Categories
Adventures in Compliance

Adventures in Compliance: The Novels – The Hound of the Baskervilles, Introduction and Compliance Lessons Learned

In this new season of Adventures in Compliance, host Tom Fox takes a deep dive into the Sherlock Holmes novels. Throughout this season, Tom will delve into each novel in a four-part series. The four novels we will consider from the ethics and compliance perspective are A Study in Scarlet, The Sign of Four, The Hound of the Baskervilles, and The Valley of Fear.

In this episode (and for the entire month of July), we focus on the most famous Holmes novel, ‘The Hound of the Baskervilles.’ Timothy and Fiona are back to explore the key elements of the novel, connecting them with compliance themes and investigative techniques. They dissect the storyline, reveal insights, and discuss timeless lessons in rational thinking, the perils of unquestioned beliefs, and the power of meticulous observation and teamwork. Additionally, Tom invites listeners to provide feedback on the use of AI voices and offers to help those interested in starting their podcasts.

Highlights include:

  • Deep Dive into The Hound of the Baskervilles
  • The Mysterious Case Unfolds
  • Holmes’ Investigation and Revelations
  • Lessons from The Hound of the Baskervilles

Resources:

The New Annotated Sherlock Holmes

Sherlock Holmes FAQ by Dave Thompson

Sherlock Holmes, The Novels, with an introduction by Michael Dirda

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

COSO’s Corporate Governance Framework: Component 2-Strategy

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 2—Strategy. This component prioritizes compliance at the forefront of value creation. This is not just about watching for missteps. It’s about enabling the entity to pursue bold goals while staying grounded in ethics, purpose, and accountability.

For compliance professionals, this is a welcome and long overdue shift. Strategy is no longer just a business conversation; it’s a strategic imperative. COSO makes it clear: strategy is governance, and governance must include compliance at every stage—from definition to execution to performance monitoring. Today, we extract five key lessons for compliance professionals ready to step into a new leadership role.

I. Strategy in the COSO CGF: What It Covers

The Strategy Component of COSO’s CGF focuses on aligning the entity’s strategic direction with its purpose, values, and long-term objectives. It’s made up of four core principles:

  1. Define Purpose and Core Values
  2. Develop and Communicate the Strategy
  3. Execute the Strategy
  4. Measure Performance Against Strategy and Adjust

These principles provide a governance framework that not only connects the board and executive management but cascades responsibility throughout the entity, from strategy rooms to front-line decision-making.

Why Strategy Matters to Compliance

For years, strategy has been seen as the exclusive domain of the CEO, CFO, and business development leaders. Compliance was invited in after the fact, to clean up, audit, or assess risks. But COSO’s framework changes the conversation.

As compliance professionals, we bring a risk-aware, ethics-focused, stakeholder-sensitive perspective to the table. In an era of ESG mandates, AI disruption, global volatility, and regulatory scrutiny, strategy without compliance is incomplete. If your compliance function is not integrated into the strategy process, you are not practicing governance; you are essentially doing damage control.

II. Five Key Lessons for Compliance Professionals

Lesson 1: Start with Purpose—Not Just Policy

Principle 7: Define Purpose and Core Values

Boards and management must define the entity’s fundamental purpose, the “why” behind the business, and articulate the core values that guide decision-making, behavior, and stakeholder relationships. These values must be embedded into operations, strategic priorities, and performance incentives.

Compliance Tip: Tie your compliance policies, training, and reporting to the entity’s purpose and values. Do not discuss rules; instead, focus on alignment. Offer to help HR and communications integrate purpose into onboarding, annual certifications, and code of conduct messaging. When purpose becomes the language of the enterprise, compliance becomes a strategic partner.

Lesson 2: Compliance Must Be at the Strategy Table

Principle 8: Develop and Communicate the Strategy

Executive management, in consultation with the board, is responsible for developing the strategic plan, which encompasses competitive positioning, market risks, stakeholder expectations, and capital allocation. Strategy development must consist of scenario planning and risk alignment to maximize long-term value.

Compliance Tip: Join strategic planning conversations early. Provide insight on regulatory trends, reputational risks, geopolitical shifts, and stakeholder concerns that could derail strategy if not addressed upfront. Offer to run a pre-mortem exercise: If this strategy fails, why will it fail? Use compliance-led facilitation to identify blind spots in the business model.

Lesson 3: Execution Is Where Ethics Live or Die

Principle 9: Execute the Strategy

Executing the strategy requires a well-defined operating model, clear accountability, aligned incentives, and integrated reporting. Middle management translates strategic goals into action, and it’s here that ethical risk often emerges.

Compliance Tip: Get involved in operational risk reviews. Ask how incentives are aligned with values. Review whether performance metrics encourage long-term thinking or shortcut-taking. Collaborate with the COO or HR to incorporate ethical conduct and risk awareness into performance evaluations and team KPIs. This helps you drive a values-based strategy from the ground up.

Lesson 4: Metrics Matter—And So Does What You Measure

Principle 10: Measure Performance Against Strategy and Adjust

Management must develop and track both financial and non-financial KPIs to assess progress against strategic goals. The board oversees these metrics and ensures that adjustments are made when results or risks shift.

