<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Corporate Compliance Insights</title>
	<atom:link href="https://www.corporatecomplianceinsights.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<description>The Web's Premier News Source for Compliance, Ethics &amp; Risk</description>
	<lastBuildDate>Fri, 14 Aug 2026 13:44:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/11/cropped-Favicon-32x32.png</url>
	<title>Corporate Compliance Insights</title>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>26% of Execs Say Audit Has Caught Public-Facing AI Mistake</title>
		<link>https://www.corporatecomplianceinsights.com/news-roundup-august-14-2026/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 13:44:38 +0000</pubDate>
				<category><![CDATA[Governance]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Board of Directors]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67942</guid>

					<description><![CDATA[<p>Few orgs say AI governance is fully mature; data center boom running into risk hurdles</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-august-14-2026/">26% of Execs Say Audit Has Caught Public-Facing AI Mistake</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: </span></i><a href="mailto:editor@corporatecomplianceinsights.com"><b><i>editor@corporatecomplianceinsights.com</i></b></a><i><span style="font-weight: 400;">.</span></i></h6>
<h2><span style="font-weight: 400;">C-suite more confident than practitioners about AI’s accuracy</span></h2>
<p><span style="font-weight: 400;">More than a quarter of business executives (26%) say audits have detected AI-generated mistakes in materials that have made their way to the </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board</b></a><span style="font-weight: 400;"> or external audiences, according to a </span><a href="https://www.workiva.com/resources/executive-benchmark-survey-verification-gap" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> from corporate reporting platform Workiva.</span></p>
<p><span style="font-weight: 400;">The survey of more than 2,200 global finance, risk and sustainability professionals also highlighted a modest split between the C-suite and practitioners when it comes to AI’s trustworthiness. About 4 in 5 executives (84%) said they’d be at least somewhat confident in AI output appearing in an annual report without human review, while only 76% of practitioners said the same.</span></p>
<p><span style="font-weight: 400;">Investors are tracking both AI’s accuracy and its profitability. Most institutional investors in the survey (89%) said they were concerned about AI accuracy in corporate disclosures, while 51% said they are tracking revenue growth to gauge AI’s return on investment. </span></p>
<p><span style="font-weight: 400;">Other findings include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">47% said their organizations formally model the climate-related impacts of AI investments and include them in the business case before approval.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Among executives at public companies or those on the path to IPOs, more than 90% were at least somewhat likely to say they would continue to publish quarterly earnings figures even if the SEC adopts a </span><a href="https://www.corporatecomplianceinsights.com/sec-proposed-quarterly-reporting-rule-compliance-costs-vs-investor-protection/" target="_blank" rel="noopener"><b>rule to permit semiannual reporting</b></a><span style="font-weight: 400;">.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">88% of executives said training their workforce on AI is a top priority in the second half of the year. </span></li>
</ul>
<h2><span style="font-weight: 400;">Less than 30% of organizations have full AI governance</span></h2>
<p><span style="font-weight: 400;">Organizations are putting money into </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> governance, but few have fully operationalized controls, according to a </span><a href="https://www.schellman.com/whitepaper/2026-state-of-ai-governance" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by Schellman, an IT </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> and </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;"> firm. </span></p>
<p><span style="font-weight: 400;">Surveying 525 US-based AI </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> professionals, Schellman found that almost all (90%) said their organizations have allocated funding for AI governance, but only 27% say their AI governance is mature, operational and continuously monitored.</span></p>
<p><span style="font-weight: 400;">Despite funding AI governance, only two-thirds (64%) of organizations have a baseline formal, documented AI acceptable use policy that’s communicated to employees, respondents reported. Less than half (44%) have documented AI-specific incident response procedures, while 57% maintain a formal AI governance policy.</span></p>
<p><span style="font-weight: 400;">Organizations’ nascent AI governance is being outpaced by agentic AI adoption, according to the survey. A vast majority (86%) have put agents into testing and 46% have agents in production. Organizations don’t always require human oversight of AI agents with 38% reporting they require human review only for high-risk or high-impact AI agent decisions, 32% requiring human review for all agent actions and 22% having defined thresholds that would trigger a human review.</span></p>
<h2><span style="font-weight: 400;">Data center boom means risk is booming, too</span></h2>
<p><span style="font-weight: 400;">As </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> center project investment is expected to balloon to more than a trillion dollars by 2027, risks for these projects are also skyrocketing with climate and labor being some of the prominent liabilities, according to a </span><a href="https://commercial.allianz.com/news-and-insights/reports/data-center-construction-risks.html" target="_blank" rel="noopener"><b>report</b></a><span style="font-weight: 400;"> by business insurance provider Allianz Commercial.</span></p>
<p><span style="font-weight: 400;">Nearly 80% of global data center capacity is located in areas exposed to heightened natural catastrophe risk, the report said. Flood, wildfire and wind exposure is highest in the Americas, affecting 86% of capacity, while chronic heat and drought stress is greatest in Asia Pacific, where 89% of capacity is exposed. Natural catastrophes rank second behind fire as the cause of the highest financial loss for data centers, according to the report. Willful acts, including physical and cyber crime, are the third-highest cause.</span></p>
<p><span style="font-weight: 400;">The data center boom is being driven by the need for </span><a href="https://apnews.com/article/ai-inflation-federal-reserve-434f02e62a02f9b92e57995d9375df57" target="_blank" rel="noopener"><b>computing power for AI</b></a><span style="font-weight: 400;">, which is being adopted rapidly by enterprises, quickly outpacing their governance of the technology, according to surveys.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-august-14-2026/">26% of Execs Say Audit Has Caught Public-Facing AI Mistake</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Hidden Link Between Sleep Deprivation &amp; Fear of Failure at Work</title>
		<link>https://www.corporatecomplianceinsights.com/hidden-link-between-sleep-deprivation-fear-failure-work/</link>
		
		<dc:creator><![CDATA[Melisa Buie]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 11:00:37 +0000</pubDate>
				<category><![CDATA[Well-Being]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67935</guid>

					<description><![CDATA[<p>Compliance will never be low-stress, but it does not have to be self-defeating</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/hidden-link-between-sleep-deprivation-fear-failure-work/">The Hidden Link Between Sleep Deprivation &#038; Fear of Failure at Work</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Compliance professionals face a paradox, writes Melisa Buie, Ph.D., organization strategist and author. Their job is to scrutinize every detail, anticipate regulatory shifts and protect the organization from consequences ranging from reputational damage to criminal liability with no margin for error. That can start a cycle undermining the cognitive sharpness their work demands.</span></i></p>
</div>
<p><span style="font-weight: 400;">There is no shortage of stress for </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> professionals. Regulatory environments are fragmenting at an accelerating pace. Teams are stretched thin trying to keep up with a patchwork of </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data privacy</b></a><span style="font-weight: 400;">, digital asset and AI </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> rules that shift from one jurisdiction to the next. Now add an arms race on top of that; criminals are using </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;">, automation and crypto to run increasingly sophisticated </span><a href="https://www.corporatecomplianceinsights.com/fraud-news/" target="_blank" rel="noopener"><b>fraud</b></a><span style="font-weight: 400;"> schemes, while many compliance teams are still stuck with legacy systems built for a different era. Layer on top of that a troubling trend toward recentralizing compliance under legal departments and reducing its visibility to senior leadership, and you have a profession operating under extraordinary pressure with diminishing organizational support.</span></p>
<p><span style="font-weight: 400;">That pressure starts in the office, but it follows the compliance professional home, and it eventually goes to bed.</span></p>
<p><span style="font-weight: 400;">Inadequate sleep can lead to serious physical and emotional problems, regardless of occupation. A 2023 </span><a href="https://www.apa.org/news/press/releases/2023/12/sleep-deprivation-anxious" target="_blank" rel="noopener"><b>analysis published in the journal Psychological Bulletin</b></a><span style="font-weight: 400;"> synthesized more than 50 years of experimental research on sleep and emotion. The results, based on 154 studies and 5,715 participants, were clear: Losing any amount of sleep, whether it&#8217;s total loss, shorter sleep or waking up at night, decreased positive feelings like happiness and satisfaction, while increasing anxiety symptoms like a fast heartbeat and excessive worrying. What made the results particularly striking was the threshold. Even losing one or two hours of sleep on a single night was enough to measurably impair emotional functioning.</span></p>
<h2><span style="font-weight: 400;">The snowball effect</span></h2>
<p><span style="font-weight: 400;">Unlike many leadership roles, where a misstep can be quietly corrected, a compliance oversight can trigger regulatory investigation, financial penalties or reputational ruin for an individual and the organization. That reality breeds a particular species of fear: not merely the fear of making a mistake but the fear that a single lapse in attention will cascade into catastrophic failure.</span></p>
<p><span style="font-weight: 400;">Research tells us that fear of failure typically threatens one or more of three domains: identity, sense of belonging or safety. Compliance professionals routinely face all three. A missed regulatory change can raise doubts about their competence. Sidelining compliance in a restructuring doesn&#8217;t just hurt the function, it threatens everyone in it, professionally and financially, especially given how real personal liability is in this line of work.</span></p>
<p><span style="font-weight: 400;">Fear activates the amygdala, the brain&#8217;s rapid-response alarm, which bypasses the rational prefrontal cortex and floods the body with stress hormones, resulting in quickened heart rate, tightened breathing and a racing mind, replaying scenarios, scanning for threats and rehearsing worst-case outcomes. And when that racing mind meets a pillow at the end of the day, sleep becomes elusive.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67935_0_6a81eddc28657   " data-unique="jnews_module_67935_0_6a81eddc28657">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/half-compliance-officers-have-anxiety/" aria-label="Read article: Half of Compliance Officers Have Anxiety; Their Org Chart Might Be the Culprit"><div class="thumbnail-container animate-lazy  size-500 "><img fetchpriority="high" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="frustrating organizational chart abstract concept" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/frustrating-organizational-chart-abstract-concept-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/frustrating-organizational-chart-abstract-concept-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/frustrating-organizational-chart-abstract-concept-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/frustrating-organizational-chart-abstract-concept-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/compliance/">Compliance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/half-compliance-officers-have-anxiety/">Half of Compliance Officers Have Anxiety; Their Org Chart Might Be the Culprit</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/jennifer-gaskin/">Jennifer L. Gaskin</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/half-compliance-officers-have-anxiety/"><i class="fa fa-clock-o"></i> February 26, 2025</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Between whiplash-inducing policy shifts in Trump's second term and ever-present personal liability concerns, compliance officers already face unprecedented pressure. Editorial director Jennifer L. Gaskin examines CCI’s striking new survey findings that reveal an equally triggering stressor hiding in plain sight:</p>
                                    <a href="https://www.corporatecomplianceinsights.com/half-compliance-officers-have-anxiety/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67935_0_6a81eddc28657 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"63640","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"40","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<p><span style="font-weight: 400;">The result is a snowball effect. Detail-oriented stress and organizational pressure feed a fear of failure. That fear disrupts sleep. Disrupted sleep degrades the very cognitive functions, attention, memory, decision-making and emotional regulation that compliance work demands. And diminished cognitive performance generates more errors, more anxiety and more fear, which further disrupts sleep. Each revolution of the cycle adds another layer, and the snowball picks up speed.</span></p>
<p><span style="font-weight: 400;">Reviews of sleep deprivation and cognitive performance in working professionals confirms the pattern: Insufficient sleep impairs executive function, attention and working memory, precisely the faculties compliance officers depend on to parse dense regulatory text, identify anomalies in transaction </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> and exercise sound judgment under ambiguity.</span></p>
<h2><span style="font-weight: 400;">Breaking the cycle</span></h2>
<p><span style="font-weight: 400;">Awareness is the first intervention. Many compliance professionals have normalized poor sleep and chronic anxiety as occupational inevitabilities rather than recognizing them as signals that the cycle has taken hold. By naming the pattern and understanding that the fear causing sleeplessness is being amplified by the lack of sleep, individuals can begin to loosen its grip.</span></p>
<p><span style="font-weight: 400;">From there, practical steps matter. Setting firm boundaries around after-hours regulatory monitoring, building intentional decompression routines before bed and engaging in structured self-reflection to separate genuine risk from catastrophic thinking can each serve as a small branch placed in front of the snowball. Organizations, too, have a role: ensuring compliance teams have adequate staffing, technology budgets and direct access to senior leadership reduces the structural stressors that set the cycle in motion.</span></p>
<p><span style="font-weight: 400;">Recognizing the hidden link between sleep deprivation and fear of failure is not a sign of weakness; it is an act of the same vigilance compliance professionals bring to every other </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> they manage. This time, the risk just happens to be their </span><a href="https://www.corporatecomplianceinsights.com/well-being/" target="_blank" rel="noopener"><b>well-being</b></a><span style="font-weight: 400;">.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/hidden-link-between-sleep-deprivation-fear-failure-work/">The Hidden Link Between Sleep Deprivation &#038; Fear of Failure at Work</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Born in the USA? The FTC Wants Your Substantiation File</title>
		<link>https://www.corporatecomplianceinsights.com/born-in-usa-ftc-wants-substantiation-file/</link>
		
