Home > Risk > Jim Comey and the practitioner’s dilemma

Jim Comey and the practitioner’s dilemma

I have just finished reading A Higher Loyalty by Jim Comey, the former FBI Director.

It is an interesting book and I recommend it as long as you can approach it the same way you would approach any audit, investigation, or risk assessment: objectively, setting aside any bias you may have.


It is very easy to come to any situation with your mind at least half made up.

That is the path to failure when performing an audit, investigation, or risk assessment.

When reading a book such as A Higher Loyalty, cognitive bias[1] and confirmation bias[2] get in the way.

If you have already made up your mind when it comes to Comey and his actions, you need to set them aside and approach a book like this the way you would as a professional approach any other task.

Listen to all the information before making your assessment or decision.


I am not going to share my opinion on Comey or his actions, although I will have a couple of comments at the end of this post.


The book is interesting because he was in a number of positions and faced challenges similar to those many of us face.


Like us, he had to:

  • Speak truth to power
  • Try to act in the interests of the organization rather than those of his boss – and his own – making decisions and sharing information that those in a position of authority over him don’t want
  • Handle political pressure to act in way he believes is wrong
  • Work for people he considers put their interests ahead of those of the organization

I can remember several situations where I faced a dilemma. I hope that I made the right decisions, but frankly am not 100% sure.

  • As an audit senior in public accounting in the UK, I led the audit of a large defense contractor. The partner had told us that, despite the prevailing wisdom that you had to wait until a project was at least 60% complete, it was possible to perform a ‘cost-to-complete’ analysis as early as 20% into a fixed price contract. The idea is that if you can reasonable project a loss, a reserve for that loss should be booked. I followed his guidance and it was very clear, based on information from the project manager and senior engineer, that the company’s largest contract would suffer a multi-million pound loss that was material to the contract and the financial statements. I communicated that to the partner. He reviewed my work and agreed. But when he met (privately) with the finance director to press for the reserve, the partner gave in to the pressure. He told me to change the assessment but wouldn’t look me in the face. I did what I was told – what option did I have? (By the way, the loss was booked a year later.)
  • One of my responsibilities as a vice president in IT for a large financial institution was the development of a data center disaster recovery plan. One of the first steps was to define the baseline assumptions. The executive vice president who was my boss’s boss dictated that we were to assume that every employee we needed for the recovery would be available when needed at the recovery site. Further, there would be no difficulties moving between the off-site location where we kept our backups and the recovery site. I should tell you that the data center, the off-site backup location, and the recovery site (by mandate) would all be within 30 miles of each other in Southern California – a major earthquake zone. I protested to my boss, but he told me to go along. I did. What choice did I have? I documented the assumptions, got them signed off, and moved on.
  • As a recently appointed vice president of internal audit, my team and I completed the investigation of a complaint against a senior vice president (a third level executive). I had informed the chair of the audit committee when we started, but neither the CFO nor the CEO. When it came time to inform the audit committee that the investigation was completed and no wrongdoing identified, I informed the CFO and he called the CEO. The CEO was livid that he had not been told as soon as the (anonymous) allegation had been received. The CFO relayed the displeasure to me and instructed me that both he and the CEO must be informed promptly in future. I stood my ground, although I was weak at the knees, and informed the CFO that the proper protocol was to limit awareness of the allegation and investigation – and not inform top management. One of the reasons was that we did not want top management to change their opinion of the ‘targeted’ executive; too often, guilt is assumed. Another was that we needed to keep the matter secret to protect the company should the allegation prove to be without merit but the target’s prospects and reputation were damaged. This time, my view prevailed (I was not fired) but it certainly didn’t help my relationship with either the CFO or CEO.
  • A few years later at the same company, my team uncovered a series of financial statement frauds. Fortunately, none were even close to being material to the consolidated financial statements. Even so, the CFO came to me and told me that he was in the process of working with bankers to float a debt offering. They were nervous about the investigations. Could I stop, at least for a while? I stood my ground and he backed off, but further damage had been done.
  • The next year, I had another problem at that company. There was clearly a common root cause for the several financial statement frauds: local controllers and management perceived pressure from corporate to ‘make the numbers’. There was insufficient evidence of specific instructions along those lines, but I felt actions needed to be taken by the CFO and CEO and that the audit committee should be informed. The top executives were not at all pleased but agreed to back me up when I shared the news with the audit committee. When the board members reacted strongly and negatively to the news, the CFO and CEO sat and watched. I believe I did the right thing, but I could not remain with the company after this.
  • Several years later, I was the vice president of a software company responsible for both internal audit and risk management when it was announced that we were to be acquired. The management of the acquiring company dictated that we had to migrate from Oracle’s to SAP’s ERP within six months. I put my team to work helping management assess and address related risks, which were huge. But word came down from the buyer‘s CFO that we were to assume that there would be no finance or financial statement related risk. Of course, this was nonsense. I went along (in public) but did my best (in private) to monitor the risk. Frankly, I couldn’t do much because I knew none of the buyer’s finance team. I did inform my CEO, who would continue to lead the business post-acquisition, and my corporate controller, who would lead the acquired business’s finance function. Should I have done more?