Compliance Tip: Contribute to KPI development. Suggest ethical culture indicators, hotline trends, third-party risk metrics, or audit closure rates as part of strategy dashboards. Push for the inclusion of lagging and leading indicators. It’s not enough to track what went wrong. Compliance needs metrics that alert us to potential issues before they occur. Compliance analytics is your secret weapon.

Lesson 5: Agility Requires Structure—Be the Change Advisor

COSO’s Strategy Component emphasizes the need for strategic agility. This is the ability to pivot in the face of market disruptions, new risks, or regulatory change. But agility does not mean chaos. It requires disciplined change management, escalation procedures, and decision-making protocols.

Compliance Tip: Be a Governance Resource During Change. Whether it’s a reorg, a product launch, a merger, or a crisis response, help ensure that the right people are consulted, documented, and accountable. Offer a compliance impact assessment for major strategic shifts. Show how culture, third-party relationships, data privacy, or anti-bribery obligations will be affected and what the plan is to stay in control.

III. Strategy Is a Compliance Priority—Not Just a Business One

COSO’s Framework makes something crystal clear: strategy is no longer “off-limits” to compliance. The board must oversee it. Executive management must align it with the purpose. And the compliance function must embed integrity, risk foresight, and stakeholder accountability into every strategic decision. We should break the old model that treated compliance as a back-end reviewer. We are now co-pilots. COSO has provided compliance with the governance language to claim its seat at the strategy table. Now it is up to us to use it.

How to Put This Into Practice

Here are five actionable steps for compliance teams:

  1. Review your company’s strategic plan through the lens of COSO’s four strategy principles. Start by mapping your organization’s current strategic plan against the four COSO Strategy principles: defining purpose and core values, developing the strategy, executing it, and measuring performance. Ask critical questions—Does the plan reflect your core values? Are ethical risks explicitly considered? Do compliance concerns inform strategic KPIs? This exercise helps compliance professionals identify gaps where compliance can bring additional value, ensuring the organization’s long-term strategy is rooted in accountability, integrity, and transparency. It also positions compliance as a proactive contributor to governance, not a reactive afterthought.
  2. Schedule a briefing with strategy or finance leaders to explore how risk and ethics are being integrated into the process. Establish a strategic dialogue with your CFO, head of strategy, or business development leadership to understand how ethical considerations and compliance risks are being integrated into planning. Bring COSO’s Strategy principles to the table as a common framework and ask how the company’s strategic models account for reputational risk, regulatory change, and stakeholder expectations. Use this time to identify areas where compliance can provide valuable insights, such as in ESG, M&A due diligence, or geopolitical risk assessment. These conversations open doors for cross-functional collaboration and foster trust with executives as they manage high-impact decisions.
  3. Develop compliance metrics that align with strategic objectives, such as trust, resilience, and stakeholder engagement, to ensure effective management and oversight. Move beyond traditional compliance outputs (e.g., number of training sessions or hotline reports closed) and align your metrics with enterprise-level strategic outcomes. Consider how to measure ethical culture, employee trust, third-party integrity, and the entity’s overall resilience to misconduct. Develop dashboards that can be integrated into strategic performance reviews or presented to executive management and the board of directors. Metrics might include culture survey participation, average investigation time, or third-party onboarding risk ratings. When compliance shows it can measure what matters to business leaders, it becomes a strategic asset, not a regulatory cost center.
  4. Pilot a strategic compliance review for a major initiative (product launch, M&A, market expansion). Choose a significant upcoming business initiative, perhaps a new product launch, geographic expansion, or merger, and embed compliance into the project team from the start. Conduct a compliance risk assessment tailored to the initiative’s strategy, market, and operating model. Ask how data privacy, third-party risk, anti-bribery compliance, and ethical culture will be protected during execution. Create an action plan that includes clear governance checkpoints, escalation triggers, and controls. This pilot not only demonstrates the value of compliance in driving strategic success, but it also establishes a replicable model for integrating compliance into future enterprise initiatives.
  5. Educate your board on the compliance implications of COSO’s Strategy Component—especially in strategy execution and performance monitoring. Prepare a board-level briefing or an audit committee presentation that focuses on how the compliance function supports strategic execution and long-term value creation. Use COSO’s Strategy principles to show how compliance intersects with business model design, culture, risk oversight, and scenario planning. Discuss how your function contributes to measuring non-financial performance indicators and adjusting strategy considering regulatory shifts or reputational risks. Reinforce the message that compliance is a governance tool, not just a defensive mechanism. By educating the board on these dynamics, you elevate the role of compliance in strategy and support a culture of forward-looking governance.

