<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Corporate Compliance Insights</title>
	<atom:link href="https://www.corporatecomplianceinsights.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<description>The Web's Premier News Source for Compliance, Ethics &amp; Risk</description>
	<lastBuildDate>Thu, 23 Jul 2026 15:04:28 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/11/cropped-Favicon-32x32.png</url>
	<title>Corporate Compliance Insights</title>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>The FCC’s Watchdog Is Mining Data Across Programs. Funding Recipients Should Take Note.</title>
		<link>https://www.corporatecomplianceinsights.com/fcc-watchdog-mining-data-across-programs/</link>
		
		<dc:creator><![CDATA[Diana Shaw, Megan Brown, Mark Sweet and Lois Ahn]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 11:00:36 +0000</pubDate>
				<category><![CDATA[Risk]]></category>
		<category><![CDATA[FCC]]></category>
		<category><![CDATA[Internal Controls]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67781</guid>

					<description><![CDATA[<p>New analytics let the OIG scale audits across larger populations and match risk indicators across programs, raising the exposure for recipients in multiple FCC funding streams</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/fcc-watchdog-mining-data-across-programs/">The FCC&#8217;s Watchdog Is Mining Data Across Programs. Funding Recipients Should Take Note.</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">The FCC&#8217;s Office of Inspector General is moving away from one-off audits of single recipients toward a data-driven model that matches risk indicators across programs and funding years. Diana Shaw, Megan Brown, Mark Sweet and Lois Ahn of Wiley explain what that means for funding recipients: a red flag in a pandemic-era program can now prompt scrutiny across a company&#8217;s other FCC funding.</span></i></p>
</div>
<p><span style="font-weight: 400;">Federal Communications Commission (FCC) funding recipients should prepare for greater scrutiny and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance risks</b></a><span style="font-weight: 400;"> as the agency’s Office of Inspector General (OIG) implements a broader, more data-driven approach to oversight. The </span><a href="https://www.fcc.gov/sites/default/files/FCC%20OIG%202026-2027%20CY%20Work%20Plan%20FINAL.pdf" target="_blank" rel="noopener"><b>FCC OIG’s 2026-27 work plan</b></a><span style="font-weight: 400;">, together with its recent reporting to Congress, signal that the OIG is increasingly using advanced analytics and cross-program </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> indicators to identify targets for audits and investigations. As a result, a red flag in one program, or even one funding year, may no longer stay confined there. For companies participating in FCC programs — including the emergency connectivity fund (ECF) and universal service fund (USF) — this shift raises the stakes for documentation, internal controls, remediation and readiness for OIG scrutiny.</span></p>
<h2><span style="font-weight: 400;">The work plan</span></h2>
<p><span style="font-weight: 400;">In late May, the OIG issued its 2026-27 work plan, outlining the audits, inspections and evaluations it plans to undertake over the next two years. The plan reflects the OIG’s continued focus on preventing fraud, waste and abuse in the FCC’s operations. But more notably, it indicates a more targeted and data-driven approach to oversight going forward, particularly for pandemic-era programs like the ECF. Read alongside OIG’s recent </span><a href="https://www.fcc.gov/sites/default/files/FCC-OIG-Spring-2026-Semiannual-Report-to-Congress.pdf" target="_blank" rel="noopener"><b>semiannual report to Congress</b></a><span style="font-weight: 400;">, the work plan reflects a more sophisticated approach to oversight, signaling the potential for broader scrutiny — and, therefore, greater exposure — for FCC funding recipients. In particular, issues identified in pandemic-era programs could result in scrutiny in other FCC funding streams, increasing compliance risks for entities that participate in multiple FCC programs.</span></p>
<p><span style="font-weight: 400;">The plan acts as a strategic roadmap and provides transparency around how the OIG intends to carry out its mission and focus its resources. Among other things, the plan identifies the OIG’s expected discretionary projects. Because these projects are elective, their focus and the challenges they are meant to address offer useful insights into office priorities for the next two years. Among the discretionary projects in the 2026-27 work plan are: “A risk-based review of </span><a href="https://www.fcc.gov/emergency-connectivity-fund" target="_blank" rel="noopener"><b>ECF</b></a><span style="font-weight: 400;"> participants to determine compliance with program requirements and identify potential fraud and improper payments,” and “A review of USAC’s program integrity activities, processes, and protocols related to </span><a href="https://www.fcc.gov/general/universal-service" target="_blank" rel="noopener"><b>USF</b></a><span style="font-weight: 400;">.”</span></p>
<p><span style="font-weight: 400;">Safeguarding the integrity of the USF and pandemic-era programs has been an important oversight priority of the FCC OIG for years. But due to limited resources, the OIG’s oversight of these programs had been discrete and less systematic in prior years. For instance, in the past, audits focused on a single funding recipient, such as a single rural healthcare facility or a single county public library and assessed its compliance with program rules during one or two funding years. Even when the OIG pursued a program-wide audit, it did so through a narrow lens, typically focusing on narrow time periods, discrete program elements and/or relatively small samples.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67781_0_6a673ac12dcf5   " data-unique="jnews_module_67781_0_6a673ac12dcf5">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/when-oversight-findings-lead-more-oversight-oig-china-exports/" aria-label="Read article: When Oversight Findings Lead to More Oversight: An OIG Report on China Exports"><div class="thumbnail-container animate-lazy  size-500 "><img fetchpriority="high" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="shipping containers" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/shipping-containers-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/shipping-containers-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/shipping-containers-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/shipping-containers-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/opinion/">Opinion</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/when-oversight-findings-lead-more-oversight-oig-china-exports/">When Oversight Findings Lead to More Oversight: An OIG Report on China Exports</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/parisa-salehi/">Parisa Salehi</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/when-oversight-findings-lead-more-oversight-oig-china-exports/"><i class="fa fa-clock-o"></i> July 15, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Six steps exporters should take to ready their due diligence, documentation and escalation for closer scrutiny</p>
                                    <a href="https://www.corporatecomplianceinsights.com/when-oversight-findings-lead-more-oversight-oig-china-exports/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67781_0_6a673ac12dcf5 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67554","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">A data-driven shift at FCC OIG</span></h2>
<p><span style="font-weight: 400;">The FCC OIG’s most recent work plan suggests that it may be adopting a new approach to how it scopes and executes its discretionary projects. The plan and report to Congress suggest that the office has adopted an integrated, data-driven and risk-based oversight model that, importantly, leverages cross-program analytics to better target limited resources.</span></p>
<p><span style="font-weight: 400;">Specifically, the work plan notes that the OIG intends to “us[e] </span><a href="https://www.corporatecomplianceinsights.com/tag/data-analytics/" target="_blank" rel="noopener"><b>data analytics</b></a><span style="font-weight: 400;"> to focus on high-risk areas and prioritiz[e] work that will assist FCC in addressing its top challenges.” The report to Congress elaborates on this intent, describing the OIG’s partnership with the Pandemic Response Accountability Committee (PRAC). The </span><a href="https://www.pandemicoversight.gov/media/file/pace-fact-sheetaugust-24-20210pdf" target="_blank" rel="noopener"><b>PRAC</b></a><span style="font-weight: 400;"> established the Pandemic Analytics Center of Excellence (PACE) to provide “a leading-edge analytic platform with the capacity and scale to help oversee more than $5 trillion in pandemic-related emergency spending.” PACE offers a range of analytic support tools to OIGs that include “data matching, anomaly detection, risk modeling, social network analysis, robotic process automation, link analysis, business intelligence, and open-source intelligence.”</span></p>
<p><span style="font-weight: 400;">These offerings have vastly enhanced federal OIGs’ ability to identify higher-risk recipients, detect anomalous patterns across large datasets and target audits and investigations more efficiently. With respect to the FCC OIG in particular, it has enabled the agency to develop data dashboards to better identify risks in three pandemic-era FCC programs: ECF, the </span><a href="https://www.corporatecomplianceinsights.com/tag/coronavirus-covid-19/" target="_blank" rel="noopener"><b>Covid-19</b></a><span style="font-weight: 400;"> telehealth program and the Emergency Broadband Benefit Program. According to the spring report, the dashboards incorporate over 30 risk indicators, such as “Small Business Administration fraud hold codes,” “delinquent federal debt” and “single audit findings,” drawn from various federal datasets. And by matching the risk indicators with the FCC’s program participants, the dashboards help the OIG identify high-risk targets for potential audits and investigations.</span></p>
<p><span style="font-weight: 400;">OIG auditors and investigators are already actively using the dashboards for their investigation and inspection of the Covid-19 telehealth program, and will use them for a “full scope risk-based review of the ECF program.” Participants who trigger multiple risk indicators will likely face heightened scrutiny, particularly where those indicators point to potential fraud, improper payments or weak internal controls.</span></p>
<h3><span style="font-weight: 400;">Scaling oversight through data analytics</span></h3>
<p><span style="font-weight: 400;">These same tools also may allow the FCC OIG to scale the scope of its audits and investigations in ways that were more difficult under its prior, more discrete oversight model. Rather than reviewing a single recipient, a narrow funding period or a limited sample of transactions, the OIG can use the analytical tools now available to identify patterns across larger populations of participants, longer time periods and multiple risk indicators. This may enable the office to design broader reviews that test compliance issues across a wider universe of recipients while still focusing investigative resources on those entities or transactions that appear most anomalous. In practice, that means future audits and investigations may be both broader in reach and more targeted in execution, increasing the likelihood that issues identified in one subset of data will prompt expanded review of related recipients, claims or funding periods.</span></p>
<h3><span style="font-weight: 400;">Expanded exposure across FCC funding streams</span></h3>
<p><span style="font-weight: 400;">Furthermore, the OIG’s new oversight approach may have implications beyond the specific pandemic-era programs under review. The office explained in its semiannual report that because “bad actors do not limit their fraud,” it enhanced the dashboards “to identify recipients in the[] COVID-era programs that participate in and receive funds from other similar FCC programs, such as Lifeline, E-Rate, and Rural Health Care.” The OIG further explained that though receiving subsequent funding is not itself problematic, being flagged for fraud, improper payments or other issues within the pandemic-era programs could result in scrutiny in multiple other FCC funding streams.</span></p>
<p><span style="font-weight: 400;">This is a meaningful development for FCC funding recipients. A finding or red flag in an emergency Covid program may prompt broader scrutiny of the participant’s conduct across other FCC funding streams, including ongoing USF programs. Taken together, the work plan and semiannual report indicate that the FCC OIG is working toward a more integrated oversight infrastructure, one that combines external datasets, interagency partnerships, risk scoring and cross-program review to identify targets and pursue remedies. This approach may allow the OIG to conduct broader and more targeted oversight despite its limited resources and may increase the compliance stakes for entities that participate in multiple FCC funding programs.</span></p>
<h2><span style="font-weight: 400;">Implications for firms participating in FCC funding programs</span></h2>
<p><span style="font-weight: 400;">For companies that participate in FCC funding programs, the key takeaway is that compliance issues are increasingly unlikely to remain isolated to a single claim, funding year or program. As the OIG becomes better able to identify patterns across datasets and funding streams, participants should expect that weak documentation, recurring control failures or unresolved audit findings may receive greater attention and potentially trigger broader review.</span></p>
<p><span style="font-weight: 400;">These risks are all the more significant in light of the FCC’s </span><a href="https://www.wiley.law/printpilot-publication-FCC-Undertakes-Major-Overhaul-With-New-Suspension-and-Debarment-Rules.pdf?1782310262" target="_blank" rel="noopener"><b>recent adoption</b></a><span style="font-weight: 400;"> of its own suspension-and-debarment program, which gives the agency a formal mechanism to exclude companies or individuals from participation in FCC funding programs such as the USF. The implications of a debarment under the program are not limited to FCC funding: Barred entities may also be precluded from doing business with the federal government more broadly.</span></p>
<p><span style="font-weight: 400;">Companies should therefore assess whether their compliance programs and internal controls are calibrated not only to meet program-specific requirements but also to withstand a more holistic, data-driven oversight review. In practical terms, that means maintaining clear support for funding requests and certifications, promptly remediating identified weaknesses and ensuring that compliance personnel can explain how controls operate across related FCC programs. Participants also may benefit from conducting targeted internal reviews of higher-risk submissions, vendors or program areas before an OIG inquiry arises.</span></p>
<p><i><span style="font-weight: 400;">This was </span></i><a href="https://www.wiley.law/alert-FCC-Inspector-Generals-New-Oversight-Plan-Raises-Stakes-for-Funding-Recipients" target="_blank" rel="noopener"><b><i>adapted</i></b></a><i><span style="font-weight: 400;"> with permission.</span></i></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/fcc-watchdog-mining-data-across-programs/">The FCC&#8217;s Watchdog Is Mining Data Across Programs. Funding Recipients Should Take Note.</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When AI Writes the Number, Who Has a Reasonable Basis to Certify It?</title>
		<link>https://www.corporatecomplianceinsights.com/when-ai-writes-numbers-who-has-reasonable-basis-certify-it/</link>
		
