Trust and Goodwill on the Balance Sheet

We often think of the balance sheet as a precise, quantitative snapshot of a company’s financial position. Cash, receivables, liabilities—clear, measurable, and defined. But one line item has always stood apart: goodwill.

Traditionally, goodwill is described as an intangible asset—something that arises during an acquisition when the purchase price exceeds the fair value of identifiable net assets. In simpler terms, it captures elements like brand strength, customer relationships, and reputation. But at its core, goodwill represents something even more fundamental: trust.

And increasingly, companies are learning that trust—and therefore goodwill—is not just a static, quantitative figure. It is a living, qualitative force that can materially impact enterprise value.

Goodwill, in effect, is the market’s belief in an organization. It is customers choosing your brand over another. It is stakeholders giving you the benefit of the doubt. It is employees aligning with your culture and purpose. This trust becomes embedded within the organization, internalized through behavior, decision-making, and corporate culture.

But here’s the challenge: while goodwill is recorded as a number, it is built—and destroyed—through qualitative factors.

Trust can erode gradually. Consider a company that slowly compromises on product quality or customer service. There is no single catastrophic event, but over time, customers drift away, loyalty weakens, and the brand loses its edge. The balance sheet may still show goodwill, but its real-world value is quietly declining.

Alternatively, trust can disappear almost instantly. A regulatory breach, a compliance failure, or an ethical lapse can undo years—sometimes decades—of reputation building. We’ve all seen examples where firms faced significant fines or public scrutiny due to supervisory failures or governance breakdowns. In those moments, goodwill is no longer an abstract accounting entry—it becomes a very real loss of confidence.

This raises an important question: Is goodwill truly a quantitative measure, or is it a quantitative reflection of qualitative realities?

Arguably, it is the latter.

The number on the balance sheet attempts to capture something inherently human—trust, perception, belief. These are shaped by leadership decisions, risk culture, and governance frameworks. They are not easily measured, yet they are critically important.

For risk management and compliance officers, this is where the conversation becomes highly relevant.

Traditionally, risk and compliance functions have focused on preventing downside—ensuring adherence to regulations, mitigating exposure, and avoiding penalties. But in today’s environment, their role is expanding. They are not just protectors of value; they are stewards of trust.

A strong compliance culture reinforces ethical behavior. Effective risk management promotes transparency and accountability. Together, they help sustain the very factors that underpin goodwill.

In other words, trust is not just a byproduct of good governance—it is an outcome that can be actively managed.

And when trust is present, it creates tangible value. Customers remain loyal. Investors stay confident. Regulators engage constructively. Employees take pride in where they work. All of this contributes to a stronger, more resilient organization.

So, while goodwill may sit quietly on the balance sheet, its true significance lies beyond the numbers. It reflects the cumulative impact of countless qualitative decisions made across the business.

The real question for organizations is not how to measure goodwill—but how to maintain and grow the trust that defines it.

Because once trust is lost, the accounting adjustment is often the least of your concerns.

My goal is to help close the gap between corporate governance and risk/compliance management — work I’ve focused on for years and don’t believe happens in isolation. If this resonates, or doesn’t match your own experience, I’d like to hear about it. Leave a comment, or send me a direct message if you’re working through a governance or compliance challenge of your own.

You Manage a Process. You Lead People.

In some was, in a complicated world, sometimes it’s good to get back to basics.

Somewhere along the way, a lot of us in compliance and risk started using the word “manager” for everything. We manage risk. We manage compliance. We manage the file, the audit, the relationship. And because the word gets used so often, it’s easy to let it bleed into how we think about the people on our team.

But here’s the distinction I keep coming back to, especially after 25-plus years in this work: you manage a process. You lead people.

Compliance is a process. It has steps, controls, documentation, deadlines, and reviews. It can — and should — be managed. Tightened. Measured. Improved.

Your compliance staff is not a process. They are not a checklist item. And when we start treating them like one — tracking their output the same way we track a control, correcting them the same way we’d patch a gap in a procedure — we lose the thing that actually makes a compliance function work: people who care enough to do it well when no one is watching.

I think this is where a lot of well-intentioned compliance leaders quietly go wrong. They are excellent at managing the process. Deadlines get hit. Reports get filed. Audits get passed. And they assume that because the process is running well, the leadership is happening too.

It isn’t the same thing.

A managed process produces compliance on paper. A led team produces a culture where people flag the thing before it becomes a problem, ask the hard question in the meeting, and stay motivated to do careful, unglamorous work because they believe it matters — not because a KPI told them to.

Your compliance staff doesn’t need someone to manage their output. They need someone who develops them, trusts them, has hard conversations with them when it counts, and shows them why this work matters beyond the audit trail. That’s leadership. And it’s a different skill set than process management, even though we often ask one person to do both — usually without ever separating the two in our own heads.

