Categories
Blog

Ted Lasso Week: Part 4 – Roy Kent: The Compliance Power of the Middle Manager

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I have considered Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 4, I consider the sometimes painful transition of an aging sports star into middle-management coaching.

In Part Three, Nate Shelley demonstrated the danger of promoting technical talent without preparing or monitoring the new manager. Roy Kent provides the counterpoint. He is demanding, impatient, and frequently intimidating, but he understands that leadership happens close to the work. Ted can articulate Richmond’s values. Rebecca can provide authority and resources. Roy determines whether those values survive contact with the locker room. He corrects behavior, confronts stars, coaches struggling employees, and translates general expectations into specific action.

For compliance professionals, Roy illustrates the power of the middle manager. He also shows the risk. The same informal authority that can strengthen culture can magnify poor judgment when it is not bounded by self-awareness, escalation, and accountability.

Authority Exists Before the Title

Roy begins the series as Richmond’s captain, not a member of management. Yet his teammates watch him, follow him, and adjust their behavior around him. He has informal authority, which often matters more than the organizational chart.

In “Trent Crimm: The Independent” (Season 1, Episode 3), Ted recognizes that Jamie Tartt and other players are bullying Nate. Rather than solve the problem solely through formal coaching authority, Ted pushes Roy to act. Roy confronts Jamie and forces the locker room to change. That is the tone in the middle. Employees often look to a respected supervisor, veteran, or peer leader to determine whether the code of conduct is real. If that person laughs at an offensive joke, ignores a control override, or protects a top performer, the policy loses. If that person intervenes, the standard gains operational force.

The DOJ Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to examine how managers at all levels encourage or discourage compliance through their words and actions. Compliance leaders therefore need to identify informal influencers, not merely designated supervisors. On this point, the ECCP states, “it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.” Culture travels through both. The ECCP goes on to state “[t]he company’s culture of compliance, including awareness among employees that any criminal conduct, including the conduct underlying the investigation, will not be tolerated.”

Standards Must Apply to Stars and to the Manager

Roy’s credibility comes partly from his willingness to confront Jamie, Richmond’s most talented player. He refuses to accept the idea that performance excuses selfishness or abuse. That is a central compliance principle. Standards that bend around revenue generators and star executives are not standards.

Roy faces the same test personally in “All Apologies” (Season 1, Episode 9). His age and injuries have reduced his performance, but his identity is tied to being captain and playing every match. When Ted decides to bench him, Roy initially resists. He ultimately reports for training in the reserve bib and supports the team. The decision matters because accountability becomes credible when the influential employee accepts the rule applied to everyone else. Roy does not enjoy the outcome, but he demonstrates that status does not confer immunity.

Effective Coaching Diagnoses the Cause

In “The Hope That Kills You” (Season 1, Episode 10), Roy selects Isaac McAdoo as the next captain. By “Rainbow” (Season 2, Episode 5), Isaac is struggling under the weight of that role. Ted asks Roy for help. Roy does not respond with another motivational speech or a threat. He takes Isaac to the neighborhood pitch where Roy learned to play and places him in an informal match. The intervention helps Isaac rediscover that football is a game he loves.

This is root-cause analysis at the individual level. The visible problem is poor performance. The underlying issue is that responsibility has displaced purpose and confidence. Roy changes the environment, observes Isaac, and chooses an intervention connected to the cause. The compliance application is substantial. When an employee misses a control, a manager should not automatically assign retraining. The cause may be an unrealistic target, conflicting procedures, poor system design, inadequate staffing, fear of escalation, or a supervisor who rewards shortcuts. Training cannot repair a misaligned incentive. Discipline cannot correct an unusable process.

Coaching Can Turn a Risk Into an Asset

Roy’s relationship with Jamie becomes his strongest management case. He begins by confronting Jamie’s entitlement. In “Man City” (Season 2, Episode 8), after Jamie finally strikes back at his abusive father, Roy recognizes the pain beneath the conduct and embraces him. The response is neither a lecture nor an endorsement of violence. It is a manager recognizing that the employee needs support before instruction.

In “4-5-1” (Season 3, Episode 3), Jamie asks how he can become better than Zava. Roy offers to train him. The work continues through “Sunflowers” (Season 3, Episode 6), when their training in Amsterdam becomes reciprocal, and Jamie teaches Roy to ride a bicycle. Roy does not lower the standard for Jamie. He gives him the discipline, attention, and feedback needed to meet a higher one. This is what good remediation should accomplish. It should protect the organization while creating a credible path for behavioral improvement.

Managers need tools for these conversations: clear expectations, documented feedback, measurable improvement goals, support resources, escalation thresholds, and follow-up. Candor without structure can become hostility. Compassion without standards can become avoidance. Roy is most effective when he combines both.

Informal Power Can Also Amplify Bad Judgment

Roy is not a flawless compliance model. In “Big Week” (Season 3, Episode 4), he and Coach Beard show the players security footage of Nate tearing the “BELIEVE” sign, despite Ted’s decision not to use it as motivation. The team becomes enraged, loses discipline, receives multiple red cards, and falls to West Ham. Roy intends to motivate. He instead weaponizes internal security footage and emotional injury.

The failure offers three lessons. First, managers must understand the limits of delegated authority. Silence or ambiguity from senior leadership is not permission to bypass its stated judgment. Second, incentives built on anger can produce foreseeable misconduct. Third, a result-driven culture can make an improper method appear acceptable until the damage becomes visible.

Roy’s training methods can also cross from demanding into unsafe or humiliating, as the red-string exercise in “The Strings That Bind Us” (Season 3, Episode 7) demonstrates. A strong manager should challenge employees. The organization must still set boundaries around safety, dignity, and acceptable conduct. This is why middle-management training cannot be limited to explaining policy. Managers need scenario-based practice on investigations, privacy, retaliation, discipline, escalation, health and safety, conflicts, and the use of employee information.

The Best Managers Remain Coachable

Roy’s development is possible because he gradually accepts that leadership does not require invulnerability. In “So Long, Farewell” (Season 3, Episode 12), he joins the Diamond Dogs, asks whether people can change, and later begins therapy. He becomes Richmond’s manager, but his promotion is framed as the next stage of development, not proof that the work is finished.

That distinction matters. Organizations often treat promotion as validation rather than increased risk. The best managers remain open to feedback, seek guidance, acknowledge uncertainty, and use available expertise. Middle managers are a critical source of that information. They should not filter out bad news to protect their numbers. Boards and executives should ask whether managers escalate emerging risks, whether the organization rewards such escalation, and whether retaliation or fear is blocking the flow of information.

Questions for CCOs

Roy’s journey should prompt five questions:

  1. Who are the organization’s informal culture carriers, and how are they engaged?
  2. Are managers evaluated and rewarded for how they achieve results, not only for the results themselves?
  3. Do managers know how to diagnose root causes, escalate concerns, and document behavioral coaching?
  4. Are high performers subject to the same conduct standards as everyone else?
  5. Does manager training distinguish productive candor from intimidation, retaliation, humiliation, and unsafe pressure?

Roy Kent demonstrates that middle managers are the operational heart of compliance. They make standards visible, detect weak signals, and decide whether employees experience accountability as fair. Compliance cannot succeed around them. It must succeed through them.

Next in the Series: Keeley Jones and Governance Under Pressure

Roy’s challenge is translating established values into frontline behavior. Keeley Jones faces the next organizational stage: building a business, accepting investor capital, managing employees, and preserving independence while personal and commercial pressures converge. Join us in our series finale, where we will examine founder risk, conflicts of interest, privacy, third-party influence, and why governance must grow as quickly as the company it is designed to protect.

Categories
Blog

Ted Lasso Week: Part 3 – Nate Shelley: When an Employee Becomes a Culture Risk

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I will consider Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 3, we consider the professional journey of Nate Shelley, who begins the series as the equipment manager, or in football parlance, the ‘kit man,’ but rises into the managerial ranks.

In Part Two, Rebecca Welton showed how concentrated authority can turn an executive’s private grievance into organizational misconduct. Nate Shelley presents a different risk. His damage begins below the executive level, after AFC Richmond promotes a technically gifted employee without preparing him to exercise power.

