Categories
Blog

From Policy to Proof: Six Compliance Priorities for the Next 90 Days

Editor’s note: I am a columnist for Compliance Week.

Compliance Week recently released its Practitioner’s Briefing, which “is crafted as a high-level recap of Compliance Week’s 2026 National Conference (CW 26), held in Washington, D.C., in May. Whether you were there or wished to be, this briefing will bring you up to speed. The briefing captures the six themes that pervaded three days of panel discussion and the networking conversations between them, with practical actions you can implement in the next ninety days.”

The compliance profession is entering the proof era. Policies still matter, but regulators, boards, and employees are asking a harder question: Can the organization demonstrate that its controls operate in practice? That is the central lesson from the Practitioner’s Briefing. Across six themes, the briefing describes a function under pressure from rapid AI adoption, faster whistleblower timelines, redistributed enforcement, expanding third-party exposure, and sharper board expectations.

Today I want to explore the themes and initiatives from the Practitioner’s Briefing. This is not about six disconnected initiatives covered at CW 26. It is an operating model that connects governance, data, accountability, and escalation around existing risks. You can use the next 90 days to produce evidence that the program knows where its risks sit, who owns the controls, how failures surface, and what happens next.

AI Governance: Accountability Must Follow Adoption

AI makes the policy-to-proof gap visible. The Practitioner’s Briefing reports that 83 percent of compliance functions have AI in production, while only 25 percent of leaders are confident in the governance controls. That is not primarily a policy problem. It is an ownership and control-design problem.

Start with your AI inventory. A defensible AI register should identify the tool, approved use case, business owner, data involved, vendor, model, access rights, validation method, human reviewer, retention rule, incident path, and kill-switch authority. Tool approval by IT cannot substitute for use-case approval by Legal, Compliance, Privacy, Security, and the accountable business leader. One platform may be acceptable for drafting training content and unacceptable for evaluating employees or third parties.

The NIST AI Risk Management Framework and ISO/IEC 42001 can help organize this work, but a framework is not the control. The control is the approval record, test result, exception log, monitoring evidence, and documented decision. Compliance should also assume that prompts, summaries, transcripts, and agent logs are discoverable business records. Retention and legal hold procedures must catch those artifacts before the first dispute or investigation forces the question.

AI in Compliance Operations: Redesign the Work

The Practitioner’s Briefing draws a useful line between AI enablement and AI theater. Strong programs redesign a workflow around AI. Weak programs bolt AI onto a slow process and call it transformation. Due diligence, regulatory tracking, training development, and self-service policy guidance are sensible starting points because the work can be scoped, tested, and measured.

Each deployment needs acceptance criteria. Validate performance against known outcomes, constrain source material where accuracy matters, monitor drift, require human review for high-risk decisions, and define escalation when the system is uncertain. Measure return on investment first in hours returned to higher-value work. Faster output that creates more review, remediation, or false confidence is not efficiency. It is control debt.

Speak-Up and Investigations: Trust Is the Control

The Practitioner’s Briefing reports that eight in ten US employees witnessed misconduct during the prior year, yet fewer than three-quarters reported it. That gap is not solved by adding another intake channel. It is solved by showing employees that reporting is safe, fair, and consequential.

One of the Practitioner’s Briefing’s most practical recommendations is to audit the career outcomes of the last 20 employees who raised concerns. Review performance ratings, promotions, transfers, compensation, leave, and departures. Patterns in those records may reveal retaliation or career stagnation that hotline statistics will never show. Pair that review with defined post-report monitoring and documented check-ins with reporters.

Speed is now part of program effectiveness. The briefing highlights a 120-day DOJ window to investigate qualifying internal reports and decide whether voluntary self-disclosure is appropriate. CCOs should calendar that period, establish rapid triage, identify decision rights, preserve evidence immediately, and maintain a standing disclosure team. The goal is not a rushed conclusion. The goal is to prevent delay, unclear ownership, or inadequate resources from deciding for the company.

Enforcement Has Shifted, Not Disappeared

Lower federal case counts are not a safe harbor. The Practitioner’s Briefing describes enforcement as redistributed across state Attorneys General, self-regulatory organizations, the False Claims Act, and future matters still inside applicable limitation periods. A quieter headline environment can encourage exactly the wrong management response: reduced staffing, deferred remediation, and lower investment in controls.

