Changes Coming to California Prop. 65 Warnings
The law might suggest warnings are required in limited situations, but that’s not how it plays out
Read moreDetailsThe post Welding Fumes Are Gassing Up New Compliance Processes appeared first on Corporate Compliance Insights.
]]>The practical implication of new welding fume designations and limitations in California and internationally is less about adding another checklist task and more about where compliance sits organizationally, explains Neeta Verma, an environmental compliance professional. For compliance teams, if you’re just looking into a bill of materials, you’re running on fumes.
In July, California’s Office of Environmental Health Hazard Assessment (OEHHA) added welding fumes, along with three prescription pharmaceuticals, to the Proposition 65 list of chemicals known to cause cancer.
For compliance leaders, the welding-fumes listing is the more consequential kind of addition. It does not simply add another chemical to check against a bill of materials. It adds a process-generated exposure that can change as manufacturing and field activities change, pushing compliance from periodic product review toward continuous coordination with engineering and environmental health and safety (EHS).
Most product compliance programs, Proposition 65 included, run on a periodic model: pull the bill of materials, check it against a chemical list, collect supplier declarations, sign off and revisit at the next product change or list update. That works when the chemical is an ingredient that can be tested for, documented or engineered out.
Welding fumes cannot be managed that way because they are not an ingredient. The OEHHA listed them through Proposition 65’s Labor Code mechanism, following a study published by the International Agency for Research on Cancer. Exposure is generated by welding and related activities wherever they occur, often outside a compliance team’s normal line of sight.
A one-time review of what is in a product says nothing about whether those activities are creating an exposure.
A product can remain unchanged on paper while the exposure scenario around it changes. Production can move to a facility with different welding processes. A supplier could subcontract fabrication without changing its material declaration. Engineering may introduce new welding techniques or a field-service team might weld when that wasn’t in the plan. None of those changes necessarily appears in a bill of materials because the risk was never encoded there.
Further, even in situations where circumstances have not changed, the information often instead sits across the organization. Engineering understands manufacturing and repair processes. EHS holds exposure-monitoring and control information. Product stewardship sees the product across its lifecycle. Supply chain knows where fabrication and service work is outsourced.
That is particularly important because the OEHHA has not yet established a level of “no significant risk” for welding fumes. Organizations can’t simply anchor their assessment to an OEHHA safe-harbor number and may need to make exposure judgments based on operational facts.
Engineering change management typically involves looking into whether modification affects specifications, cost, quality or material composition. For a process-generated risk, it also needs to involve examining if this change creates or materially alters an exposure scenario. If it does, that information needs a defined route to compliance rather than leaving compliance to discover it later.
Supplier governance faces the same problem. A material declaration identifies substances in supplied materials but may say little about fabrication or finishing processes capable of generating exposure. With subcontracted production, that information can be several tiers away from where compliance normally looks.
Field activity creates another blind spot. Installation, maintenance and warranty repair can generate exposures years after a product leaves the factory with the relevant information sitting in service-management or EHS systems that a product-compliance database was never designed to see.
Compliance teams shouldn’t create another checklist to respond to these issues, but stronger information architecture. Process changes that can alter exposure should trigger regulatory review. Relevant EHS assessments should feed compliance decisions. Supplier and service governance should provide visibility into outsourced activities that create exposure.
None of this means compliance has to take control of engineering or industrial processes. Rather, compliance needs a governance channel that allows those functions’ knowledge to reach a regulatory decision before an outside party exposes the gap.
The law might suggest warnings are required in limited situations, but that’s not how it plays out
Read moreDetailsThe international outlook suggests this is not simply a California issue.
In the European Union, the European Parliament and Council reached a provisional political agreement in June on the sixth revision of the Carcinogens, Mutagens and Reprotoxic Substances Directive. The agreement brings welding fumes within the directive’s scope and directs the European Commission to assess whether additional exposure limits are needed for substances contained in welding fumes. Formal adoption is pending.
Australia has been tightening on a similar timeline. Its workplace exposure standard for welding fumes was reduced by 80% in 2024. The workplace exposure standard for aluminium welding fumes was also reduced in 2025. In December, Australia will transition from workplace exposure standards to workplace exposure limits with revised limits affecting a range of airborne contaminants.
For multinational compliance functions, these differences reinforce the same lesson: Chemical risk cannot always be understood through product composition alone. Organizations also need visibility into the processes that create exposure.
