Categories
Blog

Odyssey Week: Leadership: Telemachus and the Succession Problem

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Tom Holland was great as Telemachus.

Odysseus is away. That is the fact around which Ithaca slowly comes apart. He is not merely on a long business trip. He is not delayed in a regional office because the quarterly review ran over. He has been gone for years. In his absence, the household becomes a leadership vacuum. Penelope holds the center as best she can. Telemachus grows up surrounded by uncertainty. The suitors occupy the palace, consume resources, abuse hospitality, and become more comfortable with every passing day. No one is quite sure who has authority.

And when authority is unclear, misconduct finds a chair at the table. That is Telemachus’s compliance lesson. He is not just the son waiting for his father’s return. He is the next generation of leadership inheriting a control environment weakened by absence, ambiguity, and tolerated abuse.

For modern companies, Telemachus represents the succession problem: what happens to governance, compliance, and accountability when the founder, CEO, general counsel, CFO, chief compliance officer, regional president, or other key executive is absent, distracted, replaced, or functionally unreachable? The company may still have policies. It may still have a code of conduct. It may still have approval matrices, committees, workflows, and board decks.

But the practical question remains: who owns compliance when the person everyone used to ask is no longer there?

The Corporate Translation

Every organization has formal authority and informal authority. Formal authority lives in charters, org charts, delegations of authority, board committee mandates, policy ownership tables, and job descriptions. Informal authority lives in the hallway, the inbox, the founder’s instincts, the CFO’s raised eyebrow, the general counsel’s quiet warning, and the compliance officer everyone calls before doing something adventurous.

The trouble begins when the company depends too heavily on informal authority. The founder knows where the risks are. The CFO knows which regional numbers smell funny. The general counsel knows which agents should never be used. The chief compliance officer knows which managers say all the right things and do something else entirely. The regional leader knows which customer relationships require special scrutiny.

Then one of them leaves, retires, burns out, gets promoted, goes on leave, is distracted by a transaction, or becomes unavailable during a crisis. Suddenly the company discovers that what it called “governance” was partly memory, personality, and habit. That is Ithaca without Odysseus.

Succession Is a Compliance Issue

Succession planning is often treated as a leadership development topic. That is too narrow. Succession is also a compliance issue.

When key people leave, the company can lose risk knowledge, control discipline, escalation history, and institutional memory. Open investigations may drift. Third-party concerns may be forgotten. Exceptions may remain unresolved. Sensitive approvals may migrate to people who do not understand the underlying risks. Business units may exploit the transition. Bad actors may test boundaries. The suitors always notice when the house is lightly supervised.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s program is well designed, adequately resourced and empowered, and working in practice. It also asks whether policies and procedures are integrated into day-to-day operations, who is responsible for that integration, and whether gatekeepers know what misconduct to look for and when to escalate concerns. Those are succession questions as much as compliance questions. A program that works only when one heroic executive is present does not work in practice. It works in person. That is a very different thing.

Delegation of Authority: Who Can String the Bow?

A delegation of authority matrix is not the most poetic corporate artifact. No one has ever said, “Gather the children by the fire while I tell the thrilling tale of approval thresholds and signature authority.” But delegation of authority matters. It defines who can approve payments, hire third parties, sign contracts, override controls, accept risk, access systems, certify reports, settle disputes, and bind the company.

When delegation is unclear, people improvise. And improvisation is where compliance problems breed. A regional manager approves a vendor because the usual executive is unavailable. A finance employee processes a payment because “someone senior said it was fine.” A business sponsor signs off on due diligence exceptions without understanding the risk. A system administrator grants access because the request came from an important person. A commercial leader commits the company before legal review because the customer needed an answer by Friday.

Each step may feel practical. Each may be defensible in isolation. Together, they reveal a governance weakness. Delegation of authority should answer three basic questions: who can decide, what can they decide, and under what conditions? It should also answer the question most likely to matter in a crisis: who decides when the usual decider is gone?

Control Ownership Cannot Be a Family Secret

In Ithaca, too much depends on Odysseus’s eventual return. That is not a control framework. That is a weather forecast with sandals. Modern companies make the same mistake when control ownership is unclear or overly personalized. Everyone assumes “finance owns that,” “legal handles that,” “compliance reviews that,” “the business manages that,” or “the board knows about that.” Assumption is not ownership. Control ownership should be specific. The owner should understand the risk the control addresses, how the control operates, what evidence demonstrates performance, when exceptions must be escalated, and who serves as backup.

