Posted inBest Practices

When compliance reporting creates false assurance

Boards are not short of compliance information. Most receive dashboards, heat maps, training figures, investigation data, audit findings, remediation updates, and regulatory summaries. The difficulty is deciding what all that information really says. A report can be accurate, well presented, and still leave directors with too much confidence. That happens when evidence of activity is […]

Posted inSanctions

How ordinary Russian investors got caught in the sanctions net

When sanctions against Russia began multiplying in 2022, the public images were hard to miss: Yachts seized in European ports, villas frozen, bank accounts linked to oligarchs blocked. What I remember from the compliance side looked less visible and much more procedural. It was passports, residence permits, source-of-wealth documents, ownership charts, explanations of old bank […]

Posted inBest Practices

Navigating the supply chainโ€™s new normal

A supply-chain disruption can look simple: A supplier cannot deliver, procurement finds an alternative, engineering qualifies it and production continues. Geopolitical disruption rarely arrives labeled as a compliance problem. It arrives as a sourcing decision, engineering fix or logistics reroute before compliance becomes involved. Recent developments include: Enforcement shows what can be at stake. In […]

Posted inBest Practices

Record-setting AML penalty against UBS was years in the making

FinCEN and several other regulators levied a combined $125 million penalty against UBS Financial Services (UBSFS), a broker-dealer and futures commission merchant, due to a series of long-standing compliance failures.ย The total penalty was a joint effort of federal regulators, including FINRA ($20 million), the Securities and Exchange Commission ($20 million), and the Commodity Futures Trading […]

Posted inBest Practices

Beyond breaching privacy: The compliance risks of workplace surveillance

When organizations implement workplace surveillance tools, the conversation often begins with privacy. Questions about employee consent, data collection, retention periods, and legal compliance are essential. But as workplace monitoring technologies become more sophisticated, focusing exclusively on privacy risks often overlooks a much larger challenge.

Posted inBest Practices

The inference gap: Auditing the AI risk no framework requires you to see

When external regulation lags, internal audit becomes the only line of defense. AIโ€™s environmental footprint is a live governance exposure, and right now, almost no one is auditing it. A company can run an AI product billions of times a day with no obligation to measure what it consumes: No requirement to report the energy […]

Posted inBest Practices

AI demands a new risk operating model. Are risk leaders up to the task?

For years, risk, compliance, and internal audit functions have been asked to absorb and integrate new technologies and ways of working while facing off against increased business expectations without fundamentally changing the risk management operating model that underpins them. Capabilities such as continuous controls monitoring, dynamic risk assessments, and new reporting requirements have been layered […]

Verify your email

We'll send a verification code to .

Gift this article