{"id":5535,"date":"2026-02-19T19:36:03","date_gmt":"2026-02-19T19:36:03","guid":{"rendered":"https:\/\/thelawyerworld.com\/blog\/?p=5535"},"modified":"2026-07-06T09:54:18","modified_gmt":"2026-07-06T09:54:18","slug":"corporate-compliance-rules-every-business-must-follow","status":"publish","type":"post","link":"https:\/\/thelawyerworld.com\/blog\/corporate-compliance-rules-every-business-must-follow\/","title":{"rendered":"Corporate Compliance Rules Every Business Must Follow"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">According to data analyzed by Protecht US businesses paid <strong>$345 billion in corporate fines<\/strong> between 2020 and 2024. That&#8217;s 180,000+ enforcement actions in five years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the companies that got hit the hardest? Most of them already had compliance programs. Written policies. Legal teams. Internal audits. The problem was never awareness \u2014 it was that nobody was actually doing what the policy said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.federalreserve.gov\/newsevents\/pressreleases\/enforcement20241010a.htm\" target=\"_blank\" rel=\"noopener\">TD Bank? <strong>$3.09 billion<\/strong><\/a> gone because their anti-money laundering system hadn&#8217;t been updated since 2014. Cummins? <strong>$1.675 billion<\/strong> \u2014 largest Clean Air Act fine ever \u2014 for rigging emissions software on nearly a million trucks. Meta? <strong>\u20ac1.2 billion<\/strong> from EU regulators for moving European user data into the US without proper protections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Combined bill for those three: over $6 billion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Same story each time. Leadership knew about the gaps. Chose not to fix them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That doesn&#8217;t fly anymore.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Which Compliance Failures Actually Cost the Most?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not all violations hit equally. Some get you a warning letter. Others end careers and drain billion-dollar reserves. Here&#8217;s what regulators have been going after hardest:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Area<\/strong><\/td><td><strong>Fine<\/strong><\/td><td><strong>Company<\/strong><\/td><td><strong>What Happened<\/strong><\/td><\/tr><tr><td>Anti-Money Laundering<\/td><td>$3.09B (2024)<\/td><td>TD Bank<\/td><td>92% of transactions unmonitored for a decade<\/td><\/tr><tr><td>Environmental<\/td><td>$1.675B (2024)<\/td><td>Cummins<\/td><td>Defeat devices on 630,000+ diesel trucks<\/td><\/tr><tr><td>Data Privacy<\/td><td>~$1.3B (2023)<\/td><td>Meta<\/td><td>EU user data shipped to US without GDPR protections<\/td><\/tr><tr><td>Workplace Safety<\/td><td>$50M (2024)<\/td><td>American Airlines<\/td><td>Repeated violations of disabled passengers&#8217; rights<\/td><\/tr><tr><td>Financial Reporting<\/td><td>Ongoing<\/td><td>Multiple<\/td><td>Weak SOX controls, AI audit risks climbing<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Every company on this list had a compliance department. Didn&#8217;t matter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>TD Bank Ignored Its Own AML Systems for a Decade \u2014 Here&#8217;s What That Cost<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This one&#8217;s worth understanding in detail because the failure pattern is so common.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TD Bank&#8217;s automated monitoring was supposed to catch suspicious transactions. Instead, between 2018 and 2024, it <strong>missed 92% of total transaction volume<\/strong>. That&#8217;s $18.3 trillion in activity \u2014 just&#8230; unwatched. Three criminal networks moved $670 million through the bank during that period. Five bank employees actively helped one network launder $39 million to Colombia.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why? TD&#8217;s leadership ran what they called a <strong>&#8220;flat cost paradigm.&#8221;<\/strong> Compliance budget stays the same every year. Doesn&#8217;t matter that the bank is growing, adding Zelle, expanding its customer base, entering new markets. The AML spending cap doesn&#8217;t move.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Their own internal auditors flagged this. Repeatedly. Management&#8217;s response? Gradually reduce the backlog. Not fix the system \u2014 just chip away at the pile of alerts nobody was looking at.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attorney General Merrick Garland put it bluntly: <strong>&#8220;By making its services convenient for criminals, TD Bank became one.