Welcome to Compliance Chronicles!

Organizational Change Episodes

How to adapt business compliance efforts using organizational change tools
July 22, 2026

Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)

Chief Information Security Officer Shellie Dreistadt joins Compliance Chronicles with Liisa Thomas to talk about how psychology, cybersecurity, and leadership resilience come together in modern security programs. She shares her nonlinear path from psychology and call‑center leadership into information security, online banking, and ultimately her current CISO role.

Shellie explains why security sits at the intersection of people and technology, and how understanding behavior, motivati…

Listen to the Episode

July 8, 2026

Developing Effective Compliance Guardrails with Bill Connolly (Ep. 14)

Stepping into compliance “by accident,” building guardrails that actually help the business, and staying curious enough to reinvent your career—Episode 14 with Bill Connolly is packed with practical lessons for anyone in risk, privacy, or compliance leadership.

In this episode of Compliance Chronicles, host Liisa Thomas talks with Bill Connolly, Head of Resiliency Risk for the U.S. retail bank at HSBC. Bill oversees a broad risk portfolio that spans information risk, business continu…

Listen to the Episode

June 10, 2026

Successful Compliance with a Yes Before No Approach with Joe Habib (Ep. 12)

In this 12th episode of Compliance Chronicles, Liisa talks with Joe Habib, who shares insights on navigating privacy, compliance, and AI. He emphasizes the importance of understanding technology, building trust, and taking a 'yes before no' approach. His journey and advice inspire a commitment to continuous learning.

Takeaways

Understanding technology

Building trust

'Yes before no' approach

Continuous learning

If you enjoy t…

Listen to the Episode

May 13, 2026

Using Operational Change in Compliance with Kam Dodge (Ep. 10)

In this episode of Compliance Chronicles, our 10th, Kam Dodge, an in‑house leader with roots in Northwestern SESP’s Learning and Organizational Change program, explains why privacy and compliance are non‑negotiable in heavily regulated industries and introduces his “rubber balls vs. glass balls” framework for prioritizing risk. He shares how to use simple expected‑value thinking (likelihood x impact) to communicate 8‑ and 9‑figure exposure in language that boards and business leaders underst…

Listen to the Episode

April 1, 2026

Saying Yes to the Long Game in Compliance with Mark Jaffe (Ep. 7)

In episode seven, Mark Jaffe shares his journey into compliance, the importance of saying yes to opportunities, the long game of compliance, risk management, ethical decision making, lessons in compliance management, and career development and growth in the compliance space.

Takeaways

Saying yes to new challenges and opportunities is important for career growth.

Compliance is a journey, and it's important to focus on the long game and risk management.

If …

Listen to the Episode

March 18, 2026

Optimizing Consumer Trust in Compliance with Jill Cusack (Ep. 6)

In this episode, we learn from Jill Cusack about her journey as a compliance professional. She shares common challenges faced in the field and gives valuable advice for those just starting out.

Jill describes the challenge of working between two worlds: helping consumers understand what is happening with their data and helping business and technology teams understand how new products and practices affect transparency, choice, and trust. She also shares the importance of humility in c…

Listen to the Episode

March 4, 2026

Operationalizing Compliance in Your Business with Derek Buehler (Ep. 5)

In this episode of Compliance Chronicles, we delve into the evolution of business and compliance and the importance of engaging business teams in compliance efforts.

Key takeaways include the concept of compliance as everyone's job and the criticality of solid market identification.

Listen to the Episode

Feb. 4, 2026

Audit Skills that Power Compliance with Katie Witt (Ep. 3)

The conversation with Katie Witt covers her journey from internal audit to privacy and compliance, the skills transition from audit to privacy compliance, and the challenges and advice for navigating the compliance journey. Katie shares insights on identifying noise and important developments, balancing methodical approach with risk, and the importance of building a network within the compliance field.

Takeaways

Transitioning from audit to privacy compliance

Balancing…

Listen to the Episode

Jan. 21, 2026

Following Unique Paths to Successful Privacy Compliance with Mike Smith (Ep. 2)

How do you turn a “strange path” through the Navy, fraud risk, and call centers into a successful career as a bank privacy officer and compliance leader? In this episode of Compliance Chronicles, Liisa Thomas sits down with Mike Smith, Privacy Officer at Wintrust and former HSBC leader, to unpack how he built a wide‑angle view of risk, regulation, and real‑world data use.

Mike shares how running a centralized privacy project pulled him into the field, why adding the CRCM and broader …

Listen to the Episode