Categories
Blog

Odyssey Week: Leadership: Penelope’s Loom: Integrity Under Pressure

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Anne Hathaway was great as Penelope.

Penelope does not get enough credit. Odysseus gets the monsters, the storms, the speeches, the disguises, and the dramatic return. He gets the action scenes. Penelope gets the waiting. If the movie version made one thing clear, such an interpretation sells her short—very short.

Penelope is not simply waiting. She is governing under pressure. Opportunists surround her. The suitors have occupied her home, consumed her resources, pressured her to choose one of them, and treated uncertainty as an invitation to abuse. Odysseus is gone. Authority is contested. Telemachus is young. The house is under stress.

So Penelope does something quietly brilliant. She promises to choose a suitor after she finishes weaving a burial shroud for Laertes. By day, she weaves. By night, she unweaves. She buys time without surrendering the core issue. It is not flashy. It is not a thunderbolt. It is not a sword fight in the hall. It is disciplined patience under pressure.

That is why Penelope belongs in the leadership section of a compliance odyssey. She reminds us that integrity is not always dramatic. Sometimes it looks like refusing to sign the certification, approve the vendor, bless the transaction, release the report, close the investigation, or accept the explanation simply because everyone is tired of waiting.

The Corporate Translation

Penelope is the leader who understands that time pressure is not the same as good governance. Every organization has Penelope moments. The quarter is closing, and someone wants revenue recognized now. A third party has not cleared diligence, but the business sponsor says the relationship is too important to delay. A certification is due, but the control owner is not comfortable with the evidence. A board report needs to go out, but the investigation findings are still incomplete. A product launch is scheduled, but privacy, security, or regulatory concerns remain unresolved. A customer is demanding speed. A senior executive wants closure. The team is exhausted.

And then someone says the magic words: “Can we just move forward?” That is the sound of the loom beginning to tighten. Penelope’s lesson is not that delay is always virtuous. It is not. Delay can be passive, political, cowardly, or evasive. But some delay is not avoidance. It is governance. The question is whether the organization can tell the difference.

Defensible Delay Is Not Obstruction

In compliance, delay has a bad reputation. That is why compliance is known as The Land of No, populated by Dr. No. Sometimes it is the Department of Business (Non)Development. Whatever the moniker is, this is why business leaders often hear “we need more time” as “compliance is blocking the business.” Sometimes that criticism is fair. Compliance functions can be too slow, too opaque, too academic, or too disconnected from commercial reality. A policy review that disappears into a black hole is not governance. It is bureaucracy with a ticket number.

But there is another kind of delay: defensible delay. Defensible delay has a reason. It has an owner. It has a process. It has a timeline. It identifies the unresolved risk and the information needed to make a decision. It is communicated clearly. It is proportionate to the issue. It protects the company from making a false, rushed, or poorly documented commitment.

Penelope’s loom was not random. It had a purpose. It created time when the available choices were bad. That matters in corporate life. A leader who refuses to approve a questionable vendor is not “being difficult” if the due diligence is incomplete and red flags remain unresolved. A CFO who refuses to sign a certification without adequate support is not “overly cautious.” A compliance officer who asks for more facts before closing an investigation is not “dragging things out.” A privacy officer who pauses a product launch because sensitive data controls are not ready is not “anti-innovation.” Sometimes the most ethical sentence in business is “Not yet.”

Culture Is Built in the Waiting

Corporate culture is often revealed by what happens during delay. When a leader says, “We need more information,” does the organization respect the concern? Or does it start applying pressure?

Does the business provide the missing evidence, or does it complain that Legal is slowing things down? Does management support the control owner, or quietly ask for a more “practical” answer? Does the board ask why the delay is necessary or simply demand that the issue be resolved before the next meeting? Does compliance explain the path forward or hide behind process? These moments shape culture.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a compliance program works in practice, whether senior and middle management have encouraged or discouraged compliance through their words and actions, and whether compliance personnel have sufficient authority, resources, and access to function effectively. It also asks whether employees have practical guidance and know when to seek advice.

That is Penelope’s world. Culture is not only what the company says about integrity. It is whether the company protects people who slow down a decision for the right reasons. If every delay is treated as disloyalty, employees learn to approve first and worry later. That is not agility. That is ethical surrender in business casual.

Ethical Resilience Under Pressure

Penelope is not powerful in the obvious way. She does not command an army. She does not remove the suitors by force. Her resilience is quieter. She endures pressure without surrendering judgment. That kind of resilience is essential in compliance.

Ethical resilience is the capacity to hold the line when the organization is tired, when the facts are inconvenient, when the deadline is real, and when compromise would be easier. It is the controller who insists on evidence. The manager who escalates a concern before approving the payment. The compliance officer who says the investigation is not complete. The board member who asks whether management’s optimism is supported by testing. The executive who tells the team, “We will not do this the wrong way just because the right way takes longer.”

The DOJ Justice Manual states that prosecutors should evaluate a company’s commitment to fostering a strong culture of compliance at all levels, including how the company incentivizes employee, executive, and director behavior through discipline, complaint handling, and compensation plans. That means ethical resilience cannot depend on heroic individuals. The system must support it.

People must know they will not be punished for raising legitimate concerns. Performance goals must not make ethical delay impossible. Leaders must model patience when facts matter. Governance bodies must ask for evidence, not just reassurance. Compliance must help the business move responsibly, not merely tell it to wait. Penelope’s loom works because she has discipline. A company’s compliance program works because discipline is built into the system.

What a Better Compliance Program Does

A better compliance program helps the organization make disciplined decisions under pressure. It defines which approvals require evidence. It gives control owners authority to withhold certifications when support is inadequate. It builds escalation paths for unresolved risk. It documents exceptions and unresolved issues. It trains leaders on how to respond when employees raise concerns. It tracks aging remediation items. It distinguishes between acceptable risk, unresolved risk, and ignored risk. It also makes delay visible.

If a vendor approval is paused, document the reason. If leadership cannot sign a certification, they should know what evidence is missing. If an investigation remains open, there should be a plan. If a product launch is delayed, stakeholders should understand which control or risk issue must be resolved. That is not bureaucracy. That is governance with receipts.

The Compliance Takeaway

Penelope’s loom is a lesson in ethical leadership. She shows that integrity is not always a grand public stand. Sometimes it is a disciplined refusal to be rushed into a bad decision. Sometimes it is the courage to say, “The facts are not ready.” Sometimes it is the wisdom to buy time without losing the trust of those who are waiting.

For compliance officers and business leaders, the challenge is to build organizations where prudent delay is respected and avoidance is exposed. Do not approve the questionable vendor because everyone is tired. Do not sign the certification because the calendar is unforgiving. Do not close the investigation because the subject is influential. Do not bless the transaction because the business has already promised the outcome.

Weave if you must. Unweave if you must. But know why you are doing it, tell the truth about the risk, and make sure the delay serves integrity rather than fear. That is Penelope’s gift to corporate compliance. She reminds us that sometimes the strongest leader in the room is the one patient enough not to make the wrong decision.

Final Thoughts

Taken together, the leadership lessons from The Odyssey show that corporate compliance is not sustained by slogans, heroes, or good intentions alone. The Trojan Horse reminds us that cleverness without discipline can become a control failure; Athena shows that wise counsel must have real authority, resources, and access to challenge power; and Odysseus demonstrates that even brilliant, high-performing leaders can become compliance risks when success becomes a shield from scrutiny.

Telemachus then carries the lesson into succession, showing that governance must survive the absence of the indispensable leader, with authority, control, ownership, and escalation clearly embedded into the business. Penelope completes the leadership arc by reminding us that integrity under pressure is often quiet, patient, and disciplined: the willingness to say “not yet” when facts are incomplete, risks are unresolved, and everyone else wants to move forward. Together, these stories teach that ethical leadership is not simply about winning the battle or reaching Ithaca; it is about building a compliance culture strong enough to resist shortcuts, challenge heroes, survive transitions, and hold the line when pressure is highest.

Categories
Blog

Odyssey Week: Leadership: Telemachus and the Succession Problem

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Tom Holland was great as Telemachus.

Odysseus is away. That is the fact around which Ithaca slowly comes apart. He is not merely on a long business trip. He is not delayed in a regional office because the quarterly review ran over. He has been gone for years. In his absence, the household becomes a leadership vacuum. Penelope holds the center as best she can. Telemachus grows up surrounded by uncertainty. The suitors occupy the palace, consume resources, abuse hospitality, and become more comfortable with every passing day. No one is quite sure who has authority.

