Featured Articles:

BAE ITAR Settlement — Part 2: Root Causes and the Real Lessons for Export Compliance

Part 1 of this series walked through the settlement terms and the sheer range of violations DDTC documented against BAE Systems, spanning unlicensed technical data exports, unauthorized defense services, agreement mismanagement, and documentation failures. In Part 2, we focus on what actually caused all of this, because DDTC’s charging letter is unusually candid about root causes, and those root causes are far more instructive than...

Why Every Organization Needs an AI Acceptable Use Policy Now, Part 1: The Risk Landscape

If your organization does not yet have a written AI Acceptable Use Policy, I can tell you exactly what is happening inside your walls right now: employees are already using AI tools, whether you have authorized it or not. They are pasting documents into chatbots to summarize them, asking generative AI to draft correspondence, running research queries, and increasingly relying on AI features quietly embedded...

Building an AI Acceptable Use Policy, Part 2: The Provisions That Actually Matter

Part 1 of this series laid out why the risk landscape around generative AI, confidentiality exposure, hallucination risk, and vendor risk, makes a written AI Acceptable Use Policy an urgent priority rather than a nice-to-have. In Part 2, I want to walk through what actually needs to be in that policy for it to function as a real governance tool rather than a document nobody...

Episode 447 — Veloxis Pharmaceuticals’ $46 Million Kickback Settlement and What the CEP Really Rewards

In this episode of Corruption, Crime and Compliance, Michael Volkov breaks down Veloxis Pharmaceuticals’ more than $46 million settlement with DOJ and HHS-OIG over a years-long kickback scheme involving its kidney transplant drug Envarsus XR, a scheme the DPA says was directed in part by the company’s own former CEO. He examines why Veloxis avoided prosecution and instead secured a deferred prosecution agreement under DOJ’s...

When You Fail to Fix an Already Flagged Compliance Gap

At $125 million, breaking the law can never be a cost of doing business. UBS Bank was hit with a $125 million FinCEN penalty, the largest ever against a broker-dealer under the Bank Secrecy Act. This is UBS’s second Bank Secrecy Act action in less than a decade. In 2018, regulators told UBS: fix your foreign currency wire monitoring. It never did. The same gap...

The FTC Opens an Antitrust Probe Into Epic Systems: Why This One Matters

Reuters reported this week that the Federal Trade Commission has opened an antitrust investigation into Epic Systems, the dominant electronic health records vendor based in Verona, Wisconsin. The report, citing two sources familiar with the matter, says the FTC has already sent investigative demands to other companies in the health technology industry, seeking information about how Epic controls access to patient data. The agency has...

BIS’s FY2025 Annual Report: An 18-Fold Enforcement Surge and What It Means for Export Compliance Programs

The Bureau of Industry and Security’s Fiscal Year 2025 Annual Report to Congress is not a routine bureaucratic filing. It reads more like a mission statement, and the numbers inside it back up the rhetoric. Export control enforcement has escalated dramatically over the past year, and companies operating in semiconductors, aerospace, defense, dual-use technology, and cross-border trade more broadly need to understand exactly how much...

BAE Systems $36 Million ITAR Settlement: Part 1 — The Penalty and the Catalog of Violations

The State Department’s Directorate of Defense Trade Controls just handed down a $36 million penalty against BAE Systems, Inc., resolving more than 100 alleged violations of the International Traffic in Arms Regulations and the Arms Export Control Act stretching from 2019 through as recently as March 2025. This is Part 1 of a two-part series on the case. Here, we walk through the settlement structure...

Episode 446 — L3Harris’s CEO Ouster and the Board Governance Lesson Nobody Learns the First Time

In this episode of Corruption, Crime and Compliance, Michael Volkov examines L3Harris Technologies’ abrupt ouster of chairman and CEO Christopher Kubasik over a code-of-conduct violation, and why the story is really a board governance cautionary tale rather than a typical enforcement matter. He traces Kubasik’s earlier, similar departure from Lockheed Martin in 2012 alongside comparable cases involving Brian Krzanich at Intel and Mark Hurd at...

Could Your Routine Customs Payment Actually Be a Bribe?

Is your routine payment actually a bribe? Scolar, an Omaha agricultural company, resolved an FCPA case for over $10 million after using customs brokers to bribe Mexican officials, about $2,000 for each train that crossed the border. It was invoiced as reinspection fees paid routinely for six years. Nobody asked what the money actually bought. Stop treating customs brokers, freight forwarders, and logistics providers like...