When external regulation lags, internal audit becomes the only line of defense. AIโs environmental footprint is a live governance exposure, and right now, almost no one is auditing it. A company can run an AI product billions of times a day with no obligation to measure what it consumes: No requirement to report the energy […]
Best Practices
AI demands a new risk operating model. Are risk leaders up to the task?
For years, risk, compliance, and internal audit functions have been asked to absorb and integrate new technologies and ways of working while facing off against increased business expectations without fundamentally changing the risk management operating model that underpins them. Capabilities such as continuous controls monitoring, dynamic risk assessments, and new reporting requirements have been layered […]
Brazil’s National Data Protection Authority: How regulators investigate and enforce its data protection law
In June of this year, Brazil’s National Data Protection Authority opened an administrative enforcement proceeding against Claro, one of the country’s largest telecom carriers, over the sharing of customer data with Serasa, the largest credit bureau in Latin America.
Practitioner lessons from Prudential Life of Japanโs scandal
Prudential Life Insuranceโs scandal in Japan attracted limited attention in the West when it broke in January, but six months on, it has become one of the most consequential compliance failures seen this year.ย
The implementation of biodiversity footprinting: Examining supply chains
Biodiversity is foundational to human health, economic stability, and industrial resilience, particularly within the pharmaceutical sector, which is intrinsically dependent on natural ecosystems.
The SEC’s crypto taxonomy changes everything. Pending enforcement targets should act now
The SEC’s Division of Corporation Finance published a 68-page interpretive release in March that, for the first time, defines what is and is not a security in the digital asset space.
World Whistleblower Day: Trust determines whether employees speak up
An employee knows something is wrong. Theyโve seen the signs. Maybe theyโve quietly weighed the risks for weeks. The question isnโt whether your organization has a hotline. Itโs whether employees trust it enough to use it. That question is at the heart of World Whistleblower Day.
From DOJ to in-house: Five mindset shifts for success in internal investigations
Hundreds of prosecutors and law enforcement agents have left the U.S. Department of Justice (โDOJโ) since January 2025. Many have landed or are seeking in-house jobs handling internal investigations of potential misconduct. But not all the instincts and skills they developed in DOJ will translate directly to the private sector. That was the message three […]
Two clean companies, one exposed entity
Why compliance integration after a merger is a risk event, not a cost exercise.
One part legal, one part behavioral: A winning recipe for a more thoughtful compliance program
Over more than three decades of defending claims, litigating False Claims Act cases, and helping clients avoid suspensions and debarments, my law firm colleagues and I have learned a fair amount about risk and what makes corporate compliance programs succeed or fail.


