When governance falters, financial crime exposure mounts, or regulators shift from inquiry to enforcement, institutions need more than advice. They need seasoned judgment. Thirty years across a Fortune 10 enterprise, the Hawaii Attorney General’s Department, and U.S. Army JAG Corps have shaped an advisory practice built for precisely those moments.
Fortifying board governance structures, committee charters, oversight frameworks, and director accountability. Practical counsel on fiduciary duty, board-management dynamics, and navigating governance crises with confidence.
Converting examination findings, consent orders, and MRAs into structured, executable remediation plans. Strategic counsel on regulator engagement, examination readiness, and positioning for sustainable compliance.
Designing, remediating, and maturing enterprise AML, OFAC, sanctions, and transaction monitoring programs. BSA/AML compliance leadership and investigative governance for institutions under regulatory scrutiny.
Constructing and strengthening ERM frameworks that align risk appetite with board reporting, executive accountability, and operational risk ownership across complex, multi-jurisdictional organizations.
International regulatory strategy, FCPA counsel, and multi-jurisdictional compliance integration for organizations operating across the U.S., Canada, and global markets where regulatory boundaries intersect.
Stepping in as interim Chief Governance Officer, Chief Risk Officer, or Chief Compliance Officer during leadership transitions, remediation periods, or organizational restructuring; with immediate operational authority.
Governance is not a compliance function. It is the discipline through which organizations make better decisions. Too often, governance is reduced to policies, committees, reporting structures, and regulatory obligations. These are important, but they are not governance. They are artifacts of governance. The true purpose of governance is to improve the quality of executive decision making by creating clarity of accountability, aligning authority with responsibility, and ensuring that critical enterprise decisions are made with appropriate insight, challenge, and oversight.
My advisory practice is founded on a simple proposition: organizations do not fail because they lack policies. They fail when the relationships that connect strategy, risk, operations, technology, finance, compliance, and leadership become fragmented. Governance is the operating discipline that brings those relationships back into alignment.
The object of governance is not merely the enterprise itself, but the network of decisions, dependencies, and accountabilities that determine whether strategy succeeds or fails. As organizations become increasingly interconnected through artificial intelligence, digital platforms, outsourcing, strategic partnerships, and global regulatory obligations, governance must evolve beyond traditional organizational boundaries. Effective governance provides executive leaders with the confidence to make better decisions in increasingly complex environments.
That philosophy shapes my advisory practice itself. Rather than treating governance, legal, risk, compliance, and technology as independent disciplines, my practice integrates them into a coherent executive decision framework that strengthens resilience, accelerates responsible innovation, and protects long-term enterprise value.
My practice advises boards, executive leadership, and organizations confronting transformational change, heightened regulatory expectations, complex risk environments, and emerging technologies. The work focuses on designing governance systems that strengthen executive decision making while integrating legal, enterprise risk, compliance, operational oversight, and strategic execution into a unified governance model.
Whether advising multinational corporations, regulated financial institutions, healthcare organizations, government agencies, or emerging companies, the objective remains consistent: to help leadership navigate complexity with confidence by transforming governance into a strategic business capability rather than an administrative obligation.
Steered enterprise risk matters involving insurance reserve exposures exceeding $150 million, providing executive leadership at a Fortune 50 multinational insurer with decisive risk counsel and regulatory positioning at the highest institutional level.
Architected litigation strategy on a $100 million insurance coverage dispute, achieving a complete defense verdict affirmed on appeal, shielding the enterprise balance sheet and preserving its regulatory standing.
Provided executive risk counsel to insulate stakeholders from severe structural liability while successfully aligning developers, contractors, and insurers to mitigate catastrophic financial exposure.
Delivered governance and operational counsel directly to flag officers, ambassadors, and multinational commanders across U.S. Pacific Command, advising at the highest echelon in a complex, multi-nation environment.
Directs capital governance frameworks and public fund fiduciary oversight to safeguard taxpayer resources for a Texas political subdivision. Secures critical regional public safety contracts while ensuring strict property tax levy compliance and statutory transparency.
Deploy elite regulatory strategy and high-stakes comprehensive frameworks to deliver results across five heavily regulated sectors.