And when authority is unclear, misconduct finds a chair at the table. That is Telemachus’s compliance lesson. He is not just the son waiting for his father’s return. He is the next generation of leadership inheriting a control environment weakened by absence, ambiguity, and tolerated abuse.

For modern companies, Telemachus represents the succession problem: what happens to governance, compliance, and accountability when the founder, CEO, general counsel, CFO, chief compliance officer, regional president, or other key executive is absent, distracted, replaced, or functionally unreachable? The company may still have policies. It may still have a code of conduct. It may still have approval matrices, committees, workflows, and board decks.

But the practical question remains: who owns compliance when the person everyone used to ask is no longer there?

The Corporate Translation

Every organization has formal authority and informal authority. Formal authority lives in charters, org charts, delegations of authority, board committee mandates, policy ownership tables, and job descriptions. Informal authority lives in the hallway, the inbox, the founder’s instincts, the CFO’s raised eyebrow, the general counsel’s quiet warning, and the compliance officer everyone calls before doing something adventurous.

The trouble begins when the company depends too heavily on informal authority. The founder knows where the risks are. The CFO knows which regional numbers smell funny. The general counsel knows which agents should never be used. The chief compliance officer knows which managers say all the right things and do something else entirely. The regional leader knows which customer relationships require special scrutiny.

Then one of them leaves, retires, burns out, gets promoted, goes on leave, is distracted by a transaction, or becomes unavailable during a crisis. Suddenly the company discovers that what it called “governance” was partly memory, personality, and habit. That is Ithaca without Odysseus.

Succession Is a Compliance Issue

Succession planning is often treated as a leadership development topic. That is too narrow. Succession is also a compliance issue.

When key people leave, the company can lose risk knowledge, control discipline, escalation history, and institutional memory. Open investigations may drift. Third-party concerns may be forgotten. Exceptions may remain unresolved. Sensitive approvals may migrate to people who do not understand the underlying risks. Business units may exploit the transition. Bad actors may test boundaries. The suitors always notice when the house is lightly supervised.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s program is well designed, adequately resourced and empowered, and working in practice. It also asks whether policies and procedures are integrated into day-to-day operations, who is responsible for that integration, and whether gatekeepers know what misconduct to look for and when to escalate concerns. Those are succession questions as much as compliance questions. A program that works only when one heroic executive is present does not work in practice. It works in person. That is a very different thing.

Delegation of Authority: Who Can String the Bow?

A delegation of authority matrix is not the most poetic corporate artifact. No one has ever said, “Gather the children by the fire while I tell the thrilling tale of approval thresholds and signature authority.” But delegation of authority matters. It defines who can approve payments, hire third parties, sign contracts, override controls, accept risk, access systems, certify reports, settle disputes, and bind the company.

When delegation is unclear, people improvise. And improvisation is where compliance problems breed. A regional manager approves a vendor because the usual executive is unavailable. A finance employee processes a payment because “someone senior said it was fine.” A business sponsor signs off on due diligence exceptions without understanding the risk. A system administrator grants access because the request came from an important person. A commercial leader commits the company before legal review because the customer needed an answer by Friday.

Each step may feel practical. Each may be defensible in isolation. Together, they reveal a governance weakness. Delegation of authority should answer three basic questions: who can decide, what can they decide, and under what conditions? It should also answer the question most likely to matter in a crisis: who decides when the usual decider is gone?

Control Ownership Cannot Be a Family Secret

In Ithaca, too much depends on Odysseus’s eventual return. That is not a control framework. That is a weather forecast with sandals. Modern companies make the same mistake when control ownership is unclear or overly personalized. Everyone assumes “finance owns that,” “legal handles that,” “compliance reviews that,” “the business manages that,” or “the board knows about that.” Assumption is not ownership. Control ownership should be specific. The owner should understand the risk the control addresses, how the control operates, what evidence demonstrates performance, when exceptions must be escalated, and who serves as backup.

This is especially important in operationally integrated compliance programs. The ECCP emphasizes that compliance policies and procedures should be reinforced through internal control systems and that employees with approval authority or certification responsibilities should receive guidance on what misconduct to look for and when to escalate. That means compliance cannot sit outside the business like a wise statue waiting to be consulted.

It must be embedded into approvals, workflows, reviews, certifications, access rights, vendor onboarding, financial controls, investigations, and reporting channels. Otherwise, when leadership changes, compliance becomes a scavenger hunt.

The Telemachus Problem in Business

Telemachus is not weak. He is inexperienced. That distinction matters. Many next-generation leaders inherit messy control environments. They did not create the old habits. They did not approve the questionable third parties. They did not design the incentive plan. They did not tolerate the difficult executive. They did not ignore the aging audit findings. But they inherit all of it.

That is the Telemachus problem. New leaders often face a painful choice. They can preserve the comfortable ambiguity that made the prior regime work, or they can impose clarity and risk making everyone uncomfortable. Compliance should help them choose clarity.

A new leader should ask, “What are the top compliance risks in this business?” Which controls depend on specific individuals? Which approvals have weak backup coverage? Which investigations or remediation items are open? Which third parties are high risk? Which exceptions have been granted? Which business units have recurring audit findings? Which employees are afraid to speak up? Which senior people are treated as untouchable?

Those questions do not undermine leadership. They establish it. Telemachus cannot govern Ithaca by pretending the suitors are merely enthusiastic guests.

Board Oversight During Transition

Boards of Directors should pay special attention during leadership transitions. A CEO departure, founder transition, CFO replacement, compliance leadership change, merger integration, restructuring, or sudden executive absence can create real compliance vulnerability. It may not appear on the face of the financials. It may not show up immediately in hotline data. But the risk is there.

The board should ask whether interim authority is clear, whether compliance has direct access to leadership, whether key controls remain staffed, whether open issues are being tracked, and whether employees understand where to escalate concerns.

A transition plan should not be limited to investor messaging and organizational charts. It should include compliance continuity. Who owns active investigations? Who signs certifications? Who approves high-risk third parties? Who can grant policy exceptions? Who reports to the board? Who monitors retaliation risk? Who tracks remediation? Who protects records and data? Who communicates expectations to employees? If those answers are unclear, the suitors are already choosing seats.

The Compliance Takeaway

Telemachus teaches us that compliance continuity matters. A company cannot rely on heroic founders, all-knowing executives, indispensable compliance officers, or informal networks of people who “just know how things work.” That may function for a while. It may even feel efficient. But when the key person is gone, the weakness becomes visible. Governance must survive absence.

Authority must be clear. Control ownership must be documented. Delegation must be practical. Oversight must continue. Compliance must be integrated into operations, not dependent on personalities. Because when authority is unclear, misconduct does not wait politely outside the palace. It pulls up a chair, pours the wine, and starts acting like it owns the place.

Join us Tomorrow

Telemachus teaches that governance must survive absence: authority must be clear, ownership documented, and compliance embedded deeply enough that Ithaca can operate without Odysseus in the room. Penelope carries that lesson into the next test, showing what ethical leadership looks like when authority is contested, pressure is relentless. Everyone wants a decision before the facts are ready. If Telemachus asks who owns compliance when the key leader is gone, Penelope asks whether the person with authority has the discipline to say “not yet” to a questionable vendor, weak certification, incomplete investigation, or rushed transaction. Together, they move the leadership arc from succession and continuity to integrity under pressure: first making governance clear, then proving it can hold the line when the suitors demand an answer.

Categories
Blog

Odyssey Week: Leadership – Odysseus the Brilliant Problem: Tone at the Top

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Matt Damon was great as Odysseus.

Odysseus is the kind of leader every board says it wants. He is brave, strategic, persuasive, resilient, creative under pressure, and very good at producing results when the situation looks impossible. He wins wars. He escapes monsters. He talks his way out of death more than once. He is the executive you send into the room when the deal is collapsing, the market is hostile, and everyone else has run out of slides.

He is also, on occasion, his own biggest compliance risk. That is what makes Odysseus so useful for business leaders and compliance professionals. He is not a cartoon villain. He is not reckless in the simple sense. He is brilliant. And brilliance can be dangerous when no one is willing to challenge it.

Odysseus reminds us that tone at the top is not only about what leaders say in polished town halls. It is about how leaders behave when the pressure is real, the stakes are high, and the rules feel inconvenient. The corporate lesson is straightforward: high-performing leaders can create high-performing risk. The organization must be able to challenge its stars.

