Categories
Blog

From Gatekeeper to Navigator: Dr. Hemma Lomax on the Decision Intelligence Gap

Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.

Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.

That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.

A Book About the Decisions Before the Decision

Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.

The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.

Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.

Why Compliance Leaders Should Read It

The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.

Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.

Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.

This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.

Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.

The Most Useful Tool: HQDM

The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.

For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.

The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.

Where the Book Requires Compliance Translation

The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.

The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.

AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.

The Verdict

This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.

CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.

Questions for CCOs and Boards

Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?

Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?

Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?

Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?

Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?

Categories
Blog

Mudd’s Women: Illusions of Consent and the Ethics of Exploitation

In this eye-opening blog post of Trekking Through Compliance, we examine Mudd’s Women, one of the earliest and most ethically provocative episodes of Star Trek. While Harcourt Fenton Mudd provides his usual comic bluster, the underlying story is a disturbing metaphor for human trafficking. The three women he transports appear glamorous, but they are victims of manipulation, economic coercion, and chemical dependency, all tactics that mirror modern trafficking schemes.

I review the key compliance lessons by breaking down how this episode reflects red flags in trafficking risk. From the illusion of choice to abusive power dynamics and the responsibility of organizations to prevent exploitation in their supply chains, Mudd’s Women provides a surprisingly timely framework for modern compliance professionals.

Key Highlights and Human Trafficking Case Illustrations

1. Illusion of Consent—When “Choice” is Conditioned by Coercion

Illustrated by: The women believing they must take the Venus drug to be desirable and accepted.

The women in this episode appear to be making choices, but those choices are shaped by manipulation, desperation, and dependency. The Venus drug becomes a stand-in for traffickers’ tools: debt bondage, false promises, or immigration threats. Compliance officers must recognize that surface-level consent does not equal genuine autonomy when coercion lurks beneath.

2. Economic Exploitation—Vulnerability Creates Risk

Illustrated by: The miners’ willingness to trade vital resources for the women, commodifying human beings.

The deal Mudd brokers—exchanging women for lithium crystals—lays bare the dynamics of commodification. In today’s terms, this is a form of transactional trafficking. Vulnerable individuals are offered to influential economic players in exchange for profit. Companies operating in high-risk jurisdictions or industries must vet third-party recruiters and labor brokers with exceptional diligence

3. Deception and Misrepresentation—The Role of Fraud in Trafficking 

Illustrated by: Mudd’s concealment of the Venus drug and misrepresentation of the women’s condition to both the women and the miners.

Human trafficking often begins with lies. Whether it’s a promise of employment, education, or escape, traffickers rely on fraud to lure victims. Mudd’s entire operation is built on deceit. A strong compliance program includes rigorous due diligence processes to detect falsified credentials, labor contract inconsistencies, and red flags in vendor onboarding.

4. Victim Support and Recognition—Beyond Enforcement to Empathy

Illustrated by: Kirk’s ultimate compassion toward Evie and her rediscovery of her inner strength without the drug.

While the episode ends with Mudd in custody, the more powerful moment is Evie realizing her self-worth independent of manipulation. This reflects a crucial compliance principle: anti-trafficking programs must prioritize survivor-centered support. This entails creating ethical exit strategies, ensuring access to justice and care, and cultivating environments where individuals are not reliant on exploitative systems to survive.

5. The Responsibility to Intervene—Compliance Can’t Be a Bystander 

Illustrated by: Kirk’s decision to arrest Mudd and expose the drug deception despite the miners’ interest in continuing the transaction.

Kirk could have turned a blind eye, but he doesn’t. This is the model for corporate action: when exploitation is found, the response must be swift and straightforward. Compliance programs must include escalation pathways and partnerships with law enforcement and NGOs to act decisively when trafficking risks emerge.