This is especially important in operationally integrated compliance programs. The ECCP emphasizes that compliance policies and procedures should be reinforced through internal control systems and that employees with approval authority or certification responsibilities should receive guidance on what misconduct to look for and when to escalate. That means compliance cannot sit outside the business like a wise statue waiting to be consulted.

It must be embedded into approvals, workflows, reviews, certifications, access rights, vendor onboarding, financial controls, investigations, and reporting channels. Otherwise, when leadership changes, compliance becomes a scavenger hunt.

The Telemachus Problem in Business

Telemachus is not weak. He is inexperienced. That distinction matters. Many next-generation leaders inherit messy control environments. They did not create the old habits. They did not approve the questionable third parties. They did not design the incentive plan. They did not tolerate the difficult executive. They did not ignore the aging audit findings. But they inherit all of it.

That is the Telemachus problem. New leaders often face a painful choice. They can preserve the comfortable ambiguity that made the prior regime work, or they can impose clarity and risk making everyone uncomfortable. Compliance should help them choose clarity.

A new leader should ask, “What are the top compliance risks in this business?” Which controls depend on specific individuals? Which approvals have weak backup coverage? Which investigations or remediation items are open? Which third parties are high risk? Which exceptions have been granted? Which business units have recurring audit findings? Which employees are afraid to speak up? Which senior people are treated as untouchable?

Those questions do not undermine leadership. They establish it. Telemachus cannot govern Ithaca by pretending the suitors are merely enthusiastic guests.

Board Oversight During Transition

Boards of Directors should pay special attention during leadership transitions. A CEO departure, founder transition, CFO replacement, compliance leadership change, merger integration, restructuring, or sudden executive absence can create real compliance vulnerability. It may not appear on the face of the financials. It may not show up immediately in hotline data. But the risk is there.

The board should ask whether interim authority is clear, whether compliance has direct access to leadership, whether key controls remain staffed, whether open issues are being tracked, and whether employees understand where to escalate concerns.

A transition plan should not be limited to investor messaging and organizational charts. It should include compliance continuity. Who owns active investigations? Who signs certifications? Who approves high-risk third parties? Who can grant policy exceptions? Who reports to the board? Who monitors retaliation risk? Who tracks remediation? Who protects records and data? Who communicates expectations to employees? If those answers are unclear, the suitors are already choosing seats.

The Compliance Takeaway

Telemachus teaches us that compliance continuity matters. A company cannot rely on heroic founders, all-knowing executives, indispensable compliance officers, or informal networks of people who “just know how things work.” That may function for a while. It may even feel efficient. But when the key person is gone, the weakness becomes visible. Governance must survive absence.

Authority must be clear. Control ownership must be documented. Delegation must be practical. Oversight must continue. Compliance must be integrated into operations, not dependent on personalities. Because when authority is unclear, misconduct does not wait politely outside the palace. It pulls up a chair, pours the wine, and starts acting like it owns the place.

Join us Tomorrow

Telemachus teaches that governance must survive absence: authority must be clear, ownership documented, and compliance embedded deeply enough that Ithaca can operate without Odysseus in the room. Penelope carries that lesson into the next test, showing what ethical leadership looks like when authority is contested, pressure is relentless. Everyone wants a decision before the facts are ready. If Telemachus asks who owns compliance when the key leader is gone, Penelope asks whether the person with authority has the discipline to say “not yet” to a questionable vendor, weak certification, incomplete investigation, or rushed transaction. Together, they move the leadership arc from succession and continuity to integrity under pressure: first making governance clear, then proving it can hold the line when the suitors demand an answer.

Categories
Blog

Odyssey Week: Leadership – Odysseus the Brilliant Problem: Tone at the Top

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Matt Damon was great as Odysseus.

Odysseus is the kind of leader every board says it wants. He is brave, strategic, persuasive, resilient, creative under pressure, and very good at producing results when the situation looks impossible. He wins wars. He escapes monsters. He talks his way out of death more than once. He is the executive you send into the room when the deal is collapsing, the market is hostile, and everyone else has run out of slides.

