
Innovation in Compliance with Tom Fox · 2026-08-11 · 26 min
Key moments - from our scoring
Substance score
47 / 100
Five dimensions, 20 points each
Diego Panama brings scaling expertise from his tenure at Liveramp and OLO to LogicGate, positioning the GRC platform for enterprise growth while maintaining founder values and culture. The conversation centers on how agentic AI - moving beyond human assistance to agents autonomously managing workflows - transforms GRC from reactive compliance to proactive risk management. Panama discusses LogicGate's RiskCloud platform's ability to provide holistic, non-siloed risk visibility across third-party, cyber, and enterprise risks, enabling real-time monitoring rather than sample-based assessments. He introduces workflow agents like the assessment agent for third-party risk and Config Newton for platform configuration, alongside an AI governance application to prevent GRC from becoming an AI adoption bottleneck. The episode addresses data access, quality, and governance as foundational to effective GRC platforms, references the DOJ's 2020 compliance program evaluation mandating data visibility across silos, and positions GRC professionals as increasingly strategic to boardroom conversations about responsible AI deployment. Panama emphasizes LogicGate's no-code capabilities evolving toward prompt-based interfaces and user experience as a core competitive advantage.
Agentic AI moves beyond stage one (AI assisting humans with text generation or recommendations) to agents autonomously handling bulk workflow tasks like third-party assessments and risk recommendations, with humans remaining in the loop for strategy and risk appetite setting.
A unified RiskCloud platform provides global visibility across all risk categories - third-party, cyber, enterprise - eliminating siloed local optimizations that create blind spots; LogicGate's approach enables companies to see downstream exposure to vendors and partners comprehensively.
Because every boardroom wants to accelerate AI adoption, but GRC professionals understand the risks and governance requirements of AI systems; they've become gatekeepers preventing reckless AI implementation and customer data exposure.
Config Newton is LogicGate's configuration agent that lets users describe their third-party risk program through conversation, automatically designing and building the application in RiskCloud rather than requiring no-code clicking or IT tickets.
The DOJ's 2020 Evaluation of Corporate Compliance Programs document stated that compliance and GRC professionals must have access to all company data - whether in data silos, lakes, or distributed systems - to maintain comprehensive visibility.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers some substantive concepts like holistic risk management, agentic AI phases, and Data governance, but frequently retreats into aspirational talking points without drilling into specifics. Most claims lack evidence: e.g., 'agents doing bulk of work' is asserted but not demonstrated with real examples, timelines, or measurable outcomes. The conversation gravitates toward vision and strategy rather than operational depth.
we are the leading AI GRC platform for the enterprise
agents are doing the bulk of the work
The core thesis - that AI elevates GRC from defensive to strategic - is increasingly common in compliance circles and the host himself claimed to have been 'evangelizing' this for 18 months. The three-phase AI maturity model (assisting, agents doing bulk work, autonomous orchestration) is a standard industry narrative. There are no contrarian takes, first-principles challenges, or unexpected insights that distinguish this from mainstream GRC vendor positioning.
GRC should really be a strategic offensive motion and not defensive reaction
agents are working alongside humans to run a more effective program
Diego Panama is a legitimate operator with scaled exits (LiveRamp IPO, 600M ARR exit) and relevant SaaS go-to-market experience. However, he is new to the GRC domain (admitted unfamiliarity with specific FCPA case), and the episode is partly a platform for his new CEO tenure rather than deep practitioner insight into GRC problems. He speaks as a vendor leader, not a battle-tested GRC practitioner who has lived the pain.