Trusted counsel to boards, executive leadership, and regulated organizations on enterprise governance, strategic risk, regulatory transformation, and financial crime compliance. Engagements include Promontory Financial Group, Capital One, ESyPet Corporation, Live Healthy Imaging, and LegalEASE.
Board leadership and fiduciary stewardship for a Texas political subdivision, with governance accountability spanning emergency services, public finance, capital investment, and community resilience.
Senior governance and enterprise risk leader at one of the world’s preeminent global insurers; overseeing matters involving $150M+ reserve exposures, international regulatory expansion, and strategic technology governance across cloud, AML, OFAC, FCPA, and PCI DSS.
Provided governance, operational risk, and strategic counsel to senior military leadership. Briefed flag officers, ambassadors, and multinational commanders on mission-critical matters throughout U.S. Pacific Command.
Legal and regulatory counsel to senior government officials on utility regulation, consumer protection, and critical infrastructure oversight; representing the Hawaii Consumer Advocate before the Public Utilities Commission.
Practical perspectives on the regulatory, governance, and financial crime issues confronting boards and executive leadership, as drawn from three decades advising from within complex regulatory environments.
Traditional governance frameworks were designed to govern a single institution. Today, the most significant governance risks arise between institutions operating across shared technologies, outsourced services, and interconnected ecosystems.
The Enterprise Governance Operating System (EGOS™) is a technology-neutral governance architecture designed specifically for this new operating environment. It provides a governance architecture that coordinates authority, accountability, trusted information exchange, and operational execution across legally independent but operationally interdependent enterprises.
Every governance challenge spanning multiple independent enterprises ultimately reduces to three fundamental questions: Who decides? What information can be shared? How is coordinated execution achieved? EGOS™ organizes ecosystem governance around these three foundational dimensions.
EGOS™ does not replace an internal governance framework. It extends it. As enterprise success becomes increasingly dependent on external partners and interconnected ecosystems, governance must extend beyond organizational boundaries. EGOS™ provides the architecture to manage cross-enterprise relationships, critical dependencies, and shared decision-making delivering stronger performance, greater resilience, and deeper trust.
See EGOS™ applied to a live governance challenge in Tokenized Banking Is Not a Technology Problem, below.
During a crisis, every major participant brings independent, specialized expertise to the table:
Yet one question is rarely asked in the executive session: Who is independently advising the Board?
Boards carry the ultimate, non-delegable fiduciary responsibility for oversight. But in a high-stakes event, directors rarely suffer from a lack of information. They suffer from a lack of integrated synthesis.
Legal counsel evaluates legal exposure. Auditors assess the financials. Forensic specialists reconstruct events. Each view is valuable; but none is structurally responsible for connecting those dots through the lens of the Board’s fiduciary duties.
This information asymmetry is where governance failures happen. When critical data stays siloed, Boards cannot exercise meaningful challenge before irreversible decisions are made.
The fix is not another policy, committee, or layer of operational legal review. Progressive organizations are instead adopting a surgical, just-in-time advisory role: Independent Board Governance Counsel.
This function is broader than traditional legal representation. Its sole client is the Board’s fiduciary mission. It does not replace management, the General Counsel, or external auditors, it complements them.
Activated during significant governance events, independent governance counsel helps directors:
As enterprise risk grows more interconnected and regulatory penalties more severe, governance infrastructure must evolve alongside it.
Every other participant in a corporate crisis has independent representation. The Board deserves the same: independent, integrated expertise that protects the enterprise balance sheet and delivers impeccable fiduciary decisions.
Boards of Trustees have long borne the fiduciary responsibility for institutional oversight. What has fundamentally shifted is the sheer complexity of the global environment in which that responsibility must now be exercised. The Anti-Money Laundering Act (AMLA) must therefore be understood not simply as financial sector legislation, but as a critical milestone in the ongoing evolution of higher education corporate governance.
Institutions that respond by merely expanding baseline compliance activities may satisfy today’s minimal regulatory expectations. Universities that strengthen governance itself will safeguard their institutions against tomorrow’s structural vulnerabilities.
Every significant regulatory reform eventually forces trustees to confront a deeper question than the language of the legislation itself. In past decades, shifts in federal funding accountability reshaped institutional transparency. Later, heightened data privacy mandates transformed campus risk governance. Today, the AMLA is reshaping board-level oversight of financial crime risk.
