Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 63 – Awakening Compliance: How ‘For the World is Hollow and I Have Touched the Sky’ Illuminates Training

One episode, “For the World is Hollow and I Have Touched the Sky,” offers a wealth of insights for designing and delivering effective compliance training. This is more than just an adventure; it is a story about the perils of ignorance, the need for transparency, and the transformative power of knowledge, all core tenets of modern compliance.

Lesson 1: Question Dogma—Don’t Train to the Test

Illustrated by: The Yonadan society follows rigid rules set by the Oracle. No one asks “why,” and those who do—like the man who claims, “For the world is hollow and I have touched the sky”—are punished or silenced.

Compliance Lesson: All too often, organizations approach compliance training as a box-checking exercise, focused solely on rote memorization of policies or procedures. Just as the Yonadans lived in a society where questioning was forbidden, employees may come to see compliance as a set of rigid “dos and don’ts” instead of a dynamic process that welcomes curiosity and improvement.

Lesson 2: Reveal the Big Picture—Context Matters

Illustrated by: The people of Yonada do not realize they are living on a generational ship, believing instead that their enclosed environment is the entire world. Only by discovering the truth can they make choices that affect their fate and survival.

Compliance Lesson: If your training never explains the “why” behind your policies and never reveals the big picture, you risk creating a workforce that follows the rules blindly or, worse, resents them.

Lesson 3: Foster Psychological Safety—Mistakes are Learning Opportunities

Illustrated by: The Oracle enforces its rules with fear and punishment. The Yonadans are afraid to admit mistakes or challenge the status quo, leading to a stagnant society unable to adapt or improve.

Compliance Lesson: A fear-driven compliance culture is doomed to fail. Employees will hide mistakes, avoid speaking up, and resist engaging with training. Psychological safety, the ability to ask questions or admit errors without fear of retribution, is foundational for any successful compliance program.

Lesson 4: Adapt Training for Changing Risks—Update and Refresh

Illustrated by: The threat facing Yonada is new—their world-ship is heading toward disaster. The Oracle’s unchanging edicts are no match for this new risk, and the society’s inability to adapt puts everyone in jeopardy.

Compliance Lesson: Compliance risks are not static. If your training program never evolves, you risk leaving your organization unprepared for the compliance challenges of tomorrow.

Lesson 5: Leadership Engagement is Critical—Lead from the Front

Illustrated by: Dr. McCoy, Captain Kirk, and Mr. Spock do not simply observe the Yonadans from a distance. They intervene, ask questions, and, critically, help Natira and others find the courage to seek the truth and lead change from within.

Compliance Lesson: Leadership’s visible commitment to compliance is the strongest signal to employees that these issues matter.

Final ComplianceLog Reflections

“For the World is Hollow and I Have Touched the Sky” is a cautionary tale about the dangers of blind obedience and the critical importance of knowledge, context, and leadership. Compliance professionals have a unique role as navigators, helping their organizations see beyond the walls of their “worlds,” challenge assumptions, and build a culture where doing the right thing is second nature. By making compliance training meaningful, adaptive, and inclusive, you’ll ensure that your organization not only avoids the fate of Yonada but instead truly “touches the sky.”

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Touching the Sky: Compliance Training Lessons from “For the World is Hollow and I Have Touched the Sky”

The worlds of science fiction and compliance may seem galaxies apart, but seasoned compliance professionals know that some of our most profound lessons come from the most unexpected places. Nowhere is this more apparent than in Star Trek: The Original Series (TOS), where moral dilemmas, societal challenges, and questions of leadership are played out on a galactic scale. One episode in particular, “For the World is Hollow and I Have Touched the Sky,” offers a wealth of insights for designing and delivering effective compliance training.

Let’s beam aboard the Enterprise, revisit this classic episode, and discover five enduring compliance training lessons drawn directly from the drama of Yonada, a generational ship whose people have forgotten their true purpose and live under a set of unquestioned, dogmatic rules. As you’ll see, the stakes aboard Yonada are not so different from those in your organization when it comes to the importance of questioning, learning, and continuous improvement.

The Enterprise crew encounters a mysterious asteroid ship on a collision course with a populated planet. On board, they find a society governed by the all-powerful Oracle, which forbids its people from questioning their world or seeking the truth. Dr. McCoy, facing a terminal illness, finds love with Natira, the High Priestess. The Enterprise team must help the Yonadans uncover the reality of their world to avert disaster.

This is more than just an adventure; it is a story about the perils of ignorance, the need for transparency, and the transformative power of knowledge, all core tenets of modern compliance.

Lesson 1: Question Dogma—Don’t Train to the Test

Illustrated by: The Yonadan society follows rigid rules set by the Oracle. No one asks “why,” and those who do—like the man who claims, “For the world is hollow and I have touched the sky”—are ”punished or silenced.

Compliance Lesson: All too often, organizations approach compliance training as a box-checking exercise, focused solely on rote memorization of policies or procedures. Just as the Yonadans lived in a society where questioning was forbidden, employees may come to see compliance as a set of rigid “dos and don’ts” instead of a dynamic process that welcomes curiosity and improvement.

What should you do? Effective compliance training should encourage questioning. Create scenarios where employees are asked “why” a rule exists, not just “what” the rule is. Empower your workforce to speak up if they notice something that doesn’t make sense. Instill the message that curiosity and healthy skepticism are not only allowed but expected.