Without a standing mechanism for feeding relevant changes into compliance, information can remain invisible until an audit, customer inquiry or enforcement action. Proposition 65’s private-enforcement structure makes that an especially expensive way to discover it.
The answer is not a task force created ahead of the 2027 warning deadline and dissolved afterward. It is a durable channel between compliance and the functions that generate and understand exposure, independent of whether any individual product ultimately requires a warning.
The broader lesson is that compliance can no longer be managed from the bill of materials alone. For process-generated risks, it must also work from real-world operations back into the compliance system.
The post Welding Fumes Are Gassing Up New Compliance Processes appeared first on Corporate Compliance Insights.
]]>The post Regulatory Intelligence Company Enhesa Names New CEO appeared first on Corporate Compliance Insights.
]]>Enhesa, a regulatory intelligence provider, has named a new CEO, with Keith Berry succeeding Peter Schramme after seven years of leadership, according to a press release.
Before being named CEO of the Brussels-based company, Berry was with Moody’s for 18 years, most recently holding the position of general manager of third-party risk management solutions, the release said. Schramme will transition to chief strategy and corporate development officer through 2026 then will become senior board adviser.
“Compliance teams must absorb regulatory change at a pace no manual process can keep up with,” Berry said in a statement. “Enhesa already sets the standard with the regulatory data and expertise AI needs most, with every determination traceable back to the source legislation. I look forward to building on that foundation, further developing Enhesa’s AI and agentic capabilities that users can trust for always-on risk and compliance.”
The post Regulatory Intelligence Company Enhesa Names New CEO appeared first on Corporate Compliance Insights.
]]>The post Marketing Compliance Platform Blee Raises $20M in Series A Round appeared first on Corporate Compliance Insights.
]]>Blee, a New York-based marketing compliance platform, has raised $20 million in Series A funding round, the company announced. The round was led by Fin Capital and SMBC Fin Atlas Beyond Fund with participation from Hannah Grey VC, National Bank of Canada, Y Combinator, Penny Jar Capital, Cardumen Capital and Treasury.
The new round brings the company’s total raised to date to $27 million. Blee, which uses AI for marketing compliance, said it will use the capital to deepen its capabilities across the content lifecycle, expand into new industries and geographies and put its product in front of legal, compliance, marketing and brand leaders at large organizations.
“Marketing teams are producing more content, across more channels, faster than ever, and legal and compliance teams are still expected to review all of it manually, with tools that weren’t built for the job,” Guy Shahar, founder and CEO of Blee, said in a statement. “Whether it’s video campaigns, affiliate content or digital ads, the volume will only grow as AI agents automate creation. The companies that set up their content governance layer now are going to be in a very different position than the ones that wait.”
The post Marketing Compliance Platform Blee Raises $20M in Series A Round appeared first on Corporate Compliance Insights.
]]>The post 67% of EMEA InfoSec Leaders Say Employees Are Using Shadow Agentic appeared first on Corporate Compliance Insights.
]]>Infosec decision-makers across Europe, the Middle East and Africa are expressing their concerns about AI governance or lack thereof, according to a survey by information technology company Veeam, which found that 70% of leaders say AI is interacting with sensitive data without full oversight in their organization.
The survey of 1,000 enterprise IT, data and security decision-makers at large European, Middle Eastern and African organizations indicated that two-thirds say employees in their companies are building agentic AI workflows the company can’t fully track.
As AI governance claims a greater share of risk oversight, more leaders are feeling the pain, with 37% reporting heightened stress and anxiety of expanding compliance obligations and 40% citing the potential for personal liability or consequences from AI-related regulatory failures. Nearly 60% of respondents said their enterprises are under new corporate accountability laws in their regions.
A few other key findings:
Nearly a third of financial services employees in the UK are encountering inaccurate or misleading AI outputs, according to a survey by training provider Skillcast.
The poll of 148 UK employees in financial services concluded that 32% of workers get poor AI outputs as use of the technology becomes widespread across the industry. Despite the frequency of poor results, almost three-quarters (72%) of workers said they use AI on a daily basis and 89% say they use it at least once a week.
While guidance on AI is rising, it’s not nearly as ubiquitous. Just over 60% of finserv workers said they have a clear, accessible AI policy, while the 60% mark was higher than what the company observed in other industries, Skillcast noted.
