Categories
Blog

Connected Compliance: Part 3 – Why Every Investigation Is a Culture Opportunity for Your Organization

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. In Blog 1, we examined communication as a compliance control. In Blog Post 2, we showed how those communications and other operational signals create a dynamic risk radar. Today in Blog Post 3, we ask what happens when a signal becomes an allegation as an introduction to how and why every investigation can be an opportunity to both pressure-test and build out your culture.

A hotline report, audit exception, control override, manager escalation, or unusual transaction may begin as just another compliance signal; once the company decides it requires investigation, the stakes change. The organization must establish what happened, protect people and evidence, make defensible decisions, and strengthen the program.

That makes an investigation more than a fact-finding exercise. It is a visible test of governance. Employees watch who is interviewed, how leaders behave, whether the process appears fair, whether high performers receive special treatment, and whether the company acts when misconduct is substantiated. Details should remain confidential, but the organization cannot erase the cultural impact. Every investigation sends a message.

Credibility Is Built Before the First Interview

The strongest investigations begin with disciplined triage. Before scheduling interviews or collecting data, the company should first identify the immediate risks that require action. Is anyone’s health or safety at risk? Could misconduct be continuing? Is evidence vulnerable? Does the allegation implicate financial reporting, government contracting, sanctions, corruption, product integrity, cybersecurity, privacy, or another obligation requiring prompt escalation?

Containment is not a conclusion. Suspending access, preserving records, pausing a payment, separating employees, or protecting a reporter may be necessary while the facts remain unresolved. The decision should be proportionate, documented, and revisited as evidence develops.

Triage should identify the functions that need to participate without turning the matter into a committee project. One person should own the process, one decision-maker should approve material scope changes, and communication lines should be defined at the outset.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places investigations squarely inside its test of program effectiveness. The 2024 Evaluation of Corporate Compliance Programs (ECCP) asks, “How does the company ensure that investigations are properly scoped?” It then asks what steps the company takes to ensure investigations are “independent, objective, appropriately conducted, and properly documented,” as well as how the company determines who should conduct an investigation.

Those words provide a practical quality standard. Proper scope means the investigation addresses the allegation and reasonably connected issues without drifting into an unlimited inquiry. Independence means the investigator is free from conflicts and improper business pressure. Objectivity requires a search for facts that may confirm or disprove the allegation. Appropriate conduct includes lawful evidence collection, fair treatment of witnesses, and proportionate methods. Proper documentation allows the company to explain what it did, why it did it, and how it reached its conclusions.

DOJ also asks whether the company applies timing metrics, monitors outcomes, and ensures accountability for findings and recommendations. Later, the ECCP describes a working program as having an “appropriately funded mechanism for the timely and thorough investigations” of allegations or suspicions of misconduct. The point is not speed at any cost. It is disciplined responsiveness supported by adequate resources.

Scope the Question, Not the Desired Answer

A written investigation plan should define the allegation, relevant policy or legal issues, time period, business units, people, data sources, immediate risks, and proposed work. It should identify the standard used to reach findings and the expected form of the report. It should also record what remains outside scope.

The plan must be flexible. Evidence may reveal additional conduct, another geography, a control failure, or management involvement. The investigator should document the new information, assess its materiality, identify any additional resources or conflicts, and obtain appropriate approval for expansion.

This discipline prevents a scope narrowed to contain the issue and investigation drift that delays a conclusion. A credible process follows the evidence while preserving a clear line of sight to the original allegation.

Choose the Investigator for the Risk

Not every matter requires outside counsel, and not every matter should remain inside the company. The choice should turn on credibility and capability, not habit. Internal investigators may understand the business and manage routine matters efficiently. External counsel or specialists may be appropriate when allegations involve senior leadership, significant legal exposure, government reporting, material financial impact, technical evidence, cross-border restrictions, litigation, or concerns about internal independence.

The company should establish decision criteria before a crisis. Who determines whether compliance, legal, human resources, internal audit, security, or outside counsel will lead? What conflicts require recusal? When does the audit committee or another independent authority oversee the matter? Which technical experts may be needed, and how will their work be directed? An outside law firm’s letterhead does not create independence. It comes from clear authority, freedom from interference, sufficient resources, access to evidence, and an escalation route when investigators encounter resistance.

Protect the Privilege with Precision

The attorney-client privilege can protect confidential communications seeking or providing legal advice, but an investigation is not privileged simply because a lawyer attends. Privilege rules are jurisdiction-specific, and careless circulation, unclear roles, or unnecessary third-party involvement can create risk.

At the beginning, counsel should define the legal purpose, identify the client and team, establish communication and documentation protocols, and explain confidentiality expectations. Team members should know which communications seek legal advice, where documents will be stored, and who may receive them. Over-labeling every document as privileged does not create stronger protection. It can undermine discipline and complicate later disclosure decisions. The better approach is to use privilege deliberately, involve counsel where legal advice is genuinely required, and preserve a reliable factual record that supports the company’s decisions.

Treat Witnesses as People, Not Evidence Containers

Witness interviews often determine whether employees experience the investigation as fair. The investigator should explain the purpose of the interview, the investigator’s role, expectations for truthful cooperation, applicable confidentiality limits, and the company’s prohibition against retaliation. The interviewer should not promise complete secrecy, prejudge the allegation, coach testimony, or imply that raising concerns created the problem.

Respect improves evidence quality. Employees are more likely to provide complete information when questions are neutral, and the interviewer listens before challenging inconsistencies. Cultural, language, disability, and power dynamics may affect participation and should be addressed thoughtfully.

Anti-retaliation protection requires more than an opening statement. Compliance and human resources should identify foreseeable risks of retaliation, monitor employment actions and workplace behavior, provide a safe escalation channel, and respond quickly to concerns. Retaliation may be subtle: exclusion, schedule changes, lost opportunities, hostile supervision, or reputational harm. A technically sound investigation can still damage culture if the reporter or witnesses pay a price for participating.

