Categories
Innovation in Compliance

Innovation in Compliance: Clarence Chio on Rethinking Third-Party Due Diligence in the Age of AI

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with Clarence Chio, co-founder and CEO of Coverbase, about modernizing third-party risk management as AI reshapes vendor due diligence.

Chio describes how traditional onboarding relies on long questionnaires, SOC 2/ISO documentation, and trust centers that streamline document exchange but were built for human-driven workflows. He argues AI makes the process risky and increasingly meaningless because vendors can auto-complete questionnaires convincingly and customers can analyze them with AI, eroding the value of nuance and attestation. Chio contrasts static, point-in-time evidence with the need for dynamic, continuous security evidence, noting software changes faster than annual assessments and third-party software frequently appears in breach chains. He proposes moving from check-the-box questionnaires to first-principles risk validation, including continuous information sharing, deeper technical evidence, and machine-readable artifacts such as SBOMs. He highlights Coverbase’s open-source Trust MCP, which provides scoped, standardized access to verified vendor evidence for an agent-driven future.

Key highlights:

  • Why Coverbase Exists
  • Trust Centers Explained
  • AI Makes Due Diligence Risky
  • Attestation and Human Loop
  • Static vs. Dynamic Evidence
  • Machine-Readable Trust Future

Resources:

Coverbase

Clarence Chio on LinkedIn

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Blog

Third-Party Due Diligence: 5 Lessons from Star Trek’s The Mark of Gideon

In the modern compliance landscape, third-party due diligence is not optional but essential. Regulators from the DOJ to the SFO have made it clear: if your business partner is involved in misconduct, you are on the hook if you did not take reasonable steps to know who you were dealing with.

Few pop culture moments capture the risks of blind engagement as vividly as Star Trek: The Original Series’ “The Mark of Gideon.” In this episode, Captain Kirk beams down to what he believes is the planet Gideon for diplomatic talks—only to find himself aboard what appears to be an empty Enterprise. What follows is a masterclass in the dangers of walking into a deal without verifying the facts. For compliance professionals, Gideon’s deception is the perfect allegory for the hazards of onboarding a third party without a thorough vetting process. Let’s break down five key lessons.

Lesson 1: Verify the True Identity of Your Counterparty

Illustrated by: When Kirk believes he is beamed down to Gideon, he is actually inside a replica of the Enterprise. The Gideonites have created this fake environment to isolate him for their purposes.

Compliance Lesson. If you do not confirm the true identity of a third party, you may find yourself dealing with a façade. Shell companies, undisclosed beneficial owners, and entities with misleading corporate registrations are the corporate world’s “empty Enterprise.”Always confirm a third party’s corporate existence and ownership through independent sources. This means checking official registries, using reliable due diligence databases, and, when needed, engaging investigative firms to trace beneficial ownership. Without these checks, you risk contracting with a front for illicit activity.

Lesson 2: Understand the Real Motives Behind the Partnership

Illustrated by: The Gideonites’ true purpose is not peaceful diplomacy; instead, they want to infect their overpopulated planet with a deadly virus carried by Kirk. They present their plan as a noble solution to their problem, but it’s built on deception and exploitation.

Compliance Lesson. Third parties sometimes have agendas that differ sharply from what they present. They may seek access to your brand to legitimize questionable practices, gain entry to restricted markets, or launder illicit funds. Beyond standard questionnaires, compliance teams should assess the commercial rationale for the relationship. Why do they want to work with you? Who else do they do business with? Are their financials consistent with the scale of the deal? If their motives don’t align with your values and compliance commitments, that is a red flag.

Lesson 3: Never Rely Solely on What the Other Party Tells You

Illustrated by: Kirk repeatedly asks the Gideonites to explain what is happening, but their answers are vague, evasive, and occasionally contradictory. They hope his lack of information will keep him compliant long enough to serve their plan.

Compliance Lesson. Self-reported information from a potential third party should be viewed as one data point, not the whole picture. Misrepresentations are common, whether deliberate or due to internal ignorance. Cross-verify all claims with independent checks, customer references, industry reputation research, litigation and sanctions screening, and on-site visits when possible. If the only source for a claim is the counterparty itself, your risk exposure rises dramatically.

Lesson 4: Assess the Operating Environment Before Engagement

Illustrated by: The Gideonites hide the actual conditions on their planet. Kirk learns later that Gideon is overcrowded to the point of people standing shoulder-to-shoulder, unable to move freely. Had this been disclosed, he would have understood the real risks before arriving.

Compliance Lesson. A third party’s operating environment, political stability, corruption levels, and regulatory enforcement directly affect your compliance risk. Entering into a business relationship without assessing this environment is akin to beaming down blind. Incorporate country risk analysis into your process. Use resources like Transparency International’s Corruption Perceptions Index, U.S. State Department human rights reports, and local legal counsel. An otherwise legitimate partner in a high-risk jurisdiction requires enhanced due diligence and monitoring.

Lesson 5: Build Exit Strategies Into the Relationship

Illustrated by: Once Kirk understands the Gideonites’ true intentions, he must escape the replica Enterprise to stop their plan. Without a clear route back to his crew, he risks being trapped indefinitely.