I started my technology career at Microsoft as a product manager
I scaled that company to an IPO and beyond when I left we were about 600 million in ARR
The episode lacks concrete evidence: no customer names, no metrics, no data points, no timelines, no dollar figures, no case studies with measurable outcomes. Claims about agent effectiveness, data governance importance, and regulatory shifts are unsupported by examples. The host references a recent FCPA case but the guest deflects; no real-world scenario is fully explored.
we have over 400 customers
agents making us even better
The host asks competent, structured questions aligned with his expertise (law school GRC teaching, compliance knowledge) and makes relevant references (DOJ 2020 guidance, recent FCPA enforcement). However, follow-ups are mostly soft. When the guest admits unfamiliarity with the FCPA case, the host moves on without pressing. Questions rarely challenge or create productive friction; the conversation reads as affirming rather than investigative. The host is a friendly moderator, not an interrogator.
I'm not familiar with that case the last couple of weeks, but it sounds like there's a blind spot
Diego, could you tell our listeners about your professional background
Computed from the transcript - who did the talking, and the words that came up most.
Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with s Diego Panama, new CEO of LogicGate. They discuss his career from Microsoft product management to scaling Live Ramp to an IPO, building go-to-market at Olo, and joining LogicGate through a planned CEO transition with co-founder Matt Kunkel. Panama describes his focus on scaling operations while preserving a customer-first, values-driven culture, and sharpening the company’s positioning as the leading AI GRC platform for enterprise. The discussion highlights AI’s role in moving GRC from check-the-box defense to real-time, strategic enablement, including holistic risk visibility across silos, third-party risk blind spots, and always-on monitoring.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to Innovation and Compliance, the only podcast focusing on innovation for the compliance professional. Today I welcome Diego Panama. Diego is the new CEO at logicgate. Listeners will remember I previously had Matt Kunkel who was the prior CEO at Logic Gate, and now Diego Panama has stepped in. We have a wide ranging and fascinating discussion about Diego's vision for the company, Enterprise Wide GRC in the age of AI and how it all relates to the compliance professional. I know you'll enjoy this episode with Diego Panama. Hello everyone, this is Tom Fox back for another episode. And I'm absolutely thrilled today to have with me Diego Panama. Diego is the new CEO at Logic Gate. Lots of the listeners this pod know I'm a huge fan of Logic Gate. So I'm thrilled when he agreed, uh, to come on the pod. So first of all, Diego, welcome and thank you so much for taking the time to visit with me.
Speaker B: Hi Tom, thank you so much for having me. I'm excited to be on the show and a listener. I know you've had Matt before and we're just thrilled to be able to keep the conversation going with you.
Speaker A: Diego, could you tell our listeners about your professional background and what led you to becoming the CEO at Logic Gate?
Speaker B: Yeah, I started my technology career, my career in technology at uh, Microsoft as a product manager actually. And I was drawn to, they had just made an acquisition of this company, company at Quantive, that was in the digital media space. I was drawn to what technology was doing to the media landscape. I saw newspapers, I saw things like DVDs and I knew that was all going to change and I wanted to be part of that. So that's where I started my career. I started making my way into sales and then joined a startup called Liveramp. I joined when we were probably 20 people or so, around 10 million in ARR. And I was just lucky to have a great run there. We scaled that company to an IPO and beyond. When I left, we were about 600 million in ARR. And I like to say I had every sales role in that company and it's just really fun because you see a lot of different faces of company. Then I joined a former colleague and good friend who had taken his company public company olo, to help him set up go to market. So I did that for OLO for a few years and then I was taking a step back when I met Matt Kunkel, who's one of Logic8Three co founders, former CEO and now our executive chairman. And from the moment Matt and I met, we just, every conversation kept getting Better and better. First, just from a values perspective, we were so aligned, and I know, like now, having seen this movie a couple of times, that a, uh, founder's values really translate into a company's culture. And that was something that was very important to me. Matt and the board had also set out this ambitious plan for the company that included a succession plan for Matt so that he could step into the executive chairman role and they could bring an operator who had seen and taken a company to scale before. So that was exciting. And then the GRC space. The GRC space is really fascinating. And it's. I like to think about it, it's a problem that every company has to solve, no matter what size. But the bigger you are, the, the bigger problem you have to solve. And it's one that I saw a clear way for technology to help out, especially the advent of AI and the new technology that we're seeing. There was just a clear opportunity for technology to disrupt how things were getting done and how things are going to get done. And like I said earlier, I've been always drawn to that in my career. And so I jumped at the opportunity to become part of the team and help us scale.