&#8221;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The damage went beyond fines:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>$1.43 billion<\/strong> criminal penalty to the DOJ<\/li>\n\n\n\n<li><strong>$452 million<\/strong> in forfeitures<\/li>\n\n\n\n<li><strong>$1.3 billion<\/strong> civil penalty to FinCEN<\/li>\n\n\n\n<li><strong>$434 billion asset cap<\/strong> from the OCC \u2014 the bank literally can&#8217;t grow its US operations until regulators approve the fix<\/li>\n\n\n\n<li>Five years of probation. Three years of independent monitoring.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">TD originally set aside $450 million for this. The final number was nearly seven times higher.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The takeaway is uncomfortable but simple.<\/strong> When the compliance budget stays flat while the business grows, the gap isn&#8217;t theoretical. It&#8217;s guaranteed. And regulators will find it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Cummins Put Defeat Devices on 630,000 Trucks \u2014 The EPA Noticed<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cummins makes the diesel engines in RAM 2500 and 3500 pickup trucks. From 2013 to 2023, those engines had software that dialed back emissions controls during normal driving but performed perfectly during EPA testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The catch? After the Volkswagen diesel scandal in 2015, the EPA started running <strong>non-standard driving tests<\/strong> at its National Vehicle and Fuel Emissions Laboratory. Not the predictable lab simulations manufacturers prep for \u2014 actual real-world driving conditions. That&#8217;s how the defeat devices got caught.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Total bill: over $2 billion.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>$1.675 billion in civil penalties (largest Clean Air Act fine in history)<\/li>\n\n\n\n<li>$326 million+ for recall programs and emissions mitigation<\/li>\n\n\n\n<li>Must repair 85% of affected vehicles within three years<\/li>\n\n\n\n<li>Fund replacement of 27 old diesel locomotive engines<\/li>\n\n\n\n<li>Complete 50 locomotive idle-reduction projects<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Cummins said it found no evidence employees acted in bad faith. The EPA&#8217;s view? The software was designed to behave differently during testing than during real use. That&#8217;s the definition of a defeat device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Bottom line:<\/strong> Environmental compliance isn&#8217;t a one-time certification. Regulators are testing smarter now. The space between &#8220;passing the test&#8221; and &#8220;actually meeting the standard&#8221; is exactly where billion-dollar fines sit.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Meta&#8217;s \u20ac1.2 Billion GDPR Fine Started With a 2020 Court Ruling They Didn&#8217;t React To<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In 2020, the EU&#8217;s highest court struck down the Privacy Shield framework in the Schrems II decision. That ruling said US surveillance practices made standard data transfer agreements inadequate for protecting European citizens&#8217; data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meta kept transferring data anyway, relying on Standard Contractual Clauses (SCCs) that regulators had already flagged as insufficient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three years later \u2014 <strong>\u20ac1.2 billion fine.<\/strong> Largest GDPR penalty ever imposed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The European Data Protection Board described the violation as &#8220;systematic, repetitive and continuous.&#8221; Millions of Facebook users affected. Massive data volumes involved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meta&#8217;s appealing. They&#8217;ve also adopted the new EU-US Data Privacy Framework introduced in July 2023. But that framework&#8217;s survival is shaky \u2014 privacy advocate Max Schrems is preparing a &#8220;Schrems III&#8221; challenge, and the US surveillance law supporting the agreement expires in April 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What matters for every other business:<\/strong> A company headquartered in the US can face European enforcement if it handles EU data. PwC&#8217;s 2025 survey found <strong>51% of executives now rank data privacy as their top compliance risk.<\/strong> Treating international data transfers as purely an IT decision is the same bet Meta made. We know how that turned out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Data Protection Rules That Actually Apply to Your Business<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Skip the theory. Here&#8217;s what regulators enforce:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Get real consent.<\/strong> Not buried-in-terms-of-service consent. Informed, clear, opt-in consent before collecting personal data.<\/li>\n\n\n\n<li><strong>Give people control.<\/strong> GDPR and CCPA both require you to let individuals access, correct, and delete their information. This has to actually work \u2014 not just exist as a form on your website.<\/li>\n\n\n\n<li><strong>Report breaches fast.<\/strong> GDPR gives you <strong>72 hours<\/strong> from discovery. Miss that window and you&#8217;re looking at a separate penalty on top of whatever caused the breach.<\/li>\n\n\n\n<li><strong>Run privacy audits.<\/strong> Document your data processing. Know where personal data lives, who has access, and what security protects it.<\/li>\n\n\n\n<li><strong>Watch the AI angle.<\/strong> Automated decision-making, AI-powered tools processing personal data, and cross-border data sharing all create new regulatory exposure that barely existed five years ago.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What SOX and Tax Compliance Actually Require<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Public companies follow <strong>GAAP or IFRS<\/strong> depending on jurisdiction. The Sarbanes-Oxley Act adds teeth \u2014 executives are <strong>personally liable<\/strong> for the accuracy of financial statements. Not the company. The individual.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That distinction matters more than most people realise. A corporate fine hits the balance sheet. SOX liability can hit the CFO&#8217;s personal freedom.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KPMG flagged a growing risk here: <strong>AI in financial reporting.<\/strong> Companies are adopting AI tools for calculations, risk modeling, and audit support. That creates efficiency \u2014 and also introduces bias, algorithmic errors, and fraud vectors that SOX internal controls now need to cover. If your AI produces an inaccurate number and it ends up in a filing, someone&#8217;s still signing off on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tax compliance spans federal, state, and local. Multi-state operations create nexus issues \u2014 you might owe taxes in a state where you have no office but hit a revenue threshold. Miss that and the interest alone compounds fast.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>OSHA, Wages, and Worker Classification \u2014 Where Employment Law Bites<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OSHA handles physical safety \u2014 safe conditions, proper training, protective equipment. That&#8217;s the obvious part.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The less obvious part is where most penalties actually come from:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Worker misclassification.<\/strong> Calling employees &#8220;independent contractors&#8221; to dodge benefits and tax obligations. The IRS, DOL, and state agencies all investigate this, and penalties compound across every misclassified worker and every pay period.<\/li>\n\n\n\n<li><strong>Wage and hour violations.<\/strong> Overtime miscalculations, meal break violations, off-the-clock work. These get expensive fast in class action suits.<\/li>\n\n\n\n<li><strong>Recordkeeping gaps.<\/strong> Payroll records, time tracking, safety logs, training documentation, harassment complaints \u2014 all need to be maintained and accessible. Missing records are treated as evidence of the violation, not ignorance of it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For compliance professionals who want deeper legal grounding, <a href=\"https:\/\/onlinelearning.csuohio.edu\/programs\/online-jd-program\" target=\"_blank\" rel=\"noopener\">online Juris Doctor program<\/a> sharpens the ability to interpret regulations and manage legal risk. Programs like Cleveland State University&#8217;s online J.D. combine flexibility with rigorous training \u2014 their curriculum includes <strong>six residential weekends<\/strong> alongside online coursework, lawyering skills intensives, and alumni networking.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>AML and Anti-Corruption After the TD Bank Fallout<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.justice.gov\/criminal\/case\/united-states-america-v-td-bank-na\" target=\"_blank\" rel=\"noopener\">TD Bank case made the business argument for AML<\/a> investment painfully clear. But the obligations go beyond banking.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Bank Secrecy Act, USA PATRIOT Act, and FCPA<\/strong> apply to financial services, manufacturing, healthcare, and any company with international operations. The practical requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Know Your Customer (KYC)<\/strong> during onboarding \u2014 verify identities, assess risk profiles<\/li>\n\n\n\n<li><strong>Transaction monitoring<\/strong> for suspicious patterns \u2014 not a static system set up once and ignored for eight years<\/li>\n\n\n\n<li><strong>Suspicious Activity Reports (SARs)<\/strong> filed when red flags appear<\/li>\n\n\n\n<li><strong>Anti-bribery policies<\/strong> covering kickbacks, conflicts of interest, and third-party vendor relationships<\/li>\n\n\n\n<li><strong>Regular risk assessments<\/strong> that actually change what the company does, not just produce a report<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">US regulators issued <strong>$4.3 billion in financial penalties in 2024 alone.<\/strong> Bank-specific penalties surged 522% year over year. Transaction monitoring fines doubled. That trajectory isn&#8217;t slowing down.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Environmental Compliance Is Shifting \u2014 But EPA Enforcement Isn&#8217;t<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two things happening at once here, and they point in opposite directions.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>On one side:<\/strong> The EPA settled the largest Clean Air Act penalty in history with Cummins. Air permits, discharge limits, hazardous materials handling \u2014 all actively enforced with real financial consequences.<\/li>\n\n\n\n<li><strong>On the other:<\/strong> In March 2025, the SEC voted to <strong><a href=\"https:\/\/www.sec.gov\/newsroom\/press-releases\/2025-58\" target=\"_blank\" rel=\"noopener\">stop defending rules<\/a><\/strong> that would&#8217;ve required companies to disclose climate-related emissions and risks. Industrial lobbying groups and Republican state attorneys general argued the rules overstepped the SEC&#8217;s authority. The case is pending in the US Court of Appeals.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So mandatory climate disclosure? Uncertain. EPA enforcement of existing environmental law? Unchanged and, if anything, escalating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many companies are hedging by adopting <strong>voluntary sustainability goals<\/strong> \u2014 driven by investors, supply chain partners, and customers rather than regulation. That approach works regardless of how the SEC case resolves.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to Build a Compliance Program That Doesn&#8217;t Just Exist on Paper<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every company in the case studies above had compliance on paper. The gap was between the document and the reality. Based on the 2024 enforcement patterns, the programs that actually survive regulatory scrutiny share a few things:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Budget that grows with the business.<\/strong> TD Bank&#8217;s compliance budget stayed flat for years while everything else grew. That&#8217;s the single most cited failure in the DOJ&#8217;s findings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Systems that get updated.<\/strong> Cummins used software that behaved differently in tests. TD Bank&#8217;s transaction monitoring was frozen since 2014. Old technology creates risk faster than old policies do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cross-border legal awareness.<\/strong> Meta got hit by EU regulators enforcing European law against a US company. If you handle international data or transactions, single-jurisdiction compliance isn&#8217;t enough.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Personal accountability at the top.<\/strong> SOX makes executives liable. The DOJ clawed back TD Bank&#8217;s CEO bonuses. Individual consequences change behaviour faster than corporate fines.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reviews triggered by events, not just calendars.<\/strong> Annual audits are a floor. New products, market expansions, regulatory changes, and acquisitions all need immediate compliance assessment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The compliance training market itself tells this story. According to Mordor Intelligence, global spending hit <strong>$6.15 billion in 2025<\/strong>, projected to reach <strong>$9.02 billion by 2030<\/strong> at a 7.96% CAGR. Companies aren&#8217;t spending more because compliance got easier. They&#8217;re spending more because they&#8217;ve watched what happens to companies that don&#8217;t.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Frequently Asked Questions<\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1771529372647\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><strong>What are the real consequences beyond fines?<\/strong><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Fines are actually the easier part. TD Bank&#8217;s $434 billion asset cap means they can&#8217;t grow US operations until regulators approve \u2014 that potentially costs more than the $3 billion penalty over time. Beyond financial hits: lawsuits, lost licenses, criminal charges against individual executives, reputational damage, investor flight, and increased regulatory surveillance going forward. Repeat violators get watched much more closely.