Partnering Between Compliance and Legal for Organizational Resilience
Host Nick Gallo sat down with Rebecca Rehm, Compliance Officer at Olympus Corporation, and Elizabeth "Beth" Frey Miller, a veteran in-house legal leader, to explore how compliance and legal can partner for organizational resilience. This recap covers every major theme: where the disconnect between the two functions really comes from, why the "legal owns legal risk, compliance owns conduct risk" divide doesn't hold up, playing to your strengths instead of your title, aligning on risk appetite for new initiatives, avoiding internal forum shopping, whether compliance needs to speak legal, vetting an organization's risk tolerance before taking a job, and practical first steps for building the kind of trusted relationship that lets both functions present a united front to the business.
Download Ethico's 2026 Benchmark Report
Latest data on case closure, substantiation rates, issue types, and more...
Joah Park
Brand Manager & Media Producer, Lead Producer for The Ethicsverse

Compliance and legal both own pieces of organizational risk, yet the two functions often speak different languages, answer the same question differently, and quietly compete for the same seat at the table. In this Ethicsverse session, host Nick Gallo, Chief Servant & Co-CEO of Ethico, sat down with Rebecca Rehm, Compliance Officer at Olympus Corporation, and Elizabeth "Beth" Frey Miller, a veteran in-house legal leader who worked alongside Rebecca for four years, to talk through what actually makes this relationship work.
Rather than treat the disconnect as inevitable, Rebecca and Beth framed the conversation around connection: what it looks like when compliance and legal genuinely partner, where the friction tends to originate, and how a foundation of trust, humility, and mutual respect for each function's specialization turns two departments into one strategic front for the business. What follows are the key takeaways.
Key Takeaways
Where the Disconnect Really Comes From
Rebecca framed the issue not as an inherent disconnect but as a lack of partnering: a lack of communication and a lack of appreciation for what each function offers. When you recognize the value your counterpart brings, you make the effort to build the relationship that lets you become a dynamic, strategic partner to the business.
Beth traced the root cause to time and effort. Disconnect happens when nobody invests in building community across the silo line. It starts with finding a common vernacular and understanding the language of the people you work with, because the modern in-house lawyer's job, in any function, is to be a strategic business partner, not simply an arbiter of legal risk.
Nick noted that compliance historically spun out of legal in many organizations, which helps explain why the tension can feel structural even when it is really just a failure to build the relationship intentionally.
The Clean Division Between Legal Risk and Conduct Risk Doesn't Hold Up
It's tempting to say legal owns legal risk and compliance owns conduct risk, but both speakers pushed back hard on that framing. Rebecca pointed out that there is no easy separation between compliance and legal responsibilities. There's a lot of overlap, and contracts, for example, also define behavior.
The disconnect in interpretation, Rebecca explained, often comes down to where each function starts. Compliance looks first to policy: what does the policy say the business can or can't do? Legal looks first to law and case law, including recent developments the policy may not yet reflect. A compliance officer who drives only from what the policy says can miss what legal is seeing in more recent interpretations.
Beth added that policy can look rigid but is actually dynamic, and the world, the business, and risk assessments change faster than policy sometimes does. When someone flags that regulatory thinking has shifted, if that conversation isn't handled strategically, people feel like their toes are being stepped on, especially when the compliance officer isn't an attorney. Honoring that role, JD or not, is essential.
Beth's advice: the delineation between the two functions is something you work out together, then communicate clearly to the business, leveraging each other's strengths rather than duplicating effort. The goal is to look cohesive with independent vision, working toward the same objective, not to be pressure-played against each other.
Play to Your Strengths, Not Your Title
Rebecca was direct about not competing with her legal colleagues on legal knowledge, that isn't her area of training. Her strength is behavioral science and understanding how to change behavior, which most lawyers, on average, haven't studied. Leaning into that difference, rather than trying to match legal expertise, is where she adds real value.
Demonstrating that value isn't about wearing a "behavioral science expert" badge, Rebecca said. It's about showing the outcome: knowing how to create psychological safety so the business is more likely to speak up about concerns, which reduces risk because the organization actually learns about problems it can address.
Beth agreed that psychological safety was the key insight, and connected it to trust: because sales and other business functions often work with an assumption of distrust from oversight functions, creating a place of safety, and showing genuine concern for how the business actually operates, is what allows real partnership to flourish.
Beth's own transition from trial lawyer to legal ops to general counsel's office was intentional. Moving into legal ops let her understand the business from the inside before returning to a more traditional legal role, which shaped a mindset built around being a strategic business partner rather than simply the arbiter of legal risk.
Trust Is Built Top-Down and Bottom-Up
Rebecca and Beth's own partnership started from a strong foundation: they inherited a legal and compliance relationship operating under a government settlement agreement that made close collaboration a necessity, and built on it with a standing weekly meeting that continued once Beth joined.
Beth credited a leader who valued both functions and gave her the "air cover" to approach the job with humility, explicitly asking Rebecca to get her up to speed on the business quickly rather than asserting legal authority from day one.
That trust had to be established at the institutional level, and then built again on an individual relationship basis. Both speakers stressed that it isn't just knowing your counterpart's function, it's knowing how the business actually operates and demonstrating genuine concern for the people you serve.
Rebecca described actively inviting her legal counterpart into business conversations that compliance could have handled alone, specifically because it showed her legal partner she valued them and showed the business that legal was a genuine partner, not an enforcement mechanism brought in to "catch" anyone.
Aligning on Risk Appetite for New Business Initiatives
The friction point Rebecca sees most often is a new, risk-forward business initiative the company hasn't tried before. Compliance's natural instinct is to look at policy and industry benchmarking, which can be limited, so she wants legal's read on the regulatory and enforcement landscape, while also asking whether the business can realistically operationalize any new guardrails.
Beth framed it as friction between comfort and openness. Once an organization has built reproducible, well-controlled processes, especially coming out of something like a corporate integrity agreement, it's easy to calcify. Staying open to new opportunity means accepting new risk, which requires an honest conversation about the organization's actual risk appetite and every input that feeds it, from the SEC to the FDA to international regulators.
Rebecca's caution: it isn't enough to approve a new initiative and then load it down with fifteen mitigation requirements. That creates a different kind of risk, a business risk, where the burden itself defeats the purpose of the initiative and the controls stop working because nobody actually follows them.
Beth's version of being a good partner isn't "legally, you can do this, now go figure out how." It's asking how she can help the business get to a better future using her own skill set, so she isn't dropping a requirement and walking away.
Avoiding Forum Shopping
Nick asked how often the business tries to play legal and compliance off each other, going to whichever function is likely to say yes. Both speakers said it happens, but rarely with bad intent, more often it's the speed of business and someone reaching whoever is available on chat when a deadline is looming.
Beth's rule: keep disagreements and alignment conversations behind the scenes, before you're in a room with the business, so a united front shows up in the meeting. When forum shopping does happen, the answer is to push back calmly and consistently rather than showing frustration to the person trying it, because staying composed disarms the dynamic and prevents distrust from festering.
Rebecca described how she and Beth would call each other directly when something like this surfaced, rather than letting a secondhand comment breed suspicion, a habit that reinforced the partnership rather than eroding it.
The payoff of staying aligned is bigger than avoiding one bad meeting. Reproducible, consistent answers build enough trust that business partners start applying the guidance themselves without escalating, and the relationship becomes strategic instead of purely tactical, allowing compliance and legal to anticipate what the business wants to do months before it happens.
Do Compliance Officers Need to Speak Legal?
Asked why the expectation usually runs one direction, compliance learning to speak like lawyers, Beth argued that's backwards. It's a lawyer's job to distill legal concepts into everyday language for whoever they're working with. Legalese only serves a very narrow, trained audience, with the occasional term of art that genuinely needs to be preserved.
Rebecca's practical version of speaking the same language is admitting what she doesn't know: openly asking her legal counterparts to explain concepts like privilege in plain terms, because that kind of trust-based question only works inside a relationship built on openness.
Should You Vet an Organization's Risk Tolerance Before Taking a Job?
Responding to an audience question, Rebecca suggested doing what due diligence is realistically available: what a company says about its values, what it does on social media relative to competitors, and what press releases actually reflect. She also drew a useful distinction: a business decision you disagree with and your job are not necessarily the same thing, since compliance is rarely telling people an outright no, more often it's laying out risk and a recommendation.
Beth added that risk tolerance itself shifts, sometimes sharply, after events like a warning letter or a change in leadership, so the more durable thing to calibrate to during an interview process is whether the company's stated values genuinely align with your own, using indirect questions to surface the facts rather than asking directly.
Where to Begin Building the Relationship
Beth's starting point is self-awareness: look internally at what kind of person you are and where you want to grow, then carve out real time, not just texts and DMs, to actually get to know the people you work with as human beings rather than titles.
Rebecca's practical addition: physically stop by the other department's office when you're in person, and ask genuine questions about what your counterpart knows, whether it's a new regulation or a recent piece of guidance. People like sharing their expertise, and asking shows you value it while giving you real insight into how that person is wired.
Closing Thoughts
The throughline of the conversation was that compliance and legal don't need a cleaner org chart to work well together, they need a relationship built on openness, humility, and authenticity. Rebecca and Beth's partnership didn't start with a perfectly defined division of labor; it started with a standing weekly meeting, a willingness to lean on each other's specialization instead of competing over it, and enough trust to pressure-test disagreements privately before presenting a united front to the business. As both speakers made clear, the work of building that trust never fully finishes, but it starts on a human-to-human basis, one conversation at a time.
Enjoyed this article?
Subscribe to our newsletter for more insights on ethics and compliance.
View All Articles