

Compliance into the Weeds
Tom Fox
What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in Compliance, going into the weeds of a topic each week. Each week, you can take a deep dive with two of the top writers, thinkers and prognosticators in compliance.
Episodes
Mentioned books

Sep 16, 2026 • 28min
Governing Agentic AI: DFS Cyber Risk Assessments, EU AI Act Accountability, and the Inventory Problem
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them fully and uncover hard-hitting compliance insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the growing compliance and cybersecurity challenges posed by agentic AI.
They focus on New York Department of Financial Services (DFS) guidance on cybersecurity risk assessments and a European survey Kelly cites. They argue DFS’s rule, requiring annual or as-needed reassessments after significant technology and threat changes and maintaining an accurate IT asset inventory, implicitly compels organizations to identify and track AI agents, even though agents are not mentioned. Kelly cites a Veeam Software survey of 1,000+ European executives reporting limited visibility into employee-created autonomous AI workflows and AI interactions with sensitive data, complicating EU AI Act requirements for human accountability. The conversation compares potential governance models to Sarbanes-Oxley sub-certifications and enterprise software management, questions whether CISOs can certify compliance amid decentralized agent creation, and notes potential enforcement avenues and the risks of industry self-regulation.
Key highlights:
Why DFS Guidance Matters
Risk Assessments Meet Agents
Accountability Under EU AI Act
SOX Style Governance Model
Enforcement and Self-Regulation
Resources:
Matt in Radical Compliance (2 posts)
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcasts, and a Top 12 Risk Management Podcasts. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

9 snips
Sep 9, 2026 • 34min
Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons
An NBA salary-cap scandal unfolds through sham endorsements, vague contracts, unusual counterparties, and a paper trail of incriminating emails. The discussion examines how roughly $18 million in extra compensation allegedly reached Kawhi Leonard, why repeated violations raised tone-at-the-top concerns, and what fines, suspensions, lost draft picks, and stronger contract oversight mean for compliance in professional sports.

Sep 2, 2026 • 22min
Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action.
Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool.
Key highlights:
ITAR data shipments trigger BAE’s $36 million penalty
Broken execution in day-to-day compliance operations
Export-control warnings before sensitive file transmission
Missing Red-Flag Prompts in Export Control System
Self-Disclosed, Cooperated, Remediated, Monitored by Another Name
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 26, 2026 • 25min
AI for Compliance: Lessons from Teaching Cohorts
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Kelly’s collaboration with Ethena to run short, paid online AI classes for compliance professionals.
Since May, there has been an excellent AI training for compliance professionals, covering vibe coding, content/video generation, and data analytics with hands-on exercises using dummy or public data. Kelly says his biggest takeaway has been how much AI education is still needed and that many compliance teams are only scratching the surface, despite fears that “everyone else” is further along. They review common tools but emphasize that success depends more on the inputs and outputs, data readiness, clear use cases, and acting on results than on which model is chosen. They also address governance, security, privacy, maintenance, technical debt, costs and token budgets, and the need to involve compliance, which often leads to AI governance. The episode ends with reflections on Dolly Parton’s leadership and a story about her retaining rights to the hit song “I Will Always Love You.”
Key highlights:
AI Class Overview
AI Skills Gap Reality Check
Good Enough to Start
AI Angst and Cost Questions
Why Compliance Should Lead AI Governance
Dolly Parton Tribute
Resources
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 19, 2026 • 24min
Compliance Implications of DOJ’s New Fraud Division and McDonald Memo
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.”
This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business.
Key highlights:
McDonald Memo Overview
Fraud Division Scope and Uncertainty
Five Fraud Categories Explained
Corporate Misconduct Questions
Compliance Program Impacts
Documentation as Defense
Mexico Cartels and Strict Liability
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 12, 2026 • 28min
Ted Lasso, Culture and Compliance
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly celebrate the return of Ted Lasso for Season 4.
Tom and Matt begin with why Ted Lasso resonates with compliance officers as a study of workplace dynamics, leadership, and building a culture of trust. They highlight how Ted focuses on coaching people and shaping club-wide culture through “thousands of imperceptible moments,” culminating in “total football,” where shared expectations and mutual support enable improvisation and performance. They connect this to compliance goals of embedding ethics so employees can handle new situations on the fly and to Jim Collins’ “level five” leadership and humility, illustrated by Ted renaming Trent Crimm’s book from “The Ted Lasso Way” to “The Richmond Way.” They also link the show to the military OODA loop (observe, orient, decide, act) as a model for empowered decision-making within clear objectives and boundaries and preview Season 4’s shift to Ted coaching a women’s team.
Key highlights:
Ted Lasso Returns Season Four
Culture and Trust at Richmond
Total Football and Compliance
The Richmond Way Leadership Lesson
Level Five Humility
OODA Loop Meets Compliance
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 5, 2026 • 26min
FinCEN’s $125MM UBS AML Order: A Culture and Resourcing Failure
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a newly issued FinCEN consent order sanctioning UBS Financial Services, the U.S. broker-dealer subsidiary of UBS.
It is a $125 million penalty, the largest FinCEN fine against a broker-dealer, for extensive anti-money laundering failures. They highlight weak transaction monitoring and suspicious activity reporting (SAR) processes, poor customer due diligence, inadequate wire-transfer data collection, and data governance gaps that led to under-reporting and hindered FinCEN’s ability to build a complete money-laundering picture. The order notes UBS failed to monitor more than 50,000 foreign-currency wires totaling over $10 billion and did not disclose ongoing deficiencies discovered after a 2018 $14 million FinCEN action requiring fixes by 2021, with problems traceable back to 2004 and not addressed until 2023. They frame the matter as a tone-at-the-top and resourcing failure, compare it to other enforcement actions (including a recent SEC fine against Merrill Lynch), and suggest a future deeper dive after reviewing the full order.
Key highlights:
What UBS Got Wrong
Scale Of The Failures
Board Oversight and Resourcing
Data Governance Breakdown
SARs, Metrics, and AI Talk
Takeaways and Next Steps
Resources:
USB Consent Order
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Jul 29, 2026 • 27min
Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.
The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.
Resources:
Matt in Radical Compliance
Tom in FCPA Compliance and Ethics Blog
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Jul 15, 2026 • 28min
The Slaughter Ruling, Regulatory Volatility and a Healthcare Compliance Fraud Case
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the June 29 Supreme Court decision in Trump v. Slaughter.
This decision upheld the president’s power to fire independent agency commissioners at will (with a carve-out for the Federal Reserve), overturning long-standing protections from Humphrey’s Executor. Kelly argues the ruling will politicize and degrade regulatory agencies, deter qualified minority-party commissioners, increase rulemaking volatility, and shift power away from Congress toward courts as rules are challenged. As an example, they cite the SEC’s proposal to allow semi-annual rather than quarterly reporting, which drew about 80,000 comments, with roughly 99% opposed, yet they predict it may proceed and later be reversed, creating compliance burdens. They then cover Georgia author Jean Wilson, sentenced to 10 years for a $66 million Medicare fraud scheme while writing healthcare compliance books.
Key highlights:
The Slaughter Ruling
Regulatory Volatility Ahead
Who Will Serve as Commissioners
Fed Carve-out and Court Power
Compliance Impact and No Easy Answers
Healthcare Compliance Fraud Story (Or is it from The Onion?)
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

10 snips
Jul 1, 2026 • 26min
Survey Finds Widespread Retaliation Against Compliance Officers
A deep look at a survey revealing how common retaliation is against compliance officers. Short accounts of the most frequent forms of mistreatment and how often they recur. Discussion of the impact on careers and workplace fear. Ideas for structural protections and legal safeguards are proposed.


