Category: General

Modifying Vendor Contracts for AI Risk (Part I of II)

Every organization that’s adopted AI tools over the past few years has also, whether it realized it or not, been signing a new category of vendor contract, one that carries risks your standard software or services agreement template was never built to address. This is Part 1 of a two-part series on modifying vendor contracts to build in real protections against AI risk. Here, we...

Caremark in 2026, Part 2: Boeing Supplies the Counterweight, and the Framework for Compliance Officers

Part 1 of this series looked at what the Teligent and Regions Financial cases teach about escalation and response under Delaware’s Caremark doctrine. In Part 2, we turn to the most significant recent Caremark development, the 2026 Boeing dismissal, and what the emerging doctrine means in practice for compliance officers building or defending an oversight program. Boeing 2026: The Counterweight to Caremark’s Expansion The most...

Caremark in 2026, Part 1: What Teligent and Regions Financial Teach About Escalation and Response

Delaware courts have spent the last several years wrestling with one of the hardest questions in corporate governance law: at what point does a board’s failure to prevent corporate misconduct stop being ordinary bad management and start being an actual breach of the fiduciary duty of loyalty? That question sits at the center of Caremark doctrine, and a run of recent decisions, involving Teligent, Regions...

OFAC’s $1.4 Million Penalty Against a US Consultant: Why “I Just Give Advice” Doesn’t Work as an Iran Sanctions Defense

OFAC fined an unnamed U.S. consultant just over $1.4 million for Iran sanctions violations tied to advisory work provided to a leading Iranian software company, and this case deserves careful attention because it demolishes a defense I still hear surprisingly often: the idea that providing remote advice, strategic guidance, or consulting services to an Iranian business, without physically operating in Iran or directly running the...

Honeywell Aerospace’s $2 Million Cybersecurity Settlement: The False Claims Act Keeps Finding NIST 800-171 Gaps

The Justice Department announced a settlement with Honeywell Aerospace requiring the company to pay $2,042,518 to resolve allegations that it violated the False Claims Act by failing to meet cybersecurity requirements built into a Department of Defense contract. This case adds to a growing body of enforcement actions confirming that DOJ’s Civil Cyber-Fraud Initiative is not slowing down, and it’s a useful reminder that cybersecurity...

KPMG’s 2026 CCO Survey: Operational Resilience Is Now the Job, Not a Side Project

KPMG just released its 2026 Global Chief Ethics and Compliance Officer Survey, drawing on responses from 725 CCOs, and the framing KPMG chose for the report tells you most of what you need to know before you even get to the data: “Feeling the pressure: A new reality for compliance leaders.” That’s not marketing language. It reflects a genuine shift in what the compliance function...

The UK’s $6.4 Million Citibank Penalty: What Operational Sanctions Failures Actually Look Like Inside a Major Bank

The UK’s Office of Financial Sanctions Implementation fined Citibank’s London branch roughly 4.7 million pounds, about $6.4 million, for violating Russia sanctions, and this case deserves close attention from every financial institution compliance team, not because the violations were exotic or novel, but because they weren’t. This is a case study in ordinary operational failure at scale: screening systems that missed a name variant, alert...

A Federal Judge Just Told DOJ It Can’t Simply Walk Away From the Adani Case

U.S. District Judge Nicholas Garaufis has rejected the Justice Department’s request to drop the remaining bribery and obstruction of justice charges against executives connected to Indian billionaire Gautam Adani’s conglomerate, and this ruling deserves attention well beyond the Adani matter itself. It’s a rare and pointed example of a federal court refusing to simply accept a prosecutor’s word that dismissal is warranted, and it raises...

BAE ITAR Settlement — Part 2: Root Causes and the Real Lessons for Export Compliance

Part 1 of this series walked through the settlement terms and the sheer range of violations DDTC documented against BAE Systems, spanning unlicensed technical data exports, unauthorized defense services, agreement mismanagement, and documentation failures. In Part 2, we focus on what actually caused all of this, because DDTC’s charging letter is unusually candid about root causes, and those root causes are far more instructive than...

Why Every Organization Needs an AI Acceptable Use Policy Now, Part 1: The Risk Landscape

If your organization does not yet have a written AI Acceptable Use Policy, I can tell you exactly what is happening inside your walls right now: employees are already using AI tools, whether you have authorized it or not. They are pasting documents into chatbots to summarize them, asking generative AI to draft correspondence, running research queries, and increasingly relying on AI features quietly embedded...