
Sign up to save your podcasts
Or


In this episode of Corruption, Crime and Compliance, Michael Volkov traces the decades-long relationship between compliance and data, from the profession's earliest, checkbox-style attempts to measure program effectiveness through crude proxies like hotline volume and training completion rates, through the rise of continuous monitoring systems, integrated dashboards, and key risk indicators that enabled expedited auditing and near-real-time visibility, and finally to the current AI-driven era, where machine learning and natural language processing can surface subtle risk patterns no human-authored rule would catch and compress the gap between detection and action to hours rather than months. He argues that each phase of this evolution was driven not by strategic foresight but by escalating business, regulatory, and litigation risk, first around proving program effectiveness itself, then data privacy and cybersecurity, and now AI governance, and closes by cautioning that AI monitoring tools will only perform as well as the underlying data infrastructure and discipline a compliance function has already built.
An AI tool isn’t a piece of software. It’s a locked door, and you have no idea how many people have a key.
Quick preview ahead of tomorrow’s webinar on AI and third-party risk, because I want you thinking about this before we dive in.
Here’s the mental shift every compliance officer needs to make: every AI tool your company adopts is a third-party vendor relationship, often a more complicated one than your typical software vendor.
Why? Because a lot of AI products are built on top of someone else’s underlying model.
Your data can pass through multiple companies before it’s fully processed, and you may not even know all the hands it touches along the way.
That means your vendor due diligence questions need to go further than usual.
Does this vendor train on your data?
Can that be turned off contractually and technically?
Where does the data actually live?
What subprocessors and underlying model providers are in that chain?
These aren’t nice-to-have questions anymore. They’re the whole ballgame.
Tomorrow we get into the specifics, but start here: if your third-party risk program hasn’t been rebuilt around AI-specific questions, it’s already out of date.
The Ethics and Compliance Q and A show is produced by One Stone Creative.
In this episode of Corruption, Crime and Compliance, Michael Volkov rounds up three major economic policy developments happening alongside Operation Economic Outcast: the State Department's rescission of Syria's nearly 47-year State Sponsor of Terrorism designation, opening the door to renewed trade and eased export controls; an escalating tariff war with Canada following the collapse of USMCA renewal talks, including a 50 percent tariff on roughly $20 billion of Canadian goods and matching retaliation; and the newly enacted Lindsey O. Graham Sanctioning Russia and Iran Act, with its novel tariff structure reaching up to 500 percent on Russian goods and up to 100 percent on top importers of Russian energy. Volkov argues these developments, read alongside the Iran crackdown, show an administration deploying economic tools more aggressively and across more simultaneous fronts than at any point in recent memory, and he closes by urging listeners to treat geopolitical risk assessment as a continuous function this quarter rather than a periodic exercise.
For anyone hoping a friendlier DOJ can make their old charges disappear, a federal judge just reminded us that vanishing requires his or her permission.
Big development out of Brooklyn federal court.
DOJ tried to drop the remaining bribery and obstruction charges against executives tied to Indian billionaire Gautam Adani.
The judge said no.
Judge Nicholas Garaufis ruled that Deputy AG Trent McCotter’s justification for dismissal didn’t include the actual facts needed to support it, just conclusions.
McCotter argued weak U.S. jurisdictional ties. Garaufis said essentially: show me the facts, not just the argument.
He’d already rejected an earlier diplomatic strain argument too, noting some conduct happened right here in the U.S.
There’s real context here. Reporting suggests DOJ’s posture shifted after Adani’s team hired a lawyer personally connected to the president.
None of that decided the legal question, but it’s exactly why a court might scrutinise DOJ’s reasoning more closely instead of rubber-stamping it.
Here’s why this matters beyond one case: a change in DOJ’s political priorities doesn’t automatically make an indictment disappear.
Courts still have to sign off.
Don’t assume that a friendlier enforcement climate erases charges already on the books.
The Ethics and Compliance Q and A show is produced by One Stone Creative.
In this episode of Corruption, Crime and Compliance, Michael Volkov devotes a full deep dive to Operation Economic Outcast, Treasury's aggressive campaign to close off Iran's remaining financial and commercial channels following the collapse of a June 2026 US-Iran memorandum of understanding. He walks through OFAC's expansion of sectoral sanctions into aviation, digital assets, gold, shipping, and technology with no U.S. nexus required, the suspension of general licenses that has disrupted universities, testing organizations, and academic and sports exchanges, a new presumption-of-denial licensing policy, updated Strait of Hormuz guidance establishing sanctions risk even without any payment changing hands, and a coordinated crackdown on banks in the UAE, Turkey, and Russia serving as Iran's financial lifelines. Volkov closes with concrete steps: reassess Iran-connected exposure immediately in the newly covered sectors, treat any activity tied to a suspended general license as ended rather than pending renewal, and build enhanced due diligence for Hormuz transits and newly designated bank counterparties.
If you’re planning for 2027 with 2025’s budget in mind, your compliance program is about to fall on its face.