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1771529379918\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><strong>How often should compliance programs get reviewed?<\/strong><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Once a year at minimum. But the real answer is: every time something significant changes. New product launch? Review. Entering a new market? Review. Regulatory change in any jurisdiction you operate in? Review. TD Bank&#8217;s monitoring sat untouched for eight years while they added Zelle and peer-to-peer payments. That&#8217;s the exact gap enforcement targets.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1771529382938\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><strong>Small businesses don&#8217;t need enterprise-level compliance&#8230; right?<\/strong><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>The scope is different. The legal obligation isn&#8217;t. Small businesses face the same core requirements around taxes, employment law, workplace safety, and data protection. Some simplified reporting exists, but wage laws, anti-discrimination rules, and breach notification requirements apply regardless of size. Professional compliance guidance almost always costs less than the violation it prevents.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\"><strong>References<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Fenergo \u2014 2024 Global Financial Institution Enforcement Actions Analysis:<a href=\"https:\/\/resources.fenergo.com\/newsroom\/fenergo-study-regulatory-penalties-in-north-america-account-for-95-of-global-financial-penalties-in-2024\" target=\"_blank\" rel=\"noopener\"> fenergo.com<\/a><\/li>\n\n\n\n<li>FinCEN \u2014 Record $1.3 Billion Penalty Against TD Bank:<a href=\"https:\/\/www.fincen.gov\/news\/news-releases\/fincen-assesses-record-13-billion-penalty-against-td-bank\" target=\"_blank\" rel=\"noopener\"> fincen.gov<\/a><\/li>\n\n\n\n<li>US EPA \u2014 2024 Cummins Inc. Vehicle Emission Control Violations Settlement:<a href=\"https:\/\/www.epa.gov\/enforcement\/2024-cummins-inc-vehicle-emission-control-violations-settlement\" target=\"_blank\" rel=\"noopener\"> epa.gov<\/a><\/li>\n\n\n\n<li>European Data Protection Board \u2014 \u20ac1.2 Billion Fine for Meta\/Facebook:<a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2023\/12-billion-euro-fine-facebook-result-edpb-binding-decision_en\" target=\"_blank\" rel=\"noopener\"> edpb.europa.eu<\/a><\/li>\n\n\n\n<li>Protecht USA \u2014 Analysis of 180,000+ US Corporate Fines 2020\u20132024:<a href=\"https:\/\/www.protechtgroup.com\/en-us\/blog\/the-most-costly-corporate-mistakes\" target=\"_blank\" rel=\"noopener\"> protechtgroup.com<\/a><\/li>\n\n\n\n<li>Mordor Intelligence \u2014 Global Corporate Compliance Training Market Size and Forecast<\/li>\n\n\n\n<li>PwC \u2014 2025 Global Risk Survey: Technology Compliance Risks<\/li>\n\n\n\n<li>KPMG \u2014 AI in Financial Reporting and SOX Compliance<\/li>\n\n\n\n<li>Cleveland State University \u2014 Online Juris Doctor Program Details<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>According to data analyzed by Protecht US businesses paid $345 billion in corporate fines between 2020 and 2024. That&#8217;s 180,000+ enforcement actions in five years. And the companies that got hit the hardest? Most of them already had compliance programs. Written policies. Legal teams. Internal audits. The problem was never awareness \u2014 it was that nobody was actually doing what the policy said. TD Bank? $3.09 billion gone because their anti-money laundering system hadn&#8217;t been updated since 2014. Cummins? $1.675 billion \u2014 largest Clean Air Act fine ever \u2014 for rigging emissions software on nearly a million trucks. Meta? \u20ac1.2<\/p>\n","protected":false},"author":7,"featured_media":5537,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[479],"tags":[],"class_list":["post-5535","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-employment"],"_links":{"self":[{"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/posts\/5535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/comments?post=5535"}],"version-history":[{"count":2,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/posts\/5535\/revisions"}],"predecessor-version":[{"id":6444,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/posts\/5535\/revisions\/6444"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/media\/5537"}],"wp:attachment":[{"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/media?parent=5535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/categories?post=5535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thelawyerworld.com\/blog\/wp-json\/wp\/v2\/tags?post=5535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}