		<dc:creator><![CDATA[Shreyas Sampath]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 11:00:32 +0000</pubDate>
				<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Financial Reporting]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67784</guid>

					<description><![CDATA[<p>Treating AI governance as an IT deliverable leaves an officer standing at the end of a chain that doesn't reach anyone who can account for the number</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/when-ai-writes-numbers-who-has-reasonable-basis-certify-it/">When AI Writes the Number, Who Has a Reasonable Basis to Certify It?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">AI has moved into financial reporting itself — proposing journal entries, drafting variance commentary — but a named officer still has to personally certify, under SOX Section 302, that the numbers fairly present the company&#8217;s condition. Shreyas Sampath argues that when a model rather than a person produces the output, the &#8220;reasonable basis&#8221; behind that signature quietly erodes.</span></i></p>
</div>
<p><span style="font-weight: 400;">When an AI model proposes a journal entry that gets recorded in the books or drafts the variance commentary that informs the financial report, a named officer still has to sign the Section 302 certification attesting that, to their knowledge, the financials fairly present the company&#8217;s condition.</span></p>
<p><span style="font-weight: 400;">&#8220;To their knowledge&#8221; is tricky here. It assumes the officer has a reasonable basis for what they are certifying. When a person prepares the number, that basis was a chain of people who could each explain their judgment. When a large language model (LLM) generates it, the chain has a gap where a reviewer used to sit, and the officer is the one who signs over that gap.</span></p>
<p><span style="font-weight: 400;">The teams I work with at Fortune 500 companies have moved AI into reporting workflows without settling what the certifying officer&#8217;s reasonable basis rests on once a model, not a person, produces the output. The answer most of them reach for — that IT owns it — is one that fails an audit.</span></p>
<p><span style="font-weight: 400;">The pressure to deploy is real, and adoption is outpacing oversight. </span><a href="https://www.cfoconnect.eu/resources/reports/state-of-ai-in-finance-2026/" target="_blank" rel="noopener"><b>More than half</b></a><span style="font-weight: 400;"> of finance leaders now use AI in some capacity, and the fastest movers are pushing it into financial reporting itself, where AI output no longer just supports human judgment. It shapes the numbers a named executive has to personally certify as accurate.</span></p>
<p><span style="font-weight: 400;">The reason this falls to the officer rather than staying a technical detail is that finance AI is not a single thing. Summarizing </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board</b></a><span style="font-weight: 400;"> prep with an LLM sits in a very different </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> category than using AI to draft variance commentary or propose journal entries that get recorded in the books. One category supports a decision a person still makes and owns. The other produces output that becomes part of the record the officer attests to.</span></p>
<p><span style="font-weight: 400;">Most teams configure both kinds of use cases the same way, which is where the exposure builds quietly. The </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> a decision-support tool needs and the governance a reporting-critical tool needs look almost nothing alike, and the officer inherits the difference.</span></p>
<p><span style="font-weight: 400;">Research </span><a href="https://www.wtwco.com/en-us/insights/2026/03/sarbanes-oxley-and-the-ai-governance-gap-d-and-o-insurance-considerations" target="_blank" rel="noopener"><b>published by WTW</b></a><span style="font-weight: 400;"> in March 2026 framed this as an emerging </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> governance gap under </span><a href="https://www.corporatecomplianceinsights.com/tag/sox-compliance/" target="_blank" rel="noopener"><b>Sarbanes-Oxley (SOX)</b></a><span style="font-weight: 400;">, with direct implications for officer certifications under Section 302. When SOX was written in 2002, it assumed a person made the material decision and could be asked to explain it. A model that generates an output from statistical patterns cannot be deposed, cannot walk an auditor through its reasoning and cannot stand behind a number the way a controller can. The reasonable basis the officer certifies to has to come from somewhere else, which means it has to be built into how the model is governed before the output ever reaches the certified statements.</span></p>
<p><span style="font-weight: 400;">Consider a use case nearly every organization wants to automate: transaction approval workflows. The logic appears straightforward. When a transaction meets a defined threshold, it should auto-approve. For categories like payments, however, the complexity surfaces quickly.</span></p>
<p><span style="font-weight: 400;">On a recent client engagement, transactions satisfied every threshold rule configured in the system, yet the underlying payment data was wrong. The result was a series of over- and underpayments to vendors, each one creating reconciliation work, </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> exposure and vendor-relationship fallout that dwarfed whatever efficiency the automation had bought. Now follow that error up the chain. Those payments hit the ledger. The ledger feeds the reporting cycle. That cycle produces the financials an officer certifies. If someone asks that officer what gave them a reasonable basis to sign, the honest answer is that an automated control approved the transactions, and the control was confirming the rule rather than the data. That is a thin basis to certify against, and it was thin from the moment the workflow was designed to validate thresholds without validating what fed them.</span></p>
<p><span style="font-weight: 400;">The reason this basis erodes so quietly is that the controls meant to protect it were built for a different actor. Internal control frameworks were designed to test whether a person followed a documented procedure. That logic does not translate cleanly to AI surfacing a reconciliation exception or drafting a journal entry for human review. When a model generates the proposal, the review control alone may not be sufficient, and the model itself often needs to be validated as part of the control design; these are choices that need to be made at Sprint One rather than discovered in Q4.</span></p>
<p><span style="font-weight: 400;">The pattern I see converging at larger audited organizations is narrower than AI vendor pitches might suggest. AI surfaces exceptions, identifies anomalies and drafts supporting analysis. A human retains sign-off on anything that flows to external reporting. The </span><a href="https://pcaobus.org/news-events/speeches/speech-detail/ai-and-the-pursuit-of-audit-quality--a-regulatory-perspective" target="_blank" rel="noopener"><b>PCAOB</b></a><span style="font-weight: 400;"> has reinforced this direction in public remarks through 2025 and early 2026, describing AI as a tool that should support rather than replace professional judgment with clear documentation of how outputs are generated and reviewed.</span></p>
<p><span style="font-weight: 400;">Teams getting this right design for audit readiness from the first sprint. Model documentation, input lineage and review evidence are built into the workflow, not retrofitted once the auditors start asking questions. </span><a href="https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey" target="_blank" rel="noopener"><b>More than three-quarters</b></a><span style="font-weight: 400;"> of executives lack strong confidence they could pass an independent AI governance audit within 90 days, which is a clear signal that retrofitting is what most programs are doing.</span></p>
<p><span style="font-weight: 400;">These teams also treat governance as a finance-led discipline. AI model validation for reporting workflows is not an IT problem. Finance owns the control, so finance has to own the parameters, the thresholds and the documentation standard.</span></p>
<p><span style="font-weight: 400;">In my ERP and finance transformation work, &#8220;audit-ready from Sprint One&#8221; is less about documentation volume and more about a handful of non-negotiables that get locked in at kickoff. Three artifacts I insist on before any configuration begins: a requirements control matrix, a </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data architecture</b></a><span style="font-weight: 400;"> and process flow diagram mapping every automated decision point as well as functional and technical specs that define what a reviewer must see, capture and retain for every AI-assisted output that touches certified reporting.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67784_1_6a673ac134b76   " data-unique="jnews_module_67784_1_6a673ac134b76">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/10-questions-every-organization-should-ask-ai-vendor/" aria-label="Read article: 10 Questions Every Organization Should Ask a Potential AI Vendor"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="hand checking off checklist" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/hand-checking-off-checklist-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/hand-checking-off-checklist-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/hand-checking-off-checklist-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/hand-checking-off-checklist-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/risk/">Risk</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/10-questions-every-organization-should-ask-ai-vendor/">10 Questions Every Organization Should Ask a Potential AI Vendor</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/angela-juneau/">Angela Juneau</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/10-questions-every-organization-should-ask-ai-vendor/"><i class="fa fa-clock-o"></i> July 15, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Adopting AI without understanding how it was built and how it handles data can expose an organization to risks that surface only once something goes wrong</p>
                                    <a href="https://www.corporatecomplianceinsights.com/10-questions-every-organization-should-ask-ai-vendor/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67784_1_6a673ac134b76 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67551","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Why ‘IT owns it’ leaves the officer exposed</span></h2>
<p><span style="font-weight: 400;">The programs that consistently stall are the ones treating AI governance as an IT deliverable. The controls end up technically sound and operationally orphaned. When the auditor asks who owns model drift monitoring for the tool that proposes accruals, finance points to IT, IT points to the vendor and nobody has a defensible answer. The officer who signed the certification is standing at the end of that chain, and the chain does not reach a person who can account for the number.</span></p>
<p><span style="font-weight: 400;">Recent analysis from </span><a href="https://kpmg.com/us/en/insights-by-topic/future-of-sox-insights.html" target="_blank" rel="noopener"><b>KPMG</b></a><span style="font-weight: 400;"> and </span><a href="https://www.grantthornton.com/insights/articles/advisory/2025/the-power-of-ai-in-efficient-sox-compliance" target="_blank" rel="noopener"><b>Grant Thornton</b></a><span style="font-weight: 400;"> point to the same conclusion: Effective programs run on joint ownership across finance, IT, </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>internal audit</b></a><span style="font-weight: 400;"> and the control owners themselves.</span></p>
<p><span style="font-weight: 400;">The gap I see most often is finance quietly outsourcing the governance question to IT because the underlying technology feels unfamiliar. The conversation usually starts with &#8220;IT is handling the AI piece,&#8221; which is a reasonable answer for infrastructure, model hosting and integration, but not for the parameters that determine whether an output is materially correct. Finance owns the threshold for what counts as a reasonable accrual, what constitutes an acceptable variance and what level of review a high-dollar payment requires. When those parameters get set by an IT team or a vendor default because finance never showed up to the design sessions, the control exists on paper but has no one in finance who can defend it to an auditor. Those parameters are the reasonable basis, restated in operational terms. An officer cannot certify a number with confidence when the thresholds behind it were set by whoever configured the tool, and finance is the only function positioned to set them well enough to make them worth standing behind.</span></p>
<h2><span style="font-weight: 400;">Building the basis before the signature</span></h2>
<p><span style="font-weight: 400;">The finance teams that pull ahead this year will treat AI adoption and control design as the same project, accepting a slower first sprint in exchange for something that scales. The deployment pressure is real, and </span><a href="https://chatfin.ai/blog/cfo-ai-readiness-scorecard-finance-assessment-2026-ai/" target="_blank" rel="noopener"><b>74% of CFOs now rank AI deployment</b></a><span style="font-weight: 400;"> as a top-three strategic priority. That pressure is exactly why the certification question cannot wait. </span></p>
<p><span style="font-weight: 400;">Every workflow that moves AI closer to certified reporting adds another output an officer will eventually sign over, and the reasonable basis for that signature is either designed in at Sprint One or reconstructed under audit pressure later. Teams who understand that are building the basis now, while it is still a design choice rather than a deposition.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/when-ai-writes-numbers-who-has-reasonable-basis-certify-it/">When AI Writes the Number, Who Has a Reasonable Basis to Certify It?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>As Costs Rise &amp; ROI Remains Elusive, Majority of Execs Say AI Agents Are Worth the Risks</title>
		<link>https://www.corporatecomplianceinsights.com/news-roundup-july-123-2026/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 11:00:02 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67775</guid>

