Categories
Blog

Da Vinci Week: Part 5 – Leonardo’s Notebooks and the Defensible Compliance Program

In the first four posts in the Leonardo Compliance Framework, we used Leonardo’s work to explore the compliance disciplines of Refine, Investigate, Innovate, and Monitor.  For our final blog post, the lesson comes not from a single Leonardo masterpiece but from the extraordinary collection of notebooks he created throughout his life. Leonardo recorded observations about anatomy, engineering, mechanics, water, optics, mathematics, architecture, flight, weapons, and the natural world. He drew machines, recorded experiments, posed questions, explored ideas, and returned repeatedly to subjects that interested him.

The compliance lesson goes beyond good note-taking. Leonardo externalized knowledge. He created a record of observations, ideas, questions, and reasoning that otherwise would have existed only in his mind. Modern corporations face a similar challenge. A CCO may understand why a particular control exists. An investigator may remember why an inquiry was expanded. A regional compliance officer may know why a distributor received enhanced scrutiny. An audit committee may understand why management accepted a particular residual risk. An AI governance committee may know why it approved a particular use case with specific limitations.

Then people leave, responsibilities change, businesses are reorganized, and memories fade. The policy remains, but the reasoning disappears. That is why documentation should be viewed as a component of compliance governance rather than simply an administrative obligation.

If It Is Not Documented, the Organization May Not Know It

Compliance professionals know the maxim that if something is not documented, it did not happen. That formulation can be overly simplistic, but it points toward a genuine problem. Organizations often know more than their systems preserve.

Consider a high-risk distributor approved five years ago. The compliance file may contain due diligence reports, certifications, contractual provisions, and an approval. Yet the people involved may have known far more. They may have discussed a government relationship, considered terminating the proposed engagement, obtained additional information, imposed enhanced controls, and ultimately concluded that the residual risk was manageable.

If the file contains only the final approval, a future reviewer may know what the company decided without understanding why. That distinction matters. Good compliance documentation should preserve significant reasoning, not simply outcomes.

This does not mean every routine decision requires a lengthy memorandum. Documentation should remain proportional to risk. A routine low-risk approval may require little explanation. A significant exception involving elevated corruption risk, a senior executive, a sensitive investigation, or a consequential AI application may warrant considerably more.

Risk-based documentation is part of a defensible compliance program.

Documentation Creates Institutional Memory

One of the most significant vulnerabilities in many compliance programs is the concentration of institutional knowledge in particular individuals. Every organization has employees who know why things work the way they do.

A longtime compliance officer remembers why a control was implemented after an investigation. An internal audit executive understands why a particular business unit receives enhanced testing. A finance employee knows why payments to a particular category of third parties require additional approval. An investigator remembers a series of cases that revealed a recurring management problem.

That knowledge has value. A new CCO should be able to understand why major components of the program exist. A new audit committee chair should understand significant unresolved compliance risks. A new investigator should be able to identify relevant historical matters. A new control owner should understand what problem the control was designed to address. Institutional memory should belong to the institution.

Documentation Supports Accountability

Clear documentation also helps answer one of the most important questions in corporate governance: who decided?

Organizations make thousands of decisions involving compliance risk. Most are routine. Some are consequential.

When a significant risk is accepted, the company should be able to identify the person or governance body with authority to accept it.

This is particularly important for exceptions.

If a high-risk third party is approved despite significant red flags, who approved the relationship? If an investigation involving a senior executive is narrowed, who authorized the scope change? If a remediation deadline is extended, who approved the extension and what interim controls are operating? If an AI system is permitted to influence consequential decisions, who approved the use case and under what conditions?

These are governance questions.

Documentation creates a decision trail.

That trail allows management, internal audit, the board, and, when necessary, regulators or enforcement authorities to understand how the organization exercised judgment.

A defensible compliance program does not require perfect decisions. Business decisions involve uncertainty.

It should, however, be able to demonstrate that significant decisions were made through an appropriate process by people with the authority and information necessary to make them.

Remediation Requires Evidence

The Michelangelo series emphasized the difference between closing a project and solving the underlying problem. Leonardo’s notebooks add another dimension: the organization should preserve evidence of what it changed and why.

Suppose an investigation identifies weak approval controls over distributor discounts. Management agrees to remediate the issue by modifying system permissions and requiring additional review.

The compliance record should identify the deficiency, remediation owner, planned corrective action, expected completion date, and evidence required for closure. When management reports that remediation is complete, the record should support that conclusion.

Was the system actually modified? Were users informed? Did testing confirm that the revised control operates as intended? Were similar vulnerabilities evaluated elsewhere? This creates a defensible chain from problem to solution.