The survey also concluded that expectations are high for AI in financial services. About 75% of financial services firms are now using AI, with another 10% planning to deploy it within the next three years, and 93% of financial services firms believe AI and machine learning will have the biggest impact on UK financial services over the next five years.
A majority of UK employers are failing to train managers on staff on discrimination and neurodiversity issues, according to a survey by compliance training company VinciWorks.
The poll of 398 HR, legal and compliance professionals found that 71% of UK employers haven’t trained managers or staff on disability discrimination or neurodiversity, and more than a third (35%) haven’t trained either group. Looking at managers and staff separately, 50% of employers haven’t given disability discrimination training to managers, while 57% haven’t trained staff on neurodiversity.
The finding comes as protected characteristics claims have spiked in the UK. A recent analysis showed cases linked to autism and ADHD nearly doubled between 2020 and 2025, rising to record levels and becoming the most common type of tribunal case in the UK.
VinciWorks also found that 43% of companies have not updated their whistleblowing policies and training since April, when sexual harassment disclosures became protected whistleblowing disclosures. More than one in 10 (11%) have no plans to update their policies or have no whistleblowing policy or training at all, the survey found.
The post 67% of EMEA InfoSec Leaders Say Employees Are Using Shadow Agentic appeared first on Corporate Compliance Insights.
]]>The post The Whistleblowing Response Playbook: 7 Scenarios & a 120-Day Clock appeared first on Corporate Compliance Insights.
]]>
How many of these scenarios have you faced?
Whitepaper
The Whistleblowing Response Playbook
What’s in this whitepaper from FaceUp:
About FaceUp
FaceUp is an ethics and compliance platform built for lean teams. Reports, investigations and cases in one place, live in hours with no IT project and yours to reshape in minutes when the rules change.
The post The Whistleblowing Response Playbook: 7 Scenarios & a 120-Day Clock appeared first on Corporate Compliance Insights.
]]>The post The Clippers Scandal vs. the Corporate Enforcement Record appeared first on Corporate Compliance Insights.
]]>A $30 million fine, loss of years’ worth of draft picks, a one-year ban for owner Steve Ballmer and a $700,000 fine for player Kawhi Leonard. That’s the NBA’s response to a yearslong scheme to evade the league’s salary cap. But alongside the sports scandal is something much more familiar to a corporate integrity audience — a greenwashing fraud and completed training that failed to prevent bad behavior. In the second of a two-part series, CCI’s Jennifer L. Gaskin digs into how the Los Angeles Clippers scandal compares to traditional corporate enforcement and what compliance, governance and ethics leaders should be thinking about no matter their industry.
Clippers owner Steve Ballmer landed himself in NBA jail, a one-year ban from team activities and games for a year. There’s a tertiary character in this story who is in actual jail right now, but even that 14-year federal prison sentence may not be the most resonant compliance lesson from the whole affair.
The Wachtell, Lipton, Rosen & Katz report covered in the first part of this series documents a failure of due diligence, of internal controls, of executive judgment and of the organizational discipline that ensures public statements and private conduct are even in the same arena. (And, according to media reports, the DOJ itself apparently thinks the case is worth exploring.)
Today, Joe Sanberg is also known as inmate No. 63886-511 at Lompoc I, a low-security federal prison in Lompoc, Calif. About 8 miles west is the Pacific Ocean, and to the north is Vandenberg Space Force Base, the site of more than a dozen SpaceX rocket launches this year alone.
Each launch delivers sonic booms and vibrations extending for miles, all the way to the Lompoc prison, where its 3,000 inmates, Sanberg now among them, can feel the ground shake but not see the sky.
For five years, the DOJ says, Sanberg, a founder and member of the board of directors of Aspiration, a fintech and sustainability services provider, ran a scheme that bilked investors and lenders out of nearly $250 million. Sanberg pleaded guilty to two counts of wire fraud in 2025 and, on June 2, 2026, was sentenced to 14 years in federal prison.
Sanberg, assistant US Attorney Bill Essayli said, was a serial fraudster who used his, “Cinderella-like background, impressive educational credentials and virtue-signaling skills to swindle investors and lenders out of hundreds of millions of dollars.”
Aspiration marketed carbon offsets, tree planting and sustainable banking to an environmentally minded customer and investor base. And the company delivered in part. Its consumer offerings, including debit and credit cards, were real, and that side of the business, since spun off under its own brand, GreenFi, is still operating today.