Compliance Lesson. Some third-party relationships turn sour despite your best due diligence efforts. Whether due to leadership changes, shifts in political conditions, or the surfacing of previously hidden misconduct, you need a plan to disengage without disrupting your operations. Include termination clauses tied to compliance breaches in your contracts. Maintain operational flexibility so you can pivot to alternate suppliers or partners if needed. Regularly re-screen third parties to ensure ongoing compliance, not just a one-time check at onboarding.

Final ComplianceLog Reflections

In The Mark of Gideon, the Enterprise crew’s lack of verified intelligence before Kirk’s “beam down” mirrors what happens when companies rush into a third-party relationship to seize a perceived opportunity. The Gideonites knew how to manipulate the Federation’s diplomatic eagerness. Likewise, unscrupulous partners today exploit companies’ urgency to enter new markets or secure rare supply chains.

The lesson? Due diligence is not a delay; it is a safeguard. The few extra weeks spent vetting a partner can prevent years of litigation, regulatory penalties, and reputational damage.

The Mark of Gideon” is not just a quirky Star Trek morality tale. It is a warning for every compliance professional. Without thorough third-party due diligence, you risk waking up in a corporate “replica Enterprise,” surrounded by partners whose true motives only become clear when it’s too late.

Your job as a compliance officer is to ensure the company doesn’t act blindly. By verifying identities, probing motives, cross-checking information, assessing environments, and building exit strategies, you safeguard your organization’s reputation and operational integrity. In short: trust, but verify, especially when the other side is as smooth-talking as the people of Gideon.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 71 – Beaming Down Blind: Compliance Lessons on Third-Party Due Diligence from “The Mark of Gideon”

Few pop culture moments capture the risks of blind engagement as vividly as Star Trek: The Original Series’ “The Mark of Gideon.” In this episode, Captain Kirk beams down to what he believes is the planet Gideon for diplomatic talks—only to find himself aboard what appears to be an empty Enterprise. What follows is a masterclass in the dangers of walking into a deal without verifying the facts. For compliance professionals, Gideon’s deception is the perfect allegory for the hazards of onboarding a third party without a thorough vetting process. Let’s break down five key lessons.

Lesson 1: Verify the True Identity of Your Counterparty

Illustrated by: When Kirk believes he is beamed down to Gideon, he is actually inside a replica of the Enterprise. The Gideonites have created this fake environment to isolate him for their purposes.

Compliance Lesson. If you do not confirm the true identity of a third party, you may find yourself dealing with a façade. Shell companies, undisclosed beneficial owners, and entities with misleading corporate registrations are the corporate world’s “empty Enterprise.”

Lesson 2: Understand the Real Motives Behind the Partnership

Illustrated by: The Gideonites present their plan as a noble solution to their problem, but it’s built on deception and exploitation.

Compliance Lesson. Third parties sometimes have agendas that differ sharply from what they present. They may seek access to your brand to legitimize questionable practices, gain entry to restricted markets, or launder illicit funds.

Lesson 3: Never Rely Solely on What the Other Party Tells You

Illustrated by: Kirk repeatedly asks the Gideonites to explain what is happening, but their answers are vague, evasive, and occasionally contradictory. They hope his lack of information will keep him compliant long enough to serve their plan.

Compliance Lesson. Self-reported information from a potential third party should be viewed as one data point, not the whole picture. Misrepresentations are common, whether deliberate or due to internal ignorance.

Lesson 4: Assess the Operating Environment Before Engagement

Illustrated by: The Gideonites hide the actual conditions on their planet. Kirk learns later that Gideon is overcrowded to the point of people standing shoulder-to-shoulder, unable to move freely.

Compliance Lesson. Entering into a business relationship without assessing this environment is akin to beaming down blind.

Lesson 5: Build Exit Strategies Into the Relationship

Illustrated by: Once Kirk understands the Gideonites’ true intentions, he must escape the replica Enterprise to stop their plan.

Compliance Lesson. Some third-party relationships turn sour, and you need a plan to disengage without disrupting your operations. Include termination clauses tied to compliance breaches in your contracts.

Final ComplianceLog Reflections

In The Mark of Gideon, the Enterprise crew’s lack of verified intelligence before Kirk’s “beam down” mirrors what happens when companies rush into a third-party relationship to seize a perceived opportunity. The Gideonites knew how to manipulate the Federation’s diplomatic eagerness. Likewise, unscrupulous partners today exploit companies’ urgency to enter new markets or secure rare supply chains.

The lesson? Due diligence is not a delay; it is a safeguard. The few extra weeks spent vetting a partner can prevent years of litigation, regulatory penalties, and reputational damage.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 68 – The Dangers of Assumption: How “Elaan of Troyius” Proves Due Diligence Is Essential

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

Lesson 1: First Impressions Are Deceptive: Always Probe Deeper

Illustrated by: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

Lesson 2: Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated by: Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble.

Lesson 3: Hidden Agendas and Sabotage: Trust, But Verify

Illustrated by: The mission is sabotaged by Elaan’s retinue; her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface.