Final Thoughts: The Future of Strategy Is Compliance-Infused

We often say that strategy sets the tone for the business. However, as compliance professionals, we now have the tools and the COSO framework to ensure that our tone is ethical, risk-aware, stakeholder-conscious, and purpose-driven. Compliance should not simply review strategy; we should all move to shape it. Bring your questions, our insights, and our integrity to the table where the most important business decisions are made. That is what governance leadership looks like. COSO just gave compliance the playbook.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 33 – Investigative Lessons from Star Trek’s “Mirror, Mirror”

In the episode titled “Mirror, Mirror,” Captain Kirk, Dr. McCoy, Uhura, and Scotty encounter a transporter accident that thrusts them into a parallel universe. This alternate reality is a distorted mirror image of their universe, familiar yet different, governed by violence, suspicion, and fear rather than trust and mutual respect. Drawing directly from this episode, we examine five investigative lessons that compliance professionals can apply in their roles to ensure ethical resilience and organizational integrity.

Lesson 1: Quickly Recognize the Unexpected

Illustrated by: In the opening sequence, Kirk and his team are transported into the Mirror Universe.

Compliance Lesson: Compliance professionals must maintain heightened situational awareness during investigations, promptly identifying unexpected deviations, whether subtle discrepancies in financial reports, irregularities in third-party behaviors, or suspicious communications.

Lesson 2: Adapt and Blend into the Environment

Illustrated By: Realizing their perilous situation, Kirk instructs his crew to blend into the mirror universe’s ruthless culture.

Compliance Lesson: Compliance officers often operate within organizational cultures that vary significantly in terms of transparency, openness, and ethical climate.

Lesson 3: Secure Critical Information Discreetly

Illustrated By: A pivotal moment occurs when Kirk and Scotty clandestinely access the computer system in the mirror Enterprise to gather data discreetly.

Compliance Lesson: Compliance investigations frequently require discretion, confidentiality, and careful handling of sensitive data.

Lesson 4: Leverage Allies Within Complex Environments

Illustrated By: One crucial decision Kirk makes is trusting the mirror universe’s Spock enough to appeal to his logic and inherent sense of reason subtly.

Compliance Lesson: Building strategic relationships and leveraging internal allies can significantly improve investigation outcomes.

Lesson 5: Provide Actionable Guidance Based on Investigative Outcomes

Illustrated By: At the climax, Kirk directly confronts Mirror-Spock, presenting him with evidence and logical arguments to inspire long-term change within the oppressive Empire.

Compliance Lesson: Compliance officers are responsible for translating investigative findings into practical actions, guidance, process improvements, controls enhancements, or training recommendations that meaningfully mitigate future risk and promote an ethical organizational culture.

Final ComplianceLog reflections

The investigative narrative depicted in “Mirror, Mirror” presents powerful lessons for compliance professionals committed to conducting thorough, ethical, and effective investigations. Kirk and his crew were thrust into an environment of distorted realities, facing the daunting task of discerning truths within complex and dangerous situations. The strategies they adopted — early recognition, swift adaptation, discreet information gathering, strategic alliances, and actionable recommendations — mirror precisely the skills compliance officers require in navigating investigations.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 32 – Leadership Lessons for Compliance Professionals from “The Changeling”

Compliance, fundamentally, is about leadership. It is about guiding individuals and entire organizations to act ethically, responsibly, and effectively, even when the path is uncertain or challenging. Today, we venture boldly into the classic episode “The Changeling,” which offers rich lessons in leadership directly applicable to the world of corporate compliance. Here are five key lessons from the episode, illustrating critical skills compliance leaders must master.

Lesson 1: Clarity of Purpose is Essential

Illustrated By: Originally designed as a peaceful explorer, its mission was corrupted following a collision with an alien probe called Tan Ru, causing its core directives to merge and mutate dangerously.

Compliance Lesson. Compliance leaders must maintain absolute clarity about their purpose and objectives.

Lesson 2: Effective Communication Prevents Crisis Escalation

Illustrated by Kirk’s precise, deliberate communication with Nomad, it slows down its destructive tendencies and provides crucial time to develop a solution.

Compliance Lesson. Communication in compliance crises is similarly critical. Compliance leaders must communicate calmly and thoughtfully, particularly in high-stakes scenarios.

Lesson 3: Recognize When Adaptation is Necessary

Illustrated By: Initially, Kirk tries conventional diplomatic approaches. Recognizing that traditional methods have failed, he adapts swiftly and strategically.

Compliance Lesson. In compliance leadership, adaptability is essential. Regulatory landscapes and compliance risks are constantly evolving, necessitating swift pivots and agile leadership responses.

Lesson 4: Confront Problems Directly and Courageously

Illustrated By: When Nomad determines Captain Kirk himself to be flawed and thus a threat, Kirk faces Nomad directly, boldly confronting it without hesitation despite understanding the risk involved.

Compliance Lesson. Compliance leaders must similarly confront compliance issues directly and courageously. Avoiding difficult conversations or deferring tough decisions can magnify risks and vulnerabilities.

Lesson 5: Cultivate Critical Thinking Within the Team

Illustrated By: Throughout the episode, Kirk relies heavily on his team, particularly Spock’s analytical logic, Scotty’s technical skills, and Uhura’s linguistic insights after Nomad erases her memory.

Compliance is a collaborative discipline that requires collective critical thinking from diverse team members.