But its corporate business is where the real fraud happened and where both greenwashing and the Clippers come into play. Aspiration sold carbon offset and sustainability services to other companies, and that part of the business accounted for a majority of its revenue thanks to a cocktail of sham deals, secret self-payments by Sanberg and overstated letters of intent Aspiration booked as signed contracts.
Ballmer lists himself among Sanberg’s victims, but an investor lawsuit has named Ballmer as having been part of the fraud by funneling money to Leonard. The Clippers and their owner were undoubtedly on the buying end of Aspiration’s services, perhaps unknown to them at the time as greenwashing. Aspiration was the team’s founding arena partner and jersey-patch sponsor under a $383 million deal, and Ballmer personally invested $60 million in the company across 2021 and 2023. In 2022, as detailed in the first part of this series, Ballmer also approved a separate $7 million annual sustainability contract with Aspiration for The Forum — another arena he owns — with a four-year total the team’s consultant would later tell Wachtell investigators he had been handed as a budget to spend, rather than having calculated based on the facility’s actual emissions.
The lawsuit filed by 11 former Aspiration investors paints Ballmer as another defendant, not a mark. Their complaint calls the billionaire “the perfect deep-pocket partner to fund [Aspiration’s] flagging operations and lend legitimacy to [its] carbon credit business.” Ballmer’s attorneys have moved to dismiss.
How much dispassionate vetting the Clippers or Ballmer did of either Aspiration or Sanberg is unknown. In his letter to the sentencing judge, Ballmer’s attorney describes an investment decision based on trust in Sanberg’s statements and a shared passion for sustainability.
Sanberg’s public persona was disarming: a Harvard and Wall Street pedigree, anti-poverty crusader, board seats at the Sierra Club Foundation and impact-adjacent nonprofits, a briefly floated 2020 presidential run on an end-poverty platform. But a proper third-party risk management process or vendor due diligence would have revealed multiple reasons for pause:
Did vetting happen? Was it not effective? Was it ignored?
Report details host of cultural, compliance & governance fouls
Read moreDetailsAside from the Aspiration fraud, this story isn’t obviously about criminal conduct, though the DOJ has opened an inquiry. What Leonard, his uncle and team executives did is perhaps skeevy, and in some ways oafishly so, but whether it rises to the level of a criminal case remains to be seen. (As noted, Ballmer has been named as a defendant in civil litigation).
But the activities of the Clippers, Leonard and Dennis Robertson, as discussed in the first part of this series, bear a striking resemblance to the kinds of conduct state and federal corporate criminal enforcement is designed to prevent and, sometimes, punish.
And it’s worth considering how the $30 million in fines and loss of draft picks for the team, as well as the $700,000 fine against Leonard, compare to enforcement actions with similar fact patterns.
In those settings, namely at the DOJ, a series of factors can be mitigating or aggravating, and the DOJ’s Criminal Division uses a policy, the CEP, to guide how they deal with companies they are investigating. That policy is meant to encourage companies to self-report illegal acts they discover inside their organizations, and it establishes a series of fine reductions companies can receive for self-reporting and other “good” conduct after the fact, up to and including the coveted declination of charges.
If this case were a white-collar criminal proceeding, would anybody involved have won themselves any points in front of the Justice Department? It’s hard to see how they could have. Consider:
In a white-collar criminal context, the closest analog to the Clippers’ conduct is in the arena of FCPA enforcement, where the government has spent years punishing companies for using third-party intermediaries to funnel improper benefits to individuals whose favor the company wanted.
Several FCPA patterns at the DOJ and SEC are reminiscent here. In each case, a company used a legitimate commercial relationship as a vehicle for an improper benefit delivered to someone whose good favor the company sought. The specific instruments vary — consulting agreements, side letters, family-member employment — but the pattern is the same, and it’s very much like the pattern the Wachtell report describes.
Which brings us to how the NBA’s punishment of the Clippers stacks up. At the end of the spectrum is the coveted declination, which the team would have no hope of, and at the other end is a penalty in the low billions globally. Where the Clippers penalty sits on that spectrum is up for debate, but compared to the team’s operating income, the $30 million fine is about 20% of what the Clippers made in 2024-25, their best recent year. That places the fine in the realm of what other companies have paid compared to their global income.
