Categories
Blog

The NBA/Clippers Investigation: Part 5 – Lessons for CCOs and Boards

The ultimate measure of a compliance program is whether it can constrain the people the organization believes it cannot afford to disappoint. Most compliance programs are designed for ordinary decisions made by ordinary employees. The real danger lies in extraordinary decisions involving people with unusual economic power. Today we conclude with lessons learned.

They may be founders, controlling owners, senior executives, rainmakers, celebrity endorsers, critical customers, or star performers. Their value to the organization can become a reason to bypass controls, reinterpret rules, or treat prohibited requests as business problems requiring creative solutions.

The investigation into the LA Clippers and Kawhi Leonard demonstrates what happens when that pressure enters the commercial ecosystem. The independent investigators’ report (Wachtell Report) concluded that Clippers leaders helped create outside-income opportunities for Leonard through companies doing business with the team, linked vendor business to endorsement arrangements, paid impermissible personal expenses, and failed to report prohibited demands.

The lessons reach well beyond professional sports. They reach into all businesses. Finally, they apply wherever commercial urgency can overwhelm governance.

Lesson One: Power Is a Compliance Risk Factor

Traditional risk assessments organize risk by geography, business unit, transaction type, or regulatory subject. They often overlook individual power.

Organizations should identify people whose economic importance, ownership position, revenue contribution, reputation, or personal relationship with leadership could weaken ordinary controls. This is not an accusation against those individuals. It is recognition that employees may respond differently when a request comes from someone perceived as indispensable.

The DOJ’s Evaluation of Corporate Compliance Programs asks whether risk management is proactive, whether resources follow risk, and whether senior leaders persist in their commitment to compliance when facing competing business objectives. A power-risk assessment helps answer those questions.

Lesson Two: Prior Misconduct Must Change the System

The Clippers had a prior circumvention violation. The NBA later investigated improper demands associated with Leonard’s 2019 free agency, established a reporting requirement, and trained the team’s senior leadership. Yet the Wachtell Report concluded that similar risks materialized again.

Training is not remediation unless the organization can demonstrate changed behavior. After an incident, compliance should identify the root cause, assign control owners, establish deadlines, test effectiveness, and report results to the board. The inquiry should continue until the organization can show it has materially reduced the opportunity for recurrence. DOJ expressly asks whether companies incorporate lessons from their own misconduct and from similar problems at peer organizations. The Organizational Sentencing Guidelines likewise make prior history relevant to risk assessment, program design, and organizational culpability.

Lesson Three: Compliance Must Have Independent Authority

The question is not whether the organization employs compliance professionals. It is whether those professionals can challenge a powerful executive, suspend a transaction, obtain complete information, and reach an independent board committee without management permission.

The DOJ evaluates whether compliance has adequate qualifications, seniority, stature, resources, autonomy, and direct board access. These are operational requirements, not organizational-chart preferences. A CCO who can advise but cannot stop or escalate is not empowered. A compliance committee dominated by the executives sponsoring the transaction is not independent. A board that receives only management-filtered information is not exercising informed oversight.

Lesson Four: Follow the Entire Commercial Relationship

The Clippers investigation involved sponsorships, consulting agreements, sustainability services, an owner’s investment, player endorsements, vendor payments, and personal expenses. Reviewing each transaction separately could obscure the common purpose. Compliance needs a consolidated view of the relationship. That requires common identifiers across procurement, contracts, accounts payable, expenses, conflict disclosures, gifts, sponsorships, and third-party systems.

The most useful question may be simple: What other business do we have with this person or entity? Make that question mandatory when a transaction involves a significant vendor, executive relationship, personal investment, public official, customer representative, agent, or other high-risk beneficiary.

Lesson Five: Test Economic Substance

According to the Wachtell Report, several endorsement arrangements had unusual economics, limited performance obligations, little public activation, and compressed negotiation timelines. Consulting agreements involved substantial advance payments. Separate agreements contained matching or closely connected amounts. The COSO Internal Control–Integrated Framework reminds organizations that controls support compliance and operational objectives, not simply accurate accounting. A payment can be correctly recorded and still serve an improper purpose.

Controls should test business rationale, market value, deliverables, proof of performance, payment timing, ultimate beneficiary, and connections to other transactions. Internal audit should be authorized to ask whether a contract makes commercial sense, not merely whether an authorized person signed it.

Lesson Six: Mandatory Reporting Requires a Closed Loop

The Wachtell Report found that Clippers leaders did not report improper solicitations made on Leonard’s behalf, despite a rule requiring reporting even if a request was rejected. A mandatory reporting policy needs more than a sentence in the code of conduct. It requires defined triggers, responsible owners, escalation deadlines, documentation, non-retaliation protection, and verification that the report reached the required recipient.

Organizations should test the reporting control. Present leaders with realistic scenarios and ask what they would do, whom they would contact, and how quickly. If answers vary, the control is not operating reliably.

Lesson Seven: Red Flags Must Reach Someone Who Can Act

The Wachtell Report described unusual payment structures, internal concern about the Forum transaction, resistance from Aspiration executives, and explicit communications linking Clippers business to Leonard’s endorsement agreement. Red flags do not protect an organization merely because they exist in an email archive. They must reach a person with authority, independence, and responsibility to act.

Boards should identify mission-critical compliance risks and establish reporting systems that deliver meaningful information. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes the board’s obligation to make a good-faith effort to establish and monitor reporting systems for central compliance risks. That does not make every control failure a Caremark violation. It does mean that silence at the board level is not a defensible oversight model.

Lesson Eight: Investigation Conduct Is Compliance Conduct

Investigators assessed not only the underlying transactions but also witness credibility and cooperation. They distinguished between witnesses who accepted responsibility and those whose accounts conflicted with documents or changed over time.

Organizations should prepare for investigations before a crisis. Document preservation, witness instructions, privilege protocols, anti-retaliation protections, escalation duties, and cooperation standards should already be in place. Outside counsel should defend legitimate interests without impairing the organization’s ability to learn the truth. An investigation is not solely a litigation event. It tests culture and governance.