Lesson 4: Emotional Reactions Cloud Judgment: Stay Objective

Illustrated by: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion.

Compliance Lesson. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

Lesson 5: The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated by: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice

Categories
Blog

When Time Accelerates: Five M&A Lessons from Star Trek’s “Wink of an Eye”

Today, we’re setting our sensors on one of Star Trek: The Original Series’ most thought-provoking episodes—“Wink of an Eye.” While this story may not feature the grand courtrooms or battlefields you might expect for compliance lessons, it’s a goldmine for any compliance officer, in-house counsel, or business leader navigating the perilous and rapidly accelerating world of mergers and acquisitions.

For those unfamiliar with the episode, “Wink of an Eye” finds the crew of the USS Enterprise responding to a distress call from the planet Scalos. But as soon as they beam down, most of the away team seem to vanish—or so it appears. In reality, the Scalosians exist in a hyper-accelerated state, moving so quickly that to the Enterprise crew, they’re invisible. Before long, Captain Kirk is forcibly accelerated to join them and quickly discovers the perils of operating at different speeds, hidden agendas, and the catastrophic results of unchecked assumptions.

Sound familiar? In the world of M&A, deals can go from zero to warp speed in the blink of an eye, and those left operating in “normal” time often find themselves blindsided by risks, unseen motives, and cultural misalignments. Today, we use the lens of “Wink of an Eye” to explore five critical M&A lessons for today’s compliance professional.

Lesson 1: Beware the Dangers of Unseen Agendas

Illustrated by: The Enterprise crew responds to a distress signal, only to find an abandoned city. In truth, the Scalosians are present but moving too fast to be detected, observing, manipulating, and acting without the crew’s awareness.

Compliance M&A Lesson. In every M&A transaction, some risks and agendas may not be immediately visible. Target companies may appear transparent, but unseen issues, ranging from latent liabilities to regulatory exposures or even toxic cultures, can operate just out of sight. Compliance professionals must be vigilant for “hyper-accelerated” problems: sudden regulatory changes, emerging enforcement risks, or compliance gaps that could metastasize after closing.

What should you do now? Never assume what you can’t see can’t hurt you. Invest in robust, multilayered due diligence. Do not rely solely on surface-level representations. Engage with local counsel, scrutinize whistleblower hotlines, and dig deep for signs of hidden trouble.

Lesson 2: Speed Kills—Or at Least, Blindsides

Illustrated by: Captain Kirk and his crew are thrust into a reality where the Scalosians’ actions occur at warp speed. The Scalosians manipulate the ship’s systems, jeopardizing the Enterprise, all before the crew can respond.

Compliance M&A Lesson. Pressure to “get the deal done” quickly is endemic in today’s market. Boardroom bravado, aggressive timelines, or fear of losing out to a competitor can push compliance to the back burner. But as the Enterprise learned, speed without visibility or controls can spell disaster. When critical steps are skipped or rushed, whether in compliance, due diligence, or integration planning, the seeds for future crises are sown.

What should you do now? Fight the tyranny of the urgent. If deal velocity is forced, demand appropriate pauses for compliance risk assessment. Build “speed bumps” into the process: no sign-off until compliance and legal due diligence are complete, and clear escalation paths for unresolved red flags.

Lesson 3: Cultural Misalignment Can Doom Even the Smartest Teams

Illustrated by: Kirk, once accelerated, finds himself isolated, unable to communicate or coordinate with his crew, who remain “out of phase.” The gulf between realities leads to mistrust, confusion, and near-catastrophe.

Compliance M&A Lesson. One of the most underestimated risks in any deal is cultural misalignment. Whether it’s differences in compliance cultures, attitudes toward regulation, or simply management style, these differences are often invisible until they aren’t. Like Kirk trying to bridge the gap between two timelines, post-deal integration can become a chaotic, error-prone process if cultural divides aren’t acknowledged and addressed.

What should you do now? Assess and plan for cultural integration from Day One. Compliance must have a seat at the table, not just for “hard” issues like controls and policies, but for the “soft” issues that often determine long-term success. Early joint training, culture assessments, and leadership buy-in are vital.

Lesson 4: Technology—Friend, Foe, or Trojan Horse?

Illustrated by: The Scalosians secretly tamper with the Enterprise’s environmental systems, seeking to convert the crew and ship to their needs. Their subtle manipulations are initially undetectable, nearly leading to disaster.

Compliance M&A Lesson. Every acquisition brings a technology integration challenge and, with it, a potential compliance nightmare. Legacy systems may be vulnerable, riddled with security holes, or subject to data localization rules you never anticipated. “Plug and play” is rarely plug-and-play. Worse, legacy tech can act as a “Trojan Horse,” hiding systemic weaknesses, cyber risk, or even evidence of past misconduct.

What should you do now? Demand comprehensive IT and data risk assessments before closing. Ensure data mapping is part of due diligence. Post-acquisition, prioritize integration of compliance tech solutions, hotlines, monitoring tools, and incident management platforms to avoid inheriting someone else’s problems.