Lesson 2: Reveal the Big Picture—Context Matters

Illustrated by: The people of Yonada do not realize they are living on a generational ship, believing instead that their enclosed environment is the entire world. Only by discovering the truth can they make choices that affect their fate and survival.

Compliance Lesson: Employees often see compliance policies as abstract or disconnected from daily business realities. If your training never explains the “why” behind your policies and never reveals the big picture, you risk creating a workforce that follows the rules blindly or, worse, resents them.

What should you do? Use compliance training to connect the dots. Show how policies fit into the company’s broader mission and values. Illustrate the impact of compliance and non-compliance with real-world stories, including enforcement actions or “near misses.” Make it clear how every employee’s actions contribute to the health and safety not only of the company but also of its broader community.

Lesson 3: Foster Psychological Safety—Mistakes are Learning Opportunities

Illustrated by: The Oracle enforces its rules with fear and punishment. The Yonadans are afraid to admit mistakes or challenge the status quo, leading to a stagnant society unable to adapt or improve.

Compliance Lesson: A fear-driven compliance culture is doomed to fail. Employees will hide mistakes, avoid speaking up, and resist engaging with training. Psychological safety, the ability to ask questions or admit errors without fear of retribution, is foundational for any successful compliance program.

What should you do? Build psychological safety into your compliance training. Include scenarios that show how mistakes should be reported and discussed openly. Make it clear that the company values transparency and improvement over blame. Encourage managers to model vulnerability by sharing their own learning experiences.

Lesson 4: Adapt Training for Changing Risks—Update and Refresh

Illustrated by: The threat facing Yonada is new—their world-ship is heading toward disaster. The Oracle’s unchanging edicts are no match for this new risk, and the society’s inability to adapt puts everyone in jeopardy.

Compliance Lesson: Compliance risks are not static. Laws change, markets shift, and new threats emerge. If your training program never evolves, you risk leaving your organization unprepared for the compliance challenges of tomorrow.

What should you do? Regularly refresh your compliance training content. Update it to reflect new regulations, emerging risks, or lessons learned from recent incidents. Solicit employee feedback to keep the program relevant. Make compliance training a living process, not a one-time event.

Lesson 5: Leadership Engagement is Critical—Lead from the Front

Illustrated by: Dr. McCoy, Captain Kirk, and Mr. Spock, they do not simply observe the Yonadans from a distance. They intervene, ask questions, and, critically, help Natira and others find the courage to seek the truth and lead change from within.

Compliance Lesson: Leadership’s visible commitment to compliance is the strongest signal to employees that these issues matter. When leaders engage directly with training, attending sessions, asking questions, and sharing their own stories, they set the tone for the entire organization.

What should you do? Make leadership involvement a non-negotiable part of compliance training. Feature C-suite executives in training videos, host “ask me anything” sessions on compliance topics, and reward leaders who model compliance-oriented behavior. The message is clear: compliance is everyone’s responsibility, starting at the very top.

Final ComplianceLog Reflections

“For the World is Hollow and I Have Touched the Sky” is a cautionary tale about the dangers of blind obedience and the critical importance of knowledge, context, and leadership. Compliance professionals have a unique role as navigators, helping their organizations see beyond the walls of their “worlds,” challenge assumptions, and build a culture where doing the right thing is second nature. By making compliance training meaningful, adaptive, and inclusive, you’ll ensure that your organization not only avoids the fate of Yonada but instead truly “touches the sky.”

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 62 – Unity on the Final Frontier: Cross-Cultural Compliance Insights from ‘Day of the Dove’

Modern compliance officers grapple with complexities arising from international business relationships, mergers, acquisitions, and partnerships, navigating disparate cultural expectations and norms. Star Trek TOS, especially the episode “Day of the Dove,” provides a surprisingly rich source of compliance insights into these challenges. In a globalized business environment, compliance professionals frequently encounter situations analogous to the manipulated hostilities between the Federation and Klingons. Misunderstandings, mistrust, and cross-cultural miscommunication can escalate tensions, threaten corporate integrity, and hinder operations. Let’s distill five critical compliance lessons from “Day of the Dove,” offering practical guidance to the compliance professional for cross-cultural scenarios.

Lesson 1: Recognize and Neutralize Bias and Stereotyping

Illustrated by: Early in the episode, the Enterprise crew and the Klingons instantly regard each other with suspicion and prejudice.

Compliance Lesson: For compliance officers, understanding and addressing implicit biases is crucial. Like the Enterprise crew, professionals often enter new markets or partnerships with preconceived ideas about cultural expectations, risk tolerance, or ethical behaviors. Such biases may cloud objective judgment and inadvertently fuel tension or compliance failures.

Lesson 2: Question Motives and Uncover Root Causes

Illustrated by: When Kirk realizes the ongoing conflict is unnatural, he questions its cause, eventually uncovering the entity exploiting their anger.

In compliance, cross-cultural misunderstandings often have deeper root causes than the surface-level tension suggests. Misaligned incentives, conflicting internal controls, and divergent perceptions of risk can escalate minor disagreements into full-blown compliance crises.