Lesson Nine: Accountability Must Reach Supervisors

The NBA’s penalties included a $30 million organizational fine, forfeiture of five first-round draft picks, individual suspensions, a payment by Leonard, a five-year restriction on Robertson, and a five-year compliance and monitoring program.

The sanctions reached individuals based on different forms of responsibility, including direct conduct, approval, supervision, and organizational leadership. Corporate consequence management should do the same. Employees who participate directly should be accountable, but so should managers who ignore red flags, approve unsupported exceptions, or fail to supervise. Enforce compliance consistently, regardless of commercial value or title.

Lesson Ten: The Board Must Oversee the Pressure Points

Boards do not need to approve every sponsorship, vendor agreement, or expense report. They do need visibility into the areas where incentives, power, and mission-critical compliance risks intersect.

The board should receive reporting on high-risk transactions, control overrides, related-party relationships, significant investigations, repeated policy violations, executive discipline, and remediation testing. It should meet privately with the CCO and internal audit leader and confirm both functions have the information and resources they need. Board oversight is not passive dashboard receipt. It is an informed challenge followed by documented action.

Practical Takeaways: A 90-Day Agenda

CCOs and risk leaders can translate these lessons into action:

  • Identify the organization’s most powerful internal and external stakeholders and assess where their requests could bypass controls.
  • Review prior investigations, violations, and audit findings to confirm that remediation was implemented and tested.
  • Map all relationships involving high-risk vendors, personal investments, sponsorships, consulting arrangements, and individual beneficiaries.
  • Establish independent review for transactions involving controlling owners, senior executives, or conflicts of interest.
  • Test procurement, payment, expense, and reporting controls using real transaction data.
  • Give compliance documented stop-work and escalation authority.
  • Define investigation cooperation and consequence-management standards before the next allegation.
  • Provide the board with targeted reporting on control overrides, repeat issues, and high-risk relationships.

The final lesson from the Clippers investigation is straightforward. Compliance fails when the organization treats the rule as an obstacle and the desired outcome as nonnegotiable. An effective program reverses that order. The rule defines the boundary, and the business must operate within it. The true measure of compliance is whether the organization can say no when yes would be more profitable, more convenient, or more popular. That is where governance becomes real.

Categories
Blog

The Clippers Investigation: Part 4 – Consequence Management at the Top

The Clippers penalties demonstrate that discipline is not the end of a compliance process. They are a public test of whether rules apply to powerful people. The Clippers investigation demonstrates why conflict controls must follow influence, economic benefit, and interconnected transactions, not merely financial ownership. In this Part 4 of a five-part series, we consider the consequences of cheating and not following the rules and regulations your organization agrees to comply with going forward. Every organization claims that no one is above the rules. Consequence management determines whether that statement is true.

The test does not come when a junior employee commits an obvious policy violation. It comes when the conduct involves a founder, controlling owner, senior executive, star performer, or other person viewed as essential to the business. The investigation into the LA Clippers and Kawhi Leonard presents that test in unusually clear terms. The independent investigators’ report of the Clippers’ NBA salary cap circumvention (Wachtell Report) attributed primary responsibility to Clippers owner Steve Ballmer, President of Business Operations Gillian Zucker, and President of Basketball Operations Lawrence Frank. It also found violations by Leonard through the conduct of his uncle and then-business manager, Dennis Robertson (Uncle Dennis).

The NBA responded with organizational, financial, individual, competitive, and monitoring consequences. For compliance professionals, the case provides a framework for considering who should be held accountable, for what conduct, and through what mechanism.

From Punishment to Consequence Management

Punishment looks backward. It asks what sanction should follow a violation. Consequence management is broader. It identifies misconduct, investigates responsibility, calibrates discipline, addresses supervisory failures, remediates control weaknesses, and communicates the organization’s expectations. All of this brings me to one of my favorite compliance phrases: consequence management.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) introduces consequence management procedures as procedures to identify, investigate, discipline, and remediate violations of law, regulation, or policy. It goes on to state that every organization must enforce them consistently across the organization and ensure the procedures are commensurate with the violations. It concludesProsecutors should also assess the extent to which the company’s communications convey to its employees that unethical conduct will not be tolerated and will bring swift consequences, regardless of the employee’s position or title

Consequence Calibration

The report provides several categories for assessing responsibility.

  1. Direct participation. Investigators concluded that Zucker initiated, facilitated, and induced endorsement agreements involving Leonard and four Clippers business partners. They found that Ballmer knowingly sought to help Leonard obtain outside income and approved the Forum agreement after learning that Aspiration had tied it to Leonard’s endorsement arrangement. Frank conveyed Robertson’s demands and approved impermissible personal expenses.
  2. Supervisory responsibility. The report concluded that Ballmer failed to supervise the organization’s most senior business executive and failed to create conditions supporting compliance with the circumvention rules.
  3. Reporting responsibility. Investigators found that Ballmer, Zucker, and Frank did not report Robertson’s improper demands, despite an NBA rule requiring those reports even when the solicitation was rejected.
  4. Personal or represented conduct. The report concluded that Leonard, through Robertson, pressured the team to help obtain outside income and failed to reimburse certain personal expenses. Robertson allegedly made the demands and applied the pressure.

A defensible consequence decision should map each individual to the conduct, knowledge, authority, benefit, supervisory obligation, and missed opportunity to intervene. Titles alone should neither establish nor eliminate responsibility.

Credibility and Cooperation Matter

The report did something particularly useful for compliance officers: it distinguished among witness behavior. Investigators wrote that Zucker made statements inconsistent with contemporaneous documents and other witnesses, professed limited recollection on significant issues, placed responsibility on subordinates, and provided inconsistent versions of events.

By contrast, they reported that Frank discussed his conduct openly, recalled important details, accepted responsibility for subordinates, and remained generally consistent across interviews. The investigators stated that cooperation and credibility, or their absence, should factor into determining consequences.