The practical implication extends well beyond standard compliance programs. It challenges trustees to examine whether their governance systems can anticipate emerging threats, integrate fragmented risk information across university silos, and exercise meaningful oversight across sprawling international research operations, satellite campuses, and multi-million-dollar advancement campaigns.
The question before a University Board is no longer whether management has implemented a baseline anti-money laundering protocol. The real question is whether the institution possesses a governance system capable of directing, challenging, and overseeing financial crime risk before federal regulators, foreign sponsors, or public scrutiny identify systemic failures. That distinction is becoming increasingly consequential to institutional longevity.
Many academic institutions continue to measure risk management success through transactional, operational activity. They count flagged student account anomalies. They monitor standard background checks on vendors. They report localized financial audits and track basic compliance training completion rates among staff.
While these operational measures remain necessary, none of them demonstrate that board-level governance is effective. Governance exists to answer fundamentally different, highly strategic questions:
Financial crime has become completely inseparable from broader higher education enterprise risk. Illicit financial flows no longer avoid academia; instead, they intersect directly with cross-border tuition layering schemes, complex international research sponsorships, cybersecurity breaches, third-party vendor networks, and anonymous endowment donations.
Furthermore, these vulnerabilities heavily overlap with digital asset transactions, artificial intelligence exposures, operational resilience, and institutional data governance. Trustees are strictly expected to ensure that university governance produces timely, reliable, and decision-ready intelligence that enables proactive, protective oversight.
Traditional board reporting frequently overemphasizes workloads such as the number of files processed; rather than true governance effectiveness. To fulfill their fiduciary duties, boards should instead demand clear insight into emerging institutional exposures, core control weaknesses, new compliance vulnerabilities within advancement offices, international third-party impacts, and strategic leadership assumptions.
Modern regulatory and audit bodies are maturing rapidly. Regulatory examinations increasingly evaluate the actual quality of board governance rather than paper documentation alone. Highly effective committee structures, documented evidence of critical board challenge, transparent decision-making records, and campus-wide risk integration are the definitive markers of mature institutional oversight.
To ensure the university is protected, trustees must bring the following five diagnostic questions directly to the committee table:
The academic institutions that consistently protect their institutional reputations and financial health govern differently. They deliberately integrate risk management across departmental boundaries, challenge operational assumptions before external events expose systemic vulnerabilities, and establish clear accountability through active governance rather than reacting to a crisis. In the modern era, financial crime oversight is a fundamental institutional capability that a university board must actively command.
Institutional risk has permanently outgrown the traditional, isolated boundaries of standard internal controls and clean financial statements. For the modern University Board of Trustees, oversight duties are no longer confined to checking accounting ledgers or reviewing routine annual audits.
Today’s University Audit and Risk Committees are increasingly expected to look much deeper, overseeing exactly how risk information is governed, challenged, and translated into strategic, protective actions across the entire institution.
Highly effective trustee committees no longer measure their ultimate success solely by the absence of financial findings or successful external reviews. Instead, their true strategic value lies in ensuring that the full board receives reliable, proactive governance intelligence. This high-level insight must be sharp enough to pinpoint emerging risks before they manifest as operational disruptions, federal funding investigations, or devastating reputational failures.
The central challenge facing university leadership is no longer whether campus management has listed its known risks. The critical issue is whether trustees are receiving decision-ready, integrated information that allows for truly informed fiduciary oversight.
As modern higher education institutions become more globally connected and operationally complex, the Audit Committee has emerged as the definitive focal point for evaluating the quality, integrity, and completeness of university-wide risk reporting.
A university’s value, enrollment stability, and institutional prestige are driven by factors that extend far beyond baseline financial reporting. Sprawling higher education operations mean that a diverse array of non-financial threats now directly dictate enterprise health, including:
Audit Committees must firmly ensure that these diverse operational exposures are presented to the board as a unified, integrated governance narrative, rather than as isolated, disconnected departmental reports.
To protect the institution effectively, boards must expect and demand a specific standard of reporting from university administration. True governance intelligence must clearly explain shifting risk trends, name management’s underlying assumptions, measure control effectiveness, identify dangerous department interdependencies, and spotlight emerging compliance gaps.
