Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 62 – Unity on the Final Frontier: Cross-Cultural Compliance Insights from ‘Day of the Dove’

Modern compliance officers grapple with complexities arising from international business relationships, mergers, acquisitions, and partnerships, navigating disparate cultural expectations and norms. Star Trek TOS, especially the episode “Day of the Dove,” provides a surprisingly rich source of compliance insights into these challenges. In a globalized business environment, compliance professionals frequently encounter situations analogous to the manipulated hostilities between the Federation and Klingons. Misunderstandings, mistrust, and cross-cultural miscommunication can escalate tensions, threaten corporate integrity, and hinder operations. Let’s distill five critical compliance lessons from “Day of the Dove,” offering practical guidance to the compliance professional for cross-cultural scenarios.

Lesson 1: Recognize and Neutralize Bias and Stereotyping

Illustrated by: Early in the episode, the Enterprise crew and the Klingons instantly regard each other with suspicion and prejudice.

Compliance Lesson: For compliance officers, understanding and addressing implicit biases is crucial. Like the Enterprise crew, professionals often enter new markets or partnerships with preconceived ideas about cultural expectations, risk tolerance, or ethical behaviors. Such biases may cloud objective judgment and inadvertently fuel tension or compliance failures.

Lesson 2: Question Motives and Uncover Root Causes

Illustrated by: When Kirk realizes the ongoing conflict is unnatural, he questions its cause, eventually uncovering the entity exploiting their anger.

In compliance, cross-cultural misunderstandings often have deeper root causes than the surface-level tension suggests. Misaligned incentives, conflicting internal controls, and divergent perceptions of risk can escalate minor disagreements into full-blown compliance crises.

Lesson 3: Collaboration and Common Goals Overcome Conflict

Illustrated by: Ultimately, Kirk and Commander Kang set aside their rivalry, jointly recognizing their mutual enemy as the manipulative entity.

Compliance Lesson: Cross-cultural compliance similarly requires organizations to align clearly defined common objectives, shared values, and mutual benefit. Whether responding to anti-corruption regulations like the FCPA, managing third-party due diligence, or harmonizing diverse internal standards, clear communication and shared goals serve as the foundation for collaboration.

Lesson 4: Communication and Transparency are Critical

Illustrated by: Misunderstandings abound initially due to poor communication between the Klingons and the Federation.

Compliance Lesson: Compliance challenges arising from cross-cultural scenarios frequently result from misunderstandings or assumptions due to poor transparency or communication. Language barriers, culturally distinct reporting methods, and differing standards of directness or openness can lead to confusion and non-compliance.

Lesson 5: Leadership Sets the Tone and Culture

Illustrated by: Both Kirk and Kang exhibit strong leadership by openly demonstrating the willingness to reconsider their positions and lead their crews in jointly rejecting the entity’s divisive influence.

Compliance Lesson: Compliance leadership must similarly set the tone and demonstrate cultural competence. Leaders who visibly prioritize integrity, open dialogue, and mutual respect set a powerful compliance culture example. Cross-cultural scenarios particularly require compliance leaders to demonstrate humility, openness, and willingness to learn and adjust behaviors.

Final ComplianceLog Reflections

The global nature of today’s business operations makes cross-cultural competency not merely a nice-to-have, but an essential compliance skill set. “Day of the Dove,” through its compelling narrative and insightful conflict resolution, mirrors real-world compliance scenarios faced by international organizations.

By integrating these timeless lessons from “Day of the Dove,” compliance professionals are better equipped to navigate complex cross-cultural challenges, transforming potential conflicts into opportunities for collaboration, understanding, and compliance excellence.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Compliance Across Cultures: Lessons from Star Trek’s “Day of the Dove”

In the dynamic and continually evolving landscape of corporate compliance, one recurring theme is the necessity of cross-cultural understanding and collaboration. Modern compliance officers grapple with complexities arising from international business relationships, mergers, acquisitions, and partnerships, navigating disparate cultural expectations and norms. Star Trek TOS, especially the episode “Day of the Dove,” provides a surprisingly rich source of compliance insights into these challenges. As we revisit this classic, let’s examine what Captain Kirk and his crew can teach today’s compliance professional about managing cross-cultural compliance risks effectively.