Cooperation does not erase underlying conduct. It should, however, affect how consequences are calibrated. An employee who preserves documents, provides candid information, accepts responsibility, and assists remediation presents a different risk from one who misleads investigators or shifts blame.

The organization should define cooperation before an investigation begins. Employees should understand that cooperation requires truthful, complete, and timely responses; preserving relevant information; correcting prior inaccuracies; and no retaliation or interference. It does not require surrendering legitimate legal rights.

Prior Misconduct Changes the Analysis

The Clippers had previously been penalized for a salary-cap circumvention violation involving an endorsement opportunity. The NBA had also investigated demands made during Leonard’s 2019 free agency and provided specific training to Clippers leaders.

Prior history matters because it changes what the organization and its leaders reasonably should have done. A first incident may reveal an unrecognized risk. A repeated incident following investigation, rule clarification, and training raises questions about culture, supervision, remediation, and willingness to comply.

The Sentencing Guidelines identify prior organizational history as relevant to culpability and direct organizations to consider similar misconduct when designing an effective program. DOJ likewise asks whether policies, training, controls, and risk assessments incorporate lessons from prior incidents.

Remediation that ends with training is incomplete. The organization must test whether behavior, decision rights, escalation pathways, and controls changed.

The NBA’s Consequence Framework

The NBA’s official action included multiple forms of individual accountability. The box score of individual consequences reads as follows:

Person Relationship Consequence
Steve Ballmer Owner: LA Clippers Fine and one-year ban
Gillian Zucker Clippers President of Business Operations One-year unpaid suspension
Lawrence Frank Clippers President of Basketball Operations 6-month Unpaid Suspension
Kawhi Leonard Clipper Player $700K fine
Uncle Dennis Leonard Representative 5-Year Ban from NBA

These measures address different risks. For corporate compliance programs, the equivalent toolkit may include termination, suspension, bonus reduction, clawbacks where legally available, promotion restrictions, written warnings, removal of approval authority, enhanced supervision, vendor termination, and mandatory remediation. Consequences need not be identical, but the process must be consistent. Consistency means applying the same decision factors to similarly situated people. It does not mean imposing the same outcome regardless of role, intent, cooperation, history, or responsibility.

Practical Takeaways

CCOs, human resources leaders, and boards should consider the following:

  • Adopt written consequence-management procedures before a significant investigation occurs.
  • Use a consistent decision matrix covering conduct, intent, seniority, authority, benefit, cooperation, prior history, and supervisory responsibility.
  • Separate factual findings from disciplinary decisions, and ensure decision-makers understand the evidentiary record.
  • Document why similarly situated individuals received similar or different outcomes.
  • Apply financial consequences where permitted and align future compensation with compliance performance.
  • Communicate substantiated outcomes internally with enough detail to reinforce expectations while respecting legal and privacy constraints.
  • Track disciplinary data by level, function, geography, and type of misconduct to identify inconsistency.
  • Require independent board oversight when senior management is implicated.

Consequence management is where culture becomes measurable. If the organization protects its most powerful people, employees will understand that performance outranks integrity. If it applies a fair, independent, and proportionate process, employees will understand that compliance is part of how the business operates.

In our final blog post, we will bring the series together and develop a practical framework for CCOs, boards, and risk leaders seeking to build a compliance program that can say no to the star.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the NBA’s sanctions against the Los Angeles Clippers for a salary-cap circumvention scheme tied to Kawhi Leonard.

In this delicious set of compliance imbroglios, senior management, including owner Steve Ballmer, allegedly arranged sham endorsement deals with four business partners and offsetting Clippers business to funnel about $18 million in extra compensation, plus improperly pay Leonard’s personal expenses. Tom and Matt review the Wachtell Lipton 36-page investigation detailing sparse contracts, unusual counterparties, rapid deal timing, and incriminating emails (including from Gillian Zucker), as well as recidivism after a similar 2019 violation. Penalties include a $30 million team fine, Leonard’s $700K fine, loss of first-round picks for five years, and suspensions for Ballmer, Zucker, and the basketball operations executive. Meanwhile, Ballmer denies wrongdoing and says the Clippers will file an appeal. They highlight contract-management and third-party due diligence lessons from FCPA-style guidance, the need to analyze patterns across multiple agreements, and the value of strong compliance roles in pro sports.

Key highlights:

  • NBA Scandal Overview
  • How The Scheme Worked and Why Salary Caps Matter
  • Sham Contracts = Red Flags
  • Paper Trail and Intent
  • Recidivism and Tone at the Top
  • Contract Patterns Lessons

Resources:

Matt in Radical Compliance

Tom in the FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and w3 Awards, all for podcast excellence.

Categories
Blog

The NBA/Clippers Investigation: Part 3 – Paper Compliance Is Not an Internal Control: Substance, Procurement, and the Audit Trail

The Clippers investigation shows why contracts, approvals, and carefully drafted emails cannot substitute for controls that test economic reality. In Part 3 of a five-part series, we explore why and how a transaction can have a contract, an approval, an invoice, and an email trail and still pose a serious compliance problem. Documentation proves that a process occurred. It does not prove that the process was legitimate.

That distinction sits at the center of the investigation into the LA Clippers and Kawhi Leonard. The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement arrangements between Leonard and four companies doing business with the team, induced those arrangements by offering business to the companies, paid impermissible personal expenses, and failed to meet improper demands made on Leonard’s behalf.

The alleged conduct crossed organizational boundaries. It touched business operations, basketball operations, procurement, sponsorships, consulting arrangements, accounts payable, expenses, legal review, and executive management. That makes this an internal controls case.

The Difference Between Evidence and Control

One of the report’s most important findings concerned introduction emails sent by Clippers President of Business Operations Gillian Zucker. The emails were written as if Boingo, Daktronics, Lockton, and later Aspiration had requested introductions to Leonard’s representatives. NBA rules permitted a narrow response when a commercial partner initiated such a request. They did not permit the team to create the opportunity for the player. The investigators concluded that the emails did not reflect the true sequence of events and, in Aspiration’s case, were created after deal development was already underway.

This is a classic paper-compliance problem. The communication used the language of the rule without satisfying its substance. A control cannot merely ask whether an introduction email contains the approved wording. It must test who initiated the contact, what discussions preceded the email, who proposed the economics, and whether team personnel remained involved afterward. Checklists confirm the form. Effective controls challenge reality.

Fragmented Transactions Hid a Common Purpose

The Wachtell Report described multiple agreements that could have appeared unrelated in separate systems. Vendors entered consulting or services agreements with the Clippers while also entering endorsement agreements with Leonard. Aspiration had sponsorship, sustainability, investment, forum, and player-endorsement relationships involving overlapping parties.

Investigators connected those transactions through timing, matching amounts, communications, and business leverage. Two companies reportedly received $10 million in consulting payments before entering endorsement agreements with Leonard. A third received a $2 million consulting payment one day after making its first payment to him.

The Forum agreement initially contemplated $7 million in annual business for Aspiration. That figure matched the annual cash component of Leonard’s endorsement agreement. Investigators further reported that the underlying carbon analysis did not generate the $28 million budget. Instead, the consultant said the Clippers supplied that budget.

The control failure was fragmentation. Procurement reviewed one agreement, marketing another, finance a payment, and business leaders the broader relationship. No control appears to have aggregated the transactions and asked whether one funded, induced, or conditioned another.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) tells prosecutors to examine how misconduct was funded, including purchase orders and reimbursements (How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash?); what controls could have prevented access to those funds (What controls failed?); whether vendor-selection procedures were followed (If vendors were involved in the misconduct, what was the process for vendor selection and did the vendor undergo that process?); and whether contract terms, payment terms, performance, and compensation were appropriate. Those are precisely the questions an organization should ask before enforcement authorities arrive.

Control Environment

The control environment begins with leadership and accountability. According to the report, the most senior business and basketball executives participated in or knew about key parts of the conduct. Investigators concluded that Ballmer failed to create conditions in which the organization followed rules it had previously violated. When senior leaders create the risk, lower-level approvals are unlikely to function as meaningful controls. Employees may view an executive request as authorization to proceed, even when the transaction presents obvious concerns.

Risk Assessment

The Clippers had a prior circumvention violation and were investigated over Leonard’s free-agency negotiations. The NBA had then provided specific training and imposed a mandatory reporting obligation. That history should have produced a targeted risk assessment covering player representatives, sponsor introductions, endorsement arrangements, personal expenses, vendor spend-back programs, and benefits flowing through third parties. Prior misconduct is not simply history. It is risk data.

Here, the ECCP asked some direct questions, including, “Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations?” Additionally, it notes that critical factors in evaluating any program include whether the program is adequately designed to maximize effectiveness in preventing and detecting employee wrongdoing and whether corporate management enforces the program or tacitly encourages or permits employees to engage in misconduct.

Control Activities

The Wachtell Report suggests potential gaps in segregation of duties, conflict review, procurement approval, contract benchmarking, expense reimbursement, and related-transaction analysis. High-risk transactions should require independent approval outside the requesting executive’s chain of command. Controls should compare compensation with deliverables, confirm actual performance, flag advance payments, and identify common counterparties across procurement and non-procurement systems.

Information and Communication

The organization reportedly had information that should have triggered escalation: demands for $10 million in annual off-court income, unusual endorsement economics, concerns from Aspiration executives, internal descriptions of a Forum deal as “shady,” and explicit threats connecting the Forum and Leonard agreements. Indeed, Uncle Dennis’s presence alone was enough of a red flag based on his prior conduct. The issue was not the absence of information. It was the failure to move that information to a function with the independence and authority to act.

Monitoring

Hundreds of personal expenses were reportedly paid without the required deduction or reimbursement. Multiple vendors signed unusual endorsement arrangements, with minimal public activation or performance. These were recurring patterns, not one-time exceptions. Monitoring should identify patterns across time. If a control repeatedly approves exceptions without examining their cumulative effect, it is not monitoring risk. It is normalizing it.

Designing Controls for Substance

An effective control architecture should include three layers. Preventive controls should require documented business rationale, competitive sourcing, conflict disclosures, independent approval, clear deliverables, market benchmarking, and legal and compliance review before committing funds.

Detective controls should compare related transactions, test payment timing, examine overrides, confirm performance, and monitor expense exceptions. They should search for patterns across legal entities and business functions. Responsive controls should define who receives red flags, when compliance can stop payment, when issues reach the audit committee, and how remediation is tracked to completion. The most important design principle is independence. The DOJ asks whether compliance has adequate authority, stature, resources, and direct access to the board. (Where within the company is the compliance function housed (e.g., within the legal department, under a business function, or as an independent function reporting to the CEO and/or board?)

If executives can bypass or overrule the control function without documented challenge, the program is not empowered.

Practical Takeaways

Compliance, audit, and risk leaders should take the following actions:

  • Inventory all systems containing vendor, contract, payment, expense, sponsorship, and conflict information.
  • Build monitoring systems that identify common parties and beneficiaries across those systems.
  • Require proof of services and measurable deliverables before releasing significant payments.
  • Review advance payments, matching amounts, compressed timelines, and executive overrides as elevated-risk indicators.
  • Treat prior violations and mandatory reporting duties as subjects for recurring control testing.
  • Give internal audit authority to examine commercial substance, not merely procedural completion.
  • Report control failures involving senior management directly to an independent board committee.

The Clippers salary cap circumvention demonstrates that an audit trail can document a failure as easily as it documents compliance. The question is whether the organization has controls that can interpret what the records mean.

In tomorrow’s blog post, we will turn from detection to accountability and examine how cooperation, credibility, seniority, prior misconduct, and supervisory failure should shape consequence management.

