Categories
Blog

The NBA/Clippers Investigation: Part 5 – Lessons for CCOs and Boards

The ultimate measure of a compliance program is whether it can constrain the people the organization believes it cannot afford to disappoint. Most compliance programs are designed for ordinary decisions made by ordinary employees. The real danger lies in extraordinary decisions involving people with unusual economic power. Today we conclude with lessons learned.

They may be founders, controlling owners, senior executives, rainmakers, celebrity endorsers, critical customers, or star performers. Their value to the organization can become a reason to bypass controls, reinterpret rules, or treat prohibited requests as business problems requiring creative solutions.

The investigation into the LA Clippers and Kawhi Leonard demonstrates what happens when that pressure enters the commercial ecosystem. The independent investigators’ report (Wachtell Report) concluded that Clippers leaders helped create outside-income opportunities for Leonard through companies doing business with the team, linked vendor business to endorsement arrangements, paid impermissible personal expenses, and failed to report prohibited demands.

The lessons reach well beyond professional sports. They reach into all businesses. Finally, they apply wherever commercial urgency can overwhelm governance.

Lesson One: Power Is a Compliance Risk Factor

Traditional risk assessments organize risk by geography, business unit, transaction type, or regulatory subject. They often overlook individual power.

Organizations should identify people whose economic importance, ownership position, revenue contribution, reputation, or personal relationship with leadership could weaken ordinary controls. This is not an accusation against those individuals. It is recognition that employees may respond differently when a request comes from someone perceived as indispensable.

The DOJ’s Evaluation of Corporate Compliance Programs asks whether risk management is proactive, whether resources follow risk, and whether senior leaders persist in their commitment to compliance when facing competing business objectives. A power-risk assessment helps answer those questions.

Lesson Two: Prior Misconduct Must Change the System

The Clippers had a prior circumvention violation. The NBA later investigated improper demands associated with Leonard’s 2019 free agency, established a reporting requirement, and trained the team’s senior leadership. Yet the Wachtell Report concluded that similar risks materialized again.

Training is not remediation unless the organization can demonstrate changed behavior. After an incident, compliance should identify the root cause, assign control owners, establish deadlines, test effectiveness, and report results to the board. The inquiry should continue until the organization can show it has materially reduced the opportunity for recurrence. DOJ expressly asks whether companies incorporate lessons from their own misconduct and from similar problems at peer organizations. The Organizational Sentencing Guidelines likewise make prior history relevant to risk assessment, program design, and organizational culpability.

Lesson Three: Compliance Must Have Independent Authority

The question is not whether the organization employs compliance professionals. It is whether those professionals can challenge a powerful executive, suspend a transaction, obtain complete information, and reach an independent board committee without management permission.

The DOJ evaluates whether compliance has adequate qualifications, seniority, stature, resources, autonomy, and direct board access. These are operational requirements, not organizational-chart preferences. A CCO who can advise but cannot stop or escalate is not empowered. A compliance committee dominated by the executives sponsoring the transaction is not independent. A board that receives only management-filtered information is not exercising informed oversight.

Lesson Four: Follow the Entire Commercial Relationship

The Clippers investigation involved sponsorships, consulting agreements, sustainability services, an owner’s investment, player endorsements, vendor payments, and personal expenses. Reviewing each transaction separately could obscure the common purpose. Compliance needs a consolidated view of the relationship. That requires common identifiers across procurement, contracts, accounts payable, expenses, conflict disclosures, gifts, sponsorships, and third-party systems.

The most useful question may be simple: What other business do we have with this person or entity? Make that question mandatory when a transaction involves a significant vendor, executive relationship, personal investment, public official, customer representative, agent, or other high-risk beneficiary.

Lesson Five: Test Economic Substance

According to the Wachtell Report, several endorsement arrangements had unusual economics, limited performance obligations, little public activation, and compressed negotiation timelines. Consulting agreements involved substantial advance payments. Separate agreements contained matching or closely connected amounts. The COSO Internal Control–Integrated Framework reminds organizations that controls support compliance and operational objectives, not simply accurate accounting. A payment can be correctly recorded and still serve an improper purpose.

Controls should test business rationale, market value, deliverables, proof of performance, payment timing, ultimate beneficiary, and connections to other transactions. Internal audit should be authorized to ask whether a contract makes commercial sense, not merely whether an authorized person signed it.

Lesson Six: Mandatory Reporting Requires a Closed Loop

The Wachtell Report found that Clippers leaders did not report improper solicitations made on Leonard’s behalf, despite a rule requiring reporting even if a request was rejected. A mandatory reporting policy needs more than a sentence in the code of conduct. It requires defined triggers, responsible owners, escalation deadlines, documentation, non-retaliation protection, and verification that the report reached the required recipient.

Organizations should test the reporting control. Present leaders with realistic scenarios and ask what they would do, whom they would contact, and how quickly. If answers vary, the control is not operating reliably.

Lesson Seven: Red Flags Must Reach Someone Who Can Act

The Wachtell Report described unusual payment structures, internal concern about the Forum transaction, resistance from Aspiration executives, and explicit communications linking Clippers business to Leonard’s endorsement agreement. Red flags do not protect an organization merely because they exist in an email archive. They must reach a person with authority, independence, and responsibility to act.

Boards should identify mission-critical compliance risks and establish reporting systems that deliver meaningful information. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes the board’s obligation to make a good-faith effort to establish and monitor reporting systems for central compliance risks. That does not make every control failure a Caremark violation. It does mean that silence at the board level is not a defensible oversight model.

Lesson Eight: Investigation Conduct Is Compliance Conduct

Investigators assessed not only the underlying transactions but also witness credibility and cooperation. They distinguished between witnesses who accepted responsibility and those whose accounts conflicted with documents or changed over time.

Organizations should prepare for investigations before a crisis. Document preservation, witness instructions, privilege protocols, anti-retaliation protections, escalation duties, and cooperation standards should already be in place. Outside counsel should defend legitimate interests without impairing the organization’s ability to learn the truth. An investigation is not solely a litigation event. It tests culture and governance.

Lesson Nine: Accountability Must Reach Supervisors

The NBA’s penalties included a $30 million organizational fine, forfeiture of five first-round draft picks, individual suspensions, a payment by Leonard, a five-year restriction on Robertson, and a five-year compliance and monitoring program.

The sanctions reached individuals based on different forms of responsibility, including direct conduct, approval, supervision, and organizational leadership. Corporate consequence management should do the same. Employees who participate directly should be accountable, but so should managers who ignore red flags, approve unsupported exceptions, or fail to supervise. Enforce compliance consistently, regardless of commercial value or title.

Lesson Ten: The Board Must Oversee the Pressure Points

Boards do not need to approve every sponsorship, vendor agreement, or expense report. They do need visibility into the areas where incentives, power, and mission-critical compliance risks intersect.

The board should receive reporting on high-risk transactions, control overrides, related-party relationships, significant investigations, repeated policy violations, executive discipline, and remediation testing. It should meet privately with the CCO and internal audit leader and confirm both functions have the information and resources they need. Board oversight is not passive dashboard receipt. It is an informed challenge followed by documented action.

Practical Takeaways: A 90-Day Agenda

CCOs and risk leaders can translate these lessons into action:

  • Identify the organization’s most powerful internal and external stakeholders and assess where their requests could bypass controls.
  • Review prior investigations, violations, and audit findings to confirm that remediation was implemented and tested.
  • Map all relationships involving high-risk vendors, personal investments, sponsorships, consulting arrangements, and individual beneficiaries.
  • Establish independent review for transactions involving controlling owners, senior executives, or conflicts of interest.
  • Test procurement, payment, expense, and reporting controls using real transaction data.
  • Give compliance documented stop-work and escalation authority.
  • Define investigation cooperation and consequence-management standards before the next allegation.
  • Provide the board with targeted reporting on control overrides, repeat issues, and high-risk relationships.

The final lesson from the Clippers investigation is straightforward. Compliance fails when the organization treats the rule as an obstacle and the desired outcome as nonnegotiable. An effective program reverses that order. The rule defines the boundary, and the business must operate within it. The true measure of compliance is whether the organization can say no when yes would be more profitable, more convenient, or more popular. That is where governance becomes real.

Categories
Blog

The Clippers Investigation: Part 4 – Consequence Management at the Top

The Clippers penalties demonstrate that discipline is not the end of a compliance process. They are a public test of whether rules apply to powerful people. The Clippers investigation demonstrates why conflict controls must follow influence, economic benefit, and interconnected transactions, not merely financial ownership. In this Part 4 of a five-part series, we consider the consequences of cheating and not following the rules and regulations your organization agrees to comply with going forward. Every organization claims that no one is above the rules. Consequence management determines whether that statement is true.

The test does not come when a junior employee commits an obvious policy violation. It comes when the conduct involves a founder, controlling owner, senior executive, star performer, or other person viewed as essential to the business. The investigation into the LA Clippers and Kawhi Leonard presents that test in unusually clear terms. The independent investigators’ report of the Clippers’ NBA salary cap circumvention (Wachtell Report) attributed primary responsibility to Clippers owner Steve Ballmer, President of Business Operations Gillian Zucker, and President of Basketball Operations Lawrence Frank. It also found violations by Leonard through the conduct of his uncle and then-business manager, Dennis Robertson (Uncle Dennis).

The NBA responded with organizational, financial, individual, competitive, and monitoring consequences. For compliance professionals, the case provides a framework for considering who should be held accountable, for what conduct, and through what mechanism.