Sprawling compliance binders do not equal protection. Highly effective board governance depends entirely upon actionable insight rather than raw data volume.
The University Audit Committee is rapidly evolving from a traditional guardian of financial integrity into a primary steward of active governance intelligence. Higher education institutions that proactively recognize and embrace this structural evolution will be infinitely better positioned to navigate funding uncertainty and operational volatility.
By elevating their risk architecture, boards will successfully preserve public confidence, protect institutional prestige, and maintain unwavering regulatory credibility.
A formal regulatory sanction, federal funding restriction, or compliance probation is traditionally viewed solely as a historic mark of institutional failure. Forward-looking university boards, however, recognize that these high-stakes enforcement actions can also serve as a profound catalyst for building stronger board-level governance, superior administrative oversight, and lasting organizational resilience.
Trustees must view public compliance remediation as significantly more than an annoying legal obligation. Properly governed, an institutional sanction creates a unique, high-leverage opportunity to strengthen administrative accountability, clarify ambiguous decision rights between academic units, upgrade campus-wide risk reporting, and institutionalize rigorous governance practices that safeguard the university long after the immediate regulatory crisis has passed.
The strategic objective of a university board facing regulatory scrutiny must never be merely to close out an external auditor’s immediate findings. The primary objective is to determine whether the foundational governance weaknesses that allowed those systemic compliance failures to emerge have been identified, corrected, and permanently prevented from recurring.
Sustainable institutional remediation requires active, probing board governance, not simply passive administrative project management.
Leading academic institutions utilize regulatory intervention as a mandate to redesign outdated governance structures. They use it to improve the reporting depth of audit and risk committees, strengthen executive-level accountability, integrate enterprise risk information across decentralized departments, and build measurable, long-term governance capabilities. These structural improvements frequently create massive operational value well beyond resolving the original compliance issue.
To fulfill their fiduciary responsibilities during a period of institutional recovery, trustee committees must demand a sophisticated standard of reporting from university leadership. Boards should receive clear, decision-ready intelligence regarding remediation progress, internal control effectiveness across distinct campus branches, emerging risks, resource constraints, and core lessons learned.
The board’s oversight focus must remain locked on whether the university’s structural governance capability is actually improving, rather than whether administrative staff are simply checking off project milestones from a list.
The most resilient universities emerge from public regulatory actions and federal audits with significantly stronger governance architectures than they possessed before the crisis.
When university trustees, chancellors, and presidents treat compliance remediation as a rare opportunity to improve foundational institutional capability rather than merely satisfy external regulators, a regulatory sanction ceases to be a liability. Instead, it becomes a permanent investment in the long-term operational excellence, academic prestige, and financial resilience of the university.
Most discussions about tokenized banking focus on distributed ledgers, digital assets, stablecoins, and smart contracts. That is understandable, but it misses the real challenge.
Banks have spent decades building governance systems designed for institutions operating largely within their own organizational boundaries. Tokenized banking changes that assumption. Financial institutions increasingly operate within ecosystems where a wide range of participants must function as a coordinated network:
The challenge is no longer simply managing risk inside a bank. It is governing the relationships between institutions that are legally independent but operationally interdependent. That is a fundamentally different governance problem.
As financial services become increasingly interconnected, operational failures rarely remain isolated. A cyber incident at a service provider, a settlement failure on a shared platform, a compromised digital identity, or a defective smart contract can rapidly propagate across multiple organizations that remain independently regulated and legally accountable.
Traditional governance models were designed to govern institutions. The highest systemic risks increasingly emerge between institutions, where accountability, information sharing, operational dependency, and decision rights intersect.
The question is not whether tokenized banking will succeed. The question is whether governance will evolve quickly enough to support it.
The next generation of governance must address questions that existing frameworks rarely contemplate:
These are governance questions before they are technology questions.
Banks that solve these governance challenges will be better positioned to participate in future financial ecosystems with greater confidence, resilience, and regulatory credibility. Technology will continue to evolve. Governance principles must endure.
That premise forms the foundation of the Enterprise Governance Operating System (EGOS™), a technology-neutral governance architecture exploring how authority, accountability, information, trust, and operational execution can be coordinated across institutions that are legally independent but operationally interdependent. EGOS is not intended to replace existing governance frameworks. It seeks to extend them to address an increasingly interconnected financial ecosystem.