The episode sees the USS Enterprise encountering a mysterious entity that thrives on conflict and hatred. After coming across Klingon survivors led by Commander Kang, Kirk’s crew and the Klingons are manipulated into perpetual conflict aboard the Enterprise. Both sides soon realize that the entity is using their hatred to feed and grow stronger. Ultimately, they unite to reject the divisiveness that feeds the entity, ending the conflict and regaining control of the Enterprise.

In a globalized business environment, compliance professionals frequently encounter situations analogous to the manipulated hostilities between the Federation and Klingons. Misunderstandings, mistrust, and cross-cultural miscommunication can escalate tensions, threaten corporate integrity, and hinder operations. Let’s distill five critical compliance lessons from “Day of the Dove,” offering practical guidance to the compliance professional for cross-cultural scenarios.

Lesson 1: Recognize and Neutralize Bias and Stereotyping

Illustrated by: Early in the episode, the Enterprise crew and the Klingons instantly regard each other with suspicion and prejudice. Their preconceived notions drive initial hostility, fueled by longstanding animosity and stereotypes.

Compliance Lesson: For compliance officers, understanding and addressing implicit biases is crucial. Like the Enterprise crew, professionals often enter new markets or partnerships with preconceived ideas about cultural expectations, risk tolerance, or ethical behaviors. Such biases may cloud objective judgment and inadvertently fuel tension or compliance failures.

To prevent this, organizations must implement targeted compliance training that explicitly addresses biases and promotes empathy and cultural intelligence. Awareness and sensitivity training programs can help staff challenge assumptions, mitigate prejudices, and foster constructive dialogue, much like Kirk’s eventual acknowledgment of shared misunderstandings.

Lesson 2: Question Motives and Uncover Root Causes

Illustrated by: When Kirk realizes the ongoing conflict is unnatural, he questions its cause, eventually uncovering the entity exploiting their anger. This epiphany sets the stage for collaboration and resolution.

In compliance, cross-cultural misunderstandings often have deeper root causes than the surface-level tension suggests. Misaligned incentives, conflicting internal controls, and divergent perceptions of risk can escalate minor disagreements into full-blown compliance crises.

Conducting effective root-cause analyses, guided by robust investigative frameworks as recommended by regulatory bodies like the DOJ and the 2024 ECCP, can uncover the underlying issues fueling compliance challenges. This diagnostic approach not only mitigates immediate issues but also promotes long-term resilience and cultural cohesion.

Lesson 3: Collaboration and Common Goals Overcome Conflict

Illustrated by: Ultimately, Kirk and Commander Kang set aside their rivalry, jointly recognizing their mutual enemy as the manipulative entity. By focusing on a shared goal, they regain their agency and restore harmony aboard the Enterprise.

Compliance Lesson: Cross-cultural compliance similarly requires organizations to align clearly defined common objectives, shared values, and mutual benefit. Whether responding to anti-corruption regulations like the FCPA, managing third-party due diligence, or harmonizing diverse internal standards, clear communication and shared goals serve as the foundation for collaboration.

Compliance leaders must foster environments where culturally diverse teams understand and internalize collective compliance objectives. Creating alignment workshops, compliance vision statements, and shared metrics are effective strategies to build unity and proactive cooperation among global stakeholders.

Lesson 4: Communication and Transparency are Critical

Illustrated by: Misunderstandings abound initially due to poor communication between the Klingons and the Federation. Once both parties openly discuss their suspicions, their improved communication proves essential in ending the conflict.

Compliance Lesson: Compliance challenges arising from cross-cultural scenarios frequently result from misunderstandings or assumptions due to poor transparency or communication. Language barriers, culturally distinct reporting methods, and differing standards of directness or openness can lead to confusion and non-compliance.

Organizations must proactively address these communication gaps by implementing multilingual training programs, culturally sensitive reporting hotlines, and comprehensive policies written clearly and accessible across cultures. Additionally, transparency must be embedded in compliance systems, ensuring stakeholders across different geographies have clear, consistent, and accessible information.

