AI has driven massive change in three years, but governance hasn’t kept up, creating integrity and compliance gaps. Risks from hallucinations, misunderstood outputs, and democratized use are now clearer, while some organizations are cutting soaring AI costs.
Ruth Prickett
Ruth Prickett graduated from Cambridge University with a BA hons in History and has specialized in business and finance journalism for the past 20 years. She was editor of Financial Management, the magazine for the Chartered Institute of Management Accountants, for many years before relaunching and editing Audit & Risk magazine for the Chartered IIA. She has written for a wide range of specialist business titles and drafted white papers and reports for clients including HSBC and Vodafone.
FCA warns firms to tighten non-financial misconduct compliance after Crispin Odey’s lifetime ban upheld
The U.K. financial regulator has warned firms that it wonโt tolerate a โslapdashโ approach to ethics and non-financial misconduct.
Manufacturers of EU digital products must now report cyber incidents within 24 hours
If you make or sell digital products in the EU, you must now report all exploited vulnerabilities and โsevereโ incidents that impact their security within 24 hours of becoming aware of them. These rules apply to every sector that produces products with a digital element โ from baby monitors to smart watches and apps.
U.K. AI risk management toolkit targets current and future compliance
The U.K. government has published an AI Risk Management Toolkit for โmultidisciplinary teamsโ who work with AI implementations, procurement, or delivery.
New audit quality control standard amended to reduce compliance burden
Important revisions to the new audit quality control QC 1000 standard have been announced by the Public Company Accounting Oversight Board. The intention is to increase flexibility for audit firms and reduce compliance costs.
U.K. promises corporate reporting reforms will slash compliance costs and focus on reportsโ purpose
The U.K. government has published a consultation promising โonce in a generationโ changes to corporate reporting. It said โcommon senseโ changes will save companies more than $603 million a year.
Moody’s urges banks to integrate compliance, culture and AI governance to accelerate processes and drive growth
Compliance teams must focus on governance, culture, and โexplainabilityโ to help banks thrive using AI in a competitive, complex regulatory environment. A new survey from Moody’s found this is why most banks now embed compliance from a project’s earliest stages, with only 17 percent treating it as a “final approval gate.”
IIA publishes guidance on how the Three Lines Model and ERM can meet evolving organizational risks
Two new position papers by the IIA highlight the way corporate governance is maturing in line with rapidly emerging risks. The documents focus on the Three Lines Model of governance and on enterprise risk management and set more ambitious parameters for collaboration between multiple governance functions, including compliance.
KPMG report urges CCOs to collaborate and invest to boost operational resilience
Enhanced operational resilience is key to improving responses to interconnected cyber, third-party and regulatory risks, according to KPMGโs 2026 chief ethics and compliance officer survey.
Deloitte agrees to pay U.S. government $21.5 million to settle alleged DEI discrimination
Professional services firm Deloitte has agreed to pay the U.S. government $21.5 million to settle a case alleging that the firmโs employment practices were discriminatory.