The future of tokenized banking will not be determined solely by better blockchains or faster settlement. It will be determined by better governance.
The institutions that lead the next generation of financial services will not necessarily be those with the fastest technology. They will be those that develop governance architectures capable of sustaining trust, accountability, and resilience across increasingly interconnected financial ecosystems.
Confidential consultations are available for boards, audit committees, C-suite executives, and regulated institutions navigating governance, risk, or regulatory challenges. Cross-border engagements welcome.
Or write directly: LDJ@GovernanceAndRisk.Com · Houston, Texas for Cross-border Availability
ATTORNEY ADVERTISING
Prior Results Do Not Guarantee A Similar Outcome.
Disclosures & Legal Notice
The information contained on this website, https://www.GovernanceAndRisk.Com (the "Website"), is provided solely for general informational and educational purposes. Nothing contained on this Website constitutes legal advice, a legal opinion, or any other professional advice and should not be relied upon as a substitute for obtaining legal or other professional advice regarding specific facts and circumstances.
No person should act or refrain from acting on the basis of any information contained on this Website without first seeking appropriate legal or other professional advice from counsel licensed in the applicable jurisdiction. The materials published on this Website reflect general legal, governance, regulatory, compliance, enterprise risk, and business principles and may not reflect the most current legal developments, legislation, regulations, administrative guidance, judicial decisions, settlements, or other legal or regulatory authorities.
The views expressed in articles, publications, newsletters, white papers, presentations, and other thought leadership materials are those of the author as of the date of publication and may change without notice.
Professional Services
L.D. Jayasekera is an attorney and governance & risk advisor. In addition to the practice of law, he provides strategic advisory services relating to corporate governance, enterprise risk management, regulatory compliance, financial crime, institutional oversight, board effectiveness, and related business matters.
Certain services described on this Website constitute consulting or advisory services rather than the practice of law and may be provided independently of legal representation. Legal services are provided only pursuant to a written engagement agreement and in accordance with applicable law and the applicable rules governing the legal profession.
Proprietary Framework
The Enterprise Governance Operating System and the designation "EGOS" are proprietary frameworks developed by L.D. Jayasekera and used on this Website to describe his advisory methodology. No license to use these marks, frameworks, or related materials is granted by virtue of viewing this Website or communicating with L.D. Jayasekera.
No Attorney Client Relationship
Viewing this Website, downloading materials, submitting an inquiry, sending electronic mail, or otherwise communicating with L.D. Jayasekera does not create an attorney client relationship. An attorney client relationship is established only after completion of any required conflicts review and the mutual execution of a written engagement agreement.
Communications transmitted through the Internet, electronic mail, website forms, or other electronic means may not be secure and should not be considered confidential, privileged, or protected unless and until an attorney client relationship has been established. Visitors should not transmit confidential, proprietary, privileged, or time sensitive information through this Website.
Representative Experience
Descriptions of representative engagements, publications, speaking engagements, board service, regulatory matters, investigations, litigation, transactions, reserve exposures, recoveries, settlements, professional accomplishments, or other experience are provided solely to illustrate the nature and scope of L.D. Jayasekera's professional background and experience. Such descriptions are not intended to predict, guarantee, or suggest the outcome of any future matter.
Jurisdiction
L.D. Jayasekera is licensed to practice law in the States of Texas, New York, and Hawaii. Legal services are offered only where authorized by applicable law and the applicable rules of professional conduct. Nothing contained on this Website is intended to solicit legal representation in any jurisdiction where such solicitation would be prohibited.
Third Party Content
This Website may contain links to third party websites or references to third party content. Such links are provided solely as a convenience to visitors. L.D. Jayasekera does not endorse, control, or assume responsibility for the accuracy, completeness, security, availability, or content of any third party website or resource.
Disclaimer of Liability
To the fullest extent permitted by applicable law, L.D. Jayasekera expressly disclaims liability for any actions taken or not taken in reliance upon the information contained on this Website and for any loss or damage arising out of or relating to the use of, or reliance upon, this Website or its contents.
Attorney Responsible for Website Content & Principal Office
L.D. Jayasekera, LDJ@GovernanceAndRisk.Com, Houston, Texas, 979-459-3411.