Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 55 – Out of Time: Due Diligence Lessons from ‘Assignment: Earth

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners all come with their backgrounds and histories.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is but what they are capable of and what they plan to do with that capability.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyber-attacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences?

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Fiona is an AI-generated voice

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 47 – Charting Unseen Risks: Investigative Strategies from ‘The Immunity Syndrome’

There is a moment in every compliance professional’s career when you must venture into the unknown: a new country, a new business line, or a merger with a company whose culture, controls, and risks you only dimly perceive. In many ways, this is the compliance professional’s dilemma when launching operations in a new jurisdiction or pursuing a new business venture. Old assumptions may no longer apply—hidden dangers lurk where we least expect. And survival, not just success, depends on investigative skills, adaptability, and a willingness to challenge everything we think we know. Today, we examine the investigative lessons from “The Immunity Syndrome” that every compliance professional should heed when boldly going where their organization has never gone before.

Lesson 1: Question Your Assumptions—The Risks May Be Invisible

Illustrated by: The Enterprise receives a distress call and learns that the Intrepid, a ship crewed entirely by Vulcans, has been destroyed by an unknown force.

Investigative Takeaways:

  • Do not assume that past success in other markets guarantees future safety.
  • Leverage local knowledge just as Spock’s unique connection gave the Enterprise vital early warning.
  • Use multiple investigative approaches: don’t rely solely on established data or processes.

Lesson 2: Conduct a Deep Diagnostic—Surface Scans Are Never Enough

Illustrated by: The Enterprise finds a “zone of darkness” in space. It is a void with no energy, no light, and no readings at all. Standard scans and probes reveal nothing.

Investigative Takeaways:

  • Supplement traditional due diligence with on-the-ground investigations and “boots on the ground” audits.
  • Look for the absence of evidence as well as the presence—missing records, unusual silence, or gaps in documentation can be just as telling as a smoking gun.
  • Enlist specialists (just as Kirk uses Spock and McCoy’s unique skills) to delve into complex risks, whether legal, cultural, or operational.

Lesson 3: Trust but Verify—Local Expertise Is Essential, But Not Infallible

Illustrated by: Kirk is forced to choose between Spock and McCoy for a dangerous reconnaissance mission into the organism’s interior.

Investigative Takeaways:

  • Respect local expertise, but always cross-check against independent sources.
  • Build diverse investigative teams, including insiders and outsiders, as well as headquarters and field personnel, such as lawyers and auditors.
  • Establish clear escalation protocols when local advice contradicts global standards.

Lesson 4: Monitor for Emerging Risks—What Starts as a Small Threat Can Escalate Rapidly

Illustrated by: Once inside the organism, the Enterprise is quickly overwhelmed.

Investigative Takeaways:

  • Establish early-warning systems for compliance and operational risks.
  • Monitor not just for violations but for near misses, rumors, and signs of stress within the local business.
  • Use “pulse checks”—quick, frequent assessments—to catch emerging issues before they escalate.

Lesson 5: Have an Exit Strategy—Sometimes the Best Move Is to Retreat and Reassess

Illustrated by: As the Enterprise is nearly destroyed, Kirk orders a desperate gambit.

Investigative Takeaways:

  • Continually assess the risk/reward calculus of continuing versus exiting.
  • Prepare senior management for “no-go” recommendations, supported by clear evidence and risk assessments.
  • Document your investigations, findings, and decision rationale thoroughly, especially when choosing to walk away.

Final ComplianceLog Reflections

In every new venture, there is a “zone of darkness.” It is a realm of unknown risks and unexpected threats. The only way to navigate it is through rigorous investigation, humility in the face of uncertainty, and the courage to act, whether that means pushing forward or pulling back.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
GSK in China: 13 Years Later

GSK In China: 13 Years Later – After the Humphreys Verdict: Managing Third-Party Risk When You Can’t Verify

Thirteen years after the GSK China scandal exploded onto the global stage, its lessons remain as urgent as ever for compliance professionals and business leaders. In this podcast series, we revisit the case not simply as corporate history, but as a living cautionary tale about culture, incentives, third parties, investigations, and governance. Each episode explores what went wrong, why it went wrong, and how those failures still echo in today’s compliance and ethics landscape. Join me as we unpack the scandal and draw practical lessons for building stronger, more resilient organizations. In this episode, we take a deep dive into the 2013 GSK China bribery scandal and examine why it remains one of the most important case studies in corporate compliance, governance, and culture. Our hosts are Timothy and Fiona.