But for the team’s multibillionaire owner, it would be the equivalent of a person with a net worth of $100,000 being fined $19. It’s a rounding error. Calling it a drop in the bucket is an insult to drops in buckets.
It’s easy to see this case as uniquely sports-related. Most compliance practitioners don’t work in companies under a cartel-like system where a centralized body does the rule enforcing, as in the case of the NBA and other sports leagues.
But the organizational failure patterns here are instructive regardless of industry:
The post The Clippers Scandal vs. the Corporate Enforcement Record appeared first on Corporate Compliance Insights.
]]>The post How Blockchain Intelligence Became Essential to Corporate Compliance appeared first on Corporate Compliance Insights.
]]>Crypto was initially built on the promise of permissionless finance, a system with no gatekeepers, no intermediaries and no paperwork. However, as the adoption of digital assets has grown, that original vision has collided with the strict realities of the traditional financial system, writes crypto intelligence writer Finn Grant. With regulators cracking down globally, crypto compliance has evolved from an abstract concern into a central operational requirement for survival.
For more than 15 years, the regulatory stance towards digital assets was somewhat ambiguous, but the rules are finally firming up. The Financial Action Task Force (FATF) reported in a June 2025 update that travel rule frameworks are already adopted or in progress across 99 different jurisdictions. With approximately $51 billion in on-chain activity linked to illicit actors in 2024 alone, regulators are pushing aggressively for industry-wide compliance.
Today, businesses involved in crypto must navigate a complex web of obligations:
The consequences of ignoring these regulations can destroy a business. Regulators have made it clear that they will aggressively pursue platforms operating with inadequate AML and KYC programs.
Enforcement actions in 2025 alone saw crypto exchanges bear $927.5M in AML/CFT penalties. Historical precedents are even steeper: Binance famously pleaded guilty in the US and paid over $4 billion to resolve its criminal liability, while BitMEX faced a $100 million enforcement action for failing to file suspicious activity reports (SARs) and institute proper AML programs. In Europe, more than 50 crypto firms had their licenses revoked under MiCA as of November 2025 for failing to meet compliance standards.
To survive in this environment, companies require a functional, risk-based compliance program, and traditional finance tools simply do not work on-chain. The public nature of blockchain ledgers creates a unique advantage: every transaction is recorded permanently and is fully auditable.
This is where blockchain intelligence steps in to bridge the gap. By using advanced analytics platforms like Arkham, compliance teams can link raw cryptocurrency activity to real-world entities. Arkham deanonymizes blockchain transactions, transforming alphanumeric noise into actionable intelligence for compliance and investigative purposes.
A customer may pass initial KYC checks at onboarding but later receive funds from a compromised source. Pure KYC cannot catch this, but continuous transaction monitoring powered by blockchain intelligence can. By integrating the Arkham API into your internal systems, you gain access to Ultra, Arkham’s proprietary crypto address-matching engine. This allows enterprise compliance teams to customize data flows, monitor transactions in near real-time and screen incoming deposits against known illicit sources before funds are ever accepted.
As regional frameworks like MiCA reach full enforcement and institutional capital demands robust compliance counterparties, having the right tech stack is no longer optional.
The post How Blockchain Intelligence Became Essential to Corporate Compliance appeared first on Corporate Compliance Insights.
]]>The post The Compliance Job Interview 2026 appeared first on Corporate Compliance Insights.
]]>The compliance job interview hasn’t kept pace with the profession. Hiring managers still rely on questions that reveal little about whether a candidate can actually navigate gray areas, influence resistant stakeholders or build a defensible program under pressure. And candidates often walk in underprepared — or worse, unprepared to evaluate whether the organization deserves them.
This toolkit, developed with guest editor Mary Shirley, is built to fix both problems. Organized by experience level, it explains not just what hiring managers are asking today but what they’re actually trying to learn and how candidates can respond with substance rather than just performance.
It also includes something most interview guides leave out: a robust set of reverse-interview questions candidates can use to assess an organization’s genuine commitment to compliance. Here’s a look at what you’ll get:
Instant Download: Read it Now
Can’t see the download form? Disable your ad blocker.
The post The Compliance Job Interview 2026 appeared first on Corporate Compliance Insights.
]]>The post Increased Anonymous Reporting is a Signal Compliance Leaders Cannot Ignore appeared first on Corporate Compliance Insights.