		<dc:creator><![CDATA[Julia Solomon Ensor and John Feldman]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 11:00:55 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67907</guid>

					<description><![CDATA[<p>The FTC is cracking down on “Made in USA” claims, but risk is not equal across all claims and all products. A series of July letters may reveal a hidden triage framework for who gets a warning and who gets a penalty, write Reed Smith attorneys John Feldman and Julia Solomon Ensor, the former leader of the commission’s Made in USA program.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/born-in-usa-ftc-wants-substantiation-file/">Born in the USA? The FTC Wants Your Substantiation File</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">The FTC is cracking down on “Made in USA” claims, but risk is not equal across all claims and all products. A series of July letters may reveal a hidden triage framework for who gets a warning and who gets a penalty, write Reed Smith attorneys John Feldman and Julia Solomon Ensor, the former leader of the commission’s Made in USA program.</span></i></p>
</div>
<p><span style="font-weight: 400;">If your company makes “Made in USA” (MUSA) or similar domestic-origin claims on labels, websites, social media or anywhere else in advertising, your </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> profile has been steadily increasing. In March, the White House issued an </span><a href="https://www.whitehouse.gov/presidential-actions/2026/03/ensuring-truthful-advertising-of-products-claiming-to-be-made-in-america/" target="_blank" rel="noopener"><b>executive order</b></a><span style="font-weight: 400;"> directing the Federal Trade Commission (FTC) to crack down on misleading origin claims, and enforcement has been accelerating since. But a recent agency signal may reveal something useful for </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> practitioners. In July, the FTC</span><a href="https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-warns-companies-making-questionable-made-usa-claims" target="_blank" rel="noopener"> <b>issued seven warning letters</b></a><span style="font-weight: 400;"> that appear to present a framework for assessing where your company falls on the FTC’s MUSA priority spectrum.</span></p>
<p><span style="font-weight: 400;">The message is clear: this is not a single enforcement sweep. It is a sustained campaign with escalating intensity in direct response to the White House’s orders.</span></p>
<p><span style="font-weight: 400;">Understanding the emerging framework and building your internal program around it could make the difference between receiving a warning letter or a law enforcement action and never hearing from the agency at all.</span></p>
<h2><span style="font-weight: 400;">What the warning letters reveal about FTC priorities</span></h2>
<p><span style="font-weight: 400;">The knee-jerk response may be that all MUSA claims are too high-risk in this environment. After all, the FTC’s </span><a href="https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-323" target="_blank" rel="noopener"><b>Made in USA labeling rule</b></a><span style="font-weight: 400;"> gives the agency authority to seek civil penalties of up to more than $53,000 per violation per day from companies that make MUSA claims on labels for products that are not “all or virtually all” MUSA. And “all or virtually all” is a difficult — if not impossible — standard to meet in today’s global economy. But if you genuinely perform significant manufacturing functions in the US, eliminating all US-origin claims deprives consumers of important information and deprives your company of a valuable marketing opportunity. Instead, a more nuanced approach is needed, with careful attention to what the July letters reveal about risk and priorities.</span></p>
<p><span style="font-weight: 400;">The July letters went to a wide range of companies, including those selling e-cigarettes, coordinate measuring machines, industrial laser machinery and musical instruments. And the challenged claims spanned a wide range too, from “Made in USA” and “Built in the USA” to “handmade in Austin, Texas” and hashtags like “#madeinUSA” and “#madeincali.”</span></p>
<p><span style="font-weight: 400;">But the companies that received the letters had one important thing in common: They received warning letters, not immediate enforcement action. Why? The answer reveals how the FTC triages its targets and how you should triage your own risk.</span></p>
<h3><span style="font-weight: 400;">Bucket 1: Jurisdictional complexity</span></h3>
<p><span style="font-weight: 400;">Three of the seven companies sell vaping and e-cigarette products. The Food and Drug Administration (FDA) has federal jurisdiction over the labeling of electronic nicotine delivery systems through its Center for Tobacco Products, which regulates their manufacture, packaging and labeling. While the FTC has jurisdiction over advertising and marketing of these products, labels are generally the FDA’s domain, and the FTC’s MUSA labeling rule, the agency’s primary tool for getting monetary relief in connection with allegations of deceptive MUSA claims, specifically does not apply where another agency has authority over a product’s labeling. Indeed, the</span><a href="https://www.federalregister.gov/documents/2021/07/14/2021-14610/made-in-usa-labeling-rule" target="_blank" rel="noopener"> <b>Federal Register notice</b></a><span style="font-weight: 400;"> announcing the final rule specifically acknowledged that “USDA and FDA have primary jurisdiction over labeling issues for the food products within their purview.” Enforcement against an FDA-regulated product’s labeling would invite a jurisdictional defense. And thus, sending a warning letter and being done is significantly less messy than trying for a penalty case.</span></p>
<p><span style="font-weight: 400;">If your product’s labeling is regulated by an agency other than the FTC, including FDA, US Department of Agriculture, Alcohol and Tobacco Tax and Trade Bureau or others, your enforcement risk from the MUSA labeling rule is lower. That does not mean the FTC cannot challenge your claims in advertising if they are misleading; the FTC retains authority over your advertising under Section 5, and a jurisdictional gray zone is not a compliance strategy, but it does mean the risk of a civil penalty or redress is lower.</span></p>
<h3><span style="font-weight: 400;">Bucket 2: Claims outside the rule’s reach</span></h3>
<p><span style="font-weight: 400;">The other four companies had claims appearing on websites, social media, brochures and trade-show materials rather than on product labels. This distinction is critical. The MUSA labeling rule was authorized by a law which specifically addresses labels on products. The commission’s authorization to apply the rule to non-label claims is tenuous to say the least. </span></p>
<p><span style="font-weight: 400;">Non-label claims are not free from risk. The FTC can and will challenge deceptive origin claims in advertising under its general authority to pursue unfair or deceptive acts and practices under Section 5 of the FTC Act. But, as with claims subject to other agencies’ jurisdictions, the financial exposure is materially different. A rule violation on a label can mean six-figure civil penalties. A Section 5 advertising case is more likely to result in an injunction and corrective action without the same monetary sting.</span></p>
<h3><span style="font-weight: 400;">Bucket 3: Qualified claims</span></h3>
<p><span style="font-weight: 400;">Notably absent from either the warning letters or recent enforcement actions are allegations that companies have made deceptive “qualified” MUSA claims, like “Made in USA of Imported Components” or “Assembled in USA.” This is an important point related to the categories discussed above. Like claims subject to other regulatory regimes or non-label statements, qualified MUSA claims fall outside the coverage of the MUSA labeling rule. And, as long as they do not reference US-origin parts, the standard marketers need to meet to substantiate them is materially lower. Marketers that substantially transform their products in the USA, without further post-transformation processing overseas, can likely make the claim without risk.</span></p>
<p><span style="font-weight: 400;">If you are confident your manufacturing process constitutes a substantial transformation in the US under US Customs and Border Protection laws, but you are not quite sure whether non-US content in the product is truly </span><i><span style="font-weight: 400;">de minimis</span></i><span style="font-weight: 400;">, a qualified claim is a low-risk option. Consider whether the marketing benefit of the unqualified claim truly outweighs the risk associated with it.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67907_1_6a81eddc2dea6   " data-unique="jnews_module_67907_1_6a81eddc2dea6">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/" aria-label="Read article: Managing Tariff Risk Through the Rest of 2026"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="shipping containers in port" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/shipping-containers-in-port-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/shipping-containers-in-port-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/shipping-containers-in-port-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/shipping-containers-in-port-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/risk/">Risk</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/">Managing Tariff Risk Through the Rest of 2026</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/charles-clevenger/">Charles Clevenger</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/"><i class="fa fa-clock-o"></i> August 11, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>The environment is likely to change even more with exclusions, negotiations, enforcement guidance, litigation and country-specific actions</p>
                                    <a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67907_1_6a81eddc2dea6 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67886","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Building your compliance program</span></h2>
<p><span style="font-weight: 400;">Understanding the FTC’s enforcement logic is only useful if it informs your internal processes. Here is what a defensible MUSA compliance program should include:</span></p>
<h3><span style="font-weight: 400;">A comprehensive claim inventory </span></h3>
<p><span style="font-weight: 400;">Identify every US-origin claim your company makes, across all channels:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Product labels and packaging.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Website copy, including product pages and “About Us” sections.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Social media posts, captions, bios and hashtags (yes, “#madeinUSA” counts).</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Brochures, trade-show materials and sales collateral.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Third-party marketplace listings (Amazon, etc.).</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Advertising.</span></li>
</ul>
<p><span style="font-weight: 400;">Do not limit your inventory to the specific language, “Made in USA.” The FTC’s July letters flagged a range of claims, including “Precision Built in the USA,” “created by American workers, engineers, and innovators,” city- and state-origin claims like “handmade in Austin, Texas” and “Made in [state]” claims. The agency has made clear it will analyze these under the same “all or virtually all” standard it applies to traditional “Made in USA” claims.</span></p>
<h3><span style="font-weight: 400;">Build and maintain substantiation files</span></h3>
<p><span style="font-weight: 400;">For every origin claim you identify, you need a substantiation file documenting:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Where final assembly or processing occurs.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Where all significant processing occurs.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The sourcing origin of all ingredients or components with particular attention to whether foreign content is more than </span><i><span style="font-weight: 400;">de minimis</span></i><span style="font-weight: 400;">.</span></li>
</ul>
<p><span style="font-weight: 400;">This is not a one-time exercise. </span><a href="https://www.corporatecomplianceinsights.com/tag/supply-chain/" target="_blank" rel="noopener"><b>Supply chains</b></a><span style="font-weight: 400;"> shift. Substantiation must be current. If your file is more than 12 months old, or if you have had any supplier changes, it is time to re-substantiate or remove the claim.</span></p>
<h3><span style="font-weight: 400;">Map your regulatory landscape</span></h3>
<p><span style="font-weight: 400;">Determine which agencies have jurisdiction over your product’s labeling. Understand which rules each agency enforces regarding origin claims and where overlapping jurisdiction may create either additional exposure or potential defenses.</span></p>
<h3><span style="font-weight: 400;">Differentiate risk by claim placement</span></h3>
<p><span style="font-weight: 400;">Based on the FTC’s revealed enforcement priorities, assess your risk profile:</span></p>
<div class="su-table su-table-responsive su-table-alternate">
<table>
<thead>
<tr>
<th>Claim placement</th>
<th>Primary authority</th>
<th>Penalty exposure</th>
<th>Priority level</th>
</tr>
</thead>
<tbody>
<tr>
<td>Unqualified claims on product labels (FTC-jurisdictional products)</td>
<td>MUSA labeling rule</td>
<td>Civil penalties (~$53K/violation)</td>
<td>Highest</td>
</tr>
<tr>
<td>Unqualified claims on product labels (other-agency products)</td>
<td>Varies; jurisdictional questions</td>
<td>Depends on agency; overall likely lower than FTC</td>
<td>Moderate</td>
</tr>
<tr>
<td>Unqualified claims on website, social media, advertising</td>
<td>Section 5</td>
<td>Injunction; limited monetary</td>
<td>Moderate</td>
</tr>
<tr>
<td>Qualified claims</td>
<td>Section 5</td>
<td>Injunction; limited monetary</td>
<td>Lower</td>
</tr>
</tbody>
</table>
</div>
<p><span style="font-weight: 400;">This does not mean it is OK to ignore non-label claims. The FTC’s warning letters demonstrate it is watching all channels. But it does provide important information on where to allocate compliance resources first.</span></p>
<h3><span style="font-weight: 400;">Establish a review cadence</span></h3>
<p><span style="font-weight: 400;">MUSA compliance is not a point-in-time exercise. Build recurring processes:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Quarterly:</b><span style="font-weight: 400;"> Review social media accounts and advertising copy for new or changed origin claims.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Annually:</b><span style="font-weight: 400;"> Full claim inventory refresh and substantiation file review.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Trigger-based:</b><span style="font-weight: 400;"> Any supplier change, product reformulation or new product launch should trigger immediate review.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Marketing review gate</b><span style="font-weight: 400;">: No origin claim goes live without compliance sign-off, including social media posts and hashtags.</span></li>
</ul>
<h2><span style="font-weight: 400;">Looking ahead</span></h2>
<p><span style="font-weight: 400;">“Made in USA” claims remain in the FTC’s crosshairs as it follows through on a central component of the Trump Administration’s domestic manufacturing agenda. Expect more action on the horizon.</span></p>
<p><span style="font-weight: 400;">In the meantime, the compliance practitioner’s job is straightforward, even if the execution is not: know who regulates you, know what claims you are making, confirm the claims are true and substantiated and build the internal processes to keep it that way. The companies that do this work now are the ones that will never see a warning letter (or worse) in their inbox.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/born-in-usa-ftc-wants-substantiation-file/">Born in the USA? The FTC Wants Your Substantiation File</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Q&amp;A: SEC’s Proposed Quarterly Reporting Rule — Compliance Costs vs. Investor Protection</title>
		<link>https://www.corporatecomplianceinsights.com/sec-proposed-quarterly-reporting-rule-compliance-costs-vs-investor-protection/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 11:00:31 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Financial Reporting]]></category>
		<category><![CDATA[SEC]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67904</guid>

