

Compliance into the Weeds
Tom Fox
What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in Compliance, going into the weeds of a topic each week. Each week, you can take a deep dive with two of the top writers, thinkers and prognosticators in compliance.
Episodes
Mentioned books

Oct 7, 2026 • 25min
New Fraud Section Guidelines
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s new Fraud Division enforcement priorities.
The DOJ’s Fraud Division enforcement priorities matter because they can quickly reshape a company’s compliance risk, especially when prosecutors are told to focus on patterns like widespread victimization, large losses, senior management involvement, and obstruction of investigations. Tom argues updates are a practical cue for compliance leaders to reopen discussions with senior management, the audit committee, and the board, while also treating whistleblower incentives and even political risk as real factors on the company risk register. Matt similarly argues that the DOJ’s new posture has changed enforcement risk and that companies should respond by refreshing risk assessments, sharpening internal controls, and briefing leadership before problems become more costly. Both perspectives are shaped by their long experience covering corporate compliance and enforcement, with Fox emphasizing proactive governance and Kelly stressing the need to translate DOJ signals into concrete, business-specific risk management.
Key highlights:
10-Factor Fraud Prosecution Memo for Corporations
Multiple Small Fraud Indicators, Material Weakness Risk
DOJ Shift Raises Compliance Costs and Stakes
Declinations for Companies That Voluntarily Self-Disclose
Corporate Enforcement Section and 2024 ECCP
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Sep 30, 2026 • 22min
Southern Glazer’s NPA: How Remediation and ECCP Alignment Drove a Favorable Settlement
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the Southern Glazer NPA.
The Southern Glazer Wine and Spirits’ non-prosecution agreement is a rare example where prosecutors credited compliance program remediation, rather than self-disclosure or extensive cooperation, as central to a favorable outcome. Southern Glazer, the largest US liquor distributor, faced a major California kickback and bribery scheme involving five former employees, fabricated records, sham agreements, and luxury benefits to retailers and others, along with alleged tax impacts. The company resolved the matter with a $12.5 million payment and a two-year NPA requiring the CEO and CCO to certify program effectiveness. Tom and Matt review how the NPA affirms DOJ’s Evaluation of Corporate Compliance Programs as still relevant and detail remediation steps: major headcount and budget increases, upgraded compliance leadership, audits of marketing spend, enhanced training, strengthened third-party controls and AP payment blocks, outside reviews, and tone-at-the-top messaging.
Key highlights:
Southern Glazer Case Setup
Industry Risks and Scheme
ECCP Guidance Still Matters
Program Overhaul Timeline
Concrete Remediation Metrics
DOJ Signals Under Trump Era
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Sep 23, 2026 • 21min
Whistleblower Resolution Delays Is Justice Denied
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a GAO audit of the Department of Homeland Security’s whistleblower retaliation program.
They use it as a case study for corporate compliance officers. DHS employees can report internally via the Office of Inspector General hotline or externally to the Office of Special Counsel. However, the GAO review focused on DHS’s internal process, where the OIG’s Whistleblower Protection Division (eight investigators) investigates retaliation and, if substantiated, sends cases to the Office of the Secretary and ultimately the DHS Secretary for corrective action. Although targets are six months for investigation and 30 days for secretarial action, GAO found investigations averaged 3.2 years (some up to six) amid rising complaint volumes, turnover, and evidence-gathering challenges. Meanwhile, none of the 11 substantiated cases were decided within 30 days because of missing written procedures and no designated accountable official—showing how delayed resolution erodes reporting culture and “institutional justice.”
Key highlights:
Why the GAO Report Matters
DHS Whistleblower Program Structure
Timeline Expectations vs. Reality
Compliance Lessons and GAO Value
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Sep 16, 2026 • 28min
Governing Agentic AI: DFS Cyber Risk Assessments, EU AI Act Accountability, and the Inventory Problem
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them fully and uncover hard-hitting compliance insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the growing compliance and cybersecurity challenges posed by agentic AI.
They focus on New York Department of Financial Services (DFS) guidance on cybersecurity risk assessments and a European survey Kelly cites. They argue DFS’s rule, requiring annual or as-needed reassessments after significant technology and threat changes and maintaining an accurate IT asset inventory, implicitly compels organizations to identify and track AI agents, even though agents are not mentioned. Kelly cites a Veeam Software survey of 1,000+ European executives reporting limited visibility into employee-created autonomous AI workflows and AI interactions with sensitive data, complicating EU AI Act requirements for human accountability. The conversation compares potential governance models to Sarbanes-Oxley sub-certifications and enterprise software management, questions whether CISOs can certify compliance amid decentralized agent creation, and notes potential enforcement avenues and the risks of industry self-regulation.
Key highlights:
Why DFS Guidance Matters
Risk Assessments Meet Agents
Accountability Under EU AI Act
SOX Style Governance Model
Enforcement and Self-Regulation
Resources:
Matt in Radical Compliance (2 posts)
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcasts, and a Top 12 Risk Management Podcasts. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

9 snips
Sep 9, 2026 • 34min
Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons
An NBA salary-cap scandal unfolds through sham endorsements, vague contracts, unusual counterparties, and a paper trail of incriminating emails. The discussion examines how roughly $18 million in extra compensation allegedly reached Kawhi Leonard, why repeated violations raised tone-at-the-top concerns, and what fines, suspensions, lost draft picks, and stronger contract oversight mean for compliance in professional sports.