Final ComplianceLog Reflections

Each leadership lesson in this episode—clarity of purpose, effective communication, adaptability, courageous confrontation, and fostering critical thinking—is fundamental to guiding organizations safely through the complex maze of modern compliance challenges. Compliance leaders today face situations not unlike the Enterprise crew: unexpected challenges, high stakes, and rapidly changing conditions. The effectiveness of compliance hinges significantly on leadership skills that navigate these complexities with clarity, confidence, and ethical fortitude.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

COSO’s Corporate Governance Framework: Component 1 – Oversight

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 1: Oversight. It is a pillar that every compliance professional should study with the care of a board director preparing for their first 10-K briefing. The Framework is a clarion call for compliance professionals to rethink how we engage with governance, board structure, and accountability. Today, we will break it down and then dive into five lessons we must take back to our programs.

What Is Oversight in the COSO Framework?

The CGF defines oversight as the foundation of effective governance and long-term value creation. It begins with a board that is informed, independent, and proactive in directing strategy, supervising executive leadership, and maintaining organizational integrity.

But COSO doesn’t stop at roles and titles. The Oversight Component is made up of six principles:

Principle 1: Establish Board Structure and Exercise Oversight

This principle emphasizes that the board must create a well-defined governance structure with clearly assigned roles, responsibilities, and committees. It must actively exercise its oversight duties to support management’s execution of strategy while maintaining accountability to shareholders and stakeholders. Compliance professionals should engage early to ensure that governance structures also include strong compliance and ethics coverage, whether as standalone committees or integrated into audit or risk structures.

Principle 2: Appoint Board Leadership and Members

Boards must appoint competent, diverse, and independent leaders who possess integrity, objectivity, and a range of skills necessary to guide the organization effectively. Board leadership, whether a chair or lead independent director, must also foster effective decision-making and conflict resolution within the boardroom. Compliance teams should be prepared to assess and brief leadership on whether the board’s independence and composition are suited to today’s complex risk environment.

Principle 3: Select CEO and Delegate Authority

The board is responsible for selecting the CEO and formally delegating authority for strategic execution and operational decision-making. This includes maintaining clarity over which powers the board retains and which are delegated to management, ensuring accountability and effectiveness. Compliance should help define these boundaries, ensuring they include escalation protocols for compliance violations, investigations, and significant legal risks.

Principle 4: Establish Executive Structure and Effectively Manage

Executive management, with board oversight, must implement a governance structure that clearly outlines roles and responsibilities while enabling strategic execution, risk management, and ethical conduct. It requires maintaining effective internal communication and accountability mechanisms across business units. This principle affirms the compliance officer’s role in building the scaffolding for transparency and internal integrity in decision-making.

Principle 5: Operate the Board Effectively

Boards must regularly evaluate and refine their processes, calendars, and communication practices to optimize their oversight role. This includes utilizing executive sessions, clear meeting agendas, providing director access to management, and maintaining structured documentation to promote effectiveness and accountability. Compliance can support this effort by briefing directors on best practices for board effectiveness and helping to integrate compliance topics into existing agendas.

Principle 6: Uphold Shareholder Rights and Accountability

Boards and executive leadership must ensure that shareholder rights are protected and that disclosures enable informed decision-making and active engagement. This includes facilitating transparent communication, majority voting, and responding to shareholder concerns with respect and accountability. Compliance should assist in evaluating disclosure risks, supporting governance transparency, and managing the evolving expectations of institutional and activist investors.

Why It Matters to Compliance

Here’s the bottom line: Oversight defines the altitude from which the board governs—and the depth to which management is held accountable. It is where compliance either has a voice or is left scrambling to clean up messes.

As COSO puts it, oversight is shaped by:

  • Legal and regulatory obligations
  • Listing exchange standards
  • Shareholder and stakeholder expectations
  • Evolving risks and strategic complexity

Crucially, effective oversight depends on trust, transparency, and the willingness of directors to challenge management when necessary. If you are a compliance officer, you are the steward of that trust every time you walk into the boardroom or brief an audit committee.

Five Key Lessons for Compliance Professionals

Lesson 1: Structure Drives Behavior—Support the Right Board Composition

COSO reminds us that structure is not simply about paperwork; rather, it is about performance in waiting. Boards must have the right mix of committees, including audit, compensation, and nominating/governance, as well as tailored structures for emerging risks such as cybersecurity, ethics, and compliance.

Compliance Tip:

Be proactive in suggesting committee enhancements. If you see ESG risks mounting, propose a joint compliance-risk-ESG working group. If your board lacks a compliance-specific charter, now is the time to offer a draft. Offer benchmarking from peer organizations or industry regulators. Bring data to the table when proposing changes to board governance.

Lesson 2: Director Independence and Expertise Matter—Help Evaluate It

The CGF emphasizes that a supermajority of the board should be independent and that independence extends beyond a lack of financial ties; it also encompasses freedom from undue influence, appropriate tenure, and cognitive diversity.

Compliance Tip:

Your compliance and risk reports can shape how directors perceive their effectiveness. Provide clear, factual, and nuanced briefings, especially around risk appetite, incident investigations, and policy gaps. Encourage your board to adopt a skills matrix and evaluate directors on competencies related to ethics, compliance, and oversight, in addition to finance and operations.

Lesson 3: Board–Executive Relationships Are a Two-Way Street—Support the Feedback Loop

COSO emphasizes that executive management and the board need a trust-based, collaborative relationship. This means access to information, clarity of delegation, and open channels of communication, especially in a crisis.

Compliance Tip:

Use your role as a bridge, not a barrier, between management and the board. Ensure the board has access to accurate, real-time insights into investigations, emerging compliance issues, and root cause analyses. Help define and document escalation protocols. In times of crisis, ambiguity kills. Clear lines of escalation protect both the board and the business.

Lesson 4: Oversight Extends to Culture—Not Just Numbers

One of the most progressive moves COSO makes in this component is tying board oversight to organizational culture and behavior modeling. Directors must demonstrate ethics, respect, and transparency, just like the CEO.

Compliance Tip:

Start including culture indicators in your regular reporting, such as hotline trends, employee engagement results, training completion rates, and code of conduct violations. Do not simply report metrics; instead, contextualize them to make them more meaningful for your audience. Invite board members to participate in listening sessions or ethics town halls. Direct exposure to employee sentiment builds empathy and accountability.

Lesson 5: Shareholders Are Oversight Partners—Prepare for Transparency

The CGF challenges entities to uphold shareholder rights and engagement through transparent disclosures, majority voting for directors, and stewardship activities.

Compliance Tip:

Work closely with investor relations and legal to ensure your compliance-related disclosures are accurate, meaningful, and aligned with shareholder expectations. Don’t wait until an activist investor demands it. Conduct a pre-mortem with your team and board: If an activist investor were to challenge our compliance program, where would they strike first? Fix that area today.

What’s New and Noteworthy?

There are several leading-edge considerations embedded in the Oversight section that every compliance officer should note:

  • Expanding compensation committee roles to include culture, diversity, and talent oversight
  • Increased use of executive sessions for confidential discussions without management
  • Policies to prevent overboard, especially for sitting executives and CEOs
  • Structured onboarding and offboarding for directors to maintain freshness and avoid stagnation

These are not just governance best practices. They are compliance enablers. A stagnant board is a blind board. A distracted director is a dangerous one.

Final Thoughts: Oversight Is a Team Sport

Too often, compliance professionals think of board oversight as something that happens to us; we prepare the decks, present our updates, and answer tough questions. But COSO’s Oversight Component invites us to flip the narrative. We are not bystanders in governance; we are builders of it. Tell the story.

When we engage with the board with clarity, courage, and consistency, we not only raise the profile of compliance but also enhance our credibility. We help shape an oversight model that can weather disruption, lead through crisis, and deliver long-term value. Let your voice be heard in the boardroom. Do not just brief on the risks; build the systems that make risk manageable. This is our moment. Let’s own it.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes on July 11, 2025.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – COSO Objective 2 – Risk Assessment

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we continue our look at the 5 COSO Objectives. Today, Number II—Risk Assessments.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – COSO Objective 1 – Control Environment

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we begin a look at the 5 COSO Objectives—first up, Number I—Control Environment.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Blog

Elementary, My Dear Compliance Officer: Communication and Training Insights from Sherlock Holmes’ ‘The Sign of Four’

One of my great pleasures is exploring the fascinating intersection of classic literature and corporate compliance. Sir Arthur Conan Doyle’s Sherlock Holmes stories, with their rich narrative and keen insights into human nature, consistently offer valuable lessons for compliance professionals. As we conclude our review of “The Sign of Four” in this month’s series on Adventures in Compliance, I aim to demonstrate how the novel offers valuable insights into the pivotal compliance domains of communication and training.

Lesson 1: Clarity and Precision in Communication

Early in “The Sign of Four,” Holmes remarks, “When you have eliminated the impossible, whatever remains, however improbable, must be the truth.” This oft-quoted maxim emphasizes the importance of clear and precise communication in compliance training and operations. Compliance professionals must eliminate ambiguity and confusion in their policies, procedures, and communications to ensure that employees understand exactly what is expected of them.

Consider Holmes’s meticulous questioning of Mary Morstan and the careful recording of details concerning the mysterious pearls. Similarly, compliance professionals must ask precise questions when developing training materials or internal communications to ensure accuracy and effectiveness. By doing so, they provide the accuracy and relevance of their messaging, ultimately aiding employees in distinguishing right from wrong and prohibiting prohibited actions.

Lesson 2: Effective Training Through Repetition and Reinforcement

In solving the mystery, Holmes revisits clues repeatedly, reinforcing their significance. Similarly, compliance training is most effective when key messages and ethical principles are regularly repeated and reinforced through multiple channels and formats. A single annual training session is inadequate in today’s fast-paced regulatory environment.

Continuous reinforcement helps embed compliance in the organizational culture, much like Holmes continually revisits facts until they form a coherent whole. Consider periodic refreshers, interactive quizzes, and regular reminders in newsletters or meetings to reinforce core compliance messages. Employees should consistently hear, see, and engage with compliance principles, transforming them from abstract guidelines into habitual behaviors.