Lesson 5: Communication Is the Antidote to Chaos

Illustrated by: As chaos mounts, Kirk finds creative ways to bridge the communication divide—leaving clues and working with Spock to slow himself down, eventually restoring balance to the ship.

Compliance M&A Lesson. All too often, compliance is left out of critical conversations during a deal or brought in too late, when the train has already left the station. Information silos, unclear chains of command, or poor stakeholder engagement leave gaps where risk thrives. Success in M&A is measured not just in legal agreements but in the effectiveness of communication between all parties before, during, and after the deal.

What should you do now? Champion open, continuous communication throughout the deal lifecycle. Establish clear escalation channels. Engage early and often with all stakeholders—from executive leadership to local compliance officers at the target entity. After closing, maintain the cadence: town halls, FAQs, and feedback loops can help manage uncertainty and set expectations.

Final ComplianceLog Reflections

“Wink of an Eye” is more than a sci-fi tale of hyper-acceleration and hidden threats. It’s a vivid parable for compliance officers tasked with shepherding organizations through the labyrinth of mergers and acquisitions. When the pace picks up and risks move faster than you can see, it’s easy to lose sight of the fundamentals. But as Star Trek teaches us, it’s precisely at these moments that discipline, vigilance, and creativity matter most.

In the ever-accelerating world of M&A, compliance is the brake that allows your ship to arrive safely, whatever the speed of your journey. So, the next time your organization beams into a new deal, ask yourself: Are you seeing the whole picture or missing the real action because it’s moving at the speed of a wink?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 55 – Out of Time: Due Diligence Lessons from ‘Assignment: Earth

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners all come with their backgrounds and histories.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is but what they are capable of and what they plan to do with that capability.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyber-attacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences?

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Fiona is an AI-generated voice

Categories
Blog

What Gary Seven and Assignment Earth Teach Us About Due Diligence

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

With its spy-fi trappings, high-stakes secrets, and moral ambiguity, “Assignment: Earth” is a goldmine for compliance professionals seeking fresh insights into what robust due diligence truly requires. Today, we beam down and explore five timeless lessons from this episode, each rooted in a scene that every compliance leader should remember the next time a critical business decision looms.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew. Spock’s scans confirm some aspects, but other elements remain mysterious. Kirk is forced to weigh trust against hard evidence, deciding that until Seven’s story is verified, he must remain under close observation.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners each have their own backgrounds and histories. “Assignment: Earth” illustrates the risks of acting on assumptions or charm; as the Enterprise crew learns, even the most convincing story requires verification. For compliance teams, this means robust onboarding processes, identity verification, and background checks not only at the outset but throughout the relationship. Trust is good; verification is better.

What should you do? Deploy enhanced due diligence for high-risk or high-impact relationships. Use independent sources, cross-check credentials, and don’t hesitate to pause the process if any red flags arise.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity. They probe his capabilities, his advanced technology, his mysterious “servo,” and the highly sophisticated computer at his headquarters. Spock and Kirk ask probing questions about Seven’s mission, intent, and track record.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is, but also what they are capable of and what they plan to do with that capability. A company’s operational strengths, compliance record, and ethical history all inform future risk. Teams must go beyond public filings and financials. Look for operational gaps, management weaknesses, and track records of regulatory engagement. Just as Kirk and Spock dig into Gary Seven’s motives and methods, compliance officers should investigate all relevant dimensions.

What should you do? Expand your checklist: evaluate litigation history, regulatory fines, press coverage, key executive backgrounds, and past compliance breaches. Interview multiple stakeholders to triangulate intent.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information. Seven’s computer contains data that could alter the fate of the planet. Both Seven and the Enterprise crew are vigilant about access, using encryption, voice authentication, and physical security to ensure information is only available to those with a legitimate need.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyberattacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands. Therefore, it is crucial to monitor who has access to key data during the diligence phase. Implement robust information barriers and control access to confidential material. Make cybersecurity a core part of your diligence process.

What should you do? Require non-disclosure agreements from all parties. Use secure data rooms and audit access logs. Include cybersecurity posture and data protection history in every due diligence report.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III. The crew must adapt instantly, using every tool and resource at their disposal to prevent disaster, even as their understanding of the mission’s stakes evolves in real time.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks. Teams must be nimble, ready to reassess, escalate, and change course as new facts emerge. Establish protocols for escalating concerns and adjusting timelines when red flags appear. Build flexibility into your diligence process; sometimes, a deal should slow down or even pause while serious concerns are addressed.

What should you do? Schedule interim reviews, not just final sign-offs. Empower team members to call for additional investigation when new risks emerge, and document all changes to scope and focus.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe. Kirk must weigh the consequences of intervening or not, understanding that the impact goes beyond the immediate crisis and could shape the entire future of humanity.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences? Does the opportunity support or threaten your compliance culture? Kirk’s willingness to consider the broader impact rather than just “following the rules” mirrors the best compliance thinking. Evaluate not just the legal and financial implications, but the reputational, cultural, and strategic impacts as well.

