Compliance into the Weeds

Tom Fox

What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in Compliance, going into the weeds of a topic each week. Each week, you can take a deep dive with two of the top writers, thinkers and prognosticators in compliance. 

  1. 6d ago

    Whistleblower Resolution Delays Is Justice Denied

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a GAO audit of the Department of Homeland Security’s whistleblower retaliation program. They use it as a case study for corporate compliance officers. DHS employees can report internally via the Office of Inspector General hotline or externally to the Office of Special Counsel. However, the GAO review focused on DHS’s internal process, where the OIG’s Whistleblower Protection Division (eight investigators) investigates retaliation and, if substantiated, sends cases to the Office of the Secretary and ultimately the DHS Secretary for corrective action. Although targets are six months for investigation and 30 days for secretarial action, GAO found investigations averaged 3.2 years (some up to six) amid rising complaint volumes, turnover, and evidence-gathering challenges. Meanwhile, none of the 11 substantiated cases were decided within 30 days because of missing written procedures and no designated accountable official—showing how delayed resolution erodes reporting culture and “institutional justice.” Key highlights: Why the GAO Report Matters DHS Whistleblower Program Structure Timeline Expectations vs. Reality Compliance Lessons and GAO Value Resources: Matt in Radical Compliance Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Whistleblower Resolution Delays Is Justice Denied
  2. Sep 16

    Governing Agentic AI: DFS Cyber Risk Assessments, EU AI Act Accountability, and the Inventory Problem

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them fully and uncover hard-hitting compliance insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the growing compliance and cybersecurity challenges posed by agentic AI. They focus on New York Department of Financial Services (DFS) guidance on cybersecurity risk assessments and a European survey Kelly cites. They argue DFS’s rule, requiring annual or as-needed reassessments after significant technology and threat changes and maintaining an accurate IT asset inventory, implicitly compels organizations to identify and track AI agents, even though agents are not mentioned. Kelly cites a Veeam Software survey of 1,000+ European executives reporting limited visibility into employee-created autonomous AI workflows and AI interactions with sensitive data, complicating EU AI Act requirements for human accountability. The conversation compares potential governance models to Sarbanes-Oxley sub-certifications and enterprise software management, questions whether CISOs can certify compliance amid decentralized agent creation, and notes potential enforcement avenues and the risks of industry self-regulation. Key highlights: Why DFS Guidance Matters Risk Assessments Meet Agents Accountability Under EU AI Act SOX Style Governance Model Enforcement and Self-Regulation Resources: Matt in Radical Compliance (2 posts) Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcasts, and a Top 12 Risk Management Podcasts. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Governing Agentic AI: DFS Cyber Risk Assessments, EU AI Act Accountability, and the Inventory Problem
  3. Sep 9

    Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the NBA’s sanctions against the Los Angeles Clippers for a salary-cap circumvention scheme tied to Kawhi Leonard. In this delicious set of compliance imbroglios, senior management, including owner Steve Ballmer, allegedly arranged sham endorsement deals with four business partners and offsetting Clippers business to funnel about $18 million in extra compensation, plus improperly pay Leonard’s personal expenses. Tom and Matt review the Wachtell Lipton 36-page investigation detailing sparse contracts, unusual counterparties, rapid deal timing, and incriminating emails (including from Gillian Zucker), as well as recidivism after a similar 2019 violation. Penalties include a $30 million team fine, Leonard’s $700K fine, loss of first-round picks for five years, and suspensions for Ballmer, Zucker, and the basketball operations executive. Meanwhile, Ballmer denies wrongdoing and says the Clippers will file an appeal. They highlight contract-management and third-party due diligence lessons from FCPA-style guidance, the need to analyze patterns across multiple agreements, and the value of strong compliance roles in pro sports. Key highlights: NBA Scandal Overview How The Scheme Worked and Why Salary Caps Matter Sham Contracts = Red Flags Paper Trail and Intent Recidivism and Tone at the Top Contract Patterns Lessons Resources: Matt in Radical Compliance Tom in the FCPA Compliance and Ethics Blog Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and w3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons
  4. Sep 2

    Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action. Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool. Key highlights: ITAR data shipments trigger BAE’s $36 million penalty Broken execution in day-to-day compliance operations Export-control warnings before sensitive file transmission Missing Red-Flag Prompts in Export Control System Self-Disclosed, Cooperated, Remediated, Monitored by Another Name Resources: Matt in Radical Compliance Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

    Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action
  5. Aug 26

    AI for Compliance: Lessons from Teaching Cohorts⁠

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Kelly’s collaboration with Ethena to run short, paid online AI classes for compliance professionals. Since May, there has been an excellent AI training for compliance professionals, covering vibe coding, content/video generation, and data analytics with hands-on exercises using dummy or public data. Kelly says his biggest takeaway has been how much AI education is still needed and that many compliance teams are only scratching the surface, despite fears that “everyone else” is further along. They review common tools but emphasize that success depends more on the inputs and outputs, data readiness, clear use cases, and acting on results than on which model is chosen. They also address governance, security, privacy, maintenance, technical debt, costs and token budgets, and the need to involve compliance, which often leads to AI governance. The episode ends with reflections on Dolly Parton’s leadership and a story about her retaining rights to the hit song “I Will Always Love You.” Key highlights: AI Class Overview AI Skills Gap Reality Check Good Enough to Start AI Angst and Cost Questions Why Compliance Should Lead AI Governance Dolly Parton Tribute Resources Matt in Radical Compliance Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.  Learn more about your ad choices. Visit megaphone.fm/adchoices

    AI for Compliance: Lessons from Teaching Cohorts⁠
  6. Aug 19

    Compliance Implications of DOJ’s New Fraud Division and McDonald Memo

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.” This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business. Key highlights: McDonald Memo Overview Fraud Division Scope and Uncertainty Five Fraud Categories Explained Corporate Misconduct Questions Compliance Program Impacts Documentation as Defense Mexico Cartels and Strict Liability Resources: Matt in Radical Compliance Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.  Learn more about your ad choices. Visit megaphone.fm/adchoices

    Compliance Implications of DOJ’s New Fraud Division and McDonald Memo
  7. Aug 12

    Ted Lasso, Culture and Compliance

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly celebrate the return of Ted Lasso for Season 4. Tom and Matt begin with why Ted Lasso resonates with compliance officers as a study of workplace dynamics, leadership, and building a culture of trust. They highlight how Ted focuses on coaching people and shaping club-wide culture through “thousands of imperceptible moments,” culminating in “total football,” where shared expectations and mutual support enable improvisation and performance. They connect this to compliance goals of embedding ethics so employees can handle new situations on the fly and to Jim Collins’ “level five” leadership and humility, illustrated by Ted renaming Trent Crimm’s book from “The Ted Lasso Way” to “The Richmond Way.” They also link the show to the military OODA loop (observe, orient, decide, act) as a model for empowered decision-making within clear objectives and boundaries and preview Season 4’s shift to Ted coaching a women’s team. Key highlights: Ted Lasso Returns Season Four Culture and Trust at Richmond Total Football and Compliance The Richmond Way Leadership Lesson Level Five Humility OODA Loop Meets Compliance Resources: Matt in Radical Compliance Tom Instagram Facebook YouTube Twitter LinkedIn A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence.  Learn more about your ad choices. Visit megaphone.fm/adchoices

    Ted Lasso, Culture and Compliance
  8. Aug 5

    FinCEN’s $125MM UBS AML Order: A Culture and Resourcing Failure

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a newly issued FinCEN consent order sanctioning UBS Financial Services, the U.S. broker-dealer subsidiary of UBS. It is a $125 million penalty, the largest FinCEN fine against a broker-dealer, for extensive anti-money laundering failures. They highlight weak transaction monitoring and suspicious activity reporting (SAR) processes, poor customer due diligence, inadequate wire-transfer data collection, and data governance gaps that led to under-reporting and hindered FinCEN’s ability to build a complete money-laundering picture. The order notes UBS failed to monitor more than 50,000 foreign-currency wires totaling over $10 billion and did not disclose ongoing deficiencies discovered after a 2018 $14 million FinCEN action requiring fixes by 2021, with problems traceable back to 2004 and not addressed until 2023. They frame the matter as a tone-at-the-top and resourcing failure, compare it to other enforcement actions (including a recent SEC fine against Merrill Lynch), and suggest a future deeper dive after reviewing the full order. Key highlights: What UBS Got Wrong Scale Of The Failures Board Oversight and Resourcing Data Governance Breakdown SARs, Metrics, and AI Talk Takeaways and Next Steps Resources: ⁠USB Consent Order⁠  Tom   ⁠Instagram⁠ ⁠Facebook⁠ ⁠YouTube⁠ ⁠Twitter⁠ ⁠LinkedIn⁠ A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence.  Learn more about your ad choices. Visit megaphone.fm/adchoices

    FinCEN’s $125MM UBS AML Order: A Culture and Resourcing Failure

Ratings & Reviews

4
out of 5
15 Ratings

About

What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in Compliance, going into the weeds of a topic each week. Each week, you can take a deep dive with two of the top writers, thinkers and prognosticators in compliance. 

You Might Also Like