Categories
Blog

The Enterprise Incident: 5 Compliance Lessons from a High-Stakes Deception

In The Enterprise Incident, Captain Kirk appears to suffer a breakdown. He orders the USS Enterprise across the Neutral Zone and into Romulan territory, where three Romulan vessels immediately surround the ship. Kirk claims that a navigational error caused the incursion. Spock refuses to support that explanation. Instead, he testifies that Kirk has become irrational and is no longer fit for command. Dr. McCoy confirms the diagnosis. Kirk then appears to die after attacking Spock. Of course, none of this is what it seems.

Kirk, Spock, and McCoy are executing a classified Federation operation to steal a Romulan cloaking device. Kirk’s breakdown is staged. Spock’s betrayal is part of the plan. The supposed Vulcan death grip is a fiction. Kirk is surgically disguised as a Romulan, returns to the enemy vessel, steals the device, and escapes with the Enterprise.

The mission succeeds. Yet operational success does not necessarily establish that the underlying decisions were ethical, properly governed, or worth the risk. That tension makes The Enterprise Incident an outstanding study in compliance leadership. It presents five lessons for compliance professionals operating in high-pressure environments.

Lesson 1: Ethical Decision-Making Requires More Than Authorization

Kirk’s mission was not an impulsive act. He was operating under Federation orders. Nevertheless, the operation required deception, an illegal border crossing, theft of sensitive technology, and conduct that could have triggered an interstellar conflict. Authorization matters, but authorization alone does not resolve the ethical question.

Corporate misconduct is often defended with some variation of “senior management approved it” or “the business required it.” Those statements do not transform improper conduct into ethical conduct. They may instead reveal weaknesses in governance, escalation, and executive accountability.

Compliance leaders must ask whether a proposed course of action is consistent with the organization’s legal obligations, stated values, risk appetite, and long-term interests. They must also consider whether the action could withstand scrutiny from regulators, shareholders, employees, and the board. Under pressure, the temptation is to focus exclusively on the desired outcome. The stronger approach is to examine both the objective and the means used to achieve it.

A successful mission can still represent a governance failure. Compliance must help the organization distinguish between what it can do, what it should do, and what it must never do.

Lesson 2: Confidentiality Must Not Eliminate Accountability

The Enterprise crew succeeds because Kirk, Spock, McCoy, and Scotty understand their roles and trust one another. Within that small group, the plan is carefully coordinated. Outside the group, almost everyone is intentionally misled. This is a classic need-to-know operation. It also demonstrates the risk created when secrecy becomes a substitute for accountability.

Organizations sometimes need to restrict information. Internal investigations, acquisition discussions, government inquiries, cybersecurity incidents, and sensitive personnel matters all require confidentiality. The mistake is assuming that confidentiality means normal controls no longer apply. Even the most sensitive matter should have an accountable owner, defined decision rights, appropriate legal oversight, protected documentation, and a process for reporting to the board when necessary. Information may be limited, but accountability should remain clear.

This lesson is particularly important in internal investigations. An investigation may require discretion, but the organization must still preserve evidence, manage conflicts, document decisions, protect against retaliation, and identify who receives the findings. The key distinction is between controlled confidentiality and organizational opacity. Controlled confidentiality protects the integrity of the process. Opacity protects decision-makers from scrutiny. Trust among a small team is valuable. It is not a replacement for governance.

Lesson 3: Sensitive Technology Demands Controls Across Its Entire Lifecycle

The Romulan cloaking device is more than a valuable piece of equipment. It is strategically significant technology capable of changing the balance of power. The Enterprise crew focuses first on acquiring the device. Scotty must then integrate an unfamiliar piece of Romulan technology into the ship’s systems while the Enterprise is under attack. There is little time for testing, security review, or compatibility analysis.

Modern organizations face similar issues with artificial intelligence, source code, proprietary algorithms, customer data, trade secrets, surveillance tools, and cybersecurity capabilities. The risk does not begin or end with acquisition. It extends across the technology’s entire lifecycle. The cloaking device also raises a broader question: Just because technology can create a strategic advantage, should the organization deploy it immediately?