Categories
Everything Compliance - Shout Outs and Rants

Everything Compliance: Shout Outs and Rants – Recycling, Tone at the Top, DEI and Lake Ontario/America

Welcome to a new season of Everything Compliance – Shout Outs and Rants. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, joining returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam shouts out to the NBA for how it handled the LA Clippers salary cap circumvention scandal.
  • Rebecca shouts out to business leaders to support your compliance professionals.
  • Jonathan rants about a UK lawyer struck off the bar list for AI hallucinations.
  • Karen shouts out to those learning a foreign language.
  • Matt shouts out to the school districts of NYC and Los Angeles for restricting AI use in the classroom.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.

Categories
Blog

The NBA/Clippers Investigation: Part 2 – Conflicts in the Commercial Ecosystem

The Clippers investigation demonstrates why conflict controls must follow influence, economic benefit, and interconnected transactions, not merely financial ownership. In Part 2 of this five-part series, we consider what conflicts of interest are, why they are so divisive, and why compliance professionals must stay vigilant to prevent them from arising.

The most consequential conflicts of interest rarely arrive with a label. They appear as introductions, relationship management, commercial creativity, customer accommodation, or an effort to satisfy an important stakeholder. Each step may look defensible on its own. The compliance risk becomes visible only when the organization connects the people, payments, contracts, incentives, and timing. That is one of the central lessons from the investigation into the LA Clippers and Kawhi Leonard salary cap circumvention.

The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement opportunities between Leonard and four companies doing business with the team: Aspiration Partners, Boingo Wireless, Daktronics, and Lockton Insurance. Investigators further found that the team induced those companies to enter the endorsement arrangements by offering or providing Clippers business.

This was not a traditional conflict involving an executive awarding a contract to a company the executive secretly owned. It was a commercial ecosystem in which organizational business, personal relationships, vendor incentives, and benefits for a powerful player allegedly became intertwined. The Athletic seemed to believe that these conflicts were all at the behest of Leonard’s personal representative, Uncle Dennis. But even if the requests originated from the Leonard Camp, the Clippers put the entire sordid process into motion.

The Conflict Was in the Network

Conflict programs often focus on a narrow question: Does the employee have a financial interest in the counterparty? That question matters, but it is not enough.

The Wachtell Report identified personal and professional relationships involving Clippers President of Business Operations Gillian Zucker and two of the companies. At one company, her husband served as board chair during the relevant period, and Zucker reportedly had a 30-year working relationship with its chief executive. At another, she had a longstanding relationship with the president and recommended him internally as the Clippers considered service providers.

Relationships do not establish wrongdoing. Longstanding connections can create legitimate business opportunities. The compliance issue is whether the relationships were disclosed, independently evaluated, and removed from decisions that could benefit the related parties or another favored stakeholder.

Aspiration presented a different form of entanglement. In September 2021, Aspiration entered into a 23-year, $382.5 million sponsorship arrangement with the Clippers, a 23-year, $72 million sustainability services agreement for the Intuit Dome, and an agreement under which Steve Ballmer personally invested $50 million in Aspiration. Weeks later, the process leading to Aspiration’s proposed endorsement agreement with Leonard began.

Again, an investment, sponsorship, services agreement, or endorsement relationship is not inherently improper. The risk arose from their combination. Investigators concluded that Clippers personnel participated in developing Leonard’s endorsement arrangement and later approved Forum business that Aspiration’s co-founder had linked to completion of that endorsement deal.

The compliance question was therefore not simply whether Ballmer had disclosed his investment. It was whether anyone independently assessed the total relationship and asked whether the organization, its owner, its vendor, and its player were participating in genuinely separate transactions.

Procurement Leverage as a Compliance Risk

The Wachtell Report’s discussion of Daktronics makes the commercial leverage particularly clear. Daktronics was competing for the Intuit Dome scoreboard and signage business. According to investigators, Clippers personnel proposed directing part of the vendor’s expected “spend back” to an endorsement agreement with Leonard.

Daktronics reportedly believed that refusing could jeopardize its opportunity to win the arena contract. Investigators found that a Clippers executive specified the proposed endorsement economics and later requested an additional payment after the scope of the scoreboard purchase increased.

This is a critical third-party risk lesson. A vendor may appear to make an independent payment, but the customer’s purchasing power can shape its decision. The organization cannot treat the vendor as an independent actor if its executives use procurement leverage to influence the vendor’s decision.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to examine the business rationale for using a third party, whether contracts accurately describe the services, whether the work was actually performed, whether compensation was commensurate with that work, and how third-party management is integrated into procurement and vendor management. Those questions apply well beyond anti-bribery enforcement.

They can be adapted to any commercial arrangement:

  • Why is this party entering the transaction?
  • Who proposed the arrangement and its economic terms?
  • Is another pending contract influencing the decision?
  • Are the services real, measurable, and proportionate to the payment?
  • Who ultimately receives the economic benefit?

If compliance cannot answer those questions, due diligence is incomplete.

The Limits of Disclosure and Recusal

Many organizations would respond to these facts by strengthening annual conflict questionnaires. That would help, but it would be insufficient. Annual disclosures capture static information. The Clippers matter involved dynamic relationships developing across sponsorship, procurement, personal investment, consulting, endorsement, and expense activity. No annual form could evaluate the full risk unless the organization also had transaction-level escalation.

Recusal presents a similar challenge. An executive can abstain from the final signature and still shape the outcome through introductions, recommendations, term-sheet comments, internal advocacy, or communications with the vendor. Effective recusal must address influence, not merely signature authority.

A defensible conflict process should contain four elements.

  1. Your organization needs a broad definition of conflict. It should cover actual, potential, and perceived conflicts, including close personal relationships, family roles, outside investments, prior professional affiliations, and benefits directed to third parties at an employee’s request.
  2. Disclosures must be tied to decisions. Procurement, legal, finance, compliance, and business approvers should receive relevant conflict information before approving the transaction.
  3. Independent reviewers or monitors must have access to the entire relationship. A sponsor agreement, consulting contract, personal investment, and endorsement deal cannot be reviewed in separate silos when they involve the same parties.
  4. Your organization must document how it managed the conflict. (Document Document Document) Approval should identify the business rationale, benchmarking, competitive process, recusals, alternative providers, deliverables, monitoring plan, and responsible control owner.