He is also, on occasion, his own biggest compliance risk. That is what makes Odysseus so useful for business leaders and compliance professionals. He is not a cartoon villain. He is not reckless in the simple sense. He is brilliant. And brilliance can be dangerous when no one is willing to challenge it.

Odysseus reminds us that tone at the top is not only about what leaders say in polished town halls. It is about how leaders behave when the pressure is real, the stakes are high, and the rules feel inconvenient. The corporate lesson is straightforward: high-performing leaders can create high-performing risk. The organization must be able to challenge its stars.

The Corporate Translation

Every company has an Odysseus. Sometimes he is the rainmaking sales leader who always makes the number. Sometimes she is the visionary founder who can charm investors, customers, regulators, and the board in a single afternoon. Sometimes it is the regional head who delivers growth in difficult markets. Sometimes it is the product leader who moves faster than the control functions can process. The organization loves this person because they win. And that is precisely the problem.

Success can become a shield. Results can become a permission structure. A leader who delivers extraordinary outcomes may slowly become exempt from ordinary scrutiny. Questions that would be asked of anyone else are softened, delayed, or skipped entirely.

  • “How did we win that deal? ”
  • “Why was that third party necessary? ”
  • “Who approved that discount? ”
  • “Why was Legal brought in so late? ”
  • “Why are employees afraid to challenge this person? ”
  • “Why does Internal Audit keep finding exceptions in this business unit? ”

In a healthy culture, these questions are routine governance. In a weak culture, they sound like betrayal. That is the Odysseus problem. He saves the quarter, dazzles the board, and leaves Internal Audit wondering why no one asked how he did it.

Tone at the Top Is Conduct, Not Content

Companies are very good at producing leadership messages. The CEO video. The annual ethics letter. The opening paragraph of the Code of Conduct. The carefully scripted statement that “integrity is our highest value” usually releases the same week everyone is being told to accelerate growth, reduce costs, launch faster, and stop bringing problems without solutions.

Leadership messaging isn’t wrong. It matters. Employees do take cues from senior leaders. The FCPA Resource Guide states that compliance begins with the board and senior executives setting the proper tone and that managers and employees take cues from corporate leaders. It also emphasizes that senior management should clearly articulate standards, communicate them unambiguously, adhere to them, and disseminate them throughout the organization.

Indeed, the Evaluation of Corporate Compliance Programs (ECCP) asks some specific questions. Regarding Conduct at the Top, these questions include: How have they modeled ethical behavior to subordinates? Have managers tolerated greater compliance risks in pursuit of new business or greater revenues? Have managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from effectively implementing their duties?

But employees are sophisticated. They listen to the speech, then watch the calendar, the budget, the promotions, the exceptions, and the discipline decisions. They notice who gets praised. They notice who gets protected. They notice whether compliance concerns change decisions or merely create additional paperwork. They notice whether the high performer who bullies employees, ignores controls, or plays games with approvals is treated as a problem or as “complicated.” Tone at the top is not what leadership says when the cameras are on. Tone at the top is what leadership tolerates when the revenue is attractive.

The Danger of the Heroic Exception

Odysseus lives by exception. That is part of his greatness. He survives because he improvises. He adapts. He reads the room, the monster, the god, the storm, and the weakness in every opponent. He does not always follow the obvious path because the obvious path often leads directly into the sea. Unfortunately, exceptions, not properly managed, are what get companies into hot water.

Business needs leaders who can adapt. Compliance should not become a shrine to rigidity. A company that cannot make decisions, approve thoughtful exceptions, or move with commercial urgency will not be admired for its purity. It will simply become irrelevant. But there is a difference between disciplined exception management and heroic exception culture.

Disciplined exception management asks, “What is the risk?” Who owns it? Who approves it? Is the exception documented? Is it time-limited? Are there compensating controls? Will we monitor it? What precedent does it create? Heroic exception culture says, “Odysseus has it handled.” That is not governance. That is mythology with a travel budget. The ECCP asks, “What exceptions to these policies has an organization permitted?”

When organizations build around heroic exceptions, they become dependent on personality rather than process. The leader’s instincts replace controls. Their confidence replaces documentation. Their track record replaces scrutiny. Their urgency replaces escalation.

Eventually, the organization is no longer asking whether the decision is right. It is asking whether it trusts the hero. That is a dangerous way to run a company. Always remember: trust, but verify.