					<description><![CDATA[<p>What do capital markets and SEC reporting experts believe a potential reporting cadence change will catalyze, and will it “Make IPOs great again?”</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/sec-proposed-quarterly-reporting-rule-compliance-costs-vs-investor-protection/">Q&#038;A: SEC’s Proposed Quarterly Reporting Rule — Compliance Costs vs. Investor Protection</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">With the SEC on the edge of changing reporting periods for listed companies from quarterly to semiannually, businesses must consider priorities in their calculations for making the adjustment, according to experts CCI asked about the change. Where does automation in reporting and lawsuit concerns fit into this equation, and what does the proposal signal about the SEC?</span></i></p>
</div>
<p><span style="font-weight: 400;">To date, the </span><a href="https://www.corporatecomplianceinsights.com/tag/sec/" target="_blank" rel="noopener"><b>SEC</b></a><span style="font-weight: 400;"> has received hundreds of thousands of public comments on its </span><a href="https://www.corporatecomplianceinsights.com/sec-proposes-making-quarterly-reporting-optional/" target="_blank" rel="noopener"><b>May proposal</b></a><span style="font-weight: 400;"> to permit listed companies to report earnings semiannually rather than quarterly. According to a </span><a href="https://tzachizach.github.io/sec-semi-annual-proposal-tracker/" target="_blank" rel="noopener"><b>tracker</b></a><span style="font-weight: 400;"> created by Ohio State business professor Tzachi Zach, less than 1% of commenters support the proposal. Despite this, </span><a href="https://www.wsj.com/finance/regulation/sec-quarterly-earnings-reports-complaints-2979d5a0" target="_blank" rel="noopener"><b>reporting by the Wall Street Journal</b></a><span style="font-weight: 400;"> suggests the commission is likely to move forward with some version of the rule. A final rule has yet to be issued, and as of this writing on Aug. 10, the </span><a href="https://www.sec.gov/comments/s7-2026-15/semiannual-reporting" target="_blank" rel="noopener"><b>public comment form</b></a><span style="font-weight: 400;"> was still active.</span></p>
<p><span style="font-weight: 400;">Among the small number of letters supporting the proposal, a reduction in the </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> burden was the most common rationale, Zach’s analysis found, being cited in 3% of all submissions. On the flip side, those opposed to the proposal were likely to cite investor protection and transparency (39%) and the </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> for </span><a href="https://www.corporatecomplianceinsights.com/fraud-news/" target="_blank" rel="noopener"><b>fraud</b></a><span style="font-weight: 400;"> or insider trading (27%). </span></p>
<p><span style="font-weight: 400;">Assuming quarterly reporting does become optional rather than mandatory for public companies, whether they switch to semiannual reporting is a question that will come down, as most things do, to each company’s unique circumstances.</span></p>
<p><span style="font-weight: 400;">“The most important action item is talking to your investors, analysts and bankers before making any recommendations to the </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board</b></a><span style="font-weight: 400;">,” Edward “Eddie” Best, co-chair of the capital markets practice at law firm Willkie Farr, said in a written Q&amp;A with CCI. “Any decision by the board must be well-informed.”</span></p>
<p><span style="font-weight: 400;">Given the nature of being a company that sells stock to investors, that group should be top of mind, wrote Payton McCoy, CEO and co-founder of Greenshoe, an SEC reporting startup:  “Companies should ask themselves a simple question: ‘Will reporting less frequently increase or decrease investor confidence?’ If the answer is decrease, any compliance savings could easily be outweighed by a higher cost of capital.”</span></p>
<p><b><i>CCI: Assuming the rule is adopted as written, though the Wall Street Journal also reported people familiar with the matter said it’s possible the rule could change based on that negative feedback, what are the biggest action items for decision-makers inside public companies? How should they go about deciding whether this is a good move for them? What factors should they consider?</i></b></p>
<p><b>Eddie Best:</b><span style="font-weight: 400;"> The most important action item is talking to your investors, analysts and bankers before making any recommendations to the board. Any decision by the board must be well-informed. Next, confirm that your debt covenants and debt agreements give you flexibility on timing. Then, check your listing exchange&#8217;s rules. Nasdaq rules currently require distribution of quarterly financial information to shareholders, so even if the SEC finalizes the rule as written, Nasdaq-listed companies may still be on the hook for quarterly financial information to shareholders. After that, loop in the audit committee and outside auditors because this touches internal controls, SOX certification cadence and audit timing. Next, determine actual cost/benefit and model the cost of providing some interim data via 8-K. Once management has all of this information, it is in a position to give the board relevant information and its recommendation. In terms of whether semiannual reporting makes sense for a company, companies will need to look at the true cost/benefit analysis and that’s not just the amount saved by only reporting twice a year. Companies will need to assess their investor base. Index funds and buy-and-hold retail investors may be relatively indifferent, whereas active managers, quant funds and sell-side analysts who rely on quarterly data for models and comparables are likely to push back and could apply a valuation discount to less-transparent issuers. You also need to look at what your peers are signaling. Companies don’t want to be outliers, as their results can be harder to benchmark, which analysts and investors may penalize with a &#8220;transparency discount&#8221; regardless of actual performance. Boards will need to look at their control environment. A company with strong </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>internal audit</b></a><span style="font-weight: 400;"> and real-time monitoring bears the risk of problems going undetected differently than one that relies on the quarterly close process itself as a forcing function. Companies also need to assess how semiannual reporting would impact their capital raising. Companies that raise debt or especially equity capital more frequently may be well-advised to continue quarterly reporting.</span></p>
<p><b>Payton McCoy: </b><span style="font-weight: 400;">The decision should be driven by how investors value transparency in your industry. I don&#8217;t think we&#8217;ll end up with one market standard; I think we&#8217;ll end up with industry-specific standards. Some companies may find semiannual reporting makes perfect sense, while others may conclude that communicating more frequently is a competitive advantage. Ultimately, the SEC sets the minimum disclosure standard, but the market will determine the optimal one. Companies should ask themselves a simple question: &#8220;Will reporting less frequently increase or decrease investor confidence?&#8221; If the answer is ‘Decrease,’ any compliance savings could easily be outweighed by a higher cost of capital. Companies used to compete on products and services. Increasingly, they&#8217;ll compete on transparency.</span></p>
<p><b><i>CCI: This rule is part of a stated administration goal to “Make IPOs great again.” In your view, would this rule help achieve that goal, and is that a goal worth achieving? Does going public or staying public necessarily make a company more fiscally sound or successful?</i></b></p>
<p><b>EB:</b><span style="font-weight: 400;"> I really don’t think that quarterly vs. semiannual reporting will make a difference to a company’s decision to stay private or go public. The reporting burden is a real but secondary factor in the IPO decision. More important is the need and availability of capital liquidity for existing shareholders, incentivizing employees and having acquisition currency. Whether having more or fewer public companies is debatable, as is whether being public makes a company more fiscally sound or successful. There are numerous examples of public companies going bankrupt or having fiscal scandals, as well as private companies thriving and growing. Going public is a financing and liquidity decision, not a mark of quality. The &#8220;success&#8221; comes from the business itself, not the listing status. In my view, the regulatory and litigation burden of being a public company should not be impediments to going or staying public.</span></p>
<p><b>PM:</b><span style="font-weight: 400;"> It&#8217;s a goal worth pursuing because strong public markets are one of society&#8217;s greatest wealth-creation engines because they allow everyday investors to participate in the growth of great companies. This rule may help reduce some of the friction of being public, but it won&#8217;t determine whether a company succeeds. Going public doesn&#8217;t make a company better, and staying private doesn&#8217;t make it worse. What matters is that companies have the right access to capital while maintaining investor confidence.</span></p>
<p><b><i>CCI: A record number of comments were received and they have been overwhelmingly opposed to the proposal. The SEC is pressing forward anyway, at least according to reporting. What does that tell us about how companies should think about the rulemaking process more broadly, and does it change how they should approach commenting on future rules?</i></b></p>
<p><b>EB: </b><span style="font-weight: 400;">The honest answer is more nuanced than &#8220;comments don&#8217;t matter&#8221; or &#8220;comments determine outcomes.&#8221; The comment process is not intended to make agency decisions up for the public to vote on. A reviewing court doesn’t look at whether more people support or oppose a rule; it&#8217;s whether the agency&#8217;s decision was &#8220;arbitrary and capricious.&#8221; In practice, a court will look at whether the agency considered dealing with significant comments rather than just ignoring them. In my experience, comments rarely reverse an agency&#8217;s direction once political leadership has committed to a policy; what they more often do is shape the details.</span></p>
<p><b>PM:</b><span style="font-weight: 400;"> I don&#8217;t think companies should conclude that commenting doesn&#8217;t matter. Rulemaking is an iterative process, and thoughtful participation remains important. What I do think it demonstrates is that companies should prepare for multiple regulatory outcomes rather than assuming any proposal will or won&#8217;t be adopted. </span></p>
<p><b><i>CCI: The SEC&#8217;s position is that Form 8-K and Regulation FD are robust enough to fill the space between semiannual reports. Do you agree, and are there categories of information that routinely appear in quarterly filings that simply wouldn&#8217;t make it out to investors on the same timeline under a semiannual schedule?</i></b></p>
<p><b>EB:</b><span style="font-weight: 400;"> The SEC&#8217;s framing overstates how much 8-K and Reg FD actually substitute for periodic reporting. Form 8-K is event-triggered and involves mostly material non-recurring events. It does not require disclosure of gradual, non-event-driven developments. There is a lot of important information that is typically disclosed in a Form 10-Q that is not covered by Form 8-K requirements. Especially important are financial results and MD&amp;A trend analysis. Regulation FD is a nondiscrimination rule. It only applies when a company chooses to disclose material nonpublic information and doesn&#8217;t obligate the company to disclose anything in the first place. A company that simply says nothing to anyone violates no Reg FD provision, no matter how stale the market&#8217;s information about it becomes. </span></p>
<p><b>PM:</b><span style="font-weight: 400;"> 8-Ks and Regulation FD can fill part of the gap, but the bigger point is that investors no longer rely on a single filing for information. Earnings calls, investor presentations, press releases, industry data, social media, peer disclosures, litigation and regulatory developments all shape the market’s understanding of a company in real-time. That makes semiannual reporting more workable than it may have been decades ago, but it also makes the monitoring problem much harder. The relevant information may be spread across a dozen different sources instead of consolidated in one 10-Q.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67904_2_6a81eddc3208d   " data-unique="jnews_module_67904_2_6a81eddc3208d">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/making-easier-go-public-same-making-easier-be-public/" aria-label="Read article: Making It Easier to Go Public Isn’t the Same as Making It Easier to Be Public"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="sec building sign" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/05/sec-building-sign-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/05/sec-building-sign-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/05/sec-building-sign-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/05/sec-building-sign-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/opinion/">Opinion</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/making-easier-go-public-same-making-easier-be-public/">Making It Easier to Go Public Isn’t the Same as Making It Easier to Be Public</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/kyle-jeziorski/">Kyle Jeziorski</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/making-easier-go-public-same-making-easier-be-public/"><i class="fa fa-clock-o"></i> July 17, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Investors won’t ignore a company’s lack of quarterly reporting and the controls that come along with it</p>
                                    <a href="https://www.corporatecomplianceinsights.com/making-easier-go-public-same-making-easier-be-public/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67904_2_6a81eddc3208d = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67600","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<p><b><i>CCI: The cost-savings argument for semiannual reporting tends to focus on eliminating cycles of auditor reviews, SOX certifications and disclosure committee sign-offs. But financial </i></b><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b><i>data</i></b></a><b><i> collection and reporting have become increasingly </i></b><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b><i>automated</i></b></a><b><i>. How much of the quarterly compliance burden is genuinely reducible through technology, and does that change how companies should think about the cost-savings case for switching?</i></b></p>
<p><b>EB: </b><span style="font-weight: 400;">Automation has certainly reduced the mechanical burden of reporting, but the parts of quarterly reporting that remain expensive are exactly the parts technology hasn’t replaced. This includes auditor review procedures, disclosure committee sign-off and legal review and capital-markets-adjacent work like comfort letters. The SEC itself estimates that the approximate net reduction in direct compliance costs would be only $198,000 per fiscal year for each issuer that switches to semiannual reporting. While “every penny counts,” this amount really won’t move the needle for most public companies.</span></p>
<p><b>PM: </b><span style="font-weight: 400;">A meaningful share of the quarterly burden is reducible through technology, particularly data collection, reconciliation, drafting, benchmarking and review. That means the cost savings from switching to semiannual reporting may be smaller over time as quarterly reporting itself becomes cheaper and more automated. Companies should therefore treat cost as one factor (not the deciding factor) and weigh it against investor expectations, transparency, litigation risk and potential effects on their cost of capital.</span></p>
<p><b><i>CCI: Some practitioners have flagged that switching to semiannual reporting could actually increase litigation risk — that a longer gap between formal disclosures gives bad news more time to accumulate before it reaches investors, and that plaintiffs&#8217; lawyers will take note. How real is that concern?</i></b></p>
<p><b>EB: </b><span style="font-weight: 400;">This is a legitimate concern, especially for companies that do not continue to issue quarterly earnings information. Bigger disclosure gaps concentrate more information into single events, which mechanically produces bigger price moves on bad news, and bigger price moves are the raw material plaintiffs&#8217; securities class actions are built on. In addition, any delayed disclosure of adverse material information could expand the class of shareholder plaintiffs who could sue in the event of a significant stock price reaction to a disclosure. Finally, there is a concern that less-frequent disclosure provides a longer runway for something to go wrong before anyone outside the company is required to look.</span></p>
<p><b>PM: </b><span style="font-weight: 400;">It&#8217;s a legitimate consideration, but it depends on how companies respond. If a company interprets semiannual reporting as permission to think about disclosure only twice a year, I think risk increases. If instead companies adopt more continuous monitoring internally while simply changing the cadence of formal reports, the risk may be much more manageable. In other words, filing less frequently shouldn&#8217;t mean paying attention less frequently.</span></p>
<p><b><i>CCI: For a company that decides semiannual reporting makes sense, what does the actual transition look like internally? What are the sequencing issues — financing agreements, investor communications, trading window policies — that need to be resolved before flipping the switch?</i></b></p>
<p><b>EB: </b><span style="font-weight: 400;">I think it’s a multi-step process. First is diligence, including talking to investors, analysts and bankers, and then checking listing rules and material agreements. A company also needs to do a careful cost/benefit analysis. Second, a company needs to decide what information, if any, it would continue to report on a quarterly basis. Third, with all of this information and analysis, a company’s management needs to make a thoughtful recommendation to the board. Fourth, a company needs to adapt its internal policies and procedures to the new reporting cadence. Finally, a company needs to communicate its decision and rationale to the market in a clear and thoughtful manner.</span></p>
<p><b>PM:</b><span style="font-weight: 400;"> It&#8217;s much broader than changing a reporting calendar. Companies would need to evaluate debt covenants, investor expectations, analyst communications, internal controls, disclosure committee processes, board reporting, earnings practices and numerous </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> policies. I suspect many companies would spend as much time preparing for the transition as deciding whether to make it in the first place.</span></p>
<p><b><i>CCI: This rule is one of several disclosure-related changes the current SEC has pursued or signaled. Taken together, are these changes moving in a coherent direction, or does the cumulative effect on investor transparency concern you?</i></b></p>
<p><b>EB:</b><span style="font-weight: 400;"> There is a coherent, even explicit, program. Chairman Paul Atkins has stated the organizing principle directly: to restore the &#8220;foundation&#8221; of the SEC&#8217;s original mandate on requiring the disclosure of &#8220;material&#8221; information, with &#8220;materiality as the North Star&#8221; and disclosure imposed &#8220;only when the expected benefits justify the likely costs and burdens.&#8221; The SEC’s </span><a href="https://www.reginfo.gov/public/do/eAgendaMain?operation=OPERATION_GET_AGENCY_RULE_LIST&amp;currentPub=true&amp;agencyCode&amp;showStage=active&amp;agencyCd=3235" target="_blank" rel="noopener"><b>2026 rulemaking agenda</b></a><span style="font-weight: 400;"> reflects a broadly deregulatory orientation aimed at cutting compliance burdens, facilitating capital formation, revitalizing public markets, widening retail access to private markets and building a crypto framework. I am not concerned about the general direction the SEC is taking. I personally agree with Chairman Atkins that the SEC has drifted from its statutory mandate. Many of its recent rules did less to protect investors than to advance political interests. On the enforcement side, the SEC seemed to focus less on protecting small investors and more on headline-grabbing settlement amounts for technical violations, such as the over $2 billion of settlements the SEC got for </span><a href="https://www.corporatecomplianceinsights.com/sec-crackdown-fines-26-firms/" target="_blank" rel="noopener"><b>banks using text messaging</b></a><span style="font-weight: 400;"> where there was no allegation that a single investor was harmed. So, from that standpoint, I support the SEC’s agenda. Of course, the devil is in the details, and there are or will be some initiatives that I think may, in fact, lessen investor protections. Depending on the final rules, semiannual reporting may be one of those.</span></p>
<p><b>PM: </b><span style="font-weight: 400;">The broader direction is toward giving companies greater flexibility in how they communicate with investors. The important question is whether flexibility ultimately produces better information for the market. My view is that markets tend to reward transparency. The SEC can establish minimum requirements, but investors will ultimately determine what level of disclosure earns confidence and commands a premium.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/sec-proposed-quarterly-reporting-rule-compliance-costs-vs-investor-protection/">Q&#038;A: SEC’s Proposed Quarterly Reporting Rule — Compliance Costs vs. Investor Protection</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Red Oak, MirrorWeb Combine</title>
		<link>https://www.corporatecomplianceinsights.com/red-oak-mirrorweb-combine/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 14:53:36 +0000</pubDate>
				<category><![CDATA[GRC Vendor News]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67897</guid>