Final ComplianceLog Reflections

Mudd’s Women may begin with lighthearted charm, but it ends with one of the most haunting portraits of exploitation in Star Trek. Beneath the fantasy is a cautionary tale of deception, dependency, and commodification, the core ingredients of human trafficking today. For compliance professionals, this episode serves as a call to action: look deeper, build proactive detection systems, and empower vulnerable individuals throughout your value chain.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Great Women in Compliance

Great Women in Compliance: Why Decision Rubrics Matter in the Age of AI with Hemma Lomax and Shalini Rajoo

In this conversation, GWIC host Dr. Hemma R. Lomax and Shalini Rajoo explore the critical role of decision rubrics in governance, accountability, and trust, especially in the context of AI. Shalini shares her journey from law to compliance, emphasizing the importance of understanding systems and the impact of leadership on decision-making processes. They discuss how transparency and clarity in decision-making can build trust within organizations and the necessity of responsible AI governance. Practical tips for improving decision quality are also provided, highlighting the importance of self-awareness and critical thinking in leadership.

Takeaways:

  • The biggest risk in governance is unclear decisions.
  • AI amplifies existing clarity or confusion in decision-making.
  • Systems and rules reflect the identities of their architects.
  • Everyone has an impact on those around them every day.
  • Leadership is about improving the people around you.
  • It’s not just about rules; it’s about how people behave.
  • Decision rubrics provide consistency and predictability in outcomes.
  • Transparency in decision-making processes builds trust.
  • Slowing down to ask questions can lead to better decision-making.
  • Writing down the reasons for decisions brings clarity and accountability.

Sound bites:

“Systems and rules are not inherently neutral.”

“Transparency in decision making builds trust.”

“Slow is smooth, and smooth is fast.”

Chapters:

00:00 Introduction to Decision Rubrics and Governance

02:55 Shalini’s Journey: From Law to Governance

06:09 The Impact of Systems on Leadership and Accountability

09:09 Transitioning to Compliance and Ethics

11:49 Understanding Decision Rubrics in Compliance

15:06 The Role of Leadership in Decision Making

18:03 Designing Conditions for Effective Decision Making

20:47 The Importance of Transparency in Decision Processes

24:09 Decision Rubrics: Building Trust in Organizations

26:49 AI and Governance: Leadership Infrastructure Failures

29:47 Responsible AI: The Role of Ethics and Compliance

32:55 Practical Tips for Improving Decision Quality

36:00 Conclusion: The Future of Decision Making in AI

Guest Biography:

Shalini Rajoo is the Founder and Principal Consultant of Shalini Rajoo Advisory, LLC, where she partners with organizations to design governance, compliance, and decision-making systems that are resilient, trustworthy, and aligned to real operational pressures. Across more than two decades in law, compliance, HR, and organizational leadership, Shalini has helped companies and leaders move beyond check-the-box frameworks to build structures that embed accountability, clarity, and performance into everyday decisions.

She began her career in South Africa, first as a public prosecutor and then leading regulatory work with the Department of Trade and Industry, collaborating with legislative and executive stakeholders on corporate, competition, and consumer law. After relocating to the U.S., Shalini practiced commercial litigation. She later served as Director of Global Business Conduct for a Fortune 500 company, where she redesigned ethics and compliance systems, led global risk assessments, and championed psychological safety and integrity-based practices.

Today, Shalini’s work centers on helping leaders clarify decision rights, governance architectures, and accountability pathways — especially as organizations adopt AI and automation. She recently spoke at the Opal Group’s Corporate Governance & Ethics in the Age of AI conference, where she reframed AI governance as a leadership-infrastructure challenge rather than a purely technical or compliance one.

Categories
Blog

Note Navy Seals Way: Moving from Continuous Monitoring to Continuous Improvement

Decision making is a critical skill for any Chief Compliance Officer (CCO) or compliance professional. Continuous monitoring and continuous improvement are now accepted as standard components of any table stakes compliance program. The Department of Justice (DOJ), in the 2020 Update to the Evaluation of Corporate Compliance Programs, made clear the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the applicable industry standards. Accordingly, prosecutors should consider whether the company has engaged in meaningful efforts to review its compliance program and ensure that it is not stale.”