Lesson 3: Collaboration and Common Goals Overcome Conflict

Illustrated by: Ultimately, Kirk and Commander Kang set aside their rivalry, jointly recognizing their mutual enemy as the manipulative entity.

Compliance Lesson: Cross-cultural compliance similarly requires organizations to align clearly defined common objectives, shared values, and mutual benefit. Whether responding to anti-corruption regulations like the FCPA, managing third-party due diligence, or harmonizing diverse internal standards, clear communication and shared goals serve as the foundation for collaboration.

Lesson 4: Communication and Transparency are Critical

Illustrated by: Misunderstandings abound initially due to poor communication between the Klingons and the Federation.

Compliance Lesson: Compliance challenges arising from cross-cultural scenarios frequently result from misunderstandings or assumptions due to poor transparency or communication. Language barriers, culturally distinct reporting methods, and differing standards of directness or openness can lead to confusion and non-compliance.

Lesson 5: Leadership Sets the Tone and Culture

Illustrated by: Both Kirk and Kang exhibit strong leadership by openly demonstrating the willingness to reconsider their positions and lead their crews in jointly rejecting the entity’s divisive influence.

Compliance Lesson: Compliance leadership must similarly set the tone and demonstrate cultural competence. Leaders who visibly prioritize integrity, open dialogue, and mutual respect set a powerful compliance culture example. Cross-cultural scenarios particularly require compliance leaders to demonstrate humility, openness, and willingness to learn and adjust behaviors.

Final ComplianceLog Reflections

The global nature of today’s business operations makes cross-cultural competency not merely a nice-to-have, but an essential compliance skill set. “Day of the Dove,” through its compelling narrative and insightful conflict resolution, mirrors real-world compliance scenarios faced by international organizations.

By integrating these timeless lessons from “Day of the Dove,” compliance professionals are better equipped to navigate complex cross-cultural challenges, transforming potential conflicts into opportunities for collaboration, understanding, and compliance excellence.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Compliance Across Cultures: Lessons from Star Trek’s “Day of the Dove”

In the dynamic and continually evolving landscape of corporate compliance, one recurring theme is the necessity of cross-cultural understanding and collaboration. Modern compliance officers grapple with complexities arising from international business relationships, mergers, acquisitions, and partnerships, navigating disparate cultural expectations and norms. Star Trek TOS, especially the episode “Day of the Dove,” provides a surprisingly rich source of compliance insights into these challenges. As we revisit this classic, let’s examine what Captain Kirk and his crew can teach today’s compliance professional about managing cross-cultural compliance risks effectively.

The episode sees the USS Enterprise encountering a mysterious entity that thrives on conflict and hatred. After coming across Klingon survivors led by Commander Kang, Kirk’s crew and the Klingons are manipulated into perpetual conflict aboard the Enterprise. Both sides soon realize that the entity is using their hatred to feed and grow stronger. Ultimately, they unite to reject the divisiveness that feeds the entity, ending the conflict and regaining control of the Enterprise.

In a globalized business environment, compliance professionals frequently encounter situations analogous to the manipulated hostilities between the Federation and Klingons. Misunderstandings, mistrust, and cross-cultural miscommunication can escalate tensions, threaten corporate integrity, and hinder operations. Let’s distill five critical compliance lessons from “Day of the Dove,” offering practical guidance to the compliance professional for cross-cultural scenarios.

Lesson 1: Recognize and Neutralize Bias and Stereotyping

Illustrated by: Early in the episode, the Enterprise crew and the Klingons instantly regard each other with suspicion and prejudice. Their preconceived notions drive initial hostility, fueled by longstanding animosity and stereotypes.

Compliance Lesson: For compliance officers, understanding and addressing implicit biases is crucial. Like the Enterprise crew, professionals often enter new markets or partnerships with preconceived ideas about cultural expectations, risk tolerance, or ethical behaviors. Such biases may cloud objective judgment and inadvertently fuel tension or compliance failures.

To prevent this, organizations must implement targeted compliance training that explicitly addresses biases and promotes empathy and cultural intelligence. Awareness and sensitivity training programs can help staff challenge assumptions, mitigate prejudices, and foster constructive dialogue, much like Kirk’s eventual acknowledgment of shared misunderstandings.

Lesson 2: Question Motives and Uncover Root Causes

Illustrated by: When Kirk realizes the ongoing conflict is unnatural, he questions its cause, eventually uncovering the entity exploiting their anger. This epiphany sets the stage for collaboration and resolution.

In compliance, cross-cultural misunderstandings often have deeper root causes than the surface-level tension suggests. Misaligned incentives, conflicting internal controls, and divergent perceptions of risk can escalate minor disagreements into full-blown compliance crises.

Conducting effective root-cause analyses, guided by robust investigative frameworks as recommended by regulatory bodies like the DOJ and the 2024 ECCP, can uncover the underlying issues fueling compliance challenges. This diagnostic approach not only mitigates immediate issues but also promotes long-term resilience and cultural cohesion.

Lesson 3: Collaboration and Common Goals Overcome Conflict

Illustrated by: Ultimately, Kirk and Commander Kang set aside their rivalry, jointly recognizing their mutual enemy as the manipulative entity. By focusing on a shared goal, they regain their agency and restore harmony aboard the Enterprise.

Compliance Lesson: Cross-cultural compliance similarly requires organizations to align clearly defined common objectives, shared values, and mutual benefit. Whether responding to anti-corruption regulations like the FCPA, managing third-party due diligence, or harmonizing diverse internal standards, clear communication and shared goals serve as the foundation for collaboration.

Compliance leaders must foster environments where culturally diverse teams understand and internalize collective compliance objectives. Creating alignment workshops, compliance vision statements, and shared metrics are effective strategies to build unity and proactive cooperation among global stakeholders.

Lesson 4: Communication and Transparency are Critical

Illustrated by: Misunderstandings abound initially due to poor communication between the Klingons and the Federation. Once both parties openly discuss their suspicions, their improved communication proves essential in ending the conflict.

Compliance Lesson: Compliance challenges arising from cross-cultural scenarios frequently result from misunderstandings or assumptions due to poor transparency or communication. Language barriers, culturally distinct reporting methods, and differing standards of directness or openness can lead to confusion and non-compliance.

Organizations must proactively address these communication gaps by implementing multilingual training programs, culturally sensitive reporting hotlines, and comprehensive policies written clearly and accessible across cultures. Additionally, transparency must be embedded in compliance systems, ensuring stakeholders across different geographies have clear, consistent, and accessible information.

Lesson 5: Leadership Sets the Tone and Culture

Illustrated by: Both Kirk and Kang exhibit strong leadership by openly demonstrating the willingness to reconsider their positions and lead their crews in jointly rejecting the entity’s divisive influence.

Compliance Lesson: Compliance leadership must similarly set the tone and demonstrate cultural competence. Leaders who visibly prioritize integrity, open dialogue, and mutual respect set a powerful compliance culture example. Cross-cultural scenarios particularly require compliance leaders to demonstrate humility, openness, and willingness to learn and adjust behaviors.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP), reinforced recently by Nicole Argentieri’s commentary, specifically highlights culture as critical to compliance effectiveness. Leaders who exemplify integrity and communicate clear, respectful expectations foster a compliance-positive environment. Such leadership inspires global employees, encouraging them to embrace company values and compliance standards.

Final ComplianceLog Reflections

The global nature of today’s business operations makes cross-cultural competency not merely a nice-to-have, but an essential compliance skill set. “Day of the Dove,” through its compelling narrative and insightful conflict resolution, mirrors real-world compliance scenarios faced by international organizations.

Just as Kirk’s crew and the Klingons successfully rejected divisiveness. They overcame manipulated hostilities. Compliance professionals must recognize and neutralize biases, uncover root causes of tension, prioritize common goals, enhance transparent communication, and demonstrate culturally sensitive leadership.

As we forge ahead in a global compliance landscape, these insights from classic Star Trek remain relevant. The universe Kirk explored may be fictional, but the lessons learned aboard the Enterprise are profoundly real and applicable for every compliance professional operating in the interconnected global business environment.

By integrating these timeless lessons from “Day of the Dove,” compliance professionals are better equipped to navigate complex cross-cultural challenges, transforming potential conflicts into opportunities for collaboration, understanding, and compliance excellence.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 61 – Gunsmoke and Gaps: How ‘Spectre of the Gun’ Informs Modern Compliance Investigations

The compliance world may not often resemble the Wild West, but the best compliance investigators know that the strange and surreal are not always fiction. Misunderstandings, missing evidence, and “unwritten rules” can make the truth as elusive as any Melkotian illusion. “Spectre of the Gun” provides a powerful lens through which to examine the investigative process. Today, we saddle up and explore five essential investigative lessons for compliance professionals from Tombstone in the Arizona Territory, as featured in this classic episode.

Lesson 1: Never Assume Reality Is What It Seems

Illustrated by: From the moment Kirk and his team arrive, things are… off.

Compliance Lesson. In a compliance investigation, assumptions are your enemy. Initial appearances can deceive, especially when dealing with incomplete data, manipulated records, or the subtle influence of organizational culture.

Lesson 2: Stay Calm in the Face of Escalating Pressure

Illustrated by: As the clock ticks toward 5:00, the hour of the gunfight, the crew experiences mounting psychological stress, but Kirk repeatedly counsels his team to stay calm and focused, even as the “inevitable” doom approaches.

Lesson 3: Leverage Diverse Perspectives and Skills

Illustrated by: Each member of the landing party brings a unique skill to the puzzle.

Compliance Lesson. No single investigator has all the answers. The best compliance investigations are team efforts, drawing on legal, HR, IT, and business expertise. This diversity helps spot blind spots and ensures that all avenues are explored.

Lesson 4: Test Hypotheses—Don’t Just Accept Stories

Illustrated by: Spock theorizes that their minds are the only reality that matters. The crew realizes they must test each new hypothesis about their environment, ultimately concluding that belief itself will determine the outcome of the gunfight.

Compliance Lesson. Compliance investigators must go beyond the “story” provided by policy manuals or initial interviews. Every theory, whether about a missing document, a suspicious transaction, or a timeline inconsistency, should be tested.

Lesson 5: Mindset Shapes Outcomes—Don’t Underestimate the Power of Belief

Illustrated by: As the showdown approaches, Spock deduces that their survival depends on their conviction that the Earps’ bullets cannot harm them. He leads the crew in a Vulcan mind meld, focusing their thoughts on total certainty in their safety.

