Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.

Categories
Blog

The Odyssey and Compliance, Part 1 – The Trojan Horse: When Cleverness Becomes a Control Failure

There are few works in Western Literature more read than The Odyssey. While a cadre of passionate specialists prefer The Iliad, it is The Odyssey that is most generally taught in US high schools. Part travelogue, part adventure yarn, part social commentary, and part treatise on Greek morals and morality, it is still a rousing tale well worth the time to read. Now, Christopher Nolan is out with another movie version of The Odyssey. I have not yet seen the movie as of this writing.

I wanted to tackle The Odyssey from the compliance perspective. There are many things we can mine from this story. Over the course of this week, I will discuss five of them. Today, we consider where the story begins: the Trojan Horse as a failure of control. On Tuesday, we look at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we look at The Cattle of Helios: Non-Negotiables and Control Breaches. On Friday, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Today, we begin with The Odyssey, which directly follows the end of The Iliad. Here are a few business strategies more celebrated than the Trojan Horse. After ten long years of war, he looked at the walls of Troy and realized brute force had failed. The Greeks could not smash their way in. They could not negotiate their way in. They could not outlast their way in. So Odysseus did what clever leaders often do when conventional methods fail: he found a workaround. Build a great wooden horse. Hide soldiers inside it. Leave it outside the gates as a supposed gift. Sail away, or at least appear to. Let the Trojans make the fatal decision themselves.

While it was brilliant from a strategic perspective, it was an absolute nightmare from a compliance perspective. The Trojan Horse is usually remembered as a triumph of strategy. It should also be remembered as the original “trusted vendor attachment.” It arrived looking valuable, symbolic, and harmless. It came wrapped in a compelling story. It appealed to ego, fatigue, and optimism. And someone, somewhere inside Troy, approved bringing it through the gates.

The Gift That Bypassed Governance

Every organization has gates. Some are literal: firewalls, access controls, locked doors, badge readers, and vendor onboarding systems. Others are procedural: approval matrices, procurement rules, due diligence reviews, cybersecurity assessments, conflict checks, and escalation protocols. The problem is that business opportunities rarely arrive wearing a sign that says, “Hello, I am a control failure.”

They arrive as partnerships. Strategic investments. Technology platforms. Emergency exceptions. Pilot programs. Customer demands. Board-level priorities. Innovation initiatives. “Just this once” requests. Special access for a trusted consultant. A new AI tool that someone found useful. A supplier who can solve the problem quickly. A deal too good to slow down.

In other words, they arrive as gifts. The Trojans did not lose because they lacked walls. They lost because they made a poor risk decision at the gate. The control existed. The wall worked. The problem was judgment, governance, and process. A control environment is not only about having policies. It is about whether people use them when the pressure is on and the opportunity looks attractive.

When Cleverness Becomes the Risk

Odysseus was not a fool. He was a strategist. That is what makes this story so useful for compliance professionals and business leaders. Many compliance failures are not born from stupidity. They are born from intelligence used without discipline. A clever workaround can be useful. A clever workaround can also serve as a bypass of governance. The distinction matters.

Think about the employee who finds a faster way to onboard a vendor by skipping required due diligence. The sales executive who routes a discount through an unusual approval path to close the quarter. The business unit that adopts an unsanctioned software tool because IT is “too slow.” The senior leader who asks for an exception because “this is strategically important.” The team that shares sensitive information with a partner before the agreement is fully papered because “we trust them.”

Each decision may have a business rationale. Each may feel practical. Each may even produce a short-term win. But the compliance question is not simply, “Did it work? “The better question is, “What did it bypass? ”

That is the Trojan Horse problem. The horse worked because it bypassed the normal defenses. In a modern company, that may mean bypassing cyber review, procurement checks, legal review, data protection analysis, sanctions screening, financial controls, conflict review, or code of conduct expectations. When leadership celebrates only the result, the organization learns the wrong lesson. It learns that controls are for ordinary days, not important ones. That is how culture begins to drift.

The Cybersecurity Lesson Inside the Horse

The Trojan Horse is one of the oldest stories in Western literature, but it feels remarkably current in an age of cyber risk and social engineering. A malicious file. A fake vendor invoice. A compromised supplier account. A phishing email that appears to come from a trusted executive. A third-party platform with excessive access. A contractor credential that is never disabled. A software update from a source no one properly vetted. These are modern Trojan Horses.