					<description><![CDATA[<p>Compliance technology provider and consultancy Red Oak and communications platform MirrorWeb, both Mainsail Partners portfolio companies, have consolidated under the Red Oak name, according to a news release. Details of the transaction, which was effective July 26, were not disclosed. Romir Bosu, most recently executive chairman at MirrorWeb, is now the CEO of the combined [&#8230;]</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/red-oak-mirrorweb-combine/">Red Oak, MirrorWeb Combine</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Compliance technology provider and consultancy Red Oak and communications platform MirrorWeb, both Mainsail Partners portfolio companies, have consolidated under the Red Oak name, according to a news release. Details of the transaction, which was effective July 26, were not disclosed.</span></i></p>
</div>
<p><span style="font-weight: 400;">Romir Bosu, most recently executive chairman at MirrorWeb, is now the CEO of the combined company, while Dave Dutch, <a href="https://www.redoak.com/lp/connected-compliance" target="_blank" rel="noopener"><strong>Red Oak</strong></a>’s former CEO, will serve as an adviser to the new Red Oak, the news release said. Other MirrorWeb executives, including CISO Philip Clegg, COO Harriet Christie and President Joshua Yulish, will remain, a company representative told CCI.</span></p>
<p><span style="font-weight: 400;"><a href="https://www.mirrorweb.com/"><strong>MirrorWeb</strong></a> will continue to operate under its name for an unspecified interim period, after which it will transition to the Red Oak name, the representative said. Red Oak will remain based in Austin, Texas, the representative told CCI, and it will provide content compliance, distribution and communications supervision in a single system for regulated financial services firms. </span></p>
<p><span style="font-weight: 400;">MirrorWeb and Red Oak have been “critical partners,” Dutch said in the release, in delivering on the vision that compliance done right is a growth engine and enabling end-to-end governance of the communication lifecycle for an increasingly shared client base. </span></p>
<p><span style="font-weight: 400;">“I&#8217;m proud of what we&#8217;ve done for clients together already and excited to see the combination of our platforms as the natural next step and growth driver for our clients,” he said in the release.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/red-oak-mirrorweb-combine/">Red Oak, MirrorWeb Combine</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Safe Harbor Compliance Means More Than Fair Pricing in Healthcare</title>
		<link>https://www.corporatecomplianceinsights.com/safe-harbor-compliance-means-more-than-fair-pricing-in-healthcare/</link>
		
		<dc:creator><![CDATA[June S. Santiago and Kaleb Rasmussen]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 11:02:10 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Anti-Kickback Statute]]></category>
		<category><![CDATA[Health Care]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67893</guid>