Indeed, the 2020 Update posed the following questions that the DOJ might ask a company under a Foreign Corrupt Practices Act (FCPA) investigation, “How often has the company updated its risk assessments and reviewed its compliance policies, procedures, and practices? Has the company undertaken a gap analysis to determine if particular areas of risk are not sufficiently addressed in its policies, controls, or training? What steps has the company taken to determine whether policies/procedures/practices make sense for particular business segments/subsidiaries? Does the company review and adapt its compliance program based upon lessons learned from its own misconduct and/or that of other companies facing similar risks?”But one question not posed is around your decision-making process in when to move from continuous monitoring to continuous improvement. I was therefore interested in a recent FastCompany.com article, entitled “3 Steps Navy SEALs Use to Make Decisions”, by Stephanie Vozza. Vozza quotes former Navy SEAL and Chief Executive Officer (CEO) of ADS, Inc., Ryan Angold who said, “With so much information out there, a lot of people get analysis paralysis. You want to do your research and you want to access all the resources you have so you can make the right decision. But you can’t sit in analysis paralysis forever. Ultimately, there’s no 100% perfect decision.”

For her piece she also interviewed former Navy and current VMWare Chief Digital Transformation Officer Mike Hayes and author of the book, Never Enough: A Navy SEAL Commander on Living a Life of Excellence, Agility, and Meaning, who laid out a framework he used as an active SEAL for decision making.

  1. Gather Input

When you are a CCO or compliance professional in a corporate compliance function, you most probably have created experiences from which you can draw. Angold noted, “The requirement in SEAL teams is that you have you’ve gone through multiple different scenarios, you’ve trained for the most extreme environment, the most challenging environment, the worst-case scenarios. These reference points are helpful. You can say, ‘Okay, we’ve seen something like this before.’ Maybe this isn’t the exact scenario—it never is. But you’ve learned how the team works and can make quick decisions.”

Both Jonathan’s from the award-winning Everything Compliance gang, Jonathan Armstrong and Jonathan Marks, talk about not simply crisis and scenario planning but practice as well. Such practice not only gives you the muscle memory of what to do when a true crisis appears but also provide the types of experiences that Angold references that the SEALs then use in missions.

Hayes added that you should listen to difference voices or inputs, noting, “Too often, we tend to seek out like-minded input. Artists tend to hire artists and engineers hire engineers. By getting input from people who don’t think like us and by having a culture that celebrates differences and raising other ideas, you help people be comfortable saying things like, ‘Hey, sir, I don’t think that’s a great idea. Here’s how I would do it.’ That framework enables the best possible decisions.” Note that Hayes’ remarks also illuminate the importance and benefits of a true “Speak-Up Culture”.

  1. Decide When to Decide

 Most interestingly, the first thing you have to determine is when to make your decision. Hayes said, “The first decision is when to make your decision. That’s the thing that most people get wrong.” Obviously in combat your decision-making window can be quite short, but the same principle applies in the corporate world. Here Hayes noted, “At some point, the value of those extra inputs in your input streams costs more than the time associated with getting more inputs. At that inflection point is when you want to make your decision. You start losing value by waiting longer.”

But this point is where experience can become more paramount. In the corporate compliance world, you will likely get information, which is both quantitative and qualitative, particularly through continuous monitoring. Do not become paralyzed at this point, and you can rely on your gut or, as Hayes said, “there are other times where you need to operate in instinct. Instinct is really a set of experiences that you can’t quite crystallize, but that you extract logic from.”

  1. Be Willing (and ready) to Course Correct

Here a key CCO and compliance professional soft skill, that of humility, both “intellectual and real will help you get to the right decision.” Do not let your ego get in the way or start considering your sunk costs. You may garner new information which gives new input. Even John Maynard Keynes said, “When my information changes, I alter my conclusions. What do you do, sir?

Hayes said this is “the ultimate sign of leadership because it’s a sign of comfort in your own skin and not needing to look good in front of an organization. Instead, you’re putting the organization before self and doing the right thing.” Angold phrased it as “It takes a lot of humility for someone to be able to recognize it was the wrong call,” he says. “That’s where the communication is important and having that transparency with your team. You can gain a lot of additional trust from your team, when you acknowledge a wrong decision.”

Continuous improvement through continuous monitoring or other similar techniques will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is in many ways a continuously evolving organism, just as your company is. You need to build in a way to keep pace with both market and regulatory changes to have a truly effective anti-corruption compliance program. By using this three-step approach, you can best determine how to move from the monitoring to the improvement phase.