Finding → Root Cause → Remediation → Ownership → Validation → Closure

That chain matters to the CCO because it shows compliance findings lead to management action. Internal Audit values it because it supports assurance. It is valuable to the board because it provides evidence that identified risks are being addressed. Documentation converts remediation from a promise into an accountable process.

AI Makes Documentation More Important

Artificial intelligence may make the documentation principle more important than ever in the modern compliance program. AI governance involves decisions that may be difficult to reconstruct after the fact if they are not documented when made.

A company evaluating a significant AI use case should preserve enough information to understand the system’s intended purpose, business owner, risk classification, relevant data, identified risks, testing, required controls, human oversight, approval conditions, and monitoring expectations.

The record should also reflect material changes.

An AI application approved as a low-risk productivity tool may later gain access to sensitive internal data. A vendor may change the underlying model. A system may become integrated into a consequential business process. An application initially used to recommend actions may eventually be authorized to take them. The governance record should evolve with the system.

This matters because AI can complicate traditional assumptions about decision-making. When a human employee makes a decision, organizations generally know who made it. When an AI system influences or takes an action, accountability can become less obvious.

Documentation should prevent that ambiguity from becoming an accountability gap. The company should be able to reconstruct what the system was authorized to do, who approved that authority, what controls applied, and who was responsible for monitoring its operation.

NIST AI RMF and ISO/IEC 42001 both reinforce the broader value of structured governance, risk management, documentation, monitoring, and continuous improvement. For the CCO, the important point is not simply alignment with a framework. It is the ability to demonstrate how the organization governed the technology in practice.

Documentation Should Feed Organizational Learning

Documentation becomes most valuable when the organization uses it. Investigation records can reveal recurring root causes. Exception records can identify controls employees routinely struggle to follow. Third-party approval records can reveal recurring risk patterns. Remediation documentation can show which corrective actions are effective. AI governance records can identify use cases generating repeated incidents or overrides.

The organization can analyze these records to improve the compliance program. This closes the loop between all five Leonardo principles.

  • Documentation captures what monitoring reveals.
  • Monitoring identifies issues requiring investigation.
  • Investigations generate lessons that drive refinement.
  • Refinement can support responsible innovation.
  • Innovation creates new risks that require monitoring and documentation.

The framework is therefore not linear. It is a learning cycle. That is perhaps the most important Leonardo lesson for the modern CCO.

Completing the Leonardo Compliance Framework

With Leonardo’s notebooks, we complete our five-part framework:

Refine-> Investigate-> Innovate-> Monitor-> Document

Together, these principles describe compliance as an organizational learning system. Effective programs learn from experience, investigate failures to understand root causes, support innovation within appropriate governance, monitor whether controls continue to work, and preserve what the organization learns so that knowledge informs future decisions.

The Mona Lisa taught us to Refine. Compliance programs should improve because organizations learn from experience, changing risks, investigations, employee feedback, and data. Leonardo’s anatomical studies taught us to Investigate. Misconduct should be examined beneath the surface so the organization understands root causes, control failures, incentives, management behavior, and systemic vulnerabilities. His flying machines taught us to Innovate. Compliance should help the company capture the value of emerging technology while maintaining risk-based governance, meaningful human oversight, and clear accountability. The Last Supper taught us to Monitor. Controls can deteriorate as the environment changes, making testing, analytics, ownership, remediation, and continuing oversight essential to program effectiveness. Leonardo’s notebooks teach us to Document.

That provides the essential contrast with Michelangelo. His framework of Challenge, Execute, Defend, Build, and Govern taught a CCO how to construct and operate an effective compliance program. Leonardo teaches a CCO how to keep that program learning and adapting. The modern compliance function needs both disciplines because strong controls can become obsolete if the organization fails to recognize changes in its business, technology, and risk environment.

That combination matters even more in 2026. AI is accelerating business change, geopolitical developments can rapidly alter risk, third-party ecosystems continue to expand, and boards need evidence that compliance systems work in practice. The CCO cannot administer yesterday’s compliance program while the business builds tomorrow’s operating model.

Leonardo’s notebooks leave us with a simple compliance mandate: learn from what the organization does, preserve what it learns, and use that knowledge to make the organization better.