Sep 2, 2026 • 22min
Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action.
Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool.
Key highlights:
ITAR data shipments trigger BAE’s $36 million penalty
Broken execution in day-to-day compliance operations
Export-control warnings before sensitive file transmission
Missing Red-Flag Prompts in Export Control System
Self-Disclosed, Cooperated, Remediated, Monitored by Another Name
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 26, 2026 • 25min
AI for Compliance: Lessons from Teaching Cohorts
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Kelly’s collaboration with Ethena to run short, paid online AI classes for compliance professionals.
Since May, there has been an excellent AI training for compliance professionals, covering vibe coding, content/video generation, and data analytics with hands-on exercises using dummy or public data. Kelly says his biggest takeaway has been how much AI education is still needed and that many compliance teams are only scratching the surface, despite fears that “everyone else” is further along. They review common tools but emphasize that success depends more on the inputs and outputs, data readiness, clear use cases, and acting on results than on which model is chosen. They also address governance, security, privacy, maintenance, technical debt, costs and token budgets, and the need to involve compliance, which often leads to AI governance. The episode ends with reflections on Dolly Parton’s leadership and a story about her retaining rights to the hit song “I Will Always Love You.”
Key highlights:
AI Class Overview
AI Skills Gap Reality Check
Good Enough to Start
AI Angst and Cost Questions
Why Compliance Should Lead AI Governance
Dolly Parton Tribute
Resources
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 19, 2026 • 24min
Compliance Implications of DOJ’s New Fraud Division and McDonald Memo
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.”
This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business.
Key highlights:
McDonald Memo Overview
Fraud Division Scope and Uncertainty
Five Fraud Categories Explained
Corporate Misconduct Questions
Compliance Program Impacts
Documentation as Defense
Mexico Cartels and Strict Liability
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 12, 2026 • 28min
Ted Lasso, Culture and Compliance
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly celebrate the return of Ted Lasso for Season 4.
Tom and Matt begin with why Ted Lasso resonates with compliance officers as a study of workplace dynamics, leadership, and building a culture of trust. They highlight how Ted focuses on coaching people and shaping club-wide culture through “thousands of imperceptible moments,” culminating in “total football,” where shared expectations and mutual support enable improvisation and performance. They connect this to compliance goals of embedding ethics so employees can handle new situations on the fly and to Jim Collins’ “level five” leadership and humility, illustrated by Ted renaming Trent Crimm’s book from “The Ted Lasso Way” to “The Richmond Way.” They also link the show to the military OODA loop (observe, orient, decide, act) as a model for empowered decision-making within clear objectives and boundaries and preview Season 4’s shift to Ted coaching a women’s team.
Key highlights:
Ted Lasso Returns Season Four
Culture and Trust at Richmond
Total Football and Compliance
The Richmond Way Leadership Lesson
Level Five Humility
OODA Loop Meets Compliance
Resources:
Matt in Radical Compliance
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices

Aug 5, 2026 • 26min
FinCEN’s $125MM UBS AML Order: A Culture and Resourcing Failure
The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a newly issued FinCEN consent order sanctioning UBS Financial Services, the U.S. broker-dealer subsidiary of UBS.
It is a $125 million penalty, the largest FinCEN fine against a broker-dealer, for extensive anti-money laundering failures. They highlight weak transaction monitoring and suspicious activity reporting (SAR) processes, poor customer due diligence, inadequate wire-transfer data collection, and data governance gaps that led to under-reporting and hindered FinCEN’s ability to build a complete money-laundering picture. The order notes UBS failed to monitor more than 50,000 foreign-currency wires totaling over $10 billion and did not disclose ongoing deficiencies discovered after a 2018 $14 million FinCEN action requiring fixes by 2021, with problems traceable back to 2004 and not addressed until 2023. They frame the matter as a tone-at-the-top and resourcing failure, compare it to other enforcement actions (including a recent SEC fine against Merrill Lynch), and suggest a future deeper dive after reviewing the full order.
Key highlights:
What UBS Got Wrong
Scale Of The Failures
Board Oversight and Resourcing
Data Governance Breakdown
SARs, Metrics, and AI Talk
Takeaways and Next Steps
Resources:
USB Consent Order
Tom
Instagram
Facebook
YouTube
Twitter
LinkedIn
A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence. Learn more about your ad choices. Visit megaphone.fm/adchoices