An Internal Control Issue, Not Just an Ethics Issue

Conflicts are frequently treated as personal ethics matters. They are also internal control risks. The COSO Internal Control–Integrated Framework provides the right lens. The control environment establishes expectations for integrity and accountability. Risk assessment identifies where influence and commercial pressure could distort decisions. Control activities impose approvals, segregation of duties, and documentation. Information and communication move relevant facts to independent decision-makers. Monitoring determines whether the controls work over time.

When conflicts span several transactions, the control system must aggregate information. A procurement reviewer may see a vendor contract. Finance may see an advance payment. Marketing may see an endorsement agreement. The owner’s office may see an investment. Compliance must be all four.

This is also a governance question. Under the Organizational Sentencing Guidelines, governing authorities must understand the compliance program and reasonably oversee its implementation and effectiveness. Board oversight becomes especially important when a transaction involves senior executives, controlling owners, or stakeholders whose commercial importance may compromise ordinary review.

The Clippers investigation shows that a conflict can exist without a secret ownership interest or a direct personal payment. It can arise when influence, relationships, and commercial leverage align to deliver a benefit that the organization could not provide directly.

Tomorrow in blog post 3, we will examine why the Clippers matter represents an internal controls failure and how procurement data, payment analytics, expense monitoring, and a substance-over-form review could have identified the pattern earlier.

Categories
Daily Compliance News

Daily Compliance News: September 4, 2026, When the Whip Comes Down, Cue the Rolling Stones Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • The NBA lowers the whip and hammer on the LA Clippers. (NBA Press Release)
  • Boeing: No monitor, No Problem. (Reuters)
  • Dutch pull gold out of the US due to ‘instability’. (WSJ)
  • Courts struggling to tame big tech. (NYT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

The NBA/Clippers Investigation: Part 1 – A Compliance Failure in Five Acts

Over the next five blog posts, we will consider how commercial pressure, weak controls, and leadership decisions turned a salary-cap rule into an enterprise-wide governance failure. Today in Part 1, we summarize those compliance failures.

The most dangerous compliance failure is not ignorance of the rules. It is knowing the rules, receiving targeted training, having a history of prior violations, and then creating a process that appears compliant while delivering a prohibited result. That is the central compliance lesson from the investigation into the LA Clippers and Kawhi Leonard.

The independent investigators’ report, prepared by the law firm Wachtell, Lipton, Rosen & Katz, concluded that the Clippers violated the NBA’s salary-cap circumvention rules through a pattern of transactions involving Leonard, his representatives, team executives, and four companies doing business with the organization. This is a sports story, but it is also much more. It is a case study in executive accountability, third-party risk, conflicts of interest, internal controls, reporting failures, organizational culture, and board oversight.

The Investigation

The matter began after the September 2025 podcast Pablo Torre Finds Out reported allegations involving a four-year endorsement agreement between Leonard and Aspiration Partners, a sustainability services company that later entered bankruptcy. Torre won a Pulitzer Prize for his podcast reporting. Thereafter, the NBA retained Wachtell Lipton to investigate. The inquiry eventually expanded beyond Aspiration to include endorsement agreements involving Boingo Wireless, Daktronics, and Lockton Insurance.

Investigators conducted 73 interviews of 60 people and reviewed more than 200,000 pages of documents. They interviewed Clippers owner Steve Ballmer; President of Business Operations Gillian Zucker; President of Basketball Operations Lawrence Frank; Leonard; and Leonard’s uncle and then-business manager, Dennis Robertson (Uncle Dennis). Third-party cooperation varied. Aspiration’s bankruptcy trustee and Daktronics provided substantial assistance, while other parties reportedly limited or refused cooperation.

The resulting 36-page report is a summary, not a complete presentation of the evidence. Nevertheless, the investigators concluded that the record was sufficient to establish multiple violations. The misconduct unfolded in five acts.

Act One: A Known Rule and a Known Risk

The NBA’s circumvention rules broadly prohibit teams from providing players with compensation, business opportunities, or anything else of value outside their authorized player contracts. The rules also prohibit attempts, solicitations, inducements, and informal understandings intended to produce such benefits. The rule has a simple underlying principle: to prevent salary cap circumvention.

The NBA provided teams with practical examples. A team representative could not recommend a player to a sponsor for an endorsement arrangement or initiate and facilitate that relationship. If a sponsor independently asked about a player, the team’s permissible response was generally limited to supplying the player’s or agent’s contact information.

The Clippers were not operating in unfamiliar territory. In 2015, the NBA fined the team $250,000 for conduct involving a potential endorsement opportunity for DeAndre Jordan. In 2019, the NBA investigated demands reportedly made by Uncle Dennis during Leonard’s free agency. The League subsequently required teams to report improper solicitations for benefits, even when the team rejected the request.

In December 2019, the NBA provided circumvention training to the Clippers’ senior leadership, including Ballmer, Zucker, and Frank. Investigators reported that all three understood the rule. This is the first compliance lesson: knowledge is not a control. Training can establish awareness, but only governance, monitoring, escalation, and accountability can translate awareness into compliant conduct.

Act Two: Pressure From a Powerful Stakeholder

According to the report, Uncle Dennis pressed the Clippers to help Leonard obtain approximately $10 million per year in off-court income. He communicated his demands to Frank, Ballmer, and Zucker. The report found no evidence that these demands were reported to the NBA, even though the reporting rule had been created in response to earlier concerns involving Robertson. Investigators also found no evidence that senior leaders clearly instructed him to stop making the requests.

Instead, contemporaneous notes reflected assurances that Clippers’ personnel would help Leonard achieve his financial goals. Uncle Dennis requested a plan, a pipeline of potential companies, and more frequent communication. This was a decisive moment. The organization had received a red flag from the highest-risk source, involving one of its most commercially valuable stakeholders. The control that mattered was not another training presentation. It was the ability to say no, document the response, escalate the demand, and make the required report.