Pressure to Perform Changes the Ethical Weather

Tone at the top is inseparable from pressure. Leaders may say all the right things about ethics and compliance, but if every business conversation ends with “just get it done,” employees hear the real message. If compensation rewards only revenue, employees hear the real message. If managers who raise concerns are labeled as blockers, employees hear the real message. If compliance is praised in public and bypassed in private, employees hear the real message.

The ECCP asks how senior leaders, through words and actions, have encouraged or discouraged compliance, how they have modeled ethical behavior, and whether managers have tolerated greater compliance risks in pursuit of new business or greater revenues. It also asks whether managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from doing their jobs.

That is an excellent test for any leadership team. Not, “Did we say integrity matters? But did our conduct make integrity practical? “A leader who sets impossible targets and then expresses surprise when employees cut corners has not created a compliance culture. He has created plausible deniability. Odysseus often survives impossible pressure. Companies should be careful about asking employees to do the same.

Challenging the Star Performer

The true test of tone at the top is whether the organization can challenge its stars. Can compliance question the top sales executive? Can internal audit review the founder’s favorite business unit? Can Legal slow down the CEO’s preferred acquisition? Can HR investigate a high-performing manager accused of retaliation or harassment? Can Finance reject revenue recognition pressure from a powerful regional leader?

Or does the organization quietly apply one standard to ordinary employees and another to those who deliver? Employees do not need a formal policy memo to understand a double standard. They see it immediately. If a junior employee is disciplined for a policy violation while a senior leader is “coached” for comparable conduct, the culture learns. If a high-performing executive is allowed to mistreat people because “the business is too important,” the culture learns that compliance matters only when it doesn’t affect the powerful. If compliance concerns disappear when they involve influential leaders, the culture learns that compliance matters only when it doesn’t affect the powerful.

The ECCP looks at whether compliance is enforced consistently and whether consequences apply regardless of an employee’s position or title. It also asks whether managers are held accountable for misconduct that occurred under their supervision and for supervisory failures. That is not just enforcement logic. It is cultural logic. A company cannot claim integrity as a value while treating performance as immunity.

What a Better Program Does

A better compliance program does not try to eliminate Odysseus. That would be both impossible and unwise. Organizations need bold leaders. They need commercial courage, strategic imagination, persuasive ability, and the confidence to act in uncertainty. The goal is not to make leaders timid. The goal is to make leadership accountable.

A better program builds controls around high-risk authority. It monitors exceptions. It reviews pressure points. It includes compliance in strategic decisions early. It gives the board visibility into recurring overrides, hotline trends, audit findings, employee turnover, and control failures in high-performing units. It trains senior leaders not only on rules but also on how their behavior shapes risk. It also asks uncomfortable questions about success.

Where are results unusually good? Where are margins unusually high? Where are approvals unusually fast? Where are complaints unusually low? Where do people say, “That is just how that leader operates”? Where does the company rely on one person’s relationships, instincts, or influence more than on process? Those are Odysseus questions. The point is not to assume misconduct. The point is to understand that extraordinary performance deserves thoughtful scrutiny, not blind applause.

The Compliance Takeaway

Odysseus is brilliant. That is why he is dangerous. He shows us that leadership risk does not always arrive as laziness, incompetence, or obvious corruption. Sometimes it arrives as charisma. Confidence. Commercial success. Strategic genius. The leader who always finds a way.

Tone at the top means ensuring that even the most successful leaders operate within the company’s values, controls, and accountability structures. It means the Board of Directors and senior executives must model ethical conduct not only in speeches but also in decisions. (Talk the Talk but also Walk the Walk.) It means performance is celebrated but not worshiped. It means the organization can ask its heroes hard questions before the journey turns into an investigation. Every company needs leaders who can win. But no company should become so dazzled by Odysseus that it forgets to check the map, inspect the ship, and ask what happened to the crew.

Join Us Tomorrow

Odysseus reminds us that brilliance can become risk when success turns into a shield, exceptions become heroic, and no one is willing to challenge the leader who always finds a way. But even the most brilliant leader eventually leaves the room, and that is when the next compliance test begins: whether governance survives without the hero. Telemachus inherits the house Odysseus left behind, where authority is uncertain, informal power has filled the gaps, and bad actors have grown comfortable at the table. If Odysseus asks whether top performers are held to the same standards as everyone else, Telemachus asks the follow-up question every board should fear: when the indispensable leader is gone, does the compliance program still work, or was it only working because Odysseus was there?

Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.

Categories
Blog

The Odyssey and Compliance, Part 1 – The Trojan Horse: When Cleverness Becomes a Control Failure

There are few works in Western Literature more read than The Odyssey. While a cadre of passionate specialists prefer The Iliad, it is The Odyssey that is most generally taught in US high schools. Part travelogue, part adventure yarn, part social commentary, and part treatise on Greek morals and morality, it is still a rousing tale well worth the time to read. Now, Christopher Nolan is out with another movie version of The Odyssey. I have not yet seen the movie as of this writing.

I wanted to tackle The Odyssey from the compliance perspective. There are many things we can mine from this story. Over the course of this week, I will discuss five of them. Today, we consider where the story begins: the Trojan Horse as a failure of control. On Tuesday, we look at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we look at The Cattle of Helios: Non-Negotiables and Control Breaches. On Friday, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Today, we begin with The Odyssey, which directly follows the end of The Iliad. Here are a few business strategies more celebrated than the Trojan Horse. After ten long years of war, he looked at the walls of Troy and realized brute force had failed. The Greeks could not smash their way in. They could not negotiate their way in. They could not outlast their way in. So Odysseus did what clever leaders often do when conventional methods fail: he found a workaround. Build a great wooden horse. Hide soldiers inside it. Leave it outside the gates as a supposed gift. Sail away, or at least appear to. Let the Trojans make the fatal decision themselves.

While it was brilliant from a strategic perspective, it was an absolute nightmare from a compliance perspective. The Trojan Horse is usually remembered as a triumph of strategy. It should also be remembered as the original “trusted vendor attachment.” It arrived looking valuable, symbolic, and harmless. It came wrapped in a compelling story. It appealed to ego, fatigue, and optimism. And someone, somewhere inside Troy, approved bringing it through the gates.

The Gift That Bypassed Governance

Every organization has gates. Some are literal: firewalls, access controls, locked doors, badge readers, and vendor onboarding systems. Others are procedural: approval matrices, procurement rules, due diligence reviews, cybersecurity assessments, conflict checks, and escalation protocols. The problem is that business opportunities rarely arrive wearing a sign that says, “Hello, I am a control failure.”

They arrive as partnerships. Strategic investments. Technology platforms. Emergency exceptions. Pilot programs. Customer demands. Board-level priorities. Innovation initiatives. “Just this once” requests. Special access for a trusted consultant. A new AI tool that someone found useful. A supplier who can solve the problem quickly. A deal too good to slow down.

In other words, they arrive as gifts. The Trojans did not lose because they lacked walls. They lost because they made a poor risk decision at the gate. The control existed. The wall worked. The problem was judgment, governance, and process. A control environment is not only about having policies. It is about whether people use them when the pressure is on and the opportunity looks attractive.

When Cleverness Becomes the Risk

Odysseus was not a fool. He was a strategist. That is what makes this story so useful for compliance professionals and business leaders. Many compliance failures are not born from stupidity. They are born from intelligence used without discipline. A clever workaround can be useful. A clever workaround can also serve as a bypass of governance. The distinction matters.

Think about the employee who finds a faster way to onboard a vendor by skipping required due diligence. The sales executive who routes a discount through an unusual approval path to close the quarter. The business unit that adopts an unsanctioned software tool because IT is “too slow.” The senior leader who asks for an exception because “this is strategically important.” The team that shares sensitive information with a partner before the agreement is fully papered because “we trust them.”

Each decision may have a business rationale. Each may feel practical. Each may even produce a short-term win. But the compliance question is not simply, “Did it work? “The better question is, “What did it bypass? ”

That is the Trojan Horse problem. The horse worked because it bypassed the normal defenses. In a modern company, that may mean bypassing cyber review, procurement checks, legal review, data protection analysis, sanctions screening, financial controls, conflict review, or code of conduct expectations. When leadership celebrates only the result, the organization learns the wrong lesson. It learns that controls are for ordinary days, not important ones. That is how culture begins to drift.