As you can probably tell, all of these situations and challenges (and more) troubled me then and even now.

Did I maintain my integrity and professional responsibilities?

You can decide for yourself whether you would have made different choices to the ones I made – and the ones Jim Comey made.


Now for some thoughts on Comey:

  • He believed that he was acting with integrity and that he had a responsibility to make the decisions he did. He was willing to put his job at risk.
  • He believed that the Department of Justice and the FBI had to be free from undue influence from the President or others in the executive branch. BUT, he failed to stand up to the President and explain very clearly that position and the reasons for it.
  • He allowed himself to be intimidated by those in power.
  • He also did not enter into his relationship with Trump with an open mind. He had a clear bias, based only on what he saw on TV, that this was a man who lacked integrity and was a liar. Even though his preconceived notions about Obama changed once he met and got to know the man, his bias when it came to Trump didn’t help him at all.
  • Finally, he failed to build relationships with those around the President, As CAE, I knew the importance of building relationships at the top of the organization, not only with the CEO and CFO.


It’s not easy to be brave (enjoy the song).

I welcome your thoughts.


[1] A cognitive bias is a mistake in reasoning, evaluating, remembering, or other cognitive process, often occurring as a result of holding onto one’s preferences and beliefs regardless of contrary information. Psychologists study cognitive biases as they relate to memory, reasoning, and decision-making. Many kinds of cognitive biases exist. For example, a confirmation bias is the tendency to seek only information that matches what one already believes. Memory biases influence what and how easily one remembers. For example, people are more likely to recall events they find humorous and better remember information they produce themselves. People are also more likely to regard as accurate memories associated with significant events or emotions (such as the memory of what one was doing when a catastrophe occurred). (See http://www.chegg.com/homework-help/definitions/cognitive-bias-13)

[2] Confirmation bias, the tendency to process information by looking for, or interpreting, information that is consistent with one’s existing beliefs. This biased approach to decision making is largely unintentional and often results in ignoring inconsistent information. Existing beliefs can include one’s expectations in a given situation and predictions about a particular outcome. People are especially likely to process information to support their own beliefs when the issue is highly important or self-relevant. (https://www.britannica.com/science/confirmation-bias)

  1. Jay R. Taylor
    April 22, 2018 at 4:11 PM

    Norman, I love the personal stories and can put myself in your shoes to make me think what I might have done differently, if anything. These would make terrific case studies in business school and would be useful in an ethics course. Regarding the book, I have to ask myself why this individual wrote it in the first place; so the motivations he might have to write a “tell all” should be considered. Second, subsequent documents provided to Congress indicate heavy doses of salt must be provided to the written word to suss out the facts in the book. Last, I don’t envy those persons put into such difficult moral and ethical situations, and realize I have trouble relating to the intense pressures he must have experienced every day. So in summary, time will tell whether you and Mr. Comey made the right decisions. Luckily in your case our Republic was not in the balance. 🙂

  2. Norman Marks
    April 22, 2018 at 4:21 PM

    Jay, I read through the memos that were provided to Congress and, as reported by the media, are 100% consistent with what Comey relates in the book.