KPMG just surveyed 725 chief compliance officers, and the headline is simple: the job has fundamentally expanded, and if your 2027 plan doesn’t reflect that, you’re already behind.
75% of CCOs say cybersecurity and data privacy are top investment priorities.
77% say the same about data analytics.
That’s not a coincidence. You need the analytics to actually use the cybersecurity investment.
But here’s the number that struck me most: 81% of CCOs feel confident collaborating with their cybersecurity teams.
That’s not an accident. That reflects compliance functions building real structural partnerships with security and resiliency teams, not waiting for an incident to force the relationship into existence.
And on AI, 68% describe themselves as mixed, leaning positive. Not hype, not fear. Measured adoption, concentrated in risk assessment, predictive analytics, and training.
The bottom line: compliance isn’t just policy and training anymore. It’s operational resilience.
If your budget doesn’t reflect that shift, fix it now.
The Ethics and Compliance Q and A show is produced by One Stone Creative.
In this episode of Corruption, Crime and Compliance, Michael Volkov examines two significant executive sentencings handed down within a day of each other: Tomás Niembro Concha, the former CEO of Puerto Rico's now-defunct Nodus International Bank, sentenced to more than nine years for a multiyear fraud scheme that fleeced his own bank of nearly $25 million and a scheme to evade U.S. sanctions on Venezuela by secretly selling a sanctioned individual's foreclosed home back to him through a front company; and Javier Aguilar, a former Vitol oil trader, sentenced to four years, well below the twelve DOJ sought, for bribing officials in Ecuador and Mexico to win Vitol more than $500 million in state oil company business. Volkov draws out the common threads between the two cases, shell entities, sham documentation, and years of concealment from the very oversight functions meant to catch it, and highlights Aguilar's rejected defense that the bribes were merely industry custom as a rationalization compliance programs should treat as a red flag whenever they hear it internally.
Lo and behold, Boeing gets sued over another safety crisis, and this time Boeing actually won.
Want to know why? They kept the receipts.
Yesterday I told you about two cases where Delaware let Caremark claims move forward. Today, the case where the board won, and its most important Caremark decision in years.
Boeing again. New litigation, this time over the 2024 Alaska Airlines door plug incident. Given Boeing’s history, you’d think this case had real legs.
Delaware dismissed it anyway.
Why? Because the record showed the board had dedicated safety committees, got regular reports on manufacturing and quality, discussed the issues repeatedly, and got updates on remediation.
The court said Caremark doesn’t ask whether oversight succeeded. It asks whether directors consciously looked away.
Here, they didn’t.
Here’s the takeaway for every board and every compliance officer: a functioning reporting system, real information flow, and genuine engagement is real protection, even when the company faces another crisis.
Build that record now, before you need it in litigation, because in Delaware, detailed board minutes showing you are paying attention might be the single best defense you have.
The Ethics and Compliance Q and A show is produced by One Stone Creative.
In this episode of Corruption, Crime and Compliance, Michael Volkov explains why standard software procurement templates fail to protect organizations in AI vendor relationships, and what to do about it. He walks through the structural differences that make AI vendors riskier than traditional software vendors, multi-layered data flows through underlying foundation models, frequent model swaps, and vendors' commercial incentive to train on customer data, and identifies the specific gaps legacy contracts leave open: silent or vague data training rights, indemnification that doesn't reach model outputs or training data provenance, missing audit rights, and liability caps that quietly undercut existing protections. The episode closes with a concrete negotiating playbook, including explicit training restrictions, coordinated indemnification and liability provisions, audit rights, subprocessor disclosure, regulatory compliance representations, and guaranteed exit and data deletion rights, along with practical guidance for organizations facing dominant vendors unwilling to negotiate.
Hiring someone to investigate misconduct isn’t always going to save your board. The line between bad management and bad faith just got real.
Here’s a question every board member should be losing sleep over: when does a board’s failure to catch corporate misconduct cross the line from bad management into an actual breach of fiduciary duty?
Delaware just gave us two new answers, and they cut in different directions.
First, Teligent, a pharma company, an FDA compliance meltdown, and a court that let claims proceed against directors and two officers because the complaint showed information and mounting regulatory problems never made it to the people who could act on it.
Second, Regions Financial case. A whistleblower sent the board a complaint about allegedly illegal overdraft fee practices back in 2019.
The board hired an investigator. Good so far, but the company didn’t stop the practices until 2021, and a $191 million CFPB consent order was imposed.
Delaware let the claims proceed here too.
Here’s the lesson from both: escalation isn’t enough. Investigating isn’t enough. The board has to actually understand what it found and actually fix it.
Stay tuned. Tomorrow I’ll tell you about the case that shows the other side of this coin.
The Ethics and Compliance Q and A show is produced by One Stone Creative.
From the publisher's feed

26,830 Listeners

3,465 Listeners

4,347 Listeners

20 Listeners

111,779 Listeners

56,445 Listeners

15 Listeners

22 Listeners

17 Listeners

56 Listeners

2,543 Listeners

12 Listeners

5,787 Listeners

15,856 Listeners

6,916 Listeners