					<description><![CDATA[<p>Getting fair-market value isn’t enough to stop the feds from pursuing an anti-kickback statute violation</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/safe-harbor-compliance-means-more-than-fair-pricing-in-healthcare/">Safe Harbor Compliance Means More Than Fair Pricing in Healthcare</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Healthcare providers, administrators and investors must scrutinize their financial arrangements to understand if their compensation structure fits into a safe harbor from anti-kickback statute prosecution, attorneys June S. Santiago and Kaleb Rasmussen of Spencer Fane write. An April reminder by federal healthcare officials made this clear.</span></i></p>
</div>
<p><span style="font-weight: 400;">Physician groups, hospital administrators and healthcare investors all navigate the complexities of healthcare </span><a href="https://www.corporatecomplianceinsights.com/fraud-news/" target="_blank" rel="noopener"><b>fraud</b></a><span style="font-weight: 400;"> and abuse statutes, including </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> with the anti-kickback statute (AKS). </span></p>
<p><span style="font-weight: 400;">The AKS is a criminal statute that makes it a crime to knowingly and willfully offer, pay, solicit or receive any form of remuneration (cash, gifts, rent, fees, etc.) to induce patient referrals for services paid by federal healthcare programs like Medicare or Medicaid. Individuals who violate the statute (as recipients or payers of such remuneration) </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> prison time and significant financial penalties. </span></p>
<p><span style="font-weight: 400;">While application of the AKS is broad, a specific intent to violate the statute is required. In addition, the AKS offers numerous provisions that provide protection from prosecution for arrangements that meet the rigorous safe harbor requirements. Safe harbor compliance is completely voluntary, and the failure to satisfy a safe harbor does not mean that an arrangement is illegal.</span></p>
<p><span style="font-weight: 400;">However, because all of the requirements of a safe harbor must be met in order for an arrangement to be protected, many arrangements fall outside the safe harbors. These unprotected arrangements often rely on ensuring compensation at fair-market value (FMV) to show that the requisite intent is not present. Just pay the other side at market rate for the goods or services, the thinking goes, and you cannot also have the requisite intent to receive remuneration for referrals because the remuneration is FMV for the goods or services provided — there is no overage to allocate as remuneration for referrals. </span></p>
<p><span style="font-weight: 400;">Not so. </span></p>
<p><span style="font-weight: 400;">In April, the US Department of Health and Human Services Office of Inspector General (OIG) </span><a href="https://oig.hhs.gov/faqs/general-questions-regarding-certain-fraud-and-abuse-authorities/" target="_blank" rel="noopener"><b>published</b></a><span style="font-weight: 400;"> an update to an FAQ reiterating past guidance and further clarifying that an arrangement may violate the AKS even if it is FMV. The OIG occasionally updates FAQ pages with relevant and applicable subregulatory guidance on how to apply the more nuanced laws and regulations based on current market trends and the OIG’s evolving enforcement focus. </span></p>
<p><span style="font-weight: 400;">Specifically, in the recent update the OIG states: “&#8230; Some health care industry stakeholders have taken the position that, so long as the remuneration offered, paid, solicited, or received in an arrangement is consistent with fair market value, there is no unlawful remuneration under the Federal anti-kickback statute, and consequently, there can be no liability under the Federal anti-kickback statute . . . OIG’s guidance has been consistent and unwavering that fair market value is not a dispositive defense under the Federal anti-kickback statute.”</span></p>
<p><span style="font-weight: 400;">The recent guidance emphasizes that complying with the AKS means more than ensuring the compensation arrangements are FMV, and this position is supported by the fact that the AKS does not use the term “fair market value” even once. Rather, FMV is a foundational condition that each stream of remuneration must meet to be compliant with the applicable safe harbor requirements. The OIG is reiterating its view that while all payments related to referrals paid for by federal healthcare funds should always be FMV, the OIG looks at many more factors when considering if an arrangement is violative and the market should recalibrate its reliance on FMV accordingly.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67893_3_6a81eddc36c8d   " data-unique="jnews_module_67893_3_6a81eddc36c8d">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/feds-telling-how-mitigate-fca-liability/" aria-label="Read article: The Feds Are Telling You How to Mitigate FCA Liability; Have You Paid Attention?"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="doj building sign" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/doj-building-sign-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/doj-building-sign-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/doj-building-sign-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/doj-building-sign-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/compliance/">Compliance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/feds-telling-how-mitigate-fca-liability/">The Feds Are Telling You How to Mitigate FCA Liability; Have You Paid Attention?</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/veronica-nannis/">Veronica Nannis</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/feds-telling-how-mitigate-fca-liability/"><i class="fa fa-clock-o"></i> June 16, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Both DOJ and OIG have issued compliance guidance in recent years</p>
                                    <a href="https://www.corporatecomplianceinsights.com/feds-telling-how-mitigate-fca-liability/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67893_3_6a81eddc36c8d = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67142","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Anticipated Impact</span></h2>
<p><span style="font-weight: 400;">Expect to see the commercial reasonableness and bona fide business purpose tests play a much larger role in the OIG’s facts and circumstances analysis of arrangements that fall outside safe harbor protections. Commercial reasonableness asks why a payment is happening. Does the arrangement make sense independent of any referrals? An arrangement is commercially reasonable if it is sensible for well-informed parties to enter into it even if they are not in a position to generate business for one another. The bona fide business purpose test looks at whether the services are necessary, real and actually provided. These tests require a much more detailed analysis than the FMV analysis, which only looks at how much is being paid and whether the amount is consistent with the market. </span></p>
<p><span style="font-weight: 400;">Accordingly, an arrangement that is compensated at FMV but is not commercially reasonable or fulfilling a bona fide business purpose will likely be found to violate the AKS. For example, leasing more space than is commercially reasonable at FMV; paying multiple medical directors FMV compensation when only one medical director is needed; and paying a referring physician at FMV for 50 hours of consulting when five hours is needed to meet the business need. These are all arrangements with FMV compensation that would fail one or both of the commercially reasonable and bona fide business purpose tests and likely violate the AKS. </span></p>
<p><span style="font-weight: 400;">In addition to more applications of the commercial reasonableness and bona fide business purpose tests, we expect to see greater reliance on the one purpose rule. The one purpose rule states that “[i]f one purpose of the payment is to induce referrals, the entire arrangement is illegal.” In application this means that where an arrangement is at FMV, is commercially reasonable and for a bona fide business purpose, if one underlying purpose of the arrangement is to induce referrals, the entire arrangement, regardless of multiple legitimate business purposes, is illegal. Accordingly, if the OIG can show that any part of the motivation for the arrangement was to secure referrals — such as an email stating that the arrangement may improve referrals — FMV, commercially reasonable, and a bona fide business purpose will not prevent a conviction.</span></p>
<p><span style="font-weight: 400;">Finally, we expect greater scrutiny of percentage-based fees that fluctuate based on the volume or value of referrals. As the OIG focuses on intent, percentage-based fee models may more frequently be viewed as circumstantial evidence of an intent to influence referrals and thereby increase the share in referral profits.</span></p>
<h6><span style="font-weight: 400;">This was </span><a href="https://www.spencerfane.com/insight/oig-reiterates-the-need-for-full-safe-harbor-compliance-and-reminds-the-health-care-industry-that-arrangements-relying-on-fair-market-value-alone-may-be-violative/" target="_blank" rel="noopener"><i><span style="font-weight: 400;">adapted with permission</span></i></a><span style="font-weight: 400;">.</span></h6>
<p>The post <a href="https://www.corporatecomplianceinsights.com/safe-harbor-compliance-means-more-than-fair-pricing-in-healthcare/">Safe Harbor Compliance Means More Than Fair Pricing in Healthcare</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Managing Tariff Risk Through the Rest of 2026</title>
		<link>https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/</link>
		
		<dc:creator><![CDATA[Charles Clevenger]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 11:00:46 +0000</pubDate>
				<category><![CDATA[Risk]]></category>
		<category><![CDATA[Supply Chain]]></category>
		<category><![CDATA[Trade Compliance]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67886</guid>

					<description><![CDATA[<p>The environment is likely to change even more with exclusions, negotiations, enforcement guidance, litigation and country-specific actions</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/">Managing Tariff Risk Through the Rest of 2026</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Charles Clevenger of UHY explains why country-level summaries no longer capture a company&#8217;s true tariff exposure — multiple duties can apply to one shipment and a rate that vanishes may be replaced by another — and lays out a disciplined approach to determining what applies now, planning for what could change and confirming how tariffs interact before repricing or reshuffling suppliers.</span></i></p>
</div>
<p><span style="font-weight: 400;">Halfway through 2026, another layer of complexity has been added to the tariff landscape. The expiration of the temporary 10% Section 122 import surcharge on July 24 removed one broadly applied cost from many imports. But on that date, </span><a href="https://ustr.gov/sites/default/files/files/Press/Releases/2026/FLIP%20301%20Investigation%20Final%20Action%20FRN%207-23-26%20FINAL.pdf" target="_blank" rel="noopener"><b>Section 301 tariffs</b></a><span style="font-weight: 400;"> took effect across 60 major US trading partners, generally at rates of 10% or 12.5%. Separate trade actions have added a 25% tariff to certain </span><a href="https://ustr.gov/about/policy-offices/press-office/press-releases/2026/july/ustr-section-301-action-brazils-unreasonable-acts-policies-and-practices" target="_blank" rel="noopener"><b>Brazilian</b> <b>imports</b></a><span style="font-weight: 400;">, while </span><a href="https://www.whitehouse.gov/fact-sheets/2026/07/fact-sheet-president-donald-j-trump-imposes-additional-tariffs-on-canada/" target="_blank" rel="noopener"><b>specified Canadian goods</b></a><span style="font-weight: 400;"> are scheduled to face an additional 50% tariff under Section 338 beginning Aug. 19, just a few days out from this writing. Section 232 tariffs continue to apply to steel, aluminum, copper and covered derivative products.</span></p>
<p><span style="font-weight: 400;">Each action has its own legal authority, effective date, product scope, exclusions and rules governing how it interacts with other duties. A tariff that disappears may be replaced by another. A rate that appears to apply to an entire country may exclude certain products. Multiple duties may apply to the same entry, while anti-stacking provisions may prevent certain combinations.</span></p>
<p><span style="font-weight: 400;">Businesses navigating the rest of the year need a disciplined process for determining what applies today, anticipating what could change and remaining flexible if duties are later modified or invalidated.</span></p>
<h2><span style="font-weight: 400;">Understand the tariff exposure at the product level</span></h2>
<p><span style="font-weight: 400;">Country-level tariff summaries can help executives understand the direction of trade policy but will not always capture total exposure.</span></p>
<p><span style="font-weight: 400;">The duty owed on a shipment may depend on its harmonized tariff schedule classification, country of origin, component materials, entry date and eligibility for an exclusion. The analysis may also need to consider ordinary customs duties, Section 232 or Section 301 tariffs, antidumping or countervailing duties and other <a href="https://www.corporatecomplianceinsights.com/tag/trade-compliance/" target="_blank" rel="noopener"><strong>trade measures</strong></a>.</span></p>
<p><span style="font-weight: 400;">The new Section 301 action involving 60 trading partners demonstrates the importance of product-level analysis. The action generally applies additional tariffs of 10% or 12.5%, subject to product exemptions and special calculations for certain trading partners. Products subject to Section 232 tariffs are excluded from the new action.</span></p>
<p><span style="font-weight: 400;">Brazil adds another layer. Certain Brazilian goods may be affected by both the separate 25% Section 301 action and the broader forced-labor-related Section 301 tariffs. Depending on the product and applicable exemptions, the additional Section 301 burden can reach 37.5% before considering ordinary duties or other charges.</span></p>
<p><span style="font-weight: 400;">Companies should determine which products are included in each tariff action and confirm that their country-of-origin treatment is accurate and well supported. That approach requires reviewing product classifications, sourcing and manufacturing details, applicable exclusions, the importer of record and relevant effective dates before estimating the financial impact.</span></p>
<h2><span style="font-weight: 400;">Plan for durability without assuming permanence</span></h2>
<p><span style="font-weight: 400;">The staying power of a tariff depends in part on the statute used to impose it; it remains to be seen how this will play out pending any litigation, but companies should assume these tariffs will be in place for an extended period.</span></p>
<p><span style="font-weight: 400;">Section 122 expressly limited the temporary surcharge to 150 days unless Congress extended it. Its July expiration was therefore built into the original action.</span></p>
<p><span style="font-weight: 400;">Other authorities operate differently. Section 301 tariffs can remain in place while the US seeks changes in another country’s trade practices. They may be modified through negotiations, product exclusions, administrative reviews or changes in policy. Section 232 measures can also remain in effect for extended periods because they are tied to national security findings rather than a fixed statutory expiration date.</span></p>
<p><span style="font-weight: 400;">The use of Section 338 against Canadian goods introduces an additional variable. That authority has been used infrequently, and the recently announced duties apply to broad lists of specified Canadian products, including some goods that qualify for preferential treatment under the United States-Mexico-Canada Agreement. Energy, potash, products subject to Section 232 and certain other goods are excluded.</span></p>
<p><span style="font-weight: 400;">For planning purposes, companies should treat tariffs currently in effect as part of their near-term cost structure while maintaining scenarios for modification, expansion or removal. Forecasts based on a single assumed rate may become outdated before a purchase order is fulfilled.</span></p>
<p><span style="font-weight: 400;">Scenario planning should include goods already ordered, products in transit and future purchases. It should also account for the possibility that things will change.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67886_4_6a81eddc39437   " data-unique="jnews_module_67886_4_6a81eddc39437">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/after-scotus-tariff-ruling-hard-work-begins/" aria-label="Read article: After SCOTUS Tariff Ruling, the Hard Work Begins"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="cargo ship heading into uncertain waters" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/02/cargo-ship-heading-into-uncertain-waters-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/02/cargo-ship-heading-into-uncertain-waters-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/02/cargo-ship-heading-into-uncertain-waters-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/02/cargo-ship-heading-into-uncertain-waters-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/featured/">Featured</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/after-scotus-tariff-ruling-hard-work-begins/">After SCOTUS Tariff Ruling, the Hard Work Begins</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/jennifer-gaskin/">Jennifer L. Gaskin</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/after-scotus-tariff-ruling-hard-work-begins/"><i class="fa fa-clock-o"></i> February 25, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p></p>
                                    <a href="https://www.corporatecomplianceinsights.com/after-scotus-tariff-ruling-hard-work-begins/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67886_4_6a81eddc39437 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"66283","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Follow the legal authority behind each action</span></h2>
<p><span style="font-weight: 400;">Legality cannot be evaluated across the tariff environment as a whole. Each tariff program rests on a distinct statute, administrative record and procedural history.</span></p>
<p><span style="font-weight: 400;">Current actions under Sections 232, 301 and 338 may raise different legal questions. A decision affecting one authority does not automatically determine the validity of another.</span></p>
<p><span style="font-weight: 400;">Businesses should continue complying with tariffs being collected while monitoring litigation and administrative developments relevant to their entries. They should also preserve classification records, entry documents, customs communications and proof of payment. Those materials may become important if a court decision, exclusion or agency action creates a recovery opportunity.</span></p>
<p><span style="font-weight: 400;">Legal uncertainty should also be incorporated into accounting and forecasting. A potential legal challenge generally does not eliminate the immediate cash requirement when goods enter the country, and a possible future refund should not be treated as available operating cash.</span></p>
<h2><span style="font-weight: 400;">Confirm tariffs stack before changing prices</span></h2>
<p><span style="font-weight: 400;">One of the most consequential questions for the rest of the year is whether multiple tariffs apply to the same product.</span></p>
<p><span style="font-weight: 400;">Some trade actions are imposed in addition to existing duties. Others contain exclusions designed to prevent overlap. The expired Section 122 surcharge, for example, generally applied in addition to other duties but did not apply to portions of imports already subject to Section 232 tariffs. The new 60-economy Section 301 action also excludes articles and parts covered by Section 232.</span></p>
<p><span style="font-weight: 400;">These provisions can produce different results for products with similar descriptions or </span><a href="https://www.corporatecomplianceinsights.com/tag/supply-chain/" target="_blank" rel="noopener"><b>supply chains</b></a><span style="font-weight: 400;">. A steel component may receive different treatment from the finished product containing it. Two products from the same supplier may fall under different tariff classifications and exclusion lists.</span></p>
<p><span style="font-weight: 400;">Companies should conduct a stacking analysis before changing customer prices, renegotiating supplier terms or shifting sourcing. Decisions made using an incomplete tariff rate can lock a business into unfavorable pricing or cause it to abandon a supplier that remains economically competitive after exclusions are considered.</span></p>
<h2><span style="font-weight: 400;">Connect customs compliance with commercial decisions</span></h2>
<p><span style="font-weight: 400;">Tariff management should involve procurement, finance, legal, tax, operations, </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> and sales. Each function controls information needed to assess the full impact.</span></p>
<p><span style="font-weight: 400;">Procurement knows which orders can be delayed, redirected or renegotiated. Customs professionals understand classification, origin and entry requirements. Finance should quantify margin and working-capital effects while legal evaluates contract language governing tariff increases, force majeure, price adjustments and refund ownership. Sales leaders need to understand which costs can be passed through to customers and which may need to be absorbed.</span></p>
<p><span style="font-weight: 400;">Contracts deserve particular attention. Businesses should determine who is responsible for duties under current shipping terms, whether pricing provisions permit tariff-related adjustments and who is entitled to a refund if duties previously passed through to a customer are later recovered.</span></p>
<p><span style="font-weight: 400;">This review is especially important for long-term agreements negotiated before the recent tariff actions and for open purchase orders involving goods that may enter after a new effective date.</span></p>
<h2><span style="font-weight: 400;">Treat refunds as an active workstream</span></h2>
<p><span style="font-weight: 400;">IEEPA refunds have created a </span><a href="https://www.corporatecomplianceinsights.com/what-antitrust-indirect-purchaser-doctrine-can-teach-tariff-refund-litigants/" target="_blank" rel="noopener"><b>meaningful recovery opportunity</b></a><span style="font-weight: 400;">, but the process requires active oversight.</span></p>
<p><span style="font-weight: 400;">Importers should identify potentially eligible entries, reconcile duties paid to their customs and accounting records, confirm the importer of record and review the status of each entry. They should also ensure that their banking information is properly established in the automated commercial environment. CBP requires eligible automated commercial environment account users to enroll for electronic refunds through the portal and provides reporting tools for monitoring refund status.</span></p>
<p><span style="font-weight: 400;">Companies should also examine whether recovered amounts affect customers, suppliers or other parties under their contracts. A refund received by the importer of record may represent a financial recovery for the company, an amount owed to a customer or a combination of both.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/managing-tariff-risk-through-rest-2026/">Managing Tariff Risk Through the Rest of 2026</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Companies Need to Know About the Evolving Youth Privacy Landscape</title>
		<link>https://www.corporatecomplianceinsights.com/what-companies-need-know-about-evolving-youth-privacy-landscape/</link>
		