Compliance Lesson. While compliance investigators don’t need Vulcan mind melds, the principle is clear: the mindset you bring to your investigation—open-mindedness, integrity, and thoroughness—shapes the outcome. Cynicism, bias, or defeatism can close your eyes to the real issues.

Final ComplianceLog Reflections

“Spectre of the Gun” is more than a surreal Star Trek adventure; rather, it is a case study in the art and science of investigation. As compliance professionals, we may not face ghostly gunfights at sundown, but we do face situations where logic, courage, and creative teamwork are our only tools against the unknown.

So, as you saddle up for your next compliance investigation, remember the lessons of the Enterprise crew in Tombstone. The truth is out there sometimes, behind the facade, and sometimes hiding in plain sight.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

 

Categories
Blog

Facing the Unknown: Five Investigative Lessons from Star Trek’s “Spectre of the Gun”

One of the most fascinating aspects of compliance investigations is navigating the unknown—those ambiguous, often illogical circumstances where instinct and method must work together. Few television episodes dramatize this challenge as vividly as the Star Trek: The Original Series (TOS) episode, “Spectre of the Gun.”

In this third-season episode, Captain Kirk and his landing party beam down to a planet of the reclusive and telepathic Melkotians, only to be punished for trespassing. Their punishment? Being cast into a surreal, incomplete recreation of the 1881 Gunfight at the O.K. Corral, destined to play the losing side against the Earps and Doc Holliday. As the Enterprise crew quickly learns, logic, memory, and even physical law are unreliable. Their investigation into their predicament and their survival depends on teamwork, analysis, and the willingness to question what’s real.

The compliance world may not often resemble the Wild West, but the best compliance investigators know that the strange and surreal are not always fiction. Misunderstandings, missing evidence, and “unwritten rules” can make the truth as elusive as any Melkotian illusion. “Spectre of the Gun” provides a powerful lens through which to examine the investigative process.

Today, we saddle up and explore five essential investigative lessons for compliance professionals from Tombstone in the Arizona Territory, as featured in this classic episode.

Lesson 1: Never Assume Reality Is What It Seems

Illustrated by: From the moment Kirk and his team arrive, things are… off. The town is half-finished, with buildings lacking walls and only a few facades standing. There are missing objects and inexplicable absences. Despite this, the crew initially tries to follow the “script” of Tombstone’s history, assuming their actions will play out as expected.

Compliance Lesson. In a compliance investigation, assumptions are your enemy. Initial appearances can deceive, especially when dealing with incomplete data, manipulated records, or the subtle influence of organizational culture. Like the Enterprise crew, investigators often find themselves in environments that “look” right but don’t quite add up.

A skilled investigator asks:

  • What’s missing from this picture?
  • Are there gaps or inconsistencies in the documentation?
  • Do witness accounts align, or are they conspicuously similar as if rehearsed?

Always challenge the first layer of evidence. Probe for context. Cross-check data sources and resist the urge to “solve” the case too quickly.

Takeaway:

If your compliance investigation feels too neat, step back and re-examine. The truth often lies in the gaps, not the obvious.

Lesson 2: Stay Calm in the Face of Escalating Pressure

Illustrated by: As the clock ticks toward 5:00, the hour of the gunfight, the tension mounts. The Earps are aggressive, and the townsfolk are hostile or unhelpful. The crew experiences mounting psychological stress, but Kirk repeatedly counsels his team to stay calm and focused, even as the “inevitable” doom approaches.

Compliance Lesson. Investigations often bring high-pressure moments: interviewees who become confrontational, business leaders who want quick resolutions, or whistleblowers who fear retaliation. In these moments, emotions can cloud judgment and cause missteps.

“Spectre of the Gun” shows that, when panic rises, clear-headed leadership and methodical process are essential. Kirk’s calm enables the team to think creatively and challenge assumptions, ultimately saving their lives.

In compliance investigations:

  • Set clear ground rules for interviews.
  • Create a calm environment, even when accusations are severe.
  • Support your team and witnesses, especially when the stakes are high.

What should you do now? Under pressure, composure and methodical thinking separate successful investigators from those who react.

Lesson 3: Leverage Diverse Perspectives and Skills

Illustrated by: Each member of the landing party brings a unique skill to the puzzle. Spock applies logic to interpret the unreality of their situation. McCoy’s medical knowledge helps craft “anti-venom” to counter the gas used by Doc Holliday. Scotty and Chekov offer technical and tactical ideas, while Kirk analyzes motivations and strategy.

Compliance Lesson. No single investigator has all the answers. The best compliance investigations are team efforts, drawing on legal, HR, IT, and business expertise. This diversity helps spot blind spots and ensures that all avenues are explored.

In the episode, Spock recognizes that their environment is illusory, and the group’s willingness to trust his logic unlocks their escape. In your investigations:

  • Gather a multidisciplinary team.
  • Encourage open debate and the airing of alternate theories.
  • Leverage outside expertise when needed, such as forensic accountants or language specialists.

What should you do now? Diversity is not just about backgrounds; it is about thinking styles and problem-solving approaches. Use every tool at your disposal.