					<description><![CDATA[<p>30% of UK managers get specially trained on sexual harassment; Gartner IDs 5 big changes for legal functions</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-july-123-2026/">As Costs Rise &#038; ROI Remains Elusive, Majority of Execs Say AI Agents Are Worth the Risks</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: </span></i><a href="mailto:editor@corporatecomplianceinsights.com"><b><i>editor@corporatecomplianceinsights.com</i></b></a><i><span style="font-weight: 400;">.</span></i></h6>
<h2><span style="font-weight: 400;">68% of companies have exceeded budget on AI projects</span></h2>
<p><span style="font-weight: 400;">While many companies still struggle to show meaningful ROI on AI projects and concerns persist over the financial risk exposure presented by agentic AI, about two-thirds of executives (64%) say the value of AI agents outweighs the risk, according to a survey by AI security and governance platform WitnessAI.</span></p>
<p><span style="font-weight: 400;">Only 9% of </span><a href="https://witness.ai/resources/2026-enterprise-ai-risk-survey-the-hidden-cost-of-enterprise-ai" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> respondents said that 75% or more of their AI projects have delivered measurable returns, while 68% said their AI projects have exceeded budgets during the past year. Just 4% said their AI projects always stay on budget.</span></p>
<p><span style="font-weight: 400;">Beyond AI budgets being busted, leaders may underestimate the cost of AI incidents, according to the survey. More than a fifth of leaders (21%) reported a single AI security incident costing $1 million or more in the past year, while 43% said the total net cost of all AI-related incidents in that time exceeded $2 million.</span></p>
<p><span style="font-weight: 400;">A few other key findings:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">44% of executives say a significant part of their total revenue would be at risk from regulatory penalties if a rogue AI agent exposes </span><a href="https://www.corporatecomplianceinsights.com/tag/data-breach/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;">.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">17% cite </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> bottlenecks as the primary reason their AI initiatives underperform on ROI expectations.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Responsibility for managing AI risk is dispersed, with the chief information officer leading the way (30%) but CISOs (15%) and others like chief technology officers and chief AI officers also playing a role.</span></li>
</ul>
<h2><span style="font-weight: 400;">1 in 5 UK managers don’t get sexual harassment training</span></h2>
<p><span style="font-weight: 400;">More than a fifth of business managers in the UK don’t receive dedicated </span><a href="https://www.corporatecomplianceinsights.com/tag/training/" target="_blank" rel="noopener"><b>training</b></a><span style="font-weight: 400;"> on sexual harassment, according to a </span><a href="https://vinciworks.com/blog/all-reasonable-steps-harassment/" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by compliance eLearning provider VinciWorks.</span></p>
<p><span style="font-weight: 400;">The poll found that of 985 UK-based HR and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> professionals surveyed, 21% said business managers aren’t given specific training on sexual harassment. Another 10% responded that mangers receive training but not consistently, while managers’ sexual harassment training is part of general staff training for just under a third.</span></p>
<p><span style="font-weight: 400;">VinciWorks’ report comes ahead of changes in the </span><a href="https://assets.publishing.service.gov.uk/media/696fabb3c0f4afaa9536a0f2/employment-rights-act-2025-overview-factsheet.pdf" target="_blank" rel="noopener"><b>UK Employment Rights Act</b></a><span style="font-weight: 400;"> that mandate more rigorous measures to prevent sexual harassment in the workplace; those are set to take effect in October. </span></p>
<p><span style="font-weight: 400;">The survey also found that 34% of employers have never carried out a sexual harassment risk assessment, which looks at where harassment could occur in the workplace, while 17% haven’t done an assessment in more than a year. </span></p>
<p><span style="font-weight: 400;">Other key findings include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Nearly half (47%) described their training as needing improvement, while 14% admitted they provide no sexual harassment training whatsoever.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Almost 43% reported they don’t provide bystander intervention training, though they would like to and another 23% don’t play to start.</span></li>
</ul>
<h2><span style="font-weight: 400;">5 themes that will define legal functions by 2030</span></h2>
<p><span style="font-weight: 400;">Gartner</span><span style="font-weight: 400;"> has identified five themes that it says will transform legal functions by 2030 in a </span><a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-15-gartner-identifies-five-themes-set-to-transform-legal-functions-by-2030" target="_blank" rel="noopener"><b>new report</b></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">R</span><span style="font-weight: 400;">egulatory change will broaden legal’s role, the company said. GCs will face new regulatory issues and a rise in AI disputes, resulting in legal teams playing a larger role in risk appetite, compliance practices, AI governance and IP protection.</span></p>
<p><span style="font-weight: 400;">Geopolitical volatility will intensify trade and </span><a href="https://www.corporatecomplianceinsights.com/tag/supply-chain/" target="_blank" rel="noopener"><b>supply chain</b></a><span style="font-weight: 400;"> risk. Changing trade policy, national security, technology battles, </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> sovereignty and privacy concerns will force legal to work more on trade compliance and supply chains.</span></p>
<p><span style="font-weight: 400;">AI and DIY technologies will change how legal work gets done. Improvements from technology will require more governance, training and human oversight.</span></p>
<p><span style="font-weight: 400;">N</span><span style="font-weight: 400;">ew talent and sourcing models will redefine legal delivery, with Gartner saying its analysts “</span><span style="font-weight: 400;">expect a more fragmented legal services market, with managed services providers, alternative legal service providers, consultants and technology vendors taking a greater share of work, while reduced junior hiring may constrain the long-term talent pipeline.”</span></p>
<p><span style="font-weight: 400;">Finally, the firm says </span><span style="font-weight: 400;">legal must support growth while operating with fewer resources. </span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-july-123-2026/">As Costs Rise &#038; ROI Remains Elusive, Majority of Execs Say AI Agents Are Worth the Risks</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2 Gurus Talk Compliance</title>
		<link>https://www.corporatecomplianceinsights.com/2-gurus-talk-compliance/</link>
		
		<dc:creator><![CDATA[Caitlin Chapman]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 17:04:27 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67751</guid>

					<description><![CDATA[<p>Welcome to the "Great Women in Compliance" podcast, co-hosted by Lisa Fine and Hemma Lomax. </p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/2-gurus-talk-compliance/">2 Gurus Talk Compliance</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-6"><div class="jeg_wrapper wpb_wrapper"><div class="row vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper "><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="640" height="640" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance.jpg" class="vc_single_image-img attachment-full" alt="" title="2_Gurus_Talk_Compliance" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance.jpg 640w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance-300x300.jpg 300w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance-150x150.jpg 150w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance-75x75.jpg 75w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2_Gurus_Talk_Compliance-350x350.jpg 350w" sizes="(max-width: 640px) 100vw, 640px" /></div>
		</figure>
	</div>
</div></div></div></div></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-6"><div class="jeg_wrapper wpb_wrapper"><div class="row vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper "><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h1><strong>2 Gurus Talk Compliance</strong></h1>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 14px;">What happens when two top compliance commentators get together? They talk compliance, of course. Kristy Grant-Hart and Tom Fox review current compliance news stories, corporate ethics, ESG and governance topics each episode, plus other top commentators in the field.</p>
<p style="font-family: work sans; font-size: 14px;">More from 2 Gurus Talk Compliance <a href="https://compliancepodcastnetwork.net/category/2-gurus-talk-compliance/">here.</a></p>

		</div>
	</div>
</div></div></div></div><div id="episodes" data-vc-full-width="true" data-vc-full-width-init="false" class="row vc_row wpb_row vc_row-fluid vc_custom_1695761270714"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h4>Listen to recent episodes:</p>
<p><iframe style="border-radius: 12px;" src="https://open.spotify.com/embed/show/4cS4Y45Lx7wrEbGeVOfSUs?utm_source=generator" width="100%" height="352" frameborder="0" allowfullscreen="allowfullscreen"></iframe></h4>

		</div>
	</div>
</div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/2-gurus-talk-compliance/">2 Gurus Talk Compliance</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Yes, You Are Allowed to Take Your Vacation</title>
		<link>https://www.corporatecomplianceinsights.com/yes-you-are-allowed-take-your-vacation/</link>
		
		<dc:creator><![CDATA[Vera Cherepanova]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 11:00:16 +0000</pubDate>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Leadership and Career]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67644</guid>