That question is central to AI governance. A new AI system may promise speed, efficiency, and competitive advantage. It may also create risks related to privacy, discrimination, intellectual property, cybersecurity, and regulatory compliance. The organization needs more than an enthusiastic business sponsor. It needs governance, testing, documentation, human oversight, and clear accountability. Innovation without controls creates unmanaged exposure. Controls without an understanding of the technology create false assurance.

Lesson 4: Regulatory and Geopolitical Risk Must Be Built into Strategy

The Neutral Zone is not simply a line on a star chart. It represents a legal, diplomatic, and military boundary. Crossing it creates consequences that extend far beyond the Enterprise. International businesses operate across their own versions of the Neutral Zone. These include anti-bribery laws, sanctions, export controls, data localization requirements, competition rules, human rights expectations, and restrictions on technology transfers.

A decision that appears commercially attractive in one jurisdiction may create serious exposure in another. A third party that looks essential to market access may present corruption or sanction risks. A technology transfer may implicate national security restrictions. A routine payment may become evidence of an improper inducement. Compliance cannot be brought in after the business has crossed the border.

The compliance function should participate in market-entry decisions, transactions, major technology transfers, and relationships involving government touchpoints. This requires more than maintaining a regulatory inventory. It requires understanding how legal, political, cultural, and enforcement risks affect business strategy. The Enterprise had only one hour to respond to the Romulan demand for surrender. Corporate leaders often face similar pressure, although usually without disruptor beams. The time to establish decision protocols is before the crisis begins.

Lesson 5: Compliance Should Enable Calculated Risk, Not Eliminate It

Stealing the cloaking device was extraordinarily risky. It also offered a significant strategic benefit. Starfleet decided that the potential value justified the exposure. Every organization takes risks. The purpose of compliance is not to eliminate risk or prevent innovation. It is to help the organization understand risk, evaluate it intelligently, establish limits, and make accountable decisions.

A calculated risk is not simply a dangerous decision that happens to succeed. It is a decision supported by reliable information, appropriate expertise, documented assumptions, mitigation measures, clear ownership, and contingency planning. The Enterprise mission depended on several assumptions. The Romulans had to accept Kirk’s apparent instability. The commander had to believe Spock’s betrayal. Kirk’s disguise had to work. Scotty had to integrate the cloaking.

Compliance adds value when it helps the business take better risks. That requires early engagement, commercial understanding, credible challenge, and a willingness to say no when the proposed conduct crosses a legal or ethical boundary.

Final Thoughts

The Enterprise Incident ends with the Enterprise escaping Romulan space under the protection of the stolen cloaking device. The operation succeeds because of extraordinary coordination, technical skill, and trust. Yet the episode leaves compliance professionals with a harder question: Was the mission properly governed, or was it simply successful?

That distinction matters. Results do not validate weak processes. Senior approval does not cure unethical conduct. Confidentiality does not remove accountability. Innovation does not override controls. Strategic pressure does not suspend legal obligations. The compliance professional’s role is to help the organization navigate those tensions before it enters the Neutral Zone.

The final compliance lesson from The Enterprise Incident is straightforward: Bold leadership may take the organization into uncertain territory, but effective compliance ensures that it does not cross the line without understanding what lies on the other side.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Red Flags Rising

Red Flags Rising: S01 E37: Carole Basri on Subsidizing World Peace: The U.S. Experiment, and the Dynamic Relationship between National Security & Corporate Compliance