What should you do? Be sure to include cultural fit, values alignment, and long-term strategy in your final diligence reports. Consult with leadership about potential impacts, positive and negative, before greenlighting a deal.

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

In today’s business environment, the threats and opportunities you face are more complex than ever. The partners, acquisitions, and investments you pursue all come with hidden variables. Like Kirk and his crew, your mission is to look deeper, ask more challenging questions, protect sensitive information, and never lose sight of the broader impact your decisions have on the world.

The next time your organization faces a pivotal deal or partnership, remember the spirit of “Assignment: Earth” and conduct your due diligence with the rigor, flexibility, and ethical perspective that the future demands.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Scoular’s $10 Million FCPA Resolution: When a “Re-inspection Fee” Becomes a Bribe

A $2,000 payment can look insignificant inside a global supply chain. Repeated train by train, approved by employees, routed through customs brokers, disguised on invoices, and paid for six years, it becomes something else entirely. For The Scoular Company, it became a Foreign Corrupt Practices Act enforcement action carrying more than $10 million in penalties and forfeiture, a three-year deferred prosecution agreement, continuing cooperation obligations, and periodic reporting to the Department of Justice.

The case is an important warning for every company engaged in cross-border trade. Customs brokers are not merely logistics providers. Border payments are not merely operational expenses. A mislabeled invoice is not merely an accounting problem. Each may represent an interconnected risk across anti-corruption, internal control, third-party, and national security.

The Scheme: $2,000 per Train

According to the DOJ Press Release (the full DPA is not yet available), between 2013 and 2019, Scoular used customs brokers to move shipments of corn and other agricultural products from the United States to Mexico. Mexican authorities inspected those shipments for dirt, soil, and other impurities. When inspectors identified problems, Scoular’s customs brokers allegedly paid Mexican officials approximately $2,000 per train to ensure that the shipments crossed the border.

The brokers then invoiced those payments back to Scoular as “reinspection fees.” Scoular paid the invoices. This was not an isolated facilitation payment or a rogue third party operating beyond the company’s knowledge. According to the court documents, Scoular employees authorized the payments, directed the brokers, and communicated about the shipments and bribes through WhatsApp and other channels.

The numbers demonstrate the business impact:

  • More than $400,000 in bribes authorized
  • More than $6.5 million in avoided fees and costs
  • A $9,769,521 criminal penalty
  • $414,351 in forfeiture
  • A three-year DPA

The company was charged with conspiracy to violate the FCPA’s anti-bribery provisions.

The Invoice Description Was a Compliance Red Flag

The phrase “reinspection fee” should be at the center of every compliance discussion about this case. The brokers did not invoice Scoular for bribes. They used a description that appeared facially connected to a legitimate customs process. That description allowed the payments to move through the company’s financial system.

This is how corruption frequently enters the books and records. It appears as:

  • Expediting fees
  • Administrative charges
  • Local processing costs
  • Customs support
  • Special handling
  • Reinspection fees
  • Consulting services

The compliance question is not whether the description sounds legitimate. The question is whether the company can establish what service was performed, who performed it, why the payment was necessary, how the amount was calculated, and who ultimately received the money. Accounts payable controls that merely match an invoice to a purchase order will not detect this type of scheme. Effective controls must examine the commercial substance of high-risk payments.

For customs-related expenses, companies should require supporting government documentation, published fee schedules, proof of service, payment to an authorized government account where appropriate, and enhanced approval for unusual or recurring charges.

Third-Party Due Diligence Is Only the Beginning

The Scoular resolution also demonstrates the limits of onboarding due diligence. A company can screen a customs broker, obtain certifications, execute an anti-corruption clause, and still face substantial FCPA exposure. The real question is what happens after the third party begins work. The answer is that the real work of compliance begins when the third-party contract is signed.

Customs brokers operate at the intersection of government interaction, time-sensitive business demands, discretionary enforcement, and local pressure. That makes them inherently high risk. An effective third-party management program should connect the following:

  • Initial due diligence
  • Contractual controls
  • Transaction monitoring
  • Invoice testing
  • Business justification
  • Periodic recertification
  • Audit rights
  • Compliance training
  • Offboarding decisions

The DOJ credited Scoular for strengthening risk-based screening and approval requirements, adding anti-corruption and audit-right provisions to contracts, and improving monitoring procedures. The company also eliminated customs brokers associated with the Mexican reinspection payments. Due diligence is not and cannot remain a static file. It must become a continuing control system tied to actual payments and operational conduct.

WhatsApp Was Part of the Business Process

Scoular employees allegedly communicated about the shipments and payments through WhatsApp and other channels. This fact should concern every CCO. When employees use personal devices or ephemeral messaging platforms to conduct high-risk business, the company may lose visibility into precisely the communications it most needs to monitor, preserve, and produce.

The answer is not necessarily to prohibit every messaging application. The answer is to establish a defensible governance model addressing the following:

  • Permitted communication platforms
  • Business-record retention
  • Preservation during investigations
  • Access to relevant communications
  • Training for high-risk employees
  • Monitoring based on legal and privacy requirements
  • Consequences for circumventing approved systems

A policy without technical controls, employee training, and consistent enforcement is unlikely to satisfy prosecutors. Messaging governance must reflect how employees actually conduct business.