The business discipline is straightforward. Monitor the full enforcement ecosystem, not one federal docket. Maintain the strictest applicable standard as the practical global baseline. Preserve the ability to investigate, cooperate, remediate, and disclose. Most importantly, do not confuse a change in enforcement cadence with a change in underlying legal or ethical risk. Today’s control gap may simply be tomorrow’s case.

Third-Party Risk: Manage the Entire Lifecycle

Third-party risk management is no longer a narrow anti-bribery process. The Practitioner’s Briefing places sanctions, forced labor, transnational crime, material support exposure, supply-chain integrity, and embedded AI inside the modern TPRM remit. That expansion requires a move from onboarding diligence to lifecycle control.

Monitor material relationships from selection through offboarding, with risk-based refreshes, event-driven alerts, beneficial ownership checks, adverse media review, and clear remediation ownership. For AI-enabled vendors, procurement should require disclosure of material fourth- and fifth-party dependencies. Contract terms should address model provenance, data lineage, audit rights, incident notice, control changes, and the ability to explain consequential decisions.

List screening alone is increasingly thin protection. High-risk supply chains may require route mapping, chokepoint analysis, and source-verified information reviewed in context by humans. AI can compress the initial diligence cycle, but it does not replace judgment on coercion, shell companies, access payments, or other facts that demand legal and operational analysis.

Board Reporting and Culture: Lead With the Problem

Directors want a compliance report that begins with bad news, explains the risk, and shows the response. That is the board-reporting message in the Practitioner’s Briefing. Activity counts belong in the appendix. The main discussion should address control failures, investigation aging, retaliation indicators, overdue high-risk diligence, AI exceptions, remediation status, and emerging exposure compared with peers.

This approach also supports a Caremark-style oversight record. The board needs credible information systems, timely escalation of red flags, and evidence that management and directors responded. A between-meetings protocol with the audit or risk committee chair is therefore a control, not a courtesy.

Culture is equally operational. The briefing reports that direct managers and immediate colleagues exert the strongest influence on 80 percent of employees, while only 58 percent of organizations evaluate how results were achieved. Compliance should train managers to receive concerns, audit incentives as rigorously as financial controls, and make conduct part of performance and promotion decisions. The real code of conduct is what the organization rewards, tolerates, and corrects.

A 90-Day Agenda for CCOs

  1. Build the evidence map. Select the highest-risk obligations in AI, investigations, and third-party management. For each one, identify the owner, control, evidence, escalation path, and board metric.
  2. Test AI governance. Reconcile the official AI inventory with procurement records, browser access, expense data, and employee attestations. Review several approved use cases from request through monitoring.
  3. Stress-test investigations. Tabletop a significant internal report against the 120-day decision window. Confirm preservation, privilege, staffing, disclosure authority, and board communication.
  4. Rebuild TPRM around lifecycle risk. Segment critical third parties, define continuous-monitoring triggers, review AI dependencies, and assign remediation deadlines with accountable owners.
  5. Change the board report. Put the three most significant problems first. Add peer comparison, trend data, remediation aging, and decisions required from the board or management.

The Compliance Lesson

The Practitioner’s Briefing is not fundamentally a technology story or an enforcement story. It is a program-effectiveness story. The effective compliance function can identify risk, assign accountability, test controls, learn from failures, and show its work. Policies establish expectations. Evidence establishes credibility. In the next 90 days, that distinction should drive the agenda of every CCO, executive team, and board committee responsible for corporate integrity.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance: Episode 32 — Shout Out to CCI

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

In this episode of 2 Gurus Talk Compliance Podcast, hosts Kristy Grant-Hart and Tom Fox discuss major developments in the compliance world. The topics include the potential scope of Boeing’s monitorship related to the 737 MAX crashes, Italian raids on luxury brand manufacturers for modern slavery violations, insights from the year’s biggest risk assessment survey, and Florida man’s futile gun battle with a Walmart drone. Additionally, they delve into articles from Corporate Compliance Insights on well-being washing, Supreme Court’s rollback of Chevron deference, trade sanctions screening, effective use of AI in compliance, and the importance of regulating ephemeral messaging. The episode concludes with an entertaining Florida man story involving a shootout with a drone.