Speaker A: You really hit on the three things that have drawn me to Logic Gate over the years, or even I've admired about the company. Number one is its culture. Number two is its technology. And in three, working in the greater GRC space. I actually teach a law school class on GRC and had Matt speak to my students on his flavor of GRC tech tech and his solution. So I hope we can continue that conversation. But now you've told us about why it was an appropriate time for a trans transition. Perhaps I could ask what is what about your leadership you believe can help continue the momentum and even accelerate it? Preparing for literally what's next?
Speaker B: Yeah, I think where I believe I could come in and help was just really helping us scale up. Uh, the way you service your first hundred customers is a certain way. And usually customers are very happy and you have some success and then you begin to scale and you have 200. Now we have over 400 customers, and that's going to keep on growing. We don't want to lose that customer first mentality, uh, treating every customer, making sure they're successful. But to do that at scale requires a certain setup, certain organizational design, certain processes that, again, I've seen before, and that's what I'm trying to help logicate with, is just making the most of our growth as we scale. Also as we grow Staying focused is a priority, and I think that's something that I helped Matt and team as I came on. It was like, it was very clear what we wanted to be. We are the leading AI GRC platform for the enterprise. And there's three words there that I'll come back to, but that's what we brought back to the team. We're going to focus on AI because the opportunity is really big for the impact they can have on our company and our customers. Companies. We're going to stay focused on grc. We're not going to be distracted by shiny potential opportunities to the side. There's enough in GRC and, and we're going to be focused on our enterprise customers, the world's biggest and best companies that can use our technology. And so having that focus area then translates to everything we do. And it's something that takes some discipline and we want to stay on as we grow and as we scale.
Speaker A: One of the things I've tried to evangelize in the compliance and greater GR space literally for that past 18 months, is that AI will allow GRC to, and compliance to operate at the speed of business. And it can help a GRC professional demonstrate true value to a company. And I wanted to ask you, is that one of the things that you see? I know you see that, but I guess in messaging to clients or potential clients, do they really understand that the opportunity for GRC is different than it's really ever been?
Speaker B: Yeah, I think most of our clients are starting to see that. And the grc, uh, should really be a strategic offensive motion and not, uh, defensive reaction. Kind of like I need to have check the box exercise. The world's best companies, the companies that are pushing the boundaries are using the GRC function to their advantage. And to do that properly nowadays, you have to do it to your point in real time. I'm using, um, AI. And you will just be better at it. You'll be able to do it in real time. You'll be more efficient, you'll be more effective, and you'll be able to support the business a lot better.
Speaker A: So the. What are some of the. I don't even know where to begin with risk, but with perhaps that. This is probably the most volatile business environment I've ever seen or done work in. But how do you help a, uh, GRC professional help a company with the emerging risk or risk literally change from one morning to one afternoon?
Speaker B: Yeah. And to your point, where AI can help is always on monitoring, just not relying on samples, like, not, not Having a siloed view of risk. So one of my favorite things about Logic Gate and a strategic bet that um, I'm proud of is that we are a GRC platform. When you level up a company all the way up, there's no such thing as third party risk or cyber risk or there's just risk and uh, you want to understand it holistically. That's really hard to do if you don't have a holistic GRC platform. And so it's important to be able to understand and rank your risk not by siloed and kind of have local optimizations, but truly have a global optimization of risk. And that's something that the risk cloud platform enables and now agents are making us even better at.
Speaker A: So a couple of weeks ago we had a rare FCPA enforcement action where the bribery violation actually occurred in the supply chain with customs agents. And one of the problems the company had was compliance did not have visibility into third party customs agents brought in. And the underlying facts happened in the last decade of this century or most previous decade. But it really demonstrated if compliance doesn't have a view into third party agents, whoever they may be, sales or supply chain side, you've got a huge unobserved risk. Is that something that really resonates with the GRC professional and or senior management today?
Speaker B: Yeah, I'm not familiar with that case the last couple of weeks, but it sounds like there's a blind spot in terms of the risks that you're being exposed to because of a third party. And that's absolutely should be and I believe is top of mind. I think most companies out there work with thousands of vendors and partners and being able to manage the risk and the downstream risk that you're exposed to, understand it and act on it as a person appropriate, I think is critical for running your business.
Speaker A: Let me turn to agentic AI because that seems to be one of the things that GRC professionals ask me about or talk about the most right now. And I know you've really rather. Logic8 has introduced workflow agents. Could you tell us about that and how that agentic AI can help the GRC professional?
Speaker B: Yeah, I think AI and specifically agentic AI is completely transforming the way a GRC program runs. And it started with what we think of stage one or AI assisting humans. You could think about what we now think of basic AI capabilities like generating text or suggesting linking recommendations for control to certain risk or things like that. That was AI making humans more efficient and more effective, like helping them. But still humans doing Most of the work with agent workflows, which we announced this summer, and with workflow agents, which we announced this summer and I'm super proud of, we're now entering into the phase where agents are doing the bulk of the work. So for example, we have an assessment agent that you can use in your third party risk application. And the assessment agent would assess the intake form and whatever documents and spit out the appropriate recommendations for that particular third party, saving the humans a lot of time, making the work a lot more precise and to what we talked about earlier and an always on. So now you can see how humans are working alongside agents to run a more effective, more precise program. That's where we are today, and this is live today. There's many skills that our agents have helping with the different workflows in grc. Where we're moving to is where the agents really take over and it becomes autonomous, always on orchestrated grc. Now we will always have humans in the loop. The humans will set the risk appetite, set the strategy, and then the agents go to work. But it's just a different level of, uh, a GRC program that's going to be a lot more effective and a lot more efficient.
Speaker A: Diego, you used a couple of phrases, upstream risk and downstream risk. I certainly think I understand what that means. Is, does that those phrases upstream and downstream risk, do they collapse into a category of just risk, or are they different risks that need to be identified differently in your mind?
Speaker B: Uh, well, I think like I said earlier, in the end, for an enterprise there's risk and there's many subcategories of risk. Again, and you could think about them upstream, downstream, cyber specific, third party specific, enterprise specific. But in the end, what's important is do we have an understanding of, uh, the global view of risk exposure for the company? What does that mean and what do we want? What are our choices around it?
Speaker A: Diego? In 2020, the Department of Justice, in a document entitled the Evaluation of Corporate Compliance Programs, said for the first time that a compliance professional and GRC professional had to have access to all company data, whether you called it data silos, data lakes, or data that there had to be visibility across. And so that was the first time the regulators, at least the Department of Justice as regulators, said that moving forward now into 2026, I still hear a lot of questions, not about visibility into data, but actually access. How important is data quality and data governance to having a superior GRC platform
Speaker B: Around these issues, I think it's critical to have not only data access, but access in the Right ways because there is actually so much data. And now because everything we do, you spit out more and more data. So to have a system that can understand it, that you can query the right way, that you can interact with the data and get the right outputs becomes really important. But it all starts with data access.
Speaker A: Diego, as I mentioned, I've uh, been a fan of Logic8 for a long time and one of the things that had always it stuck, struck me the first time I talked to Matt and stuck with me since then was the culture he was trying to build. How are you going to be able to take what I think is a great culture and build it, build upon that in a way that people like me still admire your company.