Preserve Evidence and Measure the Right Clock

Evidence management must begin early. Relevant emails, collaboration messages, mobile communications, transaction records, system logs, personnel documents, and physical evidence all require preservation. Collection should follow applicable law, privacy requirements, company policy, and forensic protocols. The team should document sources, custodians, dates, gaps, and chain of custody where necessary. Always remember the first question the DOJ will ask after you self-disclose is, “Do you have the documents tied down?

Timeliness should be measured, but the metric must support quality. Useful measures include time from intake to triage, time to investigator assignment, aging by risk category, days awaiting business action, time from finding to remediation, and overdue reporter updates. A single average completion target can create pressure to close simple matters quickly or rush complex ones. Status reviews should ask what is delaying the matter, whether scope remains appropriate, whether interim protections still work, and whether new risks require escalation. The objective is a process that explains delay, removes bottlenecks, and prioritizes higher-consequence matters.

Move Beyond the Bad Actor

An investigation that identifies who violated a policy but not why the system allowed it has completed only half the work. DOJ asks whether investigations identify “root causes, system vulnerabilities, and accountability lapses,” including those involving supervisors and senior executives.

Root-cause analysis should examine incentives, performance pressure, control design, access rights, training, supervision, third-party oversight, data availability, prior warnings, and the consistency of discipline. Did the policy prohibit the conduct but the workflow reward it? Did a manager ignore a red flag? Did an exception process become the normal process? Did earlier reports reveal the same weakness?

The answer should drive remediation, including discipline, control redesign, policy revision, monitoring, training, leadership changes, third-party action, disclosure, or resource reallocation. Each action needs an owner, deadline, evidence, and testing. Otherwise, the investigation becomes a historical record rather than a compliance control.

Close the Case and the Cultural Loop

A reasoned closure record should state the allegation, scope, steps taken, evidence considered, credibility analysis, findings, and approved response. Discipline should be consistent across ranks and levels of commercial importance, with deviations documented. Investigation data should then feed the risk assessment, training plan, control testing, and management reporting.

The reporting party also matters. Without disclosing confidential personnel information, the company can acknowledge that the review is complete, thank the person for speaking up, restate anti-retaliation protections, and provide a contact for further concerns. Silence after intake encourages employees to conclude that nothing happened.

This is the connection across the series. Communication brings information into the program. Dynamic risk assessment helps the company recognize its significance. Investigation converts allegations into facts, accountability, and learning. Therefore, join us for Part 4 tomorrow, as we will demonstrate the front door to that process: how an effective whistleblower program gives employees safe, accessible ways to report and confidence that speaking up will lead to credible follow-through.

Bonus Questions for Compliance Professionals

  1. Who has authority to triage an allegation and order immediate containment or preservation measures?
  2. What written criteria determine who should lead an investigation and when independent oversight or outside counsel is required?
  3. Can the company show that recent investigations were properly scoped, independent, objective, timely, and documented?
  4. Which stages of the investigation create the greatest delays, and are those delays risk-based or simply unmanaged?
  5. How does the organization monitor subtle retaliation against reporters and witnesses?
  6. Do investigation reports identify control failures, incentives, supervisory accountability, and root causes in addition to individual misconduct?
  7. What evidence shows that completed investigations changed controls, training, discipline, resources, or risk assessment?
  8. How does the company communicate appropriate closure to reporters without compromising confidentiality?
Categories
Blog

The Odyssey and Compliance, Part 2 – The Lotus-Eaters: Culture Drift and the Comfort of Forgetting

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of the Lotus-Eaters and the drifting of corporate culture.

Odysseus and his crew did not always face monsters with teeth. Sometimes the danger was softer. After leaving Troy, Odysseus and his men came to the land of the Lotus-Eaters. There was no battle. No ambush. No roaring beast. No angry god hurling thunderbolts. The locals simply offered the crew lotus flowers. Those who ate them lost all desire to return home. They forgot the mission. They forgot Ithaca. They forgot the purpose of the journey.

That is what makes the episode so unsettling. The Lotus-Eaters did not defeat Odysseus’s crew by force. They defeated them through comfort, distraction, and forgetfulness. Welcome to one of the most common compliance risks in modern corporate life: culture drift.

Not every compliance failure begins with greed. Not every ethical collapse starts with a suitcase of cash, a fake invoice, or someone whispering, “Let’s take this offline.” Some failures begin when people simply forget why the rules matter. They remember the annual training deadline. They remember the attestation. They remember where the Code of Conduct lives, assuming the intranet search function is having a good day. But they no longer connect compliance to the company’s mission. That is the lotus.

The Corporate Translation

Every organization has its own version of the island of the Lotus-Eaters. It may be a high-performing business unit that hits its numbers, avoids obvious scandal, and quietly stops engaging with compliance. It may be a remote office that has not seen a live compliance conversation in years. It may be a leadership team that talks about values during onboarding, but never mentions them again unless there is an investigation. It may be a group of employees who click through training modules while answering emails, eating lunch, and wondering whether the quiz has unlimited attempts.

Everyone is pleasant. Everyone is busy. Everyone is productive. Everyone is slowly detaching from the company’s stated values. This is the direct analogy: the lotus is the business unit where nothing looks obviously wrong, but no one can explain how compliance connects to the work they actually do. That is a dangerous place. Not because people are evil. Because they are comfortable.

Risk Assessment: Finding the Islands Before People Forget

A good compliance program begins with risk assessment, not vibes. Odysseus had to know where his crew was vulnerable. Were they hungry? Exhausted? Demoralized? Homesick? Easily distracted by local hospitality? The answer, unfortunately, was yes.