The Corporate Translation

Every company has an Odysseus. Sometimes he is the rainmaking sales leader who always makes the number. Sometimes she is the visionary founder who can charm investors, customers, regulators, and the board in a single afternoon. Sometimes it is the regional head who delivers growth in difficult markets. Sometimes it is the product leader who moves faster than the control functions can process. The organization loves this person because they win. And that is precisely the problem.

Success can become a shield. Results can become a permission structure. A leader who delivers extraordinary outcomes may slowly become exempt from ordinary scrutiny. Questions that would be asked of anyone else are softened, delayed, or skipped entirely.

  • “How did we win that deal? ”
  • “Why was that third party necessary? ”
  • “Who approved that discount? ”
  • “Why was Legal brought in so late? ”
  • “Why are employees afraid to challenge this person? ”
  • “Why does Internal Audit keep finding exceptions in this business unit? ”

In a healthy culture, these questions are routine governance. In a weak culture, they sound like betrayal. That is the Odysseus problem. He saves the quarter, dazzles the board, and leaves Internal Audit wondering why no one asked how he did it.

Tone at the Top Is Conduct, Not Content

Companies are very good at producing leadership messages. The CEO video. The annual ethics letter. The opening paragraph of the Code of Conduct. The carefully scripted statement that “integrity is our highest value” usually releases the same week everyone is being told to accelerate growth, reduce costs, launch faster, and stop bringing problems without solutions.

Leadership messaging isn’t wrong. It matters. Employees do take cues from senior leaders. The FCPA Resource Guide states that compliance begins with the board and senior executives setting the proper tone and that managers and employees take cues from corporate leaders. It also emphasizes that senior management should clearly articulate standards, communicate them unambiguously, adhere to them, and disseminate them throughout the organization.

Indeed, the Evaluation of Corporate Compliance Programs (ECCP) asks some specific questions. Regarding Conduct at the Top, these questions include: How have they modeled ethical behavior to subordinates? Have managers tolerated greater compliance risks in pursuit of new business or greater revenues? Have managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from effectively implementing their duties?

But employees are sophisticated. They listen to the speech, then watch the calendar, the budget, the promotions, the exceptions, and the discipline decisions. They notice who gets praised. They notice who gets protected. They notice whether compliance concerns change decisions or merely create additional paperwork. They notice whether the high performer who bullies employees, ignores controls, or plays games with approvals is treated as a problem or as “complicated.” Tone at the top is not what leadership says when the cameras are on. Tone at the top is what leadership tolerates when the revenue is attractive.

The Danger of the Heroic Exception

Odysseus lives by exception. That is part of his greatness. He survives because he improvises. He adapts. He reads the room, the monster, the god, the storm, and the weakness in every opponent. He does not always follow the obvious path because the obvious path often leads directly into the sea. Unfortunately, exceptions, not properly managed, are what get companies into hot water.

Business needs leaders who can adapt. Compliance should not become a shrine to rigidity. A company that cannot make decisions, approve thoughtful exceptions, or move with commercial urgency will not be admired for its purity. It will simply become irrelevant. But there is a difference between disciplined exception management and heroic exception culture.

Disciplined exception management asks, “What is the risk?” Who owns it? Who approves it? Is the exception documented? Is it time-limited? Are there compensating controls? Will we monitor it? What precedent does it create? Heroic exception culture says, “Odysseus has it handled.” That is not governance. That is mythology with a travel budget. The ECCP asks, “What exceptions to these policies has an organization permitted?”

When organizations build around heroic exceptions, they become dependent on personality rather than process. The leader’s instincts replace controls. Their confidence replaces documentation. Their track record replaces scrutiny. Their urgency replaces escalation.

Eventually, the organization is no longer asking whether the decision is right. It is asking whether it trusts the hero. That is a dangerous way to run a company. Always remember: trust, but verify.

Pressure to Perform Changes the Ethical Weather

Tone at the top is inseparable from pressure. Leaders may say all the right things about ethics and compliance, but if every business conversation ends with “just get it done,” employees hear the real message. If compensation rewards only revenue, employees hear the real message. If managers who raise concerns are labeled as blockers, employees hear the real message. If compliance is praised in public and bypassed in private, employees hear the real message.

The ECCP asks how senior leaders, through words and actions, have encouraged or discouraged compliance, how they have modeled ethical behavior, and whether managers have tolerated greater compliance risks in pursuit of new business or greater revenues. It also asks whether managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from doing their jobs.

That is an excellent test for any leadership team. Not, “Did we say integrity matters? But did our conduct make integrity practical? “A leader who sets impossible targets and then expresses surprise when employees cut corners has not created a compliance culture. He has created plausible deniability. Odysseus often survives impossible pressure. Companies should be careful about asking employees to do the same.

Challenging the Star Performer

The true test of tone at the top is whether the organization can challenge its stars. Can compliance question the top sales executive? Can internal audit review the founder’s favorite business unit? Can Legal slow down the CEO’s preferred acquisition? Can HR investigate a high-performing manager accused of retaliation or harassment? Can Finance reject revenue recognition pressure from a powerful regional leader?

Or does the organization quietly apply one standard to ordinary employees and another to those who deliver? Employees do not need a formal policy memo to understand a double standard. They see it immediately. If a junior employee is disciplined for a policy violation while a senior leader is “coached” for comparable conduct, the culture learns. If a high-performing executive is allowed to mistreat people because “the business is too important,” the culture learns that compliance matters only when it doesn’t affect the powerful. If compliance concerns disappear when they involve influential leaders, the culture learns that compliance matters only when it doesn’t affect the powerful.

The ECCP looks at whether compliance is enforced consistently and whether consequences apply regardless of an employee’s position or title. It also asks whether managers are held accountable for misconduct that occurred under their supervision and for supervisory failures. That is not just enforcement logic. It is cultural logic. A company cannot claim integrity as a value while treating performance as immunity.

What a Better Program Does

A better compliance program does not try to eliminate Odysseus. That would be both impossible and unwise. Organizations need bold leaders. They need commercial courage, strategic imagination, persuasive ability, and the confidence to act in uncertainty. The goal is not to make leaders timid. The goal is to make leadership accountable.

A better program builds controls around high-risk authority. It monitors exceptions. It reviews pressure points. It includes compliance in strategic decisions early. It gives the board visibility into recurring overrides, hotline trends, audit findings, employee turnover, and control failures in high-performing units. It trains senior leaders not only on rules but also on how their behavior shapes risk. It also asks uncomfortable questions about success.

Where are results unusually good? Where are margins unusually high? Where are approvals unusually fast? Where are complaints unusually low? Where do people say, “That is just how that leader operates”? Where does the company rely on one person’s relationships, instincts, or influence more than on process? Those are Odysseus questions. The point is not to assume misconduct. The point is to understand that extraordinary performance deserves thoughtful scrutiny, not blind applause.

The Compliance Takeaway

Odysseus is brilliant. That is why he is dangerous. He shows us that leadership risk does not always arrive as laziness, incompetence, or obvious corruption. Sometimes it arrives as charisma. Confidence. Commercial success. Strategic genius. The leader who always finds a way.

Tone at the top means ensuring that even the most successful leaders operate within the company’s values, controls, and accountability structures. It means the Board of Directors and senior executives must model ethical conduct not only in speeches but also in decisions. (Talk the Talk but also Walk the Walk.) It means performance is celebrated but not worshiped. It means the organization can ask its heroes hard questions before the journey turns into an investigation. Every company needs leaders who can win. But no company should become so dazzled by Odysseus that it forgets to check the map, inspect the ship, and ask what happened to the crew.

Join Us Tomorrow

Odysseus reminds us that brilliance can become risk when success turns into a shield, exceptions become heroic, and no one is willing to challenge the leader who always finds a way. But even the most brilliant leader eventually leaves the room, and that is when the next compliance test begins: whether governance survives without the hero. Telemachus inherits the house Odysseus left behind, where authority is uncertain, informal power has filled the gaps, and bad actors have grown comfortable at the table. If Odysseus asks whether top performers are held to the same standards as everyone else, Telemachus asks the follow-up question every board should fear: when the indispensable leader is gone, does the compliance program still work, or was it only working because Odysseus was there?

Categories
Blog

Odyssey Week: Leadership – Athena in the Boardroom: Independent Oversight and Counsel

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Zendaya was great as Athena.