]]>Against a backdrop of job insecurity, general instability and fear of retaliation, increased anonymous reporting will continue, Gregory Keating of Littler predicts. That is unless corporate leaders and compliance professionals make meaningful strides in their programs.
A trend has emerged that should cause tremors throughout the compliance community. Recent benchmarking and survey data indicate that anonymous reporting on whistleblower hotlines has increased or remained elevated in recent years, reversing an earlier trend toward named reporting.
NAVEX Global, which canvassed more than 2 million reports across over 4,000 organizations, reported in its 2025 benchmark report that about 52% of reports in the US were made anonymously. In a 2026 report, Ethico found a 5% drop in the number of self-identified reporters from the previous year, the largest single-year reversal in its dataset.
Seasoned compliance professionals should recognize that this is a dangerous development. While the availability of anonymous reporting is a widespread and even required feature of reporting policies and procedures, a trend toward an increased incidence of anonymous rather than named reporting introduces challenges to an organization’s efforts to identify and remedy misconduct. Complaints by anonymous reporters are significantly more challenging to investigate and often suffer from significantly lower substantiation rates. The point is not to close the door to anonymous reporting but rather to create a workplace culture in which employees with concerns feel comfortable and even welcome to come forward, knowing they will be met with serious interest and steadfast protection from retaliation.
Those familiar with organizational risk understand that the efficacy of an organization’s compliance program can be seen in the overall level and quality of reporting. On one end of the spectrum is crickets — little to no reports or communications emanating from employees up to the organization. On the other end is a steady volume of reporting where individuals come forward in person. In the middle lies continued reporting from those in the organization but in a manner whereby the reporters are more inclined to choose anonymity.
A healthy organization should experience a steady volume of compliance reports with reporters willing to identify themselves as they come forward. Professor Kyle Welch at George Washington University accessed and analyzed enormous amounts of data from hotline reporting channels. He concluded in 2020 that organizations with robust internal reporting have stronger cultures and better business outcomes, including higher profitability and return on assets, reduced litigation costs and fewer external reports to regulators.
By contrast, a culture of silence and rare reporting in the workplace is widely viewed as a leading indicator of compliance risk. A 2022 study published in MIT Sloan Management Review found that silence among workers and an unwillingness to report is directly tied to a feeling of being psychologically unsafe.
Until as recently as 2023, empirical data indicated a trend toward an increased willingness among employees to report suspected misconduct — likely the effect of increased focus on robust compliance programs and effective training. In a 2023 survey, ECI found that 72% of employees reported misconduct when they observed it. This reflected a then-record-high reporting rate.
But this upward trajectory has taken a sharp and troubling detour in the past three years. In what has been described as a trend toward “scared reporting,” an increasing number of employees have indicated that while they are generally inclined to report misconduct when they observe it, many of those same employees in fact chose not to do so when they witnessed it. Ethisphere’s 2024 ethical cultural report, based on 2 million responses from around the world, found that while 93% of employees said that they were inclined to report misconduct only 50% actually did so.
What has caused this trend? Fear. Recent developments, including geopolitical uncertainty and the rapid rise of AI in the workplace and attendant concerns about job security, have increased anxiety and uncertainty in the workplace. A 2025 Pew Research Center survey of over 5,000 employees found that 52% are worried about the future of AI in the workplace and nearly a third believed AI will lead to fewer job opportunities for them in the future. In that environment, employees may be more likely to worry that raising concerns will mark them as difficult, disloyal or expendable.
Recent data reflects that fear of retaliation is a significant factor causing workers not to report. The most recent global surveys are all consistent in finding a noticeable increase in employees reporting that they fear retaliation should they speak up about workplace misconduct. According to the Equal Employment Opportunity Commission’s enforcement and litigation statistics, retaliation is the No. 1 employment law claim in the US, making up roughly 48% of all claims.
When a friend is the target of a report, resist the urge to disrupt established processes
Read moreDetailsThe time is now for compliance professionals and the organizations they support to invest in concrete measures that will encourage a return to self-identified reporting and help avoid the potential spiral into a workplace culture of fear, silence and avoidance.
Four recommendations should be considered.
First, research overwhelmingly demonstrates that the optimal starting point for any workplace concern is with an employee’s manager. Organizations must engage in training of managers so that they understand the pivotal role they play, are able to recognize nuanced concepts like what is “protected activity” and an “adverse action” and understand their obligation to communicate effectively with compliance, HR and legal.
