Categories
Blog

Connected Compliance: Part 2 – From Risk Register to Risk Radar

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Blog 1 examined communication as the control that connects those elements. In this Part 2, we examine what compliance must do with the intelligence that communication produces.

The traditional risk assessment was built for a world that moved more slowly. Compliance gathered a group of leaders, reviewed enforcement trends, scored familiar risks, produced a heat map, and returned to the exercise the following year. That process still has value, but it is no longer enough.

Today, a new market restriction, customer demand, artificial intelligence deployment, supply-chain disruption, sanctions measure, or data rule can alter the company’s risk profile before the annual plan is approved. The central question is therefore not whether the organization has a risk register. It is whether compliance has a risk radar that can detect change, decide what matters, assign ownership, and translate the signal into action.

Every Compliance Risk Has a Political Dimension

Compliance obligations do not develop in a vacuum. They reflect choices made by governments about national security, trade, technology, labor, privacy, corruption, competition, and corporate accountability. For a multinational company, those choices may conflict, overlap, or change with little notice. Particularly in this political age, the single most-used byword is volatility.

That makes geopolitical awareness a compliance capability. It does not require the CCO to become a foreign-policy analyst. It requires the compliance function to understand how political priorities can become legal obligations, enforcement pressure, customer expectations, or operational constraints. Export controls can reshape product access. Sanctions can alter payment and counterparty risk. Forced-labor requirements can reach deep into a supply chain. AI rules can change how a business collects data, develops products, and makes decisions.

The practical lesson is that legal change is often the last stage in a longer policy development process. Compliance should monitor the earlier signals: legislative proposals, agency speeches, enforcement patterns, trade measures, customer questions, supplier difficulties, and operational workarounds. These indicators do not all demand a program change, but they should enter a disciplined triage process.

What the DOJ Is Really Asking

The Department of Justice has made dynamic risk assessment part of the effectiveness inquiry. The 2024 Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to consider “emerging risks as internal and external circumstances impacting the company’s risk profile evolve.” This risk profile can change due to factors outside a company’s control or its own business decisions. Moreover, the ECCP language moves risk assessment beyond a scheduled document and into continuous management.

DOJ then asks: “Is the company’s approach to risk management proactive or reactive?” The distinction is critical. A reactive program updates controls after a failure, enforcement action, or audit finding. A proactive program uses operational information across functions to identify change before misconduct occurs. The ECCP also asks whether periodic review is merely a point-in-time exercise or draws on continuing access to operational data, and whether the results lead to updates in policies, procedures, and controls.

The enforcement question is not whether the company predicted every development. No program can. The question is whether the company had a reasonable process for identifying material changes, directing resources to higher-risk areas, documenting its decisions, and revising the program over time.

Build the Risk Radar From Multiple Signals

A dynamic risk process begins with a wider field of vision. Regulatory alerts and outside counsel updates are useful, but they show only part of the environment. Some of the earliest warnings come from inside the business. Sales may see unusual customer demands in a new market. Procurement may find suppliers unable to provide origin information. Finance may identify payment routes that no longer fit the expected transaction. Information security may discover employees using unapproved AI tools. Human resources may raise concerns about retaliation or pressure related to performance targets. Audit may identify recurring exceptions. Hotline reports and investigations may reveal a pattern that a heat map missed.

Compliance should bring these signals together through a repeatable cadence. A quarterly cross-functional review can examine changes in the business model, geography, products, third parties, technology, enforcement, and employee concerns. High-velocity risks may require monthly or event-driven review. The objective is not to create another committee. It is to establish a reliable place where weak signals are compared, challenged, and assigned.

Or simply look at the changes wrought by the Trump Administration in 2026 alone. Venezuela is now open for business. How about the Democratic Republic of Congo? See here and here. Of course there is Iran, but you have to ask what week it is and are we doing business with Iran or are we at war with Iran.

Give One Person the Clock

Emerging risks often fall between organizational boxes. Legal understands the rule. Compliance sees the control issue. Operations owns the process. Procurement controls the supplier relationship. Technology owns the system. To use a well-worn maxim, if everyone is in charge, no one is in charge. In the corporate world, when everyone is generally responsible, no one is specifically accountable. This is both why and where compliance needs to step up its game.

Every material risk needs a named owner with the authority to convene the necessary functions, set deadlines, escalate disagreements, and report on the disposition. That person does not perform every task. The owner keeps the clock, maintains the decision record, and ensures that the issue does not disappear between meetings.

Governance should also define escalation triggers. A credible framework identifies which developments require immediate executive attention, which can be handled through a working group, and which should remain under observation. Without thresholds, organizations either under-escalate material risk or flood leadership with undeveloped issues.

Use a Two-Speed Assessment

Not every signal requires an enterprise-wide risk assessment. Compliance needs two speeds. The first is rapid triage. A small group of subject-matter experts identifies the potential legal obligation, affected operations, time horizon, severity, available data, current controls, and immediate containment needs. This is where AI can play a key role in compliance, essentially superforecasting risks to enable quick, efficient risk management strategies when volatility hits. Additionally, such an approach may lead to a decision to monitor, take interim action, or launch a deeper review.

The second is formal assessment. Complex or high-impact risks may require structured interviews, data analysis, control testing, external counsel, forensic support, or scenario planning. The deeper process should be proportionate to the exposure, not triggered simply because the issue is new. This two-speed model protects agility without sacrificing rigor. It also creates evidence that the company made a reasoned decision. A short written triage record can show what information was considered, who participated, why the company chose its response, and when the issue will be reviewed again.

Convert Assessment Into Real Controls

The most common failure is not the inability to identify risk. It is the failure to convert assessment into a viable risk management strategy and then to implement, monitor, and improve your business operations. A new questionnaire, certification, or policy may create documentation, but documentation alone does not mitigate the underlying exposure.

Consider third-party risk. A supplier questionnaire can identify missing information, but the control lies in what happens next: enhanced diligence, contractual protection, source verification, payment restrictions, audit rights, monitoring, remediation, or a decision not to proceed. The same principle applies to AI. An AI-use policy matters, but effective governance also requires an inventory of use cases, approval gates, data controls, human oversight, testing, monitoring, and accountability.

Each response should identify the control objective, owner, implementation date, evidence, and testing method. Compliance should also ask what existing control can be adapted before building a separate program. Strong governance, escalation, training, data access, and investigation processes are reusable infrastructure across risk domains.