Lesson 3: Tailored Communication to Diverse Audiences

Holmes is famously adaptable, shifting his communication style to suit the needs of his audience. His interactions vary considerably, from the sensitive approach to the distressed Mary Morstan to the precise, professional exchanges with Inspector Atheney Jones. Compliance officers must similarly tailor their messages to resonate with different employee groups, from frontline workers to senior executives.

Recognizing that one size does not fit all is crucial. Training programs and compliance communications should consider the employees’ roles, departments, and specific responsibilities. Just as Holmes intuitively adapts his investigative approach, compliance professionals must adjust the tone, style, and complexity of their communications to effectively engage diverse audiences, ensuring that everyone receives a clear and understandable message tailored to their needs.

Lesson 4: Transparency Builds Trust

“The Sign of Four” revolves significantly around the themes of honesty and transparency. The hidden treasure and clandestine actions create a web of mistrust and conflict. Conversely, Holmes’s straightforward and transparent investigative style engenders trust and cooperation among his allies.

Transparency is equally fundamental in compliance. Openness in communicating compliance objectives, procedures, and the rationale behind them fosters a culture of trust and transparency. Employees who understand why specific policies are necessary and the benefits of compliance to the organization are far more likely to adhere willingly and enthusiastically. Regular, transparent updates on compliance matters, including mistakes and lessons learned, strengthen organizational trust, promoting compliance as a positive value rather than a restrictive burden.

Lesson 5: Communication of Expectations Clearly and Early

When engaging with clients and associates, Holmes clarifies his investigative process and sets clear expectations from the outset. This approach ensures mutual understanding and alignment, which is crucial for a successful partnership.

Similarly, compliance professionals must communicate expectations as early as possible. New hires should immediately understand the importance of compliance and the standards they are expected to uphold. Regular reinforcement of these expectations at milestones and through ongoing communications ensures alignment and reduces ambiguity, minimizing the risk of inadvertent non-compliance.

Lesson 6: Interactive Training Enhances Retention

Throughout the novel, Holmes engages actively with Dr. Watson, using interactive dialogue to sharpen Watson’s observational and deductive skills. This interactive method greatly enhances Watson’s ability to absorb and retain information.

Compliance training should similarly be interactive rather than merely didactic. Interactive scenarios, case studies, role-playing exercises, and gamification of training modules can significantly improve engagement and retention. Employees actively participating in compliance training are more likely to internalize the lessons and apply them in real-world scenarios.

Lesson 7: Crisis Communication Preparedness

Holmes adeptly manages crises by remaining calm and methodically communicating his deductions and plans clearly and concisely. His approach minimizes panic and maximizes efficiency during critical moments.

Compliance professionals must adopt a similar methodical approach to crisis communication. Preparing clear, concise crisis communication protocols in advance helps organizations respond swiftly and effectively when faced with compliance issues. Training staff to remain calm, follow established communication channels, and clearly articulate necessary actions ensures organizational resilience during crises.

Conclusion

Sherlock Holmes continues to offer timeless lessons for compliance professionals, particularly in the areas of effective communication and training practices. “The Sign of Four” exemplifies these lessons vividly. Clarity, repetition, tailored messaging, transparency, early communication of expectations, interactive engagement, and preparedness for crisis communication are all critical for creating and sustaining a strong compliance culture.

By emulating Holmes’s meticulous attention to detail, adaptability, and clarity in our communications and training strategies, compliance professionals can significantly enhance their effectiveness. Ultimately, this approach not only ensures regulatory compliance but also builds stronger, more ethical organizational cultures, much as Holmes builds clarity and trust in his cases, one meticulous observation at a time.

Categories
Blog

Navigating Global Travel Risks: Essential Strategies for U.S. Employers

International business travel has always presented its own unique set of logistical hurdles; however, today’s volatile geopolitical landscape significantly elevates these challenges. Rebecca Knight’s recent Harvard Business Review article, “An International Travel Checklist for U.S. Employers,” highlights the need for organizations to reassess their international travel strategies comprehensively. Given how poorly the Trump Administration is treating all other countries, friend and foe alike, it might be a good time for every compliance professional to assess their company’s travel risks and risk management strategies.

Knight emphasizes the duty of care obligation inherent in corporate travel management. This fiduciary responsibility compels companies to ensure employee safety, comply with federal requirements, and maintain thorough preparedness for travel contingencies. The article highlights the complexity introduced by recent political shifts, notably the Trump administration’s expansive travel bans affecting numerous nations.

For U.S. employers, clarity regarding employees’ travel authorization statuses is critical. Companies must maintain precise records of sponsored visas and short-term work statuses, tracking renewal deadlines meticulously. (IE. Document Document Document) Additionally, proactive communication is key. Organizations must inform foreign nationals about potential entry issues that may arise from previous legal issues or political activities, equipping them with comprehensive information about their rights and the likely entry challenges they may face.