		<dc:creator><![CDATA[Greg Szewczyk and Madison Etherington]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 11:04:57 +0000</pubDate>
				<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Data Governance]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67879</guid>

					<description><![CDATA[<p>With numerous state youth data laws passed and more in the works, count on a patchwork adding to compliance requirements</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/what-companies-need-know-about-evolving-youth-privacy-landscape/">What Companies Need to Know About the Evolving Youth Privacy Landscape</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">There is no single compliance model for handling minors’ data, but companies can take several steps now to mitigate the risks, attorneys Greg Szewczyk and Madison Etherington of Ballard Spahr explain. </span></i></p>
</div>
<p><span style="font-weight: 400;">For years, many companies treated youth’s privacy on their apps as a narrow </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> question: Is the app directed to users under 13 years old, or does the company have actual knowledge a user is younger than 13?</span></p>
<p><span style="font-weight: 400;">The federal Children’s Online Privacy Protection Act (COPPA) remains a cornerstone for children’s privacy compliance, but state laws are rapidly joining and expanding the scope of efforts to regulate how businesses collect, use and share young people’s personal information online. App store accountability measures add yet another layer by introducing new evaluation and notice requirements governing methods by which companies receive age-related information. </span></p>
<p><span style="font-weight: 400;">As a result, businesses are being forced to review the way they collect and process information of users.</span></p>
<p><a href="https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312" target="_blank" rel="noopener"><b>COPPA</b></a><span style="font-weight: 400;"> applies to operators of websites and online services directed to youths under 13 as well as those that have actual knowledge that they collect personal information from someone under 13. Covered operators must provide notice and obtain verifiable parental consent before collecting, using or disclosing such </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">This baseline, however, is evolving. </span><a href="https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data" target="_blank" rel="noopener"><b>The FTC finalized COPPA Rule amendments in 2025</b></a><span style="font-weight: 400;"> that, among other changes, require separate parental opt-in consent before certain disclosures of youths’ personal information to third parties for targeted advertising.</span></p>
<p><span style="font-weight: 400;">In general, businesses should continue to treat COPPA as a floor for compliance, generally disclosing that products or services are not directed at children and that information will not be collected from children without first obtaining verifiable parental consent. In the event a company becomes aware of the inadvertent collection of children’s information, it should be immediately remediated by deleting the information and ceasing all related processing.</span></p>
<p><span style="font-weight: 400;">However, while </span><a href="https://www.corporatecomplianceinsights.com/what-recent-ftc-enforcement-actions-reveal-coppa-risks/" target="_blank" rel="noopener"><b>COPPA has been the baseline</b></a><span style="font-weight: 400;"> governing processing of children’s information for years, a growing number of state privacy laws are beginning to regulate </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> belonging to teenagers separately.</span></p>
<h2><span style="font-weight: 400;">Teen data is becoming its own compliance category</span></h2>
<p><span style="font-weight: 400;">Several states have begun to enact laws that require businesses to treat the data of individuals between 13 and 18 differently.</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><a href="https://ag.ny.gov/sites/default/files/2025-05/nycdpa-guidance.pdf" target="_blank" rel="noopener"><b>New York’s Child Data Protection Act</b></a><span style="font-weight: 400;"> regulates personal data belonging to covered users under 18. For users 13-17 years old, certain processing must either be strictly necessary for specified activities or supported by informed consent. The law also limits some uses of personal data collected while a user was a minor after the user becomes an adult.</span></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_454_hb0567e.pdf" target="_blank" rel="noopener"><b>Maryland’s Online Data Privacy Act</b></a><span style="font-weight: 400;"> prohibits targeted advertising and the sale of personal data involving consumers whom an organization knew or should have known were under 18.</span></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://arkleg.state.ar.us/Home/FTPDocument?path=%2FACTS%2F2025R%2FPublic%2FACT952.pdf" target="_blank" rel="noopener"><b>Arkansas’ Children and Teens’ Online Privacy Protection Act</b></a><span style="font-weight: 400;"> creates different obligations relating separately to children below 13 and teens ages 13-16 when a company has actual knowledge it collects their personal information.</span></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://coag.gov/resources/colorado-privacy-act/" target="_blank" rel="noopener"><b>Colorado’s Privacy Act</b></a><span style="font-weight: 400;"> was recently amended to provide additional protections over the data of children under 18 when a controller has actual knowledge or willfully disregards information that establishes that a user is a minor, and the Department of Law has rulemaking authority. In the draft rules that have been published, the attorney general lists factors that should be considered when determining whether a controller has willfully disregarded whether a consumer is a minor. Those factors include if the user can provide their age, if the user can edit their age, if the user has a bio section of a profile, if there is indicia of age, such as grade level, and if the company categorizes them differently for marketing purposes. However, the draft rules expressly state that the list is not exhaustive, and the determination will be based on the totality of the circumstances.</span></li>
</ul>
<p><span style="font-weight: 400;">Because of this breadth of legislation, companies face highly granular questions: When does it make sense — or become mandatory — to disable targeted advertising altogether? To limit third-party sharing? To restrict social features? In some situations, creating dedicated interfaces just for minors might offer the simplest path forward.</span></p>
<p><span style="font-weight: 400;">Along with the US, Canada’s approach is continuing to develop. In May 2026, the Office of the Privacy Commissioner of Canada </span><a href="https://www.priv.gc.ca/en/privacy-topics/age-assurance/aa-gd-web/" target="_blank" rel="noopener"><b>released guidance</b></a><span style="font-weight: 400;"> advising organizations to assess whether age assurance is necessary, use methods proportionate to the </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risks</b></a><span style="font-weight: 400;"> involved and consider alternatives, such as limiting certain data practices or turning them off by default.</span></p>
<p><span style="font-weight: 400;">Canada’s </span><a href="https://laws-lois.justice.gc.ca/eng/acts/p-8.6/" target="_blank" rel="noopener"><b>Personal Information Protection and Electronic Documents Act</b></a><span style="font-weight: 400;"> requires meaningful consent before organizations collect, use or disclose any individual’s personal information. </span><a href="https://www.priv.gc.ca/en/privacy-topics/business-privacy/collecting-personal-information/consent/gl_omc_201805/" target="_blank" rel="noopener"><b>Canadian guidance</b></a><span style="font-weight: 400;"> says parental/guardian permission is needed below age 13, while older minors’ maturity level matters more than simple birthdate cutoff. </span><a href="https://www.legisquebec.gouv.qc.ca/fr/document/lc/p-39.1?langCont=en" target="_blank" rel="noopener"><b>Quebec goes further</b></a><span style="font-weight: 400;">, barring collection directly from minors under 14 years old without parent or tutor permission unless the collection is clearly for the minor’s benefit.</span></p>
<p><span style="font-weight: 400;">Ultimately, companies should not assume that one national policy will satisfy every age threshold, consent standard or advertising restriction. All policies deserve careful review against each region’s definitions, age thresholds, consent requirements and restrictions on marketing, profiling and data transfers.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67879_5_6a81eddc3be4c   " data-unique="jnews_module_67879_5_6a81eddc3be4c">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/" aria-label="Read article: A Field Guide to Privacy Law for Companies Entering the US Market"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="us flags on wall street" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-flags-on-wall-street-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-flags-on-wall-street-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-flags-on-wall-street-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-flags-on-wall-street-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/compliance/">Compliance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/">A Field Guide to Privacy Law for Companies Entering the US Market</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/kevin-coy-erin-doyle/">Kevin Coy and Erin Doyle</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/"><i class="fa fa-clock-o"></i> July 20, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Businesses wanting to operate in the US have a variety of laws and regulations to consider</p>
                                    <a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67879_5_6a81eddc3be4c = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67640","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">App-store age signals are an emerging compliance issue</span></h2>
<p><span style="font-weight: 400;">App-store accountability laws create another compliance layer. Rather than leaving every developer solely responsible for building a separate age gate, these laws allocate responsibilities among app stores, operating-system providers and app developers.</span></p>
<p><span style="font-weight: 400;">With multiple laws already passed — and several laws that have been proposed — we are likely to see a patchwork that adds to the confusion. Some of these laws will place the core age-verification and parental-consent obligations on app stores while requiring developers to provide age ratings and notifications. Others will be more developer-facing. And to make matters more complicated, legal challenges will impact the timing and scope of the laws.</span></p>
<p><span style="font-weight: 400;">For example, </span><a href="https://legiscan.com/TX/text/SB2420/2025" target="_blank" rel="noopener"><b>Texas S.B. 2420</b></a><span style="font-weight: 400;"> took effect after</span> <a href="https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-victory-protecting-children-online-requiring-age" target="_blank" rel="noopener"><b>the Fifth Circuit stayed a preliminary injunction blocking the law</b></a><span style="font-weight: 400;">. The law requires covered app stores to verify users’ age categories, associate minor accounts with parent accounts and obtain parental consent in specified circumstances. App stores must also make age-category and consent information available to developers. Developers in turn must assign age ratings, respond to significant changes and use the information consistently with the law’s restrictions.</span></p>
<p><span style="font-weight: 400;">To make matters more complicated for app developers, app stores may have their own requirements.</span></p>
<h2><span style="font-weight: 400;">Compliance requires more than a privacy-notice update</span></h2>
<p><span style="font-weight: 400;">Companies should begin to mitigate risk in handling minors’ data by determining whether they are collecting any data within the scope of any of these laws, which may not be as simple as whether they are collecting just age data. Companies then need to assess the value of that data, what kinds of compliance obligations may need to be met and what kind of operational changes may need to be made. Vendor contracts, analytics tools and advertising technologies should also be reviewed to confirm that minors’ information is not transmitted in ways that conflict with the company’s policy or applicable law.</span></p>
<h6><i><span style="font-weight: 400;">Ballard Spahr summer associate T’Phani Perley-Schiele contributed to this report.</span></i></h6>
<p>The post <a href="https://www.corporatecomplianceinsights.com/what-companies-need-know-about-evolving-youth-privacy-landscape/">What Companies Need to Know About the Evolving Youth Privacy Landscape</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Telling Moments Compliance Leaders May Overlook in Investigations</title>
		<link>https://www.corporatecomplianceinsights.com/telling-moments-compliance-leaders-may-overlook/</link>
		