Athena does not row the ship. She does not lash herself to the mast, fight the Cyclops, navigate Scylla and Charybdis, or drag Odysseus’s crew away from every bad decision they seem determined to make. She is not in the trenches every day. She does not submit expense reports, approve vendors, review discount requests, or sit through the quarterly business review where someone explains why this deal is “strategic.” But Athena changes the journey.

She sees what Odysseus cannot see. She warns. She guides. She challenges. She protects. She appears at decisive moments when courage alone is not enough, and cleverness is about to become self-harm with better branding. That is why Athena belongs in the boardroom.

For corporate compliance, Athena represents independent oversight and wise counsel: the person, function, or governance body able to say, “That may win the deal, but it may also wreck the kingdom.” A compliance function that cannot challenge leadership is not Athena. Rather, it is simply decoration to meet a legal, statutory, or contractual requirement.

The Corporate Translation

Every company says it values compliance independence. The question is what that means when the business wants something. It is easy to celebrate compliance when compliance supports the decision already made. It is easy to invite the Chief Compliance Officer (CCO) to the meeting after the deal is signed, the press release is drafted, and the train has left the station with several questionable third parties in the dining car. That is not independence. That is archaeology.

Independent oversight means compliance has the authority, access, and resources to influence decisions before risk is accepted. It means the board hears directly from compliance. It means escalation does not depend on whether a business leader feels emotionally prepared for bad news. It means compliance can challenge high performers, powerful executives, and sacred business strategies without being treated as disloyal.

Athena does not exist to admire Odysseus. She exists to help him survive himself.

Access Is Not the Same as Influence

Many compliance officers technically have access to leadership. They attend meetings. They submit reports. They provide updates. They own several slides in the board deck, usually after cybersecurity and before “other business.” But access is not the same as influence.

Real access means compliance can raise concerns in a setting where they matter. It means there are private sessions with the board or audit committee. It means compliance can speak without management filtering, softening, or translating the message into something more comfortable. It means the board asks questions that go beyond “Any major issues?” which is the governance equivalent of asking a teenager whether school was fine.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) focuses directly on whether compliance and control functions have autonomy and resources, including sufficient stature, sufficient staffing and resources, and autonomy from management, such as direct access to the board or audit committee. That is not a technical footnote. It is a central governance point. If the compliance function only reaches the board through management, the board may be hearing the music after someone else has adjusted the volume.

Authority Must Be Real

A compliance function without authority is like Athena without wisdom: impressive in name only. Authority means compliance can stop, modify, or escalate a transaction. It means policies are not optional when revenue is large enough. It means compliance concerns are documented, tracked, and resolved. It means the business must explain why it wants to proceed despite risk, not merely pressure compliance to “be practical.”

Practical compliance is not weak compliance. Practical compliance helps the business find a lawful and ethical path forward. But there is a difference between being practical and being domesticated. A good compliance function does not say no for sport. It says no when the facts, risks, and values of the company require it. It says, “not that way.” It says, “not with that intermediary.” It says, “not without diligence.” It says, “not until we understand the data, the customer, the payment, the conflict, or the control failure.”

The ECCP specifically asks how a company has responded when compliance raised concerns and whether transactions or deals have been stopped, modified, or further scrutinized because of compliance concerns. That is the right question. The ECCP states at one point, “Have they persisted in that commitment in the face of competing interests or business objectives?” Not whether compliance attended the meeting. Whether compliance changed the outcome. The ECCP further asked, “What role has compliance played in the company’s strategic and operational decisions? How has the company responded to specific instances where compliance raised concerns? Have some transactions or deals been stopped, modified, or further scrutinized as a result of compliance concerns?”

Resources Are a Statement of Values

Companies reveal what they value through budget. A board can praise compliance all day long. Still, if the function lacks staffing, technology, data access, training budget, investigative resources, and experienced personnel, the message is clear: “We support compliance, but preferably at a discount.”

No one would ask sales to grow revenue without systems, people, and market data. No one would ask finance to close the books with three spreadsheets, two interns, and a heroic attitude. Yet compliance teams are often expected to monitor global risk with underpowered tools and just enough headcount to keep the training completion dashboard from turning red.

That is not empowerment. That is wishful thinking. The ECCP asks whether compliance personnel have sufficient staffing to audit, document, analyze, and act on compliance efforts, whether resources are comparable to other parts of the company, and whether compliance has access to relevant data for timely monitoring and testing. Regarding funding and resources, the ECCP asks, “Has there been sufficient staffing for compliance personnel to effectively audit, document, analyze, and act on the results of the compliance efforts? Has the company allocated sufficient funds for the same? Have there been times when requests for resources by compliance and control functions have been denied, and if so, on what grounds? Does the company have a mechanism to measure the commercial value of investments in compliance and risk management?”

Those questions should make boards uncomfortable in a productive way. If the business has world-class tools to capture opportunity but outdated tools to detect risk, that imbalance is itself a governance decision.

Escalation: The Road from Concern to Action

Athena’s guidance matters because it reaches Odysseus when action is still possible. That is also the purpose of escalation. A well-designed escalation process moves concerns to the right people at the right time with enough information to make a decision. A weak escalation process traps concerns in email chains, local management reviews, or “let’s monitor this” limbo until the problem becomes a reportable event, a whistleblower complaint, or a headline.

Escalation should not depend on personality. It should not depend on whether the compliance officer is unusually persistent, politically skilled, or willing to become unpopular before breakfast. It should be built into governance.

What must be escalated? To whom? Within what timeframe? With what documentation? What happens when business and compliance disagree? Who decides? How are unresolved concerns reported to senior leadership or the board? These are not theoretical questions. They are the mechanics of wise counsel. Because without escalation, Athena is whispering in a locked room.

The Board’s Role: Ask Better Questions

Boards do not need to manage the compliance program day to day. That is not their role. But boards do need to oversee whether the program is real. That means asking better questions. The board should also pay attention to the moments when compliance loses. If compliance raised concerns and the business proceeded anyway, what happened? Was the decision documented? Were compensating controls added? Was the board informed? Did the risk later materialize? You learn a great deal about culture by examining what happens when wise counsel is inconvenient.

The Compliance Takeaway

Athena does not represent bureaucracy. She represents judgment. That distinction matters. Compliance officers are sometimes caricatured as the people who slow things down, complicate decisions, or drain the romance out of heroic commercial ambition. But the best compliance functions do something far more important: they help the organization see clearly before it acts.

They bring risk into the room. They challenge assumptions. They protect the company from cleverness without discipline. They help leaders understand that winning the deal, entering the market, launching the product, or pleasing the customer is not success if the path taken damages the company’s integrity.

Independent oversight is not ceremonial access. It is authority, resources, escalation, data, board engagement, and the organizational courage to let compliance challenge power. Odysseus needed Athena because brilliance has blind spots. So does every company.

The question is whether your Athena is truly in the boardroom or merely listed on the org chart.

Join us Tomorrow

Athena teaches that independent oversight is not ceremonial access but real authority, resources, escalation, data, board engagement, and the courage to let compliance challenge power. But that lesson only matters if the organization is willing to apply it to its most celebrated leaders, not merely its easiest targets. That brings us to Odysseus: the brilliant, strategic, results-driven leader every board wants and the very leader who can become the company’s most dangerous compliance risk when success becomes a shield. If Athena is the voice saying, “That may win the deal, but it may also wreck the kingdom,” Odysseus is the leader who wins the deal and forces the organization to ask whether anyone had the authority, courage, and independence to challenge how he did it. I hope you will join us tomorrow.

Categories
AI Today in 5

AI Today in 5: August 20, 2026, The Between Scylla and Charybdis Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI for compliance in the trucking industry. (CCJ Digital)
  2. 6 top AI tools for compliance. (Impakter)
  3. Don’t let AI strategy outpace your network strategy. (Fedscoop)
  4. FTC puts companies between Scylla and Charybdis. (Law.com)
  5. AI governance and data analytics in healthcare. (Healthcare Innovation)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.

Categories
Blog

The Odyssey and Compliance, Part 4 – The Cattle of Helios: Non-Negotiables and Control Breaches

We continue our consideration of the intersection of The Odyssey and compliance by reviewing the tale of the Cattle of Helios.

Odysseus’s crew had been warned and not casually warned. Not “check the policy when you get a minute,” warned the manager. Not “Legal would prefer we avoid this,” warned. They were told clearly: do not touch the cattle of Helios. The cattle were sacred. The instruction was simple. The consequences were severe. Then hunger arrived.