The episode examines how multinational companies should manage third-party relationships and compliance in opaque markets like China when traditional intelligence-gathering is curtailed by privacy laws, using the case of corporate investigators Peter Humphreys and his wife Ying Zeng, who were hired by GSK to investigate a sex-tape scandal but were convicted and imprisoned for purchasing Chinese citizens’ personal data. The discussion highlights how the verdict created operational uncertainty for due diligence, M&A, supplier vetting, and anti-bribery efforts, and notes Humphrey’s claim that GSK withheld the fact that it faced internal whistleblower allegations of corruption. Drawing on DOJ expectations and an SCCE framework, it argues for shifting from “vet and forget” to continuous third-party management across five steps, reinforcing business justification, questionnaires, contracts, and ongoing oversight with mitigations like capped commissions, detailed invoice review, early audits, and use of public records and in-person interviews.

Key highlights:

  • Why Verification Matters
  • Privacy Laws Change Everything
  • When Partners Refuse Disclosure
  • Build Your Own Intelligence
  • Contract Controls and Oversight

Resources:

GSK in China: A Game Changer for Compliance on Amazon.com

GSK in China: Anti-Bribery Enforcement Goes Global on Amazon.com

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Ed. Note: the voices of the hosts, Timothy and Fiona, were created by Notebook LM based upon text written by Tom Fox

Categories
31 Days to More Effective Compliance Programs

31 Days to a More Effective Compliance Program: Day 22 – Level of Due Diligence

Welcome to 31 Days to a More Effective Compliance Program. Over this 31-day series in January 2026, Tom Fox will post a key component of a best-practice compliance program each day. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, with three key takeaways that you can implement at little or no cost to help update your compliance program. I hope you will join each day in January for this exploration of best practices in compliance. In today’s Day 22 episode, we consider the levels of due diligence you should use when investigating third parties.

Key highlights:

  • What are the levels of Due Diligence?
  • When is each level appropriate?
  • Key Takeaways

Resources:

Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 6th edition, by clicking here.

Categories
All Things Investigations

All Things Investigations – Navigating Compliance Challenges in Venezuela’s Energy Sector

Welcome to the Hughes Hubbard Anti-Corruption & Internal Investigations Practice Group’s podcast, All Things Investigation. In this podcast, host Tom Fox welcomes back Mike DeBernardis to discuss the implications of entering Venezuela for energy companies and the historical precedents.

They explore the return of US energy companies to the Venezuelan market and historical precedents, such as the Iraq Oil-for-Food Program, post-2003 Iraq, and the 1990s Russian market opening, to identify the risks and the necessary compliance measures. Key insights include the importance of stringent third-party controls, understanding the nuances of dealing with state-owned entities such as PdVSA, and having a robust risk management strategy. The conversation underscores the critical need for compliance professionals to thoroughly understand business operations to build effective compliance programs in high-risk environments.

Key highlights:

  • Challenges and Opportunities in Venezuela
  • Historical Parallels: Iraq Oil for Food Program
  • Lessons from Post-2003 Iraq
  • Comparing Venezuela to 1990s Russia
  • Counseling Clients on High-Risk Opportunities

Resources:

Hughes Hubbard & Reed website

Mike DeBernardis

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Due Diligence

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice for navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we are reviewing the third-party risk management process. Today, we focus on due diligence.

For more on this topic, check out The Compliance Handbook: A Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
FCPA Compliance Report

FCPA Compliance Report – Virna Di Palma on The Evolution of Third-Party Risk Management and the Role of AI

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes Virna di Palma, Head of Global Content and Brand at Ethixbase360.

Virna offers insights into her extensive background in third-party risk management, with a focus on FCPA compliance and the evolution of due diligence. They discuss the ongoing importance of third-party risk management, recent shifts in FCPA enforcement, and the growing impact of new regulations on corporate compliance. Virna highlights the transformative role of automation and AI in enhancing compliance programs while emphasizing the need for human analysis. The conversation also addresses emerging issues, such as modern slavery and sustainability, and explores how organizations can optimize investments in risk management to drive business growth and resilience.

Key highlights:

  • Importance of Third-Party Risk Management
  • Impact of FCPA Enforcement Pause
  • Technological Advancements in Compliance
  • Human Rights and Modern Slavery
  • Future of Third-Party Risk Management

Resources:

Virna Di Palma on LinkedIn

Ethixbase360

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Ricardo Wagner de Araujo on Potential Trouble in your (Latin American) Supply Chain

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Ricardo Wagner de Araujo discusses his panel at the event, “Managing New Risks in Latin America: A Look at the Biggest Ways Cartels/TCOs Are Infiltrating Businesses and Supply Chains, and How Companies Are Responding.”