Knight advises establishing a clear framework to evaluate the necessity of each business trip. Travel decisions must consider whether in-person engagement directly impacts crucial business outcomes, such as securing contracts or fostering client relationships, or if remote meetings could suffice. This framework should also ensure the equitable treatment of employees with varying passport privileges, thereby promoting fairness and equal opportunity across all international travel decisions.

Preparation includes briefing employees thoroughly about the entry requirements. Proper documentation, such as valid visas or an Electronic System for Travel Authorization (ESTA), is mandatory. Organizations should clearly outline protocols for dealing with potential border issues, including denials of entry or additional scrutiny, and identify internal support structures, such as HR and legal resources, to assist employees in navigating these challenges.

Knight further suggests developing robust contingency plans for unexpected shifts in travel policy. Companies must be agile, ready to relocate meetings or conferences, and implement alternative travel routes or pre-clearance strategies to mitigate disruptions. For example, directing employees through U.S. pre-clearance immigration locations such as Dublin can effectively manage potential border complications proactively.

Lastly, Knight emphasizes the importance of striking a balance between cautious awareness and practical decision-making. While it’s prudent to acknowledge and prepare for risks associated with international travel, organizations should avoid excessive conservatism. Effective leaders strive to maintain operational fluidity and business continuity, avoiding fear-induced paralysis.

5 Key Takeaways for Compliance Professionals:

  1. Maintain Comprehensive Employee Travel Records: Regularly update and monitor visa statuses and authorization documents to ensure compliance and readiness for policy changes. Implement robust tracking systems and databases to flag potential issues well ahead of travel dates. Proactive management of travel documentation reduces risk, enhances operational efficiency, and ensures employees can travel without interruption. Ensure that all personnel responsible for travel oversight are adequately trained to recognize and promptly address documentation discrepancies, thereby minimizing organizational vulnerability and potential legal challenges.
  2. Communicate Proactively with Foreign Nationals: Inform employees of potential risks associated with their specific circumstances, preparing them adequately for border entry scenarios. Proactive dialogue helps employees understand their rights and obligations, significantly reducing anxiety and improving compliance. Develop clear guidelines outlining possible entry complications, offer legal resources, and maintain open channels for employees to raise concerns or seek clarification. Effective communication strategies foster trust, enhance morale, and ensure smoother international travel operations.
  3. Evaluate Trip Necessity and Fairness: Implement frameworks to systematically assess the critical nature of international travel, striking a balance between business needs and equity among employees. Decisions should transparently weigh the value of in-person engagements against virtual alternatives. Explicit criteria help organizations prioritize critical business trips and provide a clear rationale for travel approvals or denials. Such frameworks should also emphasize equitable treatment of employees with differing passport privileges, ensuring that travel decisions do not inadvertently disadvantage or discriminate against certain groups.
  4. Develop Robust Contingency Plans: Anticipate and prepare for sudden policy changes or entry issues by establishing alternative meeting locations, travel routes, and comprehensive pre-clearance procedures. Robust contingency planning includes identifying alternative arrangements for meetings and conferences, pre-clearing employees at international immigration checkpoints, and routing travel through strategic hubs. Organizations should regularly rehearse contingency plans, adapting them based on evolving geopolitical contexts and operational realities. This proactive approach ensures continuity in critical business functions despite unpredictable changes in travel policy.
  5. Balance Caution with Practicality: Aim for informed, thoughtful decision-making that prioritizes employee safety and compliance without unnecessarily hindering essential business activities. Companies must navigate a careful balance between prudence and operational necessity, ensuring neither excessive caution nor reckless disregard for potential risks. Leaders should foster a culture of informed vigilance, where risks are acknowledged, prepared for, and managed effectively without overly constraining business agility. Establish clear, evidence-based decision-making protocols that empower leaders to make judicious choices, safeguarding employee welfare while sustaining organizational productivity and competitiveness.

In conclusion, navigating international travel risks demands a strategic blend of meticulous preparation, clear communication, and agile responsiveness. As geopolitical landscapes continue to shift unpredictably, compliance professionals must proactively manage employee documentation, maintain open and transparent communications, and regularly evaluate the necessity and fairness of travel decisions. Robust contingency planning, complemented by balanced and pragmatic decision-making, is crucial for mitigating potential disruptions and maintaining organizational resilience. By embracing these comprehensive strategies, companies not only ensure regulatory compliance and employee safety but also position themselves effectively to adapt and thrive in the face of ongoing global uncertainties.

Categories
Blog

What Gets Measured AI Will Automate: Compliance Lessons in the Age of AI

“What gets measured gets managed” is a long-standing business adage attributed to management guru Peter Drucker. Today, in the age of artificial intelligence (AI), we can adapt this adage into a new compliance paradigm: “What gets measured gets automated.” Compliance professionals must grasp this shift, anticipate its impacts, and leverage AI strategically to enhance their compliance programs.