So here’s the question I’d ask any CCO, risk manager, or executive reading this: when you think about your team, are you managing them or leading them? And if you’re honest, would your team say the same thing?

Why Post

I post because these challenges deserve more conversation, not less. What you read here comes from my own experience, the experiences of others, and what I continue to learn through research and literature.

My goal is to help close the gap between corporate governance and risk/compliance management — work I’ve focused on for years and don’t believe happens in isolation. If this resonates, or doesn’t match your own experience, I’d like to hear about it. Leave a comment, or send me a direct message if you’re working through a governance or compliance challenge of your own.

Making compliance easy

Lately I’ve been thinking a lot about friction — and how much it shapes whether things actually get done.

I recently replaced my road bike with a gravel bike, mostly to scratch the itch of getting back out on the roads and trails. But getting out the door still takes effort: checking tire pressure, finding the right gear, staying hydrated. So I made one small change — everything I need lives in one spot. Bike shoes stay with the bike, not tangled up with my running or hiking gear. Small fix, but it removes just enough friction that I actually get out there more.

It got me thinking about compliance and risk management. Policies and procedures often stretch across dense volumes that are hard to navigate and harder to apply in the moment. So I’ll ask the question I keep coming back to: what are we doing to make compliance easy? Is there a real focus on reducing the friction to do the right thing — not just writing the rules, but designing the experience around following them?

My take: it starts with the interface. The way people actually interact with compliance and risk day to day. If we want better adherence, we have to make the easy path and the compliant path the same path.

A few ideas on how to get there:

1. Design for the moment of decision, not the policy binder. Surface the one relevant rule at the point someone needs it, instead of expecting them to go find it in a 200-page document.

2. Explain the “why,” not just the “what.” Pair each rule with the concept or risk it’s actually protecting against. People follow principles they understand far more consistently than instructions they don’t.

3. Turn policy into a checklist, not prose. A five-step checklist gets followed. A dense paragraph gets skimmed, or skipped entirely.

4. Make the compliant option the default option. If the system is pre-configured to do the right thing, people don’t have to remember to choose it.

5. Give real-time, plain-language feedback. Tell people when something’s off before they submit, not weeks later in an audit finding.

6. Keep everything in one place. Just like my bike gear — if the forms, guidance, and approvals someone needs are scattered across five systems, they’ll find a workaround. One home for the task removes the excuse to skip it.

Reducing friction isn’t about lowering the bar. It’s about making sure the bar is easy to clear.

Why Post

I post because these challenges deserve more conversation, not less. What you read here comes from my own experience, the experiences of others, and what I continue to learn through research and literature.

My goal is to help close the gap between corporate governance and risk/compliance management — work I’ve focused on for years and don’t believe happens in isolation. If this resonates, or doesn’t match your own experience, I’d like to hear about it. Leave a comment, or send me a direct message if you’re working through a governance or compliance challenge of your own.

Psychological Safety in Compliance and Risk Leadership

The workplace feels different today.

Whether it is “forced” return-to-office mandates, restructuring, increasing regulatory pressure, economic uncertainty, or evolving expectations around work-life balance, organizations are navigating an environment filled with tension and change.

For Compliance and Risk leaders, this creates a unique challenge.

Our role often requires difficult conversations, uncomfortable decisions, escalation of issues, and supervisory oversight that can materially impact someone’s career, compensation, or reputation. Yet at the same time, we are expected to create an environment where people feel psychologically safe.

That balance is not easy.

Psychological safety does not mean avoiding accountability or difficult decisions. It does not mean lowering standards or ignoring regulatory responsibilities. In fact, in compliance and risk management, strong oversight is essential.

Psychological safety means people feel safe enough to speak up.

It means advisors feel comfortable bringing forward concerns before they become regulatory problems. Staff feel comfortable conducting supervision without fear of retaliation. Employees can admit mistakes, ask questions, challenge assumptions, and escalate issues without worrying that doing the “right thing” will damage their standing.

In highly regulated environments, this may be one of the most important leadership responsibilities we have.

Because when people stop speaking up, risk grows in silence.

Many of today’s workplace challenges make psychological safety harder to maintain. Return-to-office policies may create frustration or resentment. Increased workloads and cost pressures can create burnout. Constant organizational change can create uncertainty and distrust.

During these periods, leadership behaviours matter even more.

Historically, compliance leaders may have been evaluated primarily on technical knowledge, regulatory expertise, and control frameworks. Those skills remain critical, but today there is an increasing need for leadership capabilities that may not have been emphasized to the same extent in the past.

Skills such as:

  • Emotional intelligence
  • Active listening
  • Consistency under pressure
  • Transparency in decision-making
  • Calm communication during conflict
  • Empathy without compromising standards
  • The ability to create trust while still maintaining accountability

People do not expect leaders to make every decision they agree with.

But they do expect fairness, honesty, and respect.

Psychological safety is created through consistency. It is built in small moments over time.

It comes from how leaders react when someone raises a concern.
It comes from whether employees feel heard during disagreement.
It comes from whether mistakes become learning opportunities or public punishments.
It comes from whether supervision is viewed as supportive guidance or purely enforcement.

Culture is shaped by what leadership repeatedly reinforces.

If leaders reward silence, defensiveness, or fear-based management, those behaviours permeate the organization quickly. But if leaders encourage respectful challenge, thoughtful discussion, and early escalation of concerns, those behaviours also become embedded in the culture.

One of the strongest indicators of a healthy compliance culture is whether people are willing to bring forward bad news early.

That only happens when trust exists.

For Compliance and Risk leaders, fostering psychological safety also requires self-awareness. We need to continually evaluate how we respond under pressure. Do we become reactive? Defensive? Impatient? Do people leave conversations feeling smaller, or supported?

Leadership in risk and compliance has always required technical competence. Increasingly, it also requires emotional discipline.

The reality is that organizations will continue to face pressure, disruption, and difficult decisions. Compliance leaders will still need to deliver unpopular messages, enforce standards, and make hard calls.

But the strongest leaders will be those who can do all of that while still creating an environment where people feel respected, heard, and safe enough to speak openly.

Because in compliance and risk management, psychological safety is not simply a cultural advantage.

It is a risk management control.

Change is inevitable, How about Risk Management?

Change is inevitable has been the corporate mantra for years, and is often framed as a strategy exercise, a technology upgrade, or an operational improvement initiative. But for risk managers, change represents something deeper which is uncertainty introduced into systems, people, culture, and decision-making processes.

In my view, now more that ever with the advances in AI technology, change management effectiveness is critical.

Every meaningful change will carry risks. How many corporate changes are you aware of that have failed the corporate culture or negatively changed public perceptions of the company?

Sometimes the risk is obvious such as regulatory breaches, operational disruption, financial loss, or reputational damage. Other times the risk is less visible foe example  loss of institutional knowledge, employee disengagement, weakened controls, poor communication, or leadership fatigue.

Ironically, organizations that avoid change can also create significant risk to themselves. Markets evolve, client expectations shift, technology advances, and regulatory environments become more complex. Standing still is rarely a neutral decision.

This places risk managers in an interesting position.

Historically, risk professionals have sometimes been viewed as the people who hinder or slow things down, identify obstacles, or challenge new initiatives. In reality, effective risk managers should help organizations navigate change safely and intelligently — not prevent progress.

The role is not to eliminate risk entirely. It is to get and be involved in the process to understand it, quantify or qualify it where possible, and help leadership make informed decisions.

During periods of change, risk managers need to pay particular attention to a few areas:

• Are controls keeping pace with operational changes?
• Is communication clear and consistent across teams?
• Have roles and responsibilities shifted without proper oversight?
• Are assumptions being challenged, or simply accepted because of urgency?
• Is organizational culture supporting the change, or quietly resisting it?

One of the greatest risks in change management is overconfidence. The leadership of the organizations  will often focus heavily on the technical or financial aspects of a project while underestimating the human element. Resistance, uncertainty, and communication breakdowns can derail even well-designed initiatives.

At the same time, change can create tremendous positive opportunities.

Good leaders will have a well-managed change process that can strengthen governance, modernize processes, improve accountability, enhance culture, and create competitive advantages. Some of the strongest organizations are not those that avoid disruption, but those that adapt effectively while maintaining discipline and trust.

For leaders and risk managers alike, a few leadership skills become especially important during times of change.

First is communication. People rarely resist change simply because it is new; they resist uncertainty and lack of clarity. Leaders who communicate openly, consistently, and honestly tend to build stronger trust during transitions.

Second is adaptability. Risk managers cannot rely solely on historical experience or “the way things have always been done.” Effective risk leaders remain open to new information, evolving risks, and alternative perspectives while maintaining sound judgment.

Perhaps the real value of risk management during change is not acting as a barrier but acting as a stabilizing influence by helping organizations move forward with awareness, discipline, and confidence.

Because change itself is not the risk, failing to understand and manage it is.

Why Post

The idea behind postings on this platform is to ask questions. Also, hopefully provide ideas, concepts or thoughts that highlight the challenges facing risk and compliance managers in the corporate governance structure. These postings are based on my personal experience, the experiences of others, and developing my understanding of the many leadership challenges, through publications and literature.

It’s my desire to help close the perceived negative gaps between corporate governance and risk/compliance management. There are ways and means to enhance the relationship, which I’ve focused on for several years. Direct message me for additional information on how to create a collaborative governance environment