Stories Include:

  • To the DOJ: Go Big on Boeing. (CCI)
  •  Well-Being Washing (it’s a real thing). (CCI)
  •  Upgrading TPRM in the age of AI. (CCI)
  • Sanctioned or not? (CCI)
  • International Comms Compliance. (CCI)
  • Raids Find Luxury Handbags Being Made by Exploited Workers in Italy (WSJ)
  • Supreme Court Overrules Chevron, Sharply Limiting Judicial Deference To Agencies’ Statutory Interpretation (Gibson Dunn)
  • 2024 State of Risk & Compliance Report (NAVEX)
  • Is work taking over your life? Here’s how to reclaim your time. (WaPo)
  • A Florida man’s futile gun battle with a Walmart drone. (Fortune)

Resources:

Kristy Grant-Hart on LinkedIn

Spark Consulting

Prove Your Worth

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
FCPA Compliance Report

Alastair Parr on New Developments in TPRM

Welcome to the award-winning FCPA Compliance Report, the longest running podcast in compliance. In this special episode, I am joined by Alastair Parr, SVP of Global Products & Delivery at Prevalent to discuss developments in third-party risk management.

In this episode we consider:

  • Why is a comprehensive 3rd risk management solution not simply a nice to have but a must to have now?
  • Why is 3rd party risk management so much critical after the pandemic and the Russian invasion of Ukraine?
  • Improving the UX for TPRM.
  • Why has simplifying the UX for TPRM eluded most providers so far?
  • How can the UX be improved so the information which is the most vital and most relevant is captured and more importantly can be actioned?
  • How can the process of obtaining TPRM information to implementing controls to manage the risk be improved?
  • How can companies automate data gathering by using a single targeted assessment by building in targeted compliance mappings for legal or regulatory requirements?
  • Other areas of compliance such as modern slavery and human trafficking?
  • Do you see continued evolution of 3rd party risk management into 2025 and beyond?

Resources

Alastair Parr on LinkedIn

Prevalent

Being a Compliance Officer is Awesome on Amazon.com

Categories
Innovation in Compliance

You Can’t Outsource Risk with Sandeep Bhide


 
Sandeep Bhide is the Vice President of Product Management at ProcessUnity, a company that is making good governance, risk, and compliance (GRC) practices and tools available to organizations via third-party risk and cybersecurity program management tools. Tom Fox welcomes him to this week’s show to talk about their Third-Party Risk: A Turbulent Outlook Survey report and how ProcessUnity helps their clients.
 

 
The Purpose of ProcessUnity
Tom asks Sandeep to explain the basis of ProcessUnity and the key products and services they are offering. Sandeep says that the company offers cloud-based solutions that provide help for organizations of all sizes, that allows them to automate their risk and compliance programs. He adds that it is an easily customizable program that reduces manual administrative tasks and allows customers to focus on “the more strategic risk mitigation activities”. ProcessUnity has the ability to review the company’s GRC program and deliver great results quickly. 
 
Third-Party Risk: A Turbulent Outlook Survey Report 
Tom wants to know what was the intent behind this report and how it came to fruition. Sandeep states that the objective of the study was to determine how well organizations understood and managed risk associated with their third-party partners. 301 IT and cybersecurity decision-makers and influencers participated in the survey, and they were asked about their concerns and challenges when managing certain risks, and how it has impacted the security incidents related to their third-party partners. Sandeep shares the overall findings of the survey found that: 

  • Third-party relationships continue to expand exponentially; 
  • Companies continue to seek outsourced services and software in order to perform optimally and to replace talent and supply sources due to the pandemic;
  • The majority of respondents have experienced an IT security incident over the last two years because of a third-party relationship. 

 
The Gathering Storm
Tom asks Sandeep to explain the concept of “the gathering storm” and the technological solution ProcessUnity provides to help navigate it. Sandeep explains that the term refers to a supply chain attack executed by “close third-party relationships that have either physical or network access to equipment and premises and those that provide software vital to a business’ operation.” Sandeep then warns that companies should vet these third parties since their role is so important. Most companies would rather focus on their core businesses, however; they feel it doesn’t make economic sense for them to do everything themselves and third parties provide the types of talent they need to properly conduct their business. Sandeep comments that “companies can outsource the work which is an imperative for them, but they can’t outsource the risk”. To manage your third parties, you must have multiple in-house and out-house methods to vet them, including questionnaires or assessments. You have to get to know your partners because they have the most risk attached to them.
 
