<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Corporate Compliance Insights</title>
	<atom:link href="https://www.corporatecomplianceinsights.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<description>The Web's Premier News Source for Compliance, Ethics &amp; Risk</description>
	<lastBuildDate>Tue, 08 Sep 2026 19:41:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/11/cropped-Favicon-32x32.png</url>
	<title>Corporate Compliance Insights</title>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>How Blockchain Intelligence Became Essential To Corporate Compliance</title>
		<link>https://www.corporatecomplianceinsights.com/how-blockchain-intelligence-became-essential-corporate-compliance/</link>
		
		<dc:creator><![CDATA[Finn Grant]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 19:41:01 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[AML]]></category>
		<category><![CDATA[Cryptocurrency]]></category>
		<category><![CDATA[Know Your Customer (KYC)]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68198</guid>

					<description><![CDATA[<p>Crypto was initially built on the promise of permissionless finance, a system with no gatekeepers, no intermediaries and no paperwork. However, as the adoption of digital assets has grown, that original vision has collided with the strict realities of the traditional financial system, writes crypto intelligence writer Finn Grant. With regulators cracking down globally, crypto compliance has evolved from an abstract concern into a central operational requirement for survival.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/how-blockchain-intelligence-became-essential-corporate-compliance/">How Blockchain Intelligence Became Essential To Corporate Compliance</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><em>Crypto was initially built on the promise of permissionless finance, a system with no gatekeepers, no intermediaries and no paperwork. However, as the adoption of digital assets has grown, that original vision has collided with the strict realities of the traditional financial system, writes crypto intelligence writer Finn Grant. With regulators cracking down globally, crypto compliance has evolved from an abstract concern into a central operational requirement for survival.</em></p>
</div>
<p>For more than 15 years, the regulatory stance towards digital assets was somewhat ambiguous, but the rules are finally firming up. The Financial Action Task Force (FATF) <strong><a href="https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html" target="_blank" rel="noopener">reported in a June 2025 update</a></strong> that travel rule frameworks are already adopted or in progress across 99 different jurisdictions. With approximately $51 billion in on-chain activity linked to illicit actors in 2024 alone, regulators are pushing aggressively for industry-wide compliance.</p>
<p>Today, businesses involved in crypto must navigate a complex web of obligations:</p>
<ul>
<li><strong>KYC (Know Your Customer) and AML (anti-money laundering):</strong> Businesses must verify customer identities at onboarding and implement ongoing policies to detect and prevent money laundering.</li>
<li><strong>The travel rule:</strong> Virtual Asset Service Providers (VASPs) are required to collect, verify and share identifying information about transaction originators and beneficiaries when transferring crypto.</li>
<li><strong>Sanctions screening &amp; transaction monitoring:</strong> Companies must continuously analyze customer behavior for financial crime and check wallet addresses against government-published lists of sanctioned individuals and entities.</li>
</ul>
<h2>The billion-dollar cost of noncompliance</h2>
<p>The consequences of ignoring these regulations can destroy a business. Regulators have made it clear that they will aggressively pursue platforms operating with inadequate AML and KYC programs.</p>
<p>Enforcement actions in 2025 alone saw crypto exchanges bear $927.5M in AML/CFT penalties. Historical precedents are even steeper: Binance famously pleaded guilty in the US and paid over $4 billion to resolve its criminal liability, while BitMEX faced a $100 million enforcement action for failing to file suspicious activity reports (SARs) and institute proper AML programs. In Europe, more than 50 crypto firms had their licenses revoked under MiCA as of November 2025 for failing to meet compliance standards.</p>
<h2>Why blockchain intelligence is the solution</h2>
<p>To survive in this environment, companies require a functional, risk-based compliance program, and traditional finance tools simply do not work on-chain. The public nature of blockchain ledgers creates a unique advantage: every transaction is recorded permanently and is fully auditable.</p>
<p>This is where blockchain intelligence steps in to bridge the gap. By using advanced analytics platforms like <strong><a href="https://arkm.com/" target="_blank" rel="noopener">Arkham</a></strong>, compliance teams can link raw cryptocurrency activity to real-world entities. Arkham deanonymizes blockchain transactions, transforming alphanumeric noise into actionable intelligence for compliance and investigative purposes.</p>
<p>A customer may pass initial KYC checks at onboarding but later receive funds from a compromised source. Pure KYC cannot catch this, but continuous transaction monitoring powered by blockchain intelligence can. By integrating the <strong><a href="https://intel.arkm.com/api" target="_blank" rel="noopener">Arkham API</a></strong> into your internal systems, you gain access to Ultra, Arkham&#8217;s proprietary crypto address-matching engine. This allows enterprise compliance teams to customize data flows, monitor transactions in near real-time and screen incoming deposits against known illicit sources before funds are ever accepted.</p>
<p>As regional frameworks like MiCA reach full enforcement and institutional capital demands robust compliance counterparties, having the right tech stack is no longer optional.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/how-blockchain-intelligence-became-essential-corporate-compliance/">How Blockchain Intelligence Became Essential To Corporate Compliance</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Compliance Job Interview 2026</title>
		<link>https://www.corporatecomplianceinsights.com/compliance-job-interview-2026/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 18:36:35 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[eBooks Published by CCI]]></category>
		<category><![CDATA[Leadership and Career]]></category>
		<category><![CDATA[Resource Library]]></category>
		<category><![CDATA[Compliance Classroom]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Mentoring]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=67484</guid>

					<description><![CDATA[<p>Developed with guest editor Mary Shirley, this toolkit breaks down what compliance hiring managers are actually looking for — and arms candidates with the strategic questions they should be asking right back.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/compliance-job-interview-2026/">The Compliance Job Interview 2026</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<a href="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2026-The-Compliance-Job-Interview_062426-c-791x1024.jpg" target="_blank" class="vc_single_image-wrapper vc_box_shadow  vc_box_border_grey"><img fetchpriority="high" decoding="async" class="vc_single_image-img " src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/2026-The-Compliance-Job-Interview_062426-c-385x500.jpg" width="385" height="500" alt="2026 The Compliance Job Interview_062426-c" title="" /></a>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans;">The compliance job interview hasn&#8217;t kept pace with the profession. Hiring managers still rely on questions that reveal little about whether a candidate can actually navigate gray areas, influence resistant stakeholders or build a defensible program under pressure. And candidates often walk in underprepared — or worse, unprepared to evaluate whether the organization deserves them.</p>
<p style="font-family: work sans;">This toolkit, developed with guest editor Mary Shirley, is built to fix both problems. Organized by experience level, it explains not just what hiring managers are asking today but what they&#8217;re actually trying to learn and how candidates can respond with substance rather than just performance.</p>
<p style="font-family: work sans;">It also includes something most interview guides leave out: a robust set of reverse-interview questions candidates can use to assess an organization&#8217;s genuine commitment to compliance. Here&#8217;s a look at what you&#8217;ll get:</p>
<ul>
<li style="font-family: work sans;">Interview questions and preparation guidance for junior (1-3 years), intermediate (4-11 years) and senior (12+ years) compliance professionals.</li>
<li style="font-family: work sans;">Frank discussion of what hiring managers are actually evaluating and what candidates sometimes miss.</li>
<li style="font-family: work sans;">Strategic questions for candidates to probe organizational culture, leadership tone and program maturity.</li>
<li style="font-family: work sans;">A CCO-specific framework for assessing board access, reporting structures, resources and risk appetite.</li>
</ul>
<p style="font-family: work sans; font-weight: bold; font-size: 32px;">Instant Download: Read it Now</p>
<p style="font-family: work sans;"><em><strong>Can’t see the download form? Disable your ad blocker.</strong></em></p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "a8c1db93-2d9e-4e9c-ab49-3ad7dcbe90b2",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/compliance-job-interview-2026/">The Compliance Job Interview 2026</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Increased Anonymous Reporting is a Signal Compliance Leaders Cannot Ignore</title>
		<link>https://www.corporatecomplianceinsights.com/increased-anonymous-reporting-signal-compliance-leaders-cannot-ignore/</link>
		
		<dc:creator><![CDATA[Gregory Keating]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 11:00:08 +0000</pubDate>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Whistleblowing]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68188</guid>

					<description><![CDATA[<p>An alarming number of workers are choosing to report anonymously likely out of fear of retaliation within their organization</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/increased-anonymous-reporting-signal-compliance-leaders-cannot-ignore/">Increased Anonymous Reporting is a Signal Compliance Leaders Cannot Ignore</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Against a backdrop of job insecurity, general instability and fear of retaliation, increased anonymous reporting will continue, Gregory Keating of Littler predicts. That is unless corporate leaders and compliance professionals make meaningful strides in their programs. </span></i></p>
</div>
<p><span style="font-weight: 400;">A trend has emerged that should cause tremors throughout the </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> community. Recent benchmarking and survey data indicate that anonymous reporting on whistleblower hotlines has increased or remained elevated in recent years, reversing an earlier trend toward named reporting. </span></p>
<p><span style="font-weight: 400;">NAVEX Global, which canvassed more than 2 million reports across over 4,000 organizations, </span><a href="https://www.navex.com/en-us/resources/reports/whistleblowing-incident-management-report/" target="_blank" rel="noopener"><b>reported</b></a><span style="font-weight: 400;"> in its 2025 benchmark report that about 52% of reports in the US were made anonymously. In a </span><a href="https://www.ethico.com/resources/benchmark-report" target="_blank" rel="noopener"><b>2026 report</b></a><span style="font-weight: 400;">, Ethico found a 5% drop in the number of self-identified reporters from the previous year, the largest single-year reversal in its dataset.</span></p>
<p><span style="font-weight: 400;">Seasoned compliance professionals should recognize that this is a dangerous development. While the availability of anonymous reporting is a widespread and even required feature of reporting policies and procedures, a trend toward an increased incidence of anonymous rather than named reporting introduces challenges to an organization’s efforts to identify and remedy misconduct. Complaints by anonymous reporters are significantly more challenging to investigate and often suffer from significantly lower substantiation rates. The point is not to close the door to anonymous reporting but rather to create a workplace </span><a href="https://www.corporatecomplianceinsights.com/tag/corporate-culture/" target="_blank" rel="noopener"><b>culture</b></a><span style="font-weight: 400;"> in which employees with concerns feel comfortable and even welcome to come forward, knowing they will be met with serious interest and steadfast protection from retaliation.</span></p>
<p><span style="font-weight: 400;">Those familiar with organizational </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> understand that the efficacy of an organization’s compliance program can be seen in the overall level and quality of reporting. On one end of the spectrum is crickets — little to no reports or communications emanating from employees up to the organization. On the other end is a steady volume of reporting where individuals come forward in person. In the middle lies continued reporting from those in the organization but in a manner whereby the reporters are more inclined to choose anonymity.  </span></p>
<h2><span style="font-weight: 400;">What reporting reveals about workplace culture</span></h2>
<p><span style="font-weight: 400;">A healthy organization should experience a steady volume of compliance reports with reporters willing to identify themselves as they come forward. Professor Kyle Welch at George Washington University accessed and </span><a href="https://www.jstor.org/stable/45378713" target="_blank" rel="noopener"><b>analyzed</b></a><span style="font-weight: 400;"> enormous amounts of data from hotline reporting channels. He concluded in 2020 that organizations with robust internal reporting have stronger cultures and better business outcomes, including higher profitability and return on assets, reduced litigation costs and fewer external reports to regulators.</span></p>
<p><span style="font-weight: 400;">By contrast, a culture of silence and rare reporting in the workplace is widely viewed as a leading indicator of compliance risk. A 2022 </span><a href="https://sloanreview.mit.edu/article/fostering-ethical-conduct-through-psychological-safety/" target="_blank" rel="noopener"><b>study</b></a><span style="font-weight: 400;"> published in MIT Sloan Management Review found that silence among workers and an unwillingness to report is directly tied to a feeling of being psychologically unsafe.</span></p>
<p><span style="font-weight: 400;">Until as recently as 2023, empirical data indicated a trend toward an increased willingness among employees to report suspected misconduct — likely the effect of increased focus on robust compliance programs and effective </span><a href="https://www.corporatecomplianceinsights.com/tag/training/" target="_blank" rel="noopener"><b>training</b></a><span style="font-weight: 400;">. In a 2023 </span><a href="https://www.navex.com/en-us/blog/article/ecis-2023-global-business-ethics-survey-reveals-harsh-realities-about-ec-programs/" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;">, ECI found that 72% of employees reported misconduct when they observed it. This reflected a then-record-high reporting rate.</span></p>
<p><span style="font-weight: 400;">But this upward trajectory has taken a sharp and troubling detour in the past three years. In what has been described as a trend toward “scared reporting,” an increasing number of employees have indicated that while they are generally inclined to report misconduct when they observe it, many of those same employees in fact chose not to do so when they witnessed it. Ethisphere’s 2024 </span><a href="https://ethisphere.com/2024-culture-report/" target="_blank" rel="noopener"><b>ethical cultural report</b></a><span style="font-weight: 400;">, based on 2 million responses from around the world, found that while 93% of employees said that they were inclined to report misconduct only 50% actually did so. </span></p>
<p><span style="font-weight: 400;">What has caused this trend? Fear. Recent developments, including geopolitical uncertainty and the rapid rise of </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> in the workplace and attendant concerns about job security, have increased anxiety and uncertainty in the workplace. A 2025 Pew Research Center </span><a href="https://www.pewresearch.org/social-trends/2025/02/25/u-s-workers-are-more-worried-than-hopeful-about-future-ai-use-in-the-workplace/" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> of over 5,000 employees found that 52% are worried about the future of AI in the workplace and nearly a third believed AI will lead to fewer job opportunities for them in the future. In that environment, employees may be more likely to worry that raising concerns will mark them as difficult, disloyal or expendable.</span></p>
<p><span style="font-weight: 400;">Recent </span><a href="https://www.corporatecomplianceinsights.com/news-roundup-october-17-2024/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> reflects that fear of retaliation is a significant factor causing workers not to report. The most recent global surveys are all consistent in finding a noticeable increase in employees reporting that they fear retaliation should they speak up about workplace misconduct. According to the Equal Employment Opportunity Commission’s enforcement and litigation </span><a href="https://www.eeoc.gov/data/enforcement-and-litigation-statistics-0" target="_blank" rel="noopener"><b>statistics</b></a><span style="font-weight: 400;">, retaliation is the No. 1 employment law claim in the US, making up roughly 48% of all claims.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68188_0_6aa06b280ab0e   " data-unique="jnews_module_68188_0_6aa06b280ab0e">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/are-your-anonymous-reporting-channels-hiding-bigger-problem/" aria-label="Read article: Are Your Anonymous Reporting Channels Hiding a Bigger Problem?"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="anonymous faceless man" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/anonymous-faceless-man-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/anonymous-faceless-man-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/anonymous-faceless-man-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/03/anonymous-faceless-man-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/ethics/">Ethics</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/are-your-anonymous-reporting-channels-hiding-bigger-problem/">Are Your Anonymous Reporting Channels Hiding a Bigger Problem?</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/vera-cherepanova/">Vera Cherepanova</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/are-your-anonymous-reporting-channels-hiding-bigger-problem/"><i class="fa fa-clock-o"></i> March 18, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>When a friend is the target of a report, resist the urge to disrupt established processes</p>
                                    <a href="https://www.corporatecomplianceinsights.com/are-your-anonymous-reporting-channels-hiding-bigger-problem/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68188_0_6aa06b280ab0e = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"66407","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">What compliance professionals can do</span></h2>
<p><span style="font-weight: 400;">The time is now for compliance professionals and the organizations they support to invest in concrete measures that will encourage a return to self-identified reporting and help avoid the potential spiral into a workplace culture of fear, silence and avoidance.</span></p>
<p><span style="font-weight: 400;">Four recommendations should be considered. </span></p>
<p><span style="font-weight: 400;">First, research overwhelmingly demonstrates that the optimal starting point for any workplace concern is with an employee’s manager. Organizations must engage in training of managers so that they understand the pivotal role they play, are able to recognize nuanced concepts like what is “protected activity” and an “adverse action” and understand their obligation to communicate effectively with compliance, HR and legal. </span></p>
<p><span style="font-weight: 400;">Second, organizations should consider holding managers accountable by measuring and ranking their commitment to compliance annually as a metric in their performance evaluations. </span></p>
<p><span style="font-weight: 400;">Third, organizations should also </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>audit</b></a><span style="font-weight: 400;"> and modify their </span><a href="https://www.corporatecomplianceinsights.com/tag/internal-investigation/" target="_blank" rel="noopener"><b>investigation</b></a><span style="font-weight: 400;"> protocols to ensure that they have communication channels in place to respond to anonymous complaints. These can be challenging to investigate, but numerous vendors have established protocols that allow the organization to communicate back to anonymous reporters, who should be given the opportunity to remain anonymous yet cooperate by either providing more specific information or meeting face-to-face with an independent third-party investigator retained by the organization. </span></p>
<p><span style="font-weight: 400;">Finally, organizations should endeavor to create a culture in which good-faith reporting is modeled, encouraged and met with a prompt and effective response. An organization must articulate and commit to a strong anti-retaliation policy, protecting and encouraging employees who come forward and continuously demonstrating that others can come forward without fear of retaliation.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/increased-anonymous-reporting-signal-compliance-leaders-cannot-ignore/">Increased Anonymous Reporting is a Signal Compliance Leaders Cannot Ignore</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Is a Stickler for the Rules, but Rules Don’t See Everything</title>
		<link>https://www.corporatecomplianceinsights.com/ai-stickler-for-rules-see-everything/</link>
		
		<dc:creator><![CDATA[Neil Sahota]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 11:06:21 +0000</pubDate>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68191</guid>

					<description><![CDATA[<p>Human inconsistencies and man-made exceptions are often overlooked in AI deployments</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/ai-stickler-for-rules-see-everything/">AI Is a Stickler for the Rules, but Rules Don’t See Everything</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Rules are made for AI to follow, but exceptions to rules come from human experience. Neil Sahota, AI strategist and board director, discusses the balance of rules, experience, precision and exceptions needed to balance AI automation. Get that mix wrong and AI could commit a major foul.</span></i></p>
</div>
<p><span style="font-weight: 400;">The referee makes the call. Seconds later, play stops.</span></p>
<p><span style="font-weight: 400;">It happens across nearly all sports, where a video assistant referee (VAR), video reviews and instant replays have become ubiquitous in enforcing rules. Different angles expose details the human eye could miss, technology provides the evidence, and officials apply the rule. The decision is made … and people still argue about the call.</span></p>
<p><span style="font-weight: 400;">Our instinct is to blame VAR, but nothing malfunctioned. The technology accurately captured what happened. The officials correctly applied the rule. The system worked exactly as designed.</span></p>
<p><span style="font-weight: 400;">But what if the problem was the rule itself?</span></p>
<p><span style="font-weight: 400;">This question goes beyond sports. As companies embed </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> into </span><a href="https://www.corporatecomplianceinsights.com/fraud-news/" target="_blank" rel="noopener"><b>fraud</b></a><span style="font-weight: 400;"> detection, lending, hiring, pricing, procurement and other decisions, they excel in consistency. This is not always good news.</span></p>
<h2><span style="font-weight: 400;">Rules vs. experience</span></h2>
<p><span style="font-weight: 400;">People are inconsistent rule followers. We overlook things, we make exceptions. AI eliminates much of this variation. Give a machine a rule, and it will apply it to the first decision and the millionth with remarkable consistency. But put this in the context of a poorly written or ineffective rule: People may apply a bad rule inconsistently, but AI won’t. AI will apply the bad rule a million times.</span></p>
<p><span style="font-weight: 400;">AI&#8217;s greatest governance </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> is consistency at scale. Worse, what companies call human inconsistency isn&#8217;t always an error. Sometimes, it is experience.</span></p>
<p><span style="font-weight: 400;">Imagine veteran fraud investigators who repeatedly override the same category of AI-generated alert. Management sees exceptions. Compliance sees deviation. The AI team sees users who aren&#8217;t trusting the model. But what do the investigators see?</span></p>
<p><span style="font-weight: 400;">Perhaps they learned through thousands of cases that a particular customer behavior looks suspicious according to policy but is usually legitimate. This judgment call won’t appear in the procedure manual because it springs from years of human experience.</span></p>
<p><span style="font-weight: 400;">Historically, this is how organizations operated. The official process says one thing while experienced employees make thousands of tiny adjustments that allow the process to work in the real world. Then, AI arrives. Management says: “Automate the process.” But which process?</span></p>
<p><span style="font-weight: 400;">Typically, we encode the process we can see: the documented rules, decision trees, thresholds and procedures. Yet, the thousands of judgment calls employees make between those steps are much harder to capture.</span></p>
<p><span style="font-weight: 400;">The company believes it automated the operating model. Unfortunately, more often, it automated the function of how its operating model actually works.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68191_1_6aa06b2816176   " data-unique="jnews_module_68191_1_6aa06b2816176">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/in-healthcare-ai-mistake-cost-license-life/" aria-label="Read article: In Healthcare, an AI Mistake Can Cost a License or a Life"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="doctor with computer for head digital collage" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/doctor-with-computer-for-head-digital-collage-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/doctor-with-computer-for-head-digital-collage-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/doctor-with-computer-for-head-digital-collage-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/doctor-with-computer-for-head-digital-collage-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/compliance/">Compliance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/in-healthcare-ai-mistake-cost-license-life/">In Healthcare, an AI Mistake Can Cost a License or a Life</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/christine-chasse/">Christine Chasse</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/in-healthcare-ai-mistake-cost-license-life/"><i class="fa fa-clock-o"></i> August 3, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>AI scales safety risks in healthcare to unprecedented levels</p>
                                    <a href="https://www.corporatecomplianceinsights.com/in-healthcare-ai-mistake-cost-license-life/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68191_1_6aa06b2816176 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67814","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Precision vs. exceptions</span></h2>
<p><span style="font-weight: 400;">This is where the VAR offers a lesson. While better technology tells us with better precision what happened and if a rule was followed, it cannot determine whether the assumptions behind our rules still make sense.</span></p>
<p><span style="font-weight: 400;">In fact, greater precision may expose weaknesses that human inconsistency previously concealed. This should change how executives think about AI </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;">. Yet, we rarely ask: What human judgment makes this process work that is not documented? The answer hides in the exceptions.</span></p>
<p><span style="font-weight: 400;">Before AI eliminates your exceptions, find out why the exceptions are there and what knowledge they may signal. Consider what people interpret and establish as guidelines. Once embedded into an AI-enabled workflow, the same policy becomes executable infrastructure and operates continuously at enormous scale. This creates a different question for executive teams and </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>boards</b></a><span style="font-weight: 400;">: What assumptions do people turn into infrastructure?</span></p>
<p><span style="font-weight: 400;">During almost any sporting match, millions of people watch VAR or video replays and still question the call. Inside a company, there is no stadium watching as AI converts yesterday&#8217;s assumptions into tomorrow&#8217;s decisions.</span></p>
<p><span style="font-weight: 400;">Ironically, the true danger is that AI may understand them perfectly.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/ai-stickler-for-rules-see-everything/">AI Is a Stickler for the Rules, but Rules Don’t See Everything</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor</title>
		<link>https://www.corporatecomplianceinsights.com/deferred-not-ignored-explaining-unpatched-vulnerabilities-your-auditor/</link>
		
		<dc:creator><![CDATA[Apu Pavithran]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 11:00:58 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Cyber Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68185</guid>

					<description><![CDATA[<p>Teams should follow CISA’s lead and create the documentation and decision-making that gets the art of safe deferrals right</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/deferred-not-ignored-explaining-unpatched-vulnerabilities-your-auditor/">Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">We need to rethink patching going forward, Apu Pavithran, CEO and founder of Hexnode argues. It’s just not possible to immediately address every vulnerability, so risk prioritization becomes a defensible, evidence-based posture. </span></i></p>
</div>
<p><span style="font-weight: 400;">In June, the Cybersecurity and Infrastructure Security Agency (CISA) gave </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> teams an unexpected </span><a href="https://www.cisa.gov/news-events/news/patch-smarter-not-harder" target="_blank" rel="noopener"><b>gift</b></a><span style="font-weight: 400;">: permission </span><i><span style="font-weight: 400;">not</span></i><span style="font-weight: 400;"> to patch most of their vulnerabilities, provided they can defend the decision.</span></p>
<p><span style="font-weight: 400;">The new directive seeks to redefine urgency against a rising tide of automated vulnerabilities. Federal agencies are therefore moving away from updating software based on a calendar or severity score and toward assessing </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> and fast-tracking fixes for the most dangerous within three days.</span></p>
<p><span style="font-weight: 400;">This is a unique posture that businesses should consider mirroring for this moment. B</span><span style="font-weight: 400;">ad actors are probing networks more aggressively and reducing the time between vulnerability disclosure and exploitation</span><span style="font-weight: 400;">. Matching their speed is near-impossible, so determining what’s a priority and what’s deferrable is the next best course of action.</span></p>
<p><span style="font-weight: 400;">Crucially, chief compliance officers (CCOs) receive much-needed ammunition to explain to </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>auditors</b></a><span style="font-weight: 400;"> or insurers what’s left unpatched and why. As a result, patch prioritization is becoming both a compliance essential and security foundation.</span></p>
<p><span style="font-weight: 400;">This shift acknowledges the reality of the </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> age. </span><a href="https://www.computerweekly.com/news/366619678/CVE-volumes-head-towards-50000-in-2025-analysts-claim" target="_blank" rel="noopener"><b>Last year</b></a><span style="font-weight: 400;">, around 50,000 common vulnerabilities and exposures (CVEs) were announced, up two-thirds from 2023. The notion to “patch everything” as soon as a new vulnerability arrives is no longer feasible in this landscape.</span></p>
<p><span style="font-weight: 400;">It’s telling that this perspective is gaining traction at a federal level: The nation’s </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cyber-defense</b></a><span style="font-weight: 400;"> agency is formally instructing teams to stop treating all vulnerabilities as equal and instead triage by risk. Under the directive, a vulnerability is assessed across several factors — public exposure, automatable exploitation, whether exploitation hands an attacker full system control and evidence of real-world exploitation — with only the highest-risk few fast-tracked. Enterprises should sit up and pay attention to this because, in effect, the standard-setter is conceding that risk-based patching is the preferable posture.</span></p>
<p><span style="font-weight: 400;">Consider this alongside</span><a href="https://www.corporatecomplianceinsights.com/nist-database-change-rebalances-burden-risk/" target="_blank" rel="noopener"> <b>NIST’s recent decision</b></a><span style="font-weight: 400;"> to enrich fewer vulnerability records with severity scores and affected product details. It, too, is struggling with the scale of new vulnerabilities and deciding to focus on threats that appear in the known exploited vulnerabilities (KEV) catalog, affect software used within the federal government or apply to “critical software”.</span></p>
<p><span style="font-weight: 400;">The onus is increasingly on internal teams not only to decide what to patch first but to log the reasoning behind it. This represents a major change because prompt patching has long been a cornerstone for keeping auditors and insurers onside. But in a triage model, a clear record of what you didn’t patch and why matters just as much.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68185_2_6aa06b281bd47   " data-unique="jnews_module_68185_2_6aa06b281bd47">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/nist-database-change-rebalances-burden-risk/" aria-label="Read article: NIST Database Change Rebalances Burden of Risk"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="nist sign building" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/nist-sign-building-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/nist-sign-building-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/nist-sign-building-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/07/nist-sign-building-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/cybersecurity/">Cybersecurity</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/nist-database-change-rebalances-burden-risk/">NIST Database Change Rebalances Burden of Risk</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/nichole-windholz/">Nichole Windholz</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/nist-database-change-rebalances-burden-risk/"><i class="fa fa-clock-o"></i> July 13, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Register of common vulnerabilities and exposures will have less federal context, leaving organizations to decide if a vulnerability warrants quick remediation</p>
                                    <a href="https://www.corporatecomplianceinsights.com/nist-database-change-rebalances-burden-risk/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68185_2_6aa06b281bd47 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67523","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">A compliance decision that creates formal risk acceptance</span></h2>
<p><span style="font-weight: 400;">By taking a page from CISA, corporate compliance can become stronger by plugging the most serious holes and documenting the what and the why of every deferral. This is a beneficial technical and cultural evolution for a few reasons.</span></p>
<p><span style="font-weight: 400;">First, deferral creates formal risk acceptance. Targeting the worst-of-the-worst vulnerabilities creates a new decision-making chain that takes some of the pressure off IT and loops in the CCO. This way, companies can intentionally defer less serious vulnerabilities and connect patching to </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> with an owner, rationale and record.</span></p>
<p><span style="font-weight: 400;">Second, we already know that very few enterprises remediate every known vulnerability.</span><a href="https://www.verizon.com/business/resources/Td15/reports/2026-dbir-data-breach-investigations-report.pdf" target="_blank" rel="noopener"> <b>Last year</b></a><span style="font-weight: 400;">, only one-quarter (26%) of critical vulnerabilities on CISA’s KEV catalog were fully remediated by organizations, down from 38% the previous year. Given the context of both more sophisticated and numerous threats, the stronger position in front of a regulator is a reasoned, criteria-based decision. Incorporating and enforcing a consistent risk-based stance separates a decision from an excuse, turning “we didn’t get to it” into “we assessed it and deferred it on these grounds.”</span></p>
<p><span style="font-weight: 400;">This kind of audit trail (what was deferred, against which criteria, signed off by whom and reviewed when) is valuable internally and externally. Most security and regulatory frameworks already require that vulnerability management be evidenced, not merely performed. And cyber-insurers increasingly want to see your thought process at renewal. Being able to align vulnerability management standards with a recognized third-party benchmark puts you in a far stronger position in an exam or breach post-mortem.</span></p>
<p><span style="font-weight: 400;">Remember, there’s an important difference between ignoring and deferring patches, and this posture gives teams the flexibility to focus on the most dangerous gaps as they emerge.</span></p>
<h2><span style="font-weight: 400;">Moving patch prioritization from theory to practice</span></h2>
<p><span style="font-weight: 400;">Putting this into practice (and making deferral less dangerous) starts with establishing a named owner and approval path. Define who signs, at what risk threshold and how escalations are handled. Having this record ready now, and in the format that an auditor or insurer will ask for, makes things much smoother if and when a breach occurs.</span></p>
<p><span style="font-weight: 400;">Also connect risk-based patching with your current reporting. For example, SOC 2 — the independent audit of whether a company’s </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>data-security</b></a><span style="font-weight: 400;"> controls actually work as stated — already requires evidence of vulnerability management. However, the framework doesn’t set a rule. Instead, it requires the company itself to establish a defensible, documented and consistently applied process and prove it. This is where teams can incorporate the risk criteria and response timelines defined by CISA, providing a much stronger process than a homegrown one that must be justified from scratch.</span></p>
<p><span style="font-weight: 400;">Finally, ensure that security and compliance co-own the patch call. The deferral decision needs the former’s risk read and the latter’s documentation discipline. Siloed, it fails both sides of the enterprise. Further, the risk framework only holds if the decision can actually be executed and demonstrated across the ecosystem. </span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/deferred-not-ignored-explaining-unpatched-vulnerabilities-your-auditor/">Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Substantiate Your AI Claims Before They Become AI-Washing Challenges</title>
		<link>https://www.corporatecomplianceinsights.com/substantiate-your-ai-claims-before-they-become-ai-washing-challenges/</link>
		
		<dc:creator><![CDATA[Andrew Lustigman and Barry Greenbaum]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 11:00:34 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68183</guid>

					<description><![CDATA[<p>With models, datasets and vendor APIs changing constantly, a claim that was accurate in the past may no longer hold up</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/substantiate-your-ai-claims-before-they-become-ai-washing-challenges/">Substantiate Your AI Claims Before They Become AI-Washing Challenges</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Recent regulatory activity illustrates why companies should take AI-washing seriously, Andrew Lustigman and Barry Greenbaum of Olshan explain. Remember: Your vendors’ marketing materials should not become your substantiation record. </span></i></p>
</div>
<p><span style="font-weight: 400;">Companies increasingly describe their products and services as </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/"><b>AI</b></a><span style="font-weight: 400;">-related. They promote “AI-powered” personalization, “AI-driven” recommendations, automated customer service, predictive analytics and other features across websites, sales decks, RFP responses, customer contracts, vendor disclosures and executive interviews. </span></p>
<p><span style="font-weight: 400;">The claims are everywhere, but in many cases the technology plays only a minor role or none at all. This gap between marketing language and technical reality has become known as “AI washing,” taking a page from overstated sustainability claims and resulting greenwashing, and can result in Federal Trade Commission (FTC) enforcement actions and advertising industry regulator challenges.</span></p>
<p><span style="font-weight: 400;">Advertising substantiation is not new. Regulators have long required companies to have a reasonable basis for objective claims before those claims are disseminated. What is new is the complexity of AI claims and the difficulty of evaluating the underlying technology. The standard, however, has not changed. Companies still need a reasonable basis for their objective claims. The challenge is that AI can make that basis harder to establish, evaluate and maintain.</span></p>
<h2><span style="font-weight: 400;">Define the claim</span></h2>
<p><span style="font-weight: 400;">The first challenge is often the claim itself. “AI‑powered,” “AI‑driven,” “intelligent” and “automated” can all mean different things depending on context. A customer may reasonably believe “AI‑powered customer service” to mean that an AI system handles interactions with little or no human involvement. The underlying product, however, may use AI only to suggest responses and require human reviews prior to sending. For example, Samsung faced a </span><a href="https://bbbprograms.org/media/newsroom/decisions/samsung"><b>challenge</b></a><span style="font-weight: 400;"> from the industry’s self-regulatory body, NAD, </span><b>r</b><span style="font-weight: 400;">egarding advertising for its Bespoke refrigerators, resulting in the discontinuance of claims that “smart” connectivity was AI-driven.</span></p>
<p><span style="font-weight: 400;">Before attempting to substantiate an AI claim, legal and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/"><b>compliance</b></a><span style="font-weight: 400;"> teams should ask: What would a reasonable customer understand this statement to mean? That question forces the organization to articulate what the technology actually does, whether it makes decisions, assists a human decision-maker or performs a narrow function within a larger rules‑based system. Defining the claim is the first step toward identifying the evidence required to support it.</span></p>
<h2><span style="font-weight: 400;">Evidence must match the promise</span></h2>
<p><span style="font-weight: 400;">After defining the claim, the next questions become whether the company has evidence to support it and whether that evidence matches what the claim promises.</span></p>
<p><span style="font-weight: 400;">If a company says its AI system is “95% accurate,” that should prompt questions about how accuracy was measured, what </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/"><b>data</b></a><span style="font-weight: 400;"> was used, what the system was tested against and under what conditions. A claim that the system is “more accurate than human reviewers” involves different considerations. It requires identifying who the reviewers were, what tasks they performed and whether the comparison was statistically meaningful. If a product is described as “fully automated” but employees routinely review or correct its output, the company should consider whether that human involvement changes what customers are likely to understand from the claim.</span></p>
<p><span style="font-weight: 400;">Regulators have not ignored these types of claims. In the case of </span><a href="https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-approves-final-order-against-workado-llc-which-misrepresented-accuracy-its-artificial"><b>FTC v. Workado, LLC</b></a><span style="font-weight: 400;">, the FTC challenged a company’s AI content detector as being “98% accurate” when independent testing revealed the number was </span><a href="https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-order-requires-workado-back-artificial-intelligence-detection-claims"><b>closer to 53%</b></a><span style="font-weight: 400;">. The company settled with the agency, agreeing to prohibitions on representations about the effectiveness of its AI products unless it had competent and reliable evidence to support the claim. </span></p>
<p><span style="font-weight: 400;">More recently, the FTC brought a trio of enforcement actions </span><a href="https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-finalizes-orders-cox-media-group-two-other-firms-settling-charges-they-deceived-customers-about"><b>against Cox Media Group</b></a><span style="font-weight: 400;"> and two small marketing agencies challenging claims that their “Active Listening” branded marketing service deployed a special algorithm to listen in on consumers’ conversations overheard by smart devices. The algorithm would then facilitate the delivery of targeted advertising in the advertisers’ desired locations. The FTC contended that the listening service did not actually listen in on consumers’ conversations or use voice data. Furthermore, the FTC contended that consumers had not opted in for this service. Cox Media Group and the marketing agencies settled the actions, paying nearly $1 million and agreeing to prohibitions on the qualities or features of its advertising or marketing services; the collection and use of voice </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/"><b>data</b></a><span style="font-weight: 400;"> and whether consumers have provided their consent to collect, use or disclose their voice data; and the geographic targeting capabilities of its advertising or marketing services.</span></p>
<p><span style="font-weight: 400;">In the self-regulatory context, Horizon Brands faced an NAD </span><a href="https://bbbprograms.org/media/newsroom/decisions/horizon-ai"><b>challenge</b></a><span style="font-weight: 400;"> regarding advertising claims for its Tiny Traveler “AI-powered Smart Baby Monitor Solution.” While the presence of an AI chip supported claims that the baby monitor did employ AI technology, NAD recommended that AI “emotion detection” and “motion detection” claims note their limitations and discontinue claims that the monitor can ensure infant safety. The challenge demonstrates that companies should be careful to limit claims that a feature is available if it is not yet live and be sure to disclose any limitations on performance and operating conditions.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68183_3_6aa06b2821bb1   " data-unique="jnews_module_68183_3_6aa06b2821bb1">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/nist-is-offering-new-ai-evaluation-framework-not-compliance-checklist/" aria-label="Read article: NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="nist headquarters sign" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/nist-headquarters-sign-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/nist-headquarters-sign-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/nist-headquarters-sign-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/nist-headquarters-sign-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/cybersecurity/">Cybersecurity</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/nist-is-offering-new-ai-evaluation-framework-not-compliance-checklist/">NIST Is Offering a New AI Evaluation Framework, Not Another Compliance Checklist</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/larry-marks/">Larry Marks</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/nist-is-offering-new-ai-evaluation-framework-not-compliance-checklist/"><i class="fa fa-clock-o"></i> August 21, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Draft framework TEVV-Athlon is designed for organizational flexibility</p>
                                    <a href="https://www.corporatecomplianceinsights.com/nist-is-offering-new-ai-evaluation-framework-not-compliance-checklist/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68183_3_6aa06b2821bb1 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"67984","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Substantiating the vendor</span></h2>
<p><span style="font-weight: 400;">Substantiation becomes more complicated when a company relies on third‑party AI technology. Retailers, </span><a href="https://www.corporatecomplianceinsights.com/financial-services-news/"><b>financial institutions</b></a><span style="font-weight: 400;">, software companies and other businesses increasingly incorporate AI tools supplied by vendors. A vendor may describe its technology as highly accurate, autonomous, secure or capable of producing a particular business outcome. Those representations often find their way into the customer’s own website, sales materials or RFP responses. But a vendor’s marketing materials should not automatically become the customer’s substantiation record.</span></p>
<p><span style="font-weight: 400;">Companies should understand what their vendors are providing and what evidence supports material claims about the technology. Vendor claims should be verified before they are incorporated into the company’s own marketing or customer communications. Contracts can help facilitate that process by requiring vendors to provide technical documentation, testing reports and notice of material changes. But contractual protections are not a substitute for understanding the product. If a company tells its customers that its own service provides a particular AI-enabled benefit, pointing to a vendor’s website after the fact is unlikely to establish whether the company’s statement was adequately supported.</span></p>
<h2><span style="font-weight: 400;">Consistency across the organization</span></h2>
<p><span style="font-weight: 400;">AI claims often span multiple departments, which increases the </span><a href="https://www.corporatecomplianceinsights.com/risk-news/"><b>risk</b></a><span style="font-weight: 400;"> of inconsistency. Marketing may approve language for a website. Product developers may describe the same feature differently in a sales presentation. A salesperson may make a broader representation. An executive may characterize the technology in a different way during an interview. Each statement may seem harmless on its own, but together, they can create a picture of the product that is considerably more expansive than what the technology actually does.</span></p>
<p><span style="font-weight: 400;">A coordinated review process involving legal or compliance, product or engineering and the business or marketing team responsible for communicating with customers can help ensure that everyone is working from the same understanding of the technology; it can also outline the evidence supporting the claim. The goal is not to require every communication to use identical language but to ensure that variations in messaging do not convey materially different impressions of what the technology can do.</span></p>
<h2><span style="font-weight: 400;">Ongoing substantiation</span></h2>
<p><span style="font-weight: 400;">Finally, companies should maintain a record for material AI claims and keep it current. The record should identify:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The precise claim.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Where it is being used.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The product or feature involved.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The evidence supporting it.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Any material limitations.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The designated individual responsible.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The date it was last reviewed.</span></li>
</ul>
<p><span style="font-weight: 400;">Maintaining a live, periodically updated record ensures ongoing accuracy.</span></p>
<p><span style="font-weight: 400;">Companies should also have final checks. Before approving an AI claim, companies should thoroughly review what they are saying, what a reasonable customer would understand and what evidence they have today. The companies that can answer these questions each time a claim is made will be the ones that build lasting trust, avoid regulatory risk and maintain credibility across the market. </span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/substantiate-your-ai-claims-before-they-become-ai-washing-challenges/">Substantiate Your AI Claims Before They Become AI-Washing Challenges</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Benchmarking Study: Third-Party Risk Management</title>
		<link>https://www.corporatecomplianceinsights.com/rethink-benchmark-tprm/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 16:19:33 +0000</pubDate>
				<category><![CDATA[Risk]]></category>
		<category><![CDATA[Whitepapers]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68166</guid>

					<description><![CDATA[<p>Third-party relationships are essential to modern business, but they can also introduce significant ethics and compliance risks. A new benchmarking study by Rethink Compliance explores how organizations are identifying, screening and managing those risks.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/rethink-benchmark-tprm/">Benchmarking Study: Third-Party Risk Management</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid vc_row-o-equal-height vc_row-flex"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-4 vc_custom_1659714795294 vc_col-has-fill"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper vc_box_shadow_3d  vc_box_border_grey"><img loading="lazy" decoding="async" width="791" height="1024" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-791x1024.jpg" class="vc_single_image-img attachment-large" alt="2026 Rethink Compliance TPRM Benchmarking Report-c" title="" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-791x1024.jpg 791w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-232x300.jpg 232w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-768x994.jpg 768w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-1187x1536.jpg 1187w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-750x971.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c-1140x1475.jpg 1140w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-TPRM-Benchmarking-Report-c.jpg 1200w" sizes="(max-width: 791px) 100vw, 791px" /></div>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;">Gauge the maturity of your TPRM program</p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "b55b8664-4bee-493d-93bc-bf605798731a",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-1"><div class="jeg_wrapper wpb_wrapper"></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-7"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element no-bottom-margin" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 18px; color: #e77c30;">Benchmarking study</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans black; font-size: 50px; color: #133350; line-height: 1.2;">Third-Party Risk Management</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 16px; color: #133350;">What&#8217;s in this report from Rethink Compliance:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Third-party relationships are essential to modern business, but they can also introduce significant ethics and compliance risks. Rethink Compliance’s 2026 benchmarking study examines how organizations are identifying, screening and managing those risks, drawing on responses from nearly 130 E&amp;C practitioners across more than 20 industries. The detailed findings focus on 83 organizations with existing TPRM programs and explore the practices, controls and technologies they use.</p>
<p>The study examines:</p>
<ul>
<li>Which E&amp;C risks organizations address through their TPRM programs and where emerging risks like AI, data privacy and cybersecurity remain less commonly covered.</li>
<li>Which types of third parties are screened, from service providers and suppliers to agents, distributors, M&amp;A targets and fourth parties.</li>
<li>How organizations use due diligence, third-party codes of conduct, contractual audit rights, training and ongoing monitoring to manage risk.</li>
</ul>

		</div>
	</div>
</div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper"><div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div></div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/rethink-benchmark-tprm/">Benchmarking Study: Third-Party Risk Management</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Benchmarking Study: Training &amp; Communications</title>
		<link>https://www.corporatecomplianceinsights.com/ethics-compliance-benchmark-training-communications/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 16:12:12 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Whitepapers]]></category>
		<category><![CDATA[Corporate Communication]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68167</guid>

					<description><![CDATA[<p>Rethink Compliance's recent ethics &#038; compliance benchmark study reveals how E&#038;C training and communications are handled inside corporations, looking at who gets training (and who doesn't), and how training and communications around ethics &#038; compliance have changed over time.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/ethics-compliance-benchmark-training-communications/">Benchmarking Study: Training &#038; Communications</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid vc_row-o-equal-height vc_row-flex"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-4 vc_custom_1659714795294 vc_col-has-fill"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper vc_box_shadow_3d  vc_box_border_grey"><img loading="lazy" decoding="async" width="791" height="1024" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-791x1024.jpg" class="vc_single_image-img attachment-large" alt="2025 Rethink Compliance Training and Communications-BenchmarkingSurvey _c" title="" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-791x1024.jpg 791w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-232x300.jpg 232w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-768x994.jpg 768w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-1187x1536.jpg 1187w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-750x971.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c-1140x1475.jpg 1140w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2025-Rethink-Compliance-Training-and-Communications-BenchmarkingSurvey-_c.jpg 1200w" sizes="(max-width: 791px) 100vw, 791px" /></div>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;">What is the state of ethics &amp; compliance training?</p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "5149c2e5-dea6-4143-bb9a-b044f32162db",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-1"><div class="jeg_wrapper wpb_wrapper"></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-7"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element no-bottom-margin" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 18px; color: #e77c30;">Benchmarking study</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans black; font-size: 50px; color: #133350; line-height: 1.2;">Training &amp; Communications Report</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 16px; color: #133350;">What&#8217;s in this report from Rethink Compliance:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>Rethink Compliance&#8217;s four compliance and ethics benchmarking study, developed by compliance practitioners with decades of experience, offers insights designed to help companies enhance their organization&#8217;s compliance training approach.</p>
<p>Some key findings of the survey of more than 200 practitioners:</p>
<ul>
<li>A majority of respondents (83%) say all employees received ethics &amp; compliance training during the survey period of 2025, roughly equivalent to what the survey found in 2021.</li>
<li>In just over one-third of organizations (34%), all employees received ethics &amp; compliance training that was specific to their risk profile.</li>
<li>Only 20% of respondents said their board directors receive no ethics &amp; compliance training, a decline from 35% in 2021.</li>
</ul>

		</div>
	</div>
</div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper"><div class="vc_empty_space"   style="height: 32px"><span class="vc_empty_space_inner"></span></div></div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/ethics-compliance-benchmark-training-communications/">Benchmarking Study: Training &#038; Communications</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Raising the Bar: A New Standard for Compliance Training</title>
		<link>https://www.corporatecomplianceinsights.com/raising-the-bar-new-standard-compliance-training/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 15:43:09 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Whitepapers]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68162</guid>

					<description><![CDATA[<p>To actually work, compliance training has to matter. It has to register with its audience, ideally in ways compliance teams can prove. This requires a different standard — for the training itself and for the vendors that produce it.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/raising-the-bar-new-standard-compliance-training/">Raising the Bar: A New Standard for Compliance Training</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="row vc_row wpb_row vc_row-fluid vc_row-o-equal-height vc_row-flex"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-4 vc_custom_1659714795294 vc_col-has-fill"><div class="jeg_wrapper wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_center wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper vc_box_shadow_3d  vc_box_border_grey"><img loading="lazy" decoding="async" width="791" height="1024" src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-791x1024.jpg" class="vc_single_image-img attachment-large" alt="2026 Rethink Compliance Training Whitepaper-c" title="" srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-791x1024.jpg 791w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-232x300.jpg 232w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-768x994.jpg 768w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-1187x1536.jpg 1187w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-750x971.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c-1140x1475.jpg 1140w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/2026-Rethink-Compliance-Training-Whitepaper-c.jpg 1200w" sizes="(max-width: 791px) 100vw, 791px" /></div>
		</figure>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;">Making your compliance training matter</p>
<p><script charset="utf-8" type="text/javascript" src="//js.hsforms.net/forms/embed/v2.js"></script><br />
<script>
  hbspt.forms.create({
    portalId: "20888593",
    formId: "f714026a-73c9-4219-87b9-97b7a7a8cf5b",
    region: "na1"
  });
</script></p>

		</div>
	</div>
</div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-1"><div class="jeg_wrapper wpb_wrapper"></div></div><div class="wpb_column jeg_column vc_column_container vc_col-sm-7"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element no-bottom-margin" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 18px; color: #e77c30;">Whitepaper</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans black; font-size: 50px; color: #133350; line-height: 1.2;">Raising the Bar: A New Standard for Compliance Training</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans semibold; font-size: 16px; color: #133350;">What’s in this whitepaper from Rethink Compliance:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="font-claude-message pr-4 md:pr-9 relative leading-&#091;1.65rem&#093; &#091;&amp;_pre&gt;div&#093;:bg-bg-300 &#091;&amp;_.ignore-pre-bg&gt;div&#093;:bg-transparent &#091;&amp;_pre&#093;:-mr-4 md:&#091;&amp;_pre&#093;:-mr-9">
<div class="grid-cols-1 grid gap-2.5 &#091;&amp;_&gt;_*&#093;:min-w-0">
<p><span lang="EN-US" xml:lang="EN-US" data-contrast="none">Most compliance training libraries look similar on a demo call. The differences show up later — when you&#8217;re three years into a training program and realize the content isn&#8217;t keeping pace, your client support has quietly eroded and the customization options you were promised never materialized.</span></p>
<p>Many providers can imitate the visible layer: a library with apparent depth, some modern-looking courses, broad claims about customization and global reach. Fewer can deliver what a serious program actually requires over time.</p>
<p>That’s because doing this well requires mastering a long list of separate, difficult domains like:</p>
<ul>
<li>Broad and current topic coverage</li>
<li>Strong instructional design</li>
<li>Compelling media</li>
<li>Meaningful customization options and supportive processes</li>
<li>Reliable technology</li>
<li>Analytics that turn completion data into program intelligence</li>
</ul>
<p>Get practical insight into what actually works: inside real programs, with real budgets, real competing priorities and real pressure to show results</p>
</div>
</div>