Odysseus’s men were stranded. Supplies ran low—pressure built. Rationalizations followed. The crew looked at the sacred cattle and began doing what employees, managers, and executives have done in companies since the dawn of internal controls: they explained why the rule should not apply this time. They were desperate. The situation was unusual. The risk was theoretical. Surely the gods would understand. Surely survival mattered more than procedure. So they slaughtered the cattle. It did not end well.

For corporate compliance, the Cattle of Helios is a story about red-line rules: the things an organization says are non-negotiable. Do not falsify records. Do not retaliate. Do not bypass sanctions screening. Do not misuse customer data. Do not make unapproved payments. Do not obstruct an investigation. Do not conceal a conflict. Do not alter documents. Do not ignore a legal hold. Do not approve what you do not understand. Every company has sacred cattle. The real question is whether employees believe they are actually sacred.

The Corporate Translation

The Cattle of Helios are the company’s non-negotiables. They are not ordinary preferences. They are not “best practices.” They are not aspirational values printed on lobby walls next to a tasteful photograph of diverse employees pointing at a laptop. They are the rules that protect the organization’s license to operate.

In a strong compliance culture, employees know these rules. Managers reinforce them. Controls support them. Violations are escalated. Discipline is consistent. Pressure is acknowledged but does not excuse misconduct. In a weak compliance culture, everyone knows the words, but no one believes the consequences will be enforced. That is how red-line rules become folklore. A rule everyone knows, but no one enforces, is not a rule. It is a campfire story.

Pressure Does Not Create Character. It Reveals Controls.

Odysseus’s crew did not break the rule while comfortable, rested, and well-fed. They broke it under pressure. Most compliance breaches do not occur in calm conference rooms where everyone has read the policy, reviewed the risk matrix, and enjoyed a sensible lunch. They occur when the quarter is closing, the shipment is stuck, the customer is angry, the regulator is asking questions, the system is down, the executive is impatient, or the team is exhausted.

Pressure is the great compliance stress test. It reveals whether policies are operational or decorative. It reveals whether managers know how to supervise. It reveals whether employees believe escalation is safe. It reveals whether the organization has built controls that work when humans are hungry, tired, ambitious, afraid, or behind target.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s compliance program is not only well-designed but also applied earnestly and is working in practice. It also notes that prosecutors look at whether policies, reporting lines, training, incentives, and discipline are integrated into operations and the workforce. That is the key point. A red-line rule cannot live only in the Code of Conduct. It must live in approvals, workflows, monitoring, supervision, training, investigations, and consequences. Otherwise, when hunger comes, the cattle are on the menu.

Supervision Is Not a Ceremonial Role

There is another uncomfortable part of the myth. Odysseus is absent when the crew crosses the line. Depending on the telling, he is asleep or away praying. Either way, the leader is not effectively supervising when the critical decision is made. That should make every business leader shift slightly in their chair.

Many control breaches happen in the gap between policy and supervision. Senior leadership announces the rule. Compliance writes the policy. Legal reviews the language. Training pushes the module. Then the real decision is made by a frontline team under pressure, with a manager who either does not know, does not ask, or does not want to know. That is not a paperwork problem. That is an accountability problem.

Managers are the first line of ethical translation. They turn corporate expectations into daily behavior. If they treat compliance as an administrative burden, so will employees. If they reward results without asking how those results were achieved, employees will notice. If they punish bad news, problems will go underground. If they look away from “small” violations, they teach the business that red lines are negotiable.

Supervision is not hovering. It is not micromanagement. It is the disciplined act of identifying where the real risks lie and ensuring that employees have guidance, resources, and accountability before a breach occurs. Odysseus’s men knew the rule. What they lacked was effective control at the decisive moment.

Reporting Before the Cattle Are Slaughtered

A mature compliance program wants to hear about pressure before it becomes misconduct. That means employees need trusted ways to raise concerns, ask questions, and report violations. The ECCP identifies confidential reporting and investigation processes as hallmarks of a well-designed program, including mechanisms for reporting suspected misconduct, protection against retaliation, proper routing of complaints, timely investigations, and appropriate follow-up and discipline.

The reporting question is not simply, “Do we have a hotline? “The better question is, ‘Would the crew have used it before dinner?’ Would an employee say, ‘We are being asked to ship without required approval’? “Would a finance analyst say, “This invoice looks wrong”? Would a sales manager say, “The customer is pushing us to use an unapproved intermediary”? Would an IT employee say, “Someone wants access they shouldn’t have”? Would anyone say, “We are about to cross a line”? If the answer is no, the reporting mechanism may exist, but trust does not.

That is where anti-retaliation becomes central. Employees will not report sacred cattle violations if the organization quietly punishes the person who notices the knife. A speak-up culture is not built by posters. It is built on what happens to the first person who speaks up when the business does not want to hear it.

Discipline Must Be Consistent, Not Theatrical

After a breach, companies often want to show seriousness. That is understandable. But discipline must be more than corporate thunderbolts. It must be fair. It must be consistent. It must be documented. It must address both supervisors and direct actors. It must consider incentives and pressure. It must ask whether the rule was clear, whether training was adequate, whether controls failed, and whether leaders tolerated or encouraged the behavior.

The ECCP specifically focuses on consequence management, including procedures to identify, investigate, discipline, and remediate violations, consistent enforcement across the organization, and consequences regardless of position or title. It also asks whether companies track disciplinary outcomes and measure consistency across levels, geographies, units, and departments. That is where many companies stumble.

They discipline the employee who touched the cattle but ignore the manager who set impossible targets. They terminate the junior person but coach the rainmaker. They punish the region that got caught but ignore similar conduct elsewhere. They announce “zero tolerance” and then create exceptions for people with large books of business.

Employees are excellent readers of organizational reality. They know whether discipline is consistent. They know whether some people are protected. They know whether “non-negotiable” means non-negotiable or merely “please do not embarrass us.” A compliance program loses credibility when consequences depend on rank, revenue, geography, or internal politics.

Incentives: Who Made the Crew Hungry?

The crew was hungry. That does not excuse what they did, but it helps explain why the rule failed. Corporate compliance must ask similar questions. Were employees under unrealistic sales targets? Were bonuses tied only to revenue? Were managers rewarded for speed without regard to control quality? Were teams understaffed? Were approvals too slow? Was the policy clear but operationally impossible? Did leadership create pressure and then act shocked when employees cut corners?

The ECCP asks whether companies have considered the impact of financial rewards and other incentives on compliance, including whether commercial targets are achievable while operating in a compliant and ethical manner. That question should be posted in every executive compensation meeting. If the business model requires employees to choose between meeting targets and following the rules, do not be surprised when the cattle start disappearing.

What a Better Program Does

A better program defines its non-negotiables clearly and repeats them often. It trains employees on real pressure moments, not abstract policy language. It gives managers supplemental guidance. It builds controls around red-line rules. It monitors for breaches and near misses. It makes escalation easy. It investigates fairly. It disciplines consistently. It addresses root causes. It tests whether employees actually understand which rules cannot be bent. Most importantly, it refuses to let pressure become a universal solvent.

Pressure may explain why misconduct occurred. It should not erase accountability. When a red-line rule is breached, the organization should ask four questions.

First, did the employee know the rule?

Second, did the controls make compliance practical?

Third, did supervision reinforce the rule?

Fourth, did incentives or leadership pressure make violations more likely?

Those questions move the company beyond blame and toward remediation.

The Compliance Takeaway

The Cattle of Helios remind us that non-negotiable rules are only real when they survive pressure. It is easy to honor sacred cattle when the pantry is full. The test comes when the team is hungry, the deadline is looming, and someone says, “We have no choice.” That is when compliance has to mean something.

A company’s most important rules must be known, operationalized, monitored, and enforced. They must apply to senior leaders and junior employees. They must survive business urgency. They must be supported by reporting channels, investigations, discipline, and incentives that tell the same story.

Do not falsify records.

Do not retaliate.

Do not bypass screening.

Do not misuse data.

Do not make unapproved payments.

Do not conceal misconduct.

Do not touch the cattle.

Because if the organization says a rule is sacred but treats violations as negotiable, employees will soon learn the real policy. And by then, dinner may already be served.

Join us tomorrow as we conclude our series with a homecoming in Ithaca.