Nate is not a villain. He is the overlooked kit man whom players ridicule and leaders barely notice. Ted recognizes his tactical ability, Roy stops the bullying, and Richmond promotes him. Yet the organization mistakes recognition for readiness. Once Nate receives authority, the humiliation he experienced does not disappear. He redirects it toward people with less power.

For compliance professionals, Nate’s story shows that culture risk can emerge when organizations reward expertise, overlook behavioral warning signs, fail to adequately train new managers, and then fail to monitor them.

Promotion Changes the Risk Profile

In “Trent Crimm: The Independent” (Season 1, Episode 3), Jamie Tartt and other players bully Nate until Roy intervenes. Ted also invites Nate to contribute tactical ideas. Those decisions establish dignity and psychological safety for an employee who had neither.

By “The Hope That Kills You” (Season 1, Episode 10), Nate has been promoted to assistant coach. The promotion is understandable. He knows football, sees patterns others miss, and has already helped the team. What Richmond never appears to assess is whether he can supervise people, receive criticism, manage conflict, protect confidential information, or use authority consistently. This is a common corporate failure. The strongest engineer becomes an engineering manager. The top salesperson becomes a regional leader. The best investigator becomes an investigation director. Technical performance is treated as proof of leadership capacity.

Section 8B2.1 of the 2025 U.S. Sentencing Guidelines requires reasonable efforts in selecting personnel with substantial authority, practical training based on role and responsibility, monitoring, and consistent discipline. An effective promotion process should assess conduct, not merely output. It should also include manager training, defined escalation duties, coaching, and a meaningful review period.

Richmond changes Nate’s title. It does not build the controls that should accompany his new power.

The Bullied Employee Becomes the Bullying Manager

Nate’s deterioration becomes unmistakable in “The Signal” and “Headspace” (Season 2, Episodes 6 and 7). Public praise for his tactical decision produces the “Wonder Kid” identity he craves. He also belittles Colin Hughes and directs increasingly harsh treatment at Will, the young employee who replaced him as kit man. Coach Beard witnesses Nate humiliating Colin and tells him to do better. Nate then delivers a public apology. Yet when Will gives him a personalized jersey, Nate responds with private abuse. The apparent correction does not change the conduct. It relocates the harm to a more vulnerable target.

That sequence should concern every compliance officer. A manager confronted about misconduct may learn the wrong lesson: avoid witnesses, control the record, and retaliate where detection is less likely. Closing a matter after an apology, without checking the experience of affected employees or monitoring subsequent conduct, can make the organization less safe.

The DOJ Evaluation of Corporate Compliance Programs asks how managers at all levels demonstrate commitment to compliance, whether employees are comfortable reporting concerns, whether there are “lines of reporting and communications,” and whether discipline is consistent. “Have disciplinary actions and incentives been fairly and consistently applied across the organization? ” Does the compliance function monitor its investigations and resulting discipline to ensure consistency? “And whether the company examines root causes,” “Has the company undertaken a root cause analysis into areas where certain conduct is comparatively over- or under-reported?” Nate’s conduct calls for more than informal coaching. It calls for fact-finding, documentation, protection of Will and Colin, and a plan to determine whether behavior actually changes (i.e., ongoing monitoring).

Warning Signs Are Data

Richmond receives signals throughout Season 2. Nate becomes preoccupied with status, press coverage, social media approval, and perceived slights. He resents Roy’s return to the coaching staff. He spits at his reflection to manufacture confidence. His criticism becomes personal, and his treatment of lower-status employees worsens.

None of these facts alone proves that Nate will betray the team. Together, they form a pattern. Compliance programs fail when each signal remains isolated: Human Resources sees a complaint, a supervisor observes disrespect, colleagues notice resentment, and senior leadership sees performance. No one assembles the complete picture. This is the pattern recognition issue. If no one person or data analytics tool is watching the pattern, it may not be noticed until it is too late.

Under the COSO Internal Control Framework, Richmond’s weakness spans risk assessment (Objective 2), information and communication (Objective 4), and monitoring (Objective 5). The organization has values, but it lacks a reliable process for gathering culture data and testing whether managers operate consistently with those values.

Grievance Becomes Betrayal

Nate’s culture risk becomes an organizational crisis in “Midnight Train to Royston” (Season 2, Episode 11). Trent Crimm informs Ted that an article will reveal Ted’s panic attack and that Nate is the source. In “Inverting the Pyramid of Success” (Season 2, Episode 12), Nate accuses Ted of abandoning him, rejects Ted’s apology, acts out by tearing the “BELIEVE” sign in half, and leaves for West Ham.

Nate has legitimate feelings about recognition, communication, and his relationship with Ted. Those feelings do not justify leaking a colleague’s sensitive health information to inflict reputational harm. Explanation is not exoneration. It also leads to what I consider one of the most reprehensible lines in the entire series when Nate screams at Ted, “You don’t belong here.”

Organizations should examine both individual accountability and system failure. Why did Nate believe betrayal was his only effective channel? Why did no one detect the escalating mistreatment of employees? Who owned his development after promotion? What information could he access because of his trusted position? Why did Richmond lack a process that could address his grievance before it became retaliation? A root-cause analysis that labels Nate disloyal and stops there will miss the control failures that allowed the risk to mature.

Incentives Can Amplify the Wrong Behavior

At West Ham, Rupert rewards Nate with title, status, a car, and proximity to power. In “Smells Like Mean Spirit” (Season 3, Episode 1), Nate mocks Richmond and Ted publicly and humiliates a West Ham player during training. Rupert does not remediate Nate’s insecurity. He weaponizes it.

This is incentive design in human form. One organization can suppress destructive behavior while another celebrates it. Compensation is only one incentive. Access, attention, public praise, elite membership, and fear of exclusion can be equally powerful. Nate eventually recognizes the cost. After refusing Rupert’s invitation to a private “boys’ night,” he leaves West Ham, as confirmed in “International Break” (Season 3, Episode 10). His departure is meaningful because he gives up the status he once treated as proof of worth.

Reintegration Requires More Than Forgiveness

Nate begins repairing harm by quietly completing Will’s work and leaving an apology in “International Break.” In “Mom City” (Season 3, Episode 11), several players invite him back, but Nate hesitates because Ted has not approved the plan. Beard ultimately offers him a second chance. In “So Long, Farewell” (Season 3, Episode 12), Nate apologizes directly to Ted and returns to the coaching staff.

The human story is redemption. The compliance story is reintegration. A sound return-to-work plan would document findings, consider the views and safety of affected employees, define Nate’s role, require coaching, reinforce confidentiality and anti-retaliation standards, and monitor conduct over time. Restoration can support culture, but only if it does not communicate that talent or remorse erases accountability.

Questions for CCOs

Nate’s journey should prompt five questions:

  1. Do promotion decisions evaluate leadership conduct and risk, or only technical results?
  2. Are new managers trained on retaliation, confidentiality, escalation, discipline, and psychological safety?
  3. Can lower-status employees report misconduct by a popular or high-performing manager without fear?
  4. Does the organization combine complaint, exit, survey, investigation, and performance data to identify patterns?
  5. When a former employee returns after misconduct, is reintegration structured, documented, and monitored?

Nate becomes a culture risk because Richmond sees his talent before he understands his relationship with power. His story reminds us that employees do not become ethical managers through promotion alone.

Next in the Series: Roy Kent and the Power of the Middle Manager

Nate shows what happens when managerial authority is granted without preparation or sustained oversight. Roy Kent offers the counterpoint. He is imperfect, confrontational, and sometimes slow to change, but he understands that standards become real through daily coaching, direct feedback, and visible accountability. In Part Four, we will examine why middle managers are the operational heart of an effective compliance program and how Roy converts leadership expectations into behavior inside the locker room.

Categories
Blog

When the Captain Isn’t the Captain: Star Trek’s Turnabout Intruder as a Root Cause Analysis Case Study

One of the Department of Justice’s most consistent themes in its 2024 Update to the Evaluation of Corporate Compliance Programs (ECCP) is the need for companies to conduct effective root cause analysis following misconduct or control failures. It’s not enough to identify what went wrong; you must understand why it happened and implement measures to prevent it from happening again.

That principle is front and center in the Star Trek: The Original Series finale, Turnabout Intruder. In this episode, Captain Kirk is on an archaeological survey mission when he encounters Dr. Janice Lester, an old acquaintance from Starfleet Academy. Through a mysterious alien device, Lester transfers her consciousness into Kirk’s body, trapping his mind in her own body. What follows is a tense series of events in which “Kirk” behaves increasingly erratically, prompting suspicion among the crew.

For compliance professionals, the episode is a surprisingly apt case study in the perils of failing to dig past the surface when something seems off. Just as the crew needed to piece together the real cause of their captain’s strange behavior, compliance teams must be adept at peeling back layers to discover the true root cause of problems.

Here are five key root cause analysis lessons from Turnabout Intruder.

Lesson 1: Unusual Behavior Should Trigger an Investigation

Illustrated by: Shortly after the mind swap, “Kirk” begins making uncharacteristic decisions, belittling subordinates, ignoring Starfleet protocols, and punishing dissent in ways that are entirely out of character for the captain.

Compliance Lesson:

Behavior that deviates from established patterns should be a red flag. In corporate compliance, abrupt changes, whether in employee conduct, financial reporting patterns, or transaction activity, often indicate deeper issues.

Too often, organizations rationalize away early warning signs: “He’s under stress” or “That’s just her style.” But effective root cause analysis begins with the willingness to ask, Why is this happening now? Early detection is often the difference between a manageable problem and a full-blown crisis. Develop and maintain behavioral baselines for key personnel and functions. If something deviates sharply, investigate promptly rather than waiting for more evidence to emerge.

Lesson 2: Multiple Data Points Build a Stronger Case

Illustrated by: Several crew members—Spock, McCoy, and Scotty—each notice something odd about “Kirk.” At first, their observations are anecdotal and separate. Only when they share information do they begin to see a pattern that suggests something is seriously wrong.

Compliance Lesson. Root cause analysis is stronger when it integrates multiple perspectives and data sources. If you rely on a single source, one audit, or one complaint, you risk drawing incomplete or biased conclusions.

In the episode, no single crew member had enough to prove that Kirk wasn’t himself. But when their observations were combined, the collective evidence pointed toward an anomaly that needed urgent action. Create processes that encourage information sharing across departments. Compliance, audit, HR, and operations should have mechanisms to cross-reference findings because the root cause may only emerge when different pieces are put together.

Lesson 3: Be Alert to Hidden Motives

Illustrated by: In Kirk’s body, Lester uses her new authority to sideline suspected opponents, reassigning or threatening crew who question her behavior. Her motive isn’t mission success; it’s consolidating her stolen command.

Compliance Lesson. The apparent cause of a problem may mask deeper personal or organizational motives. Misconduct often occurs because someone pursues goals that conflict with corporate policy, whether for financial gain, personal vendettas, or reputational enhancement.

If your analysis stops at “This person violated policy,” you miss the opportunity to uncover why they were willing to risk consequences. In many cases, systemic issues, misaligned incentives, toxic culture, and weak oversight drive the behavior. In every investigation, ask, “What’s in it for them? Understanding incentives, pressures, and personal agendas can reveal root causes that process analysis alone won’t uncover.

Lesson 4: Authority Structures Can Delay Recognition of the Problem

Illustrated by: Even when evidence mounts, the crew is reluctant to challenge “Kirk” because of the chain of command. Starfleet discipline dictates deference to the captain, making it harder to act on suspicions.

Compliance Lesson. In organizations, hierarchy can block efforts to identify root causes. Employees may hesitate to report misconduct by senior leaders, or they may assume questionable directives are “above their pay grade” to question.

This dynamic often allows problems to persist far longer than they should. A compliance program must be designed to bypass those bottlenecks, giving employees safe, confidential, and credible ways to report concerns, even about top executives. Ensure that escalation procedures allow for independent review of senior management conduct. Whistleblower protections, ombuds functions, and anonymous hotlines can help surface issues that otherwise stay buried.

Lesson 5: Validate Assumptions Before Acting

Illustrated by: Spock eventually confronts “Kirk” and demands an explanation. Through logical analysis and a mind meld, he confirms the truth of the body swap. Only then can the crew take decisive action to restore the captain to his rightful body.

Compliance Lesson. One of the biggest pitfalls in root cause analysis is acting on unverified assumptions. If you jump to conclusions too early, you may “fix” the wrong problem—or make it worse. Spock’s mind meld was the ultimate verification step. In compliance, your “mind meld” might be corroborating whistleblower claims with independent documentation or testing an internal control in multiple scenarios before concluding it’s defective.

Build verification into your root cause analysis process. Don’t settle for the first plausible explanation; pressure-test your conclusions before implementing remediation.

Connecting Star Trek to DOJ Expectations

The DOJ’s ECCP explicitly asks:

  • “What is the root cause of the misconduct? ”
  • “Were prior opportunities to detect the misconduct missed? ”
  • “What systemic failures contributed to the issue? ”

Turnabout Intruder illustrates the importance of addressing these questions. If the crew had stopped at “the captain is acting oddly” and focused on damage control, they might never have uncovered the deeper truth of Lester’s body swap. Similarly, in corporate investigations, stopping at the surface level (“employee violated policy”) without probing the environment that allowed it to happen fails both the DOJ’s expectations and your prevention mandate.

Final ComplianceLog Reflections

In Turnabout Intruder, the crew’s slow realization of the true problem nearly cost them their captain and perhaps the Enterprise itself. In the compliance arena, a slow or shallow root cause analysis can let misconduct persist, control weaknesses remain unaddressed, and systemic issues metastasize.

Effective compliance leadership means not just spotting what’s wrong but relentlessly pursuing why it went wrong. That’s how you fix the problem in a way that prevents recurrence.

Like Spock confronting “Kirk,” we must gather evidence methodically, test our conclusions, and act decisively once the truth is clear. Root cause analysis isn’t about blame—it’s about ensuring your organization emerges stronger, more transparent, and more resilient than before.

Because in the end, just like the Enterprise, your mission depends on having the right people in the right roles, operating with integrity, and that’s a result only a thorough, well-executed root cause analysis can guarantee.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Ted Lasso Week: Part 2 – Rebecca Welton: Misuse of Authority, Conflicts of Interest, and the Path to Accountability

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I will consider Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 2, we consider compliance lessons through the character of team owner Rebecca Welton.

In Part 1, we considered how Ted Lasso built psychological safety and an ethical culture while sometimes allowing empathy to outrun accountability. Rebecca Welton presents the problem from the other side of the executive table. She begins as the source of AFC Richmond’s misconduct, then becomes the leader best positioned to acknowledge it.

Rebecca’s story is not simply a redemption arc. It is a governance case study about what happens when personal objectives capture corporate authority. It also shows why confession, forgiveness, and improved behavior are necessary but insufficient elements of an effective remediation program. The compliance lesson is direct: power creates risk when no independent mechanism can question the person exercising it.

When the Owner Becomes the Risk

In “Pilot” (Season 1, Episode 1), Rebecca hires Ted, an American football coach with no soccer experience, to manage a Premier League club. Her stated rationale is irrelevant because her actual purpose is to destroy the institution Rupert Mannion loves. She uses Richmond’s people, reputation, competitive position, and financial value to pursue a private grievance.

That is a classic conflict between personal interest and organizational duty. Rebecca is not accepting an envelope of cash or steering a contract to a relative. Her conflict is more fundamental: she has converted corporate decision-making into an instrument of revenge. The COSO Internal Control Framework begins with the control environment, including integrity, ethical values, oversight, authority, and accountability. At Richmond, the control environment fails at the top. The owner sets an improper objective, possesses the authority to execute it, and faces no visible independent challenge.

Compliance officers should take note. Conflicts of interest do not end with disclosure forms. They arise whenever personal relationships, status, resentment, financial incentives, or outside interests can distort business judgment. The greater the executive’s authority, the stronger the required safeguards.

Concentrated Authority Silences Challenge

Rebecca’s plan requires assistance. Higgins facilitates her agenda even though he recognizes the harm. In “Make Rebecca Great Again” (Season 1, Episode 7), Rebecca arranges for a photographer to capture Ted and Keeley in a compromising image. The objective is not legitimate media strategy. It is manufactured reputational damage intended to destabilize Ted and the club.

Higgins is not merely an unfortunate bystander. He is a senior employee who allows access, information, and organizational machinery to serve the owner’s improper purpose. His eventual resignation is a delayed act of conscience, but the episode demonstrates how authority can corrupt the escalation process. Employees may know that conduct is wrong and still conclude that challenging the owner is futile or career-ending.

The DOJ Evaluation of Corporate Compliance Programs asks whether “compliance personnel (1) sufficient qualifications, seniority, and stature (both actual and perceived) within the organization; (2) sufficient resources, namely, staff to undertake the requisite auditing, documentation, and analysis effectively; and (3) sufficient autonomy from management, such as direct access to the board of directors or the board’s audit committee.” It also asks whether managers encourage or discourage compliance through their conduct. Richmond has no credible independent function capable of reviewing Rebecca’s decisions, investigating her conduct, or escalating around her.

Accountability Begins With Truth

Keeley becomes the effective speak-up channel Richmond lacks. Once she discovers Rebecca’s scheme, she does not accept friendship, hierarchy, or reputational risk as reasons to stay silent. She insists that Rebecca tell Ted the truth. Rebecca finally does so in “All Apologies” (Season 1, Episode 9). She admits that she hired Ted to fail, orchestrated the paparazzi scheme, and engineered Jamie Tartt’s return to Manchester City to weaken Richmond. Most importantly, she does not minimize her purpose. She explains that she wanted to hurt Rupert and used Ted and the club to do it.

This is an effective apology because it identifies conduct, intent, and harm. It also accepts the possibility of consequences. Yet it is not a remediation. Nevertheless, Ted forgives her immediately, but an actual organization could not stop there. The U.S. Sentencing Guidelines require an organization to respond appropriately after misconduct and take reasonable steps to prevent similar conduct. DOJ asks whether the company performed a root-cause analysis, disciplined responsible individuals, repaired controls, and tested whether remediation works.

Richmond would need an independent review of affected personnel decisions, financial consequences, sponsor and stakeholder impacts, the use of confidential information, and Higgins’s role. It would also need governance changes that prevent one executive from repeating the conduct. An apology can reopen trust. Only remediation can reduce recurrence risk.

The Conflict Problem Returns With Sam

Rebecca’s growth does not eliminate conflicts. In “The Signal” and “Headspace” (Season 2, Episodes 6 and 7), Rebecca discovers that her anonymous Bantr match is Sam Obisanya, a Richmond player. Their relationship develops in “Man City” (Season 2, Episode 8) and continues secretly into “No Weddings and a Funeral” (Season 2, Episode 10).

The relationship is portrayed with warmth and mutual affection. That does not resolve the organizational issue. Rebecca owns the club that controls Sam’s employment environment. Her decisions can affect contracts, playing resources, sponsorships, reputation, and career opportunities. Even if she never exercises that power improperly, the imbalance creates an appearance of favoritism and raises questions about consent, retaliation, confidentiality, and recusal.

The compliance response is not moral judgment. It is a process. A conflict policy must apply to owners and senior executives, not only employees. Disclosure should go to an independent board member or committee. The organization should document safeguards, remove the conflicted leader from relevant decisions, protect the less powerful party, and monitor for retaliation or preferential treatment. Rebecca eventually pauses the relationship, but Richmond never appears to activate a formal conflict-management process. Personal restraint is not a control.

From Personal Ownership to Stewardship

Rebecca’s leadership changes when she stops treating Richmond as property and begins treating it as an institution held in trust for others. In “Do the Right-est Thing” (Season 2, Episode 3), Sam protests sponsor Dubai Air because of its connection to environmental damage in Nigeria. Rebecca backs the players despite the commercial risk. She recognizes that sponsorship revenue does not outrank organizational values.

Her transformation is clearest in “International Break” (Season 3, Episode 10). Edwin Akufo invites elite club owners to join an exclusive league built around scarcity, control, and profit. Rebecca rejects the proposal by reminding the room that football belongs to the people whose lives and communities give it meaning. She chooses stakeholder legitimacy over a lucrative insiders’ arrangement.

In “So Long, Farewell” (Season 3, Episode 12), she completes that shift by selling 49 percent of Richmond to its supporters. The woman who once used the club as a weapon ultimately distributes part of its ownership to the community.

This is what ethical remediation should seek: not a return to the status quo, but a more accountable operating model.

Questions for CCOs

Rebecca’s journey should prompt five questions:

  1. Can an allegation against the CEO, founder, controlling shareholder, or board chair bypass that person and reach an independent decision-maker?
  2. Do conflict rules cover personal relationships, vendettas, reputational motives, and executive discretion, or only financial interests?
  3. When senior misconduct occurs, who controls the investigation, discipline, disclosure, and remediation plan?
  4. Does the board receive reliable information about culture and mission-critical risks without management filtering?
  5. Are remediation measures tested, documented, and sustained after the responsible leader apologizes?
  6. Rebecca Welton shows that leaders can change. Compliance must make that change governable. Trust is rebuilt when truth is followed by independent review, proportional accountability, control improvements, and evidence that the organization learned.

Next Up: Nate Shelley and Culture Risk

Rebecca’s failure begins with power concentrated at the top. Nate Shelley’s failure develops lower in the organization, where insecurity, humiliation, status, and unaddressed resentment turn a once-overlooked employee into a destructive manager and trusted insider. In Part 3, we will examine the warning signs Richmond missed, the consequences of promoting technical talent without preparing them to lead, and why a speak-up culture must detect harm committed by newly empowered employees as readily as misconduct committed by executives.

Categories
Blog

Ted Lasso Week: Part 1 – Ted Lasso: Ethical Leadership, Psychological Safety, and the Limits of Good Intentions

Season 4 of Ted Lasso has begun dropping (a new episode releases each Wednesday). Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over the next 5 blog posts, I will consider team owner Rebecca Welton, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 1, we begin with compliance lessons through the character of Ted Lasso.

Ted Lasso arrives at AFC Richmond with no meaningful knowledge of English football, a skeptical locker room, a hostile press, and an owner who secretly hired him to fail. On paper, he is an obvious control failure. In practice, he becomes the architect of Richmond’s cultural transformation.

For compliance professionals, that transformation is the point. Ted demonstrates how a leader can create trust, encourage candor, and turn values into daily behavior. He also demonstrates the limits of values-led leadership. Good intentions do not investigate misconduct. Empathy does not test a control. Forgiveness does not remediate a root cause.

The compliance lesson from Ted is not simply to “believe.” It is to build a culture in which accountability, information, controls, and oversight support belief.

Culture Is What the Leader Does

Ted’s first contribution is not tactical. It is behavioral. He learns names, asks questions, listens to people with little formal authority, and treats the kit man, Nate Shelley, as a colleague whose observations matter. In “Trent Crimm: The Independent” (Season 1, Episode 3), Ted recognizes that Jamie Tartt and other players are humiliating Nate. Rather than deliver a speech about respect and move on, Ted engages Roy Kent, the informal leader whose intervention can change locker-room conduct.

That is tone at the top connected to conduct in the middle. The DOJ Evaluation of Corporate Compliance Programs (ECCP) asks how senior leaders and managers have encouraged compliance through their words and actions. It states in part, “Beyond compliance structures, policies, and procedures, it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.”

The Principles of Federal Prosecution of Business Organizations (Justice Manual) likewise directs prosecutors to examine culture at all levels, including discipline, treatment of complaints, and incentives. 9.28.300 states in part that prosecutors shall consider “the pervasiveness of wrongdoing within the corporation, including the complicity in, or the condoning of, the wrongdoing by individuals in corporate management”. In Section 9-28.800, it directs the DOJ to review a “company’s culture of compliance”.

Ted understands instinctively that culture does not travel through posters. It travels through managers, peer leaders, everyday decisions, and the behavior an organization tolerates. A chief compliance officer can publish a code. Only operational leaders can make that code real during the meeting, on the sales call, and inside the locker room.

Psychological Safety Requires a Response System

Ted creates space for people to speak before they have status. He accepts tactical input from Nate, invites dissent from Coach Beard, and builds the Diamond Dogs as an informal forum for candid discussion. By “La Locker Room Aux Folles” (Season 3, Episode 9), Richmond can confront Colin Hughes’s sexuality and Isaac McAdoo’s reaction with empathy. Ted initially hears the team’s claim that Colin’s identity makes no difference, then corrects the underlying message: the team should care because Colin’s experience matters.

This is psychological safety in practice. Employees must be able to raise a concern, disclose vulnerability, or challenge a decision without humiliation or retaliation. Yet a compliance program needs more than an approachable leader. Equally importantly, a culture of Speak Up must be paired with a culture of Listen Up.

Richmond relies heavily on Ted’s availability and temperament. That is a strength while Ted is present and a key-person risk when he is absent. A mature speak-up program requires intake standards, anti-retaliation controls, escalation criteria, case tracking, trend analysis, and board reporting. An open door is valuable. It is not an operating system.

Accountability Must Apply to Stars and Friends

Ted’s strongest accountability moment comes in “Tan Lines” (Season 1, Episode 5), when he benches Jamie after the star player refuses to follow the team’s approach. Ted chooses collective standards over short-term performance. That is exactly the decision many organizations avoid when the employee at issue is a top salesperson, rainmaker, founder, or executive.

He is less decisive when loyalty clouds his judgment. In “All Apologies” (Season 1, Episode 9), Beard and Nate press Ted to confront Roy’s declining performance. Ted initially resists, even though the competitive risk is visible. He eventually has the necessary conversation and gives Roy a dignified path to support the team from the bench.

The contrast matters. DOJ asks whether discipline is applied consistently and whether the company tolerates misconduct by high performers. Compliance credibility collapses when consequences depend on revenue, rank, or personal affection. Ethical leadership is not the absence of hard decisions. It is the willingness to make them fair and explain the standard.

Forgiveness Is Not Remediation

Rebecca’s confession in “All Apologies” presents Ted’s greatest strength and clearest compliance blind spot. She admits that she hired him to fail, manipulated club decisions, and used people as instruments in her campaign against Rupert. Ted forgives her immediately.

At a human level, the scene is powerful. At an organizational level, forgiveness cannot close the matter. Richmond would still need to establish what happened, preserve evidence, identify affected decisions, assess financial and stakeholder harm, determine whether others participated, evaluate disclosure obligations, and strengthen governance.

The US Sentencing Guidelines require organizations to respond appropriately after misconduct and take steps to prevent recurrence. DOJ similarly focuses on root-cause analysis, remediation, and whether control improvements are tested. Ted offers grace, which can support rehabilitation. He does not create a record showing that the organization learned from the failure.

This distinction should matter to every CCO: mercy concerns the person; remediation concerns the institution. A company may do both. It cannot substitute one for the other.

Vulnerability Can Strengthen the Control Environment

Ted’s panic attacks show the cost of a culture in which even a supportive leader believes he must appear invulnerable. His attack during karaoke in “Make Rebecca Great Again” (Season 1, Episode 7) remains largely private. In “Headspace” and “Man City” (Season 2, Episodes 7 and 8), he finally engages with Dr. Sharon Fieldstone and begins addressing the trauma connected to his father’s suicide. After Nate leaks his panic attack to the press, Ted speaks honestly to the team and the public in “Inverting the Pyramid of Success” (Season 2, Episode 12).

Leaders retain legitimate medical privacy. The compliance point is not compelled disclosure. Organizations need trusted support channels, succession and contingency plans, and an environment where asking for help is not treated as weakness. Ted’s eventual candor reduces stigma. His earlier concealment creates an information vacuum that Nate weaponizes.

Within the COSO Internal Control Framework, Ted materially improves the control environment and information and communication. Richmond’s weakness is monitoring. Warning signs involving Nate, including humiliation of subordinates, resentment, and escalating hostility, do not reach a reliable response process before he leaks Ted’s health information and leaves for West Ham.

The Final Test Is Whether Culture Outlasts the Leader

By Season 3, Ted increasingly shifts from hero to system builder. “Sunflowers” and “The Strings That Bind Us” (Season 3, Episodes 6 and 7) show Richmond developing Total Football through shared learning, role flexibility, and trust. In “So Long, Farewell” (Season 3, Episode 12), Ted leaves, but Roy, Beard, Rebecca, Higgins, and the players can carry the culture forward.

That is the institutional test. A compliance program that depends on one charismatic executive is not sustainable. Caremark oversight principles require boards to make a good-faith effort to establish and monitor information and reporting systems, particularly around mission-critical risks, as the Delaware Supreme Court emphasized in Marchand v. Barnhill (the Bluebell Ice Cream case). Ted changes Richmond’s values. Governance must ensure that those values become repeatable processes, reliable information, and accountable decisions.

Practical Takeaways for CCOs 

Ted Lasso offers five questions for a CCO and compliance team:

  1. Do employees trust leaders, and can the organization demonstrate that concerns receive a consistent response?
  2. Are high performers held to the same behavioral standards as everyone else?
  3. When misconduct occurs, does forgiveness follow investigation and remediation rather than replace them?
  4. Are managers trained and monitored as culture carriers, especially after promotion?
  5. Would the speak-up culture and compliance program remain effective if a trusted leader departed tomorrow?

Ted’s enduring lesson is that ethical culture begins with human connection. Effective compliance begins there as well, but it cannot end there. Richmond becomes stronger when curiosity replaces judgment, candor replaces silence, and team standards replace individual entitlement. The next step for any real organization is to convert those behaviors into controls that can be tested, monitored, reported, and sustained.

Join us tomorrow in Part 2, as we turn to Rebecca Welton, whose decision to use AFC Richmond as an instrument of personal revenge reveals the risks created when concentrated authority operates without independent challenge. We will examine executive conflicts, institutional remediation, and Rebecca’s transformation from conflicted owner to accountable steward by requiring governance that can hold power to account.

Categories
Blog

Institutional Justice and Fairness in Compliance: Lessons from Star Trek’s ‘The Cloud Minders’

Institutional justice and institutional fairness are not abstract ideals; they are operational requirements in a corporate compliance program. They define how policies are enforced, how decisions are made, and how employees perceive the integrity of their workplace. One of the most vivid illustrations of the dangers of systemic injustice and perceived unfairness comes from Star Trek: The Original Series in “The Cloud Minders.”

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) reinforces this point: for a compliance program to be effective, it must not only exist on paper but also operate fairly in practice. The DOJ expects companies to show that they apply compliance processes consistently across the organization, regardless of seniority, revenue generation, or personal connections.

Why the DOJ Cares About Justice and Fairness in Compliance

In the ECCP, the DOJ focused on institutional justice and institutional fairness as key mandates for the compliance function. Why? It was rooted in practicality: a compliance program that is seen as biased or inconsistent will fail. Employees will not report misconduct, will hide mistakes, and will disengage from ethics initiatives.

Prosecutors know that when misconduct occurs in such an environment, it’s often a symptom of deeper cultural problems. That’s why, during investigations, they ask:

  • Are policies applied equally to all levels of the organization?
  • Is discipline consistent and documented?
  • Do employees believe the process is fair?
  • Has the company addressed the underlying causes of misconduct?

If the answers to these questions are unsatisfactory, the DOJ is more likely to view the compliance program as ineffective, regardless of its written policies.

The Tale 

The Enterprise is sent to the planet Ardana to collect zenite, a mineral needed to stop a plague on another world. Captain Kirk and Mr. Spock beam down to Stratos, a floating city inhabited by the planet’s elite, only to discover a deep societal divide. The surface of Ardana is worked by “Troglytes,” a laborer class forced to mine zenite under hazardous conditions, denied access to the comforts and education of Stratos.

The elites justify this arrangement as necessary for stability, while the Troglytes see it as systemic exploitation. The episode becomes a study in the consequences of entrenched inequality, distrust, and the refusal to address legitimate grievances, exactly the kinds of dynamics that can erode trust in a corporate compliance program if not addressed.