Companies need the same kind of self-awareness. Where are employees most likely to forget the mission? Where are they under the most pressure? Where are the policies most disconnected from daily operations? Where has training become a ritual instead of a reinforcement?

The DOJ’s Evaluation of Corporate Compliance Programs emphasizes risk-tailored compliance and asks how a company identifies, assesses, and addresses risks, including whether it updates policies, procedures, and training as those risks evolve. It also asks whether training is tailored, whether employees understand it in practice, and whether the company measures effectiveness rather than merely delivering content.

That is an important distinction. A weak risk assessment asks, “Did everyone receive the training? “A better risk assessment asks, “Who needs what training, on which risks, at what level of depth, in what language, through what format, and how do we know it changed behavior? “That is the difference between counting lotus flowers and understanding why people are eating them.

Policies: The Mission Written Down

Policies are supposed to tell employees how the company expects them to act. But too many policies are written as if they were designed to survive litigation rather than to guide human beings. They are long, dense, passive, and beloved mainly by the people who drafted them. Employees do not use them. Managers do not reinforce them. Business teams treat them like airport terms and conditions: technically available, rarely read, and accepted under pressure.

That is a policy failure by design. A policy is not effective because it exists. It is effective when employees can find it, understand it, apply it, and believe the company expects them to follow it. The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether policies and procedures are accessible, searchable, communicated to employees and relevant third parties, integrated into operations, and reinforced through internal control systems. It also asks whether gatekeepers receive guidance and training on what misconduct to look for and when to escalate concerns.

That is practical compliance. Policies should not be museum pieces. They should be field guides. The anti-corruption policy should help a sales manager understand what to do before a government customer asks for “support.” The data privacy policy should help an operations team understand when customer information can be shared. The conflicts policy should help a procurement employee understand why her cousin’s consulting firm is not just “a good local option.” The speak-up policy should help employees know where to go before silence becomes complicity. Policies should bring people back to Ithaca. They should remind the organization: this is who we are; this is how we do business; and this is the route home.

Training: More Than the Annual Click-Through

Now we come to training, the place where many compliance programs go to become lotus farms. You know the scene. An employee gets an email: “Mandatory Compliance Training Due Friday.” The employee opens the module, clicks through the slides, answers a few questions, and receives a certificate. Somewhere, a dashboard turns green. The compliance team exhales. The business moves on.

But did anyone learn anything? That is the uncomfortable question. As Ronnie Feldman continually reminds us, training is not effective because it was assigned. Training is not effective because completion rates are high. Training is not effective because the quiz average was 94 percent, especially if the questions were written so that “Do not commit fraud” was the challenging option.

Effective training helps employees recognize risk in the moment. It gives managers language to lead. It teaches employees how to pause, ask, escalate, and document. It uses realistic scenarios, not cartoon villains. It respects the audience’s time without insulting their intelligence. The ECCP specifically points to tailored training and communications, including practical advice, case studies, shorter, targeted sessions, opportunities for employees to ask questions, and measures of employee engagement and learning. It also asks whether training affects employee behavior or operations. The goal is not training completion. The goal is better decisions.

Ethical Fatigue Is Real

There is another reason the Lotus-Eaters matter. They remind us that people get tired. Employees face pressure, complexity, change, layoffs, new systems, reorganizations, market stress, and competing messages from leadership. Then compliance arrives with another policy update, another module, another certification, another “quick reminder” that is neither quick nor memorable.

Ethical fatigue sets in. When employees are exhausted, they do not necessarily become unethical. They become passive. They stop asking questions. They stop reading carefully. They assume someone else reviewed the issue. They treat compliance as background noise. This is where culture drift becomes dangerous. The organization may still have the right words, but the words no longer move anyone.

The solution is not more noise. It is better communication. Compliance teams should ask, “What does this audience need to know?” What decisions do they actually face? What mistakes are we seeing? What near misses have occurred? What questions are employees asking? What risks are emerging? What would make this guidance useful on Tuesday afternoon when the customer is angry, the deadline is real, and the manager wants an answer? That is where compliance becomes practical.

What a Better Program Does

A better program treats culture as something to be measured, tested, and renewed. It does not assume that because employees took training, they absorbed it. It does not assume that because a policy exists, employees know how to use it. It does not assume that because leadership talks about integrity, middle management reinforces it. A better program looks for signs of forgetting.

Are hotline reports dropping because misconduct is down, or because trust is down? Are policy questions coming from all regions or only headquarters? Are employees passing training but failing audits? Are managers escalating issues or solving them quietly? Are high-risk teams receiving generic training when they need tailored guidance? Are employees afraid to ask “basic” questions because they think they should already know the answer? The compliance function should use surveys, training analytics, audit results, hotline data, investigation trends, control testing, manager feedback, and employee questions to understand whether the message is landing. And when the message isn’t landing, the answer isn’t to blame the crew. Odysseus did not leave his men among the Lotus-Eaters and say, “Well, they should have remembered Ithaca.” He dragged them back to the ships. That is leadership.

The Compliance Takeaway

The land of the Lotus-Eaters is not a place of obvious corruption. That is why it is so dangerous. It is the place where mission fades into routine, where values become posters, where policies become files. Where training becomes a click, where employees are not hostile to compliance but simply detached from it.

For compliance officers and business leaders, the lesson is clear: culture must be refreshed before it drifts. Policies must be usable before they are needed. Training must be memorable before the crisis. Risk assessment must identify not only where misconduct could occur but also where people are most likely to forget why compliance matters.

Odysseus’s crew did not need a lecture. They needed to be reminded of the journey. So do organizations. The question is not whether your people have eaten the lotus. The question is whether your compliance program would know.

Join us tomorrow in Part 3, where we consider Circe’s Island: Third-Party Influence and Culture Capture.