Act Three: The Commercial Ecosystem Becomes the Delivery Mechanism

During six days in June 2020, Zucker sent introduction emails connecting Uncle Dennis with Boingo, Daktronics, and Lockton. Each email was written as if the company had requested the introduction. Investigators did not credit that explanation. They concluded that the Clippers initiated the introductions in response to Uncle Dennis’ demands.

Leonard subsequently entered into endorsement agreements with all three companies. The agreements provided for $18 million in total compensation, all of which was paid by August 2021. Investigators identified several unusual characteristics: the agreements were negotiated rapidly during the COVID-19 shutdown, imposed minimal performance obligations, were not publicly announced, and produced little evidence of meaningful activation.

At the same time, each company was pursuing lucrative business with the Clippers or the team’s arena. The report described consulting agreements, substantial advance payments, and perceived links between vendor business and payments to Leonard. The investigators found the Daktronics arrangement particularly direct. They concluded that Clippers personnel proposed using an endorsement agreement with Leonard as part of a “spend back” arrangement connected to Daktronics’ pursuit of the Intuit Dome scoreboard contract.

Here, third-party risk and procurement risk converged. The vendors were not merely outside parties. They allegedly became the mechanism through which the prohibited benefit was delivered.

Act Four: Aspiration and the Appearance of Legitimacy

Aspiration’s relationship with the Clippers was substantial. It included a long-term sponsorship agreement, sustainability services for the Intuit Dome, and a $50 million personal investment by Ballmer. The report concluded that Zucker raised the possibility of an Aspiration endorsement agreement with Leonard, recruited a business agent to help structure it, communicated proposed financial terms, provided input on the term sheet, and remained involved after the formal introduction.

The final agreement called for $48 million in cash and equity over four years. Investigators described the compensation as extraordinarily high in relation to Leonard’s obligations and endorsement profile. The most significant issue involved a separate agreement under which the Clippers would purchase sustainability services for the Forum. Early documents contemplated $7 million in annual business for Aspiration, matching the annual cash component of Leonard’s endorsement agreement. When Aspiration’s co-founder threatened to abandon the Leonard agreement unless the Forum transaction was completed, internal Clippers’ communications reportedly reflected awareness of that linkage. Ballmer nevertheless approved the Forum agreement.

The compliance lesson is substance over form. A formal contract, documented introduction, consultant analysis, or stated business purpose does not end the inquiry. Compliance must ask who initiated the transaction, who benefits, whether the economics make sense, and whether supposedly independent agreements are actually connected.

Act Five: Expenses, Reporting, and the Control Environment

Investigators also identified hundreds of instances in which the Clippers paid personal travel, accommodations, gifts, and ticket expenses for Leonard, his family, or Uncle Dennis without making the deductions required by NBA rules. Frank authorized the payments.

The report further concluded that Ballmer, Zucker, and Frank failed to report Uncle Dennis’ improper solicitations. These findings move the case beyond isolated dealmaking. They suggest failures in expense management, accounts payable, executive approvals, legal review, reporting, and compliance escalation. Under the COSO Internal Control–Integrated Framework, internal controls support operational, reporting, and compliance objectives. They must operate across the enterprise, particularly where multiple transactions point toward the same underlying risk.

The Compliance Program Test

The DOJ’s Evaluation of Corporate Compliance Programs organizes its analysis around three fundamental questions:

  1. Is the compliance program well designed?
  2. Is it adequately resourced and empowered to function effectively?
  3. Does it work in practice?

The Clippers matter raises all three. The DOJ Organizational Sentencing Guidelines similarly require risk assessment, appropriate authority for compliance personnel, monitoring and auditing, confidential reporting mechanisms, consistent enforcement, and remediation. Prior misconduct must inform future risk assessment and control design.

The Caremark Doctrine provides the board-level perspective. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes that directors must make a good-faith effort to establish and monitor reporting systems addressing mission-critical compliance risks. The relevant point here is not that Caremark liability has been established. It is that known, central risks require reliable information to reach governing authorities, followed by documented oversight and action.

The Consequences

Following the report, the NBA imposed significant penalties. According to The Athletic the penalties are:

  • The forfeiture of five first-round picks by the Clippers;
  • A $30 million team fine for the Clippers;
  • A one-year suspension for Clippers owner Steve Ballmer
  • Suspensions without pay for two of the top Clippers executives, Gillian Zucker (president of business operations; one year) and Lawrence Frank (president of basketball operations; six months);
  • Placement in the NBA-controlled compliance and monitoring program for five years;
  • Leonard was required to forfeit $700,000; and
  • Uncle Dennis was banned and is prohibited from conducting business with NBA teams for five years.

These penalties demonstrate that governance failures can create consequences far beyond the value of the underlying transactions.

These penalties demonstrate that governance failures can create consequences far beyond the value of the underlying transactions.

Compliance Takeaways

Compliance professionals should take five immediate lessons from this matter:

  • Treat prior violations as mandates for verified remediation, not completed training exercises.
  • Map interconnected relationships among vendors, executives, customers, agents, and other powerful stakeholders.
  • Require independent review when multiple agreements may benefit the same individual.
  • Test the economic substance of transactions, including pricing, deliverables, advance payments, and ultimate beneficiaries.
  • Give compliance the authority to escalate and stop transactions involving senior executives or strategically important individuals.

The question is not whether an organization has rules. The question is whether its compliance system can withstand pressure from the people the business most wants to satisfy. In Part 2 (after Labor Day), we will examine the conflicts of interest embedded in the Clippers’ commercial ecosystem and consider how organizations should govern transactions where sponsors, vendors, executives, personal relationships, and individual benefits intersect.

