Compliance Chronicles with Liisa Thomas

Liisa Thomas

Working in privacy or compliance today means doing organizational change in an AI‑driven world, often without a playbook. Compliance Chronicles brings you lessons with leaders who have navigated that reality, using a simple structure in every episode: their career journey, the challenges they faced, the lessons they took away, and the advice they have for you. Compliance Chronicles is a practical, conversation‑driven podcast for privacy, cyber, and compliance professionals who are being asked to “figure out” AI, data protection, and regulatory change while still handling their day‑to‑day work. Liisa’s practice focuses on helping companies design and mature AI and privacy governance programs, and this show reflects the real questions clients bring into that work. Hosted by law firm partner and adjunct professor Liisa Thomas, the show is designed for CLOs, CPOs, CISOs, CCOs and their teams who need to create workable solutions to tricky AI, privacy, and cyber compliance problems. In her conversations with leaders across the industry, Liisa draws on her legal and organizational change experience helping companies build privacy and AI governance to ask the questions you wish you could have, and to surface patterns you can reuse with your own teams. In each episode, Liisa interviews leaders in the industry who share their career journey, the challenges they have faced and lessons they learned along the way, and their parting advice for others walking a similar path. Guests talk openly about moving skeptical businesses, working with boards and regulators, and operationalizing privacy, cyber, and AI governance in complex, fast‑moving environments. Whether you are new to privacy or a seasoned CPO, you will hear relatable stories, hard‑won lessons, and human‑centered strategies you can apply in your own organization. If you’re wrestling with AI, privacy and cyber governance in your own organization, you will also hear how Liisa approaches these issues in her work with clients. You can find all episodes at https://www.compliance-chronicles.com.

  1. 39m ago

    Effective Compliance by Untangling People Problems and Staying Authentic with Corey Tanner (Ep. 19)

    In this episode of Compliance Chronicles, Liisa Thomas talks with Corey Tanner about building an employment law function from the ground up and navigating the human side of compliance and investigations. Corey shares how a college job as a secretary at a small employment law firm led to law school and a career focused on workplace issues, internal investigations, and compliance across law firms, the University of Texas, and in‑house roles. She explains why she has always been drawn to the human element: understanding why people do what they do, untangling complicated facts, and helping organizations resolve difficult people problems. Along the way, Corey has created employment law functions, handled complex investigations, and learned how to show up as a trusted partner rather than “the department of no” or “the person you only call when someone is in trouble.” This episode covers: The challenge of wanting the “best possible outcome” as a young lawyer—and the freeing lesson that you can’t change the facts, only work with the circumstances in front of you How to shift perceptions from “legal/compliance means I’m in trouble” to “legal/compliance is a value‑add partner” Practical ways to build trust, including showing genuine interest in people, starting with “Where do you want to go?” and working backwards from desired outcomes Designing paths that move from A to B to X, Y, Z instead of expecting an instant jump from A to Z; and why early, ongoing partnership beats late‑stage roadblocking Balancing a heavy job with being a partner, parent, and friend, and the role of exercise, priorities, and perspective in finding some equilibrium The importance of honesty and how “the cover‑up is worse than the crime” shows up in investigations and legal practice Why almost every mistake is fixable if you own it and ask for help, and how perceived failures can become the most valuable learning experiences The concept of “moral drift”: small compromises that slowly move you far from where you intended to be, and why staying alert to those steps matters How different people can sincerely believe different versions of events, and what that means for investigations, employment law, and compliance Why authenticity, humor, and humility are Corey's core leadership principles; bringing your full self to work, being able to laugh when appropriate, and openly asking experts to “explain it like I’m a third grader” If you enjoyed this episode of Compliance Chronicles, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow Compliance Chronicles on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.

  2. Sep 2

    Ensuring Your Compliance Role Matches the Moment with Jay Cohen (Ep. 18)

    In this episode of Compliance Chronicles, Liisa Thomas talks with Jay Cohen about what it really means to lead compliance in a global insurance business, and why activity alone doesn’t prove an effective compliance program. Jay shares his journey from 20 years in New York government (including 10 years as a prosecutor in Brooklyn) into legal and regulatory compliance roles at a variety of companies including Prudential, Assurant, and ultimately QBE Insurance. He explains how he “fell into” compliance during a nationwide class action and multi‑state regulatory investigation at Prudential, where his first assignment was telling offices around the country to keep boxes and boxes of files. From there, he moved into health insurance and leadership roles, eventually becoming a chief compliance officer and consultant before stepping into his current role at QBE. This episode covers: Why regulatory compliance feels similar to appellate work: understanding the rules, telling the story, and helping business teams make those rules work in practice Jay’s “pre and post” philosophy of compliance: knowing which rules apply and knowing whether the organization is actually following them The challenge of rules that are constantly changing, not always practical, and sometimes at odds with what the business wants to do The partner vs. guardian dilemma, inspired by Ben Heineman’s work: knowing when to support the business and when to protect it, and getting the business to understand why Why counting training sessions, policies, or helpline calls doesn’t truly measure compliance effectiveness How to focus on whether changes are communicated, implemented, and whether they stick in daily operations The importance of getting out of your office, spending time with business teams, and building relationships so people know and trust you when you say “partner” or “guardian” Assuming positive intent, especially when teams resist or push back, and using that resistance as a cue to listen and recalibrate Why compliance is a “terrific way to make a living” if you care about understanding, analysis, communication, and helping companies do the right thing If you enjoyed this episode of Compliance Chronicles, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow Compliance Chronicles on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.

  3. Aug 19

    Embedding Compliance in Business Growth with Lauren Ervin (Ep. 17)

    In this episode of Compliance Chronicles, Liisa Thomas talks with Lauren Ervin, an Associate General Counsel who shares how privacy moved from a tentative “I’ll raise my hand” moment to the core of her legal and compliance work. Lauren shares how she spent over a decade in financial services—starting at a small litigation firm in Miami, then moving in‑house to a major non‑bank mortgage servicer—before a mentor encouraged her to take on privacy because “it’s going to be a big deal one day.” That nudge led her to build out privacy responsibilities and eventually support privacy, security, and data governance in her current role. She explains why privacy is often treated like “art class”—important but easily deprioritized—and how she works to reframe it as a value proposition tied directly to customer choice, trust, and business growth. Throughout the conversation, Lauren highlights the importance of understanding the business, translating regulatory mandates into tangible benefits, and using both EQ and IQ to navigate complex, evolving privacy frameworks across states, regions, and cultures. This episode covers: ·        Why privacy is often viewed as “art class,” and how to reposition it as a business‑critical function customers genuinely care about ·        How learning the business first—processes, downstream impacts, and bandwidth—builds trust and makes privacy requests more workable ·        Practical ways to turn compliance objectives (like data mapping and inventories) into tools that help product, engineering, and customer teams ·        Strategies for baking privacy into the value proposition instead of treating it as a late‑stage hurdle to growth and innovation ·        The role of EQ in privacy work: doing right by residents and the company while managing expectations, skepticism, and change ·        How cultural awareness (across geographies and job roles) helps privacy and legal teams “meet people where they are” and collaborate more effectively ·        Why you shouldn’t be afraid to ask for what you want in your career—and how clarifying your “North Star” can actually help managers support you If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.

  4. Aug 5

    Turning Privacy Into a Business Success Factor with Matthew Ellis (Ep. 16)

    In this episode of Compliance Chronicles, Liisa Thomas talks with Matthew Ellis, an “opportunity creator and problem solver” who has spent nearly 25 years building and leading privacy programs across startups, Big Four firms, global technology companies, and consumer brands. Matthew shares how he fell into privacy at an email marketing startup, went on to start EY’s first Bay Area privacy practice, led privacy at Microsoft and Peloton, and now advises small–to–mid‑tier companies on turning privacy into a true success factor. He explains why privacy is most powerful when it’s operationalized—embedded in product and R&D from the beginning—and why privacy professionals often end up owning AI, M&A diligence, and complex data questions. Throughout the conversation, Matthew highlights the importance of bridging legal and product, saying yes to stretch opportunities, and treating privacy as a long‑game career path. This episode covers: Why early collaboration with product and R&D turns privacy from a late-stage obstacle into a strategic success factor How privacy professionals can bridge the gap between legal requirements and product ambitions by “speaking both languages” Lessons from large acquisitions and M&A work, including why “signing authority to assume risk” is a critical governance question Why privacy teams are often asked to take on AI, and what it means to “do something with nothing” when it comes to data and emerging tech How building teams of passionate learners and saying yes to stretch roles can accelerate a privacy career Why privacy is likely to remain a strong, growing career path over the next 20+ years—and how to prepare for that future Practical advice on leadership, vulnerability, and knowing when to raise your hand for more responsibility If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.

  5. Jul 22

    Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)

    Chief Information Security Officer Shellie Dreistadt joins Compliance Chronicles with Liisa Thomas to talk about how psychology, cybersecurity, and leadership resilience come together in modern security programs. She shares her nonlinear path from psychology and call‑center leadership into information security, online banking, and ultimately her current CISO role. Shellie explains why security sits at the intersection of people and technology, and how understanding behavior, motivation, and trust is just as important as understanding firewalls, access controls, and tools. She describes the realities of being a CISO today: constantly evolving threats, rapid technology change, and an expanding privacy and security regulatory landscape. The conversation covers pushing risk ownership back into the business, framing issues in financial and operational terms instead of “tech speak,” and avoiding burnout by refusing to be the “single point of safety.” Shellie also shares how she builds resilient, curious, adaptable teams and why culture and psychological safety matter as much as any control. Her advice for security, privacy, and compliance professionals: stay curious, stay human, and remember that cybersecurity is a marathon, not a sprint. Security is not about being the department of no—it is about enabling the business to move forward safely. If you work in cybersecurity, information security, privacy, or compliance—or you’re aspiring to a CISO or security leadership role—this episode offers practical insight into building resilient teams and leading with both technical acumen and empathy. If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, cybersecurity, and real‑world compliance leadership.

  6. Jul 8

    Developing Effective Compliance Guardrails with Bill Connolly (Ep. 14)

    Stepping into compliance “by accident,” building guardrails that actually help the business, and staying curious enough to reinvent your career—Episode 14 with Bill Connolly is packed with practical lessons for anyone in risk, privacy, or compliance leadership. In this episode of Compliance Chronicles, host Liisa Thomas talks with Bill Connolly, Head of Resiliency Risk for the U.S. retail bank at HSBC. Bill oversees a broad risk portfolio that spans information risk, business continuity, disaster recovery, operational resilience, and more—all brought together in a single resiliency risk program. He shares how his career evolved from managing TCPA suppressions and customer choice, to vendor risk and privacy, to digital compliance, and ultimately into enterprise resiliency risk. Bill walks through his “privacy by almost accident” story: starting with do‑not‑call and do‑not‑solicit databases, helping to build practical privacy questionnaires, and being asked to relaunch a new privacy program by writing a privacy policy that actually reflected how the organization worked. That experience led him into digital compliance, where he carried forward his privacy and information risk expertise to tackle cookie compliance, cross‑border data issues, and global data privacy obligations in a large financial institution. A major theme of the conversation is how to communicate risk in a way the business understands. Bill explains how he created “guardrails” to reduce low‑value questions and empower teams: if people stay within well‑defined parameters on TCPA, privacy, or other rules, they can move quickly; if they step outside those guardrails, that’s when legal and compliance step in. He shares why this kind of tooling not only helps the business move faster but also protects second‑line teams from getting buried in ad‑hoc requests. They dig into the challenges of new regulatory and resiliency requirements, including “important business services” mapping and the sheer scope of work that often falls on a small group of people in each business unit. Bill talks about translating highly technical topics—like IT vulnerabilities—into business language and compelling risk narratives that management can act on and fund. He emphasizes the importance of understanding both the compliance requirements and the resource impact on the business, so you can prioritize, sequence, and negotiate change effectively. Bill also shares career advice for compliance, risk, and privacy professionals at different stages. For those starting out, he stresses curiosity—following your interest into areas like digital privacy or information risk, and backing it up with credentials such as CISA and IAPP certifications. For those who are bored or burned out, he suggests re‑examining your role, looking one year ahead at where you want to be, and exploring adjacent areas like digital, operations, or new risk domains where your expertise can be uniquely valuable. The conversation closes with a focus on growth and reflection: using sabbaticals or mini‑sabbaticals, mentorship, and honest self‑assessment to decide when you need a new challenge. Bill’s parting advice is to deliberately step outside your comfort zone—because no one will do that for you—and to treat each stretch assignment as a way to expand both your knowledge and your network. If you work in privacy, compliance, operational risk, or resilience at a bank or large corporate and want to become a more effective partner to the business while continuing to grow your own career, this episode is for you. If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.