Second, organizations should consider holding managers accountable by measuring and ranking their commitment to compliance annually as a metric in their performance evaluations.
Third, organizations should also audit and modify their investigation protocols to ensure that they have communication channels in place to respond to anonymous complaints. These can be challenging to investigate, but numerous vendors have established protocols that allow the organization to communicate back to anonymous reporters, who should be given the opportunity to remain anonymous yet cooperate by either providing more specific information or meeting face-to-face with an independent third-party investigator retained by the organization.
Finally, organizations should endeavor to create a culture in which good-faith reporting is modeled, encouraged and met with a prompt and effective response. An organization must articulate and commit to a strong anti-retaliation policy, protecting and encouraging employees who come forward and continuously demonstrating that others can come forward without fear of retaliation.
The post Increased Anonymous Reporting is a Signal Compliance Leaders Cannot Ignore appeared first on Corporate Compliance Insights.
]]>The post AI Is a Stickler for the Rules, but Rules Don’t See Everything appeared first on Corporate Compliance Insights.
]]>Rules are made for AI to follow, but exceptions to rules come from human experience. Neil Sahota, AI strategist and board director, discusses the balance of rules, experience, precision and exceptions needed to balance AI automation. Get that mix wrong and AI could commit a major foul.
The referee makes the call. Seconds later, play stops.
It happens across nearly all sports, where a video assistant referee (VAR), video reviews and instant replays have become ubiquitous in enforcing rules. Different angles expose details the human eye could miss, technology provides the evidence, and officials apply the rule. The decision is made … and people still argue about the call.
Our instinct is to blame VAR, but nothing malfunctioned. The technology accurately captured what happened. The officials correctly applied the rule. The system worked exactly as designed.
But what if the problem was the rule itself?
This question goes beyond sports. As companies embed AI into fraud detection, lending, hiring, pricing, procurement and other decisions, they excel in consistency. This is not always good news.
People are inconsistent rule followers. We overlook things, we make exceptions. AI eliminates much of this variation. Give a machine a rule, and it will apply it to the first decision and the millionth with remarkable consistency. But put this in the context of a poorly written or ineffective rule: People may apply a bad rule inconsistently, but AI won’t. AI will apply the bad rule a million times.
AI’s greatest governance risk is consistency at scale. Worse, what companies call human inconsistency isn’t always an error. Sometimes, it is experience.
Imagine veteran fraud investigators who repeatedly override the same category of AI-generated alert. Management sees exceptions. Compliance sees deviation. The AI team sees users who aren’t trusting the model. But what do the investigators see?
Perhaps they learned through thousands of cases that a particular customer behavior looks suspicious according to policy but is usually legitimate. This judgment call won’t appear in the procedure manual because it springs from years of human experience.
Historically, this is how organizations operated. The official process says one thing while experienced employees make thousands of tiny adjustments that allow the process to work in the real world. Then, AI arrives. Management says: “Automate the process.” But which process?
Typically, we encode the process we can see: the documented rules, decision trees, thresholds and procedures. Yet, the thousands of judgment calls employees make between those steps are much harder to capture.
The company believes it automated the operating model. Unfortunately, more often, it automated the function of how its operating model actually works.
AI scales safety risks in healthcare to unprecedented levels
Read moreDetailsThis is where the VAR offers a lesson. While better technology tells us with better precision what happened and if a rule was followed, it cannot determine whether the assumptions behind our rules still make sense.
In fact, greater precision may expose weaknesses that human inconsistency previously concealed. This should change how executives think about AI governance. Yet, we rarely ask: What human judgment makes this process work that is not documented? The answer hides in the exceptions.
Before AI eliminates your exceptions, find out why the exceptions are there and what knowledge they may signal. Consider what people interpret and establish as guidelines. Once embedded into an AI-enabled workflow, the same policy becomes executable infrastructure and operates continuously at enormous scale. This creates a different question for executive teams and boards: What assumptions do people turn into infrastructure?
During almost any sporting match, millions of people watch VAR or video replays and still question the call. Inside a company, there is no stadium watching as AI converts yesterday’s assumptions into tomorrow’s decisions.
Ironically, the true danger is that AI may understand them perfectly.
The post AI Is a Stickler for the Rules, but Rules Don’t See Everything appeared first on Corporate Compliance Insights.
]]>