Automation is no longer confined to repetitive, mundane tasks. As highlighted by Christian Catalini, Jane Wu, and Kevin Zhang in their recent HBR article, What Gets Measured, AI Will Automate, AI’s capabilities now encompass complex cognitive tasks such as analysis, design, and even creative writing. This transformation is facilitated by powerful models that can rapidly absorb, analyze, and act upon extensive data sets. For compliance professionals, this signifies that areas heavily reliant on data, such as financial analysis, audits, regulatory monitoring, and reporting, are prime candidates for automation.

Understanding AI’s Automation Potential in Compliance

To effectively leverage AI, compliance professionals must first understand the scope of its potential. The article underscores that any task definable by data, a measurable outcome, and sufficient computational power is ripe for AI-driven automation. Compliance activities, such as monitoring transaction data for suspicious activities, continuously tracking regulatory updates, and managing compliance audits, fit neatly into this framework.

Consider transaction monitoring under anti-money laundering (AML) regulations. AI systems, once trained on vast historical transaction data, can instantly identify anomalies far beyond human capability, significantly enhancing detection accuracy and reducing false positives. Similarly, AI tools can autonomously track regulatory changes across jurisdictions, interpret updates, and swiftly integrate them into compliance frameworks, ensuring continuous alignment with legal mandates.

Embracing the Automation Imperative

Catalini, Wu, and Zhang note the increasing trend toward automation, citing statistics from AI firm Anthropic, which indicate that 43% of interactions with AI involve automated tasks rather than human-augmented activities. This trend underscores the need for compliance departments to adopt automation proactively.

Organizations must actively identify and prioritize measurable compliance processes for automation, thereby reallocating human resources to areas that require complex judgment and strategic decision-making. Automation in compliance does not imply reducing the significance of the workforce; instead, it empowers compliance professionals to focus on higher-order tasks that require nuanced understanding and contextual judgment.

Navigating the Human-AI Collaboration

A crucial takeaway from the authors is the delineation between tasks suited for automation and those demanding inherent human judgment, such as ethical decision-making, nuanced risk assessments, and novel compliance strategies. Tasks involving uncertainty or requiring a human touch, like ethical deliberations and whistleblower investigations, remain less suited for full automation.

Incorporating AI, therefore, should not be an all-or-nothing strategy. Compliance professionals must strive for a harmonious partnership between humans and AI, leveraging the strengths of each. For instance, AI can efficiently manage regulatory changes while compliance teams interpret these insights and apply them strategically within their organizational context.

Strategic Implementation of AI in Compliance

The authors advocate for a strategic approach that identifies tasks that AI can readily automate based on three foundational components: data availability, measurable objectives, and computational feasibility. Compliance teams should systematically catalog compliance processes against these criteria to identify opportunities for automation and optimization.

For example, continuous monitoring systems can integrate AI to streamline monitoring and enhance predictive capabilities, proactively flagging emerging compliance risks before they manifest. AI-driven platforms can analyze extensive datasets from past compliance breaches to identify patterns and predict potential future risks, thereby enabling compliance teams to act preemptively.

Leveraging AI for Continuous Improvement

One significant advantage emphasized by the authors is AI’s ability to improve through iterative learning cycles continually. Compliance automation, supported by machine learning algorithms, continuously refines itself, becoming increasingly accurate and responsive. This capability is particularly critical in compliance, where the risk landscape constantly evolves.

By integrating AI-driven continuous improvement into their compliance monitoring systems, companies can achieve significant efficiency gains. For instance, iterative improvements in anomaly detection algorithms reduce false positives over time, enabling more precise resource allocation in compliance investigations.

Confronting Challenges and Risks

Despite AI’s potential, compliance professionals must remain vigilant regarding inherent challenges and risks, such as algorithmic bias, data privacy concerns, and model transparency. Effective governance structures must oversee the implementation of AI, ensuring its ethical deployment is aligned with regulatory expectations and organizational values.

Transparency and explainability of AI-driven compliance decisions will increasingly become regulatory imperatives, underscoring the need for models that clearly articulate their decision-making processes. Compliance professionals must advocate for model interpretability, working closely with data scientists to develop explainable AI solutions that withstand regulatory scrutiny.

Preparing for the Future

The authors emphasize a clear message: in the future landscape of compliance, tasks amenable to measurement and automation will swiftly transition into the AI domain. Compliance leaders must proactively identify these tasks, implementing robust automation strategies while simultaneously focusing human effort on navigating uncertainty, making strategic decisions, and addressing ethical considerations.

Compliance professionals can draw inspiration from innovators like Amar Bose, mentioned by the authors, who succeeded by prioritizing qualitative human experiences over quantitative metrics alone. Similarly, compliance programs must strike a balance between measurable automation efficiencies and qualitative human judgment, thereby fostering resilience and adaptability.

The future of compliance lies not in resisting automation but in embracing it strategically. Compliance professionals equipped to leverage AI’s capabilities proactively will find themselves better positioned to manage evolving risks effectively. By automating measurable tasks, compliance teams can reallocate resources to address complex uncertainties, enhancing their strategic impact and ultimately strengthening organizational integrity.

In the age of AI, compliance professionals who effectively combine automated precision with nuanced human judgment will set new benchmarks in compliance excellence.