Lesson 4: Test Hypotheses—Don’t Just Accept Stories

Illustrated by: When McCoy attempts to make “real” tranquilizer gas to stop the Earps, it fails, as the gas has no effect, because nothing in their environment is truly real. Spock theorizes that their minds are the only reality that matters. The crew realizes they must test each new hypothesis about their environment, ultimately concluding that belief itself will determine the outcome of the gunfight.

Compliance Lesson. Compliance investigators must go beyond the “story” provided by policy manuals or initial interviews. Every theory, whether about a missing document, a suspicious transaction, or a timeline inconsistency, should be tested.

This may mean:

  • Reconstructing timelines.
  • Running technical or forensic tests.
  • Seeking out independent corroboration for claims.

In the episode, only by testing (and failing) do Kirk and his team realize what’s going on. Similarly, failed hypotheses in your investigation are not a waste; they point you closer to the truth.

What should you do now? Test your investigative theories actively. Do not accept stories at face value; experiment, reconstruct, and challenge.

Lesson 5: Mindset Shapes Outcomes—Don’t Underestimate the Power of Belief

Illustrated by: As the showdown approaches, Spock deduces that their survival depends on their conviction that the Earps’ bullets cannot harm them. He leads the crew in a Vulcan mind meld, focusing their thoughts on total certainty in their safety. When the bullets fly, they are unharmed—because they believe they cannot be hurt.

Compliance Lesson. While compliance investigators don’t need Vulcan mind melds, the principle is clear: the mindset you bring to your investigation—open-mindedness, integrity, and thoroughness—shapes the outcome. Cynicism, bias, or defeatism can close your eyes to the real issues.

Additionally, the mindset of the organization matters. If employees believe investigations are futile or predetermined, they won’t participate honestly. If they believe in the integrity of the process, you’ll get better results.

Set the tone by:

  • Demonstrating impartiality.
  • Communicating the importance of the investigative process.
  • Encouraging a “speak-up” culture where all feel heard.

What should you do now? The beliefs and values you bring to an investigation shape its success. Foster a culture of open-mindedness, curiosity, and fairness.

Final ComplianceLog Reflections

“Spectre of the Gun” is more than a surreal Star Trek adventure; rather, it is a case study in the art and science of investigation. As compliance professionals, we may not face ghostly gunfights at sundown, but we do face situations where logic, courage, and creative teamwork are our only tools against the unknown.

So, as you saddle up for your next compliance investigation, remember the lessons of the Enterprise crew in Tombstone. The truth is out there, sometimes behind the facade, hiding in plain sight.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?
Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 60 – Unmasking Compliance Blind Spots: Lessons from ‘Is There in Truth No Beauty?’

No TOS episode is more apt for compliance professionals seeking to elevate their training and communications program than the third season gem, “Is There in Truth No Beauty?”

As compliance professionals, we can mine “Is There in Truth No Beauty?” for powerful lessons on building a culture of effective training and communications that prepares our teams for the uncharted territory of tomorrow’s risks. Today, we set our phasers to “inspire” and explore five key compliance training and communications lessons from this classic Trek tale.

Lesson 1: Embrace the Limits of Human Perception

Illustrated by: The crew’s first briefing about the Medusan ambassador is laden with warnings: “No one may look upon a Medusan with the naked eye.”

Compliance Lesson. Every organization has its own “Medusans” risks, regulations, and even people whose perspectives are so different they can seem incomprehensible. Too often, compliance training assumes everyone shares the same baseline understanding and comfort level. That is a dangerous assumption.

Lesson 2: Communicate Expectations—Don’t Assume Understanding

Illustrated by: Early in the episode, Captain Kirk assembles his crew for a detailed briefing. Spock and Dr. Jones reinforce the message, and the procedures for safe interaction are laid out.

Compliance Lesson. How many compliance failures begin with, “Well, I thought I understood what was required…”? In Star Trek, lives depend on explicit, repeated communication of expectations. In your organization, regulatory and reputational survival depends on it as well.

Lesson 3: Build Trust and Psychological Safety Before the Crisis

Illustrated by: The relationship between Dr. Jones and the crew is initially fraught. She is a telepath, guarded and secretive. Her sense of isolation is palpable. Yet as the episode progresses, Kirk and Spock earn her trust by inviting her into their confidence and acknowledging her unique expertise. This trust proves critical when disaster strikes.

Compliance Lesson. Effective communication is built on trust and psychological safety. If employees feel isolated, mistrusted, or afraid to speak up, no amount of “mandatory training” will make your compliance program effective.

Lesson 4: Prepare for the Unexpected—And Practice the Protocols

Illustrated by: When Kollos’s container is accidentally opened, crew member Larry Marvick is exposed to the Medusan and descends into madness, nearly destroying the Enterprise.

Compliance Lesson. Crises never unfold according to plan, but they reveal the effectiveness of your training and protocols. Star Trek demonstrates that it’s not enough to have a policy in the binder; you must train, rehearse, and test those protocols until they are second nature.

Lesson 5: Embrace Diversity—and the Value of the Outsider’s View

Illustrated by: The Medusan, Kollos, is physically incomprehensible to humans, yet he is also a being of great intelligence and empathy.

Compliance Lesson:

Homogeneity is a hidden compliance risk. Diverse teams bring broader perspectives, challenge assumptions, and spot blind spots that a monoculture would miss. In Star Trek, survival depends on learning from the outsider; in compliance, innovation, and vigilance depend on the same principle.