Corruption Is Now a National Security Issue

The most significant feature of the case may be the DOJ’s treatment of cartel risk. The government determined that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border. The DOJ stated that neither Scoular nor its employees knew about that connection. That lack of knowledge did not eliminate the seriousness of the issue.

Indeed, in the DOJ Press Release, U.S. Attorney Justin R. Simmons for the Western District of Texas was quoted as follows, “Nothing crosses into or out of Mexico without the approval and payment to Mexican drug cartels.” Further, any American businesses that engage in any cross-border trade bear a significant amount of responsibility to do so without benefitting those cartels and without threatening our national security.”

The enforcement message is clear: companies operating in high-risk border regions must consider where third-party payments may ultimately flow. A payment intended to resolve a customs problem can expose a party to corruption, money laundering, sanctions, organized crime, and national security risks. This means anti-corruption risk assessments can no longer operate in isolation. Compliance teams should integrate information from the following:

  • Anti-money laundering reviews
  • Sanctions screening
  • Security functions
  • Trade compliance
  • Supply chain risk management
  • Third-party intelligence
  • Government investigations
  • Adverse media monitoring

The government is examining the complete risk created by a payment, not merely the employee’s immediate objective.

No Voluntary Disclosure Credit, but Meaningful Cooperation Credit

Scoular did not receive voluntary self-disclosure credit because it did not promptly report the conduct to the DOJ Fraud Section. It did, however, receive credit for cooperation. The DOJ cited Scoular’s internal investigation, factual presentations, identification of individuals involved, document production, organization of evidence, and provision of counsel for current employees. The DOJ also acknowledged deficiencies during the early stages of the investigation.

After considering the company’s cooperation and remediation, the DOJ imposed a criminal penalty reflecting a 25 percent reduction from the bottom of the applicable sentencing guidelines range. This is a valuable lesson in enforcement mathematics. Missing the opportunity for voluntary disclosure does not make subsequent cooperation irrelevant. Companies can still improve outcomes through credible investigation, evidence preservation, individual accountability, timely remediation, and the organized production of information.

Yet cooperation credit is not the equivalent of voluntary disclosure credit. The decision window following discovery of potential misconduct remains critical.

Remediation Must Change the Operating Model

Scoular’s remediation went beyond issuing a new policy. According to the DOJ, the company:

  • Conducted an external compliance maturity assessment and anti-corruption risk assessment
  • Restructured its compliance function
  • Increased senior leadership oversight
  • Eliminated brokers connected to the payments
  • Strengthened risk-based monitoring through software tools
  • Revised its Code of Conduct and key compliance policies
  • Improved third-party screening and approvals
  • Added anti-corruption and audit-rights provisions
  • Revised financial controls for high-risk transactions
  • Delivered general and targeted anti-corruption training

This is the type of remediation contemplated by the DOJ’s Evaluation of Corporate Compliance Programs. It addresses root causes, resources, governance, controls, technology, training, and business ownership.

The key is operational impact. The company must be able to demonstrate that the same conduct could not pass through the organization today without being detected or escalated.

Questions for CCOs

CCOs should ask:

  • Do recurring payments cluster around specific ports, brokers, officials, products, or inspection events?
  • Are vague payment descriptions automatically escalated?
  • Does compliance have access to customs, logistics, and accounts payable data?
  • Are high-risk brokers periodically reviewed after onboarding?
  • Has the company tested whether audit rights can actually be exercised?
  • Is there a rapid escalation process for deciding whether potential misconduct should be voluntarily disclosed?

The Bottom Line

The Scoular case was not simply about customs brokers paying officials. It was about an operational process that allegedly normalized bribery, an invoicing system that disguised the payments, employees who communicated through informal channels, and third-party funds that ultimately touched cartel-linked actors.

For compliance professionals, the lesson is direct: follow the payment, test the business justification, examine the communication channel, and understand the complete risk ecosystem. A $2,000 “reinspection fee” may be small enough to escape executive attention. It is not small enough to escape the FCPA.

Categories
Blog

The Odyssey and Compliance, Part 3 – Circe’s Island: Third-Party Influence and Culture Capture

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of Circe’s Island and how third parties can not simply influence but also capture organizations.

Odysseus had seen danger before. He had survived war, storms, and the occasional poor travel decision that would have caused any modern risk committee to request an immediate meeting. But then he came to Circe’s island, where the threat did not begin with open violence. It began with hospitality. Circe welcomed Odysseus’s men. She offered food. She offered a drink. She offered comfort. Then, in one of the more memorable compliance-adjacent transformations in Greek mythology, she turned them into swine.

Subtle? Not especially. Useful for corporate compliance? Absolutely. In the corporate world, third parties rarely transform employees into literal pigs. That would at least make the investigation easier. The modern version is quieter. A consultant becomes indispensable. A reseller knows “how things work here.” A lobbyist explains that the official process is for amateurs. A distributor normalizes side payments. A strategic partner begins to shape internal decisions. A vendor’s gifts, favors, travel, and access slowly change what employees consider acceptable.