					<description><![CDATA[<p>Why does our culture make a long break feel like an ethical dilemma?</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/yes-you-are-allowed-take-your-vacation/">Yes, You Are Allowed to Take Your Vacation</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">A reader is entitled to three weeks off but can&#8217;t shake the feeling that taking them would be selfish, uncommitted or proof they&#8217;re expendable. Ask an Ethicist columnist Vera Cherepanova recognizes the setup for what it is: an ethical trap where every worry doubles back into a reason to stay at your desk.</span></i></p>
</div>
<blockquote class="pullquote align-center"><p><i><span style="font-weight: 400; font-size: 15px; line-height: 1.1em;">I would like to take three weeks off work, which I’m formally entitled to, but I keep hearing this is a bad idea. If the company can manage without me for three weeks, will that mean I am expendable? Will it make me look less committed than others? And will it be unfair to the rest of the team, who will have to cover my work? Would taking so much time off be selfish or irresponsible, or, in an age of “unprecedented technological progress and AI-driven productivity,” is it finally perfectly ethical to take care of yourself when you need it? — No One Ever</span></i></p></blockquote>
<p><span style="font-weight: 400;">If the company manages without you, maybe you are expendable. If it struggles, you have selfishly abandoned your colleagues. If you disconnect, you are not committed enough. If you remain online, you have not really taken a vacation. This is not so much an ethical dilemma as an ethical trap: Every possible outcome looks like evidence that you should continue working.</span></p>
<p><span style="font-weight: 400;">Back in 1930, the economist John Maynard Keynes made a famous </span><a href="https://onlinelibrary.wiley.com/doi/full/10.1111/ecca.12439" target="_blank" rel="noopener"><b>prediction</b></a><span style="font-weight: 400;">: By 2030, technological progress and rising prosperity would allow people in advanced economies to work 15 hours a week.</span></p>
<p><span style="font-weight: 400;">We are now in 2026, and that prediction seems very far from being realized. Many white-collar professionals regularly work 50 hours or more. In some industries, such as </span><a href="https://www.afr.com/world/north-america/how-much-sleep-does-a-banker-need-a-us-firm-settles-lawsuit-20260223-p5o4ig" target="_blank" rel="noopener"><b>investment banking</b></a><span style="font-weight: 400;">, that number can reach 80 to 120 hours. Even the four-day workweek remains an aspiration.</span></p>
<p><span style="font-weight: 400;">Yet, Keynes was not entirely wrong about the economics in question. The US became as rich and productive as he had imagined it would, substantially outpacing primary competitors, such as </span><a href="https://econofact.org/factbrief/fact-check-has-the-economic-gap-between-europe-and-the-united-states-increased-in-the-past-decade" target="_blank" rel="noopener"><b>Europe</b></a><span style="font-weight: 400;"> and</span><a href="https://alcottglobal.com/infographic/gdp-shifts-for-japan-china-the-european-union-and-the-united-states-2000-vs-2025" target="_blank" rel="noopener"> <b>Japan</b></a><span style="font-weight: 400;"> in GDP growth. What did not happen was the conversion of that prosperity into substantially shorter hours in the office.</span></p>
<p><span style="font-weight: 400;">Still, there has been some real progress, with an interesting caveat. The data shows that the average American now works about 1,200 fewer hours a year than the average worker did in the late 19th century. But when we zoom in on households, something curious </span><a href="https://www.theatlantic.com/ideas/archive/2024/04/americans-work-free-time-67-hours/678021/" target="_blank" rel="noopener"><b>happens</b></a><span style="font-weight: 400;">. In the 1880s, the typical married American couple averaged about 67 hours of paid work a week. In 2020? Still 67 hours.</span></p>
<p><span style="font-weight: 400;">Those numbers conceal an enormous social transformation. Once confined to domestic chores, more women entered the workforce thanks to household automation and profound cultural and economic changes. They began working fewer hours in the home and more outside it.</span></p>
<p><span style="font-weight: 400;">Married men underwent an opposite shift: adopting new technologies, including tractors, cars and computers, made workers more productive in their shorter workdays. Men gradually used their extra time to take on more hours of chores, errands and childcare at home. But these dynamics don’t fully explain why a rich and productive society does not allow its people to be able to work radically less or take more time off as Keynes anticipated.</span></p>
<p><span style="font-weight: 400;">There are many reasons — far more than I can fit into one column. Rising costs play a major role, but so do rising expectations about what constitutes a comfortable life. Buying a home, raising children and caring for older family members are all more expensive than they used to be.</span></p>
<p><span style="font-weight: 400;">Keeping up with the Joneses has become more challenging, too. It is difficult to feel prosperous when every part of daily life reminds you that someone else is in the faster line, using the preferred kiosk, sitting in the premium cabin or enjoying the better membership tier. Life simply feels better if you are in Boarding Group 1, right?</span></p>
<p><span style="font-weight: 400;">The rise of mass consumerism, social norms and the desire to match or exceed the lifestyle of others necessitate higher working hours, creating a hedonic treadmill effect where people feel compelled to continue working to afford the next set of luxury goods or experiences. We are also encouraged to take on more debt to afford those, which is another expansive topic for a conversation about </span><a href="https://www.corporatecomplianceinsights.com/ethics-news/" target="_blank" rel="noopener"><b>ethics</b></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">The result can be exhaustion, frustration and one reason why even upper-middle-class families can feel</span><a href="https://www.nytimes.com/2026/03/26/opinion/economy-attitudes-republicans-democrats.html" target="_blank" rel="noopener"> <b>miserable</b></a><span style="font-weight: 400;">. They have to push themselves beyond their limits just to keep up.</span></p>
<p><span style="font-weight: 400;">Another thing Keynes failed to foresee was the cultural value we would attach to work itself. Among many professionals, long hours have become a status symbol. Exactly as you write, busyness is conflated with importance, constant availability is seen as commitment and being indispensable sounds like the ultimate compliment. But is indispensability really a good proxy for value?</span></p>
<p><span style="font-weight: 400;">And what about AI, you asked Will the promised gains in efficiency finally reduce working hours? Will we at last have more time off, as we ought to?</span></p>
<p><span style="font-weight: 400;">Unlikely. Recent evidence shows that AI is making </span><a href="https://www.corporatecomplianceinsights.com/news-roundup-july-16-2026/" target="_blank" rel="noopener"><b>some people work more</b></a><span style="font-weight: 400;">, not less. In </span><a href="https://hbr.org/data-visuals/2026/03/which-functions-report-experiencing-ai-brain-fry-the-most" target="_blank" rel="noopener"><b>one</b></a><span style="font-weight: 400;"> survey, 18% of developers reported AI-related exhaustion. Turns out AI agents may not reduce work so much as multiply the amount of work humans must initiate, monitor, correct, coordinate. The human becomes an AI babysitter, switching constantly among agents, suffering cognitive overload and feeling pressure to keep machines working around the clock. Some people now set agent tasks overnight and check their output before breakfast. Instead of a shorter workweek, we may be </span><a href="https://www.theatlantic.com/technology/2026/06/ai-agents-jobs-exhaustion/687596/" target="_blank" rel="noopener"><b>moving</b></a><span style="font-weight: 400;"> toward an “infinite” one.</span></p>
<p><span style="font-weight: 400;">Technology does not automatically give people leisure time, but it gives organizations and individuals the capacity to produce more. The opportunity to generate more output never stops, unless someone deliberately sets a limit.</span></p>
<p><span style="font-weight: 400;">It looks like we are trapped in a cycle, sacrificing our </span><a href="https://www.corporatecomplianceinsights.com/well-being/" target="_blank" rel="noopener"><b>well-being</b></a><span style="font-weight: 400;"> for the next flat-screen TV, car, luxury bag or just converting every available hour into output. The bad news is that no one, not even AI, can give you permission to pause. No one, that is, except you. So, break out of the ethical trap. Take the three weeks. And do not spend the vacation checking whether everyone misses you enough.</span></p>
<p><span style="font-weight: 400;">(Speaking of taking your vacation time, Ask an Ethicist will take a summer break after this column drops to enjoy the remainder of summer. See you again in September.)</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67644_2_6a673ac13f4e4   " data-unique="jnews_module_67644_2_6a673ac13f4e4">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/" aria-label="Read article: Out of Your Technological Depth? It’s Your Duty to Say So."><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="person reaching for help in sea" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/06/person-reaching-for-help-in-sea-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/governance/">Governance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/">Out of Your Technological Depth? It’s Your Duty to Say So.</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/vera-cherepanova/">Vera Cherepanova</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/"><i class="fa fa-clock-o"></i> June 17, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>If a director can admit to not knowing enough to make a decision, it’s a sign the board has built and reinforced honesty</p>
                                    <a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67644_2_6a673ac13f4e4 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67182","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Readers respond</span></h2>
<p><span style="font-weight: 400;">The previous question came from an independent director facing increasingly technical </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board</b></a><span style="font-weight: 400;"> decisions involving AI, cyber and robotics. The dilemma revolved around whether admitting that they did not fully understand a material issue was compatible with good fiduciary conduct, raising questions about humility, competence, performative confidence, board </span><a href="https://www.corporatecomplianceinsights.com/tag/corporate-culture/" target="_blank" rel="noopener"><b>culture</b></a><span style="font-weight: 400;">, the duty of care and how directors can ask for more information or expert support without losing authority.</span></p>
<p><span style="font-weight: 400;">In my response, I noted: “In Delaware-style US corporate law, directors’ duty of care requires them to make informed decisions, so the substance of the point is sound. In the UK, directors have a statutory duty to exercise reasonable care, skill and diligence.</span></p>
<p><span style="font-weight: 400;">“John Weinberg, the man who laid down the foundational philosophy on </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> and director qualifications in the United States, </span><a href="https://weinberg.udel.edu/historic-thesis-weinberg-published/" target="_blank" rel="noopener"><b>wrote</b></a><span style="font-weight: 400;"> in his famous 1948 Princeton thesis: “A director must not only be willing to direct, but more important … must know enough to direct,” and “The primary step to be taken is a comprehensive educational program.</span></p>
<p><span style="font-weight: 400;">“That means to exercise the oversight duty, directors need to make sure they are learning, and when they are expected to project confidence rather than acknowledge limits, that’s a cause for a serious governance concern. To reframe, the duty of care includes knowing when you do not know enough, asking for clarification, expert input or more time and should be viewed not as a weakness but as a strength.” Read the full column </span><a href="https://www.corporatecomplianceinsights.com/out-your-technological-depth-duty/" target="_blank" rel="noopener"><b>here</b><span style="font-weight: 400;">.</span></a></p>
<p><i><span style="font-weight: 400;">Indeed, this kind of vulnerability should be a foundation for building and nurturing a strong organizational culture. When leaders are willing to acknowledge what they do not know, it creates psychological safety for others to speak up, ask questions and close knowledge gaps across the organization. This honesty from the top can turn uncertainty into better governance, stronger decisions and a more resilient culture. — MMA</span></i></p>
<h6>Have a response? Share your feedback on what I got right (or wrong). <strong><a href="mailto:ethicist@corporatecomplianceinsights.com" target="_blank" rel="noopener">Send me</a></strong> your comments or questions.</h6>
<p>The post <a href="https://www.corporatecomplianceinsights.com/yes-you-are-allowed-take-your-vacation/">Yes, You Are Allowed to Take Your Vacation</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Field Guide to Privacy Law for Companies Entering the US Market</title>
		<link>https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/</link>
		
		<dc:creator><![CDATA[Kevin Coy and Erin Doyle]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 11:04:23 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[HIPAA]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67640</guid>