Final ComplianceLog Reflections

“Is There in Truth No Beauty?” is a meditation on the limits of perception, the power of communication, and the necessity of embracing difference. For compliance professionals, it offers a road map for building training and communications programs that are clear, inclusive, practical, and resilient.

The universe of compliance is ever-expanding. Let’s train and communicate so our teams are ready to boldly go where no one has gone before.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI generated voice

Categories
Blog

Connected Compliance: Part 4 – From Hotline to Trust

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust them enough to speak. In Blog Post 1, we considered communication as a compliance control. Blog Post 2 showed how operational signals create a dynamic risk radar. In Blog Post 3, we explained why every investigation is a test of governance and culture. This final installment examines the front door to the entire system: the reporting program.

A company can buy a hotline in an afternoon. It cannot buy employee trust. That distinction is the starting point for an effective whistleblower program. The platform, policy, telephone number, and case-management system are necessary infrastructure. They are not the program. The real program is the experience an employee anticipates before reporting and receives after doing so.

The answers do not come primarily from policy language. They come from what employees see happen to colleagues who raise concerns. A mishandled report can teach an entire workplace that silence is safer.

The First Report Is the Real Program Test

One of the easiest ways to discourage reporting is to do a poor job after a report arrives. An ignored allegation, confidentiality breach, unexplained delay, dismissive intake, or retaliation can do more damage than an outdated hotline poster.

This is why the reporting program and investigation process cannot be separated. Intake creates an expectation of action. Investigation determines whether that expectation is met. Follow-up determines what the reporter tells others about the experience. The process should begin with prompt acknowledgment. Whenever possible, a trained person should thank the reporter, gather clarifying information, explain next steps, and set realistic expectations. An automated receipt confirms that the technology worked. Personal contact demonstrates that the organization is listening.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places confidential reporting within its evaluation of whether a compliance program is well designed. The 2024 Evaluation of Corporate Compliance Programs (ECCP) calls for an “efficient and trusted mechanism” for anonymous or confidential reports. The two words that matter most are efficient and trusted.

Efficiency requires accessible channels, proper routing, risk-based triage, qualified investigators, timely handling, documentation, and accountable remediation. Trust requires employees to believe that the company will take concerns seriously, limit information sharing, prevent retaliation, and respond consistently regardless of rank or commercial importance.

The DOJ asks whether employees know about the reporting mechanism, feel comfortable using it, and are willing to report misconduct. It also asks a difficult question: “Conversely, does the company use practices that tend to chill such reporting?” That directs compliance professionals beyond the hotline itself. Confidentiality agreements, manager behavior, performance systems, investigation delays, incentive structures, employment actions, and prior reporter experiences can all affect willingness to speak. The DOJ further asks whether the company tests hotline effectiveness by tracking a report from intake through disposition. This makes end-to-end testing a governance exercise, not a vendor-management task.

Design Channels Around the Workforce

A reporting system designed for headquarters may fail the people most likely to observe operational risk. Field employees, shift workers, remote personnel, contractors, and employees with limited computer access need channels that fit how they work. The answer is a meaningful choice. A mature program may include a telephone hotline, web portal, mobile access, email, QR codes, and in-person reporting to compliance, human resources, legal, internal audit, security, or management. Channels should be available in appropriate languages and accessible to employees with disabilities.

Placement matters. A QR code on an identification badge, break-room poster, or work-issued device may be more useful than a buried intranet link. A telephone line remains essential for employees who prefer to speak or lack reliable digital access. Many employees will first approach someone they trust. Compliance should analyze channel use by location, function, shift, language, and workforce type. A channel with no reports is not necessarily evidence that the location has no concerns. It may be evidence that the channel is unknown, inaccessible, or distrusted.

Make Speaking Up a Leadership Behavior

Tone at the top remains essential, but the employee’s immediate supervisor often controls the reporting climate. A chief executive may celebrate integrity while a frontline manager rolls their eyes, interrupts the employee, demands names, or warns that a report will hurt the team. The manager’s reaction becomes the company’s culture in that moment.

Managers need specific training. They should listen without investigating on the spot, avoid promises they cannot keep, preserve information, escalate promptly, and reinforce anti-retaliation expectations. A concern does not have to arrive through the hotline to require action. Leadership modeling should be visible. When leaders invite dissent, respond calmly to bad news, thank employees who identify risk, and communicate anonymized lessons, they show that speaking up protects the business. Regular field presence builds relationships, reveals access barriers, and provides context unavailable from a dashboard.

Tell the Truth About Confidentiality

Employees often use anonymity and confidentiality interchangeably, but they are different. An anonymous reporter does not disclose identity. Confidentiality means identity and related information are limited to people with a legitimate need to know. The company should never promise absolute secrecy when the facts make it impossible. In a small team, subject matter, timing, or witnesses may reveal who raised the concern. Overpromising creates a second breach of trust.

The better approach is candor. Explain that information will be restricted as far as reasonably possible, that some disclosure may be necessary to investigate fairly or meet legal obligations, and that retaliation is prohibited. Use role-based access, careful case notes, secure records, disciplined interview planning, and clear need-to-know rules. Confidentiality is not a slogan. It is an information-control process.