Categories
Blog

What Interruptions Reveal About Corporate Culture

Every Chief Compliance Officer talks about culture. Every company claims to value ethics, integrity, respect, inclusion, and speak-up behavior. Those words appear in codes of conduct, CEO messages, training decks, town halls, leadership offsites, and annual ethics campaigns. Yet culture is not built into the code of conduct. It is revealed in the meeting.

That is the central lesson of Research: What Interruptions Reveal About Company Culture by William Degbey, Benjamin Laker, Baniyelme Zoogah, Sanjay Kumar Singh, and Ghulam Murtaza. The authors argue that workplace culture is shaped less by formal statements and engagement programs than by everyday interaction patterns, especially interruptions in meetings. Their research found that interruptions, redirections, and moments where employees were spoken over were not merely interpersonal annoyances. They were signals of whose voice carried weight in the room.

For the CCO, that finding should land with force. A company can have a beautifully written value of “speak up.” Still, if employees learn in ordinary meetings that certain people are cut off, ignored, or not credited for their ideas, the real culture is not to speak up. It is speak-only-if-you-have-power. That is a compliance issue.

Culture Is What Happens Before the Hotline

Compliance professionals often think about speak-up culture in terms of hotline reports, investigation data, employee surveys, and anti-retaliation policies. Those are important. The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company has a trusted reporting mechanism, whether employees feel comfortable using it, whether reporting is encouraged or chilled, and whether employees can raise concerns without fear of retaliation.

But by the time an employee reaches the hotline, the culture has already taught that person a great deal. It has taught them that if management listens. It has taught them whether disagreement is welcome. It has taught them whether bad news is punished. It has taught them whether junior employees can challenge senior leaders. It has taught them whether women, employees from underrepresented groups, remote employees, finance staff, compliance staff, or local market employees are taken seriously.

The author’s most important compliance lesson is that interruptions are cultural data. They are small, repeated, observable signals that show whether the company’s stated values are protected in daily business interactions or suspended when authority, speed, revenue, or hierarchy enters the room.

Why This Matters to Ethics and Integrity

Ethics and integrity depend on voice. Employees must be willing to raise concerns, ask questions, challenge assumptions, and slow down decisions when something does not look right. If the organization’s meeting culture teaches employees that unfinished concerns can be interrupted, redirected, or appropriated, then the company is training people not to speak.

The authors found that many senior leaders interpreted interruptions as signs of efficiency and engagement. They saw energetic cross-talk as evidence of a productive culture. Yet the follow-up study found that others experienced the same conduct as exclusionary and predictable. Interruptions were disproportionately directed at women and employees from underrepresented racial and ethnic groups. In the follow-up study, 19 of 27 interviewees described women being interrupted more frequently than men; all seven Black women interviewed described early-stage interruptions, and five said others later resurfaced their ideas without attribution.

For compliance, that is not simply an inclusion issue, though it certainly is. It is also a risk-detection issue. If certain voices are routinely cut off, then certain risks will be underreported. If certain employees must speak faster, more defensively, or only when explicitly invited, the company loses early warning signals. If some ideas are accepted only when repeated by someone with greater status, then the company is not evaluating risk on its merits. It is evaluating risk through hierarchy. That is how ethical blind spots form.

The Silent Cost of Being Interrupted

One of the most powerful findings in the article is that interruptions changed employee behavior. Twenty-one of the 27 participants in the follow-up study said they changed how they contributed to meetings. Some spoke faster or more defensively. Some pre-structured arguments to avoid being cut off. Some waited for explicit permission to speak. Others stopped contributing unless necessary. That is exactly what a CCO should worry about.

A healthy compliance culture does not require employees to perform perfectly polished courage. It gives employees room to raise half-formed concerns, ask awkward questions, and test whether something feels wrong before they have built a legal brief around it. Many compliance issues begin as fragments: “Something about this consultant does not feel right.” “The customer is asking for unusual documentation.” “The timing of this payment seems odd.” “Why are we routing this through that entity? ”I am not sure the data use matches what we told customers.” Those are early-stage compliance signals. They need space.

If the meeting culture rewards only fast, polished, confident speech, then employees who need time to frame a concern may never get the chance. The authors note that faster and more confident-sounding speech was often treated as more authoritative. In comparison, slower or less forceful speech was treated as incomplete and therefore easier to interrupt. For a CCO, the lesson is clear: do not build a compliance program that only works for the loudest person in the room.

From Tone at the Top to Conduct in the Room

Compliance professionals have long emphasized “tone at the top.” That remains important. But this article reminds us that tone at the top is incomplete unless it becomes conduct in the room.

The DOJ expects companies to demonstrate that compliance policies and procedures are integrated into operations and that a culture of compliance is embedded in day-to-day activities. That is precisely where meeting behavior matters. Meetings are where risk appetite becomes real. They are where employees learn whether the company actually values integrity when there is a deal to close, a target to hit, or a senior executive to satisfy.

A CCO should, therefore, ask:

What happens when ethics enters the meeting?

Does the room slow down?

Does the leader protect the person raising the concern?

Does someone capture the issue and assign a follow-up?

Does the business discuss controls and alternatives?

Or does the concern get interrupted, minimized, joked away, or pushed offline?

The answers will tell you more about culture than a slogan.

Reading Interruptions as Compliance Data

The authors recommend that leaders stop treating interruptions as isolated incidents and begin reading them as data. It suggests observing who gets interrupted, when the interruption occurs, and what happens to the idea afterward. Is the idea acknowledged? Is it dropped? Is it later picked up without credit? That framework can be directly adapted into a compliance culture assessment.

A CCO can ask compliance, internal audit, HR, or an outside facilitator to observe selected meetings where risk decisions are made. These might include third-party approval committees, deal review meetings, product governance meetings, investigations triage meetings, M&A diligence sessions, safety committees, privacy reviews, or regional leadership calls.

The observer should not simply count who speaks. This is not about policing manners. It is about understanding whether the company’s ethical culture allows risk information to travel upward and across the organization.

Slow the Meeting to Surface the Risk

The article warns that speed and forced momentum can amplify inequality. Faster conversations often favor those who already feel entitled to the floor. Those who anticipate interruption compress their thinking, hesitate, or wait for a clear opening. The authors recommend slowing the interaction: let people finish, pause before responding, reinforce the norm when someone is cut off, and rotate facilitation. This is deeply relevant to compliance.

Many corporate failures occur not because no one saw the risk, but because the organization moved past it too quickly. The payment had to go out. The distributor had to be approved. The quarter had to close. The launch date had to be met. The customer had to be retained. In that environment, “speed” can become a cultural value that overwhelms integrity. A CCO should help leaders build an “integrity pause” into decision-making.

Protect the Contribution, Not the Ego

The article also makes an important distinction. Calling out interrupters or turning every interruption into a lesson on etiquette often does not work. It can escalate the moment and personalize the issue. The better approach is to protect the contribution directly. The authors suggest short interventions such as “Let them finish,” “I want to hear the rest of that point,” and “Let’s come back to the idea that was just interrupted.” This is practical guidance for CCOs and compliance professionals.

When someone raises a compliance concern and is interrupted, the compliance professional does not need to accuse anyone of bad intent. This helps to create psychological safety around risk information. They tell the room that compliance concerns are not interruptions to business. They are part of doing business properly.

The CCO as Culture Observer

A CCO cannot improve culture solely by issuing policies. Policies matter, but culture is reinforced through repeated behavior. The DOJ guidance recognizes that policies and procedures must give effect to ethical norms and be integrated into day-to-day operations. That means the CCO must look beyond policy architecture and ask how people actually behave when decisions are being made.

Not every interruption is retaliation. Not every fast-paced meeting is unethical. Not every dominant speaker is a compliance risk. But patterns matter. Repeated interruption of certain people, functions, geographies, or types of concerns is cultural data. A CCO should treat it as such.

Turning the Article into a Compliance Playbook

A practical CCO response could include five steps.

  1. Add meeting behavior to the culture assessment. Ask employees whether they can finish raising concerns in meetings, whether leaders invite dissent, whether objections to risk are credited, and whether certain voices are routinely ignored.
  2. Observe high-risk meetings. Select a sample of decision-making forums and map interruptions, credit, follow-up, and closure. The goal is not surveillance. The goal is to understand whether the company’s values show up when risk is discussed.
  3. Train leaders on protecting concerns. Leadership training should include simple phrases or the preservation of unfinished risk points. A manager does not need to become a compliance expert to say, “Let’s hear the rest of that concern.”
  4. Build structured dissent into key decisions. For high-risk approvals, require a final risk round before the decision. Ask compliance, finance, legal, HR, internal audit, cybersecurity, or local-market leaders whether they see an unresolved issue.
  5. Report cultural signals to the board. Boards should hear more than hotline statistics. They should understand whether the organization’s meeting culture supports candor, dissent, and ethical escalation.

Improving Corporate Culture Around Ethics and Integrity

The broader message for compliance professionals is that ethics and integrity must become observable behaviors. Employees should see integrity in how meetings are run, how concerns are handled, how dissent is credited, how leaders respond to uncertainty, and how the company treats people who slow down a decision for the right reason.

The bottom line is straightforward. The words on the wall do not prove a culture of ethics and integrity. It is proven by who gets to speak, who gets heard, and what happens when someone raises a concern that slows the room down. For the CCO, the lesson from this article is powerful: look at the meetings. That is where the culture is already speaking.

Categories
Compliance and AI

Compliance and AI: Automate the Noise Away – The Future of Financial Crime Detection with Oracle’s Jason Somrak

What is the role of Artificial Intelligence in compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this insightful episode, Tom Fox interviews Jason Somrak, Chief of Product & Strategy – Financial Crime & Compliance at Oracle Financial Services Software Limited.

They delve into the evolving role of AI in combating financial crimes and the proactive potential of AI in compliance investigations. Highlighting the transformative power of AI, Jason explains its applications, ranging from detection to investigation, and its impact on regulatory practices. They also discuss future emerging challenges in risk management and the collaboration between humans and AI in enhancing financial crime detection and compliance.

Key highlights:

  • AI’s Role in Financial Crime Prevention
  • Proactive and Preventive Measures
  • AI in Investigations and Triage
  • Automating the Noise Away
  • Regulatory Interactions and Challenges
  • Emerging Challenges in Risk Management
  • Future of AI in Compliance
  • Corporate Culture and AI Adoption

Resources:

Jason Somrak on LinkedIn

Oracle Financial Services

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Sunday Book Review

Sunday Book Review: April 6, 2025, The Books on Culture Edition

In the Sunday Book Review, Tom Fox considers books that would interest the compliance professional, the business executive, or anyone who might be curious. These could be books about business, compliance, history, leadership, current events, or anything else that might interest Tom. Today, we look at four books on culture.

  1. The Power of Culture by Laura Hamill
  2. Culture is Everything by Jeff Veyera
  3. Culture by Design by David Friedman
  4. Culture Is The New Leadership by Benjamin Ortlip
Categories
Blog

Driving Compliance Culture: Lessons from a Skills-Based Approach to Cultural Change

Regarding compliance, the tone from the top is crucial—but culture eats tone for breakfast. Compliance professionals know that a robust compliance program is only as effective as the culture supporting it. Building and sustaining that culture, however, is no small feat. Enter the skills-based approach to cultural transformation, as laid out in Per Hugander’s article in the MIT Sloan Management Review, Take a Skills-Based Approach to Culture Change. This method provides a roadmap for embedding compliance values deeply into an organization by focusing on practical skill development and real-world problem-solving. I have adapted her skills-based approach to revolutionize compliance culture, explain why traditional methods often fall short, and provide actionable strategies for compliance professionals to lead this transformation.

Why Traditional Compliance Culture Efforts Fall Short 

Many culture-change initiatives rely on workshops, seminars, and training sessions to instill new values or behaviors. While well-intentioned, these efforts often fail to address the deeply ingrained assumptions that drive behavior. Hugander explains this through Edgar Schein’s Organizational Culture Model, which emphasizes that culture is rooted in employees’ underlying assumptions, those unconscious beliefs that determine how they think, perceive, and act.

This highlights a critical issue for compliance professionals: simply telling employees to act ethically or follow the rules isn’t enough. If underlying assumptions about risk, accountability, or success conflict with compliance values, those assumptions will prevail.

 The Skills-Based Approach: A Paradigm Shift

The skills-based approach focuses on building specific, actionable skills that directly impact critical challenges. These skills—such as perspective-taking or fostering psychological safety—are practiced in real business problems. Organizations create a feedback loop that reinforces new assumptions and behaviors by linking skill application to tangible outcomes.

For example, a compliance team could focus on enhancing perspective-taking to improve employees’ handling of ethical dilemmas. By training employees to consider different viewpoints—such as the customer, regulator, or broader community—they better understand how their actions align with the organization’s compliance goals.

Breaking the Capability Trap 

Hugander warns of the “capability trap,” a common pitfall where organizations abandon new initiatives before they yield results. This happens when the costs—time, focus, and effort—are immediate, but the rewards are delayed. To overcome this, the skills-based approach emphasizes creating short feedback loops by applying new skills to high-priority challenges. This allows employees to see the benefits of the new approach more quickly, generating momentum for change.

The capability trap might manifest in compliance when a new whistleblower program is launched but does not initially generate reports, leading leaders to doubt its effectiveness. The organization can build trust in the system and encourage broader use by coupling the program with communication training for managers and immediate action on even minor concerns raised.

Compliance Lessons from the Skills-Based Approach 

  1. Start Small, Go Deep. Hugander advocates beginning with a small team and focusing on intensive skill-building sessions tied to real challenges. This allows the team to build confidence in the new approach and generate success stories that can inspire broader adoption. This means the Chief Compliance Officer (CCO) or other compliance professional should select a pilot group, such as a high-risk department or business unit, and train them on a specific compliance skill, such as ethical decision-making or identifying conflicts of interest. Have them apply these skills to actual compliance challenges and measure the outcomes.
  2. Create Cultural Champions. Identifying and empowering influential individuals to champion new behaviors is critical. These champions provide proof of concept by demonstrating how the new skills lead to better outcomes in the organization’s context. For the CCO, work to cultivate champions within senior leadership and middle management. A senior executive might lead by example in applying transparency during a compliance audit, while a middle manager might model open discussions about ethical or integrity concerns.
  3. Link Compliance to Business Outcomes. A key feature of the skills-based approach is tying new skills to measurable business improvements. Perspective-taking and psychological safety led to increased customer acquisitions and market share in Amy Edmonson’s SEB case study. For the compliance professional, you can demonstrate how compliance initiatives support business goals. Show how enhanced due diligence processes reduce the risk of fines and improve supplier reliability, ultimately benefiting the bottom line.
  4. Address Skepticism Through Experience. Short workshops are often insufficient to win over skeptics. Instead, intensive, hands-on sessions that produce actual results are more likely to shift mindsets. Skeptics who experience success become the strongest advocates for change. Integrate compliance into strategic problem-solving sessions instead of relying solely on compliance training. This would allow the compliance function to use a compliance framework to resolve a cross-functional challenge, demonstrating its practical value.

Building Momentum for Compliance Culture Change 

The skills-based approach does not stop with a single team or project. Once initial successes are achieved, the organization can share these stories to build momentum. Hugander emphasizes the power of storytelling, using real examples to illustrate how new skills or behaviors lead to meaningful outcomes. Some strategies might be to develop case studies from early adopters of compliance initiatives within your organization. You can then share these stories through town halls, newsletters, or internal training sessions.  Finally, these success stories can be used to recruit additional teams to adopt the new compliance practices.

All of this will take a concerted effort. A one-and-done superficial effort like one-off workshops or values posters, which fail to address the deeper assumptions driving behavior, will not work. True culture change requires sustained effort, leadership buy-in, and a willingness to experiment and iterate. You must regularly assess the effectiveness of compliance initiatives through employee surveys, performance metrics, and feedback loops. Adjust strategies based on what works in practice, not just in theory.

Building a compliance culture requires more than policies and procedures; it demands a shift in the underlying assumptions and behaviors that define an organization’s operation. The skills-based approach offers a practical roadmap for achieving this transformation. By focusing on skill development, linking compliance to business outcomes, and creating cultural champions, compliance professionals can foster a culture that doesn’t just follow the rules but embraces compliance as a core value.

The journey will not be quick or easy, but the payoff of creating a resilient, ethical, and high-performing organization is well worth the effort. For compliance professionals ready to lead this charge, the skills-based approach provides the tools to turn vision into reality.

Categories
Sunday Book Review

Sunday Book Review: December 29, 2024 – The Top Corporate Culture Books from 2024 Edition

In the Sunday Book Review, Tom Fox considers books that interest the compliance professional, the business executive, or anyone curious. These could be books about business, compliance, history, leadership, current events, or anything else that might interest Tom. In December, Tom will review the top books in some key areas of interest for compliance professionals and four top books on corporate culture from 2024.

  1. Unspoken by Ella F. Washington
  2. Tribe of Mentors by Timothy Ferriss
  3. Employalty by Joe Mull
  4. The Gift of Culture by Will Scott

 

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Categories
Blog

Creating, Strengthening, and Maintaining Corporate Culture: Lessons from The Mummy

Ed. Note: This week, leading up to Halloween, I will examine lessons for compliance professionals through the lens of the great Universal Movie Monsters: Frankenstein, Wolfman, Dracula, and The Mummy. Our final offer is Boris Karloff’s original film version of The Mummy. 