No one wakes up and says, “Today I shall surrender my professional judgment.” Instead, judgment softens and then stretches. Then outsourced. That is Circe’s island.

The Corporate Translation

Circe is the consultant, agent, lobbyist, reseller, distributor, broker, introducer, or strategic partner who makes questionable conduct feel sophisticated. She does not have to say, “Break the rules.” That would be too obvious. She says something more dangerous:

“This is how business is done.”

“Everyone uses this structure.”

“You are being too rigid.”

“The policy was not written for this situation.”

“You can trust me.”

“We have relationships you do not have.”

That is the language of culture capture. The third party does not merely provide a service. The third party begins to influence the organization’s standards. This is why third-party risk is not just a procurement issue. It is not just an anti-bribery issue. It is not just a contracting issue. It is a cultural issue. The most dangerous third parties do not always demand a bribe. Sometimes they simply change what your people think is normal.

The Paperwork Trap

Most companies have a third-party process. There is a questionnaire. There is a risk rating. There is a certification. There is a contract clause. Somewhere, there may even be a spreadsheet with conditional formatting, because nothing says “control environment” like a cell turning amber. These tools matter. But paperwork alone does not manage influence.

A company can collect every form and still miss the real risk. Whom is this third party influencing? Who inside the company is advocating for them? Why are they needed? What access do they have? What discretion do they exercise? Are they interacting with government officials, customers, healthcare professionals, regulators, state-owned entities, procurement teams, or other sensitive stakeholders? Are they being paid in a way that makes sense? Are they actually doing the work? Are they unusually close to the decision-maker?

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether companies apply risk-based due diligence to third-party relationships and understand the qualifications, associations, business rationale, reputation, compensation, and actual services performed by third parties. It also asks whether companies engage in ongoing monitoring through refreshed due diligence, training, audits, or certifications.

That is the point. Third-party compliance is not a one-time onboarding ritual. It is a relationship management discipline. Circe’s danger was not that she existed. The danger was that Odysseus’s men entered her house without understanding the risk.

Gifts, Hospitality, and the Slow Erosion of Judgment

Gifts and hospitality are often discussed as if the only question is whether the amount is above or below a policy threshold. That is too narrow. A meal may be permissible and still influential. A conference invitation may be properly approved and still create pressure. A vendor-sponsored trip may be documented and still tilt the relationship. A series of small favors may do more damage to independence than one obviously improper gift.

Compliance officers understand this. Business leaders sometimes resist it because influence is uncomfortable to discuss. No one wants to admit that lunch, access, flattery, or convenience can affect judgment. We prefer to believe we are all rational actors, floating above human weakness like minor gods with expense reports. We are not.

Behavioral ethics teaches a humbler lesson: people are influenced by relationships, reciprocity, loyalty, fatigue, social norms, and self-interest. A third party who becomes a friend, fixer, sponsor, or “trusted guide” can reshape decisions without issuing a single improper instruction.

That is why gifts-and-hospitality controls should look beyond monetary value. They should examine frequency, timing, recipient role, pending decisions, public-sector touchpoints, tender activity, regulatory matters, and cumulative patterns. The better question is not only, “Was this gift allowed? “The better question is, “What might this gift be trying to make feel normal? ”

Conflicts of Interest: Circe with a Business Card

Conflicts of interest are another form of enchantment. The employee recommends a vendor owned by a family member. A manager hires a consultant whom he previously employed. A procurement lead has a side investment in a supplier. A sales executive pushes a reseller because the reseller has promised future employment. A board member has ties to a strategic partner.

Often, the conflicted person does not experience the conflict as corruption. They experience it as trust.

“I know them.”

“They are good people.”

“They understand our business.”

“This will move faster.”

That may all be true. It may also be irrelevant. Conflicts do not require proof that someone acted dishonestly. A conflict means that personal interest may interfere with, or appear to interfere with, professional judgment. In compliance, appearance matters because trust matters. Circe did not need to tell the crew they were compromised. They simply became something other than what they had been. That is what unmanaged conflicts do. They transform decision-makers into advocates for interests they may not even fully recognize.

Risk-Based Due Diligence Means Asking Better Questions

A strong third-party program should be risk-based. That does not mean treating every vendor like a potential international crime syndicate. It means applying the right level of scrutiny to the right relationship. The office coffee supplier probably does not need the same review as a customs broker, government-facing consultant, high-commission sales agent, data processor, clinical partner, reseller, lobbyist, or distributor in a high-risk market.

Risk-based due diligence should ask direct questions:

What will this third party do for us?

Why do we need them?

Who selected them?

What relationships do they bring?

How will they be paid?

What access will they receive?

What decisions can they influence?

What laws, regulations, or policy areas do they touch?

What red flags appeared, and how were they resolved?

The ECCP also emphasizes risk assessment across factors such as business partners, third-party use, gifts, travel, entertainment, and other areas that may contribute to the risk of misconduct. That is a useful reminder: third-party risk rarely travels alone. It often brings friends. Gifts risk. Conflicts are risky. Books-and-records risk. Data risk. Sanctions risk. Cyber risk. Antitrust risk. Fraud risk. Reputational risk. Circe’s island is crowded.

