Featured Articles:

Updating Your Sanctions Compliance Guidance, Part 2: The Four Multi-Agency Priorities You Need to Build Into Your Program Now

Part 1 of this series revisited the 2019 OFAC Framework for Compliance Commitments and made the case that its five pillars, management commitment, risk assessment, internal controls, testing and auditing, and training, remain the right foundation for any sanctions compliance program. But a foundation isn’t a finished structure. Since 2023, DOJ, BIS, and OFAC have been issuing joint “Tri-Seal” compliance notes that build substantial new...

Updating Your Sanctions Compliance Guidance, Part 1: The 2019 Framework Is Still Your Foundation, But It’s No Longer the Whole Picture

If you built your sanctions compliance program around OFAC’s 2019 Framework for Compliance Commitments and haven’t revisited it since, you’re not alone, and you’re also overdue for an update. The 2019 Framework remains the foundational document for how OFAC evaluates a sanctions compliance program, and every one of its five pillars is still good law today. But federal sanctions enforcement has fundamentally changed shape since...

The Marriage of Compliance and Data, Part 3: AI and the Arrival of Genuine Real-Time Risk Intelligence

Part 1 of this series traced compliance’s earliest, clumsiest attempts to measure its own programs through hotline volumes and training completion rates. Part 2 covered the shift toward continuous monitoring, integrated dashboards, and key risk indicators, a real leap forward, but one still fundamentally limited by rules-based systems that could only catch risks someone had already anticipated. Part 3 closes the series by looking at...

Episode 455 — Updating Your Sanctions Compliance Program

In this episode of Corruption, Crime and Compliance, Michael Volkov explains why OFAC’s 2019 Framework for Compliance Commitments, built on the five pillars of management commitment, risk assessment, internal controls, testing and auditing, and training, remains the essential foundation for any sanctions compliance program, while also walking through the substantial multi-agency guidance that has layered on top of it since 2023 through joint DOJ, BIS,...

Is Embedded AI Slipping Past Your Controls?

Today’s version of the Trojan horse doesn’t need to sneak past your gate in the dead of night. It’s a software update to something you already let in. Second preview ahead of tomorrow’s webinar, and this one’s about a blind spot I see constantly. Most compliance officers think about shadow AI as employees going out and signing up for some random chatbot. That happens, but...

Episode 454 — The Marriage of Compliance and Data

In this episode of Corruption, Crime and Compliance, Michael Volkov traces the decades-long relationship between compliance and data, from the profession’s earliest, checkbox-style attempts to measure program effectiveness through crude proxies like hotline volume and training completion rates, through the rise of continuous monitoring systems, integrated dashboards, and key risk indicators that enabled expedited auditing and near-real-time visibility, and finally to the current AI-driven era,...

The Marriage of Compliance and Data, Part 2: Building Systems That Could Actually Keep Up

Part 1 of this series traced compliance’s early, clumsy attempts to capture data about its own programs, relying on hotline volumes and training completion rates that told you very little about whether misconduct was actually being deterred or caught. It also described the gap that emerged once regulators started expecting companies to actually use their data: the systems compliance functions had simply weren’t built to...

The Marriage of Compliance and Data, Part 1: How We Started Trying to Measure What We Could Barely See

Compliance and data have been in a long relationship, and like most long relationships, it started awkwardly. This is the first of a three-part series tracing that relationship from its earliest, clumsiest days to where it’s headed with the arrival of AI-driven real-time monitoring. Part 1 covers how the profession first tried to capture data about its own programs and figure out whether any of...

Webinar: Updating Your Sanctions Compliance Program for the Multi-Agency Enforcement Era

October 28, 2026, 12 Noon EDT Sign Up HERE OFAC’s 2019 Framework for Compliance Commitments is still the foundational document every sanctions compliance program should be built on, but if your program hasn’t been updated since then, it no longer reflects how sanctions enforcement actually works today. Since 2023, the Department of Justice, the Department of Commerce’s Bureau of Industry and Security, and OFAC have...

Is Your Third-Party Risk Program Ready for AI?

An AI tool isn’t a piece of software. It’s a locked door, and you have no idea how many people have a key. Quick preview ahead of tomorrow’s webinar on AI and third-party risk, because I want you thinking about this before we dive in. Here’s the mental shift every compliance officer needs to make: every AI tool your company adopts is a third-party vendor...