Lesson 5: Leadership Sets the Tone and Culture

Illustrated by: Both Kirk and Kang exhibit strong leadership by openly demonstrating the willingness to reconsider their positions and lead their crews in jointly rejecting the entity’s divisive influence.

Compliance Lesson: Compliance leadership must similarly set the tone and demonstrate cultural competence. Leaders who visibly prioritize integrity, open dialogue, and mutual respect set a powerful compliance culture example. Cross-cultural scenarios particularly require compliance leaders to demonstrate humility, openness, and willingness to learn and adjust behaviors.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP), reinforced recently by Nicole Argentieri’s commentary, specifically highlights culture as critical to compliance effectiveness. Leaders who exemplify integrity and communicate clear, respectful expectations foster a compliance-positive environment. Such leadership inspires global employees, encouraging them to embrace company values and compliance standards.

Final ComplianceLog Reflections

The global nature of today’s business operations makes cross-cultural competency not merely a nice-to-have, but an essential compliance skill set. “Day of the Dove,” through its compelling narrative and insightful conflict resolution, mirrors real-world compliance scenarios faced by international organizations.

Just as Kirk’s crew and the Klingons successfully rejected divisiveness. They overcame manipulated hostilities. Compliance professionals must recognize and neutralize biases, uncover root causes of tension, prioritize common goals, enhance transparent communication, and demonstrate culturally sensitive leadership.

As we forge ahead in a global compliance landscape, these insights from classic Star Trek remain relevant. The universe Kirk explored may be fictional, but the lessons learned aboard the Enterprise are profoundly real and applicable for every compliance professional operating in the interconnected global business environment.

By integrating these timeless lessons from “Day of the Dove,” compliance professionals are better equipped to navigate complex cross-cultural challenges, transforming potential conflicts into opportunities for collaboration, understanding, and compliance excellence.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Great Women in Compliance

Great Women in Compliance: Culture is What Happens When No One is Watching

Culture is one of those topics in ethics and compliance that everyone talks about—but it’s also one of the hardest things to define and even harder to build. At Compliance Week, Lisa Fine discussed this with Amy Schuh, partner at Morgan Lewis; Kilby McFadden, Managing Director and Head of Investigations at KPMG; and Michael Ortwein, Chief Compliance Officer and Assistant General Counsel at GM. Today, Amy and Kilby continue the discussion with Lisa Fine and Sarah Hadden.

They start by discussing what they see as a strong compliance culture. As Kilby says, it’s what happens when no one is watching. The conversation focuses on how organizations move beyond policies and training to build trust, encourage employees to speak up, and empower leaders to make ethical decisions—even when those decisions are difficult.

Amy and Kilby share practical insights from years of experience leading investigations and advising organizations, discussing who really owns culture, how companies can create trust in the reporting process, and why relationships with the business matter just as much as policies and procedures. They also explore the challenges of building a consistent culture across global organizations and offer ideas for strengthening culture even when resources are limited.

They also include key takeaways for compliance professionals, such as the importance of listening, staying curious about the business, and building relationships before issues arise, and each shares one “myth” about Ethics & Compliance they think should be debunked.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 39 – Federation Fundamentals: What “Journey to Babel” Teaches Us About Global Compliance

In the ever-expanding universe of corporate compliance, the question of how to bridge cultural divides is as critical as it is complex. Navigating global operations, integrating diverse teams, and balancing conflicting interests. These challenges would be familiar to Captain Kirk and the crew of the Enterprise, particularly in the classic Star Trek: The Original Series episode “Journey to Babel.”

Today, we explore five essential cross-cultural compliance lessons, each grounded in a scene from “Journey to Babel.” These insights are not simply for the Starship Enterprise. Instead, they are vital for every compliance professional in today’s globalized business world.

Lesson 1: Cultural Awareness is the Foundation of Trust

Illustrated by: At a diplomatic reception. Ambassadors Sarek (Vulcan) and Gav (Andorian) nearly come to blows over the proposed admission of Coridan to the Federation.