Some of the issues the panel will discuss are:

    • The changing risks in Latin America.
    • How TCOs and cartels exploit 3rd party relationships.
    • Tips for adapting your compliance programs in Latin America.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Final Thoughts on Pre-Acquisition Due Diligence in M&A

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we conclude our week-long series on pre-acquisition due diligence in M&A from the anti-bribery/anti-corruption perspective.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing Your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Blog

The Price of Ignorance: Five Due Diligence Lessons from Star Trek’s “Elaan of Troyius”

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

For those who have not revisited this classic, the USS Enterprise is assigned a high-stakes diplomatic mission: transport Elaan, the tempestuous Dohlman of Elas, to the planet Troyius, where her arranged marriage will seal a peace treaty between two warring worlds. As tensions flare between Elaan’s culture and that of the Federation, Captain Kirk, Spock, and the crew quickly realize that more than just a wedding is at stake; hidden motivations, subterfuge, and cross-cultural misunderstandings threaten to unravel the entire peace process. What seems a straightforward escort mission rapidly reveals layers of complexity and risk.

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

1. First Impressions Are Deceptive: Always Probe Deeper

Illustrated By: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority. The Federation diplomats are immediately intimidated and distracted by her forceful presence and sharp temperament.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? In “Elaan of Troyius,” Kirk and his crew quickly learn that initial impressions, whether good or bad, can conceal much deeper realities. Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

What should you do now? Do not accept a new partner at face value. Investigate their ownership structure, past conduct, litigation history, financial health, and compliance record. Unmasking the reality behind the reputation is the first step.

2. Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated By: The cultural gap between Elaan and the Federation nearly derails the mission. Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values. The crew is blindsided by these gaps, leading to avoidable conflict.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble. Seemingly minor cultural mismatches can lead to miscommunication, legal violations, or ethical lapses. In cross-border or third-party relationships, this risk is magnified: local customs may hide corrupt practices, labor abuses, or anti-competitive behaviors.

What should you do now? Include cultural and ethical risk assessments as part of your due diligence. Engage local experts, conduct interviews, and be ready to adapt your approach to fit the landscape without compromising your core values.

3. Hidden Agendas and Sabotage: Trust, But Verify

Illustrated By: The mission is sabotaged by Elaan’s retinue, her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses. Kirk is nearly assassinated, and the entire mission teeters on the brink of disaster because no one anticipated internal betrayal.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface. These could take the form of undisclosed beneficial ownership, connections to sanctioned parties, or corrupt insiders. Even a trusted contact within a partner organization can turn out to be a risk factor if not properly vetted. In “Elaan of Troyius,” failure to probe the intentions and backgrounds of all involved parties nearly results in catastrophe.

What should you do now? Conduct background checks not just on the company, but also on key personnel, agents, and ultimate beneficial owners. Use open-source intelligence, watchlists, and external investigators as needed. “Trust, but verify” is not simply good (Ronald Reagan) advice; it is mandatory.

4. Emotional Reactions Cloud Judgment: Stay Objective

Illustrated By: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion. His objectivity and command judgment are compromised at a critical moment, nearly dooming the ship.

Compliance Lesson. Emotional responses, from excitement about a lucrative new market to personal connections with a partner’s leadership, can cloud even the best compliance professional’s judgment. In “Elaan of Troyius,” emotional manipulation nearly brings down the Federation’s flagship. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

What should you do now? Build structured, objective processes for due diligence that minimize the risk of bias. Use checklists, outside counsel, and independent reviews to ensure no one is “drunk on the deal.” Compliance must be immune to infatuation.

5. The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated By: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines. They’re forced into a desperate race against time to fix what could have been prevented.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong. Investigations, regulatory fines, lost business opportunities, and reputational damage are all far more expensive than preventative action. Just as Kirk would rather have found the sabotage before launch, compliance professionals must treat prevention as their first line of defense.

What should you do now? View due diligence as an investment, not a cost. The price of ignorance, missed risks, surprise violations, or regulatory enforcement will always exceed the price of preparedness.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

So, the next time your organization eyes a shiny new partnership, ask yourself: Are we seeing only what we want to see? Or are we committed to the hard work of real due diligence, the only sure path to success, and to a future where both sides prosper?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha