Discover
Compliance into the Weeds
Compliance into the Weeds
Author: Tom Fox
Subscribed: 41Played: 2,092Subscribe
Share
Description
What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in Compliance, going into the weeds of a topic each week. Each week, you can take a deep dive with two of the top writers, thinkers and prognosticators in compliance.
443 Episodes
Reverse
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them fully and uncover hard-hitting compliance insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the growing compliance and cybersecurity challenges posed by agentic AI.
They focus on New York Department of Financial Services (DFS) guidance on cybersecurity risk assessments and a European survey Kelly cites. They argue DFS’s rule, requiring annual or as-needed reassessments after significant technology and threat changes and maintaining an accurate IT asset inventory, implicitly compels organizations to identify and track AI agents, even though agents are not mentioned. Kelly cites a Veeam Software survey of 1,000+ European executives reporting limited visibility into employee-created autonomous AI workflows and AI interactions with sensitive data, complicating EU AI Act requirements for human accountability. The conversation compares potential governance models to Sarbanes-Oxley sub-certifications and enterprise software management, questions whether CISOs can certify compliance amid decentralized agent creation, and notes potential enforcement avenues and the risks of industry self-regulation.
Key highlights:
Why DFS Guidance Matters
Risk Assessments Meet Agents
Accountability Under EU AI Act
SOX Style Governance Model
Enforcement and Self-Regulation
Resources:
Matt in Radical Compliance (2 posts)
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcasts, and a Top 12 Risk Management Podcasts. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the NBA’s sanctions against the Los Angeles Clippers for a salary-cap circumvention scheme tied to Kawhi Leonard.
In this delicious set of compliance imbroglios, senior management, including owner Steve Ballmer, allegedly arranged sham endorsement deals with four business partners and offsetting Clippers business to funnel about $18 million in extra compensation, plus improperly pay Leonard’s personal expenses. Tom and Matt review the Wachtell Lipton 36-page investigation detailing sparse contracts, unusual counterparties, rapid deal timing, and incriminating emails (including from Gillian Zucker), as well as recidivism after a similar 2019 violation. Penalties include a $30 million team fine, Leonard’s $700K fine, loss of first-round picks for five years, and suspensions for Ballmer, Zucker, and the basketball operations executive. Meanwhile, Ballmer denies wrongdoing and says the Clippers will file an appeal. They highlight contract-management and third-party due diligence lessons from FCPA-style guidance, the need to analyze patterns across multiple agreements, and the value of strong compliance roles in pro sports.
Key highlights:
NBA Scandal Overview
How The Scheme Worked and Why Salary Caps Matter
Sham Contracts = Red Flags
Paper Trail and Intent
Recidivism and Tone at the Top
Contract Patterns Lessons
Resources:
Matt in Radical Compliance
Tom in the FCPA Compliance and Ethics Blog
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and w3 Awards, all for podcast excellence.
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action.
Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool.
Key highlights:
ITAR data shipments trigger BAE’s $36 million penalty
Broken execution in day-to-day compliance operations
Export-control warnings before sensitive file transmission
Missing Red-Flag Prompts in Export Control System
Self-Disclosed, Cooperated, Remediated, Monitored by Another Name
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Kelly’s collaboration with Ethena to run short, paid online AI classes for compliance professionals.
Since May, there has been an excellent AI training for compliance professionals, covering vibe coding, content/video generation, and data analytics with hands-on exercises using dummy or public data. Kelly says his biggest takeaway has been how much AI education is still needed and that many compliance teams are only scratching the surface, despite fears that “everyone else” is further along. They review common tools but emphasize that success depends more on the inputs and outputs, data readiness, clear use cases, and acting on results than on which model is chosen. They also address governance, security, privacy, maintenance, technical debt, costs and token budgets, and the need to involve compliance, which often leads to AI governance. The episode ends with reflections on Dolly Parton’s leadership and a story about her retaining rights to the hit song “I Will Always Love You.”
Key highlights:
AI Class Overview
AI Skills Gap Reality Check
Good Enough to Start
AI Angst and Cost Questions
Why Compliance Should Lead AI Governance
Dolly Parton Tribute
Resources
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.”
This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business.
Key highlights:
McDonald Memo Overview
Fraud Division Scope and Uncertainty
Five Fraud Categories Explained
Corporate Misconduct Questions
Compliance Program Impacts
Documentation as Defense
Mexico Cartels and Strict Liability
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.
Learn more about your ad choices. Visit megaphone.fm/adchoices