Resource allocation is part of that conversion. If a changing risk profile calls for deeper third-party monitoring, faster export review, or additional AI oversight, the organization must decide what people, technology, and budget will support the response. Compliance cannot claim to be risk-based when yesterday’s priorities continue to dictate today’s resources. The allocation decision, including any accepted constraint, should be visible and documented.

Treat Change Management as a Control

A technically correct response can still fail if employees do not understand it or the business cannot implement it. New requirements frequently collide with established incentives, systems, customer commitments, and local practice. Change management should therefore be part of the control design. Explain why the risk changed. Identify which decisions and workflows are affected. Train the employees and gatekeepers who must act differently. Provide a practical escalation route. Test understanding. Gather feedback. Then revise the process when implementation exposes friction or unintended consequences. For a full discussion of change management as a compliance control, listen to the podcast Ronnie Feldman and I did with Caveni Wong on this episode of Creativity and Compliance.

This is where blog post 1’s communication discipline comes into play. Compliance cannot adapt to risk through broadcast messages alone. It needs a two-way channel that tells employees what changed and tells compliance whether the response works in practice.

Measure Adaptation, Not Activity

The number of risk meetings or completed assessments says little about effectiveness. Better measures test whether the organization moves from signal to decision and from decision to control. Useful indicators include the time required to triage a material development, percentage of actions with named owners and deadlines, overdue remediation, control implementation and testing results, repeat exceptions, unresolved ownership disputes, and lessons incorporated from investigations.

Compliance should also examine whether resources shifted when risk shifted. A program that identifies a higher risk but leaves staffing, monitoring, and controls unchanged has produced analysis without management. The result should be a closed loop: detect, assess, assign, mitigate, test, and learn. That loop turns risk assessment from an annual artifact into a management process.

That transition is where program credibility is tested. Join us tomorrow as we consider how organizations scope investigations, preserve independence, establish consistency, document decisions, and convert findings into remediation. A dynamic risk process helps the company see the signal. A credible investigation determines what happened and what the organization must do next.

Bonus Questions for Compliance Professionals

  1. Which internal and external signals can change the company’s risk profile between formal assessments?
  2. Who has specific ownership for emerging risks that cross legal, compliance, operations, procurement, finance, and technology?
  3. What criteria determine whether an issue is monitored, triaged, escalated, or formally assessed?
  4. Can the company show how a recent risk assessment changed a policy, control, resource allocation, or business decision?
  5. Do substantive mitigation and ongoing monitoring support questionnaires and certifications?
  6. How quickly can the organization move from a weak signal to a documented decision?
  7. What recent investigation finding should change the current risk assessment?
Categories
Blog

The Enterprise Incident: 5 Compliance Lessons from a High-Stakes Deception

In The Enterprise Incident, Captain Kirk appears to suffer a breakdown. He orders the USS Enterprise across the Neutral Zone and into Romulan territory, where three Romulan vessels immediately surround the ship. Kirk claims that a navigational error caused the incursion. Spock refuses to support that explanation. Instead, he testifies that Kirk has become irrational and is no longer fit for command. Dr. McCoy confirms the diagnosis. Kirk then appears to die after attacking Spock. Of course, none of this is what it seems.

Kirk, Spock, and McCoy are executing a classified Federation operation to steal a Romulan cloaking device. Kirk’s breakdown is staged. Spock’s betrayal is part of the plan. The supposed Vulcan death grip is a fiction. Kirk is surgically disguised as a Romulan, returns to the enemy vessel, steals the device, and escapes with the Enterprise.

The mission succeeds. Yet operational success does not necessarily establish that the underlying decisions were ethical, properly governed, or worth the risk. That tension makes The Enterprise Incident an outstanding study in compliance leadership. It presents five lessons for compliance professionals operating in high-pressure environments.

Lesson 1: Ethical Decision-Making Requires More Than Authorization

Kirk’s mission was not an impulsive act. He was operating under Federation orders. Nevertheless, the operation required deception, an illegal border crossing, theft of sensitive technology, and conduct that could have triggered an interstellar conflict. Authorization matters, but authorization alone does not resolve the ethical question.

Corporate misconduct is often defended with some variation of “senior management approved it” or “the business required it.” Those statements do not transform improper conduct into ethical conduct. They may instead reveal weaknesses in governance, escalation, and executive accountability.

Compliance leaders must ask whether a proposed course of action is consistent with the organization’s legal obligations, stated values, risk appetite, and long-term interests. They must also consider whether the action could withstand scrutiny from regulators, shareholders, employees, and the board. Under pressure, the temptation is to focus exclusively on the desired outcome. The stronger approach is to examine both the objective and the means used to achieve it.

A successful mission can still represent a governance failure. Compliance must help the organization distinguish between what it can do, what it should do, and what it must never do.

Lesson 2: Confidentiality Must Not Eliminate Accountability

The Enterprise crew succeeds because Kirk, Spock, McCoy, and Scotty understand their roles and trust one another. Within that small group, the plan is carefully coordinated. Outside the group, almost everyone is intentionally misled. This is a classic need-to-know operation. It also demonstrates the risk created when secrecy becomes a substitute for accountability.

Organizations sometimes need to restrict information. Internal investigations, acquisition discussions, government inquiries, cybersecurity incidents, and sensitive personnel matters all require confidentiality. The mistake is assuming that confidentiality means normal controls no longer apply. Even the most sensitive matter should have an accountable owner, defined decision rights, appropriate legal oversight, protected documentation, and a process for reporting to the board when necessary. Information may be limited, but accountability should remain clear.

This lesson is particularly important in internal investigations. An investigation may require discretion, but the organization must still preserve evidence, manage conflicts, document decisions, protect against retaliation, and identify who receives the findings. The key distinction is between controlled confidentiality and organizational opacity. Controlled confidentiality protects the integrity of the process. Opacity protects decision-makers from scrutiny. Trust among a small team is valuable. It is not a replacement for governance.

Lesson 3: Sensitive Technology Demands Controls Across Its Entire Lifecycle

The Romulan cloaking device is more than a valuable piece of equipment. It is strategically significant technology capable of changing the balance of power. The Enterprise crew focuses first on acquiring the device. Scotty must then integrate an unfamiliar piece of Romulan technology into the ship’s systems while the Enterprise is under attack. There is little time for testing, security review, or compatibility analysis.

Modern organizations face similar issues with artificial intelligence, source code, proprietary algorithms, customer data, trade secrets, surveillance tools, and cybersecurity capabilities. The risk does not begin or end with acquisition. It extends across the technology’s entire lifecycle. The cloaking device also raises a broader question: Just because technology can create a strategic advantage, should the organization deploy it immediately?

That question is central to AI governance. A new AI system may promise speed, efficiency, and competitive advantage. It may also create risks related to privacy, discrimination, intellectual property, cybersecurity, and regulatory compliance. The organization needs more than an enthusiastic business sponsor. It needs governance, testing, documentation, human oversight, and clear accountability. Innovation without controls creates unmanaged exposure. Controls without an understanding of the technology create false assurance.

Lesson 4: Regulatory and Geopolitical Risk Must Be Built into Strategy

The Neutral Zone is not simply a line on a star chart. It represents a legal, diplomatic, and military boundary. Crossing it creates consequences that extend far beyond the Enterprise. International businesses operate across their own versions of the Neutral Zone. These include anti-bribery laws, sanctions, export controls, data localization requirements, competition rules, human rights expectations, and restrictions on technology transfers.

A decision that appears commercially attractive in one jurisdiction may create serious exposure in another. A third party that looks essential to market access may present corruption or sanction risks. A technology transfer may implicate national security restrictions. A routine payment may become evidence of an improper inducement. Compliance cannot be brought in after the business has crossed the border.

The compliance function should participate in market-entry decisions, transactions, major technology transfers, and relationships involving government touchpoints. This requires more than maintaining a regulatory inventory. It requires understanding how legal, political, cultural, and enforcement risks affect business strategy. The Enterprise had only one hour to respond to the Romulan demand for surrender. Corporate leaders often face similar pressure, although usually without disruptor beams. The time to establish decision protocols is before the crisis begins.

Lesson 5: Compliance Should Enable Calculated Risk, Not Eliminate It

Stealing the cloaking device was extraordinarily risky. It also offered a significant strategic benefit. Starfleet decided that the potential value justified the exposure. Every organization takes risks. The purpose of compliance is not to eliminate risk or prevent innovation. It is to help the organization understand risk, evaluate it intelligently, establish limits, and make accountable decisions.

A calculated risk is not simply a dangerous decision that happens to succeed. It is a decision supported by reliable information, appropriate expertise, documented assumptions, mitigation measures, clear ownership, and contingency planning. The Enterprise mission depended on several assumptions. The Romulans had to accept Kirk’s apparent instability. The commander had to believe Spock’s betrayal. Kirk’s disguise had to work. Scotty had to integrate the cloaking.

Compliance adds value when it helps the business take better risks. That requires early engagement, commercial understanding, credible challenge, and a willingness to say no when the proposed conduct crosses a legal or ethical boundary.

Final Thoughts

The Enterprise Incident ends with the Enterprise escaping Romulan space under the protection of the stolen cloaking device. The operation succeeds because of extraordinary coordination, technical skill, and trust. Yet the episode leaves compliance professionals with a harder question: Was the mission properly governed, or was it simply successful?

That distinction matters. Results do not validate weak processes. Senior approval does not cure unethical conduct. Confidentiality does not remove accountability. Innovation does not override controls. Strategic pressure does not suspend legal obligations. The compliance professional’s role is to help the organization navigate those tensions before it enters the Neutral Zone.

The final compliance lesson from The Enterprise Incident is straightforward: Bold leadership may take the organization into uncertain territory, but effective compliance ensures that it does not cross the line without understanding what lies on the other side.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

The Odyssey and Compliance, Part 3 – Circe’s Island: Third-Party Influence and Culture Capture

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of Circe’s Island and how third parties can not simply influence but also capture organizations.

Odysseus had seen danger before. He had survived war, storms, and the occasional poor travel decision that would have caused any modern risk committee to request an immediate meeting. But then he came to Circe’s island, where the threat did not begin with open violence. It began with hospitality. Circe welcomed Odysseus’s men. She offered food. She offered a drink. She offered comfort. Then, in one of the more memorable compliance-adjacent transformations in Greek mythology, she turned them into swine.

Subtle? Not especially. Useful for corporate compliance? Absolutely. In the corporate world, third parties rarely transform employees into literal pigs. That would at least make the investigation easier. The modern version is quieter. A consultant becomes indispensable. A reseller knows “how things work here.” A lobbyist explains that the official process is for amateurs. A distributor normalizes side payments. A strategic partner begins to shape internal decisions. A vendor’s gifts, favors, travel, and access slowly change what employees consider acceptable.

No one wakes up and says, “Today I shall surrender my professional judgment.” Instead, judgment softens and then stretches. Then outsourced. That is Circe’s island.

The Corporate Translation

Circe is the consultant, agent, lobbyist, reseller, distributor, broker, introducer, or strategic partner who makes questionable conduct feel sophisticated. She does not have to say, “Break the rules.” That would be too obvious. She says something more dangerous:

“This is how business is done.”

“Everyone uses this structure.”

“You are being too rigid.”

“The policy was not written for this situation.”

“You can trust me.”

“We have relationships you do not have.”

That is the language of culture capture. The third party does not merely provide a service. The third party begins to influence the organization’s standards. This is why third-party risk is not just a procurement issue. It is not just an anti-bribery issue. It is not just a contracting issue. It is a cultural issue. The most dangerous third parties do not always demand a bribe. Sometimes they simply change what your people think is normal.

The Paperwork Trap

Most companies have a third-party process. There is a questionnaire. There is a risk rating. There is a certification. There is a contract clause. Somewhere, there may even be a spreadsheet with conditional formatting, because nothing says “control environment” like a cell turning amber. These tools matter. But paperwork alone does not manage influence.

A company can collect every form and still miss the real risk. Whom is this third party influencing? Who inside the company is advocating for them? Why are they needed? What access do they have? What discretion do they exercise? Are they interacting with government officials, customers, healthcare professionals, regulators, state-owned entities, procurement teams, or other sensitive stakeholders? Are they being paid in a way that makes sense? Are they actually doing the work? Are they unusually close to the decision-maker?

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether companies apply risk-based due diligence to third-party relationships and understand the qualifications, associations, business rationale, reputation, compensation, and actual services performed by third parties. It also asks whether companies engage in ongoing monitoring through refreshed due diligence, training, audits, or certifications.

That is the point. Third-party compliance is not a one-time onboarding ritual. It is a relationship management discipline. Circe’s danger was not that she existed. The danger was that Odysseus’s men entered her house without understanding the risk.

Gifts, Hospitality, and the Slow Erosion of Judgment

Gifts and hospitality are often discussed as if the only question is whether the amount is above or below a policy threshold. That is too narrow. A meal may be permissible and still influential. A conference invitation may be properly approved and still create pressure. A vendor-sponsored trip may be documented and still tilt the relationship. A series of small favors may do more damage to independence than one obviously improper gift.

Compliance officers understand this. Business leaders sometimes resist it because influence is uncomfortable to discuss. No one wants to admit that lunch, access, flattery, or convenience can affect judgment. We prefer to believe we are all rational actors, floating above human weakness like minor gods with expense reports. We are not.

Behavioral ethics teaches a humbler lesson: people are influenced by relationships, reciprocity, loyalty, fatigue, social norms, and self-interest. A third party who becomes a friend, fixer, sponsor, or “trusted guide” can reshape decisions without issuing a single improper instruction.

That is why gifts-and-hospitality controls should look beyond monetary value. They should examine frequency, timing, recipient role, pending decisions, public-sector touchpoints, tender activity, regulatory matters, and cumulative patterns. The better question is not only, “Was this gift allowed? “The better question is, “What might this gift be trying to make feel normal? ”

Conflicts of Interest: Circe with a Business Card

Conflicts of interest are another form of enchantment. The employee recommends a vendor owned by a family member. A manager hires a consultant whom he previously employed. A procurement lead has a side investment in a supplier. A sales executive pushes a reseller because the reseller has promised future employment. A board member has ties to a strategic partner.

Often, the conflicted person does not experience the conflict as corruption. They experience it as trust.

“I know them.”

“They are good people.”

“They understand our business.”

“This will move faster.”

That may all be true. It may also be irrelevant. Conflicts do not require proof that someone acted dishonestly. A conflict means that personal interest may interfere with, or appear to interfere with, professional judgment. In compliance, appearance matters because trust matters. Circe did not need to tell the crew they were compromised. They simply became something other than what they had been. That is what unmanaged conflicts do. They transform decision-makers into advocates for interests they may not even fully recognize.

Risk-Based Due Diligence Means Asking Better Questions

A strong third-party program should be risk-based. That does not mean treating every vendor like a potential international crime syndicate. It means applying the right level of scrutiny to the right relationship. The office coffee supplier probably does not need the same review as a customs broker, government-facing consultant, high-commission sales agent, data processor, clinical partner, reseller, lobbyist, or distributor in a high-risk market.

Risk-based due diligence should ask direct questions:

What will this third party do for us?

Why do we need them?

Who selected them?

What relationships do they bring?

How will they be paid?

What access will they receive?

What decisions can they influence?

What laws, regulations, or policy areas do they touch?

What red flags appeared, and how were they resolved?

The ECCP also emphasizes risk assessment across factors such as business partners, third-party use, gifts, travel, entertainment, and other areas that may contribute to the risk of misconduct. That is a useful reminder: third-party risk rarely travels alone. It often brings friends. Gifts risk. Conflicts are risky. Books-and-records risk. Data risk. Sanctions risk. Cyber risk. Antitrust risk. Fraud risk. Reputational risk. Circe’s island is crowded.

Training the People Who Meet Circe

Third-party policies are necessary, but people need training before they sit across the table from Circe. Sales teams need to understand the red flags for resellers and agents. Procurement teams need to spot conflicts and unusual payment terms. Finance needs to recognize vague invoices, round-dollar payments, split payments, and services that cannot be verified. Legal needs to ensure that contracts describe real services and include rights to audit, termination, compliance, and cooperation. Business sponsors need to understand that “I trust them” is not due diligence.

The ECCP asks whether training and communications are tailored to the audience and whether companies provide practical guidance, case studies, and ways for employees to get ethics advice as issues arise. It also contemplates training for appropriate agents and business partners. That is exactly right.

Do not train employees only on the policy. Train them in the moment. The moment when the consultant says the invoice needs to be vague. The moment when the distributor asks for payment to an offshore account. The moment when the lobbyist says no one can know about the meeting. The moment when the vendor offers to fly the team to a “strategy session” at a resort, suspiciously light on strategy. The moment when the business sponsor says, “Compliance is slowing this down.” That is where the program either works or becomes decorative.

What a Better Program Does

A better third-party program examines influence, not just paperwork. It connects due diligence, contracting, training, payment controls, gifts and hospitality, conflict disclosures, monitoring, audits, and termination rights. It reviews third-party activity after onboarding. It checks whether services were actually performed. It compares compensation to market value. It looks for unusual payment structures. It refreshes diligence when risk changes. It trains business sponsors, not just compliance staff. It monitors the internal champions who may become too close to the third party they manage.

Most importantly, it permits employees to be skeptical. Not cynical. Skeptical. There is a difference. Cynicism says everyone is corrupt. Skepticism says facts, controls, and accountability should support trust. Odysseus survived Circe because he received a warning, protection, and guidance before walking into the risk. Your employees need the same, preferably without needing Hermes to appear with magical herbs.

The Compliance Takeaway

Circe’s island is not just a story about transformation. It is a story about influence. Third parties can help companies grow, enter new markets, solve complex problems, and operate more effectively. Many are essential. Many are ethical. Many know things the company genuinely needs to know. But a third party should never become a substitute for the company’s judgment. When a consultant, agent, reseller, lobbyist, vendor, or strategic partner begins to redefine what is acceptable, the company has moved from third-party management to third-party capture.

That is the lesson for compliance officers and business leaders. Do not ask only whether the forms are complete. Ask whether the relationship is changing behavior. Ask whether gifts, conflicts, access, dependence, or pressure are making questionable conduct feel normal. Ask whether employees still know where the company’s standards end and Circe’s influence begins. Because in business, as in mythology, transformation rarely announces itself. One day, your people are professionals exercising independent judgment. The next day, they are defending the island.

Join us on Thursday for Post 4, where we consider The Cattle of Helios: Non-Negotiables and Control Breaches.

Categories
Blog

Re-Calibrating Risk Assessments: Uncovering FTO and TCO Exposure in Cartel-Driven Economies

This blog continues our series focusing on the upcoming ACI Forum on Cartels, TCOs, and Compliance in Latin America and why it is so timely. It is also why compliance officers need to understand that this is not simply another enforcement trend. It is a structural change in how risk must be assessed, governed, and managed. Today, I want to explore why you need to recalibrate your risk assessment in light of the US’s shift in classifying cartels from criminal organizations to Foreign Terrorist Organizations (FTOs).

For years, many companies treated cartel risk as a regional security issue, a physical safety issue, or a narrow sanctions-screening issue. That approach is no longer sufficient. Cartel-driven economies now create enterprise risk across sales, supply chain, procurement, logistics, human resources, community relations, government affairs, security, and internal controls. The CCO must help the organization move from episodic screening to a dynamic, evidence-based risk assessment model that identifies where the business may be exposed to Foreign Terrorist Organization (FTO) and Transnational Criminal Organization (TCO) risks.

The legal and enforcement environment has shifted. Executive Order 14157 established a process for certain international cartels and other organizations to be designated as FTOs or Specially Designated Global Terrorists, and described those organizations as threats to U.S. national security, foreign policy, and the economy. OFAC later issued an alert identifying eight designated organizations and warning that companies with operations in, or exposure to, high-risk jurisdictions where designated cartels are active should assess their sanctions compliance controls. That is the compliance lesson. This is not simply a legal list update. It is a risk assessment reset.

Cartel-Driven Economies Change the Risk Ranking Model

Traditional compliance risk assessments often rank risk by country, business unit, transaction value, government touchpoints, and third-party type. Those variables still matter. But cartel-driven economies require additional factors: territorial control, coercive influence, infiltration of local business networks, labor pressure, logistics-route control, cash intensity, proximity to ports or borders, public security risks, and the likelihood that a legitimate counterparty may be owned, controlled, taxed, extorted, or otherwise influenced by criminal organizations.

The ranking model should distinguish between three types of exposure. First, direct exposure, where a company deals with a designated party or a party it owns or controls. Second, indirect exposure, where a supplier, distributor, customer, logistics provider, labor broker, or security vendor is connected to cartel-linked actors. Third, environmental exposure, where the company operates in a geography or sector where coercion, extortion, or criminal facilitation is a predictable operating condition.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether third-party management is risk-based, integrated into vendor management, supported by business rationale, tied to appropriate contract terms, and subject to ongoing monitoring. Those questions should now be applied not only to anti-bribery risk, but also to FTO and TCO risk.

Create an Internal FTO Working Group

A company cannot manage this risk through sanctions screening alone. The CCO should establish an internal FTO working group with a clear charter, executive sponsorship, and board reporting. The group should include compliance, legal, sanctions, AML, procurement, sales, finance, logistics, security, HR, government affairs, community relations, internal audit, and enterprise risk management.

Its mandate should be practical: identify exposures, refresh risk rankings, define escalation protocols, review high-risk contracts, approve enhanced due diligence standards, monitor emerging typologies, and track remediation efforts. It should also define when the company will suspend a transaction, reject a counterparty, exit a relationship, seek external counsel, notify insurers, or brief the board. This working group should meet frequently at the outset, then move to a risk-based cadence. Its output should not be a memo that sits on a shelf. It should produce a revised heat map, a prioritized counterparty review list, an action tracker, and control enhancements that can be tested by internal audit.

Leverage Existing Risk Assessments

The most efficient approach is not to create a wholly separate FTO risk assessment. The better approach is to integrate FTO/TCO risk into existing assessments. Your FCPA risk assessment already identifies government touchpoints, customs brokers, permitting issues, gifts and entertainment, charitable donations, intermediaries, consultants, and high-risk payments. Those same data points are highly relevant to cartel exposure because criminal networks often exploit local permitting, customs clearance, transportation, public security, and procurement systems.

The business and human rights assessment also provides critical intelligence. The UN Guiding Principles on Business and Human Rights recognize a corporate responsibility to respect human rights through due diligence that avoids infringing on the rights of others and addresses adverse impacts with which the business is involved. In cartel-affected markets, human rights due diligence can reveal forced labor, threats against workers, community intimidation, unsafe security practices, land-access disputes, migrant exploitation, and labor-broker abuse.

Sanctions, AML, trade compliance, cybersecurity, and fraud risk assessments should also be mined. Look for recurring names, addresses, beneficial owners, banks, payment patterns, shell entities, shared directors, unusual routes, unexplained subcontractors, and counterparties that appear across unrelated business units.

Review Major Contracts and Customers for FTO/TCO Risk

Companies often focus due diligence on suppliers and intermediaries, while under-reviewing major customers. That is a mistake. A customer can create sanctions, money-laundering, books-and-records, reputational, and material-support risks. The company should identify major contracts in high-risk geographies and sectors, then re-rank them based on ownership transparency, payment behavior, sector exposure, government interaction, logistics routes, and local operating conditions. High-risk contracts should include enhanced representations, beneficial ownership update obligations, audit rights, sanctions, and FTO/TCO clauses, payment transparency requirements, subcontractor disclosure, termination rights, and controls over cash, commissions, rebates, donations, sponsorships, and community payments.

A contract should move into enhanced review when the business cannot explain the counterparty’s commercial rationale, when pricing is uneconomic, when payment comes from unrelated parties, when revenue spikes in cartel-affected regions, when the counterparty refuses beneficial ownership disclosure, or when local employees report pressure to use a particular vendor, union, broker, transporter, or security provider.

Detect Commingling of Legitimate and Illegal Activity

The core challenge is commingling. Cartels do not always operate through obviously illicit entities. They use logistics companies, fuel businesses, casinos, real estate, import-export companies, labor brokers, charities, community organizations, and professional service providers.

Recent enforcement actions show the point. Recently, the US Department of the Treasury announced multiple CJNG-linked fuel schemes involving cross-border smuggling, falsified customs documents, and shell companies. OFAC also described cartel-linked casino activity used to launder proceeds and integrate illicit funds into the legitimate financial system. For compliance professionals, these examples reinforce a familiar truth: a company’s legal form is not the same as its risk profile.

Detection requires data and local intelligence. Compare invoices to actual services. Review customs documentation against logistics activity. Test whether vendors have employees, assets, facilities, and capacity. Analyze payment flows for round-dollar amounts, rapid pass-through activity, third-party payments, and mismatches between business size and transaction volume. Monitor hotline reports for references to threats, forced vendors, security payments, labor pressure, and community demands.

Functions That Must Be in Scope

Supply chain must map critical suppliers, second-tier exposure, logistics corridors, warehousing, border crossings, ports, and emergency sourcing decisions. HR must assess labor brokers, recruitment channels, employee intimidation, workplace violence, the risk of retaliation, and escalation pathways for threatened employees. Community relations must review donations, sponsorships, local foundations, land-access payments, and community intermediaries. Union relations must assess whether labor organizations or labor contractors are being used as pressure points. Government affairs must evaluate permitting, customs, inspections, police interaction, and local political exposure. Security must review private security providers, public security coordination, incident response, travel protocols, and extortion procedures. The board should ask one question above all others: where could the company be doing legitimate business through a channel that criminal actors influence, control, or monetize?

Practical Takeaways

CCOs should refresh the risk assessment now, not after a transaction is called into question. Build the FTO working group, integrate existing FCPA and human rights intelligence, re-rank major contracts and customers, and test controls for commingling. The objective is not perfection. The objective is a documented, risk-based, board-visible process that shows the company understands its exposure, updates its controls, and acts when the risk profile changes.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For a complete list of the agenda, click here. You can receive a 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
FCPA Compliance Report

FCPA Compliance Report: Managing Compliance and National Security Risks When Doing Business in the DRC, Part 1

In this episode, Tom Fox welcomes David Simon, Partner at Foley & Lardner; Jack Korba, Of Counsel at Foley & Lardner; and Olivier Bustin, a Partner at Pinsent Masons, to talk about doing business in and with the Democratic Republic of the Congo (DRC). This is the first part of a two-part series on this topic. The guests present a detailed approach to evaluating and managing travel into a high-risk country or region.

The three argue that while governance and logistics risks remain, improved infrastructure and heightened strategic importance of the DRC’s critical minerals (including cobalt, coltan, lithium, manganese, and rare earths) make risks more manageable and the market more relevant, with noted U.S. government continuity across administrations. They discuss opportunities beyond mining, including power, logistics, banking/insurance, tech, entertainment, and education, while emphasizing infrastructure and bankability constraints. Korba outlines national security, sanctions/export controls, and supply chain “adjacency” risks, as well as the need for sector-specific analysis. The panel highlights “choke points” stemming from concentrated power and weak institutions, and Bustin explains why local content/ownership rules and patronage dynamics require diligence that goes beyond nominal ownership. They conclude by applying a risk-based compliance approach, devoting enhanced resources to higher-risk projects and counterparties.

Key highlights:

  • Why DRC Now
  • Beyond Mining Opportunities
  • National Security Risks
  • Choke Points Explained
  • Local Ownership Diligence
  • Risk-Based Compliance

Resources:

David Simon

Jack Korba

Olivier Bustin

Foley & Lardner

Pinsent Masons

The Democratic Republic of the Congo as a Near-Term Strategic Opportunity for U.S. Companies Part 1

Part 2

Part 3

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: June 3, 2026, The From No Control to Total Control Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. AI compliance needs risk management from day one. (FinTech Global)
  2. Driving AI-powered AML. (Finovate)
  3. Traditional KYC is no longer effective. (FinTech Global)
  4. Deskilling in healthcare. (Healthcare Dive)
  5. Trump wants AI companies to get government approval. (NYT)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

The Muppet C-Suite: A Compliance Professional’s Guide to Culture, Controls, and Chaos Part 4: Animal as Chief Operating Risk Officer: Managing Chaos Before Chaos Manages You

This week we are honoring the return of The Muppets for a 2026 Special Edition. I thought it would be fun to look at business leadership teams through the lens of The Muppets. Every compliance professional has worked with a Kermit, managed a Piggy, worried about a Gonzo, or tried to contain an Animal. Today, we conclude by looking at The Animal problem. This series has used the Muppet executive team as a framework to explore leadership, governance, innovation, operational risk, and corporate compliance through the lens of the DOJ’s Evaluation of Corporate Compliance Programs and modern governance expectations.

Every organization has an Animal. Sometimes it is a person. Sometimes it is a business unit. Sometimes it is a revenue stream so profitable that leadership stops asking difficult questions. But every organization eventually encounters a force that is energetic, productive, volatile, difficult to control, and capable of creating enormous operational damage if left unmanaged. That is Animal.

As Chief Operating Risk Officer, Animal represents a truth many organizations struggle to confront: the greatest operational risks are often tolerated because they generate short-term success. An animal is loud, destructive, impulsive, emotional, and frequently one bad day away from catastrophe. Yet he is also highly effective in the environment for which he was designed. He brings energy, intensity, speed, and momentum.

The problem is not that Animal exists. The problem is when the organization mistakes unmanaged volatility for sustainable performance. That is where compliance, governance, and operational discipline become critical.

Operational Risk Rarely Arrives Quietly

One of the most dangerous assumptions organizations make is that operational failure arrives gradually and predictably. Often, it does not. Operational breakdowns tend to emerge after warning signs have already been normalized:

  • repeated policy exceptions,
  • constant escalation failures,
  • excessive workload pressure,
  • ignored complaints,
  • control fatigue,
  • unmanaged third parties, and
  • and high-performing employees who are allowed to operate outside established expectations.

Animal embodies this normalization problem perfectly. Everyone knows he is dangerous. Everyone knows he is unpredictable. Everyone knows he creates operational instability. Yet the organization repeatedly tolerates the behavior because the show benefits from his energy. This is how many operational crises develop in real organizations. The issue is rarely ignorance. The issue is tolerance.

The Compliance Challenge of High-Performing Risk Creators

One of the DOJ’s most important compliance questions is whether organizations apply discipline consistently, regardless of title, status, or revenue generation. That sounds straightforward. In practice, it is extraordinarily difficult. Organizations routinely create informal exceptions for:

  • top producers,
  • senior executives,
  • innovative teams,
  • politically connected employees, and
  • and operational leaders are perceived as indispensable.

An animal represents this exact governance problem. A mature compliance program recognizes that unmanaged high performers create enterprise risk because they gradually teach the organization that controls are optional for the “right” people. Once that message spreads, culture deteriorates quickly. Employees notice:

  • who gets exceptions,
  • whose misconduct is ignored,
  • whose violations are minimized, and
  • and whether leadership consistently enforces standards.

That is why operational risk is deeply connected to culture. Operational instability rarely begins with a single process failure. It usually begins with accountability failure.

Animal and the Failure of Escalation

Perhaps the most dangerous thing about Animal is not his volatility. The organization tends to underestimate the seriousness of the risk until after damage occurs. This reflects a common corporate governance problem: escalation fatigue. Over time, organizations become accustomed to recurring dysfunction:

  • “That is just how he operates.”
  • “That team is always difficult.”
  • “They are under pressure.”
  • “The business results justify the headaches.”
  • “We can manage around it.”

Those statements are operational-risk warning signs. A mature compliance program must create escalation structures capable of identifying:

  • repeated near misses,
  • recurring control failures,
  • cultural deterioration,
  • operational shortcuts, and
  • and conduct risks before they evolve into crises.

An animal should not require an explosion before leadership intervenes. Unfortunately, many organizations wait for exactly that moment.

Root Cause Analysis Matters

When operational failures occur, organizations often focus immediately on the visible event:

  • the failed transaction,
  • the misconduct,
  • the regulatory inquiry,
  • the system failure, and
  • or the public embarrassment.