From Punishment to Consequence Management

Punishment looks backward. It asks what sanction should follow a violation. Consequence management is broader. It identifies misconduct, investigates responsibility, calibrates discipline, addresses supervisory failures, remediates control weaknesses, and communicates the organization’s expectations. All of this brings me to one of my favorite compliance phrases: consequence management.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) introduces consequence management procedures as procedures to identify, investigate, discipline, and remediate violations of law, regulation, or policy. It goes on to state that every organization must enforce them consistently across the organization and ensure the procedures are commensurate with the violations. It concludesProsecutors should also assess the extent to which the company’s communications convey to its employees that unethical conduct will not be tolerated and will bring swift consequences, regardless of the employee’s position or title

Consequence Calibration

The report provides several categories for assessing responsibility.

  1. Direct participation. Investigators concluded that Zucker initiated, facilitated, and induced endorsement agreements involving Leonard and four Clippers business partners. They found that Ballmer knowingly sought to help Leonard obtain outside income and approved the Forum agreement after learning that Aspiration had tied it to Leonard’s endorsement arrangement. Frank conveyed Robertson’s demands and approved impermissible personal expenses.
  2. Supervisory responsibility. The report concluded that Ballmer failed to supervise the organization’s most senior business executive and failed to create conditions supporting compliance with the circumvention rules.
  3. Reporting responsibility. Investigators found that Ballmer, Zucker, and Frank did not report Robertson’s improper demands, despite an NBA rule requiring those reports even when the solicitation was rejected.
  4. Personal or represented conduct. The report concluded that Leonard, through Robertson, pressured the team to help obtain outside income and failed to reimburse certain personal expenses. Robertson allegedly made the demands and applied the pressure.

A defensible consequence decision should map each individual to the conduct, knowledge, authority, benefit, supervisory obligation, and missed opportunity to intervene. Titles alone should neither establish nor eliminate responsibility.

Credibility and Cooperation Matter

The report did something particularly useful for compliance officers: it distinguished among witness behavior. Investigators wrote that Zucker made statements inconsistent with contemporaneous documents and other witnesses, professed limited recollection on significant issues, placed responsibility on subordinates, and provided inconsistent versions of events.

By contrast, they reported that Frank discussed his conduct openly, recalled important details, accepted responsibility for subordinates, and remained generally consistent across interviews. The investigators stated that cooperation and credibility, or their absence, should factor into determining consequences.

Cooperation does not erase underlying conduct. It should, however, affect how consequences are calibrated. An employee who preserves documents, provides candid information, accepts responsibility, and assists remediation presents a different risk from one who misleads investigators or shifts blame.

The organization should define cooperation before an investigation begins. Employees should understand that cooperation requires truthful, complete, and timely responses; preserving relevant information; correcting prior inaccuracies; and no retaliation or interference. It does not require surrendering legitimate legal rights.

Prior Misconduct Changes the Analysis

The Clippers had previously been penalized for a salary-cap circumvention violation involving an endorsement opportunity. The NBA had also investigated demands made during Leonard’s 2019 free agency and provided specific training to Clippers leaders.

Prior history matters because it changes what the organization and its leaders reasonably should have done. A first incident may reveal an unrecognized risk. A repeated incident following investigation, rule clarification, and training raises questions about culture, supervision, remediation, and willingness to comply.

The Sentencing Guidelines identify prior organizational history as relevant to culpability and direct organizations to consider similar misconduct when designing an effective program. DOJ likewise asks whether policies, training, controls, and risk assessments incorporate lessons from prior incidents.

Remediation that ends with training is incomplete. The organization must test whether behavior, decision rights, escalation pathways, and controls changed.

The NBA’s Consequence Framework

The NBA’s official action included multiple forms of individual accountability. The box score of individual consequences reads as follows:

Person Relationship Consequence
Steve Ballmer Owner: LA Clippers Fine and one-year ban
Gillian Zucker Clippers President of Business Operations One-year unpaid suspension
Lawrence Frank Clippers President of Basketball Operations 6-month Unpaid Suspension
Kawhi Leonard Clipper Player $700K fine
Uncle Dennis Leonard Representative 5-Year Ban from NBA

These measures address different risks. For corporate compliance programs, the equivalent toolkit may include termination, suspension, bonus reduction, clawbacks where legally available, promotion restrictions, written warnings, removal of approval authority, enhanced supervision, vendor termination, and mandatory remediation. Consequences need not be identical, but the process must be consistent. Consistency means applying the same decision factors to similarly situated people. It does not mean imposing the same outcome regardless of role, intent, cooperation, history, or responsibility.

Practical Takeaways

CCOs, human resources leaders, and boards should consider the following:

  • Adopt written consequence-management procedures before a significant investigation occurs.
  • Use a consistent decision matrix covering conduct, intent, seniority, authority, benefit, cooperation, prior history, and supervisory responsibility.
  • Separate factual findings from disciplinary decisions, and ensure decision-makers understand the evidentiary record.
  • Document why similarly situated individuals received similar or different outcomes.
  • Apply financial consequences where permitted and align future compensation with compliance performance.
  • Communicate substantiated outcomes internally with enough detail to reinforce expectations while respecting legal and privacy constraints.
  • Track disciplinary data by level, function, geography, and type of misconduct to identify inconsistency.
  • Require independent board oversight when senior management is implicated.

Consequence management is where culture becomes measurable. If the organization protects its most powerful people, employees will understand that performance outranks integrity. If it applies a fair, independent, and proportionate process, employees will understand that compliance is part of how the business operates.

In our final blog post, we will bring the series together and develop a practical framework for CCOs, boards, and risk leaders seeking to build a compliance program that can say no to the star.

Categories
Blog

The NBA/Clippers Investigation: Part 3 – Paper Compliance Is Not an Internal Control: Substance, Procurement, and the Audit Trail

The Clippers investigation shows why contracts, approvals, and carefully drafted emails cannot substitute for controls that test economic reality. In Part 3 of a five-part series, we explore why and how a transaction can have a contract, an approval, an invoice, and an email trail and still pose a serious compliance problem. Documentation proves that a process occurred. It does not prove that the process was legitimate.

That distinction sits at the center of the investigation into the LA Clippers and Kawhi Leonard. The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement arrangements between Leonard and four companies doing business with the team, induced those arrangements by offering business to the companies, paid impermissible personal expenses, and failed to meet improper demands made on Leonard’s behalf.

The alleged conduct crossed organizational boundaries. It touched business operations, basketball operations, procurement, sponsorships, consulting arrangements, accounts payable, expenses, legal review, and executive management. That makes this an internal controls case.

The Difference Between Evidence and Control

One of the report’s most important findings concerned introduction emails sent by Clippers President of Business Operations Gillian Zucker. The emails were written as if Boingo, Daktronics, Lockton, and later Aspiration had requested introductions to Leonard’s representatives. NBA rules permitted a narrow response when a commercial partner initiated such a request. They did not permit the team to create the opportunity for the player. The investigators concluded that the emails did not reflect the true sequence of events and, in Aspiration’s case, were created after deal development was already underway.

This is a classic paper-compliance problem. The communication used the language of the rule without satisfying its substance. A control cannot merely ask whether an introduction email contains the approved wording. It must test who initiated the contact, what discussions preceded the email, who proposed the economics, and whether team personnel remained involved afterward. Checklists confirm the form. Effective controls challenge reality.

Fragmented Transactions Hid a Common Purpose

The Wachtell Report described multiple agreements that could have appeared unrelated in separate systems. Vendors entered consulting or services agreements with the Clippers while also entering endorsement agreements with Leonard. Aspiration had sponsorship, sustainability, investment, forum, and player-endorsement relationships involving overlapping parties.

Investigators connected those transactions through timing, matching amounts, communications, and business leverage. Two companies reportedly received $10 million in consulting payments before entering endorsement agreements with Leonard. A third received a $2 million consulting payment one day after making its first payment to him.

The Forum agreement initially contemplated $7 million in annual business for Aspiration. That figure matched the annual cash component of Leonard’s endorsement agreement. Investigators further reported that the underlying carbon analysis did not generate the $28 million budget. Instead, the consultant said the Clippers supplied that budget.

The control failure was fragmentation. Procurement reviewed one agreement, marketing another, finance a payment, and business leaders the broader relationship. No control appears to have aggregated the transactions and asked whether one funded, induced, or conditioned another.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) tells prosecutors to examine how misconduct was funded, including purchase orders and reimbursements (How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash?); what controls could have prevented access to those funds (What controls failed?); whether vendor-selection procedures were followed (If vendors were involved in the misconduct, what was the process for vendor selection and did the vendor undergo that process?); and whether contract terms, payment terms, performance, and compensation were appropriate. Those are precisely the questions an organization should ask before enforcement authorities arrive.

Control Environment

The control environment begins with leadership and accountability. According to the report, the most senior business and basketball executives participated in or knew about key parts of the conduct. Investigators concluded that Ballmer failed to create conditions in which the organization followed rules it had previously violated. When senior leaders create the risk, lower-level approvals are unlikely to function as meaningful controls. Employees may view an executive request as authorization to proceed, even when the transaction presents obvious concerns.

Risk Assessment

The Clippers had a prior circumvention violation and were investigated over Leonard’s free-agency negotiations. The NBA had then provided specific training and imposed a mandatory reporting obligation. That history should have produced a targeted risk assessment covering player representatives, sponsor introductions, endorsement arrangements, personal expenses, vendor spend-back programs, and benefits flowing through third parties. Prior misconduct is not simply history. It is risk data.

Here, the ECCP asked some direct questions, including, “Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations?” Additionally, it notes that critical factors in evaluating any program include whether the program is adequately designed to maximize effectiveness in preventing and detecting employee wrongdoing and whether corporate management enforces the program or tacitly encourages or permits employees to engage in misconduct.

Control Activities

The Wachtell Report suggests potential gaps in segregation of duties, conflict review, procurement approval, contract benchmarking, expense reimbursement, and related-transaction analysis. High-risk transactions should require independent approval outside the requesting executive’s chain of command. Controls should compare compensation with deliverables, confirm actual performance, flag advance payments, and identify common counterparties across procurement and non-procurement systems.

Information and Communication

The organization reportedly had information that should have triggered escalation: demands for $10 million in annual off-court income, unusual endorsement economics, concerns from Aspiration executives, internal descriptions of a Forum deal as “shady,” and explicit threats connecting the Forum and Leonard agreements. Indeed, Uncle Dennis’s presence alone was enough of a red flag based on his prior conduct. The issue was not the absence of information. It was the failure to move that information to a function with the independence and authority to act.

Monitoring

Hundreds of personal expenses were reportedly paid without the required deduction or reimbursement. Multiple vendors signed unusual endorsement arrangements, with minimal public activation or performance. These were recurring patterns, not one-time exceptions. Monitoring should identify patterns across time. If a control repeatedly approves exceptions without examining their cumulative effect, it is not monitoring risk. It is normalizing it.

Designing Controls for Substance

An effective control architecture should include three layers. Preventive controls should require documented business rationale, competitive sourcing, conflict disclosures, independent approval, clear deliverables, market benchmarking, and legal and compliance review before committing funds.

Detective controls should compare related transactions, test payment timing, examine overrides, confirm performance, and monitor expense exceptions. They should search for patterns across legal entities and business functions. Responsive controls should define who receives red flags, when compliance can stop payment, when issues reach the audit committee, and how remediation is tracked to completion. The most important design principle is independence. The DOJ asks whether compliance has adequate authority, stature, resources, and direct access to the board. (Where within the company is the compliance function housed (e.g., within the legal department, under a business function, or as an independent function reporting to the CEO and/or board?)

If executives can bypass or overrule the control function without documented challenge, the program is not empowered.

Practical Takeaways

Compliance, audit, and risk leaders should take the following actions:

  • Inventory all systems containing vendor, contract, payment, expense, sponsorship, and conflict information.
  • Build monitoring systems that identify common parties and beneficiaries across those systems.
  • Require proof of services and measurable deliverables before releasing significant payments.
  • Review advance payments, matching amounts, compressed timelines, and executive overrides as elevated-risk indicators.
  • Treat prior violations and mandatory reporting duties as subjects for recurring control testing.
  • Give internal audit authority to examine commercial substance, not merely procedural completion.
  • Report control failures involving senior management directly to an independent board committee.

The Clippers salary cap circumvention demonstrates that an audit trail can document a failure as easily as it documents compliance. The question is whether the organization has controls that can interpret what the records mean.

In tomorrow’s blog post, we will turn from detection to accountability and examine how cooperation, credibility, seniority, prior misconduct, and supervisory failure should shape consequence management.

Categories
Blog

The NBA/Clippers Investigation: Part 1 – A Compliance Failure in Five Acts

Over the next five blog posts, we will consider how commercial pressure, weak controls, and leadership decisions turned a salary-cap rule into an enterprise-wide governance failure. Today in Part 1, we summarize those compliance failures.

The most dangerous compliance failure is not ignorance of the rules. It is knowing the rules, receiving targeted training, having a history of prior violations, and then creating a process that appears compliant while delivering a prohibited result. That is the central compliance lesson from the investigation into the LA Clippers and Kawhi Leonard.

The independent investigators’ report, prepared by the law firm Wachtell, Lipton, Rosen & Katz, concluded that the Clippers violated the NBA’s salary-cap circumvention rules through a pattern of transactions involving Leonard, his representatives, team executives, and four companies doing business with the organization. This is a sports story, but it is also much more. It is a case study in executive accountability, third-party risk, conflicts of interest, internal controls, reporting failures, organizational culture, and board oversight.

The Investigation

The matter began after the September 2025 podcast Pablo Torre Finds Out reported allegations involving a four-year endorsement agreement between Leonard and Aspiration Partners, a sustainability services company that later entered bankruptcy. Torre won a Pulitzer Prize for his podcast reporting. Thereafter, the NBA retained Wachtell Lipton to investigate. The inquiry eventually expanded beyond Aspiration to include endorsement agreements involving Boingo Wireless, Daktronics, and Lockton Insurance.

Investigators conducted 73 interviews of 60 people and reviewed more than 200,000 pages of documents. They interviewed Clippers owner Steve Ballmer; President of Business Operations Gillian Zucker; President of Basketball Operations Lawrence Frank; Leonard; and Leonard’s uncle and then-business manager, Dennis Robertson (Uncle Dennis). Third-party cooperation varied. Aspiration’s bankruptcy trustee and Daktronics provided substantial assistance, while other parties reportedly limited or refused cooperation.

The resulting 36-page report is a summary, not a complete presentation of the evidence. Nevertheless, the investigators concluded that the record was sufficient to establish multiple violations. The misconduct unfolded in five acts.

Act One: A Known Rule and a Known Risk

The NBA’s circumvention rules broadly prohibit teams from providing players with compensation, business opportunities, or anything else of value outside their authorized player contracts. The rules also prohibit attempts, solicitations, inducements, and informal understandings intended to produce such benefits. The rule has a simple underlying principle: to prevent salary cap circumvention.

The NBA provided teams with practical examples. A team representative could not recommend a player to a sponsor for an endorsement arrangement or initiate and facilitate that relationship. If a sponsor independently asked about a player, the team’s permissible response was generally limited to supplying the player’s or agent’s contact information.

The Clippers were not operating in unfamiliar territory. In 2015, the NBA fined the team $250,000 for conduct involving a potential endorsement opportunity for DeAndre Jordan. In 2019, the NBA investigated demands reportedly made by Uncle Dennis during Leonard’s free agency. The League subsequently required teams to report improper solicitations for benefits, even when the team rejected the request.

In December 2019, the NBA provided circumvention training to the Clippers’ senior leadership, including Ballmer, Zucker, and Frank. Investigators reported that all three understood the rule. This is the first compliance lesson: knowledge is not a control. Training can establish awareness, but only governance, monitoring, escalation, and accountability can translate awareness into compliant conduct.

Act Two: Pressure From a Powerful Stakeholder

According to the report, Uncle Dennis pressed the Clippers to help Leonard obtain approximately $10 million per year in off-court income. He communicated his demands to Frank, Ballmer, and Zucker. The report found no evidence that these demands were reported to the NBA, even though the reporting rule had been created in response to earlier concerns involving Robertson. Investigators also found no evidence that senior leaders clearly instructed him to stop making the requests.

Instead, contemporaneous notes reflected assurances that Clippers’ personnel would help Leonard achieve his financial goals. Uncle Dennis requested a plan, a pipeline of potential companies, and more frequent communication. This was a decisive moment. The organization had received a red flag from the highest-risk source, involving one of its most commercially valuable stakeholders. The control that mattered was not another training presentation. It was the ability to say no, document the response, escalate the demand, and make the required report.

Act Three: The Commercial Ecosystem Becomes the Delivery Mechanism

During six days in June 2020, Zucker sent introduction emails connecting Uncle Dennis with Boingo, Daktronics, and Lockton. Each email was written as if the company had requested the introduction. Investigators did not credit that explanation. They concluded that the Clippers initiated the introductions in response to Uncle Dennis’ demands.

Leonard subsequently entered into endorsement agreements with all three companies. The agreements provided for $18 million in total compensation, all of which was paid by August 2021. Investigators identified several unusual characteristics: the agreements were negotiated rapidly during the COVID-19 shutdown, imposed minimal performance obligations, were not publicly announced, and produced little evidence of meaningful activation.

At the same time, each company was pursuing lucrative business with the Clippers or the team’s arena. The report described consulting agreements, substantial advance payments, and perceived links between vendor business and payments to Leonard. The investigators found the Daktronics arrangement particularly direct. They concluded that Clippers personnel proposed using an endorsement agreement with Leonard as part of a “spend back” arrangement connected to Daktronics’ pursuit of the Intuit Dome scoreboard contract.

Here, third-party risk and procurement risk converged. The vendors were not merely outside parties. They allegedly became the mechanism through which the prohibited benefit was delivered.

Act Four: Aspiration and the Appearance of Legitimacy

Aspiration’s relationship with the Clippers was substantial. It included a long-term sponsorship agreement, sustainability services for the Intuit Dome, and a $50 million personal investment by Ballmer. The report concluded that Zucker raised the possibility of an Aspiration endorsement agreement with Leonard, recruited a business agent to help structure it, communicated proposed financial terms, provided input on the term sheet, and remained involved after the formal introduction.

The final agreement called for $48 million in cash and equity over four years. Investigators described the compensation as extraordinarily high in relation to Leonard’s obligations and endorsement profile. The most significant issue involved a separate agreement under which the Clippers would purchase sustainability services for the Forum. Early documents contemplated $7 million in annual business for Aspiration, matching the annual cash component of Leonard’s endorsement agreement. When Aspiration’s co-founder threatened to abandon the Leonard agreement unless the Forum transaction was completed, internal Clippers’ communications reportedly reflected awareness of that linkage. Ballmer nevertheless approved the Forum agreement.

The compliance lesson is substance over form. A formal contract, documented introduction, consultant analysis, or stated business purpose does not end the inquiry. Compliance must ask who initiated the transaction, who benefits, whether the economics make sense, and whether supposedly independent agreements are actually connected.

Act Five: Expenses, Reporting, and the Control Environment

Investigators also identified hundreds of instances in which the Clippers paid personal travel, accommodations, gifts, and ticket expenses for Leonard, his family, or Uncle Dennis without making the deductions required by NBA rules. Frank authorized the payments.

The report further concluded that Ballmer, Zucker, and Frank failed to report Uncle Dennis’ improper solicitations. These findings move the case beyond isolated dealmaking. They suggest failures in expense management, accounts payable, executive approvals, legal review, reporting, and compliance escalation. Under the COSO Internal Control–Integrated Framework, internal controls support operational, reporting, and compliance objectives. They must operate across the enterprise, particularly where multiple transactions point toward the same underlying risk.

The Compliance Program Test

The DOJ’s Evaluation of Corporate Compliance Programs organizes its analysis around three fundamental questions:

  1. Is the compliance program well designed?
  2. Is it adequately resourced and empowered to function effectively?
  3. Does it work in practice?

The Clippers matter raises all three. The DOJ Organizational Sentencing Guidelines similarly require risk assessment, appropriate authority for compliance personnel, monitoring and auditing, confidential reporting mechanisms, consistent enforcement, and remediation. Prior misconduct must inform future risk assessment and control design.

The Caremark Doctrine provides the board-level perspective. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes that directors must make a good-faith effort to establish and monitor reporting systems addressing mission-critical compliance risks. The relevant point here is not that Caremark liability has been established. It is that known, central risks require reliable information to reach governing authorities, followed by documented oversight and action.

The Consequences

Following the report, the NBA imposed significant penalties. According to The Athletic the penalties are:

  • The forfeiture of five first-round picks by the Clippers;
  • A $30 million team fine for the Clippers;
  • A one-year suspension for Clippers owner Steve Ballmer
  • Suspensions without pay for two of the top Clippers executives, Gillian Zucker (president of business operations; one year) and Lawrence Frank (president of basketball operations; six months);
  • Placement in the NBA-controlled compliance and monitoring program for five years;
  • Leonard was required to forfeit $700,000; and
  • Uncle Dennis was banned and is prohibited from conducting business with NBA teams for five years.

These penalties demonstrate that governance failures can create consequences far beyond the value of the underlying transactions.

These penalties demonstrate that governance failures can create consequences far beyond the value of the underlying transactions.

Compliance Takeaways

Compliance professionals should take five immediate lessons from this matter:

  • Treat prior violations as mandates for verified remediation, not completed training exercises.
  • Map interconnected relationships among vendors, executives, customers, agents, and other powerful stakeholders.
  • Require independent review when multiple agreements may benefit the same individual.
  • Test the economic substance of transactions, including pricing, deliverables, advance payments, and ultimate beneficiaries.
  • Give compliance the authority to escalate and stop transactions involving senior executives or strategically important individuals.

The question is not whether an organization has rules. The question is whether its compliance system can withstand pressure from the people the business most wants to satisfy. In Part 2 (after Labor Day), we will examine the conflicts of interest embedded in the Clippers’ commercial ecosystem and consider how organizations should govern transactions where sponsors, vendors, executives, personal relationships, and individual benefits intersect.

Categories
Blog

Odyssey Week: Leadership: Penelope’s Loom: Integrity Under Pressure

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Anne Hathaway was great as Penelope.

Penelope does not get enough credit. Odysseus gets the monsters, the storms, the speeches, the disguises, and the dramatic return. He gets the action scenes. Penelope gets the waiting. If the movie version made one thing clear, such an interpretation sells her short—very short.

Penelope is not simply waiting. She is governing under pressure. Opportunists surround her. The suitors have occupied her home, consumed her resources, pressured her to choose one of them, and treated uncertainty as an invitation to abuse. Odysseus is gone. Authority is contested. Telemachus is young. The house is under stress.

So Penelope does something quietly brilliant. She promises to choose a suitor after she finishes weaving a burial shroud for Laertes. By day, she weaves. By night, she unweaves. She buys time without surrendering the core issue. It is not flashy. It is not a thunderbolt. It is not a sword fight in the hall. It is disciplined patience under pressure.

That is why Penelope belongs in the leadership section of a compliance odyssey. She reminds us that integrity is not always dramatic. Sometimes it looks like refusing to sign the certification, approve the vendor, bless the transaction, release the report, close the investigation, or accept the explanation simply because everyone is tired of waiting.

The Corporate Translation

Penelope is the leader who understands that time pressure is not the same as good governance. Every organization has Penelope moments. The quarter is closing, and someone wants revenue recognized now. A third party has not cleared diligence, but the business sponsor says the relationship is too important to delay. A certification is due, but the control owner is not comfortable with the evidence. A board report needs to go out, but the investigation findings are still incomplete. A product launch is scheduled, but privacy, security, or regulatory concerns remain unresolved. A customer is demanding speed. A senior executive wants closure. The team is exhausted.

And then someone says the magic words: “Can we just move forward?” That is the sound of the loom beginning to tighten. Penelope’s lesson is not that delay is always virtuous. It is not. Delay can be passive, political, cowardly, or evasive. But some delay is not avoidance. It is governance. The question is whether the organization can tell the difference.

Defensible Delay Is Not Obstruction

In compliance, delay has a bad reputation. That is why compliance is known as The Land of No, populated by Dr. No. Sometimes it is the Department of Business (Non)Development. Whatever the moniker is, this is why business leaders often hear “we need more time” as “compliance is blocking the business.” Sometimes that criticism is fair. Compliance functions can be too slow, too opaque, too academic, or too disconnected from commercial reality. A policy review that disappears into a black hole is not governance. It is bureaucracy with a ticket number.

But there is another kind of delay: defensible delay. Defensible delay has a reason. It has an owner. It has a process. It has a timeline. It identifies the unresolved risk and the information needed to make a decision. It is communicated clearly. It is proportionate to the issue. It protects the company from making a false, rushed, or poorly documented commitment.

Penelope’s loom was not random. It had a purpose. It created time when the available choices were bad. That matters in corporate life. A leader who refuses to approve a questionable vendor is not “being difficult” if the due diligence is incomplete and red flags remain unresolved. A CFO who refuses to sign a certification without adequate support is not “overly cautious.” A compliance officer who asks for more facts before closing an investigation is not “dragging things out.” A privacy officer who pauses a product launch because sensitive data controls are not ready is not “anti-innovation.” Sometimes the most ethical sentence in business is “Not yet.”

Culture Is Built in the Waiting

Corporate culture is often revealed by what happens during delay. When a leader says, “We need more information,” does the organization respect the concern? Or does it start applying pressure?

Does the business provide the missing evidence, or does it complain that Legal is slowing things down? Does management support the control owner, or quietly ask for a more “practical” answer? Does the board ask why the delay is necessary or simply demand that the issue be resolved before the next meeting? Does compliance explain the path forward or hide behind process? These moments shape culture.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a compliance program works in practice, whether senior and middle management have encouraged or discouraged compliance through their words and actions, and whether compliance personnel have sufficient authority, resources, and access to function effectively. It also asks whether employees have practical guidance and know when to seek advice.

That is Penelope’s world. Culture is not only what the company says about integrity. It is whether the company protects people who slow down a decision for the right reasons. If every delay is treated as disloyalty, employees learn to approve first and worry later. That is not agility. That is ethical surrender in business casual.

Ethical Resilience Under Pressure

Penelope is not powerful in the obvious way. She does not command an army. She does not remove the suitors by force. Her resilience is quieter. She endures pressure without surrendering judgment. That kind of resilience is essential in compliance.

Ethical resilience is the capacity to hold the line when the organization is tired, when the facts are inconvenient, when the deadline is real, and when compromise would be easier. It is the controller who insists on evidence. The manager who escalates a concern before approving the payment. The compliance officer who says the investigation is not complete. The board member who asks whether management’s optimism is supported by testing. The executive who tells the team, “We will not do this the wrong way just because the right way takes longer.”

The DOJ Justice Manual states that prosecutors should evaluate a company’s commitment to fostering a strong culture of compliance at all levels, including how the company incentivizes employee, executive, and director behavior through discipline, complaint handling, and compensation plans. That means ethical resilience cannot depend on heroic individuals. The system must support it.

People must know they will not be punished for raising legitimate concerns. Performance goals must not make ethical delay impossible. Leaders must model patience when facts matter. Governance bodies must ask for evidence, not just reassurance. Compliance must help the business move responsibly, not merely tell it to wait. Penelope’s loom works because she has discipline. A company’s compliance program works because discipline is built into the system.

What a Better Compliance Program Does

A better compliance program helps the organization make disciplined decisions under pressure. It defines which approvals require evidence. It gives control owners authority to withhold certifications when support is inadequate. It builds escalation paths for unresolved risk. It documents exceptions and unresolved issues. It trains leaders on how to respond when employees raise concerns. It tracks aging remediation items. It distinguishes between acceptable risk, unresolved risk, and ignored risk. It also makes delay visible.

If a vendor approval is paused, document the reason. If leadership cannot sign a certification, they should know what evidence is missing. If an investigation remains open, there should be a plan. If a product launch is delayed, stakeholders should understand which control or risk issue must be resolved. That is not bureaucracy. That is governance with receipts.

The Compliance Takeaway

Penelope’s loom is a lesson in ethical leadership. She shows that integrity is not always a grand public stand. Sometimes it is a disciplined refusal to be rushed into a bad decision. Sometimes it is the courage to say, “The facts are not ready.” Sometimes it is the wisdom to buy time without losing the trust of those who are waiting.

For compliance officers and business leaders, the challenge is to build organizations where prudent delay is respected and avoidance is exposed. Do not approve the questionable vendor because everyone is tired. Do not sign the certification because the calendar is unforgiving. Do not close the investigation because the subject is influential. Do not bless the transaction because the business has already promised the outcome.

Weave if you must. Unweave if you must. But know why you are doing it, tell the truth about the risk, and make sure the delay serves integrity rather than fear. That is Penelope’s gift to corporate compliance. She reminds us that sometimes the strongest leader in the room is the one patient enough not to make the wrong decision.

Final Thoughts

Taken together, the leadership lessons from The Odyssey show that corporate compliance is not sustained by slogans, heroes, or good intentions alone. The Trojan Horse reminds us that cleverness without discipline can become a control failure; Athena shows that wise counsel must have real authority, resources, and access to challenge power; and Odysseus demonstrates that even brilliant, high-performing leaders can become compliance risks when success becomes a shield from scrutiny.

Telemachus then carries the lesson into succession, showing that governance must survive the absence of the indispensable leader, with authority, control, ownership, and escalation clearly embedded into the business. Penelope completes the leadership arc by reminding us that integrity under pressure is often quiet, patient, and disciplined: the willingness to say “not yet” when facts are incomplete, risks are unresolved, and everyone else wants to move forward. Together, these stories teach that ethical leadership is not simply about winning the battle or reaching Ithaca; it is about building a compliance culture strong enough to resist shortcuts, challenge heroes, survive transitions, and hold the line when pressure is highest.

Categories
Blog

Odyssey Week: Leadership: Telemachus and the Succession Problem

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Tom Holland was great as Telemachus.

Odysseus is away. That is the fact around which Ithaca slowly comes apart. He is not merely on a long business trip. He is not delayed in a regional office because the quarterly review ran over. He has been gone for years. In his absence, the household becomes a leadership vacuum. Penelope holds the center as best she can. Telemachus grows up surrounded by uncertainty. The suitors occupy the palace, consume resources, abuse hospitality, and become more comfortable with every passing day. No one is quite sure who has authority.

And when authority is unclear, misconduct finds a chair at the table. That is Telemachus’s compliance lesson. He is not just the son waiting for his father’s return. He is the next generation of leadership inheriting a control environment weakened by absence, ambiguity, and tolerated abuse.

For modern companies, Telemachus represents the succession problem: what happens to governance, compliance, and accountability when the founder, CEO, general counsel, CFO, chief compliance officer, regional president, or other key executive is absent, distracted, replaced, or functionally unreachable? The company may still have policies. It may still have a code of conduct. It may still have approval matrices, committees, workflows, and board decks.

But the practical question remains: who owns compliance when the person everyone used to ask is no longer there?

The Corporate Translation

Every organization has formal authority and informal authority. Formal authority lives in charters, org charts, delegations of authority, board committee mandates, policy ownership tables, and job descriptions. Informal authority lives in the hallway, the inbox, the founder’s instincts, the CFO’s raised eyebrow, the general counsel’s quiet warning, and the compliance officer everyone calls before doing something adventurous.

The trouble begins when the company depends too heavily on informal authority. The founder knows where the risks are. The CFO knows which regional numbers smell funny. The general counsel knows which agents should never be used. The chief compliance officer knows which managers say all the right things and do something else entirely. The regional leader knows which customer relationships require special scrutiny.

Then one of them leaves, retires, burns out, gets promoted, goes on leave, is distracted by a transaction, or becomes unavailable during a crisis. Suddenly the company discovers that what it called “governance” was partly memory, personality, and habit. That is Ithaca without Odysseus.

Succession Is a Compliance Issue

Succession planning is often treated as a leadership development topic. That is too narrow. Succession is also a compliance issue.

When key people leave, the company can lose risk knowledge, control discipline, escalation history, and institutional memory. Open investigations may drift. Third-party concerns may be forgotten. Exceptions may remain unresolved. Sensitive approvals may migrate to people who do not understand the underlying risks. Business units may exploit the transition. Bad actors may test boundaries. The suitors always notice when the house is lightly supervised.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s program is well designed, adequately resourced and empowered, and working in practice. It also asks whether policies and procedures are integrated into day-to-day operations, who is responsible for that integration, and whether gatekeepers know what misconduct to look for and when to escalate concerns. Those are succession questions as much as compliance questions. A program that works only when one heroic executive is present does not work in practice. It works in person. That is a very different thing.

Delegation of Authority: Who Can String the Bow?

A delegation of authority matrix is not the most poetic corporate artifact. No one has ever said, “Gather the children by the fire while I tell the thrilling tale of approval thresholds and signature authority.” But delegation of authority matters. It defines who can approve payments, hire third parties, sign contracts, override controls, accept risk, access systems, certify reports, settle disputes, and bind the company.

When delegation is unclear, people improvise. And improvisation is where compliance problems breed. A regional manager approves a vendor because the usual executive is unavailable. A finance employee processes a payment because “someone senior said it was fine.” A business sponsor signs off on due diligence exceptions without understanding the risk. A system administrator grants access because the request came from an important person. A commercial leader commits the company before legal review because the customer needed an answer by Friday.

Each step may feel practical. Each may be defensible in isolation. Together, they reveal a governance weakness. Delegation of authority should answer three basic questions: who can decide, what can they decide, and under what conditions? It should also answer the question most likely to matter in a crisis: who decides when the usual decider is gone?

Control Ownership Cannot Be a Family Secret

In Ithaca, too much depends on Odysseus’s eventual return. That is not a control framework. That is a weather forecast with sandals. Modern companies make the same mistake when control ownership is unclear or overly personalized. Everyone assumes “finance owns that,” “legal handles that,” “compliance reviews that,” “the business manages that,” or “the board knows about that.” Assumption is not ownership. Control ownership should be specific. The owner should understand the risk the control addresses, how the control operates, what evidence demonstrates performance, when exceptions must be escalated, and who serves as backup.

This is especially important in operationally integrated compliance programs. The ECCP emphasizes that compliance policies and procedures should be reinforced through internal control systems and that employees with approval authority or certification responsibilities should receive guidance on what misconduct to look for and when to escalate. That means compliance cannot sit outside the business like a wise statue waiting to be consulted.

It must be embedded into approvals, workflows, reviews, certifications, access rights, vendor onboarding, financial controls, investigations, and reporting channels. Otherwise, when leadership changes, compliance becomes a scavenger hunt.

The Telemachus Problem in Business

Telemachus is not weak. He is inexperienced. That distinction matters. Many next-generation leaders inherit messy control environments. They did not create the old habits. They did not approve the questionable third parties. They did not design the incentive plan. They did not tolerate the difficult executive. They did not ignore the aging audit findings. But they inherit all of it.

That is the Telemachus problem. New leaders often face a painful choice. They can preserve the comfortable ambiguity that made the prior regime work, or they can impose clarity and risk making everyone uncomfortable. Compliance should help them choose clarity.

A new leader should ask, “What are the top compliance risks in this business?” Which controls depend on specific individuals? Which approvals have weak backup coverage? Which investigations or remediation items are open? Which third parties are high risk? Which exceptions have been granted? Which business units have recurring audit findings? Which employees are afraid to speak up? Which senior people are treated as untouchable?

Those questions do not undermine leadership. They establish it. Telemachus cannot govern Ithaca by pretending the suitors are merely enthusiastic guests.

Board Oversight During Transition

Boards of Directors should pay special attention during leadership transitions. A CEO departure, founder transition, CFO replacement, compliance leadership change, merger integration, restructuring, or sudden executive absence can create real compliance vulnerability. It may not appear on the face of the financials. It may not show up immediately in hotline data. But the risk is there.

The board should ask whether interim authority is clear, whether compliance has direct access to leadership, whether key controls remain staffed, whether open issues are being tracked, and whether employees understand where to escalate concerns.

A transition plan should not be limited to investor messaging and organizational charts. It should include compliance continuity. Who owns active investigations? Who signs certifications? Who approves high-risk third parties? Who can grant policy exceptions? Who reports to the board? Who monitors retaliation risk? Who tracks remediation? Who protects records and data? Who communicates expectations to employees? If those answers are unclear, the suitors are already choosing seats.

The Compliance Takeaway

Telemachus teaches us that compliance continuity matters. A company cannot rely on heroic founders, all-knowing executives, indispensable compliance officers, or informal networks of people who “just know how things work.” That may function for a while. It may even feel efficient. But when the key person is gone, the weakness becomes visible. Governance must survive absence.

Authority must be clear. Control ownership must be documented. Delegation must be practical. Oversight must continue. Compliance must be integrated into operations, not dependent on personalities. Because when authority is unclear, misconduct does not wait politely outside the palace. It pulls up a chair, pours the wine, and starts acting like it owns the place.

Join us Tomorrow

Telemachus teaches that governance must survive absence: authority must be clear, ownership documented, and compliance embedded deeply enough that Ithaca can operate without Odysseus in the room. Penelope carries that lesson into the next test, showing what ethical leadership looks like when authority is contested, pressure is relentless. Everyone wants a decision before the facts are ready. If Telemachus asks who owns compliance when the key leader is gone, Penelope asks whether the person with authority has the discipline to say “not yet” to a questionable vendor, weak certification, incomplete investigation, or rushed transaction. Together, they move the leadership arc from succession and continuity to integrity under pressure: first making governance clear, then proving it can hold the line when the suitors demand an answer.

Categories
Blog

Ted Lasso Week: Part 4 – Roy Kent: The Compliance Power of the Middle Manager

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I have considered Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 4, I consider the sometimes painful transition of an aging sports star into middle-management coaching.

In Part Three, Nate Shelley demonstrated the danger of promoting technical talent without preparing or monitoring the new manager. Roy Kent provides the counterpoint. He is demanding, impatient, and frequently intimidating, but he understands that leadership happens close to the work. Ted can articulate Richmond’s values. Rebecca can provide authority and resources. Roy determines whether those values survive contact with the locker room. He corrects behavior, confronts stars, coaches struggling employees, and translates general expectations into specific action.

For compliance professionals, Roy illustrates the power of the middle manager. He also shows the risk. The same informal authority that can strengthen culture can magnify poor judgment when it is not bounded by self-awareness, escalation, and accountability.

Authority Exists Before the Title

Roy begins the series as Richmond’s captain, not a member of management. Yet his teammates watch him, follow him, and adjust their behavior around him. He has informal authority, which often matters more than the organizational chart.

In “Trent Crimm: The Independent” (Season 1, Episode 3), Ted recognizes that Jamie Tartt and other players are bullying Nate. Rather than solve the problem solely through formal coaching authority, Ted pushes Roy to act. Roy confronts Jamie and forces the locker room to change. That is the tone in the middle. Employees often look to a respected supervisor, veteran, or peer leader to determine whether the code of conduct is real. If that person laughs at an offensive joke, ignores a control override, or protects a top performer, the policy loses. If that person intervenes, the standard gains operational force.

The DOJ Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to examine how managers at all levels encourage or discourage compliance through their words and actions. Compliance leaders therefore need to identify informal influencers, not merely designated supervisors. On this point, the ECCP states, “it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.” Culture travels through both. The ECCP goes on to state “[t]he company’s culture of compliance, including awareness among employees that any criminal conduct, including the conduct underlying the investigation, will not be tolerated.”

Standards Must Apply to Stars and to the Manager

Roy’s credibility comes partly from his willingness to confront Jamie, Richmond’s most talented player. He refuses to accept the idea that performance excuses selfishness or abuse. That is a central compliance principle. Standards that bend around revenue generators and star executives are not standards.

Roy faces the same test personally in “All Apologies” (Season 1, Episode 9). His age and injuries have reduced his performance, but his identity is tied to being captain and playing every match. When Ted decides to bench him, Roy initially resists. He ultimately reports for training in the reserve bib and supports the team. The decision matters because accountability becomes credible when the influential employee accepts the rule applied to everyone else. Roy does not enjoy the outcome, but he demonstrates that status does not confer immunity.

Effective Coaching Diagnoses the Cause

In “The Hope That Kills You” (Season 1, Episode 10), Roy selects Isaac McAdoo as the next captain. By “Rainbow” (Season 2, Episode 5), Isaac is struggling under the weight of that role. Ted asks Roy for help. Roy does not respond with another motivational speech or a threat. He takes Isaac to the neighborhood pitch where Roy learned to play and places him in an informal match. The intervention helps Isaac rediscover that football is a game he loves.

This is root-cause analysis at the individual level. The visible problem is poor performance. The underlying issue is that responsibility has displaced purpose and confidence. Roy changes the environment, observes Isaac, and chooses an intervention connected to the cause. The compliance application is substantial. When an employee misses a control, a manager should not automatically assign retraining. The cause may be an unrealistic target, conflicting procedures, poor system design, inadequate staffing, fear of escalation, or a supervisor who rewards shortcuts. Training cannot repair a misaligned incentive. Discipline cannot correct an unusable process.

Coaching Can Turn a Risk Into an Asset

Roy’s relationship with Jamie becomes his strongest management case. He begins by confronting Jamie’s entitlement. In “Man City” (Season 2, Episode 8), after Jamie finally strikes back at his abusive father, Roy recognizes the pain beneath the conduct and embraces him. The response is neither a lecture nor an endorsement of violence. It is a manager recognizing that the employee needs support before instruction.

In “4-5-1” (Season 3, Episode 3), Jamie asks how he can become better than Zava. Roy offers to train him. The work continues through “Sunflowers” (Season 3, Episode 6), when their training in Amsterdam becomes reciprocal, and Jamie teaches Roy to ride a bicycle. Roy does not lower the standard for Jamie. He gives him the discipline, attention, and feedback needed to meet a higher one. This is what good remediation should accomplish. It should protect the organization while creating a credible path for behavioral improvement.

Managers need tools for these conversations: clear expectations, documented feedback, measurable improvement goals, support resources, escalation thresholds, and follow-up. Candor without structure can become hostility. Compassion without standards can become avoidance. Roy is most effective when he combines both.

Informal Power Can Also Amplify Bad Judgment

Roy is not a flawless compliance model. In “Big Week” (Season 3, Episode 4), he and Coach Beard show the players security footage of Nate tearing the “BELIEVE” sign, despite Ted’s decision not to use it as motivation. The team becomes enraged, loses discipline, receives multiple red cards, and falls to West Ham. Roy intends to motivate. He instead weaponizes internal security footage and emotional injury.

The failure offers three lessons. First, managers must understand the limits of delegated authority. Silence or ambiguity from senior leadership is not permission to bypass its stated judgment. Second, incentives built on anger can produce foreseeable misconduct. Third, a result-driven culture can make an improper method appear acceptable until the damage becomes visible.

Roy’s training methods can also cross from demanding into unsafe or humiliating, as the red-string exercise in “The Strings That Bind Us” (Season 3, Episode 7) demonstrates. A strong manager should challenge employees. The organization must still set boundaries around safety, dignity, and acceptable conduct. This is why middle-management training cannot be limited to explaining policy. Managers need scenario-based practice on investigations, privacy, retaliation, discipline, escalation, health and safety, conflicts, and the use of employee information.

The Best Managers Remain Coachable

Roy’s development is possible because he gradually accepts that leadership does not require invulnerability. In “So Long, Farewell” (Season 3, Episode 12), he joins the Diamond Dogs, asks whether people can change, and later begins therapy. He becomes Richmond’s manager, but his promotion is framed as the next stage of development, not proof that the work is finished.

That distinction matters. Organizations often treat promotion as validation rather than increased risk. The best managers remain open to feedback, seek guidance, acknowledge uncertainty, and use available expertise. Middle managers are a critical source of that information. They should not filter out bad news to protect their numbers. Boards and executives should ask whether managers escalate emerging risks, whether the organization rewards such escalation, and whether retaliation or fear is blocking the flow of information.

Questions for CCOs

Roy’s journey should prompt five questions:

  1. Who are the organization’s informal culture carriers, and how are they engaged?
  2. Are managers evaluated and rewarded for how they achieve results, not only for the results themselves?
  3. Do managers know how to diagnose root causes, escalate concerns, and document behavioral coaching?
  4. Are high performers subject to the same conduct standards as everyone else?
  5. Does manager training distinguish productive candor from intimidation, retaliation, humiliation, and unsafe pressure?

Roy Kent demonstrates that middle managers are the operational heart of compliance. They make standards visible, detect weak signals, and decide whether employees experience accountability as fair. Compliance cannot succeed around them. It must succeed through them.

Next in the Series: Keeley Jones and Governance Under Pressure

Roy’s challenge is translating established values into frontline behavior. Keeley Jones faces the next organizational stage: building a business, accepting investor capital, managing employees, and preserving independence while personal and commercial pressures converge. Join us in our series finale, where we will examine founder risk, conflicts of interest, privacy, third-party influence, and why governance must grow as quickly as the company it is designed to protect.

Categories
Blog

Ted Lasso Week: Part 3 – Nate Shelley: When an Employee Becomes a Culture Risk

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I will consider Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 3, we consider the professional journey of Nate Shelley, who begins the series as the equipment manager, or in football parlance, the ‘kit man,’ but rises into the managerial ranks.

In Part Two, Rebecca Welton showed how concentrated authority can turn an executive’s private grievance into organizational misconduct. Nate Shelley presents a different risk. His damage begins below the executive level, after AFC Richmond promotes a technically gifted employee without preparing him to exercise power.

Nate is not a villain. He is the overlooked kit man whom players ridicule and leaders barely notice. Ted recognizes his tactical ability, Roy stops the bullying, and Richmond promotes him. Yet the organization mistakes recognition for readiness. Once Nate receives authority, the humiliation he experienced does not disappear. He redirects it toward people with less power.

For compliance professionals, Nate’s story shows that culture risk can emerge when organizations reward expertise, overlook behavioral warning signs, fail to adequately train new managers, and then fail to monitor them.

Promotion Changes the Risk Profile

In “Trent Crimm: The Independent” (Season 1, Episode 3), Jamie Tartt and other players bully Nate until Roy intervenes. Ted also invites Nate to contribute tactical ideas. Those decisions establish dignity and psychological safety for an employee who had neither.

By “The Hope That Kills You” (Season 1, Episode 10), Nate has been promoted to assistant coach. The promotion is understandable. He knows football, sees patterns others miss, and has already helped the team. What Richmond never appears to assess is whether he can supervise people, receive criticism, manage conflict, protect confidential information, or use authority consistently. This is a common corporate failure. The strongest engineer becomes an engineering manager. The top salesperson becomes a regional leader. The best investigator becomes an investigation director. Technical performance is treated as proof of leadership capacity.

Section 8B2.1 of the 2025 U.S. Sentencing Guidelines requires reasonable efforts in selecting personnel with substantial authority, practical training based on role and responsibility, monitoring, and consistent discipline. An effective promotion process should assess conduct, not merely output. It should also include manager training, defined escalation duties, coaching, and a meaningful review period.

Richmond changes Nate’s title. It does not build the controls that should accompany his new power.

The Bullied Employee Becomes the Bullying Manager

Nate’s deterioration becomes unmistakable in “The Signal” and “Headspace” (Season 2, Episodes 6 and 7). Public praise for his tactical decision produces the “Wonder Kid” identity he craves. He also belittles Colin Hughes and directs increasingly harsh treatment at Will, the young employee who replaced him as kit man. Coach Beard witnesses Nate humiliating Colin and tells him to do better. Nate then delivers a public apology. Yet when Will gives him a personalized jersey, Nate responds with private abuse. The apparent correction does not change the conduct. It relocates the harm to a more vulnerable target.

That sequence should concern every compliance officer. A manager confronted about misconduct may learn the wrong lesson: avoid witnesses, control the record, and retaliate where detection is less likely. Closing a matter after an apology, without checking the experience of affected employees or monitoring subsequent conduct, can make the organization less safe.