===========================================================

In the 1932 classic The Mummy, Boris Karloff’s portrayal of Imhotep reveals a lesson far beyond the supernatural realm: the dangers of neglecting the past and allowing an ancient curse to resurface. The movie’s central theme of resurrection and control reflects what happens in corporate culture when old habits, unaddressed problems, or toxic elements re-emerge due to inattention. Building a strong, resilient corporate culture is crucial for compliance professionals, not unlike guarding against an ancient curse that could unravel the organization.

In her recent speech at the SCCE conference, Nicole Argentieri provided valuable insights into the importance of creating, strengthening, and maintaining corporate culture. Her message was clear: corporate culture is not a static entity. Like Imhotep’s curse, it can decay if not properly maintained, leading to disastrous consequences. The 2024 Evaluation of Corporate Compliance Programs (2024 ECCP) emphasizes the importance of culture in mitigating compliance risks, making it clear that companies must prioritize their corporate ethos as a proactive strategy for risk management.

The Origins of Corporate Culture: Digging into the Foundations

In The Mummy, the archaeological team unknowingly unleashes a destructive force by uncovering and neglecting the historical warning signs of the curse. This is analogous to companies that need more of their corporate culture. Just as the archaeologists ignored the history behind Imhotep’s tomb, companies often overlook the foundational values and behaviors that drive their internal culture.

Argentieri’s speech underscores the importance of understanding where your corporate culture comes from. The 2024 ECCP stresses the need for companies to actively cultivate a culture of compliance, ethics, and integrity. It’s not enough to have values written in a code of conduct—those values must be woven into the company’s fabric, from leadership to the newest employee.

The origins of a corporate culture come directly from leadership. Just as the resurrection of Imhotep was enabled by human error, a toxic or lax corporate culture can take root if leaders do not actively promote ethical behavior. Compliance professionals must work with leadership to ensure the company’s mission, values, and expectations are clearly communicated and consistently upheld. Without this strong foundation, the “mummy” of unethical behavior can quickly rise.

Resurrecting Old Problems: The Danger of Neglect

In The Mummy, Imhotep’s curse returns because it was never truly addressed; it was sealed away but not eradicated. This is a powerful metaphor for what happens in corporate culture when old issues, such as poor leadership behavior, unethical practices, or lack of accountability, are allowed to fester. If left unchecked, these issues can resurface and cause significant harm to the organization.

Argentieri’s speech touched on this very point. Moreover, the 2024 ECCP requires companies to identify and address the risks that could undermine their culture. Compliance professionals must proactively monitor the workplace for signs of cultural erosion. These issues must be confronted head-on, whether lax attitudes toward compliance, a lack of whistleblower protections, or unethical leadership practices.

Regular audits, surveys, and employee feedback mechanisms are critical tools for uncovering hidden problems before they escalate. By monitoring corporate culture at regular intervals, compliance professionals can prevent “mummies” from reawakening and wreaking havoc on the organization.

Leadership: The Keepers of the Tomb

In The Mummy, the characters who succeed are the ones who recognize the danger and take action to stop it. For a company to maintain a strong culture, leadership must play an active role. The tone from the top is crucial in shaping the behavior of the entire organization. Leaders who demonstrate a commitment to compliance and ethical behavior set the standard for others to follow.

Argentieri highlighted the importance of leadership in her speech, noting that the DOJ expects company leadership to be fully engaged in promoting and maintaining a culture of compliance. The 2024 ECCP calls for leadership to demonstrate commitment to compliance in words and actions. This includes regular involvement in compliance activities, support for compliance personnel, and a clear message that ethical behavior is non-negotiable.

Just as the characters in The Mummy had to confront the curse with courage and resolve, corporate leaders must take ownership of the company’s ethical standards. They are the keepers of the tomb, ensuring that the organization’s values and principles are protected from decay.

Strengthening the Culture: Continuous Vigilance

One of the key themes of The Mummy is the importance of vigilance. Imhotep’s return resulted from human negligence—those responsible did not take the necessary precautions to prevent his resurrection. Similarly, a company’s corporate culture can weaken without continuous effort to maintain and strengthen it.

Argentieri’s speech clarified that the DOJ wants companies to maintain their corporate culture proactively. The 2024 ECCP expects companies to actively monitor their culture, assess risks, and adjust their compliance programs as needed. This requires a commitment to continuous improvement, strengthening internal controls, updating policies, and providing regular training to employees at all levels.

A strong compliance program evolves with the organization. Just as archaeologists learn from the past to protect the future, compliance officers must learn from past mistakes and adjust their strategies to prevent future failures. This might mean revisiting training programs, adjusting disciplinary measures, or enhancing whistleblower protections.

Maintaining a Culture of Compliance: The Final Seal

The ending of The Mummy reminds us that threats can be contained, but only with the right tools and vigilance. In the corporate world, maintaining a culture of compliance is an ongoing process. It requires a commitment to ethical behavior, continuous monitoring, and strong leadership. A company’s corporate culture must be seen as a living entity—one that requires nurturing, attention, and protection.

The 2024 ECCP provides clear guidelines for how companies can maintain a strong culture of compliance. It emphasizes clear communication, regular training, and leadership engagement. Compliance professionals ensure these elements are in place, and the culture remains strong even as new risks emerge.

Learning from The Mummy

The Mummy teaches us that neglecting the past can have dangerous consequences; the same is true for corporate culture. If a company fails to build, strengthen, and maintain its culture of compliance, it risks allowing unethical behavior to resurface, potentially leading to disastrous outcomes.

