’s Communication Component reminds us that in governance, silence is a risk, confusion is a vulnerability, and transparency is a strength.

As compliance professionals, we are communicators by necessity, but COSO invites us to become communicators by design. That means building systems that convey messages, address concerns, and connect people to their purpose. Governance is not just about structure; in many ways, it is about story. Make sure yours is told well.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.

Categories
Daily Compliance News

Daily Compliance News: July 9, 2025, The TACO Don Caves Again Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top compliance stories:

  • What happens when your bot goes antisemitic? (⁠NYT⁠)
  • Spanish PM announces new ABC laws amid graft probe. (⁠Bloomberg)⁠
  • Trump pushes back on tariff dates yet again. (⁠WSJ⁠)
  • Vibe coding for compliance. (⁠WSJ⁠)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief ⁠here⁠

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Internal Control Deficiencies

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with concise, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at how to deal with and report internal control deficiencies.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Assessing Internal Controls

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at how to assess your internal controls under COSO.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.