Back in January 2024, Mike and Brent had the good fortune to meet Carole Basri at an event at NYU Law School. On this episode of Red Flags Rising, they welcome her as a guest to talk about her specialties: national security, geopolitics, and corporate compliance. They specifically discuss Carole’s extensive professional background (00:59), a new treatise on National Security Law that Carole, Mike, and Brent are writing for the Practising Law Institute (PLI) (04:00), an upcoming event co-hosted by the New York State Bar Association’s International Section, Corporate Compliance Committee and Morgan Lewis, to which the new Assistant Secretary for Export Enforcement David Peters is an invited keynote speaker (08:18), why public enforcement officials remarks are relevant under U.S. export controls and other probability-based (i.e., “red flags”-driven) national security laws (09:26), how the U.S. Foreign Corrupt Practices Act (FCPA) was not only an example of that but also was really a child of an era where economic interdependency required a level of transparency and clean commerce to continue (12:00), and the relationship between Bretton Woods, Belt and Road, and Mike’s favorite book, Tales of an Economic Hitman, and what could be viewed with hindsight as effectively a U.S. policy decision to trade its own economic security for decades of (relative) world peace, increased global productivity, and increased living standards (16:52). Brent then closes out the discussion with the latest installment of his “Managing Up” segment (21:57), after which Mike makes some (further) book recommendations based on the discussion for those interested in further exploring some of the idea and concepts covered during the discussion:

More about Carole

Contact Brent: brent@redflagsrising.com

Contact Mike: michael.huneke@morganlewis.com

Interested in learning more about the March 10, 2026, event? Contact Mike & Brent at the email addresses above.

Categories
Principled Podcast

Season 8 – Episode 12 – Part 2: Geopolitics and the Interconnectedness of Compliance Risks

What you’ll learn on this podcast episode

In this episode of the Principled Podcast, host Susan Divers continues her conversation from Episode 11 with Tom Fox, the founder of the Compliance Podcast Network, on the changing geopolitical landscape and its impact on E&C. Listen in as the two discuss how anti-corruption is a key component of ESG, the consequences of compliance in cybersecurity, and the growing interconnectedness of risks. You can listen to Episode 11 here. 

To learn more, download a copy of Tom Fox’s white paper Never the Same: Five Key Areas in Which Business Will Never Be the Same After the Russian Invasion. 

Guest: Tom Fox

Tom_Fox_grayscale

Tom Fox is literally the guy who wrote the book on compliance with the international compliance best-seller The Compliance Handbook, 3rd edition, which was released by LexisNexis in May 2022. Tom has authored 23 other books on business leadership, compliance and ethics, and corporate governance, including the international best-sellers Lessons Learned on Compliance and Ethics and Best Practices Under the FCPA and Bribery Act, as well as his award-winning series “Fox on Compliance.”

Tom leads the social media discussion on compliance with his award-winning blog, and is the Voice of Compliance, having founded the award-winning Compliance Podcast Network and hosting or producing multiple award-winning podcasts. He is an executive leader at the C-Suite Network, the world’s most trusted network of C-Suite leaders. He can be reached at tfox@tfoxlaw.com.

Host: Susan Divers

Susan_Divers_Principled_Podcast

Susan Divers is the director of thought leadership and best practices with LRN Corporation. She brings 30+ years’ accomplishments and experience in the ethics and compliance arena to LRN clients and colleagues. This expertise includes building state-of-the-art compliance programs infused with values, designing user-friendly means of engaging and informing employees, fostering an embedded culture of compliance, and sharing substantial subject matter expertise in anti-corruption, export controls, sanctions, and other key areas of compliance.

Prior to joining LRN, Mrs. Divers served as AECOM’s Assistant General for Global Ethics & Compliance and Chief Ethics & Compliance Officer. Under her leadership, AECOM’s ethics and compliance program garnered six external awards in recognition of its effectiveness and Mrs. Divers’ thought leadership in the ethics field. In 2011, Mrs. Divers received the AECOM CEO Award of Excellence, which recognized her work in advancing the company’s ethics and compliance program.

Before joining AECOM, she worked at SAIC and Lockheed Martin in the international compliance area. Prior to that, she was a partner with the DC office of Sonnenschein, Nath & Rosenthal. She also spent four years in London and is qualified as a Solicitor to the High Court of England and Wales, practicing in the international arena with the law firms of Theodore Goddard & Co. and Herbert Smith & Co. She also served as an attorney in the Office of the Legal Advisor at the Department of State and was a member of the U.S. delegation to the UN working on the first anti-corruption multilateral treaty initiative.