Categories
Blog

The Odyssey and Compliance, Part 3 – Circe’s Island: Third-Party Influence and Culture Capture

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of Circe’s Island and how third parties can not simply influence but also capture organizations.

Odysseus had seen danger before. He had survived war, storms, and the occasional poor travel decision that would have caused any modern risk committee to request an immediate meeting. But then he came to Circe’s island, where the threat did not begin with open violence. It began with hospitality. Circe welcomed Odysseus’s men. She offered food. She offered a drink. She offered comfort. Then, in one of the more memorable compliance-adjacent transformations in Greek mythology, she turned them into swine.

Subtle? Not especially. Useful for corporate compliance? Absolutely. In the corporate world, third parties rarely transform employees into literal pigs. That would at least make the investigation easier. The modern version is quieter. A consultant becomes indispensable. A reseller knows “how things work here.” A lobbyist explains that the official process is for amateurs. A distributor normalizes side payments. A strategic partner begins to shape internal decisions. A vendor’s gifts, favors, travel, and access slowly change what employees consider acceptable.

No one wakes up and says, “Today I shall surrender my professional judgment.” Instead, judgment softens and then stretches. Then outsourced. That is Circe’s island.

The Corporate Translation

Circe is the consultant, agent, lobbyist, reseller, distributor, broker, introducer, or strategic partner who makes questionable conduct feel sophisticated. She does not have to say, “Break the rules.” That would be too obvious. She says something more dangerous:

“This is how business is done.”

“Everyone uses this structure.”

“You are being too rigid.”

“The policy was not written for this situation.”

“You can trust me.”

“We have relationships you do not have.”

That is the language of culture capture. The third party does not merely provide a service. The third party begins to influence the organization’s standards. This is why third-party risk is not just a procurement issue. It is not just an anti-bribery issue. It is not just a contracting issue. It is a cultural issue. The most dangerous third parties do not always demand a bribe. Sometimes they simply change what your people think is normal.

The Paperwork Trap

Most companies have a third-party process. There is a questionnaire. There is a risk rating. There is a certification. There is a contract clause. Somewhere, there may even be a spreadsheet with conditional formatting, because nothing says “control environment” like a cell turning amber. These tools matter. But paperwork alone does not manage influence.

A company can collect every form and still miss the real risk. Whom is this third party influencing? Who inside the company is advocating for them? Why are they needed? What access do they have? What discretion do they exercise? Are they interacting with government officials, customers, healthcare professionals, regulators, state-owned entities, procurement teams, or other sensitive stakeholders? Are they being paid in a way that makes sense? Are they actually doing the work? Are they unusually close to the decision-maker?

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether companies apply risk-based due diligence to third-party relationships and understand the qualifications, associations, business rationale, reputation, compensation, and actual services performed by third parties. It also asks whether companies engage in ongoing monitoring through refreshed due diligence, training, audits, or certifications.

That is the point. Third-party compliance is not a one-time onboarding ritual. It is a relationship management discipline. Circe’s danger was not that she existed. The danger was that Odysseus’s men entered her house without understanding the risk.

Gifts, Hospitality, and the Slow Erosion of Judgment

Gifts and hospitality are often discussed as if the only question is whether the amount is above or below a policy threshold. That is too narrow. A meal may be permissible and still influential. A conference invitation may be properly approved and still create pressure. A vendor-sponsored trip may be documented and still tilt the relationship. A series of small favors may do more damage to independence than one obviously improper gift.

Compliance officers understand this. Business leaders sometimes resist it because influence is uncomfortable to discuss. No one wants to admit that lunch, access, flattery, or convenience can affect judgment. We prefer to believe we are all rational actors, floating above human weakness like minor gods with expense reports. We are not.

Behavioral ethics teaches a humbler lesson: people are influenced by relationships, reciprocity, loyalty, fatigue, social norms, and self-interest. A third party who becomes a friend, fixer, sponsor, or “trusted guide” can reshape decisions without issuing a single improper instruction.

That is why gifts-and-hospitality controls should look beyond monetary value. They should examine frequency, timing, recipient role, pending decisions, public-sector touchpoints, tender activity, regulatory matters, and cumulative patterns. The better question is not only, “Was this gift allowed? “The better question is, “What might this gift be trying to make feel normal? ”

Conflicts of Interest: Circe with a Business Card

Conflicts of interest are another form of enchantment. The employee recommends a vendor owned by a family member. A manager hires a consultant whom he previously employed. A procurement lead has a side investment in a supplier. A sales executive pushes a reseller because the reseller has promised future employment. A board member has ties to a strategic partner.

Often, the conflicted person does not experience the conflict as corruption. They experience it as trust.

“I know them.”

“They are good people.”

“They understand our business.”

“This will move faster.”

That may all be true. It may also be irrelevant. Conflicts do not require proof that someone acted dishonestly. A conflict means that personal interest may interfere with, or appear to interfere with, professional judgment. In compliance, appearance matters because trust matters. Circe did not need to tell the crew they were compromised. They simply became something other than what they had been. That is what unmanaged conflicts do. They transform decision-makers into advocates for interests they may not even fully recognize.

Risk-Based Due Diligence Means Asking Better Questions

A strong third-party program should be risk-based. That does not mean treating every vendor like a potential international crime syndicate. It means applying the right level of scrutiny to the right relationship. The office coffee supplier probably does not need the same review as a customs broker, government-facing consultant, high-commission sales agent, data processor, clinical partner, reseller, lobbyist, or distributor in a high-risk market.

Risk-based due diligence should ask direct questions:

What will this third party do for us?

Why do we need them?

Who selected them?

What relationships do they bring?

How will they be paid?

What access will they receive?

What decisions can they influence?

What laws, regulations, or policy areas do they touch?

What red flags appeared, and how were they resolved?

The ECCP also emphasizes risk assessment across factors such as business partners, third-party use, gifts, travel, entertainment, and other areas that may contribute to the risk of misconduct. That is a useful reminder: third-party risk rarely travels alone. It often brings friends. Gifts risk. Conflicts are risky. Books-and-records risk. Data risk. Sanctions risk. Cyber risk. Antitrust risk. Fraud risk. Reputational risk. Circe’s island is crowded.

Training the People Who Meet Circe

Third-party policies are necessary, but people need training before they sit across the table from Circe. Sales teams need to understand the red flags for resellers and agents. Procurement teams need to spot conflicts and unusual payment terms. Finance needs to recognize vague invoices, round-dollar payments, split payments, and services that cannot be verified. Legal needs to ensure that contracts describe real services and include rights to audit, termination, compliance, and cooperation. Business sponsors need to understand that “I trust them” is not due diligence.

The ECCP asks whether training and communications are tailored to the audience and whether companies provide practical guidance, case studies, and ways for employees to get ethics advice as issues arise. It also contemplates training for appropriate agents and business partners. That is exactly right.

Do not train employees only on the policy. Train them in the moment. The moment when the consultant says the invoice needs to be vague. The moment when the distributor asks for payment to an offshore account. The moment when the lobbyist says no one can know about the meeting. The moment when the vendor offers to fly the team to a “strategy session” at a resort, suspiciously light on strategy. The moment when the business sponsor says, “Compliance is slowing this down.” That is where the program either works or becomes decorative.

What a Better Program Does

A better third-party program examines influence, not just paperwork. It connects due diligence, contracting, training, payment controls, gifts and hospitality, conflict disclosures, monitoring, audits, and termination rights. It reviews third-party activity after onboarding. It checks whether services were actually performed. It compares compensation to market value. It looks for unusual payment structures. It refreshes diligence when risk changes. It trains business sponsors, not just compliance staff. It monitors the internal champions who may become too close to the third party they manage.

Most importantly, it permits employees to be skeptical. Not cynical. Skeptical. There is a difference. Cynicism says everyone is corrupt. Skepticism says facts, controls, and accountability should support trust. Odysseus survived Circe because he received a warning, protection, and guidance before walking into the risk. Your employees need the same, preferably without needing Hermes to appear with magical herbs.

The Compliance Takeaway

Circe’s island is not just a story about transformation. It is a story about influence. Third parties can help companies grow, enter new markets, solve complex problems, and operate more effectively. Many are essential. Many are ethical. Many know things the company genuinely needs to know. But a third party should never become a substitute for the company’s judgment. When a consultant, agent, reseller, lobbyist, vendor, or strategic partner begins to redefine what is acceptable, the company has moved from third-party management to third-party capture.