  7. Jun 24

    Creative Connections with Business Teams, with Katie Tomashevski (Ep. 13)

    In this lucky 13th episode of Compliance Chronicles, host Liisa Thomas talks with Katie Tomashevski, a New York–born, London‑trained British solicitor and internal auditor who specializes in data privacy and compliance. Katie shares her path from photojournalism and the entertainment and music industry into regulation, then into data protection, internal audit, and privacy roles in a large company. Katie explains how working in PR, marketing, and entertainment licensing led her to law school and ultimately to becoming a “second‑career solicitor,” using her creative background to connect with stakeholders and translate complex regulatory requirements into practical guidance. She describes going from “poacher to gamekeeper” as a regulator under multiple licensing and safety regimes, and how that experience shaped her approach to helping businesses do what they really want to do while staying compliant. They dig into the realities of compliance work: why “nobody likes compliance,” why most people genuinely want to do the right thing, and how curiosity and context are essential for getting buy‑in. Katie talks about how dyslexia has made her a better privacy and compliance professional, because it forces her to demand context, clear agendas, and upfront information so she can give her best advice. She shares how this mindset helps her understand business objectives, identify real risks, and avoid selling “solutions in search of a problem.” The conversation also explores Katie’s time as a data protection officer and internal advisor on data privacy, including a vivid story about data retention, data subject access requests, and what happens when organizations keep personal data far longer than promised. She highlights a key lesson: privacy and compliance teams advise on the “how,” but the business owns the “what” and the accountability for data processing decisions. Finally, Katie offers practical, encouraging advice for privacy, compliance, and audit professionals at every stage: be curious about what people actually want to achieve, see yourself as a trusted advisor rather than the “fun police,” and learn to speak the client’s language so your guidance lands and drives real behavior change. She emphasizes that every business, function, and client group has its own vocabulary—and the more you can mirror it, the more effective you become as a compliance and data privacy partner. If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.

5
out of 5
35 Ratings

About

Working in privacy or compliance today means doing organizational change in an AI‑driven world, often without a playbook. Compliance Chronicles brings you lessons with leaders who have navigated that reality, using a simple structure in every episode: their career journey, the challenges they faced, the lessons they took away, and the advice they have for you. Compliance Chronicles is a practical, conversation‑driven podcast for privacy, cyber, and compliance professionals who are being asked to “figure out” AI, data protection, and regulatory change while still handling their day‑to‑day work. Liisa’s practice focuses on helping companies design and mature AI and privacy governance programs, and this show reflects the real questions clients bring into that work. Hosted by law firm partner and adjunct professor Liisa Thomas, the show is designed for CLOs, CPOs, CISOs, CCOs and their teams who need to create workable solutions to tricky AI, privacy, and cyber compliance problems. In her conversations with leaders across the industry, Liisa draws on her legal and organizational change experience helping companies build privacy and AI governance to ask the questions you wish you could have, and to surface patterns you can reuse with your own teams. In each episode, Liisa interviews leaders in the industry who share their career journey, the challenges they have faced and lessons they learned along the way, and their parting advice for others walking a similar path. Guests talk openly about moving skeptical businesses, working with boards and regulators, and operationalizing privacy, cyber, and AI governance in complex, fast‑moving environments. Whether you are new to privacy or a seasoned CPO, you will hear relatable stories, hard‑won lessons, and human‑centered strategies you can apply in your own organization. If you’re wrestling with AI, privacy and cyber governance in your own organization, you will also hear how Liisa approaches these issues in her work with clients. You can find all episodes at https://www.compliance-chronicles.com.

You Might Also Like