But effective governance requires deeper analysis. The ECCP specifically emphasizes root cause analysis because sustainable remediation depends on understanding why the failure occurred in the first place. With Animal, the obvious answer might be: “Animal lost control.”

But the real questions are:

  • Why was the risk tolerated repeatedly?
  • Why were escalation signals ignored?
  • Why were controls insufficient?
  • Why did leadership normalize the volatility?
  • Why were prior incidents dismissed as isolated?

Those questions move the organization from blame to governance. A mature compliance function should always ask whether operational failure reflects:

  • incentive problems,
  • leadership failures,
  • staffing pressures,
  • inadequate oversight,
  • resource constraints, and
  • or cultural normalization of misconduct.

Without root cause analysis, organizations simply reset the stage for the next crisis.

Speak-Up Culture and Operational Risk

Animal also highlights the importance of a culture of speaking up. In many organizations, employees recognize operational risk long before leadership does. The problem is that employees often conclude:

  • raising concerns changes nothing,
  • leadership already knows,
  • retaliation risk is too high,
  • or operational pressure outweighs ethical concerns.

That silence becomes dangerous. The DOJ increasingly expects organizations to maintain effective reporting channels, anti-retaliation protections, and meaningful investigative response mechanisms. But a speak-up culture is not merely a hotline issue. It is a credibility issue. Employees must believe:

  • concerns will be heard,
  • escalation will occur,
  • retaliation will not be tolerated,
  • and leadership is willing to intervene even when operational performance is affected.

In Animal’s world, the organization often appears resigned to the chaos. That resignation is itself a governance failure.

Crisis Management Is a Governance Discipline

Animal is also a reminder that crisis management is not public relations. It is governance under pressure. Operational crises test:

  • leadership credibility,
  • escalation systems,
  • internal communication,
  • decision-making discipline,
  • documentation quality, and
  • and organizational resilience.

Strong organizations prepare for operational disruption before it occurs. That means:

  • crisis-management protocols,
  • escalation matrices,
  • tabletop exercises,
  • communication plans,
  • cross-functional coordination, and
  • and clear authority structures.

Animal should never be the organization’s first operational surprise.

Yet many companies operate as though volatility itself is unpredictable when, in reality, warning signs existed for months or years. The question is whether leadership chose to recognize them.

Control Fatigue Is Real

One of the most overlooked operational risks is control fatigue. When organizations operate under constant pressure, employees gradually begin bypassing safeguards:

  • approvals become rushed,
  • documentation becomes incomplete,
  • exceptions become routine,
  • monitoring weakens,
  • and oversight becomes reactive instead of preventive.

Animal accelerates this dynamic because his operational style rewards speed and intensity over discipline and sustainability. That creates a dangerous cycle:

  1. pressure increases,
  2. controls weaken,
  3. near misses increase,
  4. normalization expands, and
  5. and eventually failure becomes inevitable.

A mature compliance program continuously monitors for this pattern because operational collapse rarely occurs without warning.

5 Key Takeaways for the Compliance Professional

1. Operational risk is often tolerated because it produces results.

Organizations must resist creating informal exceptions for high-performing but destabilizing individuals or business units.

2. Escalation failures are early warning signs.

Repeated policy exceptions, ignored concerns, and normalized dysfunction frequently precede major operational breakdowns.

3. Root cause analysis is essential for sustainable remediation.

Organizations should investigate not only what failed, but why leadership and controls allowed the failure to persist.

4. Speak-up culture directly affects operational resilience.

Employees must trust that concerns will be heard, investigated, and acted upon without retaliation.

5. Crisis management is a governance function.

Effective organizations prepare for operational disruption through planning, escalation structures, monitoring, and cross-functional coordination.

The Final Governance Lesson

Across this series, Kermit, Piggy, Gonzo, and Animal together represent the four forces constantly shaping corporate governance:

  • leadership,
  • reputation,
  • innovation,
  • and operational risk.

The lesson is not that organizations should eliminate strong personalities, ambition, experimentation, or intensity. The lesson is that mature governance recognizes these forces early and builds systems capable of channeling them responsibly.

Kermit provides stability.

Piggy creates visibility.

Gonzo drives innovation.

Animal tests the strength of operational controls.

Every organization contains all four. The real question for compliance professionals is whether the governance structure is strong enough to keep the theater standing when all four are operating at the same time. Because eventually, they will be.

Long Live The Muppets

Categories
Compliance Into the Weeds

Compliance into the Weeds: Banking Regulators Cut Model Risk Guidance: Implications for Compliance, Audit, and AML Oversight

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully, and looking for some hard-hitting insights on compliance. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss new Federal Reserve, FDIC, and OCC model risk management guidance issued late Friday, arguing it replaces detailed, bright-line expectations with thin, principles-based language.

They contrast the prior OCC guidance (109 pages) with the new 12-page document, saying it describes model risk governance abstractly but offers little direction on what banks should do, leaving decisions about materiality and oversight to management. They highlight practical consequences for bank compliance and internal audit, including reduced leverage to insist on prudent governance, potential weakening of AML model oversight under the strict-liability Bank Secrecy Act, and the risk of more arbitrary enforcement amid reduced regulatory staffing. They also note that the guidance excludes AI models, with future AI guidance promised only through a later comment process.

Key highlights:

  • From 109 pages to 12
  • Principles vs specifics debate
  • Internal audit sidelined
  • Regulators and capacity cuts
  • AI models left out 

Resources:

Matt on Radical Compliance

 Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, a Communicator Award, and a W3 Award, all for podcast excellence.

Categories
Blog

AI Risk Appetite: The Conversation Boards Are Not Having

There is a quiet but serious problem developing in boardrooms around AI. Directors are hearing about innovation. They are hearing about productivity gains. They are hearing about competitive pressure, transformation, and speed. What they are not hearing enough about is risk appetite. That is the missing conversation.

Most companies are already using AI in one form or another. Some are deploying enterprise tools. Some are approving vendor solutions with embedded AI. Some are allowing business units to experiment in a controlled fashion. Some, of course, are doing all of the above and pretending it is a strategy. Yet for all the discussion about adoption, there has been far less focus on a basic governance question: what level of AI-driven decision risk is acceptable for this company? That is not a technical question. It is a board question.

The Risk Appetite Gap in AI Governance

AI is not simply another software purchase. It can influence recommendations, rankings, forecasts, summaries, classifications, and decisions. It can operate upstream from business judgments or directly within them. It can affect customer communications, hiring decisions, compliance monitoring, internal investigations, financial analysis, and reporting workflows. So the central governance challenge is not whether AI exists in the enterprise. It is how much authority the company is willing to give it, in what contexts, with what controls, and with what margin for error. If you do not define that, you do not have AI governance. You have AI optimism.