Resources 
Sandeep Bhide | LinkedIn | ProcessUnity
 

Categories
Innovation in Compliance

Managing Compliance Complexity with Mac Bartine


 
Mac Bartine is the CEO of SmartRIA, a market-leading compliance software platform. Tom Fox welcomes him to this week’s show to talk about his company’s services and contributions to the compliance sector, what SmartRIA offers clients in terms of cybersecurity, and the future of technology solutions.  
 

 
The Minimum Viable Product
The Minimum Viable Product (MVP) is the first part of the startup process for platforms. It is recognizing the problems within your platforms and also believing that you can solve them. Mac explains to Tom that the problem SmartRIA solution identified in terms of the MVP is the compliance obligations. So many individuals are not experienced in managing compliance in their given industries, and so need a source of structure that understands where they are. SmartRIA offers them that, as well as the tools and frameworks needed. 
 
Vendor Due Diligence & Data Governance
Vendor due diligence and vendor management are key to managing cybersecurity risk. “You have to understand who you’re working with and what precautions they’re taking as a business to protect you from cyber risk,” Mac tells Tom. Having access to the proper documentation that reflects this is also important. SmartRIA has a plethora of different policies and procedures to protect clients’ data and takes the lists of vendors their clients have and itemizes each risk. Data governance falls under the same bracket as due diligence, that is, who has access to the vendors and what devices they use to access the data from those vendors.
 
SmartRIA as an SEC Solution
The solutions that you use for compliance obligations have to be done in a way that documents everything as it happens. “If it isn’t documented, it didn’t happen,” Mac says. Internal auditors aren’t in the position of giving the benefit of the doubt because they have no evidence of due diligence. SmartRIA has the tools to help its clients through this by way of PDF files, workflows, and documents. 
 
To The Future
Tom asks Mac what the future will be like for technology solutions. Regulations in every industry are going to increase. “Across every industry, there is an increasing need for cybersecurity-related evidence, and tracking of what’s happening in that space,” Mac says. Data governance and vendor due diligence are big parts of that, but compliance management is going to also become more important.
 
Resources
Mac Bartine | LinkedIn | Twitter 
SmartRIA
 

Categories
Innovation in Compliance

Exiger on the Evolution in Supplier Compliance in COVID – Third-Party Party Risk Management Solutions with Erika Peters and Skyler Chi


Welcome to the fifth and final episode of a special five-part podcast series, sponsored by Exiger, on topics From Third-Party Risk Management to Supply Chain Risk Management: Exiger on the Evolution in Supplier Compliance in COVID. Exiger was founded to fight financial crime, fraud and terrorist financing by introducing technology-enabled solutions to the market’s biggest supply chain, risk, investigation, litigation, and compliance challenges. A global authority on risk and compliance, Exiger serves the world’s largest banks, Fortune 1000 companies and government agencies and regulators. Over the past five episodes, we have put a spotlight on Financial Institutions with Tara Loftus and Samar Pratt; focus on corporations with Aaron Narva and George ‘Ren’ McEachern; consider the Federal Government and Supply Chains with Carrie Wibben and Vishnu Anantatmula; review the pillars of good compliance with Brandon Daniels and Carrie Wibben; and end with a review of third-party risk management solutions with Erika Peters and Skyler Chi.
Today, Part 5, we conclude with a review of third-party risk management solutions with Erika Peters and Skyler Chi. Peters is an Associate Managing Director based in Exiger’s New York office, where she focuses on the firm’s financial crime compliance and assurance practices. Chi is an Associate Director based in Exiger’s New York office. With nearly ten years of forensic accounting and investigative experience he leverages world-class technology (e.g., SQL, Python, Tableau, natural language processing and machine learning) in order to aid in financial investigations and government clients in bank/investment statement reviews and analyses, data analysis efforts, large document analyses, and extensive e-mail reviews.
For more information on Exiger, click here.
For more information on Erika Peters, click here.