Client Alerts & Insights
Pragmatic Regulatory Compliance for Global Risk
June 11, 2025
Authored By:
Geopolitical risks to supply chains are top of mind across C-suites, but few say what it means. The term “geopolitical risk” has largely become a code word for import, export, and economic sanctions compliance. The fast pace of change in 2025 requires adopting meaningful compliance structures that achieve results. It is no longer acceptable to simply rely on a “policy” that collects dust. Today thoughtful compliance structures are mission-critical for making sure sales and deliveries occur, payments are received, supply is not interrupted, investors are happy, and negative headlines are avoided.
Now is the time to think strategically about developing quality compliance programs that empower personnel in procurement, sales, shipping, and logistics roles to do the right thing and protect the company. Four keys to successful compliance structures can help deliver results.
1) Risk Assessment and Awareness
Every supply chain has unique compliance risks. Those are driven by footprint, industry sector, and types of third-party relationships. Some companies will face very real forced labor risk for import compliance, critical technology risk for export compliance, sanctions risk for financial transactions with foreign relationships, and many others. A good kicking-off point is to conduct a preliminary risk assessment followed by awareness training. Lack of awareness for company-specific risks has become acute among many internal teams, suppliers and customers, and supply chain service providers. Recent tariff changes and the Ukraine War have made this painfully clear to many supply chains.
2) Roles and Responsibilities
Getting the right team around enterprise-wide compliance, and at appropriate roles within business units, is as important as identifying incidents and managing through those. If there are red flags or concerns, then clarity on how to escalate those, and to whom, is half the battle. We are living in a “see something say something” environment. The other half of the battle is that compliance leadership or outside counsel will swiftly resolve any concerns from personnel or investigate whether or not a violation occurred. In most cases learnings can be found to improve ongoing processes even if there is no violation. If there are material issues, then corrective actions can be implemented and voluntary disclosures can be considered to mitigate risk of civil penalties. This exercise also produces valuable documentation to defend against government investigation.
3) Risk-Appropriate Compliance Processes
Compliance is a process. It must begin, and it never ends. It is essential to create behaviors and resources that maintain awareness of rules and red flags for the existing team and new hires as well as for responding to global changes. The toolbox for business operations compliance is full: appropriate compliance policies, internal and external training resources, processes for risk and role specific functions like sales or shipping, consolidated classification of HTS codes for imports and ECCN codes for non-military exports, and automated sanctions screening functionality in company ERPs and operating systems. Compliance personnel must determine which mix of tools is best for managing compliance without unreasonably restricting business. This is not a one-size-fits-all problem. If done well, then a thoughtful foundational compliance program can grow and change to meet the evolving company relationships, footprint, and trade lanes.
4) Procurement and Sales Teams
The golden rule of compliance is to avoid self-blinding. Procurement and sales professionals are on the leading edge of defense against regulatory violations, quality assurance, and financial risk. Targeted questions on the front end can be as helpful in recognizing geopolitical risk as assessing credit is for financial performance. Developing thoughtful onboarding processes can ensure that responsible due diligence occurs before sending or taking a purchase order. Every supply chain is different, but key questions can include: company demographics like top leaders and ownership, company footprints around the world, company affiliates, credit ratings, and banks through which the company will pay or get paid. Those onboarding records yield party names and fact patterns for screening.
Jonathan Todd is Vice Chair of Benesch’s Transportation & Logistics Practice Group. He may be reached at 216.363.4658 and jtodd@beneschlaw.com.
Latest News
DOJ’s National Fraud Enforcement Division Issues Corporate Enforcement Directive, Signaling Heightened Scrutiny of Corporate Fraud
DOJ’s new enforcement framework reinforces that corporate fraud investigations will remain a significant enforcement priority, particularly in healthcare, government contracting, tax and international trade.
Lessons from Kai Spears v. The New York Times Co.: A Historic Defamation Verdict
The first defamation verdict against The New York Times in more than 50 years highlights the significant litigation risks that can arise when reporting relies on inadequately vetted anonymous sources and critical editorial safeguards are not followed.
Back To Wright Line: NLRB Resets Standards for Workplace Misconduct
Employers have regained greater flexibility to address offensive or abusive employee conduct that occurs during union activity or other activity protected by the National Labor Relations Act. On September 23, 2026, the National Labor Relations Board (the “Board”) issued a significant decision in Lion Elastomers LLC, 375 NLRB No. 41, restoring the prior standard for evaluating discipline when employee misconduct occurs during protected concerted activity from General Motors LLC, 369 NLRB No. 127.
Can an Algorithm Commit a Tort? The Circuit Split Over Section 230
A growing circuit split is reshaping the scope of Section 230 immunity. While the Fourth and Ninth Circuits continue to view algorithmic recommendations as protected publisher conduct, the Third Circuit has taken a narrower approach, holding that certain algorithm-driven content recommendations may constitute a platform’s own conduct and therefore fall outside Section 230’s protections.