					<description><![CDATA[<p>Businesses wanting to operate in the US have a variety of laws and regulations to consider</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/">A Field Guide to Privacy Law for Companies Entering the US Market</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Many non‑US businesses assume that compliance with the European Union’s GDPR or a similar home‑country law will largely address US requirements, Kevin Coy and Erin Doyle of Arnall Golden Gregory write. But the US regulatory picture is fragmented, highly sector- and state-specific and generates distinct regulatory and litigation risks that often are not addressed by compliance with home-country laws.</span></i></p>
</div>
<p><span style="font-weight: 400;">Compliance professionals, in‑house counsel and business leaders should consider 12 areas of </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data privacy</b></a><span style="font-weight: 400;"> and security diligence, contract terms and </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> when planning US operations. </span></p>
<p><span style="font-weight: 400;">These areas are not mutually exclusive, and they often overlap. This list is also not exhaustive. Discrete federal and state privacy laws regulate a host of other areas not addressed here, ranging from motor vehicle records and educational records to video rental records, library records and loyalty program information, among others.</span></p>
<h2><span style="font-weight: 400;">1. Sectoral federal privacy laws </span></h2>
<p><span style="font-weight: 400;">While the US does not have an omnibus privacy law, it does have a number of sectoral and issue-specific privacy laws. HIPAA regulations, covering certain health‑related entities, and the Gramm-Leach-Bliley Act, which regulates </span><a href="https://www.corporatecomplianceinsights.com/financial-services-news/" target="_blank" rel="noopener"><b>financial institutions</b></a><span style="font-weight: 400;">, are prominent examples.</span></p>
<p><span style="font-weight: 400;">HIPAA governs protected health information held by “covered entities,” including many healthcare providers and health plans and their “business associates,” a broad array of companies providing services that involve processing protected health information on behalf of covered entities. Covered entities and their business associates must address HIPAA’s privacy, security and </span><a href="https://www.corporatecomplianceinsights.com/tag/data-breach/" target="_blank" rel="noopener"><b>data breach</b></a><span style="font-weight: 400;"> notification regulations, including specific contracting and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> requirements.</span></p>
<p><span style="font-weight: 400;">Some states, such as Washington and Nevada, have adopted robust health information privacy laws intended to fill gaps regarding the privacy of consumer health data where the HIPAA privacy rules do not apply, and the Washington law includes a private right of action.</span></p>
<p><span style="font-weight: 400;">The Gramm-Leach-Bliley Act applies to a wide array of financial institutions, not just </span><a href="https://www.corporatecomplianceinsights.com/tag/banks/" target="_blank" rel="noopener"><b>banks</b></a><span style="font-weight: 400;">, and requires specific privacy notices, regulates the sharing of “non‑public personal information” and imposes information security requirements.</span></p>
<p><span style="font-weight: 400;">Foreign businesses entering the health or financial services sectors should treat HIPAA and the Gramm-Leach-Bliley Act as primary regulatory regimes, not as mere supplements to home-country requirements.</span></p>
<h2><span style="font-weight: 400;">2. State privacy laws</span></h2>
<p><span style="font-weight: 400;">The US still lacks a single federal </span><a href="https://www.corporatecomplianceinsights.com/tag/gdpr/" target="_blank" rel="noopener"><b>GDPR</b></a><span style="font-weight: 400;">‑style law, but more than 20 states have now enacted comprehensive consumer privacy statutes, starting with the California Consumer Privacy Act and followed by states like Virginia, Colorado, Connecticut, Texas and others. California is one of the most operationally demanding states: It created a dedicated privacy regulator, the California Privacy Protection Agency and is comparatively aggressive with enforcement.</span></p>
<p><span style="font-weight: 400;">Each state’s law is distinct, but they all typically include privacy notice requirements, consumer rights obligations (for example, access, deletion, correction and opt‑out options), purpose limitation concepts, data minimization concepts and vendor contracting obligations. While these laws apply across sectors, they do not apply to all businesses due to a range of different applicability triggers and exceptions. As a result, the impact of this category of state laws depends on the size and scope of business operations and the states where business will be conducted. A threshold assessment of which state laws actually apply to an entity should therefore be considered a necessary first step in any US privacy strategy.</span></p>
<h2><span style="font-weight: 400;">3. Marketing and communications privacy</span></h2>
<p><span style="font-weight: 400;">In the marketing and communications space, the US federal CAN‑SPAM Act and similar state laws set rules for commercial email, including identification requirements, opt‑out mechanisms and header‑information accuracy. The Telephone Consumer Protection Act and parallel state mini‑TCPA statutes heavily regulate telemarketing, text messaging and certain automated calling. Do-not-call list rules also apply particularly but not exclusively to telemarketing communications. Some of these laws have driven substantial class action litigation.</span></p>
<h2><span style="font-weight: 400;">4. Website tracking and video or call recording</span></h2>
<p><span style="font-weight: 400;">Additional US laws regulate the recording of videos or calls and using website tracking technologies. Federal and state wiretapping and eavesdropping statutes, as well as call‑recording laws, require one‑party or all‑party consent to record depending on the jurisdiction. Additionally, plaintiffs are increasingly challenging “session replay” and other online tracking technologies like cookies and pixels under these legal frameworks.</span></p>
<p><span style="font-weight: 400;">For businesses considering US physical retail stores or other locations in the US, notices regarding video surveillance also may be required. Businesses entering the US market that are planning to engage in these types of activities should carefully review their practices in these areas to address compliance concerns and mitigate potential </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;">.</span></p>
<h2><span style="font-weight: 400;">5. Children’s privacy</span></h2>
<p><span style="font-weight: 400;">Businesses processing personal data about children must consider federal and state privacy laws. US federal law is anchored by the Children’s Online Privacy Protection Act, which applies to online services directed to children under 13 or that knowingly collect personal information from such children. COPPA requires clear notices, verifiable parental consent before collecting most </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;">, limits on use and disclosure and reasonable security. COPPA is enforced primarily by the US Federal Trade Commission and state attorneys general.</span></p>
<p><span style="font-weight: 400;">In parallel, an expanding set of state child‑focused privacy and online safety laws (for example, age‑appropriate design‑style codes and teen‑specific protections) for people up to age 18 are imposing additional obligations around profiling, targeted advertising and default settings for minors, creating a multilayered regulatory framework.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67640_3_6a673ac14292d   " data-unique="jnews_module_67640_3_6a673ac14292d">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/new-cipa-claims-expand-privacy-litigation-risk-website-banners/" aria-label="Read article: New CIPA Claims Expand Privacy Litigation Risk Over Website Consent Banners"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="website opt out banner" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/website-opt-out-banner-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/website-opt-out-banner-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/website-opt-out-banner-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/website-opt-out-banner-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/data-privacy/">Data Privacy</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/new-cipa-claims-expand-privacy-litigation-risk-website-banners/">New CIPA Claims Expand Privacy Litigation Risk Over Website Consent Banners</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/andrew-chase/">Andrew Chase</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/new-cipa-claims-expand-privacy-litigation-risk-website-banners/"><i class="fa fa-clock-o"></i> July 17, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>A lawsuit against Ace Hardware demonstrates the claims that can be brought against organizations under new California laws</p>
                                    <a href="https://www.corporatecomplianceinsights.com/new-cipa-claims-expand-privacy-litigation-risk-website-banners/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67640_3_6a673ac14292d = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67598","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">6. AI and automated decision-making technology laws</span></h2>
<p><span style="font-weight: 400;">New and proposed state laws governing </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> and automated decision‑making technology are proliferating, focusing on AI transparency, data minimization, bias and discrimination risks and the need for impact assessments where models rely on sensitive personal information or materially affect individuals (for example, employment, housing, credit or access to essential services).</span></p>
<p><span style="font-weight: 400;">Non‑US businesses may need to adapt AI governance programs built around GDPR, the EU AI Act or other laws to address specific US disclosure, consent, notice and opt‑out expectations, as well as heightened scrutiny of training data, profiling and the reuse of consumer and employee data for AI purposes.</span></p>
<h2><span style="font-weight: 400;">7. Employee and applicant privacy</span></h2>
<p><span style="font-weight: 400;">Businesses entering the US market may be surprised by the patchwork of US employee‑focused rules. The federal Fair Credit Reporting Act and similar laws in many states regulate the use of third‑party background screening reports regarding applicants and employees, as well as use of such reports for other purposes. State and local “ban the box,” “fair chance” and antidiscrimination laws restrict when and how criminal history information can be requested and used during hiring, typically requiring delayed inquiries and individualized assessments. Other state laws restrict the use of credit reports and salary history information as part of the hiring process.</span></p>
<p><span style="font-weight: 400;">Employers also face state laws regarding lawful off‑duty conduct (for example, protecting certain lawful products or activities), drug‑testing constraints and restrictions on requesting social media credentials or disciplining employees for lawful online activity. These laws collectively require careful coordination of global human resources and compliance policies. Employee health plans also may be subject to HIPAA requirements for covered entities.</span></p>
<h2><span style="font-weight: 400;">8. Biometrics privacy laws</span></h2>
<p><span style="font-weight: 400;">Several states have enacted biometric privacy statutes, the Illinois Biometric Information Privacy Act being the most prominent example that is frequently cited in private class actions. These laws can apply to technologies like fingerprint time clocks, facial recognition for physical or logical access and voiceprints. These often require informed consent, data retention limits and secure disposal.</span></p>
<h2><span style="font-weight: 400;">9. Cybersecurity laws</span></h2>
<p><span style="font-weight: 400;">Data security obligations are increasingly being codified not just as general “reasonable security” requirements but as more detailed statutory standards and regulatory guidance. Many state privacy laws expressly require appropriate technical, administrative and physical safeguards connected to the sensitivity and volume of personal data, and some state laws prescribe specific controls, risk assessments, </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>audits</b></a><span style="font-weight: 400;"> and governance structures particularly in financial services and critical infrastructure contexts. In addition, California will soon require certain businesses covered by COPPA to conduct </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;"> audits and submit certifications. These state rules sit alongside — and sometimes go beyond — federal sectoral requirements, such as those under HIPAA or the Gramm-Leach-Bliley Act.</span></p>
<p><span style="font-weight: 400;">Businesses that have designed their security programs around GDPR or a single global standard should assess whether US state- or sector-specific mandates regarding encryption, access management, multifactor authentication, vendor oversight, incident response, </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board‑level</b></a><span style="font-weight: 400;"> reporting and regulatory reporting require tailored enhancements for US operations.</span></p>
<h2><span style="font-weight: 400;">10. Data breach notification laws</span></h2>
<p><span style="font-weight: 400;">All US states and territories have </span><a href="https://www.corporatecomplianceinsights.com/tag/data-breach/" target="_blank" rel="noopener"><b>data breach</b></a><span style="font-weight: 400;"> notification statutes that impose obligations to notify individuals (and sometimes regulators or credit bureaus) when defined personal information is accessed or acquired without authorization, often subject to specific notification timelines and notice content requirements. These laws differ on the scope of covered entities and covered data, whether they carry risk‑of‑harm exceptions and whether delays are permitted for law enforcement needs, so multistate incidents require coordinated, state‑specific analysis.</span></p>
<p><span style="font-weight: 400;">In addition, some businesses are subject to federal breach notification rules under regimes, such as Securities and Exchange Commission requirements for reporting by publicly traded companies, HIPAA or the Gramm-Leach-Bliley Act. As such, businesses entering the US market should consider developing US-focused breach notification protocols to anticipate their response to a breach of US personal data.</span></p>
<h2><span style="font-weight: 400;">11. Government and bulk US sensitive data transfer regulations</span></h2>
<p><span style="font-weight: 400;">Unlike GDPR and many national data protection laws, the US has not traditionally regulated the export of personal data to other jurisdictions. In January 2025, however, the </span><a href="https://www.corporatecomplianceinsights.com/tag/doj/" target="_blank" rel="noopener"><b>US Department of Justice</b></a><span style="font-weight: 400;"> finalized regulations that restrict or prohibit certain “covered data transactions” involving bulk US sensitive personal data or US government‑related data with specified “</span><a href="https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern" target="_blank" rel="noopener"><b>countries of concern</b></a><span style="font-weight: 400;">” and “covered persons.” The rule defines “bulk US sensitive personal data” broadly to include categories like certain personal identifiers, precise geolocation, biometric identifiers, health and financial data and human genetic and molecular biological data when certain thresholds are met within a 12‑month period.</span></p>
<p><span style="font-weight: 400;">A separate law enacted in 2024 also restricts the sale or transfer of personal data by third-party data brokers to “adversary countries” or entities under their control, which could apply instead of or in addition to the DOJ regulations. Compliance with these requirements necessitates an understanding of data flows given that contractual safeguards differ depending on whether the parties involved are US, foreign or covered persons under these regulations. These measures would apply in addition to any data transfer requirements required by home-country data protection laws, such as GDPR.</span></p>
<h2><span style="font-weight: 400;">12. Federal and state unfair or deceptive acts and practices laws</span></h2>
<p><span style="font-weight: 400;">The FTC and state regulators have long used federal and state prohibitions on unfair or deceptive acts and practices (UDAP) to bring actions against businesses that have failed to keep their privacy and data security promises, as well as to act against businesses that engage in unfair privacy and data security practices. While businesses may overlook UDAP laws because they are broad prohibitions rather than detailed operational compliance regimes, federal and state regulators have brought hundreds of UDAP cases over the years. To avoid engaging in deceptive practices, it is important to ensure that a business’s public privacy and security promises are kept in practice. Additionally, unfairness claims do not require an unkept promise. For example, they can be brought if inadequate data security practices result in substantial injury to a consumer that the consumer could not have reasonably avoided. As a result, businesses considering US market entry should consider reviewing their privacy policies, notices and other promises and data security practices from this broader perspective in addition to more specific requirements applicable to their US operations.</span></p>
<h2><span style="font-weight: 400;">Regulatory and litigation risks</span></h2>
<p><span style="font-weight: 400;">Many of the privacy and security laws and regulations discussed above provide private rights of action that make the US litigation environment particularly attractive for class-action plaintiffs. Meanwhile, federal and state regulators — including the FTC, sectoral regulators, state attorneys general and specialized bodies like the California Privacy Protection Agency — actively bring regulatory enforcement actions for privacy and security violations.</span></p>
<p><span style="font-weight: 400;">Compliance with the GDPR or other non‑US data protection frameworks likely will support US compliance efforts, but it is not determinative. Even in instances where US federal and state laws share the same privacy protection goals as non-US privacy regulations, US laws can differ significantly regarding issues like scope, legal bases, consent standards, notice design and content, automated‑decision rules and, crucially, private litigation exposure. Non‑US businesses planning to enter or expand in the US market should therefore consider undertaking a targeted US privacy and data use assessment covering consumer, employee and business-to-business data flows to calibrate governance, contracting, technology and insurance strategies to this distinct regulatory and litigation landscape.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/field-guide-privacy-law-companies-entering-us-market/">A Field Guide to Privacy Law for Companies Entering the US Market</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When Misconduct Reaches the C-Suite, Who Investigates?</title>
		<link>https://www.corporatecomplianceinsights.com/when-misconduct-reaches-c-suite-who-investigates/</link>
		