Training the People Who Meet Circe

Third-party policies are necessary, but people need training before they sit across the table from Circe. Sales teams need to understand the red flags for resellers and agents. Procurement teams need to spot conflicts and unusual payment terms. Finance needs to recognize vague invoices, round-dollar payments, split payments, and services that cannot be verified. Legal needs to ensure that contracts describe real services and include rights to audit, termination, compliance, and cooperation. Business sponsors need to understand that “I trust them” is not due diligence.

The ECCP asks whether training and communications are tailored to the audience and whether companies provide practical guidance, case studies, and ways for employees to get ethics advice as issues arise. It also contemplates training for appropriate agents and business partners. That is exactly right.

Do not train employees only on the policy. Train them in the moment. The moment when the consultant says the invoice needs to be vague. The moment when the distributor asks for payment to an offshore account. The moment when the lobbyist says no one can know about the meeting. The moment when the vendor offers to fly the team to a “strategy session” at a resort, suspiciously light on strategy. The moment when the business sponsor says, “Compliance is slowing this down.” That is where the program either works or becomes decorative.

What a Better Program Does

A better third-party program examines influence, not just paperwork. It connects due diligence, contracting, training, payment controls, gifts and hospitality, conflict disclosures, monitoring, audits, and termination rights. It reviews third-party activity after onboarding. It checks whether services were actually performed. It compares compensation to market value. It looks for unusual payment structures. It refreshes diligence when risk changes. It trains business sponsors, not just compliance staff. It monitors the internal champions who may become too close to the third party they manage.

Most importantly, it permits employees to be skeptical. Not cynical. Skeptical. There is a difference. Cynicism says everyone is corrupt. Skepticism says facts, controls, and accountability should support trust. Odysseus survived Circe because he received a warning, protection, and guidance before walking into the risk. Your employees need the same, preferably without needing Hermes to appear with magical herbs.

The Compliance Takeaway

Circe’s island is not just a story about transformation. It is a story about influence. Third parties can help companies grow, enter new markets, solve complex problems, and operate more effectively. Many are essential. Many are ethical. Many know things the company genuinely needs to know. But a third party should never become a substitute for the company’s judgment. When a consultant, agent, reseller, lobbyist, vendor, or strategic partner begins to redefine what is acceptable, the company has moved from third-party management to third-party capture.

That is the lesson for compliance officers and business leaders. Do not ask only whether the forms are complete. Ask whether the relationship is changing behavior. Ask whether gifts, conflicts, access, dependence, or pressure are making questionable conduct feel normal. Ask whether employees still know where the company’s standards end and Circe’s influence begins. Because in business, as in mythology, transformation rarely announces itself. One day, your people are professionals exercising independent judgment. The next day, they are defending the island.

Join us on Thursday for Post 4, where we consider The Cattle of Helios: Non-Negotiables and Control Breaches.

Categories
GSK in China: 13 Years Later

GSK In China: 13 Years Later – After the Humphreys Verdict: Managing Third-Party Risk When You Can’t Verify

Thirteen years after the GSK China scandal exploded onto the global stage, its lessons remain as urgent as ever for compliance professionals and business leaders. In this podcast series, we revisit the case not simply as corporate history, but as a living cautionary tale about culture, incentives, third parties, investigations, and governance. Each episode explores what went wrong, why it went wrong, and how those failures still echo in today’s compliance and ethics landscape. Join me as we unpack the scandal and draw practical lessons for building stronger, more resilient organizations. In this episode, we take a deep dive into the 2013 GSK China bribery scandal and examine why it remains one of the most important case studies in corporate compliance, governance, and culture. Our hosts are Timothy and Fiona.

The episode examines how multinational companies should manage third-party relationships and compliance in opaque markets like China when traditional intelligence-gathering is curtailed by privacy laws, using the case of corporate investigators Peter Humphreys and his wife Ying Zeng, who were hired by GSK to investigate a sex-tape scandal but were convicted and imprisoned for purchasing Chinese citizens’ personal data. The discussion highlights how the verdict created operational uncertainty for due diligence, M&A, supplier vetting, and anti-bribery efforts, and notes Humphrey’s claim that GSK withheld the fact that it faced internal whistleblower allegations of corruption. Drawing on DOJ expectations and an SCCE framework, it argues for shifting from “vet and forget” to continuous third-party management across five steps, reinforcing business justification, questionnaires, contracts, and ongoing oversight with mitigations like capped commissions, detailed invoice review, early audits, and use of public records and in-person interviews.

Key highlights:

  • Why Verification Matters
  • Privacy Laws Change Everything
  • When Partners Refuse Disclosure
  • Build Your Own Intelligence
  • Contract Controls and Oversight

Resources:

GSK in China: A Game Changer for Compliance on Amazon.com

GSK in China: Anti-Bribery Enforcement Goes Global on Amazon.com

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Ed. Note: the voices of the hosts, Timothy and Fiona, were created by Notebook LM based upon text written by Tom Fox