The Cybersecurity Lesson Inside the Horse

The Trojan Horse is one of the oldest stories in Western literature, but it feels remarkably current in an age of cyber risk and social engineering. A malicious file. A fake vendor invoice. A compromised supplier account. A phishing email that appears to come from a trusted executive. A third-party platform with excessive access. A contractor credential that is never disabled. A software update from a source no one properly vetted. These are modern Trojan Horses.

They do not always break the wall. They persuade someone to open the gate. This is why cybersecurity is not merely an IT function. It is a governance issue. NIST’s Cybersecurity Framework 2.0 places significant emphasis on the Governance function, which addresses how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policies.

That is compliance language as much as cyber language. Who owns the risk? Who approves exceptions? Who monitors access? Who understands the business context? Who has the authority to say no? Who makes sure the organization learns from near misses? If no one can answer those questions clearly, the horse is already inside the gate.

Attractive Risks Test the Control Environment

It is easy to say no to obviously bad ideas. The real test comes when the risk is attached to something the business wants. A lucrative customer. A prestigious partner. A promising technology. A powerful executive sponsor. A deadline. A crisis. A competitor is moving faster. A board presentation next week. That is when the control environment reveals itself.

In a strong control environment, the organization can move quickly without becoming careless. It can evaluate risk without killing innovation. It can escalate concerns without making people feel disloyal. It can approve exceptions, but only with transparency, documentation, and accountability.

In a weak control environment, speed becomes the excuse for opacity. Trust becomes the substitute for diligence. Seniority becomes the overriding control. Documentation comes later, which usually means never. Compliance is invited after the decision has already been made. That is not innovation. That is improvisation with a budget.

The code of conduct should matter most when the business case is compelling. Internal controls should matter most when the pressure is real. Cybersecurity should matter most when the new tool looks exciting. Risk assessment should matter most when everyone is tired of waiting. Troy did not need a better wall. Troy needed a better approval process.

The Insider Threat Dimension

There is another uncomfortable lesson in the Trojan Horse. The Greeks got inside Troy because the Trojans cooperated with the plan. Not intentionally, perhaps. Not corruptly, necessarily. But they cooperated all the same. That is the nature of many insider threats.

The insider is not always a villain. Sometimes the insider is rushed, flattered, distracted, pressured, or insufficiently trained. Sometimes the insider believes they are helping. Sometimes they trust the wrong person. Sometimes they assume someone else has checked. That is why compliance programs cannot rely solely on good intentions.

Good people need good systems. They need clear policies, practical training, escalation paths, and a culture that rewards thoughtful skepticism. They need permission to ask, “Why are we bringing this inside the walls? ”

This is especially important in organizations where questioning a business opportunity is viewed negatively. Compliance should not be the Department of No, but neither should the business become the Department of Please Do Not Ask Too Many Questions. Healthy skepticism is not cynicism. It is stewardship.

What a Better Program Does

A better compliance program does not ban wooden horses. It asks better questions before opening the gate. Who sent it? Why now? What access does it require? What data will it touch? What assumptions are we making? Has the vendor been reviewed? Has the technology been tested? Is there a conflict? Is there a regulatory issue? What is the worst-case scenario? Who approved the exception? How will we monitor it after approval?

The point is not to slow down every decision. The point is to prevent charm, urgency, and executive enthusiasm from replacing governance. A strong program also makes risk ownership visible. If the business wants to accept a risk, that decision should be documented. If a control is bypassed, there should be a reason, an approver, a time limit, and compensating controls. If a new tool, vendor, or relationship is brought inside the organization, someone should be accountable for monitoring it. The Trojan Horse teaches that the most dangerous risks are not always those from outside. Sometimes they are the ones we invite in because they look like success.

The Compliance Takeaway

Odysseus won because he understood human nature. He knew the Trojans would see what they wanted to see: victory, tribute, closure, and a symbol of their own endurance. That is the uncomfortable lesson for corporate compliance. Risk often enters through desire. The desire to win. To move fast. To close the deal. To trust the familiar. To avoid friction. To believe the story makes the opportunity easier to approve.

Not every gift is a threat. Not every workaround is misconduct. Not every clever idea is a control failure. But every organization needs the discipline to ask whether cleverness is serving governance or bypassing it. The horse may be beautiful. The story may be compelling. The business sponsor may be persuasive. Open the gate only after the controls have done their work.

Join us tomorrow, where we consider The Lotus-Eaters: Culture Drift and the Comfort of Forgetting.