That is the lesson for compliance officers and business leaders. Do not ask only whether the forms are complete. Ask whether the relationship is changing behavior. Ask whether gifts, conflicts, access, dependence, or pressure are making questionable conduct feel normal. Ask whether employees still know where the company’s standards end and Circe’s influence begins. Because in business, as in mythology, transformation rarely announces itself. One day, your people are professionals exercising independent judgment. The next day, they are defending the island.

Join us on Thursday for Post 4, where we consider The Cattle of Helios: Non-Negotiables and Control Breaches.

Categories
Blog

The Odyssey and Compliance, Part 2 – The Lotus-Eaters: Culture Drift and the Comfort of Forgetting

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of the Lotus-Eaters and the drifting of corporate culture.

Odysseus and his crew did not always face monsters with teeth. Sometimes the danger was softer. After leaving Troy, Odysseus and his men came to the land of the Lotus-Eaters. There was no battle. No ambush. No roaring beast. No angry god hurling thunderbolts. The locals simply offered the crew lotus flowers. Those who ate them lost all desire to return home. They forgot the mission. They forgot Ithaca. They forgot the purpose of the journey.

That is what makes the episode so unsettling. The Lotus-Eaters did not defeat Odysseus’s crew by force. They defeated them through comfort, distraction, and forgetfulness. Welcome to one of the most common compliance risks in modern corporate life: culture drift.

Not every compliance failure begins with greed. Not every ethical collapse starts with a suitcase of cash, a fake invoice, or someone whispering, “Let’s take this offline.” Some failures begin when people simply forget why the rules matter. They remember the annual training deadline. They remember the attestation. They remember where the Code of Conduct lives, assuming the intranet search function is having a good day. But they no longer connect compliance to the company’s mission. That is the lotus.

The Corporate Translation

Every organization has its own version of the island of the Lotus-Eaters. It may be a high-performing business unit that hits its numbers, avoids obvious scandal, and quietly stops engaging with compliance. It may be a remote office that has not seen a live compliance conversation in years. It may be a leadership team that talks about values during onboarding, but never mentions them again unless there is an investigation. It may be a group of employees who click through training modules while answering emails, eating lunch, and wondering whether the quiz has unlimited attempts.

Everyone is pleasant. Everyone is busy. Everyone is productive. Everyone is slowly detaching from the company’s stated values. This is the direct analogy: the lotus is the business unit where nothing looks obviously wrong, but no one can explain how compliance connects to the work they actually do. That is a dangerous place. Not because people are evil. Because they are comfortable.

Risk Assessment: Finding the Islands Before People Forget

A good compliance program begins with risk assessment, not vibes. Odysseus had to know where his crew was vulnerable. Were they hungry? Exhausted? Demoralized? Homesick? Easily distracted by local hospitality? The answer, unfortunately, was yes.

Companies need the same kind of self-awareness. Where are employees most likely to forget the mission? Where are they under the most pressure? Where are the policies most disconnected from daily operations? Where has training become a ritual instead of a reinforcement?

The DOJ’s Evaluation of Corporate Compliance Programs emphasizes risk-tailored compliance and asks how a company identifies, assesses, and addresses risks, including whether it updates policies, procedures, and training as those risks evolve. It also asks whether training is tailored, whether employees understand it in practice, and whether the company measures effectiveness rather than merely delivering content.

That is an important distinction. A weak risk assessment asks, “Did everyone receive the training? “A better risk assessment asks, “Who needs what training, on which risks, at what level of depth, in what language, through what format, and how do we know it changed behavior? “That is the difference between counting lotus flowers and understanding why people are eating them.

Policies: The Mission Written Down

Policies are supposed to tell employees how the company expects them to act. But too many policies are written as if they were designed to survive litigation rather than to guide human beings. They are long, dense, passive, and beloved mainly by the people who drafted them. Employees do not use them. Managers do not reinforce them. Business teams treat them like airport terms and conditions: technically available, rarely read, and accepted under pressure.

That is a policy failure by design. A policy is not effective because it exists. It is effective when employees can find it, understand it, apply it, and believe the company expects them to follow it. The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether policies and procedures are accessible, searchable, communicated to employees and relevant third parties, integrated into operations, and reinforced through internal control systems. It also asks whether gatekeepers receive guidance and training on what misconduct to look for and when to escalate concerns.

That is practical compliance. Policies should not be museum pieces. They should be field guides. The anti-corruption policy should help a sales manager understand what to do before a government customer asks for “support.” The data privacy policy should help an operations team understand when customer information can be shared. The conflicts policy should help a procurement employee understand why her cousin’s consulting firm is not just “a good local option.” The speak-up policy should help employees know where to go before silence becomes complicity. Policies should bring people back to Ithaca. They should remind the organization: this is who we are; this is how we do business; and this is the route home.

Training: More Than the Annual Click-Through

Now we come to training, the place where many compliance programs go to become lotus farms. You know the scene. An employee gets an email: “Mandatory Compliance Training Due Friday.” The employee opens the module, clicks through the slides, answers a few questions, and receives a certificate. Somewhere, a dashboard turns green. The compliance team exhales. The business moves on.

But did anyone learn anything? That is the uncomfortable question. As Ronnie Feldman continually reminds us, training is not effective because it was assigned. Training is not effective because completion rates are high. Training is not effective because the quiz average was 94 percent, especially if the questions were written so that “Do not commit fraud” was the challenging option.

Effective training helps employees recognize risk in the moment. It gives managers language to lead. It teaches employees how to pause, ask, escalate, and document. It uses realistic scenarios, not cartoon villains. It respects the audience’s time without insulting their intelligence. The ECCP specifically points to tailored training and communications, including practical advice, case studies, shorter, targeted sessions, opportunities for employees to ask questions, and measures of employee engagement and learning. It also asks whether training affects employee behavior or operations. The goal is not training completion. The goal is better decisions.

Ethical Fatigue Is Real

There is another reason the Lotus-Eaters matter. They remind us that people get tired. Employees face pressure, complexity, change, layoffs, new systems, reorganizations, market stress, and competing messages from leadership. Then compliance arrives with another policy update, another module, another certification, another “quick reminder” that is neither quick nor memorable.

Ethical fatigue sets in. When employees are exhausted, they do not necessarily become unethical. They become passive. They stop asking questions. They stop reading carefully. They assume someone else reviewed the issue. They treat compliance as background noise. This is where culture drift becomes dangerous. The organization may still have the right words, but the words no longer move anyone.

The solution is not more noise. It is better communication. Compliance teams should ask, “What does this audience need to know?” What decisions do they actually face? What mistakes are we seeing? What near misses have occurred? What questions are employees asking? What risks are emerging? What would make this guidance useful on Tuesday afternoon when the customer is angry, the deadline is real, and the manager wants an answer? That is where compliance becomes practical.

What a Better Program Does

A better program treats culture as something to be measured, tested, and renewed. It does not assume that because employees took training, they absorbed it. It does not assume that because a policy exists, employees know how to use it. It does not assume that because leadership talks about integrity, middle management reinforces it. A better program looks for signs of forgetting.

Are hotline reports dropping because misconduct is down, or because trust is down? Are policy questions coming from all regions or only headquarters? Are employees passing training but failing audits? Are managers escalating issues or solving them quietly? Are high-risk teams receiving generic training when they need tailored guidance? Are employees afraid to ask “basic” questions because they think they should already know the answer? The compliance function should use surveys, training analytics, audit results, hotline data, investigation trends, control testing, manager feedback, and employee questions to understand whether the message is landing. And when the message isn’t landing, the answer isn’t to blame the crew. Odysseus did not leave his men among the Lotus-Eaters and say, “Well, they should have remembered Ithaca.” He dragged them back to the ships. That is leadership.

The Compliance Takeaway

The land of the Lotus-Eaters is not a place of obvious corruption. That is why it is so dangerous. It is the place where mission fades into routine, where values become posters, where policies become files. Where training becomes a click, where employees are not hostile to compliance but simply detached from it.

For compliance officers and business leaders, the lesson is clear: culture must be refreshed before it drifts. Policies must be usable before they are needed. Training must be memorable before the crisis. Risk assessment must identify not only where misconduct could occur but also where people are most likely to forget why compliance matters.

Odysseus’s crew did not need a lecture. They needed to be reminded of the journey. So do organizations. The question is not whether your people have eaten the lotus. The question is whether your compliance program would know.