The DOJ Evaluation of Corporate Compliance Programs asks how managers at all levels demonstrate commitment to compliance, whether employees are comfortable reporting concerns, whether there are “lines of reporting and communications,” and whether discipline is consistent. “Have disciplinary actions and incentives been fairly and consistently applied across the organization? ” Does the compliance function monitor its investigations and resulting discipline to ensure consistency? “And whether the company examines root causes,” “Has the company undertaken a root cause analysis into areas where certain conduct is comparatively over- or under-reported?” Nate’s conduct calls for more than informal coaching. It calls for fact-finding, documentation, protection of Will and Colin, and a plan to determine whether behavior actually changes (i.e., ongoing monitoring).

Warning Signs Are Data

Richmond receives signals throughout Season 2. Nate becomes preoccupied with status, press coverage, social media approval, and perceived slights. He resents Roy’s return to the coaching staff. He spits at his reflection to manufacture confidence. His criticism becomes personal, and his treatment of lower-status employees worsens.

None of these facts alone proves that Nate will betray the team. Together, they form a pattern. Compliance programs fail when each signal remains isolated: Human Resources sees a complaint, a supervisor observes disrespect, colleagues notice resentment, and senior leadership sees performance. No one assembles the complete picture. This is the pattern recognition issue. If no one person or data analytics tool is watching the pattern, it may not be noticed until it is too late.

Under the COSO Internal Control Framework, Richmond’s weakness spans risk assessment (Objective 2), information and communication (Objective 4), and monitoring (Objective 5). The organization has values, but it lacks a reliable process for gathering culture data and testing whether managers operate consistently with those values.

Grievance Becomes Betrayal

Nate’s culture risk becomes an organizational crisis in “Midnight Train to Royston” (Season 2, Episode 11). Trent Crimm informs Ted that an article will reveal Ted’s panic attack and that Nate is the source. In “Inverting the Pyramid of Success” (Season 2, Episode 12), Nate accuses Ted of abandoning him, rejects Ted’s apology, acts out by tearing the “BELIEVE” sign in half, and leaves for West Ham.

Nate has legitimate feelings about recognition, communication, and his relationship with Ted. Those feelings do not justify leaking a colleague’s sensitive health information to inflict reputational harm. Explanation is not exoneration. It also leads to what I consider one of the most reprehensible lines in the entire series when Nate screams at Ted, “You don’t belong here.”

Organizations should examine both individual accountability and system failure. Why did Nate believe betrayal was his only effective channel? Why did no one detect the escalating mistreatment of employees? Who owned his development after promotion? What information could he access because of his trusted position? Why did Richmond lack a process that could address his grievance before it became retaliation? A root-cause analysis that labels Nate disloyal and stops there will miss the control failures that allowed the risk to mature.

Incentives Can Amplify the Wrong Behavior

At West Ham, Rupert rewards Nate with title, status, a car, and proximity to power. In “Smells Like Mean Spirit” (Season 3, Episode 1), Nate mocks Richmond and Ted publicly and humiliates a West Ham player during training. Rupert does not remediate Nate’s insecurity. He weaponizes it.

This is incentive design in human form. One organization can suppress destructive behavior while another celebrates it. Compensation is only one incentive. Access, attention, public praise, elite membership, and fear of exclusion can be equally powerful. Nate eventually recognizes the cost. After refusing Rupert’s invitation to a private “boys’ night,” he leaves West Ham, as confirmed in “International Break” (Season 3, Episode 10). His departure is meaningful because he gives up the status he once treated as proof of worth.

Reintegration Requires More Than Forgiveness

Nate begins repairing harm by quietly completing Will’s work and leaving an apology in “International Break.” In “Mom City” (Season 3, Episode 11), several players invite him back, but Nate hesitates because Ted has not approved the plan. Beard ultimately offers him a second chance. In “So Long, Farewell” (Season 3, Episode 12), Nate apologizes directly to Ted and returns to the coaching staff.

The human story is redemption. The compliance story is reintegration. A sound return-to-work plan would document findings, consider the views and safety of affected employees, define Nate’s role, require coaching, reinforce confidentiality and anti-retaliation standards, and monitor conduct over time. Restoration can support culture, but only if it does not communicate that talent or remorse erases accountability.

Questions for CCOs

Nate’s journey should prompt five questions:

  1. Do promotion decisions evaluate leadership conduct and risk, or only technical results?
  2. Are new managers trained on retaliation, confidentiality, escalation, discipline, and psychological safety?
  3. Can lower-status employees report misconduct by a popular or high-performing manager without fear?
  4. Does the organization combine complaint, exit, survey, investigation, and performance data to identify patterns?
  5. When a former employee returns after misconduct, is reintegration structured, documented, and monitored?

Nate becomes a culture risk because Richmond sees his talent before he understands his relationship with power. His story reminds us that employees do not become ethical managers through promotion alone.

Next in the Series: Roy Kent and the Power of the Middle Manager

Nate shows what happens when managerial authority is granted without preparation or sustained oversight. Roy Kent offers the counterpoint. He is imperfect, confrontational, and sometimes slow to change, but he understands that standards become real through daily coaching, direct feedback, and visible accountability. In Part Four, we will examine why middle managers are the operational heart of an effective compliance program and how Roy converts leadership expectations into behavior inside the locker room.

Categories
Blog

When the Captain Isn’t the Captain: Star Trek’s Turnabout Intruder as a Root Cause Analysis Case Study

One of the Department of Justice’s most consistent themes in its 2024 Update to the Evaluation of Corporate Compliance Programs (ECCP) is the need for companies to conduct effective root cause analysis following misconduct or control failures. It’s not enough to identify what went wrong; you must understand why it happened and implement measures to prevent it from happening again.

That principle is front and center in the Star Trek: The Original Series finale, Turnabout Intruder. In this episode, Captain Kirk is on an archaeological survey mission when he encounters Dr. Janice Lester, an old acquaintance from Starfleet Academy. Through a mysterious alien device, Lester transfers her consciousness into Kirk’s body, trapping his mind in her own body. What follows is a tense series of events in which “Kirk” behaves increasingly erratically, prompting suspicion among the crew.

For compliance professionals, the episode is a surprisingly apt case study in the perils of failing to dig past the surface when something seems off. Just as the crew needed to piece together the real cause of their captain’s strange behavior, compliance teams must be adept at peeling back layers to discover the true root cause of problems.

Here are five key root cause analysis lessons from Turnabout Intruder.

Lesson 1: Unusual Behavior Should Trigger an Investigation

Illustrated by: Shortly after the mind swap, “Kirk” begins making uncharacteristic decisions, belittling subordinates, ignoring Starfleet protocols, and punishing dissent in ways that are entirely out of character for the captain.

Compliance Lesson:

Behavior that deviates from established patterns should be a red flag. In corporate compliance, abrupt changes, whether in employee conduct, financial reporting patterns, or transaction activity, often indicate deeper issues.

Too often, organizations rationalize away early warning signs: “He’s under stress” or “That’s just her style.” But effective root cause analysis begins with the willingness to ask, Why is this happening now? Early detection is often the difference between a manageable problem and a full-blown crisis. Develop and maintain behavioral baselines for key personnel and functions. If something deviates sharply, investigate promptly rather than waiting for more evidence to emerge.

Lesson 2: Multiple Data Points Build a Stronger Case

Illustrated by: Several crew members—Spock, McCoy, and Scotty—each notice something odd about “Kirk.” At first, their observations are anecdotal and separate. Only when they share information do they begin to see a pattern that suggests something is seriously wrong.

Compliance Lesson. Root cause analysis is stronger when it integrates multiple perspectives and data sources. If you rely on a single source, one audit, or one complaint, you risk drawing incomplete or biased conclusions.

In the episode, no single crew member had enough to prove that Kirk wasn’t himself. But when their observations were combined, the collective evidence pointed toward an anomaly that needed urgent action. Create processes that encourage information sharing across departments. Compliance, audit, HR, and operations should have mechanisms to cross-reference findings because the root cause may only emerge when different pieces are put together.

Lesson 3: Be Alert to Hidden Motives

Illustrated by: In Kirk’s body, Lester uses her new authority to sideline suspected opponents, reassigning or threatening crew who question her behavior. Her motive isn’t mission success; it’s consolidating her stolen command.

Compliance Lesson. The apparent cause of a problem may mask deeper personal or organizational motives. Misconduct often occurs because someone pursues goals that conflict with corporate policy, whether for financial gain, personal vendettas, or reputational enhancement.

If your analysis stops at “This person violated policy,” you miss the opportunity to uncover why they were willing to risk consequences. In many cases, systemic issues, misaligned incentives, toxic culture, and weak oversight drive the behavior. In every investigation, ask, “What’s in it for them? Understanding incentives, pressures, and personal agendas can reveal root causes that process analysis alone won’t uncover.

Lesson 4: Authority Structures Can Delay Recognition of the Problem

Illustrated by: Even when evidence mounts, the crew is reluctant to challenge “Kirk” because of the chain of command. Starfleet discipline dictates deference to the captain, making it harder to act on suspicions.

Compliance Lesson. In organizations, hierarchy can block efforts to identify root causes. Employees may hesitate to report misconduct by senior leaders, or they may assume questionable directives are “above their pay grade” to question.

This dynamic often allows problems to persist far longer than they should. A compliance program must be designed to bypass those bottlenecks, giving employees safe, confidential, and credible ways to report concerns, even about top executives. Ensure that escalation procedures allow for independent review of senior management conduct. Whistleblower protections, ombuds functions, and anonymous hotlines can help surface issues that otherwise stay buried.

Lesson 5: Validate Assumptions Before Acting

Illustrated by: Spock eventually confronts “Kirk” and demands an explanation. Through logical analysis and a mind meld, he confirms the truth of the body swap. Only then can the crew take decisive action to restore the captain to his rightful body.