  3. Norman Marks
    April 22, 2018 at 4:22 PM

    PS, the memo that Comey passed to his friend and thus to the press was clearly marked nonclassified, and the DOJ redacted not a word. I doubt Comey will be charged with leaking.

  4. April 22, 2018 at 6:12 PM


    I love this piece as it relates to the parallels you draw but can’t resist registering my disappointment in some of your interpretation of Comey and his motivations. You clearly don’t get Trump nor the extent of the corruption in Comey and other FBI and DoJ leaders, not to mention the political class.

    If you want to understand the other side of the story, consider reading “Killing the Deep State” by Corsi. You may find your own, possibly subconscious biases revealed.


  5. Arnold Schanfield
    April 23, 2018 at 10:07 AM

    I echo this individual’s comments above Chris Mandel and could refer you to at least 20 other books written by conservatives that could help in balancing out thought. When the dust settles, I hope that there is equal justice under the law. I believe from hundreds of different articles read and countless newspapers from both the left and the right, that Comey is a both a lier and a leaker, broke numerous laws and should be help to account.

    You either understand Trump or you do not. Prior to my embarking on a plethora of balanced reading, I did not get him at all. For example in his area of tweeting. How could a President be tweeting and of course the kinds of things? Well, the answer is that he tweets because he wants to get his message out to the people and does not trust the liberal, biased media and the entire Deep State to do this. By the end of this year, Trump will have the Nobel prize and that’s because no one understands that “thugs only understand one thing” and that is thuggery back. Trump is behaving like a thug not because he was born and raised as a thug ( he was not) but because he understands the game very well and no one will push him around unlike our prior weaklings in office.

    As far as Comey is concerned, he is missing an emotional component as does Hillary Clinton and such absence is a disconnect from people. This is one of the reasons that Trump won. He was able to connect with the people. Comey is disgracing the FBI and hurting our country tremendously through his book tour.

    • Mike Corcoran
      April 25, 2018 at 10:40 AM

      Arnold, well said my friend.

  6. April 25, 2018 at 6:25 AM

    Great post Norman. Thank you for sharing your experiences especially those where you retain some doubts of the final action. That kind of retrospective is essential to honest self assessment and continuous improvement. It is also an inspiration to others in Risk, Audit, Compliance and other regulatory roles to act with integrity and help the organization do the right thing.

  7. Mike Corcoran
    April 25, 2018 at 10:38 AM

    I will no longer read your posts as they now contain ads. I did not opt in or allow.

    • Norman Marks
      April 26, 2018 at 8:17 AM

      Sorry to hear that, Mike. I have no control over the ads nor derive any revenue from them. I suggest an ad blocker – that’s what I use

  8. Craig.J.Brain
    June 30, 2018 at 4:00 PM

    Norman, again thank you for the though provoking article. I doubt that there is any real risk manager worthy of the title that hasn’t had concerns with some of the directions that they have been given. I was told by a slippery manager of mine a while ago, “If it’s not in writing, it never happened.” I made a habit of emailing him and asking to clarify his directions in writing, and he had a habit of telling subordinate staff to phone me in response.
    The day did come where he tried to throw me under the bus for questionable direction and I was able to demonstrate a prolonged history of avoiding accountability own his part.
    I like the idea of noting assumptions and limitations, no matter how ridiculous and artificial, and keeping them in an archived copy of the draft that I send out for review. Track changes is your friend in such cases.

  1. April 22, 2018 at 3:05 PM

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: