Benjamin Dunlap ← Perspectives

Perspectives · Corporate Compliance · 19 June 2026 · 1 min

What the Company Did About the Red Flag Matters More Than the Flag

General Counsel who inherit a financial crime problem from a predecessor often face the same fundamental challenge: the documentation of what was known, when it was known, and what was done about it is incomplete.

That gap is not always the result of bad faith. It is usually the result of compliance programs that were designed to detect and report, not to investigate and document. When the regulatory inquiry arrives, or when litigation follows, the GC is left reconstructing a timeline from fragmented records, incomplete investigation files, and personnel who have since departed.

I have worked alongside General Counsel on both sides of that problem. On the front end, helping companies build investigation protocols and documentation standards that hold up under regulatory scrutiny. On the back end, helping GCs reconstruct what happened, when, and to what extent the company’s compliance program was operating as designed.

The financial crime problems that create the most legal exposure for companies are rarely the ones that were hidden intentionally. They are the ones that were visible in the data, flagged somewhere in the compliance infrastructure, and never investigated to a documented conclusion. When a regulator or opposing counsel asks what the company did when it saw the red flag, the answer matters more than the flag itself.

Across my career, I have seen this pattern across every major jurisdiction and industry sector. The companies that manage it best are the ones that treat investigation documentation as a legal asset, not a compliance checkbox.

If you are managing a financial crime matter or building out the investigative infrastructure around your compliance program, I am happy to discuss what that looks like in practice.


Benjamin Dunlap

Benjamin Dunlap

CPA · CFE · CAMS

Member: AICPA, ACFE, ACAMS

Los Angeles, California