Ethico
Webinars2026-08-06T14:00:00.000Z11 min read

EV MBA: Engaging Operations, Supply Chain, and Tech Teams

The fifth installment of the Ethicsverse MBA series turns to the machine behind the brand — operations, supply chain, and technology. Host Nick Gallo argues that most business risk lives in the back office where the boots are on the ground, and shows how compliance can map supply chain tiers, build fluency with the tech stack and data governance, ask the right questions of a CTO, and use an operational risk heat map to reach every process in the enterprise. Anchored by the Boeing 737 MAX and Rana Plaza case studies, this recap covers the full session.

Joah Park

Brand Manager & Media Producer, Lead Producer for The Ethicsverse

Share
EV MBA: Engaging Operations, Supply Chain, and Tech Teams

How many suppliers does your company have? Now, how many of their suppliers can you name? That second number is your supply chain visibility — and it is exactly where the risk that ends up in the headlines tends to live.

This session of the Ethicsverse MBA series continues host Nick Gallo's mission to help compliance professionals speak the language of business and show up as a business person first and a specialist second. Where earlier installments covered understanding the business, the financial language of the CFO, connecting compliance to strategy, and the sales-and-marketing revenue engine, this fifth session turns to the machine behind the brand: operations, supply chain, and technology — the parts of the business you don't see day to day unless you go looking for them. The core argument is that most compliance programs are built around the front office, around people in suits working in offices, while the majority of business risk actually lives in the back office, out where the boots are on the ground. The discussion walks through the physical reality of operations, the layered and opaque nature of modern supply chains, the tech stack and data governance a compliance officer needs enough fluency to question, and the emerging risk surface of AI. It grounds all of this in two hard case studies — the Boeing 737 MAX and the Rana Plaza factory collapse — before closing with practical tools: a set of questions to ask your CTO, an operational risk heat map, and a mindset shift from compliance that stops at the office door to compliance as the circulatory system that touches every organ of the business.

Key Takeaways

Most Business Risk Lives in the Back Office

  • Compliance programs are typically designed around the front office — the visible, surface-level work of people in offices — yet in most industries the majority of employees are actually doing physical work: on the shop floor in a manufacturer, in the wards of a hospital system, in warehouses and call centers.

  • Regulatory violations happen on the floor, not in the boardroom. It is rarely a director laundering money or paying a bribe; it is the salesperson in another country trying to hit quota, and environmental compliance is almost entirely operational.

  • If your program only covers the people in suits, you are likely missing roughly 80% of the risk. Operational shortcuts always create risk — safety, quality, brand, and bottom-line risk — because every department has its own OKRs and pressures that trickle downhill.

  • Compliance is one of the few functions that acts as connective tissue across every department, which is both a burden and an opportunity to make better bets with limited time.

Supply Chain Visibility Falls Off a Cliff After Tier One

  • Supply chains break into tiers: tier one is your direct suppliers, tier two is your suppliers' suppliers, and tier three is the deep supply chain you effectively cannot see. Visibility does not decline linearly — it falls off a cliff after tier one.

  • An estimated 60% of supply chain risk lives beyond that first tier, in the tier-two and tier-three relationships where you have limited leverage. You can push a major supplier for audits and terms when you are a big customer; that power evaporates deeper in the chain.

  • COVID and the more recent wave of tariffs both laid bare how fragile and international modern supply chains have become, exposing vulnerabilities most organizations never had to think about before.

  • A growing body of regulation now gives these risks teeth — the Uyghur Forced Labor Prevention Act, the German Supply Chain Due Diligence Act, the EU Corporate Sustainability Due Diligence Directive, conflict minerals rules under Dodd-Frank, and modern slavery acts. These laws broadly require five things: map your supply chain, identify human rights and environmental risks, implement preventative measures you can show receipts for, establish a grievance mechanism, and report on your due diligence findings.

  • Five years ago supply chain compliance meant checking a box. Today it means mapping the supply chain — at least on a materiality basis — or risking enforcement and getting caught out when the tide goes out and a disruption hits.

You Need Enough Tech and Data Fluency to Ask Good Questions

  • Every business process runs on technology, and the fluency required only increases as AI spreads. You do not need to code or read binary to have an intelligent, risk-focused conversation with an expert — your job is to bring the risk lens, focus on business impact, and collaborate adult-to-adult.

  • A simplified tech stack has five layers: infrastructure (servers, cloud, networks), platforms (databases, middleware, APIs), applications (the software users touch, often dozens or hundreds of them), data (the information stored and processed), and security (the protections at every layer).

  • Technology expands the attack surface: data breaches are compliance events with reporting requirements, cloud migrations change the risk profile, API integrations open many new doorways into the "city walls," and shadow IT is a persistent blind spot.

  • Data is simultaneously the company's most valuable asset and its biggest liability. Data governance essentials include classification, mapping (where does the data actually live — laptops, phones, the secure network?), retention policies, access controls, and deletion capabilities. Most organizations struggle with over-retention rather than under-retention, because deleting is a decision and humans default to keeping things — especially as storage gets cheap.