Argentieri’s recent SCCE speech and the 2024 ECCP offer a roadmap for compliance professionals. By focusing on strong leadership, continuous monitoring, and proactive risk management, companies can create a culture that not only withstands the test of time but also thrives in an ever-changing business environment.

The curse of Imhotep may have been fiction, but the risks facing corporate culture are all too real. Compliance professionals must act as guardians, ensuring that their organizations are protected from ethical missteps that can lead to the unearthing of far more dangerous threats.

Categories
Great Women in Compliance

Great Women in Compliance: Juliana Molina on The Culture We Deserve

Welcome to the Great Women in Compliance Podcast. In this episode, Hemma visits with Juliana Molina, the globe-trotting Compliance and Ethics expert. With law licenses in Brazil and Spain, and as in-house counsel in the US, she brings a multicultural touch to her work. She thrives as an advisor to various industries, driven by a passion to make compliance and ethics more human-centric.

Juliana’s extensive international experience gives her a unique perspective on how culture influences compliance and ethics practices, and how to adapt to different cultural contexts. She prioritizes facilitating ethical choices and fully informed decisions.

Juliana’s perspective on cultural transformation in ethics and compliance is deeply rooted in her belief that an ethical organization is one that views compliance not just as a matter of adherence to rules, but as a commitment to prioritizing the well-being and dignity of all its stakeholders.

Her experience in advising international businesses has reinforced her emphasis on understanding and addressing the diverse needs and experiences of everyone involved, including employees, customers, shareholders, and vendors.

Juliana’s vision of a human-centric approach to compliance promotes empathy, open communication, and collaboration in the co-creation and implementation of compliance programs. By embracing the diverse perspectives within an organization, Juliana believes we can make more informed decisions, drive cultural change, and ultimately align our operations with our vision and goals.

Key Highlights:

  • Human-Centric Cultural Transformation in Ethics and Compliance
  • Fostering Open Communication for Ethical Leadership
  • Leadership’s Role in Driving Organizational Cultural Transformation
  • Ethical Leadership to Prevent Toxic Workplaces
  • Ethical Culture Through Compliance and Empathy
  • An Inclusive Approach for Female Empowerment in Compliance

Resources:

Join the Great Women in Compliance community on LinkedIn here.

Categories
Blog

Transforming Culture: Part 3 – Assessing Change Through the Culture Audit™

Boeing is not the first company to find itself amid a massive scandal. You can think of Siemens’ bribery and corruption scandal, the VW emissions-testing scandal, the Wells Fargo fraudulent accounts scandal, or any other myriad of corporate scandals where culture failed and created a toxic culture. The question for any organization in such a situation is how to transform its culture. Currently running on the Culture Crafters podcast on the Compliance Podcast Network is a 5–part of podcast series with myself and Sam Silverstein, the most trusted voice in America on accountability. (The Culture Audit™ is the sponsor of this blog post series.)

Over this companion, 5-part blog post series, we look at how a company in the depths of such a toxic culture can begin to make a culture comeback by planning and taking concrete steps to turn around and rebuild its culture. In Part 3, we consider assessing change through The Culture Audit™ as a starting point for culture transformation.

The Culture Audit™ plays a pivotal role in culture transformation. It serves as a structured framework for assessing key cultural aspects, providing a comprehensive analysis of strengths and areas needing improvement. By leveraging this assessment tool, organizations can gain valuable insights into their cultural landscape, paving the way for informed decision-making and targeted interventions to drive positive change. The Culture Audit™ is not just about knowing the existing culture, but about providing actionable insights and an action plan for organizations to implement changes and enhance their culture effectively. Its true transformative potential lies in its ability to catalyze meaningful cultural shifts by pinpointing areas of alignment and discord within an organization.

The Culture Audit™ provides organizations with a clear roadmap for culture transformation. The emphasis on anonymity within the audit process lets employees express their perceptions candidly, fostering a culture of openness and transparency. By providing a platform where individuals can share their feedback without fear of retribution, organizations can obtain honest and valuable insights to understand the actual state of their culture.

The Culture Audit™ stands out from traditional assessment strategies due to its unique features. It offers ease, speed, accuracy, and anonymity, making it a cost-effective and efficient tool for organizations striving to enhance their culture. Its ability to support multiple languages ensures accurate and in-depth insights from diverse workforce populations, further setting it apart from other tools.

The Culture Audit™ measures various aspects of a company’s culture, including compliance practices, hiring processes, and employee engagement. It generates a comprehensive report highlighting gaps and providing actionable improvement steps. The tool mainly benefits global organizations as it supports international language communication.

One key feature of The Culture Audit™ is its emphasis on auditability and transparency. In the event of a regulator’s inquiry, the tool provides a detailed report that can be shared to demonstrate the company’s commitment to assessing and improving its culture. The Culture Audit™ goes beyond basic measures of engagement and assesses accountability and decision-making processes, providing a comprehensive view of an organization’s culture. The raw data collected during The Culture Audit™ is also retained for future reference, allowing organizations to track their progress over time.

The Culture Audit™ brings significant benefits to organizations. It not only identifies areas for improvement but also provides actionable insights. The audit report includes a detailed action plan that guides organizations on specific areas to focus on and steps to take for improvement. As Silverstein emphasized, by continuously reinforcing positive aspects of their culture, organizations can prevent a decline over time. This continuous improvement approach is crucial for all companies, whether they are underperforming or reinforcing what they are already good at.

In conclusion, The Culture Audit™ provides organizations with a powerful tool to assess and improve their corporate culture. By measuring various aspects of culture, providing actionable insights, and emphasizing auditability and transparency, The Culture Audit™ helps organizations create a positive and productive workplace environment. With regulators’ increasing focus on corporate culture, The Culture Audit™ can also help companies demonstrate their commitment to ethical behavior and compliance. By utilizing this tool, organizations can drive better leadership, improve employee engagement, and ultimately enhance their bottom line.