From this story, we can extract five compliance lessons on institutional justice and institutional fairness.

Lesson 1: Consistency in Standards Is Non-Negotiable

Illustrated by: Stratos leaders apply rules differently depending on social status. The elite enjoy cultural and political freedoms, while Troglytes face restrictions and harsher punishments for similar conduct.

Compliance Lesson. The DOJ has repeatedly emphasized that policies and disciplinary measures must be applied consistently. If employees perceive that “rainmakers” or executives receive lighter sanctions, or none at all, for policy violations, trust in the compliance function evaporates. In The Cloud Minders, the double standard deepens resentment and drives conflict, precisely what can happen inside a company when justice is selective.

Why It Matters to DOJ: Prosecutors evaluate whether discipline is enforced “consistently across the organization, regardless of position or power.” Inconsistency is a red flag that the program is a paper exercise rather than a living system.

What should you do?

  • Establish clear, documented disciplinary protocols.
  • Apply them uniformly, with oversight from the compliance function.
  • Communicate to the workforce that no one is above the rules.

Lesson 2: Address Root Causes, Not Just Symptoms

Illustrated by: The Troglytes’ performance and health are impaired because mining zenite exposes them to toxic vapors. The elites interpret this as proof of inferiority, ignoring the environmental cause.

Compliance Lesson. Organizations sometimes treat compliance failures as isolated misconduct rather than symptoms of deeper issues, such as inadequate training, unrealistic sales targets, or flawed incentive structures. In Ardana, fixing the air quality in the mines would have solved much of the productivity gap, just as fixing systemic drivers of noncompliance prevents repeat issues.

Why It Matters to DOJ: The DOJ looks for root cause analysis after misconduct. They want to see whether the company took corrective action to address systemic issues, not just discipline the individuals involved.

What should you do?

  • Investigate not only “who” did something wrong, but “why” it happened.
  • Use findings to improve processes, incentives, and controls.
  • Share non-confidential lessons learned with the workforce to demonstrate fairness and transparency.

Lesson 3: Perceived Fairness Matters as Much as Actual Fairness

Illustrated by: Even when Kirk offers protective gear to the Troglytes, they are slow to trust his intentions. Years of mistreatment have convinced them that promises from the elites are empty.

Compliance Parallel: Employees judge compliance programs not only by their design but by how fair they feel in practice. If people believe investigations are biased or that whistleblowers will be punished, they will avoid reporting, even if the official policy says otherwise. On Ardana, the lack of trust kept both sides from pursuing good-faith solutions—something corporate leaders must avoid at all costs.

Why It Matters to DOJ: Prosecutors assess whether employees trust the compliance program enough to use it. A hotline no one calls is not evidence of a healthy culture—it may be proof of fear or cynicism.

What should you do?

  • Publicize examples where issues were raised and resolved fairly.
  • Protect whistleblowers from retaliation and make that protection visible.
  • Use employee surveys to measure trust in compliance processes.

Lesson 4: Leadership Must Model Ethical Behavior

Illustrated by: Stratos’s leaders speak about justice and stability, but are unwilling to live under the same risks or hardships as the Troglytes. Their detachment from the reality of mining life fuels the unrest.

Compliance Lesson. Leaders who preach ethics but cut corners for themselves undermine institutional fairness. Employees take cues from the top; if executives are exempt from rules, the rest of the organization will follow suit. In The Cloud Minders, the Stratos elite’s credibility collapses because they refuse to share the burdens of those they govern, a mistake no corporate leadership team should make.

Why It Matters to DOJ: The DOJ examines “tone at the top” and “conduct at the middle.” They want to see that leadership’s actions match their words and that managers reinforce the message through daily decisions.

What should you do?

  • Ensure executives participate in the same training and certifications as all employees.
  • Make leadership accountable for compliance metrics.
  • Publicly acknowledge when senior leaders are held to account for violations.

Lesson 5: Dialogue and Inclusion Are Tools for Justice

Illustrated by: Spock approaches the Troglytes with genuine respect, listening to their grievances and acknowledging their intelligence. His willingness to engage earns him credibility that Stratos leaders lack.

Compliance Parallel: Institutional fairness is strengthened when employees feel heard and included in shaping solutions. This doesn’t mean every request can be granted, but listening and considering input builds trust. Just as Spock bridged the divide on Ardana, compliance leaders can bridge trust gaps by treating all stakeholders with respect and dignity.

Why It Matters to DOJ: A compliance program is stronger when it incorporates feedback from the workforce. The DOJ favors companies that regularly assess the program’s effectiveness through interviews, surveys, and focus groups.

What should you do?

  • Include employee representatives in policy review committees.
  • Hold listening sessions for employees and other stakeholders after major incidents or policy changes.
  • Act on feasible suggestions and explain when ideas can’t be implemented.

Practical Compliance Takeaways from The Cloud Minders

  1. Apply Rules Equally: Avoid double standards by holding everyone—from the C-suite to front-line staff—to the exact requirements.
  2. Investigate Root Causes: Fix systemic issues, not just individual mistakes.
  3. Build Trust in the Process: Ensure employees perceive the program as fair and protective.
  4. Lead by Example: Leadership must model the ethical behavior expected of all.
  5. Listen and Include: Use dialogue to bridge divides and strengthen buy-in.

Final ComplianceLog Reflections

The Cloud Minders is more than a parable about class division; it is a warning for any institution that neglects fairness and justice. In Ardana, injustice created resentment, distrust, and rebellion. In a corporation, those same dynamics can lead to silent disengagement, hidden misconduct, and public scandal.

The DOJ’s message is clear: fairness and justice are not optional add-ons to compliance; they are the foundation of a program that works. As compliance leaders, our role is to be the “Spock” in the room, listening, respecting, and bridging divides while ensuring that the rules are fair, transparent, and consistently applied.

When we do that, we do not just comply with the DOJ’s expectations; we build organizations where people trust the system enough to make it work.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?
Categories
Blog

Connected Compliance: Part 4 – From Hotline to Trust

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust them enough to speak. In Blog Post 1, we considered communication as a compliance control. Blog Post 2 showed how operational signals create a dynamic risk radar. In Blog Post 3, we explained why every investigation is a test of governance and culture. This final installment examines the front door to the entire system: the reporting program.

A company can buy a hotline in an afternoon. It cannot buy employee trust. That distinction is the starting point for an effective whistleblower program. The platform, policy, telephone number, and case-management system are necessary infrastructure. They are not the program. The real program is the experience an employee anticipates before reporting and receives after doing so.

The answers do not come primarily from policy language. They come from what employees see happen to colleagues who raise concerns. A mishandled report can teach an entire workplace that silence is safer.

The First Report Is the Real Program Test

One of the easiest ways to discourage reporting is to do a poor job after a report arrives. An ignored allegation, confidentiality breach, unexplained delay, dismissive intake, or retaliation can do more damage than an outdated hotline poster.

This is why the reporting program and investigation process cannot be separated. Intake creates an expectation of action. Investigation determines whether that expectation is met. Follow-up determines what the reporter tells others about the experience. The process should begin with prompt acknowledgment. Whenever possible, a trained person should thank the reporter, gather clarifying information, explain next steps, and set realistic expectations. An automated receipt confirms that the technology worked. Personal contact demonstrates that the organization is listening.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places confidential reporting within its evaluation of whether a compliance program is well designed. The 2024 Evaluation of Corporate Compliance Programs (ECCP) calls for an “efficient and trusted mechanism” for anonymous or confidential reports. The two words that matter most are efficient and trusted.

Efficiency requires accessible channels, proper routing, risk-based triage, qualified investigators, timely handling, documentation, and accountable remediation. Trust requires employees to believe that the company will take concerns seriously, limit information sharing, prevent retaliation, and respond consistently regardless of rank or commercial importance.

The DOJ asks whether employees know about the reporting mechanism, feel comfortable using it, and are willing to report misconduct. It also asks a difficult question: “Conversely, does the company use practices that tend to chill such reporting?” That directs compliance professionals beyond the hotline itself. Confidentiality agreements, manager behavior, performance systems, investigation delays, incentive structures, employment actions, and prior reporter experiences can all affect willingness to speak. The DOJ further asks whether the company tests hotline effectiveness by tracking a report from intake through disposition. This makes end-to-end testing a governance exercise, not a vendor-management task.