		<dc:creator><![CDATA[Pamela Meyer]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 11:02:58 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Internal Investigation]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67875</guid>

					<description><![CDATA[<p>Understanding how people recount details in an interview is just as important as the words they say</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/telling-moments-compliance-leaders-may-overlook/">Telling Moments Compliance Leaders May Overlook in Investigations</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">A compliance leader’s advantage is rarely access to more words when investigating possible wrongdoing; it is the ability to notice when the words become hard to say or grow vague and devoid of accountability, writes author and speaker Pamela Meyer. And be warned: That is often where the unexamined risk sits. </span></i></p>
</div>
<p><span style="font-weight: 400;">Intake calls, <a href="https://www.corporatecomplianceinsights.com/tag/internal-investigation" target="_blank" rel="noopener"><strong>investigative interviews</strong></a> and executive briefings produce lots of information that </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> leaders unknowingly miss. Most professionals are not trained to notice or track patterns in hesitation. Their notes might record what an employee alleged but not the moment “I saw” became distancing language, such as “People are concerned,” or the point at which a detailed account collapsed into, “And then there were some issues.”</span></p>
<p><span style="font-weight: 400;">Those changes matter. While they do not prove dishonesty or culpability, they can be signals that the conversation has entered difficult territory.</span></p>
<p><span style="font-weight: 400;">Compliance professionals are trained to separate fact from impression. That discipline is essential, but it can lead them to discard useful information. A shift in language, timing or participation can mark an inflection point where memory becomes strained or personal exposure increases.</span></p>
<h2><span style="font-weight: 400;">Understanding story structure</span></h2>
<p><span style="font-weight: 400;">We listen carefully to the content of someone’s story, but we rarely pay attention to the story’s structure. People rarely admit that they are afraid of naming a senior executive, implicating a colleague or exposing their own failure to act. But if you pay attention to how a story is told, the red flags will emerge.</span></p>
<p><span style="font-weight: 400;">Callers often begin with direct observation: “I saw him change the numbers.” A few minutes later, when asked who knew, they retreat into collective language: “People were uncomfortable.” Another employee describes an ordinary meeting in close detail, then reduces the crucial 20 minutes to “we discussed the situation.” A third minimizes the allegation before stating it: “This may be nothing, and I do not want to cause trouble, but … ”</span></p>
<p><span style="font-weight: 400;">Here are some red flags an interviewer should notice and dig deeper on:</span></p>
<h3><span style="font-weight: 400;">Stories told in strict, rehearsed-sounding chronological order</span></h3>
<p><span style="font-weight: 400;">Natural, honest stories tend to be told with the most emotional elements of the story being most prominent. “The conference went well … Oh, but the speaker fell off the stage at the end.” Or, “When we arrived, I saw him throw the documents in the trash in the lobby.” Stories that jump around tend to be honest. The executive who needs to avoid key facts will provide a too-clean chronology.</span></p>
<h3><span style="font-weight: 400;">Main event pushed to the end of the story, no epilogue</span></h3>
<p><span style="font-weight: 400;">Most compliance issues revolve around a particular event of concern. If the story is told with the main event pushed to the end without an emotional remark to close it, ask a few more questions. “I can’t believe I left the door unlocked. I feel terrible that it was stolen” would be a typical closing epilogue that includes emotion.</span></p>
<h3><span style="font-weight: 400;">Inappropriate amount of detail </span></h3>
<p><span style="font-weight: 400;">Do you have a teenager? “I missed curfew because the bus broke, then I had to walk 5 blocks, look at the holes in my shoes from it.” We include unnecessary details to bolster our accounts in an attempt to seem credible, yet that backfires and undermines the story. Check for the right amount of detail throughout.</span></p>
<h3><span style="font-weight: 400;">Distancing language</span></h3>
<p><span style="font-weight: 400;">Notice where the account loses ownership or resolution. That point may indicate fear of retaliation, uncertainty about what was observed or embarrassment about one’s own role. “The invoice was approved,” “There may have been some issues,” “People started asking questions” all remove the actor. The meaningful moment comes when someone who typically names people stops doing so around one event.</span></p>
<h3><span style="font-weight: 400;">Shift in behavioral baseline </span></h3>
<p><span style="font-weight: 400;">A useful baseline comes from the speaker’s ordinary communication pattern. Note their cadence, tone, laugh and posture. Some people pause often, qualify everything or speak in broad summaries. Those habits become informative only when they change around the discussion of a particular person, period, event or decision. If you don’t know the subject’s typical baseline, then ask a few questions at the beginning of the interview to get a reliable reference point for measuring changes later. “What are you doing this weekend?” or “How was lunch?” can put the subject at ease, letting you see how they usually communicate when they’re not under pressure.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67875_6_6a81eddc3ebfd   " data-unique="jnews_module_67875_6_6a81eddc3ebfd">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/once-you-have-decided-self-disclose-how-do-right/" aria-label="Read article: Once You&#8217;ve Decided to Self-Disclose, Here&#8217;s How to Do It Right"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="us doj building with flag" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-doj-building-with-flag-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-doj-building-with-flag-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-doj-building-with-flag-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/us-doj-building-with-flag-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/featured/">Featured</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/once-you-have-decided-self-disclose-how-do-right/">Once You&#8217;ve Decided to Self-Disclose, Here&#8217;s How to Do It Right</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/sean-farrell-thomas-rybarczyk/">Sean M. Farrell and Thomas F. Rybarczyk</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/once-you-have-decided-self-disclose-how-do-right/"><i class="fa fa-clock-o"></i> July 29, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p></p>
                                    <a href="https://www.corporatecomplianceinsights.com/once-you-have-decided-self-disclose-how-do-right/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67875_6_6a81eddc3ebfd = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67795","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">What to do when the story changes</span></h2>
<p><span style="font-weight: 400;">Always start with open-ended questions. Ask, “Take me through what happened” not, “Where were you at 7 p.m.?” Let your subject talk and develop rapport before narrowing your focus.</span></p>
<p><span style="font-weight: 400;">Do not confront behavioral shifts. Anxiety can reflect fear, shame, divided loyalty or simple cognitive strain. Naming the hesitation or saying, “You seem nervous” only makes your subject self-conscious and shows where your concern lies. Note the change privately and keep asking neutral questions.</span></p>
<p><span style="font-weight: 400;">Freeze the moment where the account loses detail. Ask for the 60 seconds before and after the story becomes vague: Who spoke first? What words were used? What did the person do next? People often compress the part of an account that carries the greatest psychological cost.</span></p>
<p><span style="font-weight: 400;">Hold back the evidence. Get the complete account before introducing emails, calendar entries or access records. Then present one item at a time and ask the person to reconcile it with what they already said. Showing the evidence too early gives them the facts needed to repair the story.</span></p>
<h2><span style="font-weight: 400;">Signs power is distorting the decision</span></h2>
<p><span style="font-weight: 400;">Commercial concerns can influence how evidence is judged, so a few areas to watch here include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Consensus that appears before discussion. If a senior leader says, “I think we all agree this was poor judgment, not misconduct,” before others have spoken, request that each person state an independent view.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The allegation is softened. When retaliation becomes a “performance issue” or falsification becomes a “process breakdown,” restate the original conduct without interpretation before the softer label becomes part of the lexicon.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The discussion turns to calculating the cost of discipline. If lost clients, missed targets or succession problems become prominent elements of the conversation before the compliance analysis is complete, pause and restate what happened first.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Rank changes the likely outcome. Replace the executive’s name with “regional manager” and ask what action the same facts would produce if the employee had less status and fewer protectors.</span></li>
</ul>
<p><span style="font-weight: 400;">Also, the order of discussion matters. Establish the conduct and the standard before considering commercial consequences. Otherwise, business impact becomes an unofficial test of whether the rules apply. </span></p>
<p><span style="font-weight: 400;">The leader who carefully tracks language patterns and follows up at the right time with a better question has a greater chance of identifying problems before their organization is forced to explain why it did not prevent a crisis.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/telling-moments-compliance-leaders-may-overlook/">Telling Moments Compliance Leaders May Overlook in Investigations</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks</title>
		<link>https://www.corporatecomplianceinsights.com/audit-dominated-risk-oversight-leaves-boards-blind-modern-risks/</link>
		
		<dc:creator><![CDATA[Adley John Fisher]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 11:00:18 +0000</pubDate>
				<category><![CDATA[Governance]]></category>
		<category><![CDATA[Internal Audit]]></category>
		<category><![CDATA[Board of Directors]]></category>
		<category><![CDATA[Board Risk Oversight]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67871</guid>