Compliance Lesson: Cultural awareness is the bedrock of ethical business practice. As compliance professionals, we must recognize that every culture brings its perspectives, values, and sensitivities to the table.

Lesson 2: Personal Bias Must Never Trump Professional Duty

Illustrated by: Kirk discovers that Spock’s parents, Sarek and Amanda, are aboard.

Compliance Lesson: Compliance professionals must create policies and foster cultures that prioritize professional integrity above personal interest, even (or especially) when emotions run high.

Lesson 3: Open Communication is Critical in Preventing Escalation

Illustrated by: Tensions flare after Ambassador Gav’s murder.

Compliance Lesson: Silence or closed-door decisions breed mistrust and can quickly escalate a manageable issue into a full-blown crisis.

Lesson 4: Ethical Leadership Means Making the Hard Call

Illustrated by: Kirk, gravely wounded during an assassination attempt, insists on returning to the bridge rather than receiving treatment so that Spock can perform surgery on Sarek.

Compliance Lesson: Effective compliance leaders are those who lead by example, making tough decisions that may be unpopular or personally costly but which uphold the organization’s mission and values.

Lesson 5: Unity Through Diversity Drives Mission Success

Illustrated by: Despite assassination attempts, sabotage, and political intrigue, the Enterprise ultimately succeeds in its mission.

Compliance Lesson: When managed ethically, cross-cultural teams produce better solutions, more robust risk assessments, and more effective compliance outcomes.

Final ComplianceLog Reflections

Journey to Babel” reminds us that successful missions, whether in interstellar diplomacy or global business, depend on more than technical expertise or strategic positioning. They require cultural competence, ethical leadership, and a willingness to prioritize the mission over personal interests.

For the compliance professional, the lessons are clear: invest in cultural awareness, build transparency, foster ethical leadership, and leverage diversity as a driver of success. In today’s interconnected world, the road to Babel is one we all travel. It is your job as a compliance professional to ensure we do so ethically, collaboratively, and boldly.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Timothy and Fiona are AI-generated voices

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 25 – Cross-Cultural Lessons from Devil in the Dark

Show Summary

The classic episode “Devil in the Dark” is a compelling exploration of misunderstandings, communication breakdowns, and reconciliation between vastly different cultures—lessons that resonate strongly with corporate compliance officers navigating today’s global marketplace.

In “Devil in the Dark,” the USS Enterprise is dispatched to investigate mysterious deaths in a mining colony. What initially seems like straightforward monster attacks turns out to be a profound misunderstanding between humans and an alien creature called the Horta. Today, we will examine five key compliance lessons that corporate professionals can learn from the iconic Star Trek episode.

Lesson 1: Recognize and Challenge Your Own Biases

Illustrated By: When the Enterprise crew arrives, the miners describe a monstrous creature attacking and killing miners, labeling it simply as a dangerous beast to be eliminated. Their preconceived notions blinded them to the possibility of understanding the creature.

Compliance Lesson: Compliance professionals must actively recognize and challenge their assumptions and biases.

Lesson 2: Effective Communication Requires Genuine Effort and Empathy

Illustrated By: The turning point of the episode comes when Spock mind-melds with the Horta. Through genuine empathy and effort, he discovers that the Horta is not malevolent but is protecting its offspring, the silicon nodules that the miners had inadvertently been destroying.

Compliance Lesson: Corporate compliance teams operating in multinational contexts must make a genuine effort to communicate effectively with global partners, subsidiaries, and stakeholders.

Lesson 3: Cultural Awareness as a Risk Mitigation Strategy

Illustrated By: The miners’ failure to recognize the silicon nodules as living offspring stems from ignorance about the Hortas’ culture and biology. This ignorance creates hostility and unnecessary conflict.

Compliance Lesson: Understanding local cultural norms, regulatory landscapes, and business ethics is vital for operating ethically and legally across jurisdictions.

Lesson 4: Embrace Diversity to Foster Innovation and Solutions

Illustrated By: The Enterprise crew’s diverse backgrounds and experiences enable them to devise innovative solutions. Spock’s unique Vulcan abilities allow communication with the Horta, transforming a volatile situation into a collaborative one.

