For more than two decades, assurance and compliance frameworks have rested on a simple assumption: Material decisions are made by people. PostโSarbanes-Oxley Act (SOX) assurance reset worked because it aligned accountability with human behavior.ย That assumption shapes how internal controls are designed, how accountability is assigned, and how assurance is delivered.
Best Practices
Six AI questions compliance officers must answer in 2026
As artificial intelligence reshapes business, compliance teams face new questions about risk and oversight. These are the key issues compliance professionals should be asking as they evaluate their programs heading into 2026.
Congress Is About to Regulate Crypto. Criminals Are Ready.
Congress is moving toward rules for cryptocurrency. Thatโs overdue. For years, crypto markets have grown faster than the laws meant to ensure they arenโt exploited by criminals.
Experts outline core skills compliance teams need to develop in 2026
Compliance teams will face a range of ongoing challenges in the coming year, as well as greater demands from boards and management for better, wider, and more real-time assurance on an increasing range of risk topics.ย
Managing the permanent tension between compliance and business delivery
Business delivery runs on market deadlines. Compliance runs on regulatory mandates.
From NATO to nature crime. A practitionerโs perspective on greenwashing
From NATO and the UN to wildlife crime and finance, Chris Jagger explains why banks need smarter, more agile compliance to stay ahead of criminals.
Safely leveraging generative AI: A practical guide for compliance leaders
Generative AI (GenAI) has moved rapidly from experimentation into day-to-day use across many organizations. Over the past year, teams have shifted from exploratory pilots to relying on these tools for core activities such as contract analysis, research, and software development.ย
Bribery exposure doesnโt start with policy failure. It starts with training.
Anti-bribery and corruption failures in financial institutions rarely stem from bad policies.
Building resilient teams in cyberdefense
The stress on cyberdefense teams can be accurately described as a form of chronic occupational trauma stemming from several unique pressures. But there are ways to build a culture that combats these pressures.
The invisible cost of digital defense on mental health
Cybersecurity professionals, particularly those in leadership roles, often face immense pressure and stress due to the constant threat of cyberattacks.ย


