Author: Michael Volkov

Two Important Webinars: Third-Party Risk and Sanctions & Effective Compliance Programs in the Age of AI

Third-Party Risk and Sanctions: Screening, Diligence, and Enforcement September 30, 2026, 12 Noon EST Sign Up HERE ___________________________________________________________________________ Building an Effective Ethics and Compliance Program in the Age of AI October 14, 2026, 12 Noon EST Sign Up HERE ____________________________________________________________________________ Join Michael Volkov for Two Important Webinars: Third-Party Risk and Sanctions: Screening, Diligence and Enforcement: Sanctions enforcement is accelerating, and the U.S. and its allies are...

Caremark in 2026, Part 2: Boeing Supplies the Counterweight, and the Framework for Compliance Officers

Part 1 of this series looked at what the Teligent and Regions Financial cases teach about escalation and response under Delaware’s Caremark doctrine. In Part 2, we turn to the most significant recent Caremark development, the 2026 Boeing dismissal, and what the emerging doctrine means in practice for compliance officers building or defending an oversight program. Boeing 2026: The Counterweight to Caremark’s Expansion The most...

Caremark in 2026, Part 1: What Teligent and Regions Financial Teach About Escalation and Response

Delaware courts have spent the last several years wrestling with one of the hardest questions in corporate governance law: at what point does a board’s failure to prevent corporate misconduct stop being ordinary bad management and start being an actual breach of the fiduciary duty of loyalty? That question sits at the center of Caremark doctrine, and a run of recent decisions, involving Teligent, Regions...

OFAC’s $1.4 Million Penalty Against a US Consultant: Why “I Just Give Advice” Doesn’t Work as an Iran Sanctions Defense

OFAC fined an unnamed U.S. consultant just over $1.4 million for Iran sanctions violations tied to advisory work provided to a leading Iranian software company, and this case deserves careful attention because it demolishes a defense I still hear surprisingly often: the idea that providing remote advice, strategic guidance, or consulting services to an Iranian business, without physically operating in Iran or directly running the...

Honeywell Aerospace’s $2 Million Cybersecurity Settlement: The False Claims Act Keeps Finding NIST 800-171 Gaps

The Justice Department announced a settlement with Honeywell Aerospace requiring the company to pay $2,042,518 to resolve allegations that it violated the False Claims Act by failing to meet cybersecurity requirements built into a Department of Defense contract. This case adds to a growing body of enforcement actions confirming that DOJ’s Civil Cyber-Fraud Initiative is not slowing down, and it’s a useful reminder that cybersecurity...

Can You Get Off the SDN List?

Has OFAC branded your company with the scarlet letter? Getting removed from the SDN list is possible, but it’s not fast, it’s not easy, and it’s not guaranteed. The primary path is a petition for administrative reconsideration filed with OFAC, arguing mistaken identity, changed circumstances, or that the original factual basis was simply wrong.You must prove it with real documented evidence. OFAC is skeptical of...

Episode 448: Caremark in 2026 — Where Delaware Draws the Line Between Bad Judgment and Bad Faith

In this episode of Corruption, Crime and Compliance, Michael Volkov examines how Delaware’s Caremark doctrine has matured through a recent run of decisions involving Teligent, Regions Financial, and Boeing, all centered on the question of when a board’s failure to prevent corporate misconduct crosses from ordinary mismanagement into an actual breach of the duty of loyalty. He walks through Teligent’s officer-level oversight failures in FDA...

KPMG’s 2026 CCO Survey: Operational Resilience Is Now the Job, Not a Side Project

KPMG just released its 2026 Global Chief Ethics and Compliance Officer Survey, drawing on responses from 725 CCOs, and the framing KPMG chose for the report tells you most of what you need to know before you even get to the data: “Feeling the pressure: A new reality for compliance leaders.” That’s not marketing language. It reflects a genuine shift in what the compliance function...

The UK’s $6.4 Million Citibank Penalty: What Operational Sanctions Failures Actually Look Like Inside a Major Bank

The UK’s Office of Financial Sanctions Implementation fined Citibank’s London branch roughly 4.7 million pounds, about $6.4 million, for violating Russia sanctions, and this case deserves close attention from every financial institution compliance team, not because the violations were exotic or novel, but because they weren’t. This is a case study in ordinary operational failure at scale: screening systems that missed a name variant, alert...