Design Channels Around the Workforce

A reporting system designed for headquarters may fail the people most likely to observe operational risk. Field employees, shift workers, remote personnel, contractors, and employees with limited computer access need channels that fit how they work. The answer is a meaningful choice. A mature program may include a telephone hotline, web portal, mobile access, email, QR codes, and in-person reporting to compliance, human resources, legal, internal audit, security, or management. Channels should be available in appropriate languages and accessible to employees with disabilities.

Placement matters. A QR code on an identification badge, break-room poster, or work-issued device may be more useful than a buried intranet link. A telephone line remains essential for employees who prefer to speak or lack reliable digital access. Many employees will first approach someone they trust. Compliance should analyze channel use by location, function, shift, language, and workforce type. A channel with no reports is not necessarily evidence that the location has no concerns. It may be evidence that the channel is unknown, inaccessible, or distrusted.

Make Speaking Up a Leadership Behavior

Tone at the top remains essential, but the employee’s immediate supervisor often controls the reporting climate. A chief executive may celebrate integrity while a frontline manager rolls their eyes, interrupts the employee, demands names, or warns that a report will hurt the team. The manager’s reaction becomes the company’s culture in that moment.

Managers need specific training. They should listen without investigating on the spot, avoid promises they cannot keep, preserve information, escalate promptly, and reinforce anti-retaliation expectations. A concern does not have to arrive through the hotline to require action. Leadership modeling should be visible. When leaders invite dissent, respond calmly to bad news, thank employees who identify risk, and communicate anonymized lessons, they show that speaking up protects the business. Regular field presence builds relationships, reveals access barriers, and provides context unavailable from a dashboard.

Tell the Truth About Confidentiality

Employees often use anonymity and confidentiality interchangeably, but they are different. An anonymous reporter does not disclose identity. Confidentiality means identity and related information are limited to people with a legitimate need to know. The company should never promise absolute secrecy when the facts make it impossible. In a small team, subject matter, timing, or witnesses may reveal who raised the concern. Overpromising creates a second breach of trust.

The better approach is candor. Explain that information will be restricted as far as reasonably possible, that some disclosure may be necessary to investigate fairly or meet legal obligations, and that retaliation is prohibited. Use role-based access, careful case notes, secure records, disciplined interview planning, and clear need-to-know rules. Confidentiality is not a slogan. It is an information-control process.

Communicate Without Compromising the Investigation

Silence during a long investigation can feel like indifference. Reporters do not need access to witness statements or confidential personnel decisions, but they do need evidence that the matter remains active. Set a communication cadence based on case risk and expected duration. Provide updates even when the update is that the review continues. Explain delays where appropriate, remind the reporter how to provide additional information, and repeat the anti-retaliation contact route.

At closure, confirm that the concern was reviewed and addressed as appropriate. Thank the reporter and reinforce anti-retaliation protection. The company may be unable to disclose findings or discipline, but it can close the human loop.

Treat Anti-Retaliation as an Active Control

An anti-retaliation policy is necessary, but it is not self-executing. Retaliation can be direct, such as termination, demotion, or loss of pay. It can also be subtle: exclusion from meetings, undesirable shifts, lost development opportunities, hostile supervision, damaged reputation, or social isolation. The company should assess retaliation risk throughout the matter. Compliance and human resources should preserve a baseline of the reporter’s role and treatment, monitor employment actions, schedule check-ins, and provide an escalation route outside the normal chain. Monitoring should continue after closure.

Protection does not mean immunity from legitimate performance management. It means employment decisions affecting a reporter receive appropriate review, are supported by contemporaneous evidence, and are not influenced by protected activity. When retaliation occurs, discipline should be prompt and visible enough, within confidentiality limits, to reinforce the rule.

Do Not Discredit the Difficult Messenger

Serial reporters and incomplete reports create operational challenges, but frequency, frustration, or poor drafting does not determine whether an allegation is true. Each concern should be assessed on its merits. A sparse report may still contain breadcrumbs. Investigators can review organizational charts, personnel changes, transactions, prior complaints, and control data before concluding that the matter cannot proceed. Multiple reports may reveal an unresolved environmental problem or weak earlier investigations.

Motivation can be relevant to credibility, but it should not replace evidence. Labeling someone a troublemaker is often an easy way to miss a difficult fact and an effective way to chill the next reporter.

Measure Trust, Not Just Volume

Hotline volume alone is a weak measure. A low number may reflect a healthy culture, a small risk population, inaccessible channels, fear, or lack of awareness. A rising number may reflect deteriorating conduct or growing confidence in the program. A useful dashboard combines volume with context: awareness and comfort survey results, reports by workforce segment, intake-to-acknowledgment time, triage time, case aging by risk, substantiation patterns, repeat allegations, reporter-update timeliness, retaliation concerns, remediation completion, and employee feedback after closure.

Compliance should test the entire system. Submit a controlled report, trace routing and access, review acknowledgments, confirm escalation rules, examine investigation handoffs, and verify closure and retention. Analyze whether reporting data changes risk assessment, controls, training, and resources. The objective is evidence that the program learns.

Closing the Connected Compliance Program

This four-part blog post series began with communication because employees cannot use a system they do not understand. It moved to dynamic risk assessment because organizations must recognize changing signals. It then examined investigations because allegations require independent facts, accountability, and remediation. Today we discussed whistleblower programs because none of those capabilities matter if people do not trust the company enough to speak. Join us tomorrow in our concluding Part 5 for a deeper discussion of how compliance truly is connected.

The connected compliance program is a loop. Communication builds awareness. Reporting supplies risk intelligence. Investigation converts allegations into reliable findings. Remediation improves controls. Feedback strengthens culture and makes future reporting more likely.

For the compliance professional, the final test is not whether the hotline exists. It is whether an employee facing a difficult choice believes that raising a concern will protect the organization, lead to a credible response, and not cost that employee a career. That is how a reporting channel becomes a trusted control and how culture becomes credibility.

Bonus Questions for Compliance Professionals

  1. Can every workforce segment access a reporting channel during the way and hours in which it actually works?
  2. Do employees know the available channels, understand external reporting rights, and say they feel comfortable using them?
  3. What happens during the first 24 hours after a report arrives, and who is accountable for acknowledgment, triage, and protection?
  4. Are managers trained to recognize and escalate concerns received outside formal reporting channels?
  5. Can the company show how reporter identity and case information are restricted to people with a legitimate need to know?
  6. How does the organization monitor direct and subtle retaliation during and after an investigation?
  7. Does the company communicate appropriately with reporters when an investigation is delayed and when it closes?
  8. Are serial, anonymous, and incomplete reports assessed on evidence and context rather than labels or assumptions?
  9. What reporting data has changed the risk assessment, controls, training, discipline, or resource allocation during the past year?
  10. Has the company recently tested one report from submission through routing, investigation, remediation, feedback, and retention?
Categories
Blog

Connected Compliance: Part 3 – Why Every Investigation Is a Culture Opportunity for Your Organization

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. In Blog 1, we examined communication as a compliance control. In Blog Post 2, we showed how those communications and other operational signals create a dynamic risk radar. Today in Blog Post 3, we ask what happens when a signal becomes an allegation as an introduction to how and why every investigation can be an opportunity to both pressure-test and build out your culture.

A hotline report, audit exception, control override, manager escalation, or unusual transaction may begin as just another compliance signal; once the company decides it requires investigation, the stakes change. The organization must establish what happened, protect people and evidence, make defensible decisions, and strengthen the program.

That makes an investigation more than a fact-finding exercise. It is a visible test of governance. Employees watch who is interviewed, how leaders behave, whether the process appears fair, whether high performers receive special treatment, and whether the company acts when misconduct is substantiated. Details should remain confidential, but the organization cannot erase the cultural impact. Every investigation sends a message.