Compliance Lesson: Diverse compliance teams bring varied experiences, perspectives, and problem-solving approaches essential for effectively managing complex compliance challenges.

Lesson 5: Seek Win-Win Solutions through Collaboration

Illustrated By: Ultimately, Captain Kirk brokers a cooperative agreement between the miners and the Horta, allowing peaceful coexistence and mutual benefit. The miners extracting resources and the Horta species continue unharmed.

Compliance Lesson: Compliance professionals should adopt a win-win mindset, working collaboratively with regulatory authorities, local communities, employees, and third-party partners to align compliance objectives with mutual benefits.

Final ComplianceLog Reflections

Star Trek’s “Devil in the Dark” vividly illustrates the consequences of cross-cultural misunderstandings and the immense benefits of cultural empathy, clear communication, diversity, and collaborative problem-solving. For corporate compliance professionals, this episode serves as a powerful reminder that effective compliance programs necessitate intentional cross-cultural engagement, ongoing education, and empathy-driven interactions.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Innovation in Compliance

Innovation in Compliance: Rethinking SpeakUp: UX, Trust, and AI in Whistleblowing and Investigations with Tim Morss

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode,  host Tom visits with Tim Morss, CEO at SpeakUp, about the evolution of speak-up systems from the employee perspective.

Morss describes his background in compliance technology and SpeakUp’s global footprint, emphasizing that employee expectations favor frictionless, mobile-first, intuitive reporting with transparency and feedback over 800-number hotlines and complex forms. He notes common program gaps: hard-to-find reporting channels, poor mobile experiences, overreliance on telephony (especially problematic for non-English speakers), insufficient guidance on what to report, and weak trust due to lack of follow-up and perceived inaction. They consider generational preferences, privacy-aware deployment, such as QR code placement, and AI use cases such as multilingual voice intake for illiterate supply-chain workers, while cautioning against unsafe AI practices and autonomous decision-making. Morss highlights investigative management as a major opportunity beyond basic case repositories and forecasts greater AI-driven integration with in-house systems amid geopolitical and regulatory divergence.

Key highlights:

  • Employee Expectations Shift
  • Common SpeakUp Mistakes
  • Trust and Anti-Retaliation
  • Gen Z Reporting Channels
  • AI Voice for Workers
  • One Practical CCO Tip

Resources:

Connect with Tim Morss on LinkedIn

SpeakUp

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Blog

The Miri Mandate: Compliance Lessons in Crisis and Contingency

Show Summary

Today, we explore one of the eeriest and most profound cautionary tales in the Star Trek canon—Miri. When the crew responds to a distress signal from a planet that’s an exact duplicate of Earth, they find a society ravaged by a failed experiment in human longevity. Only children remain, while the adult “grups” have all died from a virulent disease.

This haunting story is not science fiction. It’s a case study of what happens when risk management is treated as an afterthought. We draw parallels between the biohazard breakdowns on the planet and the kinds of failures that modern compliance officers must guard against, whether in public health readiness, supply chain risk, or workforce welfare.

Key Highlights and Risk Management Case Illustrations

1. Disaster Preparedness—A Cure Without a Contingency Plan

Illustrated by: The civilization’s experiment to extend life, which instead wipes out all adults.

This central failure underscores the risks associated with scientific advancement that lacks proper risk assessment. The developers had no fallback, no regulatory oversight, and no crisis management framework. For compliance professionals, this serves as a reminder that innovation must be paired with effective scenario planning and disaster recovery protocols.

2. Environmental and Public Health Compliance—Invisible Risks Become Existential Threats

Illustrated by: The crew’s infection with the disease upon beaming down, with lesions appearing days later.

This serves as a metaphor for health and safety non-compliance. Enterprises must be vigilant about how workplace conditions, unseen hazards, and biological risks can impact staff and operations. Proactive monitoring and rapid-response mechanisms are essential components of any risk management strategy.