Communicate Without Compromising the Investigation

Silence during a long investigation can feel like indifference. Reporters do not need access to witness statements or confidential personnel decisions, but they do need evidence that the matter remains active. Set a communication cadence based on case risk and expected duration. Provide updates even when the update is that the review continues. Explain delays where appropriate, remind the reporter how to provide additional information, and repeat the anti-retaliation contact route.

At closure, confirm that the concern was reviewed and addressed as appropriate. Thank the reporter and reinforce anti-retaliation protection. The company may be unable to disclose findings or discipline, but it can close the human loop.

Treat Anti-Retaliation as an Active Control

An anti-retaliation policy is necessary, but it is not self-executing. Retaliation can be direct, such as termination, demotion, or loss of pay. It can also be subtle: exclusion from meetings, undesirable shifts, lost development opportunities, hostile supervision, damaged reputation, or social isolation. The company should assess retaliation risk throughout the matter. Compliance and human resources should preserve a baseline of the reporter’s role and treatment, monitor employment actions, schedule check-ins, and provide an escalation route outside the normal chain. Monitoring should continue after closure.

Protection does not mean immunity from legitimate performance management. It means employment decisions affecting a reporter receive appropriate review, are supported by contemporaneous evidence, and are not influenced by protected activity. When retaliation occurs, discipline should be prompt and visible enough, within confidentiality limits, to reinforce the rule.

Do Not Discredit the Difficult Messenger

Serial reporters and incomplete reports create operational challenges, but frequency, frustration, or poor drafting does not determine whether an allegation is true. Each concern should be assessed on its merits. A sparse report may still contain breadcrumbs. Investigators can review organizational charts, personnel changes, transactions, prior complaints, and control data before concluding that the matter cannot proceed. Multiple reports may reveal an unresolved environmental problem or weak earlier investigations.

Motivation can be relevant to credibility, but it should not replace evidence. Labeling someone a troublemaker is often an easy way to miss a difficult fact and an effective way to chill the next reporter.

Measure Trust, Not Just Volume

Hotline volume alone is a weak measure. A low number may reflect a healthy culture, a small risk population, inaccessible channels, fear, or lack of awareness. A rising number may reflect deteriorating conduct or growing confidence in the program. A useful dashboard combines volume with context: awareness and comfort survey results, reports by workforce segment, intake-to-acknowledgment time, triage time, case aging by risk, substantiation patterns, repeat allegations, reporter-update timeliness, retaliation concerns, remediation completion, and employee feedback after closure.

Compliance should test the entire system. Submit a controlled report, trace routing and access, review acknowledgments, confirm escalation rules, examine investigation handoffs, and verify closure and retention. Analyze whether reporting data changes risk assessment, controls, training, and resources. The objective is evidence that the program learns.

Closing the Connected Compliance Program

This four-part blog post series began with communication because employees cannot use a system they do not understand. It moved to dynamic risk assessment because organizations must recognize changing signals. It then examined investigations because allegations require independent facts, accountability, and remediation. Today we discussed whistleblower programs because none of those capabilities matter if people do not trust the company enough to speak. Join us tomorrow in our concluding Part 5 for a deeper discussion of how compliance truly is connected.

The connected compliance program is a loop. Communication builds awareness. Reporting supplies risk intelligence. Investigation converts allegations into reliable findings. Remediation improves controls. Feedback strengthens culture and makes future reporting more likely.

For the compliance professional, the final test is not whether the hotline exists. It is whether an employee facing a difficult choice believes that raising a concern will protect the organization, lead to a credible response, and not cost that employee a career. That is how a reporting channel becomes a trusted control and how culture becomes credibility.

Bonus Questions for Compliance Professionals

  1. Can every workforce segment access a reporting channel during the way and hours in which it actually works?
  2. Do employees know the available channels, understand external reporting rights, and say they feel comfortable using them?
  3. What happens during the first 24 hours after a report arrives, and who is accountable for acknowledgment, triage, and protection?
  4. Are managers trained to recognize and escalate concerns received outside formal reporting channels?
  5. Can the company show how reporter identity and case information are restricted to people with a legitimate need to know?
  6. How does the organization monitor direct and subtle retaliation during and after an investigation?
  7. Does the company communicate appropriately with reporters when an investigation is delayed and when it closes?
  8. Are serial, anonymous, and incomplete reports assessed on evidence and context rather than labels or assumptions?
  9. What reporting data has changed the risk assessment, controls, training, discipline, or resource allocation during the past year?
  10. Has the company recently tested one report from submission through routing, investigation, remediation, feedback, and retention?
Categories
Great Women in Compliance

Great Women in Compliance: GWIC x Everything Compliance – Summer 2026

We are back with another GWIC x Everything Compliance crossover, with Hemma and Lisa joining Kristy Grant-Hart and Karen Moore to talk about what’s on their minds and the compliance news of the day. They discuss everything from Scoular Company entering into a Deferred Prosecution Agreement and paying over $10m for FCPA violations, lessons for Ethics & Compliance professionals from the World Cup, the resolution of the allegations against Alibaba and AUS Merchant Services, and what we can take from the leaked draft of the EU’s New Public Procurement Regulations.

And, of course, it wouldn’t be Everything Compliance without the rants and raves.