Join us tomorrow in Part 3, where we consider Circe’s Island: Third-Party Influence and Culture Capture.

Categories
Blog

The Odyssey and Compliance, Part 1 – The Trojan Horse: When Cleverness Becomes a Control Failure

There are few works in Western Literature more read than The Odyssey. While a cadre of passionate specialists prefer The Iliad, it is The Odyssey that is most generally taught in US high schools. Part travelogue, part adventure yarn, part social commentary, and part treatise on Greek morals and morality, it is still a rousing tale well worth the time to read. Now, Christopher Nolan is out with another movie version of The Odyssey. I have not yet seen the movie as of this writing.

I wanted to tackle The Odyssey from the compliance perspective. There are many things we can mine from this story. Over the course of this week, I will discuss five of them. Today, we consider where the story begins: the Trojan Horse as a failure of control. On Tuesday, we look at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we look at The Cattle of Helios: Non-Negotiables and Control Breaches. On Friday, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Today, we begin with The Odyssey, which directly follows the end of The Iliad. Here are a few business strategies more celebrated than the Trojan Horse. After ten long years of war, he looked at the walls of Troy and realized brute force had failed. The Greeks could not smash their way in. They could not negotiate their way in. They could not outlast their way in. So Odysseus did what clever leaders often do when conventional methods fail: he found a workaround. Build a great wooden horse. Hide soldiers inside it. Leave it outside the gates as a supposed gift. Sail away, or at least appear to. Let the Trojans make the fatal decision themselves.

While it was brilliant from a strategic perspective, it was an absolute nightmare from a compliance perspective. The Trojan Horse is usually remembered as a triumph of strategy. It should also be remembered as the original “trusted vendor attachment.” It arrived looking valuable, symbolic, and harmless. It came wrapped in a compelling story. It appealed to ego, fatigue, and optimism. And someone, somewhere inside Troy, approved bringing it through the gates.

The Gift That Bypassed Governance

Every organization has gates. Some are literal: firewalls, access controls, locked doors, badge readers, and vendor onboarding systems. Others are procedural: approval matrices, procurement rules, due diligence reviews, cybersecurity assessments, conflict checks, and escalation protocols. The problem is that business opportunities rarely arrive wearing a sign that says, “Hello, I am a control failure.”

They arrive as partnerships. Strategic investments. Technology platforms. Emergency exceptions. Pilot programs. Customer demands. Board-level priorities. Innovation initiatives. “Just this once” requests. Special access for a trusted consultant. A new AI tool that someone found useful. A supplier who can solve the problem quickly. A deal too good to slow down.

In other words, they arrive as gifts. The Trojans did not lose because they lacked walls. They lost because they made a poor risk decision at the gate. The control existed. The wall worked. The problem was judgment, governance, and process. A control environment is not only about having policies. It is about whether people use them when the pressure is on and the opportunity looks attractive.

When Cleverness Becomes the Risk

Odysseus was not a fool. He was a strategist. That is what makes this story so useful for compliance professionals and business leaders. Many compliance failures are not born from stupidity. They are born from intelligence used without discipline. A clever workaround can be useful. A clever workaround can also serve as a bypass of governance. The distinction matters.

Think about the employee who finds a faster way to onboard a vendor by skipping required due diligence. The sales executive who routes a discount through an unusual approval path to close the quarter. The business unit that adopts an unsanctioned software tool because IT is “too slow.” The senior leader who asks for an exception because “this is strategically important.” The team that shares sensitive information with a partner before the agreement is fully papered because “we trust them.”

Each decision may have a business rationale. Each may feel practical. Each may even produce a short-term win. But the compliance question is not simply, “Did it work? “The better question is, “What did it bypass? ”

That is the Trojan Horse problem. The horse worked because it bypassed the normal defenses. In a modern company, that may mean bypassing cyber review, procurement checks, legal review, data protection analysis, sanctions screening, financial controls, conflict review, or code of conduct expectations. When leadership celebrates only the result, the organization learns the wrong lesson. It learns that controls are for ordinary days, not important ones. That is how culture begins to drift.

The Cybersecurity Lesson Inside the Horse

The Trojan Horse is one of the oldest stories in Western literature, but it feels remarkably current in an age of cyber risk and social engineering. A malicious file. A fake vendor invoice. A compromised supplier account. A phishing email that appears to come from a trusted executive. A third-party platform with excessive access. A contractor credential that is never disabled. A software update from a source no one properly vetted. These are modern Trojan Horses.

They do not always break the wall. They persuade someone to open the gate. This is why cybersecurity is not merely an IT function. It is a governance issue. NIST’s Cybersecurity Framework 2.0 places significant emphasis on the Governance function, which addresses how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policies.

That is compliance language as much as cyber language. Who owns the risk? Who approves exceptions? Who monitors access? Who understands the business context? Who has the authority to say no? Who makes sure the organization learns from near misses? If no one can answer those questions clearly, the horse is already inside the gate.

Attractive Risks Test the Control Environment

It is easy to say no to obviously bad ideas. The real test comes when the risk is attached to something the business wants. A lucrative customer. A prestigious partner. A promising technology. A powerful executive sponsor. A deadline. A crisis. A competitor is moving faster. A board presentation next week. That is when the control environment reveals itself.

In a strong control environment, the organization can move quickly without becoming careless. It can evaluate risk without killing innovation. It can escalate concerns without making people feel disloyal. It can approve exceptions, but only with transparency, documentation, and accountability.

In a weak control environment, speed becomes the excuse for opacity. Trust becomes the substitute for diligence. Seniority becomes the overriding control. Documentation comes later, which usually means never. Compliance is invited after the decision has already been made. That is not innovation. That is improvisation with a budget.

The code of conduct should matter most when the business case is compelling. Internal controls should matter most when the pressure is real. Cybersecurity should matter most when the new tool looks exciting. Risk assessment should matter most when everyone is tired of waiting. Troy did not need a better wall. Troy needed a better approval process.

The Insider Threat Dimension

There is another uncomfortable lesson in the Trojan Horse. The Greeks got inside Troy because the Trojans cooperated with the plan. Not intentionally, perhaps. Not corruptly, necessarily. But they cooperated all the same. That is the nature of many insider threats.

The insider is not always a villain. Sometimes the insider is rushed, flattered, distracted, pressured, or insufficiently trained. Sometimes the insider believes they are helping. Sometimes they trust the wrong person. Sometimes they assume someone else has checked. That is why compliance programs cannot rely solely on good intentions.

Good people need good systems. They need clear policies, practical training, escalation paths, and a culture that rewards thoughtful skepticism. They need permission to ask, “Why are we bringing this inside the walls? ”

This is especially important in organizations where questioning a business opportunity is viewed negatively. Compliance should not be the Department of No, but neither should the business become the Department of Please Do Not Ask Too Many Questions. Healthy skepticism is not cynicism. It is stewardship.

What a Better Program Does

A better compliance program does not ban wooden horses. It asks better questions before opening the gate. Who sent it? Why now? What access does it require? What data will it touch? What assumptions are we making? Has the vendor been reviewed? Has the technology been tested? Is there a conflict? Is there a regulatory issue? What is the worst-case scenario? Who approved the exception? How will we monitor it after approval?

The point is not to slow down every decision. The point is to prevent charm, urgency, and executive enthusiasm from replacing governance. A strong program also makes risk ownership visible. If the business wants to accept a risk, that decision should be documented. If a control is bypassed, there should be a reason, an approver, a time limit, and compensating controls. If a new tool, vendor, or relationship is brought inside the organization, someone should be accountable for monitoring it. The Trojan Horse teaches that the most dangerous risks are not always those from outside. Sometimes they are the ones we invite in because they look like success.

The Compliance Takeaway

Odysseus won because he understood human nature. He knew the Trojans would see what they wanted to see: victory, tribute, closure, and a symbol of their own endurance. That is the uncomfortable lesson for corporate compliance. Risk often enters through desire. The desire to win. To move fast. To close the deal. To trust the familiar. To avoid friction. To believe the story makes the opportunity easier to approve.

Not every gift is a threat. Not every workaround is misconduct. Not every clever idea is a control failure. But every organization needs the discipline to ask whether cleverness is serving governance or bypassing it. The horse may be beautiful. The story may be compelling. The business sponsor may be persuasive. Open the gate only after the controls have done their work.

Join us tomorrow, where we consider The Lotus-Eaters: Culture Drift and the Comfort of Forgetting.