Quarterly Roundup: Self-Disclosure Pays, Export Controls Stumble, and Who Owns AI Governance
In the Q3 2026 Ethicsverse quarterly roundup, Matt Kelly of Radical Compliance and Nick Gallo of Ethico were joined by Karen Moore of Sounding Board Compliance LLC and Mara Senn of Ethakos to analyze the quarter in ethics and compliance: a CEO who personally self-disclosed misconduct and earned a non-prosecution agreement, export control failures rooted in staff turnover, the Los Angeles Clippers' sham endorsement contracts, and the growing AI governance ownership gap.
Download Ethico's 2026 Benchmark Report
Latest data on case closure, substantiation rates, issue types, and more...
Joah Park
Lead Producer for The Ethicsverse

Every quarter, The Ethicsverse takes a step back from single-topic deep dives to look at what actually happened in the world of ethics and compliance. For the Q3 2026 edition, host Matt Kelly, Editor and CEO of Radical Compliance, was joined by Nick Gallo, Chief Servant and Co-CEO of Ethico, along with guest analysts Karen Moore, Principal, Sounding Board Compliance LLC, and Mara Senn, Founder & CEO, Ethakos, and a former senior compliance executive at GE Healthcare, Zimmer Biomet, and the World Bank.
The panel worked through a quarter of contrasts: companies rewarded for doing the right thing, large organizations still stumbling on export controls, a professional sports franchise caught running sham contracts, and an AI governance problem that no one yet knows how to own. Here are the key takeaways.
Key Takeaways
Self-Disclosure Is Earning Real Credit
The U.S. subsidiary of Italian pharmaceutical company Dompé was caught conditioning its donations to patient assistance programs on receiving data about which patients were using its products, a violation of the Anti-Kickback Statute and the False Claims Act.
What stood out was the response: the CEO of the Italian parent personally called the U.S. Attorney to self-disclose. The company paid roughly $32 million in restitution but received a non-prosecution agreement, with no guilty plea.
Moore called it a success story for the compliance function. The CEO did not dump the problem on compliance; he credited routine monitoring and auditing for surfacing it. As she put it, the question is never whether something goes wrong, but when you find it, how you find it, and what you do about it.
Senn noted that executives rarely self-report personally because it is risky: the DOJ values hearing the unfiltered story, but a stray comment can expand the scope of an investigation. That kind of scope creep is the real danger, so a company needs to have its arms around a narrow, well-understood issue first.
Gallo pointed out that for the CEO to make that call at all, the information had to reach him, which is itself proof that the internal reporting system worked. That gesture will likely pay off in multiples in the company's ethical culture.
A Florida liquor distributor offered a second example. After self-disclosing employee misconduct with suppliers and retailers, it elevated its general counsel to chief legal and compliance officer, doubled its compliance budget and staff, and settled for a non-prosecution agreement with about $12 million in restitution.
Chief compliance officer certifications are still alive. In that settlement, the CCO and CEO must jointly certify the effectiveness of the program at the end of the two-year term.
Why Aren't Programs Built Before the Crisis?
Gallo compared the DOJ's approach to NASA's Aviation Safety Reporting System, where limited liability protection for self-reporters produced a massive database of near misses. Enough of these cases have now accumulated to show that the DOJ's promised incentive is real.
Moore raised the frustrating pattern behind these outcomes: companies rush to build strong programs, identify risks, and close the loop only after misconduct surfaces. Assessing risk and matching it against the program should happen much earlier.
Senn was candid about the reality: money follows fear. Tight budgets mean compliance investment tends to rise only when enforcement pressure does, and having worked both inside and opposite the DOJ, she would still counsel caution before self-disclosing anything the government was unlikely to find on its own.
Export Controls Keep Tripping Up Large Companies
The U.S. subsidiary of a major British defense contractor was fined $36 million by the State Department for exporting sensitive technical data, including GPS schematics sent to a manufacturing partner in China and data shared with allies such as Canada, Britain, and Italy without proper licenses.
Other failures included a subcontractor wrongly assuming the prime contractor's license covered it, and a license that lapsed because no one was watching it. It follows last quarter's Bosch case, where a similar gap came from gross understaffing.
Senn explained why trade compliance is so hard: it is deeply operational. Violations happen on the loading dock, such as picking the wrong item off a pallet, and classification at the front end is complex. Trade compliance teams need practical people who work directly with shipping and manufacturing.
Her advice is to risk-rank: identify the few products with the highest export risk, keep the tightest controls there, and scale resources down from that point.