What Is AI Risk Appetite?

At its core, AI risk appetite is the level and type of AI-related risk an organization is willing to accept in pursuit of business value. That includes a series of questions boards ought to be asking. How much error is acceptable in AI-generated output before a human must intervene? Which uses are low-risk productivity enhancements, and which are sensitive, consequential, or reputation-threatening? In what contexts can AI make recommendations only, and in what contexts can it influence or automate action? How much dependence on opaque third-party models is acceptable? What degree of explainability does the company require for different use cases? When does speed stop being a benefit and start becoming exposure?

Many boards are currently discussing AI deployment without ever discussing AI tolerance. That is like approving a global third-party strategy without deciding what level of distributor risk, sanctions exposure, or bribery risk the company is prepared to accept. No compliance professional would recommend that. Yet in AI, organizations do versions of it every day.

Why Boards Avoid the Conversation

There are several reasons boards have been slow to engage on AI risk appetite.

First, the technology moves fast, and the terminology can become a fog machine. Directors do not want to look uninformed, so discussions often stay broad and strategic. Second, management may not yet have the internal inventory or classification framework needed to make a risk-appetite conversation concrete. Third, many companies are still in an experimentation phase, which creates the illusion that formal governance can come later. Fourth, there is a natural tendency to believe AI risk belongs to IT, legal, or security, rather than to enterprise oversight.

AI risk appetite cannot be delegated away because it intersects with business judgment, ethics, records, privacy, data governance, resilience, and culture. It cuts across functions. It also cuts across reputational boundaries. If a company uses AI in a way that produces unfair results, faulty decisions, poor disclosures, or customer harm, nobody is going to say, “Well, that was a technical issue, so the board need not have been involved.” Boards do not get a hall pass when the governance system is missing.

The Conversations Boards Need to Be Having

Risk Map. The first conversation is about where AI sits on the company’s risk map. Is AI a productivity tool, a strategic platform, a decision-support capability, or some combination of all three? The answer matters because it affects the level of oversight. A company using AI for internal drafting support faces one type of exposure. A company using AI in customer-facing interactions, underwriting, hiring, fraud detection, or compliance monitoring faces another challenge.

Decision Significance. Boards need to ask where AI is being used in decisions that affect legal rights, financial outcomes, customer treatment, employment status, compliance judgments, or public disclosures. Not all uses are equal. A board that treats AI use in marketing copy the same as AI use in employee discipline is not governing. It is lumping.

Acceptable Error and Human Review. Boards should ask: what level of inaccuracy can the company tolerate in a given use case, and who is accountable for checking the output before action is taken? Human oversight has become one of those phrases everybody likes, and few define. Directors need something more disciplined. When is review mandatory? What does a meaningful review look like? What evidence shows that the reviewer is not simply rubber-stamping machine output?

Data and Model |Dependency. What data is being used? Who owns it? Who has the right to it? How current is it? Are third-party vendors changing capabilities under existing contracts? Is the company becoming dependent on systems it does not fully understand or cannot easily audit? Boards should not need to know how the engine works, but they absolutely need to know whether the company is driving a car with uncertain brakes.

Incident Tolerance and Escalation. What types of AI failures must be reported to senior leadership or the board? A hallucinated internal memo may be embarrassing. A flawed AI-assisted hiring screen or customer communication may be far more serious. The board should ensure management has defined materiality thresholds before an incident occurs, not after the headlines begin.

The CCO’s Role in Shaping the Conversation

This is where compliance officers can be enormously helpful.

The CCO is often the person in the enterprise most experienced at turning abstract risk into operating discipline. Compliance knows how to frame risk-based governance. It knows how to create escalation structures, policy frameworks, investigations protocols, and oversight dashboards. It knows that culture and control design matter just as much as rules. Here are four ways to do so.

  1. A CCO can help management develop a tiered inventory of AI use cases. This is essential. Boards cannot discuss appetite in the abstract. They need to see the map. Which uses are low risk? Which are medium? Which are high? Which are prohibited absent specific approval?
  2. Compliance can help translate legal, ethical, and operational concerns into board-level language. Directors do not need a seminar on neural networks. They need clear framing around consequences, control points, accountabilities, and thresholds.
  3. A CCO can help build governance around human review, documentation, and escalation. If the company says a human is responsible, compliance can help test whether that responsibility is real, documented, and operational.
  4. Compliance can keep the conversation grounded in how people actually behave. Employees will choose convenience. Business teams will move quickly. Vendors will market aggressively. Managers may trust the generated output more than they should. A good compliance officer knows that policy must be built for actual human behavior, not ideal behavior.

Compliance as Risk Mitigation and Business Enablement

One of the enduring frustrations in compliance is that governance is often viewed as a speed bump until something goes wrong. AI gives us another chance to make the larger point. Governance does not slow innovation. Bad governance slows innovation by causing rework, distrust, remediation, and public embarrassment.

A well-defined AI risk appetite does the opposite. It gives the business clarity. It tells innovation teams where they can move quickly and where they must slow down. It helps procurement negotiate the right terms. It helps managers know when to escalate. It helps employees understand when they may rely on AI and when they must verify it. Most importantly, it gives the board a strategic rather than reactive basis for oversight.

That is compliance at its best. Not Dr. No, from the Land of “no,” but the function that makes responsible growth possible.

Final Thoughts

Boards need not fear AI. But they do need to govern it. And governance begins with clarity about appetite. If your board has discussed an AI opportunity but not AI tolerance, it has only had half the conversation. If your company has adopted tools but has not defined acceptable levels of error, autonomy, dependency, and oversight, it is operating on hope. Hope, as every compliance professional knows, is not a strategy and certainly not a control.

Here are the questions I would leave you with. Has your board defined what level of AI-driven decision risk it is willing to accept? Can management explain how that appetite changes across low-risk and high-risk use cases? And can your compliance function show, with evidence, whether the company is operating inside those lines? If the answer is no, then the conversation boards may be the most important AI conversation of all.

Categories
AI Today in 5

AI Today in 5: March 25, 2026, The AI Risk Handbook Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Why your AI factory will fail without compliance and security. (Forbes)
  2. Amazon introduces agentic AI for healthcare. (AHA)
  3. Cisco announces security tools for AI agents. (Yahoo! Finance)
  4. New regulatory mandates for finance risk assessments. (FinTechGlobal)
  5. AI risk handbook for finance. (FinTechGlobal)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.