Drew Shaddock

Director of Ethics & Compliance. I run the program and the investigations, lead responsible AI adoption across the enterprise, and stay accountable for the risk. 20+ years across compliance, legal, regulatory, and IT roles — 12+ years leading the ethics and compliance program for a $2.7B publicly traded industrial company.

0+
Years of Experience
0+
Investigations Managed
0
Manufacturing Facilities
0%
Training Completion Rate
Drew Shaddock
Scroll
Drew Shaddock
Drew Shaddock
Director of Ethics & Compliance

Building Programs
That Actually Work

I am responsible for the design, operation, and execution of a corporate ethics and compliance program spanning Code of Conduct governance, the investigations framework, hotline and speak-up channels, policy management, training, communications, and reporting to senior leadership and the Board’s Audit Committee.

My team runs day-to-day investigations and program activities. I set direction, make escalation and remediation decisions, and ensure issues are handled consistently and fairly. Under my leadership, the function manages roughly 160 investigations per year across fraud, employee misconduct, harassment and retaliation, conflicts of interest, FCPA/anti-corruption, and labor and union matters.

“The team sustains 96% annual training completion, 94% policy attestation, and 70% measured employee confidence in reporting — consistent performance over more than a decade.”

I work closely with HR, Legal, operations, and external counsel on investigations, remedial actions, and M&A due diligence and post-close integration, ensuring counterparties adopt our Code of Conduct, speak-up channels, and core training quickly.

Juris Doctor

Legal foundation for regulatory and compliance leadership

CCEP Certified

Certified Compliance & Ethics Professional

Georgetown AI Governance

Certificate in AI Governance and Compliance, Georgetown University School of Continuing Studies (2026)

Cornell AI Law & Policy

Certificate in AI Law and Policy, Cornell University (2026)

Harvard AI for Leaders

Certificate in AI strategy and enterprise implementation, Harvard Business School Online (2026)

Empowered Official

ITAR/EAR/DOE Part 810 export control authority

Technology

AI & Compliance Technology

Selected to lead responsible AI adoption across the enterprise — proving it first in legal and compliance, then opening the door for teams company-wide. The discipline that makes it defensible is the same one that runs the investigations: deploy where it helps, govern the risk, keep accountable people in the decision.

⚡ Early AI Adoption in Legal & Compliance

Selected, deployed, and governed AI tools for compliance operations early in the adoption curve — putting natural language processing to work on investigation documentation while owning the risk, the controls, and the accountability. Cut investigation report drafting from 4 hours to 45 minutes with human review preserved at every step.

First Mover

🎓 Enterprise AI Champion

Led the effort to secure governed company-wide access, extending AI deployment to departments beyond legal and compliance with the guardrails already tested. Made the compliance function the proving ground for responsible AI use rather than the brake on it.

Change Leadership

📚 Compliance Technology & E-Discovery

IT leadership background in data center infrastructure, SAP, and enterprise platforms now applied to selecting and shaping compliance technology, e-discovery tools, and data structures — making work better evidenced, less manual, and easier to monitor.

Tech-Enabled Compliance

🎓 Formal AI Governance Credentials

Certificates in AI Governance and Compliance (Georgetown), AI Law and Policy (Cornell), and AI for Leaders (Harvard Business School Online) — three programs completed in 2026, building a working framework for responsible AI deployment in regulated industries with national security implications.

Georgetown · Cornell · Harvard
Career

Professional Experience

20+ years building, leading, and maturing compliance programs at organizations where precision and integrity are non-negotiable.

2013 — Present

Director, Ethics & Compliance

BWX Technologies — $2.7B Nuclear Manufacturing • NYSE: BWXT

Design, operation, and execution of the full corporate ethics and compliance program across 18 facilities and 10,000+ employees
Managing ~160 investigations per year (1,800+ over tenure) spanning fraud, misconduct, harassment, FCPA/anti-corruption, and labor matters
Periodic and on-request presentations to the Compliance Committee and Board Audit Committee on program health, investigation trends, and risk posture
Yearly Board presentations on export controls and regulatory compliance
Built and led an export controls framework (ITAR/EAR/DOE Part 810) as one regulatory domain within broader compliance responsibilities
Led compliance due diligence and post-close integration for M&A transactions, ensuring rapid adoption of Code of Conduct, speak-up channels, and core training
Earlier Career

Compliance Manager & IT Leadership

Progressive Roles in Legal, Regulatory & Technology

Compliance Manager responsible for investigations, training programs, and policy implementation prior to promotion to Director
Led large IT and enterprise systems projects including data center infrastructure, SAP, and related platforms
Built foundational expertise in compliance technology, e-discovery, and data structures that now informs technology selection and implementation
Developed cross-functional skills across Legal, HR, and operations that strengthen compliance program integration today
Capabilities

Core Expertise

Deep specialization across the compliance landscape — from investigations and anti-corruption to export controls and board reporting.

🔎

Investigations

1,800+ investigations across fraud, misconduct, harassment, retaliation, FCPA, conflicts of interest, and labor matters. Consistent, fair, and well-evidenced case management.

🌐

Anti-Corruption & FCPA

Third-party due diligence, gifts & entertainment monitoring, and anti-bribery frameworks. Hands-on investigation and remediation of corruption-related matters.

Export Controls

Built and led ITAR/EAR/DOE Part 810 frameworks as one domain within a broader compliance portfolio. Empowered Official with classification and determination authority.

📣

Speak-Up Culture

Hotline governance, anti-retaliation programs, and reporting confidence initiatives sustaining 70% measured employee confidence in speak-up channels across 10,000+ employees.

📊

Board & Committee Reporting

Periodic and on-request reporting to the Compliance Committee and Board Audit Committee on export controls, investigation trends, program metrics, and regulatory risk posture.

🤝

M&A Integration

Compliance due diligence and post-close integration ensuring rapid adoption of Code of Conduct, speak-up channels, investigations framework, and core training.

Perspective

How I Think About AI and Compliance

Positions formed running a compliance program while leading AI adoption inside it, not from the sidelines.

Governance written by people who have never run a case fails in predictable places

Most AI governance frameworks are drafted by teams that will never live under them. They are strong on principle and weak at the point where someone has to make a decision on an actual matter, on a deadline, with incomplete facts. The test of a framework is not whether it reads well to a board. It is whether the person doing the work can apply it on a Tuesday afternoon without calling a lawyer.

Compliance should be the first adopter, not the last approver

The standard pattern puts compliance at the end of the process, reviewing what other functions have already built. That guarantees friction and produces governance that arrives too late to shape anything. Running the tools inside compliance first means the guardrails are tested on real work before they are imposed on anyone else, and it means the function has standing when it does say no.

The efficiency case and the risk case are the same case

Time saved on drafting is only real if the output survives scrutiny. An investigation report produced in 45 minutes instead of four hours is worthless if it cannot withstand a regulator, a plaintiff, or an arbitrator. Human review at every step is not a concession to caution. It is what makes the speed defensible.

Regulated industries do not get to wait for the rules to settle

Waiting for regulatory clarity is a strategy for sectors that can afford to be late. In a national-security-adjacent manufacturing environment, the tools are already in use whether or not a policy exists. The practical question is not whether to adopt but whether adoption happens with visibility and controls or without them.

Connect

Compare Notes

I write and speak about AI governance, investigations, and compliance program design in regulated industries. If you are working through the same problems, I am glad to compare notes.