					<description><![CDATA[<p>The solution won’t be found in incremental tweaks to existing compliance templates but in a spirit to change how the board is built</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/audit-dominated-risk-oversight-leaves-boards-blind-modern-risks/">Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Enterprise risk oversight anchored primarily in audit was once sufficient, but today, it is a blind spot, writes Adley John Fisher, risk management professional. Boards that continue relying predominantly on assurance-based visibility may remain formally compliant while becoming strategically blind to emerging enterprise exposure.</span></i></p>
</div>
<p><span style="font-weight: 400;">Over the past two decades, </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>boards</b></a><span style="font-weight: 400;"> have formally expanded their responsibility for </span><a href="https://www.corporatecomplianceinsights.com/tag/board-risk-oversight/" target="_blank" rel="noopener"><b>enterprise risk oversight</b></a><span style="font-weight: 400;">. In practice, however, the </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> structures through which most boards oversee </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> remain deeply anchored in </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>audit</b></a><span style="font-weight: 400;"> and </span><a href="https://www.corporatecomplianceinsights.com/tag/financial-reporting/" target="_blank" rel="noopener"><b>financial reporting</b></a><span style="font-weight: 400;"> paradigms. While this design was historically appropriate, it has become increasingly misaligned with the sources of today’s most consequential corporate failures.</span></p>
<p><span style="font-weight: 400;">Audit-dominated </span><a href="https://www.corporatecomplianceinsights.com/tag/risk-assessment/" target="_blank" rel="noopener"><b>risk oversight</b></a> <span style="font-weight: 400;">has transitioned from a historical standard to a modern governance liability. Current board-level risk architectures tend to systematically privilege financial assurance over proactive risk intelligence, can suppress weak operational and technical signals and leave boards exposed to failures that are foreseeable in retrospect but invisible in advance.</span></p>
<h2><span style="font-weight: 400;">The structural legacy of audit-anchored risk oversight</span></h2>
<p><span style="font-weight: 400;">Board-level risk oversight did not evolve by accident. Modern governance frameworks grew out of a period in which financial integrity, regulatory </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> and internal controls represented the dominant sources of corporate risk. In that context, anchoring risk oversight within audit committees was rational, efficient and widely considered the proper governance standard.</span></p>
<p><span style="font-weight: 400;">But risk has evolved. Today, the threats most likely to destabilize organizations increasingly originate outside traditional financial reporting domains. They arise across cyber, operations, supply chains, technology, </span><a href="https://www.corporatecomplianceinsights.com/tag/corporate-culture/" target="_blank" rel="noopener"><b>culture</b></a><span style="font-weight: 400;"> and strategy. As complexity has increased, so has the strain on governance structures. </span></p>
<p><span style="font-weight: 400;">As highlighted in the </span><a href="https://www.ecgi.global/sites/default/files/codes/documents/walker_review_261109.pdf" target="_blank" rel="noopener"><b>2009 Walker Review</b></a><span style="font-weight: 400;">, governance reforms after the financial crisis explicitly recognized the need to reduce overload on audit committees and introduced the concept of separate board risk committees to improve forward-looking risk oversight. </span><a href="https://www.zscaler.com/blogs/cxo-insights/analysis-board-level-cybersecurity-risk-oversight" target="_blank" rel="noopener"><b>Empirical evidence</b></a> <span style="font-weight: 400;">reinforces this structural pattern. As of 2026, </span><a href="https://www.linkedin.com/pulse/cyber-audit-committee-strategic-red-flag-rob-sloan-zfhzc/" target="_blank" rel="noopener"><b>nearly 80% of S&amp;P 500 companies</b></a><span style="font-weight: 400;"> assign </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;"> risk oversight to the audit committee with fewer than 10% assigning it to a dedicated risk committee.</span></p>
<p><span style="font-weight: 400;">This structural legacy creates a pull toward audit-centric thinking, and the methodology heavily favors risks that are easy to quantify, audit and map to existing internal controls but may under-emphasize emerging systemic threats that lack historical precedent or measurable assurance indicators. The limitation is not audit itself but its design, which is to assess whether controls work, not whether underlying assumptions about risk still hold.</span></p>
<p><span style="font-weight: 400;">At its core, this reveals a tension between retrospective assurance and proactive risk intelligence. Audit is necessarily backward-looking in its primary function, validating that controls function as intended. Risk oversight, by contrast, must be forward-looking, assess emerging exposure and anticipate how complex systems may fail under stress before control failures become visible.</span></p>
<p><span style="font-weight: 400;">When risk is governed primarily through an audit lens, boards may inadvertently receive lagging indicators presented as forward-looking assurance. This creates a dangerous paradox where strong assurance over existing controls grows exposure to risks those controls were never designed to address. Major failures like </span><a href="https://www.scirp.org/pdf/me_2021092814371880.pdf" target="_blank" rel="noopener"><b>Wirecard</b></a><span style="font-weight: 400;"> and </span><a href="https://publications.parliament.uk/pa/cm201719/cmselect/cmworpen/769/76903.htm" target="_blank" rel="noopener"><b>Carillion</b></a><span style="font-weight: 400;"> illustrate this pattern as partial contributing factors rather than sole causes. Boards were not short of data, but the data was filtered through an audit paradigm that prioritized compliance while obscuring deeper operational, cultural and technological fragilities. </span></p>
<h2><span style="font-weight: 400;">The filtering of weak signals</span></h2>
<p><span style="font-weight: 400;">Today, the earliest indicators of significant failure rarely appear first in financial statements. More often than not, they emerge as weak operational or technical signals. It starts with a subtle deterioration in safety culture or recurring technology workarounds. It looks like near-miss incidents, </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data governance</b></a> <span style="font-weight: 400;">weaknesses, </span><a href="https://www.corporatecomplianceinsights.com/tag/supply-chain/" target="_blank" rel="noopener"><b>supply chain</b></a><span style="font-weight: 400;"> dependencies, talent capability gaps or abnormal operational behaviors. Individually, these issues appear manageable. Collectively, they are systemic.</span></p>
<p><span style="font-weight: 400;">In audit-dominated structures, these signals often require translation into financial, compliance or control-based language before escalation to the board. This translation process acts as a corporate filter.</span></p>
<p><span style="font-weight: 400;">The </span><a href="https://www.gsb.stanford.edu/faculty-research/publications/solar-flare-systemic-organizational-risk-residential-solar-industry" target="_blank" rel="noopener"><b>systemic blind spots</b></a><span style="font-weight: 400;"> caused by these filters are reflected in governance case studies like</span><a href="https://www.gsb.stanford.edu/faculty-research/publications/boeing-737-max" target="_blank" rel="noopener"> <b>Boeing’s 737 MAX</b></a><span style="font-weight: 400;">, where cultural, engineering and escalation </span><a href="https://www.corporatecomplianceinsights.com/boeing-saga-whitepaper/" target="_blank" rel="noopener"><b>failures</b></a><span style="font-weight: 400;"> prevented early warning signals from reaching the board effectively. Signals that are operationally significant but not yet financially measurable are often deprioritized, softened or absorbed within management reporting layers before reaching directors. As a result, boards may maintain strong visibility over control compliance while possessing limited visibility over the organization’s true exposure landscape.</span></p>
<p><span style="font-weight: 400;">Recent governance failures demonstrate that boards often struggle not because information was entirely absent but because the information reaching them </span><a href="https://democrats-transportation.house.gov/committee-activity/boeing-737-max-investigation" target="_blank" rel="noopener"><b>had already been filtered</b></a><span style="font-weight: 400;"> through assurance-oriented reporting pathways. These pathways naturally prioritize control effectiveness, policy adherence and measurable compliance metrics over unresolved ambiguity, technical complexity or systemic vulnerability. Governance visibility becomes strongest where uncertainty is lowest, while the organization’s most consequential emerging risks frequently remain outside the board’s direct field of vision until failure hits.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67871_7_6a81eddc41967   " data-unique="jnews_module_67871_7_6a81eddc41967">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/" aria-label="Read article: Out of Your Technological Depth? It’s Your Duty to Say So."><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="person reaching for help in sea" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/governance/">Governance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/">Out of Your Technological Depth? It’s Your Duty to Say So.</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/vera-cherepanova/">Vera Cherepanova</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/"><i class="fa fa-clock-o"></i> June 17, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>If a director can admit to not knowing enough to make a decision, it’s a sign the board has built and reinforced honesty</p>
                                    <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67871_7_6a81eddc41967 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67182","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Structural misalignment at board level</span></h2>
<p><span style="font-weight: 400;">Realistically, incremental enhancements to risk registers or reporting templates will not fix this. If the underlying oversight architecture remains unchanged, the structural misalignment stays. Instead, boards must fundamentally re-examine several foundational assumptions:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Mandate: </b><span style="font-weight: 400;">Is enterprise risk oversight concentrated within committees whose expertise and historical orientation remain primarily financial?</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Focus: </b><span style="font-weight: 400;">Does board reporting primarily emphasise control effectiveness and assurance outcomes, or does it also provide visibility into emerging exposure, operational uncertainty and systemic fragility?</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Escalation pathways:</b><span style="font-weight: 400;"> Are non-financial risks elevated only after they become measurable in financial or compliance terms?</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Expertise:</b><span style="font-weight: 400;"> Does the board consistently engage sufficient operational, technological, cyber, safety or systems-level expertise when overseeing complex enterprise risks?</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Information architecture: </b><span style="font-weight: 400;">Are directors receiving sufficiently unfiltered operational perspectives, or only management-curated assurance summaries designed around existing reporting structures?</span></li>
</ul>
<p><span style="font-weight: 400;">Research increasingly supports a clearer separation between audit assurance and enterprise risk oversight functions, particularly within large or operationally complex organizations. Such separation is not intended to diminish audit’s importance but to recognize that assurance and strategic risk oversight are distinct governance disciplines requiring different orientations, information flows and expertise.</span></p>
<p><span style="font-weight: 400;">But let&#8217;s be realistic — simply splitting into two entities may backfire. One wrong step and we end up creating information silos, turf wars over who owns what and a mountain of duplicated paperwork that bombards management while critical risks slip right through the cracks between committees.</span></p>
<h2><span style="font-weight: 400;">How to actually build a modern risk structure</span></h2>
<p><span style="font-weight: 400;">To make this work in the real world, a board should consider three practical changes:</span></p>
<h3><span style="font-weight: 400;">Separate the work, but connect the people</span></h3>
<p><span style="font-weight: 400;">The audit committee needs to keep its eyes firmly on the rear-view mirror, focusing on financial integrity, accounting controls, overall operational controls and legal compliance. At the same time, a dedicated risk committee needs to look through the windshield, focusing entirely on forward-looking vulnerabilities and systemic operational threats.</span></p>
<p><span style="font-weight: 400;">To prevent an oil-and-water situation between committees, the board should mandate that the chair of each committee sits as a member of the other, the old “in my shoes” method. Even better, bring both committees together twice a year for joint sessions to look at the overlap, like how a massive cyber breach would impact financial liability or the hidden compliance risks of deploying new AI tools.</span></p>
<h3><span style="font-weight: 400;">Create a direct line to the chief risk officer</span></h3>
<p><span style="font-weight: 400;">We have to stop looking at risk through a filter. The chief risk officer needs a direct, independent reporting line straight to the risk committee that is completely separate from the CFO&#8217;s office and parallel to how internal audit talks to the audit committee.</span></p>
<p><span style="font-weight: 400;">To ensure this line carries real value rather than polished corporate speak, board reporting should include explicit sections for unresolved operational anomalies and emerging risk themes, enabling directors to observe early warning signals rather than only formalized risk summaries.</span></p>
<h3><span style="font-weight: 400;">Put ‘systems-native’ directors in the room</span></h3>
<p><span style="font-weight: 400;">A new committee structure loses its effectiveness if the people sitting at the table don&#8217;t change. The </span><a href="https://www.corporatecomplianceinsights.com/tag/board-composition/" target="_blank" rel="noopener"><b>traditional board matrix</b></a><span style="font-weight: 400;">, usually packed with retired CEOs, CFOs and corporate lawyers, needs an injection of different real-world experience. If a company operates in a complex environment, the board must recruit at least one operationally native director.</span></p>
<p><span style="font-weight: 400;">These are people who have spent their careers running cybersecurity operations, managing messy supply chains, leading engineering teams in high-stakes industries, traveling from one workplace to another and understanding a screw press like it’s the back of their hand. When management presents a risk report, these directors know how to push past the talking points and stress-test the actual assumptions.</span></p>
<h2><span style="font-weight: 400;">Conclusion</span></h2>
<p><span style="font-weight: 400;">The issue is not the value of audit but its structural dominance within modern risk governance architectures. Governance systems designed around financial integrity and control assurance are increasingly ill-equipped to oversee risks that emerge from operational complexity, technological interdependence, organizational culture and systemic fragility. </span></p>
<p><span style="font-weight: 400;">Boards that recognize this structural gap and adapt by incorporating broader domain expertise, diversified reporting pathways and more direct exposure-focused intelligence, will likely be better positioned to fulfil their fiduciary responsibilities in substance rather than merely in form.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/audit-dominated-risk-oversight-leaves-boards-blind-modern-risks/">Audit‑Dominated Risk Oversight Leaves Boards Blind to Modern Risks</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>