Categories
Blog

Netflix Acquisition of Warner Brothers: Part 5 – Post-Merger Integration – Where Compliance Either Succeeds or Fails

When Netflix announced its acquisition of Warner Bros., attention quickly turned to strategic synergies, content pipelines, and market influence. These are important, but they are not where the transaction’s success or failure will ultimately be determined. Deals succeed or fail in post-merger integration. For compliance professionals, this is the crucible. It is the period where two companies attempt to unify processes, cultures, systems, and risk management frameworks while moving at operational speed. When integration falters, compliance failures follow. When integration excels, compliance becomes a stabilizing force that supports the organization during a period of high-velocity change.

Compliance sits at the center of integration because compliance touches everything: governance, culture, systems, third-party relationships, data, reporting lines, training, investigations, and internal controls. It is one of the few functions that spans the entire enterprise. That makes compliance uniquely positioned to guide integration successfully. It also makes compliance uniquely exposed when integration fails.

Today, in our concluding Part 5, we explore why integration is the moment where compliance either rises or falters and what compliance leaders must do to ensure that the post-merger period strengthens rather than destabilizes the combined enterprise.

Day One Through Day Three Hundred: The Critical Window

The first year after closing defines the trajectory of a merger. This window is where employees decide whether leadership is credible, processes are coherent, and the combined organization knows where it is going. It is also the period when the greatest number of decisions must be made quickly and often without perfect information. That is where risk seeps into the cracks.

Compliance must treat integration as an enterprise-wide transformation project. That means establishing a structured roadmap for the first 30, 60, 180, and 300 days. Without this structure, integration becomes reactive rather than strategic. Reactive integration is where compliance failures escalate.

In this period, compliance must monitor employee sentiment, decision-making patterns, escalation pathways, and early deviation from established controls. Whether an organization grows stronger or weaker during integration depends on how quickly compliance identifies deviations and reinforces accountability.

Building a Unified Compliance Architecture

One of the first imperatives of integration is building a unified compliance architecture. Netflix and Warner Bros. bring different compliance footprints. Netflix has a culture that emphasizes transparency, individual accountability, and rapid feedback cycles. Warner Bros. brings decades of risk controls shaped by studio operations, talent relationships, union agreements, and global production infrastructure.

A unified architecture requires more than merging documents or standardizing policies. It requires understanding where each legacy system is strong, where it is vulnerable, and where alignment creates new risk.

Compliance leaders must establish:

  • A consolidated Code of Conduct.
  • A harmonized policy library.
  • Unified reporting channels.
  • Shared investigative procedures.
  • Enterprise-wide risk assessment methodologies.
  • Coherent training programs.

These components cannot be written. They must be communicated, taught, operationalized, and reinforced. Employees must understand not only what the policies say but also why they matter in the new organization.

Rationalizing Reporting Lines and Escalation Pathways

Mergers create confusion. Employees do not always know whom to contact, how to escalate concerns, or whether the people they previously relied on still have authority. That ambiguity is an enormous compliance risk.

Compliance leaders must create clarity early:

  • Who receives concerns?
  • How are investigations assigned?
  • What are the escalation criteria?
  • What timelines apply to decision-making?
  • How will employees receive feedback on issues they raise?

This clarity is not a luxury. It is a control. Without defined reporting pathways, concerns go unreported or unresolved. Both outcomes expose the business to avoidable harm.

Technology Integration: Where Risk Hides in Plain Sight

Technology integration is one of the most underestimated compliance risks. During a merger, companies aim to integrate systems spanning HR and payroll, content management, production workflows, distribution platforms, data governance, and internal controls.

Compliance must ensure that:

  • Data mapping is accurate.
  • Privacy rules are harmonized.
  • Access rights reflect new reporting structures.
  • Legacy systems are retired responsibly.
  • Audit trails are preserved, and
  • System changes do not inadvertently lower control effectiveness

Technology teams often focus on functionality and speed. Compliance must focus on integrity and accountability. Without disciplined oversight, integrations can create gaps or duplications that allow misconduct, data loss, or process failures to occur undetected.

Third-Party Integration: The Often Forgotten Battlefield

Netflix and Warner Bros. maintain extensive third-party ecosystems: production companies, talent agencies, global distributors, technology vendors, marketing partners, and international subsidiaries. Each third-party relationship carries risk. During a merger, that risk is magnified because:

  • Contract ownership may be ambiguous.
  • Oversight structures may change.
  • Legacy due diligence may be incomplete.
  • Vendor performance may deteriorate, and
  • New conflicts of interest may emerge.

Compliance must therefore implement a unified third-party risk management framework that includes:

  • Centralized onboarding and risk ranking;
  • Revised due diligence standards.
  • Contract alignment with the new Code of Conduct;
  • Clear monitoring obligations; and
  • Documented remediation protocols

An ungoverned third-party ecosystem is one of the most common sources of post-merger compliance failures.