Speaker B: Yeah, I appreciate that Tom, and that's Matt and I spent a lot of time talking about this, but in a way it's an easy conversation because we knew from the beginning how aligned we were on our values. And really the top value is people first. We all have context. I don't know what you went through this morning and I'm grateful that you're with me right now, but we have to have an open mind and give each other the benefit of the doubt. So showing up for each other, showing up with a people first mentality will always be part of our culture and it's something that we're going to embrace as a company. We have six values that Matt and uh, our co founders came up with very early on. They're here in my wall. We will continue to live by those six values and that will anchor our culture. Now then, parts of your culture continue to evolve as you scale the company. We're now becoming like more deliberate around our intensity on what I call a high say do ratio. If you say you're going to do something, let's make sure you do it. Like having accountability around that, having a high performance culture, all those things are not exclusive to the heart of our culture, to no pun intended, which is being people first and really caring for each other.
Speaker A: The other. I have another friend in compliance named Carson Tams and he has one phrase that he always uses and it's always true and the phrase is it's all about the ux. Everything compliant in compliance is about the ux. How are you able to incorporate the user experience into literally every product or service that Logic 8 delivers?
Speaker B: Yeah, the user experience, um, really many product is the most important thing and it's how they experience your product. Uh, as I've come to get to know our customers and how they're Using our platform, uh, risk cloud. From the very beginning, the, what we used to call no code capabilities around the platform, um, were just a winning formula. People really appreciate the ability to click and drag and make your own changes. Not having to file a ticket with it and having it to be very intuitive. Where we are really pushing on that, because where I think technology is taking us is the no code concept is going to be a thing of the past as we all now just prompt to execute. And literally we have an agent, a configuration agent that we fondly call Config Newton that you basically have a conversation with around. You can say, hey, here is my blueprint for my third party risk program. Here are some of the things I care about. Have a. And then it'll design your third party risk application to the point where it'll put it in the platform. And then you may say you'll just tell it actually can you add this approval process on that step? Can you make sure that this step is required? And it's just a conversation with the platform uh, that's really evolving the ux, the user experience in a very cool, futuristic way. So how our uh, users experience our product is always top of mind and we continue to invest in it quite a bit.
Speaker A: Diego, I think it would be fair to say that if you had a conversation or I had a conversation with a fellow GRC professional, compliance professional or risk manager, we would all get it, we would understand. But I wanted to flip that. Do you see a uh, change in either at the board level or senior management to beginning to understand that the true value that a grc, that risk management professional, that a compliance professional can bring in an overall risk management. If we can just say risk. And where do you see really at that level of a corporation? Because, because I would assume you're talking really to those level people in your role.
Speaker B: Yeah, I do see it evolving in where GRC and the concept of risk in particular is seen as a more strategic conversation. It's very interesting. We have a good part of our business outside of the us, around the UK and Europe. And I'd say like they are a little bit further ahead in terms of the maturity of that uh, GRC plays in the enterprise. But we're quickly catching up here based on the conversations. And I think one of the catalysts has been this conversation around AI. Every boardroom, every C level is saying we need to use more AI. Uh, and then it gets to the GRC team and the GRC professionals and they're like, okay, I understand the imperative and the direction of using AI. But have we stopped to think about all the risks associated with that and do we really want to put our customer data into that platform and do we understand what the potential implications are? So now GRC professionals are in this very strategic position where they are the keys to the kingdom in terms of using AI in the enterprise. We're proud to have an AI governance application that makes their jobs a lot easier so they don't become the bottleneck of innovation and AI. But I think that the need for quick adoption of this technology has elevated the position of GRC professionals, GRC teams and like the strategic nature of them to the executive team and to the boardroom.
Speaker A: Let me flip that just a little bit by asking you the following. If I ask you to speak to my GRC class, what would you tell the 21 year old, perhaps the graduate student, 24, 25 year old, about the opportunities that GRC would present to them now and into the future?
Speaker B: Yeah, I think there couldn't be a more exciting time to be in GRC because we are right at the intersection of uh, technology and business strategy. So highly recommend that it's a field that it would be great to go into to better bet your career into because sometimes internally we call it the sleeping giant of the enterprise. It's such an important problem to solve that if you can help companies solve this problem, you're going to have a great career.
Speaker A: So from, I now know from your professional background that you told us about a little earlier, you started with one of the world's biggest companies and certainly one of the most recognizable. Could you say a few words about the value of having data experience yet moving into this world of both startups? Logic Gate's obviously not a startup, but just sort of a little bit more entrepreneurial bend that you took and how working for a large corporation actually helped make you a better entrepreneur.
Speaker B: Yeah, I love my time at Microsoft and I'm grateful for many execs, uh, that I learned a lot from there including running a business with key metrics. But one of the things that sticks with me from Microsoft and which you might think it's only relevant to Microsoft, but I think it's relevant to all of us for Microsoft to do something. The bar is pretty high. You could start a new business unit, you could have a great idea and um, if it's only going to make tens of millions, maybe hundreds of millions, it's just not going to get any airtime. You really have to have a needle moving initiative for it to have the focus and the resources. And that to me, really, uh, helped me with the discipline around focus, which I talked about earlier today, and picking your bets because you don't want to spread yourself too thin. Having focus and having clarity on where you're going and bringing the entire team along becomes really important. And that's something that Microsoft has not always been great at. So I got to see what happens. When I was in a phase where we were really distracted and trying to do many things there, we had missed the mobile phone and trying to catch up on search. And so I saw the implications of that in an organization. And so on the flip side, being able to focus and have clarity and just bring everybody along, trying to go in the same direction can be pretty powerful.
Speaker A: Another one of the conversations I have right now is the rapid change of technology and GRC compliance and risk management. What advice can you offer to the current GRC professional who's trying to navigate these literally, maybe even day to day changes in technology?
Speaker B: Yeah, one of our six values here is to be curious and to always be learning. I, uh, think no matter what professional role you're in, I think that's pretty sound advice to be curious, to always be learning. And don't lose sight of your North Star, which for GRC professionals, like anybody else in the company, is to support and make the business successful. So understand what your business is in, what the outcomes they're looking for are, and then you understand the role that GRC needs to play to support those outcomes. But be curious about what your business is trying to do, what the technology that's out there, how you can use it, and try to have some fun along the way.
Speaker A: Diego, unfortunately we are near the end of our time for this episode, but before we leave I wanted to ask you if any of our listeners wanted to connect with you, find out more about Logic Gate or really any of the topics we've touched on today. What would be the best place or places for them to go?
Speaker B: Yeah. Thank you so much for the time today, Tom. Happy to connect with any of your listeners. If you want to reach out, I'm@Diego.PanaMagicGate uh.com or if you want to learn more about Logic8, you can go to our website, LogicGate.com and learn more. But please reach out. I'd love to connect.
Speaker A: Diego, thanks again for taking the time to visit with me and I hope we can continue this conversation.
Speaker B: Likewise. Thank you. Tom.
Speaker A: Um, thank you for listening to this episode of the award winning Innovation and Compliance. I'm thrilled to announce three new podcasts on the Compliance Podcast Network. Two are weekly news wrap ups of AI the first AI Today in five in Healthcare, the second AI Today and five in Fintech, where I took a look at the top stories in both of those disciplines from the AI perspective. They both, uh, are released on Friday, so check out either one of those. I've also released a new podcast on GSK in China, 12 Years, a 12 year retrospective where I look at this one of the most significant scandals in China in the past decades and what are the continuing compliance lessons learned from the scandal. So check out GSK in China, a 12 year retrospective. Finally, the Innovation and Compliance Podcast is produced by myself, Tom Fox, with assistance from Jaja Derdar as a production assistant. Thanks so much for listening and we look forward to visiting with you again next week.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.