3. Data Governance and Early Warning Systems—Responding Too Late

Illustrated by: The automated distress signal continued even though no adult survivors remained.

The signal was still active, but no one was listening until it was far too late. In modern organizations, this is equivalent to ignoring audit logs, internal control alerts, or whistleblower reports that go unread. A culture of attentiveness to data and signals is crucial to catching issues before they cascade.

4. Supply Chain Risk—Critical Resource Shortages in the Field

Illustrated by: The crew’s struggle to develop a cure under limited time, with no labs and deteriorating conditions.

Kirk and McCoy were caught without adequate resources. This scenario mirrors the real-world risks companies face when they lack supply chain redundancy, fail to audit vendor health, or fail to plan for logistical disruptions. A robust compliance framework includes stress-testing the supply chain for resilience under duress.

5. Employee Welfare and Isolation—Psychological and Ethical Concerns in Hazard Zones 

Illustrated by: Spock’s decision not to return to the Enterprise due to the risk of contamination.

Spock’s sacrifice is a model of ethical risk containment. In any risk environment, whether it is a pandemic, a data breach, or financial misconduct, companies must empower employees to make ethically sound decisions while providing mental health support for those isolated by crisis-response roles.

Final ComplianceLog Reflections

Miri is a chilling illustration of what happens when ambition outpaces ethics and planning. The children left behind are the victims of a society that prioritizes progress over protection. For compliance professionals, this episode serves as a vivid reminder that a well-crafted compliance program is not just about preventing misconduct; rather, it is about preparing for the unknown.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

John Locke and the Legitimacy of Compliance Governance

We continue our exploration of Enlightenment Thinkers to see their influence on modern compliance programs. This week’s category is broader than philosophers, as many of these men excelled in numerous fields such as science, mathematics, calculus, and medicine. However, each contributed a key component that relates directly to our modern compliance regimes. In this post, we consider René Descartes and what he teaches as the next step beyond Bacon: evidence must be examined rigorously.

If Francis Bacon teaches us that compliance must be grounded in evidence, and René Descartes teaches us that evidence must be examined with rigor, John Locke brings us to the next great question: why should anyone trust the system itself? That question sits at the center of every modern compliance program. Employees are asked to report concerns, managers are expected to model ethical behavior, boards are charged with oversight, and companies routinely tell regulators that their compliance program is real, effective, and embedded in the business. But none of that works if the people inside the organization do not believe the system is fair, credible, and worthy of trust. That is why John Locke matters so much to the modern compliance professional.

Locke is often remembered as a philosopher of liberty, consent, rights, and accountable government. He argued that authority is legitimate only when it is exercised responsibly and for the benefit of those subject to it. Power, in Locke’s world, is not self-justifying. It must be bounded, accountable, and tied to obligations. That idea is highly relevant to corporate compliance. A compliance program is not legitimate simply because senior management approved it, or because the board receives quarterly updates, or because policies have been published on an intranet site. It is legitimate when employees experience it as fair, when reports are taken seriously, when retaliation is not tolerated, when discipline is consistent, and when leadership is seen to be accountable to the same standards as everyone else. That is not abstract philosophy. That is compliance governance.

Why Locke Matters to Compliance

Locke’s central insight is that authority derives its legitimacy from responsible exercise and reciprocal obligation. In a political context, that meant government existed to protect rights and serve the governed, not simply to command obedience. In the corporate context, the analogy is not exact, but the lesson is powerful. Employees will not trust a compliance program merely because it exists. They will trust it only if they believe it operates fairly, protects those who raise concerns, applies standards consistently, and treats power as accountable.

This is where Locke helps compliance professionals understand something many organizations still miss. Trust in a compliance system is not automatic. It has to be earned. An employee deciding whether to call a hotline is making a deeply practical judgment. Will anyone listen? Will the matter be reviewed fairly? Will the reporter be protected from retaliation? Will the senior executive who generated the concern be treated differently from everyone else? If the employee believes the answer to those questions is no, the reporting system has already failed, no matter how polished the company’s policy language may be.

The DOJ’s Compliance Expectations Are About Legitimacy

The Department of Justice does not use the language of social contract theory, but its Evaluation of Corporate Compliance Programs (ECCP) is filled with Locke’s concerns. The ECCP asks whether the program is well-designed, applied in good faith, and works in practice. It asks about tone at the top and tone in the middle. It asks whether reporting mechanisms are trusted, whether investigations are handled properly, whether discipline is applied consistently, and whether there is protection against retaliation. Those are all questions of legitimacy. A compliance program that employees do not trust cannot work in practice.

This point is critical because too many organizations still frame culture as something soft and secondary, a matter of messaging rather than system design. Locke would reject that categorically. In his framework, legitimacy is not a decoration added to authority. It is what makes authority durable and acceptable. In a company, that means culture and governance cannot be separated. Speak-up systems, fair treatment, board attention, transparent escalation, and consistent discipline are not peripheral to compliance. They are core structural elements of it.

Speak-Up Culture Is a Test of Governance

Few areas of compliance reveal Locke’s relevance more clearly than a speak-up culture. Every company says it wants employees to raise concerns. Every company says it prohibits retaliation. But the real issue is whether employees believe those statements are true in lived experience. That belief is shaped more by organizational behavior than by slogans.

If employees see complaints buried, if they watch high performers protected despite repeated concerns, if they hear that reporting a problem is career-limiting, or if they conclude that management is more interested in identifying the reporter than addressing the underlying issue, the company has lost legitimacy. In Lockean terms, authority has ceased to be trustworthy because it is no longer being exercised for the benefit of those subject to it.

This is why non-retaliation is so important. It is not simply an employment-law consideration or a human-resources aspiration. It is a governance imperative. Retaliation tells employees that the system serves power rather than principle. Once that lesson is absorbed, reporting declines, silent resignation grows, and risk moves underground. A company may still claim to have a hotline, but it no longer has a functioning speak-up culture.

Fairness Is Not Soft. It Is a Control.

Locke also helps us understand the role of fairness in a compliance program. In many organizations, fairness is discussed as a value. It should be discussed as a control. Why? Because fairness shapes behavior. When employees believe standards will be applied consistently, they are more likely to follow them, more likely to report deviations, and more likely to trust the company’s response when issues arise. When employees believe discipline is arbitrary, selective, or influenced by rank and revenue generation, the opposite occurs. Cynicism spreads quickly. Policies become performative. Reporting drops. Informal norms replace formal standards.

That is why the ECCP pays so much attention to disciplinary consistency. Regulators understand that a compliance program loses credibility when senior leaders are treated differently from line employees. Locke would have recognized the point immediately. In any system of authority, legitimacy is undermined when rules are used to bind the weak but not the powerful.

Board Oversight and Accountable Authority

Locke’s philosophy is equally useful when thinking about board oversight. He believed that those entrusted with authority must remain accountable for how they exercise it. That is a principle every board member should understand in the context of compliance.

Board oversight is not merely about receiving information. It is about ensuring that authority inside the company is properly bounded, monitored, and answerable. The board does not run day-to-day compliance, but it is responsible for ensuring that management has created a system worthy of trust. That means asking whether reporting channels work, whether investigations are independent, whether non-retaliation protections are real, whether major risks are escalated, and whether compliance has stature and access.

This is particularly important because boards sometimes fall into the trap of treating compliance as a downstream operational matter. Locke would have viewed that as a category mistake. Governance is not something separate from legitimacy. Governance is how legitimacy is maintained.

For the modern board, that means compliance oversight must be substantive. Directors should ask not only for dashboards, but for explanations. How does management know employees trust reporting channels? What evidence supports claims of a strong culture? How is middle management assessed? What happens when senior leaders are implicated? What trends in reporting, substantiation, retaliation, and discipline should concern the board? Those questions move oversight from ceremonial to real.

In that sense, Locke also speaks directly to Caremark-era expectations. Directors have obligations not simply to exist, but to oversee. A board that does not ensure the company has credible systems of information and response is not exercising accountable authority. It is abdicating it.