The Cultural Dimension: The Invisible Integrator or Divider

Culture is the single greatest determinant of whether integration strengthens or weakens the enterprise. Netflix’s culture of candor and Warner Bros’ culture of tradition do not naturally conflict, but they do require careful alignment. Compliance must monitor cultural friction closely:

  • Decreased willingness to speak up
  • Divergent interpretations of policies
  • Informal workarounds
  • Turnover spikes in key departments
  • Erosion of decision transparency

Culture determines whether employees trust the compliance function, adhere to policies, and promptly escalate concerns. If cultural alignment is not prioritized, controls weaken regardless of the sophistication of the compliance architecture.

Documentation: The Foundation of Regulatory Credibility

Regulators expect visibility during integration. They expect companies to demonstrate that decisions were documented, risks were assessed, concerns were escalated, and oversight was effective.

Compliance must preserve:

  • Integration plans
  • Meeting notes
  • Risk assessments
  • Policy revisions
  • Training materials
  • Incident logs
  • Decision memos

Documentation is not bureaucratic. It is evidence. It demonstrates that the company fulfilled its obligations and that compliance was central to the integration process.

The Compliance Lesson

Integration is not an administrative exercise. It is a risk multiplier. It is also the moment when compliance can demonstrate its value most clearly. The Netflix acquisition of Warner Bros. offers an unmistakable reminder: strategic ambition means nothing if integration is weak. Compliance must lead with clarity, discipline, and foresight.

Where integration is intentional, guided, and well governed, compliance becomes a competitive asset. It stabilizes the organization, protects employees, and supports leadership during a period of profound change. Where integration is fragmented, rushed, or ignored, compliance fails. It fails not because of a lack of knowledge but because of a lack of structure.

For compliance professionals, this final lesson is the most important: the acquisition may create opportunity, but integration determines destiny.

Categories
Adventures in Compliance

Adventures in Compliance: The Novels – A Study in Scarlet, Dr. Watson

In this new season of Adventures in Compliance, host Tom Fox will dive deep into the Sherlock Holmes novels. Over this season, Tom will do so in a four-part series. The four novels we will consider from the ethics and compliance perspective are A Study in Scarlet, The Sign of Four, The Hound of the Baskervilles, and The Valley of Fear.

We begin with A Study in Scarlet for our first offering this new season. In Part 2, Tom will take a deep dive into Dr. Watson, how he and Holmes met, and Watson’s contributions to their partnership and consider Watson’s professional training as a doctor, his war services and injuries during the Second Anglo-Afghan War, and his return to England, all leading to his initial introduction to Holmes by their mutual acquaintance Stamford. Watson’s involvement in the case helps Holmes move beyond isolated brilliance to true investigative mastery. In compliance, pairing sharp analytic talent with professionals rooted in operational or practical experience often yields the strongest compliance strategies.

Highlights include:

  • Diversified Skill Sets
  • Trust Encourages Innovation
  • Objective Feedback Sharpens Analysis
  • Emotional Intelligence Deepens Understanding
  • Structured Communication Improves Decision-Making

Resources:

The New Annotated Sherlock Holmes

Sherlock Holmes FAQ by Dave Thompson

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
FCPA Compliance Report

FCPA Compliance Report: Adrienne Bellehumeur on Design – Centric Approaches to Internal Controls

Welcome to the award-winning FCPA Compliance Report, the longest running podcast in compliance.

In this edition of the FCPA Compliance Report, Tom Fox welcomes back Adrienne Bellehumeur, a chartered accountant and expert in internal controls and documentation.

Adrienne discusses her recent article on design-centric internal control and emphasizes the importance of focusing on design as the foundation for effective control programs. She outlines five key principles for improving control design and details her approach to challenging processes and governance systems. The conversation also touches on the necessity of continuously updating controls to adapt to evolving business and regulatory environments.

Adrienne shares tips on fostering better design through workshops, effective interviewing, and continuous improvement, while also addressing new developments such as AI and ESG. The episode finishes with insights into how internal controls can support whistleblower programs and the importance of back-to-basics documentation and information management.

Highlights in this Episode:

  • Professional Background
  • Design-Centric Approach to Internal Controls
  • Challenges and Importance of Good Design
  • Principles for Improving Control Design
  • Back to Basics: Adapting to New Business Developments
  • Whistleblower Programs and Internal Controls

 Resources:

Adrienne Bellehumeur on LinkedIn

Risk Oversight

New Approaches to Control Design

Tom Fox

Instagram

Facebook

YouTube