		</div>
	</div>
<div class="vc_empty_space"   style="height: 42px"><span class="vc_empty_space_inner"></span></div><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div><div class="vc_empty_space"   style="height: 42px"><span class="vc_empty_space_inner"></span></div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="font-family: work sans; font-size: 24px;"><b>About Rethink Compliance</b></p>
<p style="font-family: work sans; font-size: 14px;">At <a href="https://www.rethinkcomplianceco.com/"><strong>Rethink</strong></a>, we built our business around a different vision: that compliance leaders deserve a partner that can sustain a serious compliance training program, not just launch one.</p>

		</div>
	</div>
</div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper"></div></div></div></div><div class="row vc_row wpb_row vc_row-fluid"><div class="jeg-vc-wrapper"><div class="wpb_column jeg_column vc_column_container vc_col-sm-12"><div class="jeg_wrapper wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			
		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corporatecomplianceinsights.com/raising-the-bar-new-standard-compliance-training/">Raising the Bar: A New Standard for Compliance Training</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Pros Name Social Engineering as Top Human Risk</title>
		<link>https://www.corporatecomplianceinsights.com/news-roundup-september-4-2026/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 14:46:49 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Cyber Risk]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68150</guid>

					<description><![CDATA[<p>Plus: 20-point bump for AI in financial predictions; July sees ransomware peak</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-september-4-2026/">Cybersecurity Pros Name Social Engineering as Top Human Risk</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: </span></i><a href="mailto:editor@corporatecomplianceinsights.com"><b><i>editor@corporatecomplianceinsights.com</i></b></a><i><span style="font-weight: 400;">.</span></i></h6>
<h2><span style="font-weight: 400;">Social engineering tops more than 75% of security experts concerns</span></h2>
<p><span style="font-weight: 400;">Cyber crooks tricking employees into handing over access to company information is the top human risk for more than three-fourths of </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;"> personnel, a </span><a href="https://www.sans.org/mlp/ssa-security-awareness-report?utm_medium=Press_Release&amp;utm_source=PR_Web&amp;utm_content=SAR26&amp;utm_campaign=Paper_SecurityAwarenessReport_2026&amp;utm_rdetail=Global&amp;utm_goal=Leads&amp;utm_type=SSA" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by SANS Institute concluded. </span></p>
<p><span style="font-weight: 400;">The global survey of more than 1,700 cybersecurity practitioners found that 77% say social engineering is their organization’s top human </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;">, while phishing remained the primary attack method. But fake texts and voice scams are on the rise, the survey said.</span></p>
<p><span style="font-weight: 400;">AI has made it easier for hackers to research victims and launch social engineering attacks, the survey reported, and, reflecting this reality, </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> jumped from the fourth spot two years ago to second place this year in cybersecurity experts’ ranking of human risks. More than two in five (42%) respondents said AI was a top risk as they’re particularly concerned with organizations not having policies in place to govern AI and not knowing how employees are using unauthorized AI, a practice known as shadow AI.</span></p>
<p><span style="font-weight: 400;">With 39% of respondents naming incorrect handling of </span><a href="https://www.corporatecomplianceinsights.com/data-privacy-news/" target="_blank" rel="noopener"><b>sensitive data</b></a><span style="font-weight: 400;"> as a human risk, the issue ranked third, while password and authentication risk ranked fourth with 22% saying </span><a href="https://www.corporatecomplianceinsights.com/tag/cyber-risk/" target="_blank" rel="noopener"><b>cyber attackers</b></a><span style="font-weight: 400;"> getting ahold of these credentials is a major concern. Password and authentication risk have dropped two spots over the past two years in the rankings. </span></p>
<h2><span style="font-weight: 400;">More finance functions turning to AI</span></h2>
<p><span style="font-weight: 400;">Companies have increasingly turned to AI to make money predictions. with a nearly 20-percentage-point jump over the past year in leaders using the technology to forecast financials, according to a new </span><a href="https://www.protiviti.com/us-en/survey/global-finance-trends-survey?utm_source=ProPR&amp;utm_medium=Press_Release&amp;utm_campaign=2026_Finance_Trends" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by Protiviti. Over the past year, the percentage of leaders using AI for financial forecasts increased from 58% to 76%, the survey of 902 worldwide executives found.</span></p>
<p><span style="font-weight: 400;">Despite the rise in usage, how much cash AI brings in is still hard for companies to measure, Protiviti said. Only 35% of finance functions say they are highly or moderately effective at measuring AI return on investment. That may be due to a lack of an AI plan. Just 14% deploy AI with a defined strategy, the survey found.</span></p>
<p><span style="font-weight: 400;">Finance leaders are also concerned about security as AI adoption increases and the technology&#8217;s </span><a href="https://www.corporatecomplianceinsights.com/tag/data-breach/" target="_blank" rel="noopener"><b>access to data</b></a><span style="font-weight: 400;"> ramps up, according to the survey. Data privacy and security ranked as the top finance priority for a third year in a row.</span></p>
<p><span style="font-weight: 400;">&#8220;Finance leaders have moved beyond asking whether to adopt AI. Today&#8217;s challenge is to use AI to make more informed business decisions and prove that it is delivering measurable value,&#8221; Christopher Wright, global leader of Protiviti&#8217;s CFO solutions and business performance improvement practice, said in a statement. &#8220;Organizations that pair strong </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data governance</b></a><span style="font-weight: 400;"> with clear business objectives are better positioned to navigate economic uncertainty, shifting market conditions and rising expectations for finance transformation.&#8221;</span></p>
<p><span style="font-weight: 400;">Other key findings include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">77% of finance organizations now use AI.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">67% use AI for risk assessment and management.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">56% use the technology for process automation.</span></li>
</ul>
<h2><span style="font-weight: 400;">Ransomware attacks reached year high in July</span></h2>
<p><span style="font-weight: 400;">Hackers had a prolific summer as ransomware activity spiked in July to its highest point since February 2025, according to a </span><a href="https://www.nccgroup.com/resource-hub/cyber-threat-intelligence-reports/" target="_blank" rel="noopener"><b>report</b></a><span style="font-weight: 400;"> by NCC Group, representing a 22% increase from June. </span></p>
<p><span style="font-weight: 400;">The ransomware activity remains concentrated in North America, where 41% of </span><a href="https://www.corporatecomplianceinsights.com/tag/cyber-crime/" target="_blank" rel="noopener"><b>cyber attacks</b></a><span style="font-weight: 400;"> occurred, and Europe, which accounted for 29%. Industrials were the most targeted sector, with 250 attacks (28%), followed by consumer discretionary with 165 (18%) and information technology with 103 (12%) attacks. </span></p>
<p><span style="font-weight: 400;">The report also highlighted what cybersecurity group Sysdig in early July </span><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank" rel="noopener"><b>called</b></a><span style="font-weight: 400;"> the first documented case of agentic ransomware, giving the AI agent the name JADEPUFFER and describing the attack as “a complete extortion operation driven end-to-end by a large language model.” </span></p>
<p><span style="font-weight: 400;">“AI is changing the speed and scale of cyber attacks,” Matt Hull, </span><span style="font-weight: 400;">NCC Group </span><span style="font-weight: 400;">vice president of cyber intelligence and response, said in a statement. “It’s allowing attackers to automate more of what they do, operate at greater scale and create increasingly convincing phishing, social engineering and other malicious content. That can make threats harder for both organizations and individuals to identify.”</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-september-4-2026/">Cybersecurity Pros Name Social Engineering as Top Human Risk</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>