Compliance Lesson. One of the biggest pitfalls in root cause analysis is acting on unverified assumptions. If you jump to conclusions too early, you may “fix” the wrong problem—or make it worse. Spock’s mind meld was the ultimate verification step. In compliance, your “mind meld” might be corroborating whistleblower claims with independent documentation or testing an internal control in multiple scenarios before concluding it’s defective.

Build verification into your root cause analysis process. Don’t settle for the first plausible explanation; pressure-test your conclusions before implementing remediation.

Connecting Star Trek to DOJ Expectations

The DOJ’s ECCP explicitly asks:

  • “What is the root cause of the misconduct? ”
  • “Were prior opportunities to detect the misconduct missed? ”
  • “What systemic failures contributed to the issue? ”

Turnabout Intruder illustrates the importance of addressing these questions. If the crew had stopped at “the captain is acting oddly” and focused on damage control, they might never have uncovered the deeper truth of Lester’s body swap. Similarly, in corporate investigations, stopping at the surface level (“employee violated policy”) without probing the environment that allowed it to happen fails both the DOJ’s expectations and your prevention mandate.

Final ComplianceLog Reflections

In Turnabout Intruder, the crew’s slow realization of the true problem nearly cost them their captain and perhaps the Enterprise itself. In the compliance arena, a slow or shallow root cause analysis can let misconduct persist, control weaknesses remain unaddressed, and systemic issues metastasize.

Effective compliance leadership means not just spotting what’s wrong but relentlessly pursuing why it went wrong. That’s how you fix the problem in a way that prevents recurrence.

Like Spock confronting “Kirk,” we must gather evidence methodically, test our conclusions, and act decisively once the truth is clear. Root cause analysis isn’t about blame—it’s about ensuring your organization emerges stronger, more transparent, and more resilient than before.

Because in the end, just like the Enterprise, your mission depends on having the right people in the right roles, operating with integrity, and that’s a result only a thorough, well-executed root cause analysis can guarantee.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Ted Lasso Week: Part 2 – Rebecca Welton: Misuse of Authority, Conflicts of Interest, and the Path to Accountability

Season 4 of Ted Lasso is out. Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over five blog posts, I will consider Manager Ted Lasso, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 2, we consider compliance lessons through the character of team owner Rebecca Welton.

In Part 1, we considered how Ted Lasso built psychological safety and an ethical culture while sometimes allowing empathy to outrun accountability. Rebecca Welton presents the problem from the other side of the executive table. She begins as the source of AFC Richmond’s misconduct, then becomes the leader best positioned to acknowledge it.

Rebecca’s story is not simply a redemption arc. It is a governance case study about what happens when personal objectives capture corporate authority. It also shows why confession, forgiveness, and improved behavior are necessary but insufficient elements of an effective remediation program. The compliance lesson is direct: power creates risk when no independent mechanism can question the person exercising it.

When the Owner Becomes the Risk

In “Pilot” (Season 1, Episode 1), Rebecca hires Ted, an American football coach with no soccer experience, to manage a Premier League club. Her stated rationale is irrelevant because her actual purpose is to destroy the institution Rupert Mannion loves. She uses Richmond’s people, reputation, competitive position, and financial value to pursue a private grievance.

That is a classic conflict between personal interest and organizational duty. Rebecca is not accepting an envelope of cash or steering a contract to a relative. Her conflict is more fundamental: she has converted corporate decision-making into an instrument of revenge. The COSO Internal Control Framework begins with the control environment, including integrity, ethical values, oversight, authority, and accountability. At Richmond, the control environment fails at the top. The owner sets an improper objective, possesses the authority to execute it, and faces no visible independent challenge.

Compliance officers should take note. Conflicts of interest do not end with disclosure forms. They arise whenever personal relationships, status, resentment, financial incentives, or outside interests can distort business judgment. The greater the executive’s authority, the stronger the required safeguards.

Concentrated Authority Silences Challenge

Rebecca’s plan requires assistance. Higgins facilitates her agenda even though he recognizes the harm. In “Make Rebecca Great Again” (Season 1, Episode 7), Rebecca arranges for a photographer to capture Ted and Keeley in a compromising image. The objective is not legitimate media strategy. It is manufactured reputational damage intended to destabilize Ted and the club.

Higgins is not merely an unfortunate bystander. He is a senior employee who allows access, information, and organizational machinery to serve the owner’s improper purpose. His eventual resignation is a delayed act of conscience, but the episode demonstrates how authority can corrupt the escalation process. Employees may know that conduct is wrong and still conclude that challenging the owner is futile or career-ending.

The DOJ Evaluation of Corporate Compliance Programs asks whether “compliance personnel (1) sufficient qualifications, seniority, and stature (both actual and perceived) within the organization; (2) sufficient resources, namely, staff to undertake the requisite auditing, documentation, and analysis effectively; and (3) sufficient autonomy from management, such as direct access to the board of directors or the board’s audit committee.” It also asks whether managers encourage or discourage compliance through their conduct. Richmond has no credible independent function capable of reviewing Rebecca’s decisions, investigating her conduct, or escalating around her.

Accountability Begins With Truth

Keeley becomes the effective speak-up channel Richmond lacks. Once she discovers Rebecca’s scheme, she does not accept friendship, hierarchy, or reputational risk as reasons to stay silent. She insists that Rebecca tell Ted the truth. Rebecca finally does so in “All Apologies” (Season 1, Episode 9). She admits that she hired Ted to fail, orchestrated the paparazzi scheme, and engineered Jamie Tartt’s return to Manchester City to weaken Richmond. Most importantly, she does not minimize her purpose. She explains that she wanted to hurt Rupert and used Ted and the club to do it.

This is an effective apology because it identifies conduct, intent, and harm. It also accepts the possibility of consequences. Yet it is not a remediation. Nevertheless, Ted forgives her immediately, but an actual organization could not stop there. The U.S. Sentencing Guidelines require an organization to respond appropriately after misconduct and take reasonable steps to prevent similar conduct. DOJ asks whether the company performed a root-cause analysis, disciplined responsible individuals, repaired controls, and tested whether remediation works.

Richmond would need an independent review of affected personnel decisions, financial consequences, sponsor and stakeholder impacts, the use of confidential information, and Higgins’s role. It would also need governance changes that prevent one executive from repeating the conduct. An apology can reopen trust. Only remediation can reduce recurrence risk.

The Conflict Problem Returns With Sam

Rebecca’s growth does not eliminate conflicts. In “The Signal” and “Headspace” (Season 2, Episodes 6 and 7), Rebecca discovers that her anonymous Bantr match is Sam Obisanya, a Richmond player. Their relationship develops in “Man City” (Season 2, Episode 8) and continues secretly into “No Weddings and a Funeral” (Season 2, Episode 10).

The relationship is portrayed with warmth and mutual affection. That does not resolve the organizational issue. Rebecca owns the club that controls Sam’s employment environment. Her decisions can affect contracts, playing resources, sponsorships, reputation, and career opportunities. Even if she never exercises that power improperly, the imbalance creates an appearance of favoritism and raises questions about consent, retaliation, confidentiality, and recusal.

The compliance response is not moral judgment. It is a process. A conflict policy must apply to owners and senior executives, not only employees. Disclosure should go to an independent board member or committee. The organization should document safeguards, remove the conflicted leader from relevant decisions, protect the less powerful party, and monitor for retaliation or preferential treatment. Rebecca eventually pauses the relationship, but Richmond never appears to activate a formal conflict-management process. Personal restraint is not a control.

From Personal Ownership to Stewardship

Rebecca’s leadership changes when she stops treating Richmond as property and begins treating it as an institution held in trust for others. In “Do the Right-est Thing” (Season 2, Episode 3), Sam protests sponsor Dubai Air because of its connection to environmental damage in Nigeria. Rebecca backs the players despite the commercial risk. She recognizes that sponsorship revenue does not outrank organizational values.

Her transformation is clearest in “International Break” (Season 3, Episode 10). Edwin Akufo invites elite club owners to join an exclusive league built around scarcity, control, and profit. Rebecca rejects the proposal by reminding the room that football belongs to the people whose lives and communities give it meaning. She chooses stakeholder legitimacy over a lucrative insiders’ arrangement.

In “So Long, Farewell” (Season 3, Episode 12), she completes that shift by selling 49 percent of Richmond to its supporters. The woman who once used the club as a weapon ultimately distributes part of its ownership to the community.

This is what ethical remediation should seek: not a return to the status quo, but a more accountable operating model.

Questions for CCOs

Rebecca’s journey should prompt five questions:

  1. Can an allegation against the CEO, founder, controlling shareholder, or board chair bypass that person and reach an independent decision-maker?
  2. Do conflict rules cover personal relationships, vendettas, reputational motives, and executive discretion, or only financial interests?
  3. When senior misconduct occurs, who controls the investigation, discipline, disclosure, and remediation plan?
  4. Does the board receive reliable information about culture and mission-critical risks without management filtering?
  5. Are remediation measures tested, documented, and sustained after the responsible leader apologizes?
  6. Rebecca Welton shows that leaders can change. Compliance must make that change governable. Trust is rebuilt when truth is followed by independent review, proportional accountability, control improvements, and evidence that the organization learned.

Next Up: Nate Shelley and Culture Risk

Rebecca’s failure begins with power concentrated at the top. Nate Shelley’s failure develops lower in the organization, where insecurity, humiliation, status, and unaddressed resentment turn a once-overlooked employee into a destructive manager and trusted insider. In Part 3, we will examine the warning signs Richmond missed, the consequences of promoting technical talent without preparing them to lead, and why a speak-up culture must detect harm committed by newly empowered employees as readily as misconduct committed by executives.