Categories
AI Today in 5

AI Today in 5: September 22, 2025, The Chaos of Consent Episode

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI, so start your day, sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5, all from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest related to AI.

Top AI stories include:

  • JFrog advances investment compliance. (Simply Wall St)
  • Using AI to navigate consent. (MarTech)
  • Making risk management a competitive advantage. (KPMG)
  • Using AI for cybersecurity. (IBM)
  • The AI race is like the Space Race. (Bloomberg)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
Blog

Untangling Fraud, Waste, and Abuse: A Primer for the Compliance Professional

In the world of compliance, few phrases are tossed around with as much frequency and often as little precision as “fraud, waste, and abuse.” In the government sector, this triad is well-defined. Federal and state agencies spend billions each year tracking, auditing, and enforcing rules to combat it. But in the private sector, the phrase is no less relevant. Whether you are managing a global compliance program, overseeing internal controls, or leading an ethics initiative, fraud, Waste, and abuse can quietly erode corporate value, undermine trust, and invite unwanted scrutiny from regulators, auditors, and stakeholders.

Yet too many compliance professionals lump these terms together, failing to appreciate the important differences between them. Fraud, Waste, and abuse may sometimes overlap in practice, but they require distinct prevention strategies, tailored controls, and cultural messaging. Today, we begin a multipart blog post series to unpack what each of these terms means for the private sector and explore how your organization can fight against their scourge.

Fraud: The Deliberate Deception

Fraud is the most familiar of the three. It is intentional deception or misrepresentation made with the knowledge that it will result in an unauthorized benefit. In the corporate world, fraud is not limited to elaborate Ponzi schemes or headline-grabbing accounting scandals; it often hides in plain sight.

Examples from the private sector include:

  • Financial statement fraud. Inflating revenue or concealing liabilities to present a healthier picture of the business. Enron, WorldCom, and Wirecard are stark reminders.
  • Procurement fraud. Kickbacks from suppliers, false invoices, or bid-rigging. A procurement officer who colludes with a vendor to inflate prices is not just wasting company money; they are stealing it.
  • Expense reimbursement fraud. Employees are submitting falsified receipts or double-billing travel expenses. What starts as “a little padding” quickly snowballs into a systemic problem.

Fraud is deliberate, targeted, and harmful by design. It requires intent to deceive. For this reason, fraud often falls under the purview of regulators and prosecutors, resulting in criminal charges, civil penalties, and severe reputational damage.

Waste: The Silent Erosion of Value

Waste, by contrast, is rarely intentional. It refers to the careless or unnecessary use of resources, leading to inefficiency and loss of value. Waste does not always involve dishonesty; usually, it is more often a byproduct of poor management, weak oversight, or cultural indifference.

Examples from the private sector include:

  • Operational inefficiencies. A manufacturing line that continues to use outdated machinery, consuming more energy than modern alternatives. However, it can also encompass basic corporate functions, such as failing to timely service vehicles and other large pieces of equipment until they break down.
  • Bloated corporate travel. Business units booked last-minute flights in premium class when lower-cost options were available with better planning.
  • Technology sprawl. Companies are paying for redundant software licenses because IT and business units fail to coordinate their procurement.

Waste drains profitability. Unlike fraud, it may not land your employees in court, but over time, it corrodes competitiveness, frustrates shareholders, and damages morale. For the compliance professional, Waste is tricky. Because it often lacks intent, it falls into a gray zone between compliance, internal audit, and operations. But leaving Waste unchecked is an abdication of governance responsibility. And of course, it can be very costly.

Abuse: The Exploitation of Loopholes

Abuse sits somewhere between fraud and Waste. It involves the improper or excessive use of resources or authority, but without a clear intent to defraud. Abuse may not violate the letter of company policy, but it often violates its spirit.

Examples from the private sector include:

  • Excessive executive perks. A senior leader insists on flying private, despite company policy allowing business class.
  • Overtime gaming. Employees schedule themselves in ways that maximize overtime pay, even when workloads do not justify it.
  • Supplier favoritism. A manager repeatedly awards contracts to a personal acquaintance without competitive bidding, even if the price is technically “market.”

Abuse thrives in cultures of entitlement and weak oversight. It often signals to employees that procurement rules are flexible or merely suggestions, undermining trust in leadership. Regulators may not always prosecute abuse, but investors, boards, and employees will notice.

Five Key Takeaways for the Compliance Professional

1. Know the Difference

Fraud, Waste, and abuse are often lumped together, but they are distinct risks with different causes and remedies. Fraud is intentional deception designed to enrich the perpetrator at the company’s expense. Waste is careless or inefficient use of resources, often unintentional but just as costly. Abuse sits in the middle ground, exploiting loopholes, gray areas, or authority for personal gain. If you treat these three risks as interchangeable, your controls will be blunt instruments. The savvy compliance professional tailors training, monitoring, and cultural messaging to each risk, ensuring prevention efforts are both precise and effective.

2. Fraud Is Not the Only Threat

Compliance programs often emphasize fraud because it creates legal exposure, attracts regulatory scrutiny, and can lead to criminal liability. Yet fraud is not the only drain on corporate value. Waste can hollow out profitability year after year through inefficiency and mismanagement. Abuse corrodes employee trust, culture, and morale, even when it does not cross a legal line. Boards and shareholders increasingly look beyond compliance “check the box” fraud controls. They demand stewardship, efficiency, and accountability across the enterprise. Expanding your program’s scope to tackle Waste and abuse demonstrates leadership, adds measurable business value, and positions compliance as a strategic partner.

3. Culture Is the Battleground for Abuse

You can design airtight policies and sophisticated controls to prevent fraud or reduce Waste, but abuse is more insidious. It thrives in cultures of entitlement, favoritism, and “wink-and-nod” exceptions to the rules. Abuse may not always break laws or policies, but it violates fairness and damages trust. That is why culture is the key battleground. Compliance leaders must set clear expectations, train managers to model ethical behavior, and empower employees to speak up when necessary. When entitlement and corner-cutting are tolerated, abuse spreads. When accountability, transparency, and stewardship are celebrated, abuse withers. Culture, not checklists, is the ultimate safeguard.

4. Data Is Your Ally

The complexity of modern business means fraud, Waste, and abuse can hide in plain sight. Data analytics provides compliance professionals with the tools to detect risks early. Anomalies in travel expenses may uncover not only fraudulent reimbursement but also systemic Waste in last-minute bookings or abusive upgrades. Procurement analytics can expose inflated invoices, duplicate payments, or favoritism in the vendor selection process. The key is not just gathering data but integrating it across compliance, audit, and finance systems. With proper dashboards and regular reviews, data becomes a proactive ally, identifying red flags before they metastasize into scandals that damage reputation and value.

5. Build Cross-Functional Coalitions

Fraud, Waste, and abuse do not respect organizational silos. They intersect with compliance, audit, HR, procurement, finance, and operations. If each function fights its own battles in isolation, risks will inevitably slip through the cracks. The compliance professional is uniquely positioned to serve as the connector, building coalitions that share data, align incentives, and coordinate responses. For example, a fraud indicator spotted by finance may also highlight Waste tracked by operations. HR may uncover abusive practices that compliance can remediate with policy changes. When functions collaborate, blind spots shrink, accountability rises, and the entire organization becomes more resilient.

Stewardship as Compliance

Fraud, Waste, and abuse may manifest differently, but together they represent a continuum of risks that can erode profitability, corrode culture, and undermine trust in leadership. For the compliance professional, the way forward lies in anchoring your program on five core pillars.

First, you need to understand the difference. Fraud, Waste, and abuse require distinct approaches, and treating them as interchangeable dulls your controls. Second, remember that fraud is not the only threat. Waste and abuse, while less visible, can be just as damaging to shareholders and boards who care about stewardship as much as compliance. Third, recognize that culture is the battleground for abuse. Without accountability and transparency embedded in daily operations, policies and controls are powerless against entitlement and favoritism. Fourth, leverage the fact that data is your ally. Analytics reveal patterns across all three categories, allowing you to act before small issues metastasize. Finally, build cross-functional coalitions. Fraud, Waste, and abuse cut across silos, and only through collaboration can you close the gaps.

Taken together, these five strategies form more than a compliance toolkit; they create a holistic framework for corporate stewardship. By clearly distinguishing risks, broadening your scope, reinforcing your culture, embracing data, and building coalitions, you elevate compliance from a defensive shield to a proactive value driver.

The organizations that thrive in today’s demanding environment will be those that go beyond chasing fraud and instead build resilient, data-driven, and culture-anchored programs to fight fraud, Waste, and abuse in all their forms. That is the mandate for the modern compliance professional.

Join us tomorrow as we explore how your anti-corruption compliance program can help your company combat fraud, Waste, and abuse.

Categories
Blog

Speed as a Compliance Decision: Lessons from Amazon’s Andy Jassy

When Andy Jassy succeeded Jeff Bezos as CEO of Amazon in 2021, many questioned whether the company could maintain its legendary momentum. Four years later, Jassy has not only sustained but also accelerated growth, adding more than $230 billion in revenue, expanding AI initiatives, and reinventing the management culture of one of the world’s most complex enterprises. That is why I was intrigued by an article in the Harvard Business Review (HBR) entitled, Speed Is a Leadership Decision,” where reporter Adi Ignatius interviewed Andy Jassy.

For compliance professionals, Jassy’s insights about speed, risk, culture, and innovation offer timely lessons. Too often, compliance leaders fall back on the excuse that “we’re too big, too regulated, too constrained to move quickly.” Jassy flips that script: speed, he insists, is a leadership decision. And the same is true for compliance.

Today, we look at five key lessons compliance professionals can draw from Jassy’s leadership playbook.

1. Speed Is a Leadership Decision

Jassy bluntly states that “speed disproportionately matters in every business at every time”. He challenges leaders to stop accepting bureaucracy and regulation as excuses. Instead, leaders must actively identify and remove barriers, empowering teams to act with urgency.

For compliance professionals, the lesson is clear: do not let the weight of regulations, policies, or oversight structures become a drag on effectiveness. Yes, compliance requires controls, documentation, and approvals, but speed is also important. Think of third-party due diligence reviews, hotline triage, or incident investigations. When compliance moves slowly, it signals indifference or ineffectiveness, and risks fester.

The decision to prioritize speed, backed by streamlined processes, real-time monitoring, and empowered teams, can transform compliance from a bureaucratic bottleneck into a proactive partner to the business.

2. Risk-Taking and Failure Are Essential to Innovation

Jassy observes that as companies grow, they tend to become risk-averse. Achievement-oriented professionals “play not to lose” rather than take chances. He emphasizes that the only way to build something truly unique is to take risks, make mistakes, and learn from them. Compliance teams face this challenge daily. The instinct is to avoid risk entirely, to say “no” rather than take a chance. But compliance innovation, whether adopting AI for monitoring, piloting new training formats, or embedding compliance into business processes, requires taking calculated risks. This means that risk management strategies must be implemented, monitored, and updated as necessary.

Failure in compliance is not about missing a regulatory requirement. It is about learning that a new process does not resonate with employees, or a monitoring tool generates too many false positives. Leaders should create safe zones for experimentation. If you never fail, you are not pushing hard enough. Compliance innovation must be iterative, and tolerance for small, recoverable failures is the price of true progress.

3. Flattening Bureaucracy Fuels Accountability

Jassy highlights Amazon’s initiative to flatten its organization and empower individual contributors. By increasing the ratio of builders to managers, reducing layers of decision-making, and encouraging employees to own “two-way-door decisions”. Those are choices that can easily be reversed. With this strategy, Amazon streamlined processes and accelerated innovation.

Compliance functions are often drowning in pre-meetings and approval chains. A compliance officer identifies a risk, drafts a recommendation, and waits while three levels of committees review it. Meanwhile, the risk festers. The compliance profession should adopt Jassy’s model: empower frontline employees to make two-way decisions in real-time. For example, a compliance manager in Brazil should have the authority to pause a suspicious vendor engagement without waiting for headquarters. Flattening decision-making structures creates accountability, agility, and credibility. Compliance must be a builder’s mindset: see the problem, fix the problem, move forward.

4. Culture Must Be Reinvented Continuously

“Culture is not our birthright,” Jassy warns. As companies scale, their culture stretches and must be deliberately reinforced. At Amazon, this means reasserting ownership, accountability, and a customer-centric approach, even as new layers of management emerge. For compliance professionals, this is a powerful reminder: culture is not static. A “speak-up” culture may flourish in year one and decay by year five if it isn’t nurtured. New geographies, acquisitions, and technologies stretch corporate culture in unpredictable ways.

The compliance function must continuously assess cultural health: are employees still raising concerns? Do managers still model ethical behavior? Are incentive structures still aligned with compliance values? A strong compliance culture requires constant reinvention: new training, new channels, new metrics; so that employees see it as living and evolving, not stale or perfunctory.

5. AI, Innovation, and Responsibility Must Go Hand in Hand

Jassy views AI as the biggest transformation since the internet, with the power to reinvent every customer experience. He emphasizes that progress is inevitable, so leaders must focus on using AI responsibly and productively.

Compliance professionals face the same dual imperative. On the one hand, AI tools, such as automated transaction monitoring, predictive analytics, and natural language chatbots, can make compliance faster, smarter, and more effective. On the other hand, AI introduces new risks, including bias, opacity, privacy breaches, and increased regulatory scrutiny.

The compliance leader’s role is not to resist AI but to guide its responsible adoption. Establish AI governance frameworks. Ensure transparency and explainability. Audit data inputs and outputs. Partner with business units to embed compliance guardrails into AI development. If compliance can keep pace with AI’s speed while safeguarding ethics, it will become indispensable to the business.

Compliance at the Speed of Leadership

Andy Jassy’s mantra, “speed is a leadership decision,” rings true far beyond Amazon. For compliance professionals, it reframes the mission. Compliance does not require slow responses, being bureaucratic, or being risk-averse. (Always remember, you do not have brakes on a car to drive slowly; instead, you have brakes on a car to drive fast.) Leaders can choose speed by empowering their teams, flattening the decision-making process, fostering a culture of ownership, tolerating smart failures, and embracing technology responsibly.

The stakes are high. Compliance must move at the same speed as the business, not the other way around. Regulators expect swift detection and remediation. Employees expect rapid answers to ethics and compliance questions. Boards expect real-time risk visibility. Compliance that lags will be seen as irrelevant or ineffective.

The lesson from Amazon’s Jassy is that compliance speed is not about cutting corners. It is about clarity of leadership, empowerment of people, and continuous cultural reinvention. In an era of accelerating technology and mounting risk, compliance professionals must embrace speed as a core leadership choice.

Categories
Innovation in Compliance

Innovation in Compliance – Gaurav Kapoor on Risk Management and the Role of AI in GRC

Innovation comes in many areas, and compliance professionals need to be ready for it and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, Tom Fox interviews Gaurav Kapoor, Vice Chairman, Co-Founder and Board Member of MetricStream, discussing his extensive professional background, from co-founding MetricStream to his current focus on customer intimacy amid AI market disruptions.

Kapoor delves into the evolving landscape of risk management, emphasizing the importance of midyear reviews and integration of various risk themes like operational risk, audit compliance, and cybersecurity. He elaborates on the role of AI in GRC, stating how generative and agent AI can streamline compliance processes and enhance risk management strategies. The conversation also touches on the increasing significance of cybersecurity, geopolitical instability, and climate impact on risk assessment. Kapoor highlights the shift from compliance to a more resilient and risk-aware culture within organizations.

Key highlights:

  • The Importance of July in Risk Management
  • AI’s Role in GRC
  • Emerging Risks and AI Applications
  • Counseling Boards on Risk Management
  • Top Concerns for the Second Half of 2025
  • Evolving Role of Compliance and Risk Officers

Resources:

MetricStream Website and on LinkedIn

Gaurav Kapoor on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI Today in 5

AI Today in 5: August 13, 2025, The Beware the EU AI Act Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

For more information on the use of AI in compliance programs, see Tom Fox’s new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
AI Today in 5

AI Today in 5: August 5, 2025, The AI at the SEC Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI. 

 

For more information on the use of AI in Compliance programs, Tom Fox’s new book is Upping Your Game. You can purchase a copy of the book on ⁠Amazon.com.

Categories
Blog

10 Prompts for Compliance

A colleague recently asked me to provide them with some prompts they could use to start their journey using AgenticAI, machine learning, and natural language processing. They also wanted an explanation of why these prompts would be helpful. I thought about it and came up with a list of the Top 10 prompts compliance professionals frequently use or need to use, along with a detailed explanation of their critical importance. I have added an answer for each prompt. To obtain these prompts, I began with the following query to ChatGPT. ‘You are a compliance professional at a US corporation. Please list the top 10 prompts I can use to start my journey of using AI to improve a corporate compliance program.’

1. “Identify emerging compliance risks in our industry.”

Explanation:

This prompt is foundational for proactive compliance management. Compliance professionals must continuously scan the regulatory landscape, industry developments, technology advancements, and geopolitical shifts to detect emerging risks. Understanding new threats before they fully materialize allows compliance teams to take proactive steps, adapt policies, provide training, and mitigate potential issues before they result in violations or enforcement actions. Moreover, this prompt promotes a forward-looking compliance program, which aligns with regulatory expectations such as those outlined by the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), making this a critical practice for effective compliance professionals.

2. “Summarize recent regulatory updates relevant to our business operations.”

Explanation:

Compliance landscapes are dynamic, with rules frequently evolving. This prompt ensures compliance professionals remain fully informed about current regulatory changes that directly impact their company’s operations. Effective compliance teams leverage these summaries to update policies, provide timely training, and communicate clearly to management and employees. Staying abreast of regulatory developments also positions compliance professionals to strategically advise senior leadership on business decisions, mitigate regulatory risk, and avoid costly penalties or enforcement actions resulting from non-compliance or outdated practices.

3. “Provide best practices for conducting a thorough compliance risk assessment.”

Explanation:

Risk assessment is the cornerstone of an effective compliance program, as emphasized by regulatory guidelines from bodies as diverse as the DOJ and COSO. This prompt enables compliance professionals to leverage proven methodologies, frameworks, and standards to identify, prioritize, and address key risk areas systematically. An effective compliance risk assessment not only satisfies regulatory expectations but also informs strategic allocation of compliance resources. Moreover, a robust risk assessment is foundational for proactive management, policy development, and training, enhancing an organization’s overall compliance posture and reducing potential liabilities.

4. “Generate scenario-based training examples on ethical dilemmas and compliance issues.”

Explanation:

Training remains a critical element in a strong compliance program. Scenario-based prompts help compliance professionals create realistic, relatable training modules that resonate with employees. Ethical dilemmas and practical compliance scenarios allow employees to practice decision-making, reflect upon corporate values, and internalize compliance expectations. Such scenario-based training significantly improves retention, awareness, and adherence to corporate standards. Additionally, regulators frequently examine training effectiveness during compliance reviews, and scenario-based training demonstrates a genuine commitment to fostering a culture of compliance.

5. “Draft a communication plan for implementing significant compliance program changes.”

Explanation:

Clear, structured communication is essential when changes occur in compliance programs, procedures, or policies. This prompt helps compliance professionals ensure they address critical points transparently and consistently to all stakeholders. A thoughtful communication plan ensures key messages are effectively conveyed, minimizes confusion, and reinforces the seriousness of compliance updates. Effective communication plans also document a defensible record of the company’s efforts to implement and socialize compliance changes, satisfying regulatory expectations for robust internal communication, transparency, and awareness across the organization.

6. “Suggest steps for performing effective third-party due diligence and monitoring.”

Explanation:

Third-party relationships pose significant compliance and reputational risks, especially concerning bribery, corruption, fraud, and sanctions violations. This prompt assists compliance professionals in defining robust due diligence and monitoring procedures aligned with international best practices and regulatory expectations such as those in the FCPA and the UK Bribery Act. Effective due diligence steps allow companies to proactively identify potential red flags, implement controls, and continuously monitor third-party activities. This approach helps mitigate liability from third-party misconduct and demonstrates regulatory rigor and commitment to compliance oversight.

7. “Explain key lessons learned from recent enforcement actions relevant to our sector.”

Explanation:

Learning from regulatory enforcement actions is pivotal in compliance. This prompt ensures compliance professionals leverage real-world cases to strengthen their compliance programs. By analyzing enforcement trends and critical lessons, compliance officers identify and rectify gaps before they lead to serious issues. Regulators often expect companies to adjust their compliance efforts based on industry-specific enforcement activity, and proactively analyzing recent cases underscores an organization’s commitment to continuous improvement and diligent compliance management. This practice helps mitigate risk, avoid similar pitfalls, and demonstrate compliance program effectiveness.

8. “Guide developing or updating a whistleblower policy and protection procedures.”

Explanation:

Whistleblower protection is not just regulatory guidance; it’s often legally required. This prompt helps compliance professionals craft robust whistleblower policies to encourage employees to report misconduct safely without fear of retaliation. An effective whistleblower program builds trust, integrity, and accountability within an organization. Regulatory bodies, such as the SEC and DOJ, evaluate whistleblower programs as indicators of a mature compliance culture. Hence, this prompt helps compliance teams align policy with best practices and legal mandates, protecting both whistleblowers and the company from serious compliance violations and reputational harm.

9. “Outline a structured root cause analysis process for compliance failures.”

Explanation:

Conducting a root cause analysis (RCA) is essential for compliance professionals to identify underlying factors contributing to compliance failures. This prompt provides compliance officers with a structured methodology to systematically evaluate incidents, prevent recurrence, and make informed decisions on corrective measures. Regulators, including the DOJ, increasingly require companies to demonstrate a systematic RCA process following a compliance breach. Utilizing RCA strengthens an organization’s ability to enhance controls, improve policies, refine training, and demonstrate commitment to compliance effectiveness, thus enhancing credibility with regulators.

10. “Draft a checklist for auditing and monitoring compliance program effectiveness.”

Explanation:

Auditing and monitoring are fundamental elements of a strong compliance program. This prompt helps compliance professionals systematically evaluate their programs’ design, implementation, and ongoing performance. Detailed checklists facilitate consistent reviews, identify vulnerabilities, track remediation progress, and ensure continuous improvement. Regulators regularly review auditing and monitoring processes as evidence of a compliance program’s maturity. Thus, having articulated auditing checklists underscores a proactive approach to maintaining compliance program effectiveness and regulatory readiness and ensures swift corrective actions whenever issues arise.

Conclusion:

These top 10 prompts embody essential practices in modern compliance management. Leveraging these prompts enables compliance professionals to proactively manage risk, remain informed, educate effectively, communicate clearly, and demonstrate regulatory rigor. They ensure that organizations maintain robust compliance programs that protect the business and sustain an ethical, accountable, and risk-aware culture.

Categories
Blog

Chasing Shadows: Five Compliance Lessons from the Hound of the Baskervilles

The Hound of the Baskervilles,” penned by Sir Arthur Conan Doyle, is not only the most famous Sherlock Holmes story and a riveting detective tale but also presents timeless lessons in compliance applicable to corporate governance and risk management. Through its intricate plot and detailed character portrayals, the novel underscores several critical principles that every compliance professional should heed.

The story itself blends mystery, suspense, and supernatural elements. Sherlock Holmes and Dr. Watson investigate Sir Charles Baskerville’s mysterious death on the eerie Devonshire moors, connected to a legendary demonic hound curse. Holmes sends Watson with his heir, Sir Henry Baskerville, to the estate, where suspicious servants, an escaped convict, and peculiar neighbors—the Stapletons—heighten tensions. Watson’s observations reveal Jack Stapleton’s instability and jealousy over Sir Henry’s attention to Beryl Stapleton. Secretly investigating, Holmes identifies Stapleton as a Baskerville relative plotting Sir Henry’s death to claim the inheritance. Stapleton’s deception includes staging supernatural events to exploit local superstition. In the climax, Stapleton releases a phosphorus-painted hound to kill Sir Henry, but Holmes and Watson intervene, killing the beast. Stapleton flees, presumed dead in the Grimpen Mire. Holmes’s rational deductions triumph, dismissing supernatural fears and reinforcing logic and reason. Watson’s meticulous work is instrumental, showcasing his courage and skill. The novel concludes by affirming reason over superstition, demonstrating the dangers of irrational fear.

Here are five key compliance lessons derived from specific events within this classic tale.

Lesson 1: Avoiding Complacency in Risk Assessment

The initial approach to the mystery of Sir Charles Baskerville’s death illustrates a critical lesson in risk assessment: the importance of maintaining vigilance. Dr. Mortimer initially attributes the death to supernatural causes, influenced by local legends of a family curse. Sherlock Holmes immediately challenges this complacency, emphasizing the need for rational investigation over reliance on myths or unexamined assumptions. Holmes insists on examining evidence logically rather than accepting straightforward, sensational explanations.

Compliance professionals must similarly avoid complacency. It is easy for an organization to rely on historical assumptions or superficial risk assessments. However, genuine vigilance requires continuous questioning and reevaluation of all potential threats. By regularly revisiting risk assessments and remaining skeptical of conventional wisdom, compliance teams can better anticipate, mitigate, and respond to potential compliance failures before they escalate into significant issues.

Lesson 2: Effective Use of Data and Evidence

Throughout “The Hound of the Baskervilles,” Holmes’s meticulous use of evidence exemplifies the necessity of thorough documentation and analysis in achieving effective compliance outcomes. One key example is Holmes’s careful examination of Sir Henry Baskerville’s stolen boots. Holmes correctly deduces that the shoes were stolen to provide the hound with Sir Henry’s scent. This attention to minute detail and systematic analysis underscores the importance of robust documentation and record-keeping.

Compliance professionals should similarly prioritize precise data collection, rigorous documentation, and evidence-based decision-making. Proper documentation provides transparency, facilitates effective audits, and ensures clarity when addressing compliance issues or regulatory inquiries. By fostering a culture where data-driven decision-making is standard practice, organizations can strengthen their compliance programs and more effectively prevent violations.

Lesson 3: Maintaining Independence and Objectivity

A pivotal moment in the novel occurs when Holmes secretly arrives on the moor, independent of Watson’s investigation. Holmes understands the importance of maintaining independence to gather unbiased information. By conducting a parallel investigation that is free from local biases and personal relationships, Holmes preserves objectivity and ultimately identifies the true culprit, Jack Stapleton.

For compliance professionals, maintaining independence and objectivity is equally vital. Conflicts of interest can obscure judgment and compromise investigations. Compliance officers must be empowered to act independently, free from undue influence, to ensure the integrity of their findings and recommendations. Establishing clear reporting structures and supporting unbiased investigative procedures can significantly enhance an organization’s overall compliance effectiveness.

Lesson 4: Transparent Communication and Reporting

Transparency is repeatedly highlighted as essential throughout Conan Doyle’s narrative. Watson’s regular and detailed correspondence with Holmes exemplifies clear, transparent reporting. Watson meticulously records his observations, suspicions, and interactions, ensuring Holmes remains informed of developments in real time. This ongoing communication proves instrumental in Holmes’s eventual successful intervention.

In the realm of corporate compliance, transparent communication and reporting are equally critical. Employees must feel encouraged and supported in reporting suspicious activities or compliance concerns without fear of retaliation or retribution. Implementing precise and accessible reporting mechanisms, while ensuring open lines of communication, fosters a culture that is compliant-friendly. This transparency enables compliance teams to detect and address issues promptly, thereby reducing organizational exposure to risk and promoting an ethical business environment.

Lesson 5: Importance of Culture and Ethics

The actions and eventual downfall of Jack Stapleton underscore a profound lesson in compliance regarding organizational culture and ethics. Stapleton manipulates local fears and exploits the legend of the supernatural hound to facilitate his criminal plans. His unethical behavior, driven by greed and a disregard for human life, ultimately led to his ruin.

Organizations must prioritize building and maintaining a strong ethical culture. Leadership should exemplify ethical behavior, clearly communicate expectations, and swiftly address unethical actions. Regular training and communication regarding ethical standards reinforce an organization’s values and expectations. By cultivating a robust ethical culture, organizations not only reduce the likelihood of compliance violations but also enhance their reputation and long-term sustainability.

The Hound of the Baskervilles” offers rich insights for compliance professionals. Avoiding complacency, emphasizing evidence-based decision-making, maintaining independence, ensuring transparent communication, and fostering a robust ethical culture are foundational principles that are vividly highlighted throughout Conan Doyle’s timeless narrative. These lessons, illustrated through specific events and character decisions within the story, remain deeply relevant in guiding modern corporate compliance practices.

Categories
#RiskNYC Speaker Series

#Risk New York Speaker Series- Upping Your Game with Tom Fox

Join myself and hundreds of other GRC professionals in the city that never sleeps, New York City on July 9 & 10 for one of the top conferences around #Risk New York. current US landscape – shaped by evolving policies, rapid AI advancements, and shifting global dynamics – demands adaptive strategies and cross-functional collaboration.

At #RISK New York you will master the New Regulatory Reality by Getting ahead of US regulatory shifts and their impact. Conquer AI & Tech Risk by Safeguarding your organization in an AI-driven world and understand the implications of major tech investments. Navigate Financial & Crypto Volatility by Protecting assets and explore solutions in a dynamic market. Strengthen Your GRC Framework by Leverage governance, risk, and compliance for strategic advantage. Protect Digital Trust by Addressing challenges in cybersecurity, data privacy, and combating misinformation. All while meeting

In this episode of the Risk New York podcast series, Tom Fox introduces the upcoming Risk New York Conference, scheduled for July 9-10 at Fordham Law School. The conference, hosted by GRC World Forums, will focus on various aspects of risk management, including AI, tech risk, financial and crypto risk, and GRC frameworks. Tom discusses his keynote based on his book ‘Upping the Game’ and highlights key speakers and exhibitors, including Robert Clark from Howard University, Bill Coffin and Erica Alburn from Ecosphere, and Michael Rasmussen, known as the father of GRC. The episode emphasizes the significance of the conference and provides information on discounted tickets and other details available in the show notes.

Resources

#Risk Conference Series

#RiskNYC-Tickets and Information

Categories
Trekking Through Compliance

Trekking Through Compliance – Episode 8 – Miri

In this episode of Trekking Through Compliance, we consider the episode Miri, which aired on October 27, 1966, Star Date 2713.5. In this episode of Trekking Through Compliance, we explore one of the eeriest and most profound cautionary tales in the Star Trek canon: “Miri.” When the crew responds to a distress signal from a planet that’s an exact duplicate of Earth, they find a society ravaged by a failed experiment in human longevity. Only children remain, while the adults, the “grups,” have all died from a virulent disease.

This haunting story is not simply science fiction. It is a case study of what happens when risk management is treated as an afterthought. We draw parallels between the biohazard breakdowns on the planet and the kinds of failures that modern compliance officers must guard against, whether in public health readiness, supply chain risk, or workforce welfare.

Episode Summary

A disfigured man attacks a landing party, who die after Kirk strikes him. They discover a preadolescent, Miri, who ran away from them because “grups” kill and maim children before dying. She and her friends are “onlies,” the only ones left. The distress call is traced to an automated signal. The landing party, except for Spock, notices purple lesions on their bodies; Miri tells them that these are the first signs of the disease, and they will soon develop into the same condition as the other adults. When the disease begins, its victims have seven days to live. Although Spock is immune, he considers himself a carrier who could infect the Enterprise if he returns.

Back on the Enterprise, after vaccinating everyone and leaving the children in the care of a medical team, Kirk sends for teachers and advisers to help the children improve their lives.

Key highlights:

1. Disaster Preparedness—A Cure Without a Contingency Plan

🖖Illustrated by: The civilization’s experiment to extend life, which instead wipes out all adults.

This central failure underscores the risks associated with scientific advancement that lacks proper risk assessment. The developers had no fallback, no regulatory oversight, and no crisis management framework in place. For compliance professionals, this serves as a reminder that innovation must be paired with effective scenario planning and disaster recovery protocols.

2. Environmental and Public Health Compliance—Invisible Risks Become Existential Threats

🖖Illustrated by: The crew’s infection with the disease upon beaming down, with lesions appearing days later.

This serves as a metaphor for health and safety non-compliance. Enterprises must be vigilant about how workplace conditions, unseen hazards, and biological risks can impact staff and operations. Proactive monitoring and rapid-response mechanisms are essential components of any risk management strategy.

3. Data Governance and Early Warning Systems—Responding Too Late

🖖Illustrated by: The automated distress signal continued even though no adult survivors remained.

The signal was still active, but no one was listening until it was far too late. In modern organizations, this is equivalent to ignoring audit logs, internal control alerts, or whistleblower reports that go unread. A culture of attentiveness to data and signals is crucial to catching issues before they cascade.

4. Supply Chain Risk—Critical Resource Shortages in the Field

🖖Illustrated by: The crew’s struggle to develop a cure with limited time, no labs, and deteriorating conditions.

Kirk and McCoy were caught without adequate resources. This scenario mirrors the real-world risks companies face when they lack redundancy in their supply chains, fail to conduct thorough vendor audits, or fail to plan for logistical disruptions. A robust compliance framework includes stress-testing the supply chain for resilience under duress.

Employee Welfare and Isolation—Psychological and Ethical Concerns in Hazard Zones

🖖Illustrated by: Spock’s decision not to return to the Enterprise due to the risk of contamination.

Spock’s sacrifice is a model of ethical risk containment. In any risk environment, whether it is a pandemic, data breach, or financial misconduct, companies must empower employees to make ethically sound decisions while providing mental health support for those isolated by crisis response roles.

Final Starlog Reflections

Miri is a chilling illustration of what happens when ambition outpaces ethics and planning. The children left behind are the victims of a society that prioritizes progress over protection. For compliance professionals, this episode serves as a vivid reminder that a well-crafted compliance program is not just about preventing misconduct—it’s about preparing for the unknown.

Resources

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha