<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[Compliance Chronicles with Liisa Thomas]]></title><description><![CDATA[<p>Working in privacy or compliance today means doing organizational change in an AI‑driven world, often without a playbook. Compliance Chronicles brings you lessons with leaders who have navigated that reality, using a simple structure in every episode: their career journey, the challenges they faced, the lessons they took away, and the advice they have for you.</p><p></p><p>Compliance Chronicles is a practical, conversation‑driven podcast for privacy, cyber, and compliance professionals who are being asked to “figure out” AI, data protection, and regulatory change while still handling their day‑to‑day work. Liisa’s practice focuses on helping companies design and mature AI and privacy governance programs, and this show reflects the real questions clients bring into that work.</p><p></p><p>Hosted by law firm partner and adjunct professor Liisa Thomas, the show is designed for CLOs, CPOs, CISOs, CCOs and their teams who need to create workable solutions to tricky AI, privacy, and cyber compliance problems. In her conversations with leaders across the industry, Liisa draws on her legal and organizational change experience helping companies build privacy and AI governance to ask the questions you wish you could have, and to surface patterns you can reuse with your own teams.</p><p></p><p>In each episode, Liisa interviews leaders in the industry who share their career journey, the challenges they have faced and lessons they learned along the way, and their parting advice for others walking a similar path. Guests talk openly about moving skeptical businesses, working with boards and regulators, and operationalizing privacy, cyber, and AI governance in complex, fast‑moving environments.</p><p></p><p>Whether you are new to privacy or a seasoned CPO, you will hear relatable stories, hard‑won lessons, and human‑centered strategies you can apply in your own organization. If you’re wrestling with AI, privacy and cyber governance in your own organization, you will also hear how Liisa approaches these issues in her work with clients.</p><p></p><p>You can find all episodes at <a rel="noopener noreferrer nofollow" href="https://www.compliance-chronicles.com" target="_blank">https://www.compliance-chronicles.com</a>.</p>]]></description><link>https://www.compliance-chronicles.com</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Fri, 25 Sep 2026 23:48:45 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/gYpNjBDf.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Liisa Thomas]]></author><pubDate>Tue, 06 Jan 2026 02:44:20 GMT</pubDate><copyright><![CDATA[2026 Liisa Thomas]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Management]]></category><category><![CDATA[Self-Improvement]]></category><itunes:author>Liisa Thomas</itunes:author><itunes:summary>&lt;p&gt;Working in privacy or compliance today means doing organizational change in an AI‑driven world, often without a playbook. Compliance Chronicles brings you lessons with leaders who have navigated that reality, using a simple structure in every episode: their career journey, the challenges they faced, the lessons they took away, and the advice they have for you.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Compliance Chronicles is a practical, conversation‑driven podcast for privacy, cyber, and compliance professionals who are being asked to “figure out” AI, data protection, and regulatory change while still handling their day‑to‑day work. Liisa’s practice focuses on helping companies design and mature AI and privacy governance programs, and this show reflects the real questions clients bring into that work.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Hosted by law firm partner and adjunct professor Liisa Thomas, the show is designed for CLOs, CPOs, CISOs, CCOs and their teams who need to create workable solutions to tricky AI, privacy, and cyber compliance problems. In her conversations with leaders across the industry, Liisa draws on her legal and organizational change experience helping companies build privacy and AI governance to ask the questions you wish you could have, and to surface patterns you can reuse with your own teams.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In each episode, Liisa interviews leaders in the industry who share their career journey, the challenges they have faced and lessons they learned along the way, and their parting advice for others walking a similar path. Guests talk openly about moving skeptical businesses, working with boards and regulators, and operationalizing privacy, cyber, and AI governance in complex, fast‑moving environments.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Whether you are new to privacy or a seasoned CPO, you will hear relatable stories, hard‑won lessons, and human‑centered strategies you can apply in your own organization. If you’re wrestling with AI, privacy and cyber governance in your own organization, you will also hear how Liisa approaches these issues in her work with clients.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;You can find all episodes at &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.compliance-chronicles.com&quot; target=&quot;_blank&quot;&gt;https://www.compliance-chronicles.com&lt;/a&gt;.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Liisa Thomas</itunes:name><itunes:email>liisa.thomas@gmail.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"><itunes:category text="Management"/></itunes:category><itunes:category text="Education"><itunes:category text="Self-Improvement"/></itunes:category><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><item><title><![CDATA[Effective Compliance by Untangling People Problems and Staying Authentic with Corey Tanner (Ep. 19)]]></title><description><![CDATA[<p>In this episode of <i>Compliance Chronicles</i>, Liisa Thomas talks with <b>Corey Tanner</b> about building an employment law function from the ground up and navigating the human side of compliance and investigations. Corey shares how a college job as a secretary at a small employment law firm led to law school and a career focused on workplace issues, internal investigations, and compliance across law firms, the University of Texas, and in‑house roles.</p><p></p><p>She explains why she has always been drawn to the human element: understanding why people do what they do, untangling complicated facts, and helping organizations resolve difficult people problems. Along the way, Corey has created employment law functions, handled complex investigations, and learned how to show up as a trusted partner rather than “the department of no” or “the person you only call when someone is in trouble.”</p><p></p><p>This episode covers:</p><p></p><ul><li>The challenge of wanting the “best possible outcome” as a young lawyer—and the freeing lesson that you can’t change the facts, only work with the circumstances in front of you<p></p></li><li>How to shift perceptions from “legal/compliance means I’m in trouble” to “legal/compliance is a value‑add partner”<p></p></li><li>Practical ways to build trust, including showing genuine interest in people, starting with “Where do you want to go?” and working backwards from desired outcomes<p></p></li><li>Designing paths that move from A to B to X, Y, Z instead of expecting an instant jump from A to Z; and why early, ongoing partnership beats late‑stage roadblocking<p></p></li><li>Balancing a heavy job with being a partner, parent, and friend, and the role of exercise, priorities, and perspective in finding some equilibrium<p></p></li><li>The importance of honesty and how “the cover‑up is worse than the crime” shows up in investigations and legal practice<p></p></li><li>Why almost every mistake is fixable if you own it and ask for help, and how perceived failures can become the most valuable learning experiences<p></p></li><li>The concept of “moral drift”: small compromises that slowly move you far from where you intended to be, and why staying alert to those steps matters<p></p></li><li>How different people can sincerely believe different versions of events, and what that means for investigations, employment law, and compliance<p></p></li><li>Why authenticity, humor, and humility are Corey's core leadership principles; bringing your full self to work, being able to laugh when appropriate, and openly asking experts to “explain it like I’m a third grader”</li></ul><p></p><p><b>If you enjoyed this episode of <i>Compliance Chronicles</i>, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow <i>Compliance Chronicles</i> on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.</b></p>]]></description><guid isPermaLink="false">8a90ba88-5893-4f62-adec-06291684b1d0</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 16 Sep 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/88e9399ac135508389ca1e7f87f10930f1c3a4113345883605a3bc7e8e633c88/eyJlcGlzb2RlSWQiOiI4YTkwYmE4OC01ODkzLTRmNjItYWRlYy0wNjI5MTY4NGIxZDAiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE2MzhmNjQ3ZDNiNDJkNWY1MjRiMWRmL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNy0yNF9fMTgtMTQtMjgubXAzIn0=.mp3" length="18355243" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/8a90ba88-5893-4f62-adec-06291684b1d0/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, Liisa Thomas talks with &lt;b&gt;Corey Tanner&lt;/b&gt; about building an employment law function from the ground up and navigating the human side of compliance and investigations. Corey shares how a college job as a secretary at a small employment law firm led to law school and a career focused on workplace issues, internal investigations, and compliance across law firms, the University of Texas, and in‑house roles.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;She explains why she has always been drawn to the human element: understanding why people do what they do, untangling complicated facts, and helping organizations resolve difficult people problems. Along the way, Corey has created employment law functions, handled complex investigations, and learned how to show up as a trusted partner rather than “the department of no” or “the person you only call when someone is in trouble.”&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This episode covers:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The challenge of wanting the “best possible outcome” as a young lawyer—and the freeing lesson that you can’t change the facts, only work with the circumstances in front of you&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;How to shift perceptions from “legal/compliance means I’m in trouble” to “legal/compliance is a value‑add partner”&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Practical ways to build trust, including showing genuine interest in people, starting with “Where do you want to go?” and working backwards from desired outcomes&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Designing paths that move from A to B to X, Y, Z instead of expecting an instant jump from A to Z; and why early, ongoing partnership beats late‑stage roadblocking&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Balancing a heavy job with being a partner, parent, and friend, and the role of exercise, priorities, and perspective in finding some equilibrium&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;The importance of honesty and how “the cover‑up is worse than the crime” shows up in investigations and legal practice&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why almost every mistake is fixable if you own it and ask for help, and how perceived failures can become the most valuable learning experiences&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;The concept of “moral drift”: small compromises that slowly move you far from where you intended to be, and why staying alert to those steps matters&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;How different people can sincerely believe different versions of events, and what that means for investigations, employment law, and compliance&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why authenticity, humor, and humility are Corey&apos;s core leadership principles; bringing your full self to work, being able to laugh when appropriate, and openly asking experts to “explain it like I’m a third grader”&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoyed this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow &lt;i&gt;Compliance Chronicles&lt;/i&gt; on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:34</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:title>Effective Compliance by Untangling People Problems and Staying Authentic with Corey Tanner (Ep. 19)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Ensuring Your Compliance Role Matches the Moment with Jay Cohen (Ep. 18)]]></title><description><![CDATA[<p>In this episode of <i>Compliance Chronicles</i>, Liisa Thomas talks with <b>Jay Cohen</b> about what it really means to lead compliance in a global insurance business, and why activity alone doesn’t prove an effective compliance program. Jay shares his journey from 20 years in New York government (including 10 years as a prosecutor in Brooklyn) into legal and regulatory compliance roles at a variety of companies including Prudential, Assurant, and ultimately QBE Insurance.</p><p></p><p>He explains how he “fell into” compliance during a nationwide class action and multi‑state regulatory investigation at Prudential, where his first assignment was telling offices around the country to keep boxes and boxes of files. From there, he moved into health insurance and leadership roles, eventually becoming a chief compliance officer and consultant before stepping into his current role at QBE.</p><p></p><p>This episode covers:</p><p></p><ul><li>Why regulatory compliance feels similar to appellate work: understanding the rules, telling the story, and helping business teams make those rules work in practice<p></p></li><li>Jay’s “pre and post” philosophy of compliance: knowing which rules apply and knowing whether the organization is actually following them<p></p></li><li>The challenge of rules that are constantly changing, not always practical, and sometimes at odds with what the business wants to do<p></p></li><li>The partner vs. guardian dilemma, inspired by Ben Heineman’s work: knowing when to support the business and when to protect it, and getting the business to understand why<p></p></li><li>Why counting training sessions, policies, or helpline calls doesn’t truly measure compliance effectiveness<p></p></li><li>How to focus on whether changes are communicated, implemented, and whether they <i>stick</i> in daily operations<p></p></li><li>The importance of getting out of your office, spending time with business teams, and building relationships so people know and trust you when you say “partner” or “guardian”<p></p></li><li>Assuming positive intent, especially when teams resist or push back, and using that resistance as a cue to listen and recalibrate<p></p></li><li>Why compliance is a “terrific way to make a living” if you care about understanding, analysis, communication, and helping companies do the right thing</li></ul><p></p><p><b>If you enjoyed this episode of <i>Compliance Chronicles</i>, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow <i>Compliance Chronicles</i> on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.</b></p>]]></description><guid isPermaLink="false">8859ede6-b3ce-4b4d-9a61-b6a0fddaecda</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 02 Sep 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/cc378f867343af12170a267dd1012d9dfb42ac2b7961545378a3236d48d63de0/eyJlcGlzb2RlSWQiOiI4ODU5ZWRlNi1iM2NlLTRiNGQtOWE2MS1iNmEwZmRkYWVjZGEiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0NmI3OWZlMmU3NDlmZDY4NjliMjJkL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNy0yX18yMS0xMC0yMy5tcDMifQ==.mp3" length="18853450" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/8859ede6-b3ce-4b4d-9a61-b6a0fddaecda/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, Liisa Thomas talks with &lt;b&gt;Jay Cohen&lt;/b&gt; about what it really means to lead compliance in a global insurance business, and why activity alone doesn’t prove an effective compliance program. Jay shares his journey from 20 years in New York government (including 10 years as a prosecutor in Brooklyn) into legal and regulatory compliance roles at a variety of companies including Prudential, Assurant, and ultimately QBE Insurance.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;He explains how he “fell into” compliance during a nationwide class action and multi‑state regulatory investigation at Prudential, where his first assignment was telling offices around the country to keep boxes and boxes of files. From there, he moved into health insurance and leadership roles, eventually becoming a chief compliance officer and consultant before stepping into his current role at QBE.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This episode covers:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Why regulatory compliance feels similar to appellate work: understanding the rules, telling the story, and helping business teams make those rules work in practice&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Jay’s “pre and post” philosophy of compliance: knowing which rules apply and knowing whether the organization is actually following them&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;The challenge of rules that are constantly changing, not always practical, and sometimes at odds with what the business wants to do&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;The partner vs. guardian dilemma, inspired by Ben Heineman’s work: knowing when to support the business and when to protect it, and getting the business to understand why&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why counting training sessions, policies, or helpline calls doesn’t truly measure compliance effectiveness&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;How to focus on whether changes are communicated, implemented, and whether they &lt;i&gt;stick&lt;/i&gt; in daily operations&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;The importance of getting out of your office, spending time with business teams, and building relationships so people know and trust you when you say “partner” or “guardian”&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Assuming positive intent, especially when teams resist or push back, and using that resistance as a cue to listen and recalibrate&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why compliance is a “terrific way to make a living” if you care about understanding, analysis, communication, and helping companies do the right thing&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoyed this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, please consider subscribing and leaving a rating or review—it helps others discover the show and supports more conversations with leaders across privacy, risk, and compliance. Follow &lt;i&gt;Compliance Chronicles&lt;/i&gt; on your favorite podcast platform (Spotify, Apple Podcasts, YouTube, and more) and connect with Liisa on LinkedIn so you don’t miss future episodes.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:49</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:title>Ensuring Your Compliance Role Matches the Moment with Jay Cohen (Ep. 18)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Embedding Compliance in Business Growth with Lauren Ervin (Ep. 17)]]></title><description><![CDATA[<p>In this episode of <i>Compliance Chronicles</i>, Liisa Thomas talks with <b>Lauren Ervin</b>, an Associate General Counsel who shares how privacy moved from a tentative “I’ll raise my hand” moment to the core of her legal and compliance work. Lauren shares how she spent over a decade in financial services—starting at a small litigation firm in Miami, then moving in‑house to a major non‑bank mortgage servicer—before a mentor encouraged her to take on privacy because “it’s going to be a big deal one day.” That nudge led her to build out privacy responsibilities and eventually support privacy, security, and data governance in her current role.</p><p></p><p>She explains why privacy is often treated like “art class”—important but easily deprioritized—and how she works to reframe it as a value proposition tied directly to customer choice, trust, and business growth. Throughout the conversation, Lauren highlights the importance of understanding the business, translating regulatory mandates into tangible benefits, and using both EQ and IQ to navigate complex, evolving privacy frameworks across states, regions, and cultures.</p><p></p><p>This episode covers:</p><p>·        Why privacy is often viewed as “art class,” and how to reposition it as a business‑critical function customers genuinely care about</p><p>·        How learning the business first—processes, downstream impacts, and bandwidth—builds trust and makes privacy requests more workable</p><p>·        Practical ways to turn compliance objectives (like data mapping and inventories) into tools that help product, engineering, and customer teams</p><p>·        Strategies for baking privacy into the value proposition instead of treating it as a late‑stage hurdle to growth and innovation</p><p>·        The role of EQ in privacy work: doing right by residents and the company while managing expectations, skepticism, and change</p><p>·        How cultural awareness (across geographies and job roles) helps privacy and legal teams “meet people where they are” and collaborate more effectively</p><p>·        Why you shouldn’t be afraid to ask for what you want in your career—and how clarifying your “North Star” can actually help managers support you</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to <i>Compliance Chronicles</i> in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">745e9921-a0c4-486d-acc4-7d6db2f27423</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 19 Aug 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/8e2be01b9698a6e40273e3bb498c2f6ffd2acbf91a5f42ab0f42420acc9c13b1/eyJlcGlzb2RlSWQiOiI3NDVlOTkyMS1hMGM0LTQ4NmQtYWNjNC03ZDZkYjJmMjc0MjMiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0YzFmZDk0YzZhMTYyNzQyMzU0ZWMxL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNy02X18yMy0zNi0yNS5tcDMifQ==.mp3" length="18694626" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/745e9921-a0c4-486d-acc4-7d6db2f27423/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, Liisa Thomas talks with &lt;b&gt;Lauren Ervin&lt;/b&gt;, an Associate General Counsel who shares how privacy moved from a tentative “I’ll raise my hand” moment to the core of her legal and compliance work. Lauren shares how she spent over a decade in financial services—starting at a small litigation firm in Miami, then moving in‑house to a major non‑bank mortgage servicer—before a mentor encouraged her to take on privacy because “it’s going to be a big deal one day.” That nudge led her to build out privacy responsibilities and eventually support privacy, security, and data governance in her current role.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;She explains why privacy is often treated like “art class”—important but easily deprioritized—and how she works to reframe it as a value proposition tied directly to customer choice, trust, and business growth. Throughout the conversation, Lauren highlights the importance of understanding the business, translating regulatory mandates into tangible benefits, and using both EQ and IQ to navigate complex, evolving privacy frameworks across states, regions, and cultures.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This episode covers:&lt;/p&gt;&lt;p&gt;·        Why privacy is often viewed as “art class,” and how to reposition it as a business‑critical function customers genuinely care about&lt;/p&gt;&lt;p&gt;·        How learning the business first—processes, downstream impacts, and bandwidth—builds trust and makes privacy requests more workable&lt;/p&gt;&lt;p&gt;·        Practical ways to turn compliance objectives (like data mapping and inventories) into tools that help product, engineering, and customer teams&lt;/p&gt;&lt;p&gt;·        Strategies for baking privacy into the value proposition instead of treating it as a late‑stage hurdle to growth and innovation&lt;/p&gt;&lt;p&gt;·        The role of EQ in privacy work: doing right by residents and the company while managing expectations, skepticism, and change&lt;/p&gt;&lt;p&gt;·        How cultural awareness (across geographies and job roles) helps privacy and legal teams “meet people where they are” and collaborate more effectively&lt;/p&gt;&lt;p&gt;·        Why you shouldn’t be afraid to ask for what you want in your career—and how clarifying your “North Star” can actually help managers support you&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to &lt;i&gt;Compliance Chronicles&lt;/i&gt; in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:44</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:title>Embedding Compliance in Business Growth with Lauren Ervin (Ep. 17)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Turning Privacy Into a Business Success Factor with Matthew Ellis (Ep. 16)]]></title><description><![CDATA[<p>In this episode of <i>Compliance Chronicles</i>, Liisa Thomas talks with <b>Matthew Ellis</b>, an “opportunity creator and problem solver” who has spent nearly 25 years building and leading privacy programs across startups, Big Four firms, global technology companies, and consumer brands. Matthew shares how he fell into privacy at an email marketing startup, went on to start EY’s first Bay Area privacy practice, led privacy at Microsoft and Peloton, and now advises small–to–mid‑tier companies on turning privacy into a true success factor.</p><p></p><p>He explains why privacy is most powerful when it’s operationalized—embedded in product and R&amp;D from the beginning—and why privacy professionals often end up owning AI, M&amp;A diligence, and complex data questions. Throughout the conversation, Matthew highlights the importance of bridging legal and product, saying yes to stretch opportunities, and treating privacy as a long‑game career path.</p><p></p><p>This episode covers:</p><p></p><ul><li>Why early collaboration with product and R&amp;D turns privacy from a late-stage obstacle into a <b>strategic success factor</b><p></p></li><li>How privacy professionals can bridge the gap between legal requirements and product ambitions by “speaking both languages”<p></p></li><li>Lessons from large acquisitions and M&amp;A work, including why “signing authority to assume risk” is a critical governance question<p></p></li><li>Why privacy teams are often asked to take on AI, and what it means to “do something with nothing” when it comes to data and emerging tech<p></p></li><li>How building teams of passionate learners and saying yes to stretch roles can accelerate a privacy career<p></p></li><li>Why privacy is likely to remain a strong, growing career path over the next 20+ years—and how to prepare for that future<p></p></li><li>Practical advice on leadership, vulnerability, and knowing when to raise your hand for more responsibility</li></ul><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">f2cdf7a0-19de-4556-867d-40c0bfbd400e</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 05 Aug 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/2905d2d384afa98b82e8803776cd8b84d581a2537f9c5442d41d70cb58171b9b/eyJlcGlzb2RlSWQiOiJmMmNkZjdhMC0xOWRlLTQ1NTYtODY3ZC00MGMwYmZiZDQwMGUiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0NTc4ZTE0NTBiZGJlYWRiY2QzYjUyL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNy0xX18yMi0zMC0yNS5tcDMifQ==.mp3" length="18556699" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/f2cdf7a0-19de-4556-867d-40c0bfbd400e/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of &lt;i&gt;Compliance Chronicles&lt;/i&gt;, Liisa Thomas talks with &lt;b&gt;Matthew Ellis&lt;/b&gt;, an “opportunity creator and problem solver” who has spent nearly 25 years building and leading privacy programs across startups, Big Four firms, global technology companies, and consumer brands. Matthew shares how he fell into privacy at an email marketing startup, went on to start EY’s first Bay Area privacy practice, led privacy at Microsoft and Peloton, and now advises small–to–mid‑tier companies on turning privacy into a true success factor.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;He explains why privacy is most powerful when it’s operationalized—embedded in product and R&amp;amp;D from the beginning—and why privacy professionals often end up owning AI, M&amp;amp;A diligence, and complex data questions. Throughout the conversation, Matthew highlights the importance of bridging legal and product, saying yes to stretch opportunities, and treating privacy as a long‑game career path.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This episode covers:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Why early collaboration with product and R&amp;amp;D turns privacy from a late-stage obstacle into a &lt;b&gt;strategic success factor&lt;/b&gt;&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;How privacy professionals can bridge the gap between legal requirements and product ambitions by “speaking both languages”&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Lessons from large acquisitions and M&amp;amp;A work, including why “signing authority to assume risk” is a critical governance question&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why privacy teams are often asked to take on AI, and what it means to “do something with nothing” when it comes to data and emerging tech&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;How building teams of passionate learners and saying yes to stretch roles can accelerate a privacy career&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Why privacy is likely to remain a strong, growing career path over the next 20+ years—and how to prepare for that future&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;Practical advice on leadership, vulnerability, and knowing when to raise your hand for more responsibility&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:40</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:title>Turning Privacy Into a Business Success Factor with Matthew Ellis (Ep. 16)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)]]></title><description><![CDATA[<p>Chief Information Security Officer Shellie Dreistadt joins Compliance Chronicles with Liisa Thomas to talk about how psychology, cybersecurity, and leadership resilience come together in modern security programs. She shares her nonlinear path from psychology and call‑center leadership into information security, online banking, and ultimately her current CISO role.</p><p></p><p>Shellie explains why security sits at the intersection of people and technology, and how understanding behavior, motivation, and trust is just as important as understanding firewalls, access controls, and tools. She describes the realities of being a CISO today: constantly evolving threats, rapid technology change, and an expanding privacy and security regulatory landscape.</p><p></p><p>The conversation covers pushing risk ownership back into the business, framing issues in financial and operational terms instead of “tech speak,” and avoiding burnout by refusing to be the “single point of safety.” Shellie also shares how she builds resilient, curious, adaptable teams and why culture and psychological safety matter as much as any control.</p><p></p><p>Her advice for security, privacy, and compliance professionals: stay curious, stay human, and remember that cybersecurity is a marathon, not a sprint. Security is not about being the department of no—it is about enabling the business to move forward safely.</p><p></p><p>If you work in cybersecurity, information security, privacy, or compliance—or you’re aspiring to a CISO or security leadership role—this episode offers practical insight into building resilient teams and leading with both technical acumen and empathy.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, cybersecurity, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">1bf8c9d7-e688-4187-9106-6db87ea5fc71</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 22 Jul 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/44b3d4a86af8a05c991704d0374fdb0bc54f15ad1adda2da0e00361ee2afacf1/eyJlcGlzb2RlSWQiOiIxYmY4YzlkNy1lNjg4LTQxODctOTEwNi02ZGI4N2VhNWZjNzEiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmYjQ4ZTZmMzhjYWZiY2M3ZWJjNTFhL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNS02X18xNS01Ny01OC5tcDMifQ==.mp3" length="22537343" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/1bf8c9d7-e688-4187-9106-6db87ea5fc71/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Chief Information Security Officer Shellie Dreistadt joins Compliance Chronicles with Liisa Thomas to talk about how psychology, cybersecurity, and leadership resilience come together in modern security programs. She shares her nonlinear path from psychology and call‑center leadership into information security, online banking, and ultimately her current CISO role.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Shellie explains why security sits at the intersection of people and technology, and how understanding behavior, motivation, and trust is just as important as understanding firewalls, access controls, and tools. She describes the realities of being a CISO today: constantly evolving threats, rapid technology change, and an expanding privacy and security regulatory landscape.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The conversation covers pushing risk ownership back into the business, framing issues in financial and operational terms instead of “tech speak,” and avoiding burnout by refusing to be the “single point of safety.” Shellie also shares how she builds resilient, curious, adaptable teams and why culture and psychological safety matter as much as any control.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Her advice for security, privacy, and compliance professionals: stay curious, stay human, and remember that cybersecurity is a marathon, not a sprint. Security is not about being the department of no—it is about enabling the business to move forward safely.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If you work in cybersecurity, information security, privacy, or compliance—or you’re aspiring to a CISO or security leadership role—this episode offers practical insight into building resilient teams and leading with both technical acumen and empathy.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, cybersecurity, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:11:44</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>15</itunes:episode><itunes:title>Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The Path From Big Law Litigator to CLO with Lori Baggett (Ep. 11)]]></title><description><![CDATA[<p>Chief Legal Office Lori Baggett shares her journey from small‑town Florida to Big Law litigator to CLO at PODS, a national moving and storage company. In this 11th Episode of Compliance Chronicles, she talks with host Liisa Thomas about what really changes when you move from law firm partner to in‑house counsel and ultimately into the chief legal officer role.</p><p></p><p>Lori describes her path from Division I basketball player to clerk on the Eleventh Circuit, to 18 years at a prestigious firm where she built a practice in employment law, construction, and OSHA workplace safety—while also taking on leadership roles like hiring partner and office managing shareholder.</p><p></p><p>A central theme is the identity shift that comes with going in‑house. She contrasts the law firm environment, where everything is organized around selling your legal services, with the in‑house world, where the focus is on being a business person with a law degree, not “the lawyer” in the corner office.</p><p></p><p>Lori and Liisa dig into how to avoid being seen as “the department of no” and instead become a trusted partner who helps the business get to yes. Lori shares how she learned to make sure she’s invited to the right meetings, build credibility with business colleagues, and communicate that her job is to help them achieve their goals in a safe, compliant way. She talks about mentors who modeled calm, unflappable leadership and taught her when to push, when to listen, and how to stay steady in chaos.</p><p></p><p>The conversation tackles people leadership and feedback as ongoing challenges, no matter the setting. Lori discusses learning to give and receive constructive feedback, advocate for yourself, and live out her personal mantra: “Do no harm, but take no stuff.” She emphasizes the importance of standing up for your needs—whether that’s feedback, mentorship, or opportunities—while still being a supportive leader for your team and partners.</p><p></p><p>Operationally, Lori shares how she thinks about building systems that set people up to do the right thing. She talks about looking at leadership workloads, time and motion studies, and the realistic number of hours in a workday when designing compliance and safety expectations. Instead of endlessly adding to the plate of field leaders, she emphasizes prioritization, clarity, and creating structures that make compliance achievable rather than overwhelming.</p><p>Lori also offers a powerful mindset shift around blame and mistakes. She explains why she reminds herself that people don’t wake up wanting to do a terrible job at work; most are trying their best within the systems and information they have. That perspective leads her to “link arms” with colleagues, use “we” language, and focus on understanding why something happened before Monday‑morning quarterbacking. She shares her belief that each of us is “one of one,” and that careers get better when we own who we are instead of trying to fit someone else’s mold. For those earlier in their journey, she encourages patience: you will find your “sea legs,” and staying true to yourself will help you find the spaces that are truly the right fit.</p><p></p><p>If you’re a law firm partner thinking about moving in‑house, an aspiring general counsel or chief legal officer, or a compliance and risk leader looking for inspiration on how to be a better business partner, this episode offers candid insight and practical takeaways.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p><p></p>]]></description><guid isPermaLink="false">5c85c6b3-067f-4067-9011-c98c42fd89f4</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 27 May 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/31e31101f9f456c145900618a890b5ff1e55a4e8ba27c1763419206b868e52e9/eyJlcGlzb2RlSWQiOiI1Yzg1YzZiMy0wNjdmLTQwNjctOTAxMS1jOThjNDJmZDg5ZjQiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmN2I0ZjFjNDY2OGU2NTdjMTc1NTc4L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNS0zX18yMi00OS01My5tcDMifQ==.mp3" length="18469764" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/5c85c6b3-067f-4067-9011-c98c42fd89f4/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Chief Legal Office Lori Baggett shares her journey from small‑town Florida to Big Law litigator to CLO at PODS, a national moving and storage company. In this 11th Episode of Compliance Chronicles, she talks with host Liisa Thomas about what really changes when you move from law firm partner to in‑house counsel and ultimately into the chief legal officer role.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Lori describes her path from Division I basketball player to clerk on the Eleventh Circuit, to 18 years at a prestigious firm where she built a practice in employment law, construction, and OSHA workplace safety—while also taking on leadership roles like hiring partner and office managing shareholder.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;A central theme is the identity shift that comes with going in‑house. She contrasts the law firm environment, where everything is organized around selling your legal services, with the in‑house world, where the focus is on being a business person with a law degree, not “the lawyer” in the corner office.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Lori and Liisa dig into how to avoid being seen as “the department of no” and instead become a trusted partner who helps the business get to yes. Lori shares how she learned to make sure she’s invited to the right meetings, build credibility with business colleagues, and communicate that her job is to help them achieve their goals in a safe, compliant way. She talks about mentors who modeled calm, unflappable leadership and taught her when to push, when to listen, and how to stay steady in chaos.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The conversation tackles people leadership and feedback as ongoing challenges, no matter the setting. Lori discusses learning to give and receive constructive feedback, advocate for yourself, and live out her personal mantra: “Do no harm, but take no stuff.” She emphasizes the importance of standing up for your needs—whether that’s feedback, mentorship, or opportunities—while still being a supportive leader for your team and partners.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Operationally, Lori shares how she thinks about building systems that set people up to do the right thing. She talks about looking at leadership workloads, time and motion studies, and the realistic number of hours in a workday when designing compliance and safety expectations. Instead of endlessly adding to the plate of field leaders, she emphasizes prioritization, clarity, and creating structures that make compliance achievable rather than overwhelming.&lt;/p&gt;&lt;p&gt;Lori also offers a powerful mindset shift around blame and mistakes. She explains why she reminds herself that people don’t wake up wanting to do a terrible job at work; most are trying their best within the systems and information they have. That perspective leads her to “link arms” with colleagues, use “we” language, and focus on understanding why something happened before Monday‑morning quarterbacking. She shares her belief that each of us is “one of one,” and that careers get better when we own who we are instead of trying to fit someone else’s mold. For those earlier in their journey, she encourages patience: you will find your “sea legs,” and staying true to yourself will help you find the spaces that are truly the right fit.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If you’re a law firm partner thinking about moving in‑house, an aspiring general counsel or chief legal officer, or a compliance and risk leader looking for inspiration on how to be a better business partner, this episode offers candid insight and practical takeaways.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:37</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>11</itunes:episode><itunes:title>The Path From Big Law Litigator to CLO with Lori Baggett (Ep. 11)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Developing Effective Compliance Guardrails with Bill Connolly (Ep. 14)]]></title><description><![CDATA[<p>Stepping into compliance “by accident,” building guardrails that actually help the business, and staying curious enough to reinvent your career—Episode 14 with Bill Connolly is packed with practical lessons for anyone in risk, privacy, or compliance leadership.</p><p></p><p>In this episode of Compliance Chronicles, host Liisa Thomas talks with Bill Connolly, Head of Resiliency Risk for the U.S. retail bank at HSBC. Bill oversees a broad risk portfolio that spans information risk, business continuity, disaster recovery, operational resilience, and more—all brought together in a single resiliency risk program. He shares how his career evolved from managing TCPA suppressions and customer choice, to vendor risk and privacy, to digital compliance, and ultimately into enterprise resiliency risk.</p><p></p><p>Bill walks through his “privacy by almost accident” story: starting with do‑not‑call and do‑not‑solicit databases, helping to build practical privacy questionnaires, and being asked to relaunch a new privacy program by writing a privacy policy that actually reflected how the organization worked. That experience led him into digital compliance, where he carried forward his privacy and information risk expertise to tackle cookie compliance, cross‑border data issues, and global data privacy obligations in a large financial institution.</p><p></p><p>A major theme of the conversation is how to communicate risk in a way the business understands. Bill explains how he created “guardrails” to reduce low‑value questions and empower teams: if people stay within well‑defined parameters on TCPA, privacy, or other rules, they can move quickly; if they step outside those guardrails, that’s when legal and compliance step in. He shares why this kind of tooling not only helps the business move faster but also protects second‑line teams from getting buried in ad‑hoc requests.</p><p></p><p>They dig into the challenges of new regulatory and resiliency requirements, including “important business services” mapping and the sheer scope of work that often falls on a small group of people in each business unit. Bill talks about translating highly technical topics—like IT vulnerabilities—into business language and compelling risk narratives that management can act on and fund. He emphasizes the importance of understanding both the compliance requirements and the resource impact on the business, so you can prioritize, sequence, and negotiate change effectively.</p><p></p><p>Bill also shares career advice for compliance, risk, and privacy professionals at different stages. For those starting out, he stresses curiosity—following your interest into areas like digital privacy or information risk, and backing it up with credentials such as CISA and IAPP certifications. For those who are bored or burned out, he suggests re‑examining your role, looking one year ahead at where you want to be, and exploring adjacent areas like digital, operations, or new risk domains where your expertise can be uniquely valuable.</p><p></p><p>The conversation closes with a focus on growth and reflection: using sabbaticals or mini‑sabbaticals, mentorship, and honest self‑assessment to decide when you need a new challenge. Bill’s parting advice is to deliberately step outside your comfort zone—because no one will do that for you—and to treat each stretch assignment as a way to expand both your knowledge and your network.</p><p></p><p>If you work in privacy, compliance, operational risk, or resilience at a bank or large corporate and want to become a more effective partner to the business while continuing to grow your own career, this episode is for you.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">d647f6c9-51a5-40f2-9ecb-8f96d3425c31</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 08 Jul 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/e40356615c4844f29a8eb5cd51285b3fda0bced7136f41e1556c8cfbf79b5680/eyJlcGlzb2RlSWQiOiJkNjQ3ZjZjOS01MWE1LTQwZjItOWVjYi04Zjk2ZDM0MjVjMzEiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmN2JkMGI0YzEzODNhYjEyMjM3ODRlL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNS0zX18yMy0yNC0yNy5tcDMifQ==.mp3" length="25733895" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/d647f6c9-51a5-40f2-9ecb-8f96d3425c31/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;Stepping into compliance “by accident,” building guardrails that actually help the business, and staying curious enough to reinvent your career—Episode 14 with Bill Connolly is packed with practical lessons for anyone in risk, privacy, or compliance leadership.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode of Compliance Chronicles, host Liisa Thomas talks with Bill Connolly, Head of Resiliency Risk for the U.S. retail bank at HSBC. Bill oversees a broad risk portfolio that spans information risk, business continuity, disaster recovery, operational resilience, and more—all brought together in a single resiliency risk program. He shares how his career evolved from managing TCPA suppressions and customer choice, to vendor risk and privacy, to digital compliance, and ultimately into enterprise resiliency risk.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Bill walks through his “privacy by almost accident” story: starting with do‑not‑call and do‑not‑solicit databases, helping to build practical privacy questionnaires, and being asked to relaunch a new privacy program by writing a privacy policy that actually reflected how the organization worked. That experience led him into digital compliance, where he carried forward his privacy and information risk expertise to tackle cookie compliance, cross‑border data issues, and global data privacy obligations in a large financial institution.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;A major theme of the conversation is how to communicate risk in a way the business understands. Bill explains how he created “guardrails” to reduce low‑value questions and empower teams: if people stay within well‑defined parameters on TCPA, privacy, or other rules, they can move quickly; if they step outside those guardrails, that’s when legal and compliance step in. He shares why this kind of tooling not only helps the business move faster but also protects second‑line teams from getting buried in ad‑hoc requests.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;They dig into the challenges of new regulatory and resiliency requirements, including “important business services” mapping and the sheer scope of work that often falls on a small group of people in each business unit. Bill talks about translating highly technical topics—like IT vulnerabilities—into business language and compelling risk narratives that management can act on and fund. He emphasizes the importance of understanding both the compliance requirements and the resource impact on the business, so you can prioritize, sequence, and negotiate change effectively.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Bill also shares career advice for compliance, risk, and privacy professionals at different stages. For those starting out, he stresses curiosity—following your interest into areas like digital privacy or information risk, and backing it up with credentials such as CISA and IAPP certifications. For those who are bored or burned out, he suggests re‑examining your role, looking one year ahead at where you want to be, and exploring adjacent areas like digital, operations, or new risk domains where your expertise can be uniquely valuable.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The conversation closes with a focus on growth and reflection: using sabbaticals or mini‑sabbaticals, mentorship, and honest self‑assessment to decide when you need a new challenge. Bill’s parting advice is to deliberately step outside your comfort zone—because no one will do that for you—and to treat each stretch assignment as a way to expand both your knowledge and your network.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If you work in privacy, compliance, operational risk, or resilience at a bank or large corporate and want to become a more effective partner to the business while continuing to grow your own career, this episode is for you.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:13:24</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>14</itunes:episode><itunes:title>Developing Effective Compliance Guardrails with Bill Connolly (Ep. 14)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Successful Compliance: Taking a Yes Before No Approach with Joe Habib (Ep. 12)]]></title><description><![CDATA[<p>In this 12th episode of Compliance Chronicles, Liisa talks with Joe Habib, who shares insights on navigating privacy, compliance, and AI. He emphasizes the importance of understanding technology, building trust, and taking a 'yes before no' approach. His journey and advice inspire a commitment to continuous learning.</p><p></p><p>Takeaways</p><ul><li>Understanding technology</li><li>Building trust</li><li>'Yes before no' approach</li><li>Continuous learning<p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p><p></p></li></ul>]]></description><guid isPermaLink="false">cc0e4e30-85a3-41f9-80a9-95436ec2089e</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 10 Jun 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/027d93396230f44cfa62d1bf595974d0b3a9020b020a983654df583cd3d1f006/eyJlcGlzb2RlSWQiOiJjYzBlNGUzMC04NWEzLTQxZjktODBhOS05NTQzNmVjMjA4OWUiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmN2JmYWVhZTdmMTQ5M2RkODk5YmNjL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNS0zX18yMy0zNS00Mi5tcDMifQ==.mp3" length="23481095" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/cc0e4e30-85a3-41f9-80a9-95436ec2089e/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this 12th episode of Compliance Chronicles, Liisa talks with Joe Habib, who shares insights on navigating privacy, compliance, and AI. He emphasizes the importance of understanding technology, building trust, and taking a &apos;yes before no&apos; approach. His journey and advice inspire a commitment to continuous learning.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Understanding technology&lt;/li&gt;&lt;li&gt;Building trust&lt;/li&gt;&lt;li&gt;&apos;Yes before no&apos; approach&lt;/li&gt;&lt;li&gt;Continuous learning&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:12:14</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>12</itunes:episode><itunes:title>Successful Compliance: Taking a Yes Before No Approach with Joe Habib (Ep. 12)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Creative Connections with Business Teams, with Katie Tomashevski (Ep. 13)]]></title><description><![CDATA[<p>In this lucky 13th episode of Compliance Chronicles, host Liisa Thomas talks with Katie Tomashevski, a New York–born, London‑trained British solicitor and internal auditor who specializes in data privacy and compliance. Katie shares her path from photojournalism and the entertainment and music industry into regulation, then into data protection, internal audit, and privacy roles in a large company.</p><p></p><p>Katie explains how working in PR, marketing, and entertainment licensing led her to law school and ultimately to becoming a “second‑career solicitor,” using her creative background to connect with stakeholders and translate complex regulatory requirements into practical guidance. She describes going from “poacher to gamekeeper” as a regulator under multiple licensing and safety regimes, and how that experience shaped her approach to helping businesses do what they really want to do while staying compliant.</p><p></p><p>They dig into the realities of compliance work: why “nobody likes compliance,” why most people genuinely want to do the right thing, and how curiosity and context are essential for getting buy‑in. Katie talks about how dyslexia has made her a better privacy and compliance professional, because it forces her to demand context, clear agendas, and upfront information so she can give her best advice. She shares how this mindset helps her understand business objectives, identify real risks, and avoid selling “solutions in search of a problem.”</p><p></p><p>The conversation also explores Katie’s time as a data protection officer and internal advisor on data privacy, including a vivid story about data retention, data subject access requests, and what happens when organizations keep personal data far longer than promised. She highlights a key lesson: privacy and compliance teams advise on the “how,” but the business owns the “what” and the accountability for data processing decisions.</p><p></p><p>Finally, Katie offers practical, encouraging advice for privacy, compliance, and audit professionals at every stage: be curious about what people actually want to achieve, see yourself as a trusted advisor rather than the “fun police,” and learn to speak the client’s language so your guidance lands and drives real behavior change. She emphasizes that every business, function, and client group has its own vocabulary—and the more you can mirror it, the more effective you become as a compliance and data privacy partner.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">5aef9a7d-e44a-4e71-a357-441c3b7757bf</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/85c359b9e38915e6d23b1e396f30f5b2b05143b711ec0a46ff4e86a00700db2f/eyJlcGlzb2RlSWQiOiI1YWVmOWE3ZC1lNDRhLTRlNzEtYTM1Ny00NDFjM2I3NzU3YmYiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlmN2MxMDFmM2M4NmRmMzQ4NTM5YjA0L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNS0zX18yMy00MS0yMS5tcDMifQ==.mp3" length="18387008" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/5aef9a7d-e44a-4e71-a357-441c3b7757bf/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this lucky 13th episode of Compliance Chronicles, host Liisa Thomas talks with Katie Tomashevski, a New York–born, London‑trained British solicitor and internal auditor who specializes in data privacy and compliance. Katie shares her path from photojournalism and the entertainment and music industry into regulation, then into data protection, internal audit, and privacy roles in a large company.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Katie explains how working in PR, marketing, and entertainment licensing led her to law school and ultimately to becoming a “second‑career solicitor,” using her creative background to connect with stakeholders and translate complex regulatory requirements into practical guidance. She describes going from “poacher to gamekeeper” as a regulator under multiple licensing and safety regimes, and how that experience shaped her approach to helping businesses do what they really want to do while staying compliant.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;They dig into the realities of compliance work: why “nobody likes compliance,” why most people genuinely want to do the right thing, and how curiosity and context are essential for getting buy‑in. Katie talks about how dyslexia has made her a better privacy and compliance professional, because it forces her to demand context, clear agendas, and upfront information so she can give her best advice. She shares how this mindset helps her understand business objectives, identify real risks, and avoid selling “solutions in search of a problem.”&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The conversation also explores Katie’s time as a data protection officer and internal advisor on data privacy, including a vivid story about data retention, data subject access requests, and what happens when organizations keep personal data far longer than promised. She highlights a key lesson: privacy and compliance teams advise on the “how,” but the business owns the “what” and the accountability for data processing decisions.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Finally, Katie offers practical, encouraging advice for privacy, compliance, and audit professionals at every stage: be curious about what people actually want to achieve, see yourself as a trusted advisor rather than the “fun police,” and learn to speak the client’s language so your guidance lands and drives real behavior change. She emphasizes that every business, function, and client group has its own vocabulary—and the more you can mirror it, the more effective you become as a compliance and data privacy partner.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:35</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>13</itunes:episode><itunes:title>Creative Connections with Business Teams, with Katie Tomashevski (Ep. 13)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Using Operational Change in Compliance with Kam Dodge (Ep. 10)]]></title><description><![CDATA[<p>In this episode of <b>Compliance Chronicles</b>, our 10th, <b>Kam Dodge</b>, an in‑house leader with roots in <b>Northwestern SESP</b>’s Learning and Organizational Change program, explains why privacy and compliance are non‑negotiable in heavily regulated industries and introduces his “rubber balls vs. glass balls” framework for prioritizing risk. He shares how to use simple expected‑value thinking (likelihood x impact) to communicate 8‑ and 9‑figure exposure in language that boards and business leaders understand.</p><p></p><p>You’ll hear how Kam:</p><ul><li>Looks for opportunities to showcase strong compliance</li><li>Builds partnerships with CTOs and CIOs by being willing to ask “basic” questions</li><li>Uses a straightforward test: does this outcome match what a reasonable customer would expect if you explained it at the dinner table?</li></ul><p></p><p>This episode is ideal for in‑house counsel, privacy and compliance professionals, and leaders in financial services and other highly regulated sectors who want practical, business‑savvy ways to manage risk and strengthen customer trust.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">33714894-37a7-43a9-a75e-cbb0052a983e</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 13 May 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/c35175cdffc85d3dc7700dead10c59e3e81b00f5f84906ecd0dbfcc497edd916/eyJlcGlzb2RlSWQiOiIzMzcxNDg5NC0zN2E3LTQzYTktYTc1ZS1jYmIwMDUyYTk4M2UiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjllZmQ1ZDc3ZjhjZmYyM2ZjMTcwZWE5L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtNC0yN19fMjMtMzItNy5tcDMifQ==.mp3" length="19921754" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/33714894-37a7-43a9-a75e-cbb0052a983e/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode of &lt;b&gt;Compliance Chronicles&lt;/b&gt;, our 10th, &lt;b&gt;Kam Dodge&lt;/b&gt;, an in‑house leader with roots in &lt;b&gt;Northwestern SESP&lt;/b&gt;’s Learning and Organizational Change program, explains why privacy and compliance are non‑negotiable in heavily regulated industries and introduces his “rubber balls vs. glass balls” framework for prioritizing risk. He shares how to use simple expected‑value thinking (likelihood x impact) to communicate 8‑ and 9‑figure exposure in language that boards and business leaders understand.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;You’ll hear how Kam:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Looks for opportunities to showcase strong compliance&lt;/li&gt;&lt;li&gt;Builds partnerships with CTOs and CIOs by being willing to ask “basic” questions&lt;/li&gt;&lt;li&gt;Uses a straightforward test: does this outcome match what a reasonable customer would expect if you explained it at the dinner table?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This episode is ideal for in‑house counsel, privacy and compliance professionals, and leaders in financial services and other highly regulated sectors who want practical, business‑savvy ways to manage risk and strengthen customer trust.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:10:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>10</itunes:episode><itunes:title>Using Operational Change in Compliance with Kam Dodge (Ep. 10)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Thriving in Compliance Gray Areas with Deb Sokol (Ep. 9)]]></title><description><![CDATA[<p>In episode nine of Compliance Chronicles, we learn from Deb Sokol the importance of embracing the gray and look at the evolving nature of compliance. Deb shares her compliance journey and lessons she's learned along the way.</p><p></p><p>What we cover:</p><p></p><ul><li>Being open to new opportunities and volunteering for stretch assignments can unexpectedly launch a career in privacy and compliance</li><li>Moving from a pure legal role into a compliance role requires a mindset shift toward controls, documentation, metrics, and disciplined, programmatic thinking</li><li>Mature compliance programs are built on clearly defined controls, monitoring, testing, and consistent documentation</li><li>Privacy and AI work often happens “in the gray,” where laws are incomplete or unclear, and professionals must use analogies, principles, and creativity</li><li>Giving specific, actionable guidance to the business is challenging when statutes and regulations leave gaps or ambiguities</li><li>Rotations or close work inside a compliance function help lawyers better understand operational realities and what “good” looks like on the ground</li><li>Building a strong network and “phoning a friend” — peers, experts, and trade organizations — is critical when working in uncertain or novel areas</li><li>Learning to be comfortable with ambiguity reduces anxiety and enables better decision-making in evolving regulatory landscapes</li><li>Effective compliance planning starts with mapping principles and end goals, then designing a practical program around them</li><li>When teams feel overwhelmed by a compliance plan, it helps to prioritize: start with what is highest risk or what must be done first to enable everything else</li><li>Version one of a solution does not need to be perfect; a good-enough, law-compliant baseline can be iterated over time</li><li>Risk-based prioritization allows teams to focus limited resources on changes with the greatest impact, while deferring lower-risk improvements</li><li>Stepping outside your comfort zone is essential for growth in privacy and compliance, even when it feels uncomfortable</li><li>Raising your hand and being known as someone willing to try new things expands opportunities and builds a deeper experience base</li><li>Each new experience, even tangential ones, adds to your toolkit and confidence for future roles and challenges</li><li>Curiosity is a superpower in a fast-changing field; asking follow-up questions and staying inquisitive keeps you adaptable and effective</li></ul><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">47f2abbb-088c-4b25-91b4-40332ceb6f34</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 29 Apr 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0017b7bd5682d4ab3f1f7d236934b6bcaa2bb7c6a1755baa9d2b008a29afa373/eyJlcGlzb2RlSWQiOiI0N2YyYWJiYi0wODhjLTRiMjUtOTFiNC00MDMzMmNlYjZmMzQiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlhYjY0YWUzOWFmMjk4YTlmNDNmMmJhL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMy03X18wLTM1LTkubXAzIn0=.mp3" length="14293725" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/47f2abbb-088c-4b25-91b4-40332ceb6f34/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In episode nine of Compliance Chronicles, we learn from Deb Sokol the importance of embracing the gray and look at the evolving nature of compliance. Deb shares her compliance journey and lessons she&apos;s learned along the way.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;What we cover:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Being open to new opportunities and volunteering for stretch assignments can unexpectedly launch a career in privacy and compliance&lt;/li&gt;&lt;li&gt;Moving from a pure legal role into a compliance role requires a mindset shift toward controls, documentation, metrics, and disciplined, programmatic thinking&lt;/li&gt;&lt;li&gt;Mature compliance programs are built on clearly defined controls, monitoring, testing, and consistent documentation&lt;/li&gt;&lt;li&gt;Privacy and AI work often happens “in the gray,” where laws are incomplete or unclear, and professionals must use analogies, principles, and creativity&lt;/li&gt;&lt;li&gt;Giving specific, actionable guidance to the business is challenging when statutes and regulations leave gaps or ambiguities&lt;/li&gt;&lt;li&gt;Rotations or close work inside a compliance function help lawyers better understand operational realities and what “good” looks like on the ground&lt;/li&gt;&lt;li&gt;Building a strong network and “phoning a friend” — peers, experts, and trade organizations — is critical when working in uncertain or novel areas&lt;/li&gt;&lt;li&gt;Learning to be comfortable with ambiguity reduces anxiety and enables better decision-making in evolving regulatory landscapes&lt;/li&gt;&lt;li&gt;Effective compliance planning starts with mapping principles and end goals, then designing a practical program around them&lt;/li&gt;&lt;li&gt;When teams feel overwhelmed by a compliance plan, it helps to prioritize: start with what is highest risk or what must be done first to enable everything else&lt;/li&gt;&lt;li&gt;Version one of a solution does not need to be perfect; a good-enough, law-compliant baseline can be iterated over time&lt;/li&gt;&lt;li&gt;Risk-based prioritization allows teams to focus limited resources on changes with the greatest impact, while deferring lower-risk improvements&lt;/li&gt;&lt;li&gt;Stepping outside your comfort zone is essential for growth in privacy and compliance, even when it feels uncomfortable&lt;/li&gt;&lt;li&gt;Raising your hand and being known as someone willing to try new things expands opportunities and builds a deeper experience base&lt;/li&gt;&lt;li&gt;Each new experience, even tangential ones, adds to your toolkit and confidence for future roles and challenges&lt;/li&gt;&lt;li&gt;Curiosity is a superpower in a fast-changing field; asking follow-up questions and staying inquisitive keeps you adaptable and effective&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:56</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>9</itunes:episode><itunes:title>Thriving in Compliance Gray Areas with Deb Sokol (Ep. 9)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Compliance Success: Building Relationships with Business Teams with Rebecca Hanovice  (Ep. 8)]]></title><description><![CDATA[<p>In our eight episode, we are joined by Rebecca Hanovice, who shares her journey to privacy leadership. She highlights the importance of community and support in the field of privacy compliance.</p><p></p><p>Takeaways include:</p><ul><li>The constant evolution of privacy law</li><li>Building relationships with the business</li><li>Importance of community and support<p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p><p></p></li></ul>]]></description><guid isPermaLink="false">43438359-9754-435f-9112-da5b33179f9c</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 15 Apr 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3bb42d2dadc3a1f6850b99feec2bc49eba8fbff5da17b7c421b8dcd4339f111d/eyJlcGlzb2RlSWQiOiI0MzQzODM1OS05NzU0LTQzNWYtOTExMi1kYTViMzMxNzlmOWMiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlhYjU1ODczOTY2OWEzZDMwYzkwYWNhL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMy02X18yMy0zMC0zMC5tcDMifQ==.mp3" length="13470554" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/43438359-9754-435f-9112-da5b33179f9c/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In our eight episode, we are joined by Rebecca Hanovice, who shares her journey to privacy leadership. She highlights the importance of community and support in the field of privacy compliance.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The constant evolution of privacy law&lt;/li&gt;&lt;li&gt;Building relationships with the business&lt;/li&gt;&lt;li&gt;Importance of community and support&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>8</itunes:episode><itunes:title>Compliance Success: Building Relationships with Business Teams with Rebecca Hanovice  (Ep. 8)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Saying Yes to the Long Game in Compliance with Mark Jaffe (Ep. 7)]]></title><description><![CDATA[<p>In episode seven, Mark Jaffe shares his journey into compliance, the importance of saying yes to opportunities, the long game of compliance, risk management, ethical decision making, lessons in compliance management, and career development and growth in the compliance space.</p><p></p><p>Takeaways</p><ul><li>Saying yes to new challenges and opportunities is important for career growth.</li><li>Compliance is a journey, and it's important to focus on the long game and risk management.</li></ul><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">54993188-5bf0-471c-929f-0ef3843f18c0</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 01 Apr 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0a05bec20832dc83fe7fe711577bcbace7b1fc310bf7eb03836d3d7402d97ced/eyJlcGlzb2RlSWQiOiI1NDk5MzE4OC01YmYwLTQ3MWMtOTI5Zi0wZWYzODQzZjE4YzAiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlhYjE0MzkzM2MyNzY1MGVlNTg4ZTI0L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMy02X18xOC01MS01Mi5tcDMifQ==.mp3" length="13290623" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/episodes/54993188-5bf0-471c-929f-0ef3843f18c0/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In episode seven, Mark Jaffe shares his journey into compliance, the importance of saying yes to opportunities, the long game of compliance, risk management, ethical decision making, lessons in compliance management, and career development and growth in the compliance space.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Saying yes to new challenges and opportunities is important for career growth.&lt;/li&gt;&lt;li&gt;Compliance is a journey, and it&apos;s important to focus on the long game and risk management.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:14</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>7</itunes:episode><itunes:title>Saying Yes to the Long Game in Compliance with Mark Jaffe (Ep. 7)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Optimizing Consumer Trust in Compliance with Jill Cusack (Ep. 6)]]></title><description><![CDATA[<p>In this episode, we learn from Jill Cusack about her journey as a compliance professional. She shares common challenges faced in the field and gives valuable advice for those just starting out.</p><p></p><p>Jill describes the challenge of working between two worlds: helping consumers understand what is happening with their data and helping business and technology teams understand how new products and practices affect transparency, choice, and trust. She also shares the importance of humility in compliance work. Rather than always trying to be the immediate “yes or no” expert, Jill emphasizes the value of saying “I don’t know,” looking deeper, and collaborating with others to reach the right answer.</p><p></p><p>What is covered:</p><p></p><ul><li>Privacy compliance requires translation between legal, technical, and consumer perspectives</li><li>When a data practice feels invasive, creepy, or out of control, it likely needs to be questioned or rethought</li><li>Humility is a core strength in compliance work, including being willing to say “I don’t know” and research the right answer</li><li>Collaboration across legal, compliance, IT, and business teams leads to better privacy outcomes</li><li>Viewing privacy issues through the eyes of a consumer or non-expert family member reveals gaps in transparency and communication</li><li>Real-world consumer touchpoints should guide how organizations design notices, choices, and data handling practices</li><li>Privacy is an evolving, emerging field, so continuous learning and adaptation are essential</li><li>Effective privacy professionals balance regulatory requirements with practical implementation in complex, regulated industries</li><li>Empathy and clear communication help build consumer trust around data use and protection</li></ul><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p><p></p><p></p><p></p><p><br /> </p>]]></description><guid isPermaLink="false">fea0bfa7-fc0e-435e-9db2-bd412db5ed7f</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 18 Mar 2026 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f15b237a546b01be2e4c45a5a8d037e22670da18f1a757e1f4ec13adf2d82448/eyJlcGlzb2RlSWQiOiJmZWEwYmZhNy1mYzBlLTQzNWUtOWRiMi1iZDQxMmRiNWVkN2YiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk5YzhmNWY3ZTY1MWViNTExYzJkNGE4L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMi0yM19fMTgtMzMtMTkubXAzIn0=.mp3" length="11310750" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode, we learn from Jill Cusack about her journey as a compliance professional. She shares common challenges faced in the field and gives valuable advice for those just starting out.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Jill describes the challenge of working between two worlds: helping consumers understand what is happening with their data and helping business and technology teams understand how new products and practices affect transparency, choice, and trust. She also shares the importance of humility in compliance work. Rather than always trying to be the immediate “yes or no” expert, Jill emphasizes the value of saying “I don’t know,” looking deeper, and collaborating with others to reach the right answer.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;What is covered:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Privacy compliance requires translation between legal, technical, and consumer perspectives&lt;/li&gt;&lt;li&gt;When a data practice feels invasive, creepy, or out of control, it likely needs to be questioned or rethought&lt;/li&gt;&lt;li&gt;Humility is a core strength in compliance work, including being willing to say “I don’t know” and research the right answer&lt;/li&gt;&lt;li&gt;Collaboration across legal, compliance, IT, and business teams leads to better privacy outcomes&lt;/li&gt;&lt;li&gt;Viewing privacy issues through the eyes of a consumer or non-expert family member reveals gaps in transparency and communication&lt;/li&gt;&lt;li&gt;Real-world consumer touchpoints should guide how organizations design notices, choices, and data handling practices&lt;/li&gt;&lt;li&gt;Privacy is an evolving, emerging field, so continuous learning and adaptation are essential&lt;/li&gt;&lt;li&gt;Effective privacy professionals balance regulatory requirements with practical implementation in complex, regulated industries&lt;/li&gt;&lt;li&gt;Empathy and clear communication help build consumer trust around data use and protection&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:07:51</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>6</itunes:episode><itunes:title>Optimizing Consumer Trust in Compliance with Jill Cusack (Ep. 6)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Operationalizing Compliance in Your Business with Derek Buehler (Ep. 5)]]></title><description><![CDATA[<p>In this episode of Compliance Chronicles, we delve into the evolution of business and compliance and the importance of engaging business teams in compliance efforts.</p><p></p><p>Key takeaways include the concept of compliance as everyone's job and the criticality of solid market identification.</p><p></p><p></p>]]></description><guid isPermaLink="false">03cda635-f557-469a-a0a2-0603232307c4</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 04 Mar 2026 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/02be8bc2bc4bd1c341a279cd58175a1776a5bcf4d9aeed08f6484517aab5f48e/eyJlcGlzb2RlSWQiOiIwM2NkYTYzNS1mNTU3LTQ2OWEtYTBhMi0wNjAzMjMyMzA3YzQiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk5Yzg0NmFkZWU5MzQyNDkyYzc5YmI3L2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMi0yM19fMTctNDYtMzQubXAzIn0=.mp3" length="9585414" type="audio/mpeg"/><itunes:summary>&lt;p&gt;In this episode of Compliance Chronicles, we delve into the evolution of business and compliance and the importance of engaging business teams in compliance efforts.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Key takeaways include the concept of compliance as everyone&apos;s job and the criticality of solid market identification.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:06:39</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Operationalizing Compliance in Your Business with Derek Buehler (Ep. 5)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Overcoming Hurdles in Privacy Compliance with Donna Del-Greco (Ep. 4)]]></title><description><![CDATA[<p>Donna Del Greco, Vice President of Legal Services at SciPlay Games, shares her journey and insights into the privacy compliance space. The conversation covers her introduction to the privacy world, the challenges in navigating privacy compliance, and key advice for privacy compliance professionals.</p><p></p><p>Takeaways</p><ul><li>Data Privacy and Compliance</li><li>Challenges in Privacy Compliance<p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p></li></ul><p></p>]]></description><guid isPermaLink="false">275945af-9781-4d72-b9a6-652626cb0f7b</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 18 Feb 2026 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f3eeab319c91f0da4afa9515baa7d9f9a08d7e46823be2a279f7964c37752577/eyJlcGlzb2RlSWQiOiIyNzU5NDVhZi05NzgxLTRkNzItYjlhNi02NTI2MjZjYjBmN2IiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk2YzMzYzY4Yzc4ZWRiMTgxY2JiNWMyL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMS0xOF9fMi0xMy00Mi5tcDMifQ==.mp3" length="5615661" type="audio/mpeg"/><itunes:summary>&lt;p&gt;Donna Del Greco, Vice President of Legal Services at SciPlay Games, shares her journey and insights into the privacy compliance space. The conversation covers her introduction to the privacy world, the challenges in navigating privacy compliance, and key advice for privacy compliance professionals.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Data Privacy and Compliance&lt;/li&gt;&lt;li&gt;Challenges in Privacy Compliance&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:07:46</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><itunes:title>Overcoming Hurdles in Privacy Compliance with Donna Del-Greco (Ep. 4)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Audit Skills that Power Compliance with Katie Witt (Ep. 3)]]></title><description><![CDATA[<p>The conversation with Katie Witt covers her journey from internal audit to privacy and compliance, the skills transition from audit to privacy compliance, and the challenges and advice for navigating the compliance journey. Katie shares insights on identifying noise and important developments, balancing methodical approach with risk, and the importance of building a network within the compliance field.</p><p></p><p>Takeaways</p><ul><li>Transitioning from audit to privacy compliance</li><li>Balancing methodical approach with risk</li></ul><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p><p></p>]]></description><guid isPermaLink="false">f6bfeb8c-19be-451c-b134-4a96c0d22ea6</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 04 Feb 2026 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/55c6122b4a6dca7934c5083be71fa9e1e04b9a47f9fc6812508a7a6b7b5dbae1/eyJlcGlzb2RlSWQiOiJmNmJmZWI4Yy0xOWJlLTQ1MWMtYjEzNC00YTk2YzBkMjJlYTYiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk2YzJmZjVkZjk3MmRhZTQyMDc2MGJlL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMS0xOF9fMS01Ny0yNS5tcDMifQ==.mp3" length="6958975" type="audio/mpeg"/><itunes:summary>&lt;p&gt;The conversation with Katie Witt covers her journey from internal audit to privacy and compliance, the skills transition from audit to privacy compliance, and the challenges and advice for navigating the compliance journey. Katie shares insights on identifying noise and important developments, balancing methodical approach with risk, and the importance of building a network within the compliance field.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Takeaways&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Transitioning from audit to privacy compliance&lt;/li&gt;&lt;li&gt;Balancing methodical approach with risk&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:09:38</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><itunes:title>Audit Skills that Power Compliance with Katie Witt (Ep. 3)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Building a Global Compliance Career with Keikoh Park (Ep. 1)]]></title><description><![CDATA[<p>What does it look like to build a global ethics and compliance career from the ground up? In this episode of Compliance Chronicles, Liisa Thomas talks with Keikoh Park, former Vice President and Head of Ethics and Compliance for CBRE’s Global Program Office and longtime JLL lawyer, about how she made the leap into cross‑border compliance and never looked back.</p><p></p><p>Keikoh shares how negotiating massive multinational real‑estate deals opened her eyes to the risk buried in pages of contractual obligations—and why that curiosity led her to raise her hand for a brand‑new global compliance role. She explains the realities of international regulatory compliance, from navigating conflicting data privacy regimes to balancing cultural nuance with consistent standards, and why relationship‑building is the most underrated tool in a compliance leader’s toolkit.</p><p></p><p>You’ll hear candid lessons on job moves for long‑term growth, building credibility so you are not seen as the corporate police, and finding fulfillment in work that constantly changes with new laws, enforcement priorities, and business risks. This episode is a must‑listen for in‑house lawyers, global compliance professionals, and anyone wondering whether a lateral move into ethics and compliance could actually be the best career decision they ever make.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">824e4164-943e-4d21-a0ee-305d912267a2</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 07 Jan 2026 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a87918e1cb2f86da5ea672bada64dd433246d559a9b27e1e5f4e468e06c6306d/eyJlcGlzb2RlSWQiOiI4MjRlNDE2NC05NDNlLTRkMjEtYTBlZS0zMDVkOTEyMjY3YTIiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk1YzgyN2ZlMmY5NWEzNzI5ZmQyZmJhL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMS02X180LTMzLTE5Lm1wMyJ9.mp3" length="8694347" type="audio/mpeg"/><itunes:summary>&lt;p&gt;What does it look like to build a global ethics and compliance career from the ground up? In this episode of Compliance Chronicles, Liisa Thomas talks with Keikoh Park, former Vice President and Head of Ethics and Compliance for CBRE’s Global Program Office and longtime JLL lawyer, about how she made the leap into cross‑border compliance and never looked back.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Keikoh shares how negotiating massive multinational real‑estate deals opened her eyes to the risk buried in pages of contractual obligations—and why that curiosity led her to raise her hand for a brand‑new global compliance role. She explains the realities of international regulatory compliance, from navigating conflicting data privacy regimes to balancing cultural nuance with consistent standards, and why relationship‑building is the most underrated tool in a compliance leader’s toolkit.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;You’ll hear candid lessons on job moves for long‑term growth, building credibility so you are not seen as the corporate police, and finding fulfillment in work that constantly changes with new laws, enforcement priorities, and business risks. This episode is a must‑listen for in‑house lawyers, global compliance professionals, and anyone wondering whether a lateral move into ethics and compliance could actually be the best career decision they ever make.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:12:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:title>Building a Global Compliance Career with Keikoh Park (Ep. 1)</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Following Unique Paths to Successful Privacy Compliance with Mike Smith (Ep. 2)]]></title><description><![CDATA[<p>How do you turn a “strange path” through the Navy, fraud risk, and call centers into a successful career as a bank privacy officer and compliance leader? In this episode of Compliance Chronicles, Liisa Thomas sits down with Mike Smith, Privacy Officer at Wintrust and former HSBC leader, to unpack how he built a wide‑angle view of risk, regulation, and real‑world data use.</p><p></p><p>Mike shares how running a centralized privacy project pulled him into the field, why adding the CRCM and broader regulatory compliance responsibilities changed his career ceiling, and how he thinks about the line between smart data use and “creepiness” in financial services. You’ll hear honest reflections on burnout, finding new energy in a fast‑moving regulatory landscape, and the importance of picturing a real person at the other end of the data—whether that’s your own family member or your most vulnerable customer.</p><p></p><p>Perfect for: privacy and compliance professionals in banking and financial services, aspiring CPOs, and anyone considering a move from fraud, risk, or operations into data privacy.</p><p></p><p><b>If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.</b></p>]]></description><guid isPermaLink="false">70fdae2d-74e7-4cd3-b749-a861daeec69e</guid><dc:creator><![CDATA[Liisa Thomas]]></dc:creator><pubDate>Wed, 21 Jan 2026 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/2d2d0ef66c9ae2dc7618b2eaa72a64c592402d426ee0b0e6faa8b19dd67fd2d5/eyJlcGlzb2RlSWQiOiI3MGZkYWUyZC03NGU3LTRjZDMtYjc0OS1hODYxZGFlZWM2OWUiLCJwb2RjYXN0SWQiOiJmODJmNjk4MC1iMTVlLTQ3ZjgtYTE5NC0zOTgwODhmNGRiMTQiLCJhY2NvdW50SWQiOiI2OTFmNmY3YjIyYjMxZjcyNjdiMmJkMzYiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjk1YzdmNTg5MTZiM2ZmNmRjNzI4MjNiL2xpaXNhLXRob21hc3Mtc3R1ZGlvLWNvbXBvc2VyLTIwMjYtMS02X180LTE5LTUyLm1wMyJ9.mp3" length="8546293" type="audio/mpeg"/><itunes:summary>&lt;p&gt;How do you turn a “strange path” through the Navy, fraud risk, and call centers into a successful career as a bank privacy officer and compliance leader? In this episode of Compliance Chronicles, Liisa Thomas sits down with Mike Smith, Privacy Officer at Wintrust and former HSBC leader, to unpack how he built a wide‑angle view of risk, regulation, and real‑world data use.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Mike shares how running a centralized privacy project pulled him into the field, why adding the CRCM and broader regulatory compliance responsibilities changed his career ceiling, and how he thinks about the line between smart data use and “creepiness” in financial services. You’ll hear honest reflections on burnout, finding new energy in a fast‑moving regulatory landscape, and the importance of picturing a real person at the other end of the data—whether that’s your own family member or your most vulnerable customer.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Perfect for: privacy and compliance professionals in banking and financial services, aspiring CPOs, and anyone considering a move from fraud, risk, or operations into data privacy.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, and real‑world compliance leadership.&lt;/b&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:11:56</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/f82f6980-b15e-47f8-a194-398088f4db14/logos/04dfc19b-227e-4704-8f65-290ec15b2a90.png"/><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Following Unique Paths to Successful Privacy Compliance with Mike Smith (Ep. 2)</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>