An Approved AI Tool Is Not an Approved AI Use

By |2026-09-01T15:17:00-06:00July 14th, 2026|AI, AI Ethics, AI Ethics and Risks, Compliance Blog, Data Privacy, Protecting Confidential Information, Todd's Blog|

Xcelus · Responsible AI & Governance An Approved AI Tool Is Not an Approved AI Use Your security review cleared the technology. It wasn’t clear what your people are putting into it. Quick answer: Approving an AI tool clears the technology. It does not automatically approve every data type, business purpose, or workflow that the tool is used for. Most organizations have published an approved software list and nothing else — so employees reasonably conclude that if the tool [...]

Comments Off on An Approved AI Tool Is Not an Approved AI Use

The $81,000 AI Bill and the Missing Guardrail: Who Owns AI Spend?

By |2026-07-04T14:11:34-06:00July 4th, 2026|AI Ethics and Risks, Compliance Blog, GRC|

Responsible AI · Leadership & Governance The $81,000 AI Bill Wasn’t the Real Problem. The Missing Guardrail Was. When you tell everyone to “go use AI” and set no limits, the overspend isn’t a discipline problem. It’s a governance gap — and it belongs to leadership. The Short Answer Who is responsible when an employee runs up a huge AI bill? Responsibility is shared, but the primary failure is usually structural, not personal. When leadership enables an uncapped AI [...]

Comments Off on The $81,000 AI Bill and the Missing Guardrail: Who Owns AI Spend?

Why Good Companies Miss the Chance at a DOJ Declination

By |2026-06-30T17:00:32-06:00June 30th, 2026|Compliance Blog, Todd's Blog|

What is the biggest reason companies miss the chance at a DOJ declination? It is almost never a decision not to disclose, and it is rarely ignorance of the law. The most common reason a company loses the chance at a declination is internal speed: the report surfaces somewhere in the organization and then moves too slowly — stalling in an escalation chain, waiting on “one more fact” — so that by the time decision-makers can act, the window [...]

Comments Off on Why Good Companies Miss the Chance at a DOJ Declination

Is the FCPA Still Being Enforced in 2026? What It Means for Training

By |2026-06-25T10:21:54-06:00June 25th, 2026|Compliance Blog|

Is the FCPA Still Being Enforced in 2026? What It Means for Training Is the FCPA still being enforced in 2026? Yes. Enforcement of the Foreign Corrupt Practices Act was paused by executive order in February 2025, then resumed in June 2025 under new Department of Justice guidelines that narrowed its focus toward cases tied to US national security and economic competitiveness, cartels, state-owned enterprises, and large-scale or concealed bribery. The law itself did not change, and prosecutions have [...]

Comments Off on Is the FCPA Still Being Enforced in 2026? What It Means for Training

Reorganize, or Make Better Decisions?

By |2026-06-15T10:56:41-06:00June 15th, 2026|Compliance Blog, Todd's Blog|

Reorganize, or Make Better Decisions? The Variable Most Cross-Functional Failures Miss By Todd Corbett, Xcelus When something goes wrong across departments — a data breach that also involved employee misconduct, a harassment complaint that also created exposure to retaliation — the instinct at the top is almost always the same. Redraw the org chart. Add an escalation policy. Stand up a committee. Clarify who reports to whom. Those responses are legitimate. Sometimes, the structure really is broken and needs [...]

Comments Off on Reorganize, or Make Better Decisions?

Cybersecurity Runs Tabletop Exercises. Why Doesn’t Compliance?

By |2026-06-17T08:14:26-06:00June 9th, 2026|Compliance Blog, Todd's Blog|

Xcelus Blog — Compliance Leadership Cybersecurity Runs Tabletop Exercises. Why Doesn't Compliance? By the Xcelus Editorial Team Editor's Note The opening scenario below is the basis for one of our Executive Decision Lab™ kits, The Invisible Insider — a 90-minute facilitated session designed for public company leadership teams who want to practice these conversations before an incident forces them. Imagine your organization discovers that a vendor employee accessed confidential FDA approval information and shared it with a family member [...]

Comments Off on Cybersecurity Runs Tabletop Exercises. Why Doesn’t Compliance?

What Four Senior Leaders Wish Every Employee Knew (And Why Training Rarely Tells Them)

By |2026-05-30T16:06:37-06:00May 30th, 2026|Compliance Blog, Culture of Compliance|

What Four Senior Leaders Wish Every Employee Knew (And Why Training Rarely Tells Them) Here's a thought experiment I've been sitting with lately. Ask a Chief Compliance Officer, an HR leader, a VP of Security Awareness, and a VP of AI Readiness the same question—what do you wish every employee actually knew?—and you'll get four different lists. Different priorities, different language, different fears. But if you read all four answers carefully, one thread runs through all of them. It's [...]

Comments Off on What Four Senior Leaders Wish Every Employee Knew (And Why Training Rarely Tells Them)

Is Your Compliance Training Program Designed for an Audit — or for Behavior Change?

By |2026-05-05T13:40:15-06:00April 17th, 2026|Compliance Blog, Scenario-based Compliance Training|

Is Your Compliance Training Program Designed for an Audit — or for Behavior Change? The Real Test of Compliance Training An employee is under pressure to close a deal before the quarter's end.A vendor relationship feels routine, but something is slightly off.The rules were covered in training. But in that moment, the question isn’t:“Do I remember the policy?” It’s:“Is this okay… or not?” This is where compliance programs are actually tested.Not during training. Not during an audit. But in [...]

Comments Off on Is Your Compliance Training Program Designed for an Audit — or for Behavior Change?

Where Is My Company’s Code of Conduct? Why the Better Question Is Whether Your Employees Need to Find It.

By |2026-04-16T10:53:55-06:00April 16th, 2026|Blog/News, Compliance Blog, Scenario-based Compliance Training|

Where Is My Company’s Code of Conduct? Why the Better Question Is Whether Employees Need to Find It Most employees don’t know where their company’s Code of Conduct is. That’s not just a usability issue. It’s a signal that the compliance program may not be designed for the moments when employees actually need it. You completed your annual compliance training in February. You clicked through the Code of Conduct course, passed the knowledge check, and signed the acknowledgment form. [...]

Comments Off on Where Is My Company’s Code of Conduct? Why the Better Question Is Whether Your Employees Need to Find It.

One Code of Conduct, Two Training Programs: Why Field Employees Need Different Scenarios Than Office Employees

By |2026-04-06T15:49:59-06:00April 6th, 2026|Compliance Blog|

One Code of Conduct, Two Training Programs: Why Field Employees Need Different Scenarios Than Office Employees Every organization with a Code of Conduct wants the same thing: employees who recognize compliance risks and know what to do when they encounter one. The Code of Conduct applies to everyone. The training that makes it effective isn't. For organizations with both office and field workforces — manufacturers, energy companies, construction firms, logistics operations, mining companies — a single compliance training program [...]

Comments Off on One Code of Conduct, Two Training Programs: Why Field Employees Need Different Scenarios Than Office Employees
Go to Top