Credibility Is Built Before the First Interview

The strongest investigations begin with disciplined triage. Before scheduling interviews or collecting data, the company should first identify the immediate risks that require action. Is anyone’s health or safety at risk? Could misconduct be continuing? Is evidence vulnerable? Does the allegation implicate financial reporting, government contracting, sanctions, corruption, product integrity, cybersecurity, privacy, or another obligation requiring prompt escalation?

Containment is not a conclusion. Suspending access, preserving records, pausing a payment, separating employees, or protecting a reporter may be necessary while the facts remain unresolved. The decision should be proportionate, documented, and revisited as evidence develops.

Triage should identify the functions that need to participate without turning the matter into a committee project. One person should own the process, one decision-maker should approve material scope changes, and communication lines should be defined at the outset.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places investigations squarely inside its test of program effectiveness. The 2024 Evaluation of Corporate Compliance Programs (ECCP) asks, “How does the company ensure that investigations are properly scoped?” It then asks what steps the company takes to ensure investigations are “independent, objective, appropriately conducted, and properly documented,” as well as how the company determines who should conduct an investigation.

Those words provide a practical quality standard. Proper scope means the investigation addresses the allegation and reasonably connected issues without drifting into an unlimited inquiry. Independence means the investigator is free from conflicts and improper business pressure. Objectivity requires a search for facts that may confirm or disprove the allegation. Appropriate conduct includes lawful evidence collection, fair treatment of witnesses, and proportionate methods. Proper documentation allows the company to explain what it did, why it did it, and how it reached its conclusions.

DOJ also asks whether the company applies timing metrics, monitors outcomes, and ensures accountability for findings and recommendations. Later, the ECCP describes a working program as having an “appropriately funded mechanism for the timely and thorough investigations” of allegations or suspicions of misconduct. The point is not speed at any cost. It is disciplined responsiveness supported by adequate resources.

Scope the Question, Not the Desired Answer

A written investigation plan should define the allegation, relevant policy or legal issues, time period, business units, people, data sources, immediate risks, and proposed work. It should identify the standard used to reach findings and the expected form of the report. It should also record what remains outside scope.

The plan must be flexible. Evidence may reveal additional conduct, another geography, a control failure, or management involvement. The investigator should document the new information, assess its materiality, identify any additional resources or conflicts, and obtain appropriate approval for expansion.

This discipline prevents a scope narrowed to contain the issue and investigation drift that delays a conclusion. A credible process follows the evidence while preserving a clear line of sight to the original allegation.

Choose the Investigator for the Risk

Not every matter requires outside counsel, and not every matter should remain inside the company. The choice should turn on credibility and capability, not habit. Internal investigators may understand the business and manage routine matters efficiently. External counsel or specialists may be appropriate when allegations involve senior leadership, significant legal exposure, government reporting, material financial impact, technical evidence, cross-border restrictions, litigation, or concerns about internal independence.

The company should establish decision criteria before a crisis. Who determines whether compliance, legal, human resources, internal audit, security, or outside counsel will lead? What conflicts require recusal? When does the audit committee or another independent authority oversee the matter? Which technical experts may be needed, and how will their work be directed? An outside law firm’s letterhead does not create independence. It comes from clear authority, freedom from interference, sufficient resources, access to evidence, and an escalation route when investigators encounter resistance.

Protect the Privilege with Precision

The attorney-client privilege can protect confidential communications seeking or providing legal advice, but an investigation is not privileged simply because a lawyer attends. Privilege rules are jurisdiction-specific, and careless circulation, unclear roles, or unnecessary third-party involvement can create risk.

At the beginning, counsel should define the legal purpose, identify the client and team, establish communication and documentation protocols, and explain confidentiality expectations. Team members should know which communications seek legal advice, where documents will be stored, and who may receive them. Over-labeling every document as privileged does not create stronger protection. It can undermine discipline and complicate later disclosure decisions. The better approach is to use privilege deliberately, involve counsel where legal advice is genuinely required, and preserve a reliable factual record that supports the company’s decisions.

Treat Witnesses as People, Not Evidence Containers

Witness interviews often determine whether employees experience the investigation as fair. The investigator should explain the purpose of the interview, the investigator’s role, expectations for truthful cooperation, applicable confidentiality limits, and the company’s prohibition against retaliation. The interviewer should not promise complete secrecy, prejudge the allegation, coach testimony, or imply that raising concerns created the problem.

Respect improves evidence quality. Employees are more likely to provide complete information when questions are neutral, and the interviewer listens before challenging inconsistencies. Cultural, language, disability, and power dynamics may affect participation and should be addressed thoughtfully.

Anti-retaliation protection requires more than an opening statement. Compliance and human resources should identify foreseeable risks of retaliation, monitor employment actions and workplace behavior, provide a safe escalation channel, and respond quickly to concerns. Retaliation may be subtle: exclusion, schedule changes, lost opportunities, hostile supervision, or reputational harm. A technically sound investigation can still damage culture if the reporter or witnesses pay a price for participating.

Preserve Evidence and Measure the Right Clock

Evidence management must begin early. Relevant emails, collaboration messages, mobile communications, transaction records, system logs, personnel documents, and physical evidence all require preservation. Collection should follow applicable law, privacy requirements, company policy, and forensic protocols. The team should document sources, custodians, dates, gaps, and chain of custody where necessary. Always remember the first question the DOJ will ask after you self-disclose is, “Do you have the documents tied down?

Timeliness should be measured, but the metric must support quality. Useful measures include time from intake to triage, time to investigator assignment, aging by risk category, days awaiting business action, time from finding to remediation, and overdue reporter updates. A single average completion target can create pressure to close simple matters quickly or rush complex ones. Status reviews should ask what is delaying the matter, whether scope remains appropriate, whether interim protections still work, and whether new risks require escalation. The objective is a process that explains delay, removes bottlenecks, and prioritizes higher-consequence matters.

Move Beyond the Bad Actor

An investigation that identifies who violated a policy but not why the system allowed it has completed only half the work. DOJ asks whether investigations identify “root causes, system vulnerabilities, and accountability lapses,” including those involving supervisors and senior executives.

Root-cause analysis should examine incentives, performance pressure, control design, access rights, training, supervision, third-party oversight, data availability, prior warnings, and the consistency of discipline. Did the policy prohibit the conduct but the workflow reward it? Did a manager ignore a red flag? Did an exception process become the normal process? Did earlier reports reveal the same weakness?

The answer should drive remediation, including discipline, control redesign, policy revision, monitoring, training, leadership changes, third-party action, disclosure, or resource reallocation. Each action needs an owner, deadline, evidence, and testing. Otherwise, the investigation becomes a historical record rather than a compliance control.

Close the Case and the Cultural Loop

A reasoned closure record should state the allegation, scope, steps taken, evidence considered, credibility analysis, findings, and approved response. Discipline should be consistent across ranks and levels of commercial importance, with deviations documented. Investigation data should then feed the risk assessment, training plan, control testing, and management reporting.

The reporting party also matters. Without disclosing confidential personnel information, the company can acknowledge that the review is complete, thank the person for speaking up, restate anti-retaliation protections, and provide a contact for further concerns. Silence after intake encourages employees to conclude that nothing happened.

This is the connection across the series. Communication brings information into the program. Dynamic risk assessment helps the company recognize its significance. Investigation converts allegations into facts, accountability, and learning. Therefore, join us for Part 4 tomorrow, as we will demonstrate the front door to that process: how an effective whistleblower program gives employees safe, accessible ways to report and confidence that speaking up will lead to credible follow-through.

Bonus Questions for Compliance Professionals

  1. Who has authority to triage an allegation and order immediate containment or preservation measures?
  2. What written criteria determine who should lead an investigation and when independent oversight or outside counsel is required?
  3. Can the company show that recent investigations were properly scoped, independent, objective, timely, and documented?
  4. Which stages of the investigation create the greatest delays, and are those delays risk-based or simply unmanaged?
  5. How does the organization monitor subtle retaliation against reporters and witnesses?
  6. Do investigation reports identify control failures, incentives, supervisory accountability, and root causes in addition to individual misconduct?
  7. What evidence shows that completed investigations changed controls, training, discipline, resources, or risk assessment?
  8. How does the company communicate appropriate closure to reporters without compromising confidentiality?