They do not always break the wall. They persuade someone to open the gate. This is why cybersecurity is not merely an IT function. It is a governance issue. NIST’s Cybersecurity Framework 2.0 places significant emphasis on the Governance function, which addresses how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policies.

That is compliance language as much as cyber language. Who owns the risk? Who approves exceptions? Who monitors access? Who understands the business context? Who has the authority to say no? Who makes sure the organization learns from near misses? If no one can answer those questions clearly, the horse is already inside the gate.

Attractive Risks Test the Control Environment

It is easy to say no to obviously bad ideas. The real test comes when the risk is attached to something the business wants. A lucrative customer. A prestigious partner. A promising technology. A powerful executive sponsor. A deadline. A crisis. A competitor is moving faster. A board presentation next week. That is when the control environment reveals itself.

In a strong control environment, the organization can move quickly without becoming careless. It can evaluate risk without killing innovation. It can escalate concerns without making people feel disloyal. It can approve exceptions, but only with transparency, documentation, and accountability.

In a weak control environment, speed becomes the excuse for opacity. Trust becomes the substitute for diligence. Seniority becomes the overriding control. Documentation comes later, which usually means never. Compliance is invited after the decision has already been made. That is not innovation. That is improvisation with a budget.

The code of conduct should matter most when the business case is compelling. Internal controls should matter most when the pressure is real. Cybersecurity should matter most when the new tool looks exciting. Risk assessment should matter most when everyone is tired of waiting. Troy did not need a better wall. Troy needed a better approval process.

The Insider Threat Dimension

There is another uncomfortable lesson in the Trojan Horse. The Greeks got inside Troy because the Trojans cooperated with the plan. Not intentionally, perhaps. Not corruptly, necessarily. But they cooperated all the same. That is the nature of many insider threats.

The insider is not always a villain. Sometimes the insider is rushed, flattered, distracted, pressured, or insufficiently trained. Sometimes the insider believes they are helping. Sometimes they trust the wrong person. Sometimes they assume someone else has checked. That is why compliance programs cannot rely solely on good intentions.

Good people need good systems. They need clear policies, practical training, escalation paths, and a culture that rewards thoughtful skepticism. They need permission to ask, “Why are we bringing this inside the walls? ”

This is especially important in organizations where questioning a business opportunity is viewed negatively. Compliance should not be the Department of No, but neither should the business become the Department of Please Do Not Ask Too Many Questions. Healthy skepticism is not cynicism. It is stewardship.

What a Better Program Does

A better compliance program does not ban wooden horses. It asks better questions before opening the gate. Who sent it? Why now? What access does it require? What data will it touch? What assumptions are we making? Has the vendor been reviewed? Has the technology been tested? Is there a conflict? Is there a regulatory issue? What is the worst-case scenario? Who approved the exception? How will we monitor it after approval?

The point is not to slow down every decision. The point is to prevent charm, urgency, and executive enthusiasm from replacing governance. A strong program also makes risk ownership visible. If the business wants to accept a risk, that decision should be documented. If a control is bypassed, there should be a reason, an approver, a time limit, and compensating controls. If a new tool, vendor, or relationship is brought inside the organization, someone should be accountable for monitoring it. The Trojan Horse teaches that the most dangerous risks are not always those from outside. Sometimes they are the ones we invite in because they look like success.

The Compliance Takeaway

Odysseus won because he understood human nature. He knew the Trojans would see what they wanted to see: victory, tribute, closure, and a symbol of their own endurance. That is the uncomfortable lesson for corporate compliance. Risk often enters through desire. The desire to win. To move fast. To close the deal. To trust the familiar. To avoid friction. To believe the story makes the opportunity easier to approve.

Not every gift is a threat. Not every workaround is misconduct. Not every clever idea is a control failure. But every organization needs the discipline to ask whether cleverness is serving governance or bypassing it. The horse may be beautiful. The story may be compelling. The business sponsor may be persuasive. Open the gate only after the controls have done their work.

Join us tomorrow, where we consider The Lotus-Eaters: Culture Drift and the Comfort of Forgetting.