AI Governance Starts With Knowing How AI Is Actually Used

  • You no longer need to know how to code — technology has been dramatically democratized — but you do need to know how AI is being used across your organization. Building a register of AI use cases gives you a starting point for where risk might live.

  • Know which decisions AI is making and which it is influencing, and ensure human oversight at the high-impact decision points. A salesperson using AI is worried about quota, not data privacy.

  • Useful questions for any AI system in use: What is it trained on? What decisions does it make or influence? Who is affected? Do we test for bias? What happens when something goes wrong and who is accountable? Can we explain its decisions? Do we have human override?

  • Don't wait for regulation to act. AI rules will likely follow the patchwork path privacy took — state-level rules plus broader EU frameworks — but you can apply your own judgment to curtail risk now, the same way you'd secure a passenger before any law required a seatbelt.

Case Study — The Boeing 737 MAX

  • Racing to compete with Airbus and losing orders, Boeing chose to re-engineer the 737 rather than design a new plane. To address aerodynamic issues it added MCAS, a software system that could automatically push the nose down based on a single sensor input with no redundancy.

  • Boeing minimized the significance of MCAS to the FAA and airlines to avoid triggering costly pilot retraining, while the FAA was simultaneously delegating more safety self-certification back to manufacturers and did not catch the decisions. Two crashes killed 346 people.

  • The lessons: operational pressure is the most dangerous compliance risk because that's when people cut corners; self-certification creates a moral hazard (you weren't allowed to grade your own tests in school for a reason); cost optimization and safety are in constant tension; and compliance independence matters most when there is money on the line.

  • The pattern rhymes with Wells Fargo and Volkswagen — the people closest to the risk were under the most pressure to ignore it. There is rarely a villain twisting his mustache in the boardroom, which is precisely why an independent compliance voice must be heard.

Case Study — Rana Plaza

  • In 2013 an illegally constructed factory building expanded to eight floors on an unstable, unpermitted foundation collapsed in Bangladesh, killing 1,134 garment workers. Cracks had appeared in the walls the day before; workers were told to go back in anyway.

  • The brands sourcing from the five factories packed into that building had never audited the building itself — a stark illustration of how much risk hides in the second tier of suppliers when companies buy on price and fly blind.

  • Takeaways: ethical audits and financial or safety audits are not the same thing; sub-tier subcontracting can hide risks headquarters never sees while it celebrates saving 20% on inputs; and local pressure to keep production running can override safety warnings. Everyone saw the cracks — no one with the power to stop production did.

  • The point is not that compliance officers must personally inspect every building, but that materiality-based diligence should reach beyond tier one, and that new tooling now makes it possible to go deeper and uncover more risk without a proportional increase in effort on a team whose scope has grown far faster than its headcount.

Build the Technology Relationship and Ask the Right Questions

  • The relationship with your technology leader should be one of your strongest, because so much risk lives in the tech stack. You don't have to understand every cord and server room to have an intelligent, risk-mitigating conversation.

  • Five questions to ask your CTO on an ongoing basis: What are your biggest technology risks right now? Where does our most sensitive data live? What AI/ML systems are we deploying? How do we manage third-party software risk? What keeps you up at night from a security perspective?

  • Sometimes ask questions you already know the answer to — investigators do this — because how a leader talks about a risk (flippantly or seriously) tells you where they really stand and how much you can rely on them to execute your program.

  • Focus on business impact over technical detail, ask people to explain things "like I'm sixteen" without insecurity, request architecture diagrams (even sketched on a napkin), and collaborate on governance frameworks rather than imposing them — the HBR article Fair Process explains why buy-in beats mandate in knowledge work.

Map Operational Risk and Get Out of the Office

  • Beyond the annual, high-level risk assessment, build an operational risk heat map — even one just for yourself in a notebook or spreadsheet — mapping compliance and operational risks across the entire value chain from procurement to production to distribution to customer service, then scoring each by likelihood and impact.

  • The exercise forces the materiality lens, surfaces gaps in current coverage, and helps prioritize the next quarter's workplan by regulatory or business-impact exposure. Like the blind men and the elephant, compliance is one of the few functions positioned to assemble the whole animal from the pieces each department sees.

  • Practical steps: walk the floor and visit operations as often as you can, interview operational leaders in informal conversations (lean on your investigative skills to build relationships, not interrogations), review incident and near-miss data, track regulatory trends, and map technology dependencies.

  • The mindset shift is from legacy compliance that stops at the office door and lives in binders and unvisited SharePoint sites, to compliance as the circulatory system that touches every organ: every process, every supplier, every system, and anywhere money flows.

  • This week's homework: get out of the office — visit a warehouse, manufacturing floor, data center, or call center; talk to frontline people; and ask what compliance looks like from their perspective. You'll find processes you didn't know existed, risks that never appeared on your assessment, and high-conscientiousness allies across the business. The future of the profession is wide open, and it's on you to solve for outcomes.

The best compliance programs don't just reach the boardroom — they reach the factory floor, the warehouses, the data centers, the salespeople across borders, and into the code repository. If your program doesn't yet, that's not a problem; it's an opportunity to broaden your impact.

Enjoyed this article?

Subscribe to our newsletter for more insights on ethics and compliance.

View All Articles