		<dc:creator><![CDATA[Carrington Giammittorio, Taryn McDonald and Miles Moody]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 11:02:45 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Internal Investigation]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67636</guid>

					<description><![CDATA[<p>From selecting outside counsel to safeguarding privilege, the decisions in-house counsel makes early determine an independent investigation’s credibility</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/when-misconduct-reaches-c-suite-who-investigates/">When Misconduct Reaches the C-Suite, Who Investigates?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Some allegations are too sensitive for an internal team to handle credibly, particularly when they reach senior management or are likely to draw regulators&#8217; attention. Carrington Giammittorio, Taryn McDonald and Miles Moody of Haynes Boone lay out how in-house counsel can recognize those moments and shape an independent investigation.</span></i></p>
</div>
<p><span style="font-weight: 400;">When allegations of serious misconduct surface within an organization, few decisions carry greater consequence than how to </span><a href="https://www.corporatecomplianceinsights.com/tag/internal-investigation/" target="_blank" rel="noopener"><b>investigate</b></a><span style="font-weight: 400;"> them. While routine </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> concerns can often be handled internally, certain matters may require an independent approach. </span></p>
<p><span style="font-weight: 400;">In-house counsel plays a critical role in recognizing when an independent investigation may be necessary, selecting outside counsel to lead it, assisting outside counsel with access to information and witnesses and safeguarding privilege throughout the process. </span></p>
<h2><span style="font-weight: 400;">When an independent investigation is warranted</span></h2>
<p><span style="font-weight: 400;">While a variety of circumstances may warrant an independent investigation, the most clear trigger is when the allegations implicate senior management, including C-suite executives, </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>board members</b></a><span style="font-weight: 400;"> or individuals with authority over compliance functions. In these situations, an internal team may face real or perceived conflicts of interest that undermine the investigation’s efficacy and even its credibility.</span></p>
<p><span style="font-weight: 400;">Similarly, when allegations are likely to attract regulatory scrutiny from agencies such as the </span><a href="https://www.corporatecomplianceinsights.com/tag/doj/" target="_blank" rel="noopener"><b>DOJ</b></a><span style="font-weight: 400;">, the </span><a href="https://www.corporatecomplianceinsights.com/tag/sec/" target="_blank" rel="noopener"><b>SEC</b></a><span style="font-weight: 400;"> or state attorneys general, an independent investigation signals to regulators that the organization is taking the matter seriously and conducting a thorough, unbiased review.</span></p>
<p><span style="font-weight: 400;">Other situations warranting retention of independent counsel include matters involving potential financial restatements, significant </span><a href="https://www.corporatecomplianceinsights.com/tag/whistleblowing/" target="_blank" rel="noopener"><b>whistleblower</b></a><span style="font-weight: 400;"> complaints, allegations of systemic compliance failures and cases where litigation is anticipated or already underway. In each of these scenarios, the perceived independence of the investigation can be as important as the substantive findings themselves. </span></p>
<h2><span style="font-weight: 400;">Structuring the investigation for credibility and effectiveness</span></h2>
<p><span style="font-weight: 400;">Once in-house counsel decides to pursue an independent investigation, they must ensure that the investigation’s structure supports its objectives. Several key elements require careful consideration from the outset.</span></p>
<h3><span style="font-weight: 400;">Selecting outside counsel </span></h3>
<p><span style="font-weight: 400;">Outside counsel should have deep experience in internal investigations and, if applicable, familiarity with the relevant regulatory landscape. When the investigation touches on regulatory issues, retaining a firm with credibility before the regulators’ scrutiny can pay dividends if the investigation’s findings are later presented to the government. </span></p>
<p><span style="font-weight: 400;">Equally important is that counsel be free from conflicts of interest, not only with regard to the potential subjects of the investigation but also with regard to the company’s regular business. This means that in-house counsel may need to look beyond the company’s usual outside counsel relationships if their independence could be questioned. In-house counsel should conduct thorough conflicts checks, evaluate candidates’ relationships with the relevant regulators and ensure that the engagement terms clearly define the scope, responsibilities and reporting lines.</span></p>
<h3><span style="font-weight: 400;">Establishing oversight and defining scope</span></h3>
<p><span style="font-weight: 400;">In-house counsel should ensure that independent counsel reports to the board of directors, an independent committee of the board or a specially formed committee rather than to management. This reporting structure reinforces the investigation’s independence and helps insulate its findings from accusations of bias. </span></p>
<p><span style="font-weight: 400;">In-house counsel should work with the relevant company committee to clearly define the scope of the investigation and the committee’s authority. Defining these parameters early helps prevent scope disputes and role confusion as the investigation progresses and can help streamline privilege determinations later.</span></p>
<p><span style="font-weight: 400;">The scope should be broad enough to address the core allegations and any reasonably related conduct but sufficiently focused to avoid the investigation becoming unwieldy. The scope should also be documented in writing at the outset of the investigation and revisited periodically, as new facts may necessitate expansion or refinement. Overly narrow scoping risks missing related misconduct, while an unbounded investigation can drain resources and delay resolution. </span></p>
<p><span style="font-weight: 400;">Counsel should also ensure that the scope and engagement clearly indicate the company’s reason for the investigation, which will further assist in protecting privilege down the road. Finally, in-house counsel should establish a process for outside counsel to flag scope questions in real time so adjustments can be made promptly to avoid delaying the investigation.</span></p>
<h3><span style="font-weight: 400;">Managing document preservation and collection</span></h3>
<p><span style="font-weight: 400;">One of the first steps in-house counsel must take in support of an investigation is issuing a litigation hold or document preservation notice to all relevant custodians. This notice should be clear, comprehensive and promptly distributed. In-house counsel should coordinate with outside counsel and forensic vendors to oversee the collection process and ensure defensibility of the steps taken to retain relevant information. Counsel should consider and balance competing priorities: collecting and producing documents to outside counsel in a timely manner while limiting the number of individuals involved to protect privilege or safeguard sensitive information. This balance relies on the needs of the investigation and any time constraints as identified in the investigation plan.</span></p>
<p><span style="font-weight: 400;">In collecting and preserving information, in-house counsel should pay particular attention to ephemeral messaging platforms, personal devices, cloud-based repositories and </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;">-based programs, such as Copilot or ChatGPT, which are increasingly common sources of relevant evidence and frequent subjects of regulatory inquiry. Organizations with </span><a href="https://www.corporatecomplianceinsights.com/tag/byod/" target="_blank" rel="noopener"><b>bring-your-own-device</b></a><span style="font-weight: 400;"> policies face additional complexity, as personal devices used for work purposes may contain relevant data that must be preserved and collected while navigating employee privacy expectations and any applicable agreements. </span></p>
<p><span style="font-weight: 400;">In-house counsel is often best positioned to identify custodians, locate data sources and facilitate access within the organization. If the investigation involves extremely sensitive or confidential subject matter, such that there is a </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> in broadcasting its existence even to a limited set of custodians, in-house counsel should work with internal and external IT vendors to ensure that all routine deletion is suspended from the back-end.</span></p>
<h3><span style="font-weight: 400;">Conducting witness interviews</span></h3>
<p><span style="font-weight: 400;">Witness interviews are the backbone of most internal investigations. In-house counsel should work with outside counsel to identify key witnesses and ensure that all relevant documents are provided before each interview session. In-house counsel plays a key logistical role in making witnesses available for interviews. In practice, witnesses are more receptive to cooperating with outside counsel when introduced by in-house counsel. Beyond facilitating an introduction, in-house counsel should assist in providing an appropriate private space for interviews to be conducted, ensuring that the setting preserves confidentiality and minimizes the risk that other employees will learn who is being interviewed. In-house counsel can also be instrumental in impressing upon witnesses the importance of not sharing the substance of the interview with other potential fact witnesses.</span></p>
<p><span style="font-weight: 400;">Some witnesses may be hesitant to work with outside counsel and may fear retaliation by the company for participating in the interview or providing honest disclosures. In-house counsel may consider including a copy of the company’s retaliation or whistleblower protection policy in its original outreach email to provide witnesses with reassurance that their rights will be protected. Additionally, these policies can help ease the hesitation some witnesses experience after outside counsel administers </span><a href="https://content.next.westlaw.com/practical-law/document/Ibb0a39dfef0511e28578f7ccc38dcbee/Upjohn-Warning?viewType=FullText&amp;transitionType=Default&amp;contextData=(sc.Default)" target="_blank" rel="noopener"><b>Upjohn warnings</b></a><span style="font-weight: 400;"> at the outset of every interview. While they can be uncomfortable, Upjohn warnings are necessary to inform witnesses that (1) counsel represents the organization and not the individual, (2) the conversation is privileged, but (3) the organization and not the witness holds the privilege and may choose to waive it. </span></p>
<p><span style="font-weight: 400;">Failure to provide these warnings can create confusion, jeopardize the privilege and expose the organization to claims of improper representation. However, in determining how to deliver the warning, and who is the best conduit, due consideration must also be given to ensuring that the witness feels protected and empowered to freely and completely provide all information available to them.</span></p>
<h3><span style="font-weight: 400;">Preparing the final product </span></h3>
<p><span style="font-weight: 400;">In-house counsel should work with outside counsel and the board or designated committee early in the process to determine the form of the investigation’s final work product, whether a written report, an oral presentation to the board or a combination. </span></p>
<p><span style="font-weight: 400;">Written reports create a detailed record but also create a discoverable document if privilege is waived or successfully challenged. Oral presentations preserve greater flexibility but may be viewed as less rigorous. The choice often depends on the anticipated regulatory posture and litigation landscape. Regardless of format, in-house counsel should ensure that findings are presented with precision and supported by the evidentiary record.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67636_4_6a673ac14e2b1   " data-unique="jnews_module_67636_4_6a673ac14e2b1">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/ai-risk-2026-critical-changes-general-counsel/" aria-label="Read article: AI Risk in 2026: 3 Critical Changes for the General Counsel"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="scales of justice statue on desk" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/01/scales-of-justice-statue-on-desk-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/01/scales-of-justice-statue-on-desk-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/01/scales-of-justice-statue-on-desk-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/01/scales-of-justice-statue-on-desk-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/governance/">Governance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/ai-risk-2026-critical-changes-general-counsel/">AI Risk in 2026: 3 Critical Changes for the General Counsel</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/jenny-hamilton/">Jenny Hamilton</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/ai-risk-2026-critical-changes-general-counsel/"><i class="fa fa-clock-o"></i> January 20, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>The discipline legal ops brings — technology evaluation, vendor management, compliance monitoring — maps to capabilities required for AI governance</p>
                                    <a href="https://www.corporatecomplianceinsights.com/ai-risk-2026-critical-changes-general-counsel/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67636_4_6a673ac14e2b1 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"65965","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Privilege and confidentiality concerns</span></h2>
<p><span style="font-weight: 400;">Privilege and confidentiality issues permeate every stage of an independent investigation. While outside counsel bears primary responsibility for establishing the protocols that protect these interests, in-house counsel plays an integral part in enforcing these protocols within the company.</span></p>
<p><span style="font-weight: 400;">The attorney-client privilege protects communications made for the purpose of obtaining legal advice, and the work product doctrine shields materials prepared in anticipation of litigation. To preserve both, in-house counsel should ensure that (1) outside counsel’s engagement is clearly documented as a legal engagement and includes the purpose of the investigation, (2) communications are marked as privileged and confidential where appropriate and (3) the circle of individuals with access to privileged materials is carefully limited to those necessary to the successful completion of the investigation. In-house counsel should establish clear internal protocols that separate legal communications from business communications, especially when in-house counsel often wears both a legal and a business hat. Mixing legal and business purposes in investigation communications is one of the most common ways privilege is inadvertently weakened or waived.</span></p>
<p><span style="font-weight: 400;">The tension between a desire for transparency and the preservation of privilege is often most pronounced when a government investigation proceeds alongside an internal inquiry. Regulators may request or expect full cooperation, which can include sharing the findings of an internal investigation. In-house counsel must carefully consider whether, to what extent and via what means to disclose investigation results to the government. Voluntary disclosure of privileged materials to a regulator may constitute a waiver of privilege as to third parties. In-house counsel should therefore develop a disclosure strategy in coordination with outside counsel, identifying what can be shared without waiving privilege, what requires a confidentiality agreement or common interest arrangement and what should be withheld.</span></p>
<p><span style="font-weight: 400;">Finally, beyond privilege, in-house counsel should not overlook the confidentiality expectations of employees and other stakeholders. Witnesses may have concerns about retaliation, and information leaks can compromise the investigation’s integrity. In-house counsel should establish clear protocols for information security, limit dissemination of findings on a need-to-know basis and ensure compliance with whistleblower protection laws and policies.</span></p>
<h3><span style="font-weight: 400;">Reporting and self-disclosure obligations </span></h3>
<p><span style="font-weight: 400;">One of the most challenging tasks during an independent investigation is determining whether and how to report findings up the chain of command and, in certain circumstances, outside the organization. Under </span><a href="https://www.congress.gov/bill/107th-congress/house-bill/3763" target="_blank" rel="noopener"><b>the Sarbanes-Oxley Act</b></a><span style="font-weight: 400;"> and the </span><a href="https://www.sec.gov/rules-regulations/2003/01/implementation-standards-professional-conduct-attorneys" target="_blank" rel="noopener"><b>SEC’s standards of professional conduct</b></a><span style="font-weight: 400;">, in-house attorneys who become aware of evidence of a material violation of securities laws or a breach of fiduciary duty are required to report that evidence up the ladder, beginning with the chief legal officer or the CEO. If the initial report does not result in an appropriate response, in-house counsel must escalate the matter to the </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>audit</b></a><span style="font-weight: 400;"> committee, another independent committee of the board or the full board of directors. Failure to report up can expose both the attorney and the organization to significant regulatory consequences.</span></p>
<p><span style="font-weight: 400;">Beyond reporting up, in-house counsel must also evaluate self-disclosure obligations to external regulators and law enforcement. Certain regulatory regimes impose mandatory disclosure requirements or provide significant benefits for companies that self-report potential violations. For example, the DOJ’s</span> <span style="font-weight: 400;">corporate enforcement and voluntary </span><a href="https://www.corporatecomplianceinsights.com/one-cep-rule-them-all/" target="_blank" rel="noopener"><b>self-disclosure policy</b></a><span style="font-weight: 400;"> provides concrete benefits, up to and including potential declination of prosecution, for companies that voluntarily self-disclose misconduct, cooperate fully and remediate promptly. Similar incentive structures exist at the SEC (see </span><a href="https://www.sec.gov/files/enforcementmanual.pdf" target="_blank" rel="noopener"><b>SEC enforcement manual</b></a><span style="font-weight: 400;"> § 2.5.1), CFTC (see </span><a href="https://www.cftc.gov/PressRoom/PressReleases/9234-26" target="_blank" rel="noopener"><b>Letter 26-15</b></a><span style="font-weight: 400;">) and other federal and state agencies.</span></p>
<p><span style="font-weight: 400;">Despite the potential benefits, the decision to self-disclose is rarely straightforward. In-house counsel must weigh those potential benefits, such as cooperation credit and reduced penalties, against the risks, including triggering government investigations, waiving privilege and creating exposure for individuals within the organization. In-house counsel should work closely with outside counsel and the board or audit committee to develop a disclosure strategy that accounts for the specific regulatory landscape, the strength of the evidence or severity of the potential misconduct, the organization’s remediation efforts and the potential impact on ongoing or anticipated private litigation.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/when-misconduct-reaches-c-suite-who-investigates/">When Misconduct Reaches the C-Suite, Who Investigates?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Does Your Organization Have a Compliant Gift Policy Under Federal, State &amp; Local Law?</title>
		<link>https://www.corporatecomplianceinsights.com/does-your-organization-have-compliant-gift-policy-under-law/</link>
		