Mrs. Divers is a member of the DC Bar and a graduate of Trinity College, Washington D.C. and of the National Law Center of George Washington University. In 2011, 2012, 2013 and 2014 Ethisphere Magazine listed her as one the “Attorneys Who Matter” in the ethics & compliance area. She is a member of the Advisory Boards of the Rutgers University Center for Ethical Behavior and served as a member of the Board of Directors for the Institute for Practical Training from 2005-2008. She resides in Northern Virginia and is a frequent speaker, writer and commentator on ethics and compliance topics.

 

Categories
Principled Podcast

Season 8 – Episode 11 – Part 1: Geopolitics are Impacting Workplace Ethics and Compliance Programs

What you’ll learn on this podcast episode

As the world emerges from a pandemic mindset, we confront new geopolitical realities with Putin’s war in Ukraine and increasingly fraught relations between the US and China. How is this geopolitical landscape changing the compliance landscape? In this episode of the Principled Podcast, host Susan Divers is joined by Tom Fox, the founder of the Compliance Podcast Network and aptly accredited “Voice of Compliance.” Listen in as the two discuss the impact of geopolitics on ethics and compliance and what issues should be top-of-mind for E&C leaders in the near future.

To learn more, download a copy of Tom Fox’s white paper Never the Same: Five Key Areas in Which Business Will Never Be the Same After the Russian Invasion.

Guest: Tom Fox

Tom_Fox_grayscale

Tom Fox is literally the guy who wrote the book on compliance with the international compliance best-seller The Compliance Handbook, 3rd edition, which LexisNexis released in May 2022. Tom has authored 23 other books on business leadership, compliance, ethics, and corporate governance, including the international best-sellers Lessons Learned on Compliance and Ethics and Best Practices Under the FCPA and Bribery Act, as well as his award-winning series “Fox on Compliance.”

Tom leads the social media discussion on compliance with his award-winning blog and is the Voice of Compliance, having founded the Compliance Podcast Network and hosting or producing multiple award-winning podcasts. He is an executive leader at the C-Suite Network, the world’s most trusted network of C-Suite leaders. He can be reached at tfox@tfoxlaw.com.

Host: Susan Divers

Susan_Divers_Principled_Podcast

Susan Divers is the director of thought leadership and best practices with LRN Corporation. She brings 30+ years of accomplishments and experience in the ethics and compliance arena to LRN clients and colleagues. This expertise includes building state-of-the-art compliance programs infused with values, designing user-friendly means of engaging and informing employees, fostering an embedded culture of compliance, and sharing substantial subject matter expertise in anti-corruption, export controls, sanctions, and other key areas of compliance.

Prior to joining LRN, Mrs. Divers served as AECOM’s Assistant General for Global Ethics & Compliance and Chief Ethics & Compliance Officer. Under her leadership, AECOM’s ethics and compliance program garnered six external awards in recognition of its effectiveness and Mrs. Divers’ thought leadership in the ethics field. In 2011, Mrs. Divers received the AECOM CEO Award of Excellence, recognizing her work advancing the company’s ethics and compliance program.

Before joining AECOM, she worked at SAIC and Lockheed Martin in the international compliance area. Before that, she partnered with the DC office of Sonnenschein, Nath & Rosenthal. She also spent four years in London and is qualified as a Solicitor to the High Court of England and Wales, practicing in the international arena with Theodore Goddard & Co. and Herbert Smith & Co law firms. She also served as an attorney in the Office of the Legal Advisor at the Department of State. She was a member of the U.S. delegation to the UN, working on the first anti-corruption multilateral treaty initiative.

Mrs. Divers is a member of the DC Bar and a graduate of Trinity College, Washington D.C., and of the National Law Center of George Washington University. In 2011, 2012, 2013, and 2014 Ethisphere Magazine listed her as one of the “Attorneys Who Matter” in the ethics & compliance area. She is a member of the Advisory Boards of the Rutgers University Center for Ethical Behavior and served as a member of the Board of Directors for the Institute for Practical Training from 2005-2008. She resides in Northern Virginia and is a frequent speaker, writer, and commentator on ethics and compliance topics.