Categories
Daily Compliance News

Daily Compliance News: June 30, 2026, The New Auditor Ethics Rule Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • WeWork grows up. (FT)
  • The unknown unknowns of using AI at work. (NYT)
  • How a new auditor ethics rule may reshape litigation. (Reuters)
  • More ex-NBA players indicted in gambling probe. (ESPN)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Full-Court Compliance: What the Knicks’ Championship Teaches CCOs About Winning the Right Way

While later surpassed by the Michael Jordan Bulls and the back-to-back NBA Champs, my (then) hometown heroes, the Houston Rockets, my favorite NBA team from my teen years was the two-time NBA champs, the New York Knicks. I can still name the starting lineup from the 70-71 champs (Walt Frazier, Dick Barnett, Dave DeBusschere, Bill Bradley, and Willis Reed). So, while I live down the road from San Antonio, I was one of the very few people in Kerrville, TX, rooting for the Knicks.

Today, the New York Knicks are NBA champions for the first time since the 1972-73 season, and for compliance professionals, the story is more than basketball. It is a case study in governance, risk appetite, culture, talent strategy, controls, remediation, and execution under pressure. As reported by ESPN, New York defeated the San Antonio Spurs in five games to win its first NBA championship in 53 years, with Jalen Brunson scoring 45 points in the closeout Game 5 and earning Finals MVP honors.

The scoreboard tells the story of a team that operated under pressure:

Game Score
Game 1 at San Antonio Knicks 105, Spurs 95
Game 2 at San Antonio Knicks 105, Spurs 104
Game 3 at New York Spurs 115, Knicks 111
Game 4 at New York Knicks 107, Spurs 106
Game 5 at San Antonio Knicks 94, Spurs 90

ESPN’s Finals matchup summary listed the Knicks as the 4-1 series winners, based on those five-game results.

For CCOs, the championship lesson starts with roster construction. Leon Rose, the Knicks’ president of basketball operations and chief roster architect, did not build this team by chasing headlines. He built it the way an effective CCO builds a compliance program: with a clear risk assessment, disciplined resource allocation, cultural fit, control remediation, and continuous monitoring.

Start with Jalen Brunson. The Knicks acquired Brunson through free agency in 2022, and NBA.com described him as the central acquisition in Rose’s rebuild. Brunson later agreed to a below-market extension, which gave the organization flexibility to retain and add other players. That is a compliance principle in the form of basketball. You do not spend all your capital on one control and leave no budget for investigations, training, data analytics, third-party management, and monitoring. Brunson was the control owner, but the program still needed a full system around him.

Then came the risk-based gap analysis. Rose did not simply ask, “Who is available? ” He asked the compliance equivalent of, “What risk remains unmitigated? ”The answer was size, defense, positional versatility, rebounding, and playoff resilience. Karl-Anthony Towns arrived through a 2024 three-team trade with Minnesota, giving the Knicks elite frontcourt skill and passing. OG Anunoby came from Toronto in 2023 because the Knicks needed a high-end defender who could handle elite wings and still contribute offensively. Mikal Bridges came from Brooklyn in 2024 as a multi-position wing who could defend and shoot. Josh Hart arrived in a 2023 trade with Portland, bringing toughness, energy, leadership, and the intangible glue that every good system requires.

That is how a compliance officer should think about program design. Policies alone are not enough. Training alone is not enough. Hotline data alone is not enough. A championship compliance program needs anti-corruption controls, third-party due diligence, internal accounting controls, sanctions screening, speak-up culture, investigation protocols, data testing, and board reporting. Each element has a role. Each element covers a gap. Each element must work under stress.

The Knicks also demonstrated the value of cultural due diligence. Brunson, Bridges, and Hart carried a Villanova connection, but the lesson is not nostalgia. The lesson is known as performance under known pressure. Rose understood that talent without fit is a control failure waiting to happen. Compliance leaders understand this point well. A technically gifted executive who rejects controls, bypasses procurement, bullies internal audit, or treats legal review as an obstacle is not a high performer. That executive is a risk amplifier.

The Bridges trade is especially instructive. Rose paid a significant price, sending multiple first-round assets to Brooklyn. NBA.com described it as one of Rose’s biggest and most questioned risks before Bridges proved his value in the postseason. In terms of compliance, this was not risk avoidance. It was risk governance. The question for any board is not whether a strategy carries risk. All meaningful strategies carry risk. The question is whether management has identified the risk, documented the rationale, designed mitigation, and monitored outcomes.

Game 4 was the stress test. The Knicks trailed by 29 points and still beat the Spurs 107-106, completing the largest comeback in NBA Finals history under modern play-by-play tracking. In compliance, this is where paper programs fail, and real programs prove themselves. A company can look strong during the annual training season. The test comes when a whistleblower allegation arrives before the close of a quarter, a high-risk distributor is tied to a government official, a sanctions rule changes overnight, or a business leader asks for an exception because “the deal is too important.”

The Knicks did not win because they avoided adversity. They won because their controls held when adversity arrived. NBA.com noted that every game in the series was within five points in the last five minutes, and the Knicks erased double-digit deficits throughout the Finals. That is program effectiveness. A compliance program is not effective because the code of conduct is polished. It is effective because people make the right decisions when the score is close, the pressure is high, and the wrong shortcut looks attractive.

Finally, Rose made the coaching decision. Mike Brown replaced Tom Thibodeau in 2025, and NBA.com reported that Brown’s approach helped win over the locker room and make strategic changes during the playoff run. This is remediation. Mature organizations do not confuse past success with future sufficiency. Thibodeau helped move the Knicks forward, but Rose concluded that the next stage required a different operating model. CCOs face the same challenge when a legacy control, legacy investigator, legacy third-party process, or legacy reporting structure no longer fits the risk environment.

The Knicks’ championship was not an accident. It was the result of governance, discipline, culture, and controls. That is why CCOs should study it. Define your risk appetite before the season starts. Build around culture, not just talent. Spend resources where the risk assessment shows the gaps. Treat major decisions as board-defensible governance judgments. Most importantly, test whether your program can perform in the final five minutes, because that is where championships and compliance failures are decided.