Culture and the Middle Management Problem

No discussion of compliance legitimacy would be complete without examining middle management. The DOJ, in both the ECCP and the FCPA Resource Guide, 2nd edition, has long emphasized that “tone at the top” is not enough. Tone in the middle matters enormously, because employees experience the company most directly through their immediate supervisors.

This is another place where Locke offers real insight. In any system of authority, legitimacy rises or falls through those who exercise power closest to the governed. If middle managers pressure employees to ignore controls, discourage escalation, roll their eyes at compliance training, or quietly punish bad news, the company’s formal commitments will collapse in practice.

This is why companies must treat middle management behavior as a governance issue. Are managers trained not just on rules, but on their duty to support reporting and ethical decision-making? Are they evaluated on how they build culture? Do promotion and bonus structures reinforce ethical leadership, or only financial performance? Are there consequences when managers create pressure that undermines compliance expectations?

These are not marginal considerations. They are central to whether the compliance program is experienced as legitimate in daily operations. Locke reminds us that people judge institutions less by official declarations than by how authority is exercised.

The Compliance Officer as Steward of Institutional Legitimacy

Locke casts the compliance officer as a steward of institutional legitimacy. That is an important and underappreciated role. The compliance officer helps the company earn trust, not through public relations, but through structure, fairness, and accountability. The compliance officer helps ensure that when people speak up, they are heard; when misconduct occurs, it is handled consistently; when leaders exercise authority, they do so under standards that bind them as well. In this sense, compliance is not just about preventing legal violations. It is about making the institution worthy of confidence.

That is why legitimacy matters so much. A company with high trust in its compliance system detects issues earlier, responds more effectively, learns more quickly, and sustains a stronger ethical culture over time. A company without that trust becomes opaque to itself. Risk goes silent. Problems surface late. Governance becomes reactive. The institution loses one of its most important defenses: its own people’s willingness to tell it the truth.

Five Lessons Learned for the Modern Compliance Professional

First, a compliance program must be legitimate to be effective. Employees must believe the system is fair, credible, and trustworthy.

Second, speak-up culture is a governance test. Reporting mechanisms only work when employees believe concerns will be taken seriously and retaliation will not follow.

Third, fairness is a control. Consistent discipline, equal treatment across levels of seniority, and transparent standards strengthen compliance credibility.

Fourth, boards must exercise accountable oversight. They should test management’s claims about culture, reporting, and non-retaliation with real evidence.

Fifth, middle management is where legitimacy lives or dies. A company must align manager incentives, expectations, and accountability with its compliance values.

Coming Next: Thomas Hobbes and Why Every Compliance Program Needs Order

If John Locke teaches us that compliance governance must be legitimate, Thomas Hobbes will remind us that legitimacy alone is not enough. A company also needs structure, clear rules, assigned authority, escalation pathways, and credible enforcement. In Part 4, I will explore how Hobbes helps explain the roles of policies, procedures, internal controls, and operational discipline in a best-practices compliance program. Trust matters, but so does order.

Categories
Great Women in Compliance

Great Women in Compliance: Culture Check: Are Your Speak Up Channels Effective?

Ever wish you could benchmark your Speak Up channels against more than just volume, issue types, and time to close? 

The Speak Up Self-Assessment (SUSA) was designed to help you go deeper by assessing organizational infrastructure—including reporting channels, confidentiality safeguards, follow-up processes, and governance of whistleblowing systems.

In this roundtable episode, we speak with guests: 

  • Professor Jessica McManus Warnell
  • Dr. Mary Gentile 
  • Allison Narmi 

about the work they are doing to bring a free, anonymous diagnostic tool to self-assess speak-up channels. Building on the work done in the EU, our guests today are members of the project team that has developed an American version of the tool, with support from the Notre Dame Deloitte Center for Ethical Leadership. Link to the EU version here – https://edhec.az1.qualtrics.com/jfe/form/SV_eleMjkHraHzw6Hk

U.S. version coming soon.  

Categories
Daily Compliance News

Daily Compliance News: April 16, 2026, The Bribery is Legal in Illinois Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

For more information on the use of AI in Compliance programs, my new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.