Q2 2026 Integrity Advocate
Compliance Controls: Only as Strong as Their Weakest Link
A recent enforcement action involving TradeStation Securities, Inc. offers an important reminder for every employee: even well-designed compliance programs can fail if the processes, controls, and technology supporting them are not properly configured, tested, monitored, and maintained. One weak link in the control chain can expose the entire compliance process.
TradeStation agreed to pay $1,110,661 to settle potential civil liability for 481 apparent sanctions violations involving customers located in Iran, Syria, and Crimea, according to the Office of Foreign Assets Control (OFAC). OFAC is a division of the U.S. Department of Treasury with the primary role of administering and enforcing economic and trade sanctions. The issue was not that the company lacked compliance controls on paper. Rather, weaknesses in testing, change management, technology configuration, and oversight caused key controls to stop working as intended.
What Went Wrong
TradeStation had multiple layers of sanctions controls, including customer screening, daily rescreening, and geo-blocking tools designed to prevent access from sanctioned jurisdictions. However, several breakdowns prevented those controls from working as intended:
- A prior mobile platform upgrade affected one geo-blocking control.
- A later cloud-related software update resulted in another control being disabled and not re-enabled.
- Automated testing intended to confirm whether those controls were working was discontinued without an effective replacement.
- The company did not promptly detect that both its compliance processes and supporting technology were no longer operating as designed.
Why This Matters to Us
This case demonstrates that compliance controls are only as effective as their day-to-day operation. Technology can strengthen a compliance program, but neither processes nor systems should be treated as “set it and forget it.” Changes to systems, platforms, workflows, vendors, responsibilities, or configurations can create unintended gaps if they are not reviewed through a strong change management process. Regular testing, validation, documentation, and oversight help ensure controls continue to function as intended—especially after upgrades, migrations, vendor changes, process updates, or other significant changes.
Warning Signs That Controls May Need Attention
Employees should remain alert to indicators that a control may no longer be operating as intended, including:
- A recent system upgrade, migration, or configuration change
- Replacement of a vendor or third-party platform
- A recurring review, test, certification, or monitoring activity that has been discontinued
- Changes in personnel, responsibilities, or ownership without corresponding process updates
- Control activities that suddenly stop generating exceptions or results
- Documentation that no longer reflects current practices
What Employees Can Do
- Confirm processes and systems are properly designed, configured, documented, and understood by the employees responsible for them.
- Test controls at appropriate intervals and after significant process, system, vendor, responsibility, or configuration changes.
- Use proper change management before controls are altered, disabled, bypassed, or replaced.
- Raise concerns promptly if a control does not appear to be working as intended or no longer aligns with the process it supports.
- Understand who owns each control, who performs it, and who is responsible for verifying that it remains effective following process or system changes.
Employees who own, support, or rely on compliance-related processes and systems should confirm that controls are properly designed, configured, tested at appropriate intervals, and reviewed after any significant change. If something does not appear to be working as expected, or if a control is disabled, bypassed, changed, or no longer aligned with the process it supports, raise the issue promptly. Effective compliance requires more than well-written policies and well-designed controls. It requires continuous ownership, testing, monitoring, and improvement. A control that exists on paper, but no longer works in practice, provides little protection when regulators come calling.
Source: Radical Compliance, “Trader Fined $1.1M on Testing, Software Snafus,” March 17, 2026.
BI&C Partners: Strengthening Our Culture of Integrity
MPC’s Compliance and Ethics (C&E) Program supports our shared commitment to integrity, transparency, and ethical decision-making by helping employees access the resources, guidance, and support they need to do the right thing every day.
A key part of this effort is our network of Business Integrity & Compliance (BI&C) Partners, who serve as local compliance and ethics ambassadors across the enterprise. They help connect employees with the Code of Business Conduct (the Code), company policies, and resources available through the C&E Program.
New BI&C Partners
We are pleased to welcome five new BI&C Partners. As trusted resources within their organizations, these Partners will help strengthen our culture of integrity and reinforce awareness of compliance and ethics expectations across the business.

Responsibilites of the BI&C Partner
- Actively look for opportunities to work with the organization and local management to increase employee awareness and understanding of the Code, Company Policies, Integrity as a Core Value, and our C&E Program.
- Assist the organization and local management to understand the disclosure and approval requirements associated with the Conflicts of Interest and Business Courtesies policies.
- Encourage the reporting of allegations to appropriate resources, including, but not limited to the Integrity Helpline.
- Reinforce the Company’s anti-retaliation policy.
- Assist BI&C with presenting compliance and ethics training.
- Act as a liaison between the organization or location and BI&C to identify specific compliance and ethics issues and determine targeted training needs; meet at least quarterly with the organization or local management.
- Promote and encourage the timely completion of the Annual Code of Business Conduct Questionnaire and Certification and answer employee questions.
- Distribute publications and other BI&C materials and help reinforce messaging, with special attention given during Corporate Compliance and Ethics Week in November.
- Provide feedback to BI&C on the effectiveness of BI&C’s strategies, communications, and training initiatives.
Who is Your BI&C Partner
Designated groups throughout the enterprise have at least one BI&C Partner supporting their area. Do you know who your group's appointed Partner is? Visit the BI&C Partner Page on MPCConnect to learn more about the Program and find out who serves this role in your group.
Connect with Your BI&C Partner
Employees are encouraged to connect with their BI&C Partner when they have questions, need guidance, or want support navigating compliance and ethics resources. Partners also play an important role in helping reinforce BI&C initiatives across the organization, making employee engagement an essential part of sustaining our culture of integrity.
As we welcome these five new Partners, we also recognize the broader BI&C Partner network and the important role it plays in supporting employees, encouraging questions, and reinforcing our shared commitment to doing the right thing. Through their continued engagement, Partners help strengthen a workplace grounded in trust, accountability, and ethical leadership.
Glad You Asked
Below is a sample of inquiries received by Business Integrity and Compliance and responses to the same.
Click arrows below to view the company response to the concern.
The Question: Would a lunch for MPC employees, held during business hours at a restaurant, be considered a “gift” that requires preapproval or disclosure?
The Answer: No. In accordance with Policy #2009 – Business Courtesies, this is considered a meal rather than a gift. A meal attended only by Company employees does not require preapproval or disclosure under the policy. However, the meal should be reasonable in costs and properly expensed and reported in accordance with Policy #3004 - Employee Business Expense and the Travel, Corporate Credit Card and Business Expense Reports Guidelines.
The Question: A third-party vendor asked whether I could serve as a reference and speak with one of its potential customers. Does MPC policy address this type of request?
The Answer: In general, employees may not participate in any testimonials, endorsements or promotions of individuals, companies, products or services in accordance with Policy #12002 - Internal and External Release of Proprietary Information. Many MPC agreements with business partners include non-publicity provisions meaning the MPC-business partner relationship is itself confidential information. Even a simple referral could therefore result in unauthorized disclosure of such relationship or other confidential information in violation of our agreements. In addition, if the intent of the referral is to garner favor for the recipient, it would make it a work-related endorsement, which would make it a violation of the current MPC policy.
Contact the Law organization before making any testimonials, endorsements or promotions related to MPC business, individuals or other companies, products, or services.
The Question: I have an update to make to my previous conflict of interest disclosure. Do I wait until the Annual Code of Business Conduct Questionnaire and Certification comes back around, or should I update it now? I tried to go on the site to update my current disclosure, but I could only find where to submit a new one.
The Answer: Outside of the Annual Code of Business Conduct Questionnaire process, Business Integrity & Compliance (BI&C) can change an existing disclosure status to "Pending" to allow for updates. Doing so will allow the employee to edit and resubmit. When changes are needed, employees should contact BI&C to ask for this modification and advise if they encounter any issues making the necessary updates or have questions regarding the disclosure process.
The Question: Is it acceptable, under Company Policy, to give a monetary gift of less than $100 to a contractor?
The Answer: No, under Policy #2009 – Business Courtesies, employees and anyone acting on behalf of the Company may not accept, offer, promise, authorize, pay for, or provide cash or cash-equivalent gifts, regardless of amount. Cash equivalents include items such as non-retail brand gift cards or certificates, pre-loaded debit cards, stocks, and bonds.
Click here to review additional inquiries and responses.
Be an Integrity Advocate
Being an advocate is about speaking up not only about what may be wrong, but also about what is going right. Examples of ethical conduct should be highlighted and celebrated!
We invite you to help expand our scope to include positive stories of integrity in action in future issues of the Integrity Advocate by submitting instances of integrity in action to Business Integrity and Compliance, Room M-01-004 Findlay Campus or [email protected].