Moore added that trade and sanctions risk has climbed the same way data privacy did. Organizations cannot rest on an old risk profile; they must continuously reexamine their operations, the regulatory environment, and geopolitics.
Turnover Is a Compliance Root Cause
The company's own root cause analysis cited personnel turnover in leadership, which created confusion about who was authorized to grant which permissions. Kelly said he had rarely seen staff attrition named as a root cause of a compliance failure.
Moore's message: if you are struggling to find experts, at least manage to keep them. When people leave, knowledge walks out the door, and misconduct occurs in the cracks. Policy, training, and a control on paper will not substitute for expertise and decision support at the point of the transaction.
An audience member noted that employees turn to their leader first when they have a question. With leader turnover, everyone ends up turning to each other and asking what to do.
Gallo framed it as a Jevons squeeze: a flat-headcount team juggling a roughly fivefold expansion in export rules and tariff complexity, leading to burnout, attrition, and the loss of tacit knowledge that can take nine months for a replacement to rebuild.
The fix is advocacy. The penalty worked out to roughly $350,000 per violation, and would have been significantly higher without an $18 million reduction. Numbers like that are the path of persuasion for getting leadership to fund the team before a crisis.
The Clippers and the Sham Contract Playbook
The NBA found that the Los Angeles Clippers arranged sham endorsement deals for star Kawhi Leonard through business partners, who then received more business from the team, a way around the salary cap. Penalties included a $30 million fine, the loss of five first-round draft picks, a one-year suspension for owner Steve Ballmer, suspensions for senior executives, and five years of compliance supervision.
Moore noted that if you strip away the basketball, the red flags are familiar to any compliance officer: third parties, side arrangements, unusual contracts, and benefits flowing indirectly. Simple contract analytics looking at connected transactions, duplicate counterparties, and payments without demonstrable deliverables should have surfaced it. Each contract may look plausible alone; the problem only appears when they are connected.
Senn stressed that safeguards fail when the owner is in on the deal. She also argued that compliance should have more visibility into fake vendors and purchase orders, an area usually left to finance, which does not look at it through a compliance lens.
Gallo invoked Goodhart's Law: when a measure becomes a target, it ceases to be a good measure. A hard limit like a salary cap creates side-door markets, so compliance teams should anticipate how people might route around firm rules.
The misconduct followed a 2019 NBA settlement over prior dealings with the same player, after which Ballmer publicly pledged to run a compliant operation. The case was surfaced by a reporter, not internally, raising the question of whether it was ever safe to speak up, and where the independence of the compliance function lies when you cannot challenge the owner.
AI Governance Has an Ownership Problem
Kelly cited a European survey of roughly 1,000 executives: 70% said they know their AI systems are touching confidential data but lack visibility into how, and two-thirds said their teams cannot keep pace with the number of AI agents employees are creating.
Without an inventory, companies cannot enforce the human oversight and accountability required by the EU AI Act and New York's cybersecurity rule for financial firms.
Moore described fractured ownership: technology understands the model, the business understands the use case, security understands the threat, and legal and compliance understand the regulatory exposure. When it is everybody's job, it becomes nobody's job.
As AI moves from a tool that gives answers to an agent that takes actions, governance must scale with the degree of autonomy. In Moore's words, the question is not who owns the AI, but who owns the decisions the AI is making.
Senn recommended an approval procedure before agents are let loose on company data: experiment in a sandbox, then vet and publish a library of tested agents with known capabilities and limitations. She also flagged a new risk for platforms whose customers now require them to allow outside agents in.
Gallo noted that unlike postwar nuclear nonproliferation, AI capability sits in the private sector with strong profit motives, compounding pressure at the company level to move faster than the risks are understood. The best framework he has seen pushes governance down to the employee level.
Kelly closed the topic with a reported case of AI agents accessing an Australian national health system's confidential data without being told to, asking who gets held accountable when no human gave the instruction. Criminal liability may be hard to assign, but product liability is waiting around the corner.
Closing Thoughts
The quarter's headlines pointed in a consistent direction. Regulators are rewarding companies that find problems, surface them quickly, and invest in fixing them. The failures, whether in export controls, a sports front office, or ungoverned AI agents, trace back to the same gaps: understaffed teams, lost institutional knowledge, compromised independence, and unclear ownership. For compliance leaders, the practical lesson is to use cases like these to make the business case for resources before the next crisis, not after.
Enjoyed this article?
Subscribe to our newsletter for more insights on ethics and compliance.
View All Articles