		<dc:creator><![CDATA[Pei Pei Cheng de Castro and Jennifer Hopkins]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 11:00:48 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Anti-Bribery]]></category>
		<category><![CDATA[Anti-Corruption]]></category>
		<category><![CDATA[Code of Conduct]]></category>
		<category><![CDATA[Employee Handbooks]]></category>
		<category><![CDATA[Internal Controls]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67632</guid>

					<description><![CDATA[<p>Meals, travel, charitable donations made on an official’s behalf are among categories many gift policies overlook</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/does-your-organization-have-compliant-gift-policy-under-law/">Does Your Organization Have a Compliant Gift Policy Under Federal, State &#038; Local Law?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Relationships with public officials may sometimes become blurred through long-term projects and pressures of prolonging or keeping an engagement. Pei Pei Cheng de Castro and Jennifer Hopkins of Barclay Damon explain how compliance and legal units can spring to action to address these concerns.</span></i></p>
</div>
<p><span style="font-weight: 400;">The primary legal </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risks</b></a><span style="font-weight: 400;"> implicated by gifts, gratuities and hospitality may include federal, state and local criminal bribery and gratuities exposure, lobbying gift restrictions, procurement gift restrictions and related conflicts of interest. </span></p>
<p><span style="font-weight: 400;">Key components of an organization’s gift-giving policy operating under a federal jurisdictional framework should also account for restrictions imposed by state and local jurisdictions. It is critical for in-house counsel and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> officers to regularly review and ensure corporate policies are up to date, emphasizing prohibitions on </span><i><span style="font-weight: 400;">quid pro quo</span></i><span style="font-weight: 400;">, testing preapproval and tracking controls, instilling transparency and accurate records and implementing heightened controls for employees who regularly deal with public officials and compete for public projects. </span></p>
<p><span style="font-weight: 400;">It is equally important for organizations to </span><a href="https://www.corporatecomplianceinsights.com/tag/training/" target="_blank" rel="noopener"><b>train</b></a><span style="font-weight: 400;"> on these topics, especially for those employees interacting with public officials.</span></p>
<h2><span style="font-weight: 400;">The laws and rules</span></h2>
<p><a href="https://www.law.cornell.edu/uscode/text/18/201" target="_blank" rel="noopener"><b>Federal law</b></a><span style="font-weight: 400;"> addresses giving or offering &#8220;anything of value&#8221; to public officials &#8220;for or because of any official act performed or to be performed&#8221; and separately addresses corrupt giving with intent. </span><a href="https://www.law.cornell.edu/cfr/text/5/2635.204" target="_blank" rel="noopener"><b>Federal rules</b></a><span style="font-weight: 400;"> for executive branch personnel permit acceptance only pursuant to </span><a href="https://www.corporatecomplianceinsights.com/ethics-news/" target="_blank" rel="noopener"><b>ethics</b></a><span style="font-weight: 400;">-office rules but expressly prohibit acceptance &#8220;in return for being influenced in the performance of any official act.&#8221; Executive branch officials and employees are generally prohibited from soliciting or accepting gifts or items of monetary value from persons or entities seeking official action, doing business with or regulated by the employee&#8217;s agency or whose interests may be substantially affected by the employee&#8217;s duties. </span></p>
<p><span style="font-weight: 400;">Contracting officers must identify and evaluate potential conflicts of interest early and avoid, neutralize or mitigate significant potential conflicts before contract award. In addition, the </span><a href="https://www.corporatecomplianceinsights.com/fcpa-news/" target="_blank" rel="noopener"><b>FCPA</b></a><span style="font-weight: 400;"> prohibits giving something of value for the purpose of influencing acts or decisions of a foreign official, inducing unlawful acts or omissions or securing an improper advantage to obtain or retain business.</span></p>
<p><span style="font-weight: 400;">States and local jurisdictions also have laws prohibiting or restricting the giving of gifts to public officials, including bans on providing &#8220;directly or indirectly&#8221; gifts, entertainment, food and beverage, lodging, transportation or anything of value. This may include indirect gifts, such as donations to nonprofits made on behalf of or at the recommendation of a public official or their immediate family. In addition, gratuities — different from gifts — may also be prohibited.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_67632_5_6a673ac151200   " data-unique="jnews_module_67632_5_6a673ac151200">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/fcpa-compliance-programs-missing-nuances-bribery-persian-gulf/" aria-label="Read article: FCPA Compliance Programs Are Missing Important Nuances About How Bribery Works in the Persian Gulf"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="gulf coast countries map" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/gulf-coast-countries-map-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/gulf-coast-countries-map-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/gulf-coast-countries-map-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/gulf-coast-countries-map-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/fcpa/">FCPA</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/fcpa-compliance-programs-missing-nuances-bribery-persian-gulf/">FCPA Compliance Programs Are Missing Important Nuances About How Bribery Works in the Persian Gulf</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/majid-mumtaz/">Majid Mumtaz</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/fcpa-compliance-programs-missing-nuances-bribery-persian-gulf/"><i class="fa fa-clock-o"></i> April 1, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p></p>
                                    <a href="https://www.corporatecomplianceinsights.com/fcpa-compliance-programs-missing-nuances-bribery-persian-gulf/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_67632_5_6a673ac151200 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"66467","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Compliance policies</span></h2>
<p><span style="font-weight: 400;">A compliant policy should define &#8220;gift and thing of value&#8221; broadly to include not only tangible items but also meals, entertainment, travel, lodging, transportation and other benefits, including indirect transfers. This breadth aligns with federal public-official concepts that address &#8220;anything of value&#8221; given directly or indirectly. It also aligns with the practical reality that state and local ethics laws often prohibit the direct or indirect provision of anything of value to public officials and may treat certain third-party benefits, including charitable donations made on an official&#8217;s recommendation, as prohibited gifts. Many policies do not mention or incorporate the concept of gratuities, which under certain jurisdictions may be unlawful.</span></p>
<p><span style="font-weight: 400;">A gift policy should include a clear prohibition on offering, giving or promising anything of value in exchange for influence or because of influence on an official act. The policy should also make it clear that intent to influence isn’t allowed. This is consistent with federal restrictions addressing giving anything of value &#8220;for or because of any official act&#8221; and separately addressing corrupt giving with intent. It is also consistent with the executive-branch gift framework that, regardless of ethics-office rules, prohibits accepting gifts &#8220;in return for being influenced in the performance of any official act.&#8221; Operationally, the policy should require employees to evaluate not only the item&#8217;s value but also the surrounding circumstances (timing, pending matters, recipient role and business purpose) to avoid gifts that could be construed as consideration for official action.</span></p>
<p><span style="font-weight: 400;">Heightened </span><a href="https://www.corporatecomplianceinsights.com/tag/internal-controls/" target="_blank" rel="noopener"><b>controls</b></a><span style="font-weight: 400;"> in the policies are necessary when dealing with government officials. Because executive-branch employees are generally prohibited from accepting gifts from certain sources (including those seeking official action or doing business with the agency), a company policy should impose heightened controls whenever the recipient is a public official or government employee. The policy should require preapproval or legal/compliance consultation before offering anything of value to any public official at any level of government because state and local jurisdictions may impose additional bans or stricter limits. </span></p>
<p><span style="font-weight: 400;">Furthermore, the policy should address and provide guidelines for situations when a public official solicits the gift or gratuity. How to address solicitation by the public official is often lacking in an organization’s gift giving policy. A practical control is a mandatory permissibility check before anything of value is offered or given, including meals and event tickets, as well as indirect benefits, such as charitable donations connected to an official.</span></p>
<p><span style="font-weight: 400;">For entities that compete for or perform government </span><a href="https://www.corporatecomplianceinsights.com/tag/contract-management/" target="_blank" rel="noopener"><b>contracts</b></a><span style="font-weight: 400;">, the policy should emphasize related restricted contracts during blackout periods and implement controls to instill procurement integrity. Contracting officers must identify and avoid or neutralize significant conflicts before and after award. Early escalation to compliance and legal units should be incorporated when gifts, hospitality or relationships could create an appearance of impropriety or risk claims of unequal access. A practical control is a mandatory disclosure form for a vendor to disclose known or potential conflicts of interest.</span></p>
<p><span style="font-weight: 400;">If the organization interacts with foreign officials, the policy should incorporate FCPA standards: prohibiting giving anything of value to influence a foreign official&#8217;s acts or decisions, induce unlawful acts or omissions or secure an improper advantage to obtain or retain business. The policy should also address that certain expenditures, such as travel and lodging, may be defensible only if they are &#8220;</span><a href="https://www.justice.gov/sites/default/files/criminal-fraud/legacy/2012/11/14/fcpa-english.pdf" target="_blank" rel="noopener"><b>reasonable and </b><b><i>bona fide</i></b></a><span style="font-weight: 400;">&#8221; and directly related to legitimate purposes as reflected in the statutory language. The policy should require preapproval and documentation for any travel, lodging or hospitality involving foreign officials, including a written business justification and confirmation of permissibility under applicable written local laws where relevant to the statutory affirmative defense.</span></p>
<p><span style="font-weight: 400;">Equally important is to implement targeted training for employees interacting with government officials and procurement personnel, emphasizing prohibited-source concepts, restricted contacts, solicitations, conflict of interest, gratuities and the need to avoid even the appearance of impropriety.  </span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/does-your-organization-have-compliant-gift-policy-under-law/">Does Your Organization Have a Compliant Gift Policy Under Federal, State &#038; Local Law?</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deals in Dispute: Activism Against M&amp;A</title>
		<link>https://www.corporatecomplianceinsights.com/2026-activism-in-mergers-acquisitions/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 19:07:41 +0000</pubDate>
				<category><![CDATA[Governance]]></category>
		<category><![CDATA[Whitepapers]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Mergers and Acquisitions]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67657</guid>

					<description><![CDATA[<p>A new report from Diligent Market Intelligence and Seward &#038; Kissel examines nearly 300 activist demands opposing the sale of US-listed companies since 2015, analyzing what makes deals vulnerable to challenge and how activists build leverage against them.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/2026-activism-in-mergers-acquisitions/">Deals in Dispute: Activism Against M&#038;A</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid vc_row-o-equal-height vc_row-flex"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-4 vc_custom_1659714795294 vc_col-has-fill"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper vc_box_shadow_3d  vc_box_border_grey"><img loading="lazy" decoding="async" width="791" height="1024" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-791x1024.jpg" class="vc_single_image-img attachment-large" alt="Diligent Deals in Dispute Report 2026-c" title="" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-791x1024.jpg 791w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-232x300.jpg 232w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-768x994.jpg 768w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-1187x1536.jpg 1187w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-750x971.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c-1140x1475.jpg 1140w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/Diligent-Deals-in-Dispute-Report-2026-c.jpg 1200w" sizes="(max-width: 791px) 100vw, 791px" /></div>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;">What it takes to break a deal and how boards should prepare</p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "8f0157a7-e1d7-4350-a9c4-fc7ece8c1d60",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-1"><div class="jeg_wrapper wpb_wrapper"></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-7"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element no-bottom-margin" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 18px; color: #e77c30;">2026 report</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans black; font-size: 50px; color: #133350; line-height: 1.2;">Deals in Dispute: Activism Against M&amp;A</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 16px; color: #133350;">What&#8217;s in this report from Diligent Market Intelligence and Seward &amp; Kissel:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Contested M&amp;A is no longer a niche concern. A new report from Diligent Market Intelligence, produced in association with Seward &amp; Kissel, examines nearly 300 activist demands opposing the sale of US-listed companies since 2015, drawing on Diligent&#8217;s activism, voting and governance datasets. Opposition to announced deals has become a more durable feature of the public-company landscape, with activist success rates reaching their highest level in 2025 since 2018.</p>
<p>Some key findings:</p>
<ul>
<li>Proxy advisor recommendations remain a significant factor in contested deals, with the average vote in favor of an opposed merger varying dramatically depending on whether ISS recommended for or against.</li>
<li>CEO tenure at target companies correlates with campaign outcomes, with oppose-sale demands proving considerably more likely to succeed against companies with shorter-tenured chief executives.</li>
<li>Occasional activists accounted for the majority of oppose-sale demands examined and achieved at least partial success at a rate comparable to more established firms.</li>
</ul>

		</div>
	</div>
</div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper"><div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div></div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/2026-activism-in-mergers-acquisitions/">Deals in Dispute: Activism Against M&#038;A</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2026 Proxy Season Trends &amp; Updates</title>
		<link>https://www.corporatecomplianceinsights.com/proxy-season-trends-updates-2026/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 19:02:40 +0000</pubDate>
				<category><![CDATA[Governance]]></category>
		<category><![CDATA[Whitepapers]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[SEC]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67654</guid>

					<description><![CDATA[<p>A new report from Freshfields examines the trends and regulatory developments that defined the 2026 proxy season, from a sharp rise in governance proposals to the SEC's decision to step back from its role as arbiter of shareholder proposal exclusions. </p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/proxy-season-trends-updates-2026/">2026 Proxy Season Trends &#038; Updates</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid vc_row-o-equal-height vc_row-flex"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-4 vc_custom_1659714795294 vc_col-has-fill"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper vc_box_shadow_3d  vc_box_border_grey"><img loading="lazy" decoding="async" width="1024" height="791" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-1024x791.jpg" class="vc_single_image-img attachment-large" alt="freshfields-trends-and-updates-from-the-2026-proxy-season-c" title="" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-1024x791.jpg 1024w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-300x232.jpg 300w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-768x593.jpg 768w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-750x579.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c-1140x881.jpg 1140w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/freshfields-trends-and-updates-from-the-2026-proxy-season-c.jpg 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></div>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;">What defined the 2026 proxy season?</p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "2a7a9f36-f936-41df-9153-7de27ada6230",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-1"><div class="jeg_wrapper wpb_wrapper"></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-7"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element no-bottom-margin" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 18px; color: #e77c30;">2026 report</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans black; font-size: 50px; color: #133350; line-height: 1.2;">Trends &amp; Updates From the 2026 Proxy Season</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 16px; color: #133350;">What&#8217;s in this report from Freshfields:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>The 2026 proxy season was shaped by a significant shift in the SEC&#8217;s approach to shareholder proposals, widespread uncertainty around the future of Rule 14a-8 and a notable rebalancing of proposal categories. Governance proposals rose sharply to 322, up from 244 the year prior, while social proposals fell by nearly half and environmental proposals declined as well, even as support for both increased slightly. This report from Freshfields examines how those dynamics played out and what they signal heading into next year.</p>
<p>Some key findings:</p>
<ul>
<li>The SEC&#8217;s November 2025 decision to step back from its long-standing role as arbiter under Rule 14a-8 left companies and investors without clear precedent on exclusions, and at least six companies have since faced investor lawsuits over excluded proposals.</li>
<li>AI-related proposals grew in number and scope, with institutional investors and proxy advisory firms also grappling with how AI is affecting their own stewardship models.</li>
<li>Institutional investor influence is splintering away from a more centralized stewardship model, shifting the dynamics of shareholder engagement and how companies approach proxy solicitation.</li>
</ul>

		</div>
	</div>
</div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper"><div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div></div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/proxy-season-trends-updates-2026/">2026 Proxy Season Trends &#038; Updates</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>