<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>Corporate Compliance Insights</title>
	<atom:link href="https://www.corporatecomplianceinsights.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<description>The Web's Premier News Source for Compliance, Ethics &amp; Risk</description>
	<lastBuildDate>Thu, 01 Oct 2026 15:56:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/11/cropped-Favicon-32x32.png</url>
	<title>Corporate Compliance Insights</title>
	<link>https://www.corporatecomplianceinsights.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>Company Leaders Wary Over AI-Related Labor Issues</title>
		<link>https://www.corporatecomplianceinsights.com/news-roundup-october-1-2026/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Thu, 01 Oct 2026 15:09:13 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Business Continuity Planning]]></category>
		<category><![CDATA[Cyber Risk]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68497</guid>

					<description><![CDATA[<p>Plus: Most companies experienced a cyberattack recently; C-suite rift revealed on business disruption</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-october-1-2026/">Company Leaders Wary Over AI-Related Labor Issues</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: </span></i><a href="mailto:editor@corporatecomplianceinsights.com"><b><i>editor@corporatecomplianceinsights.com</i></b></a><i><span style="font-weight: 400;">.</span></i></h6>
<h2><span style="font-weight: 400;">Less than 10% of company leaders confident in managing labor relations and AI</span></h2>
<p><span style="font-weight: 400;">Only 9% of top company officials believe their organizations are very prepared to handle labor relations issues brought up by the adoption of </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;">, a </span><a href="https://www.littler.com/news-analysis/littler-report/littler-labor-survey-report-2026" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by Littler found.</span></p>
<p><span style="font-weight: 400;">The survey of 665 in-house lawyers, </span><a href="https://www.corporatecomplianceinsights.com/hr-compliance-news/" target="_blank" rel="noopener"><b>HR professionals</b></a><span style="font-weight: 400;"> and business executives also found that about 70% reported being moderately to somewhat prepared and 20% reported not being prepared at all.</span></p>
<p><span style="font-weight: 400;">That lack of confidence comes as leaders recognize significant changes AI can make in their workforce. The survey found that 87% of respondents expect unions to use employee fears about AI displacing or changing jobs to fuel organizing interest in the next year. A notable portion also believes that increased AI use will reshape job responsibilities (67%), redistribute work across teams (42%) and reduce entry-level roles (30%).</span></p>
<p><span style="font-weight: 400;">More than half (58%) of unionized organizations have already heard concerns about job displacement and workforce reduction in union discussions, and 56% said concerns from workers about AI-related shifts in job responsibilities or productivity expectations have emerged.</span></p>
<h2><span style="font-weight: 400;">Almost 90% of companies experienced a cyberattack this year</span></h2>
<p><span style="font-weight: 400;">Nearly nine out of 10 multi-location companies were victims of </span><a href="https://www.corporatecomplianceinsights.com/tag/cyber-risk/" target="_blank" rel="noopener"><b>cyberattacks</b></a><span style="font-weight: 400;"> in the past 12 months, according to a </span><a href="https://go.vikingcloud.com/l/1000211/2026-09-09/52hrf/1000211/1788981236zCHvEQ7y/_Report__2026_Cyber_Threat_Landscape_Report_Sept26.pdf" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by VikingCloud.</span></p>
<p><span style="font-weight: 400;">The survey of 200 security and IT decision-makers at US and European companies with locations across the globe found that 86% reported having a cyberattack recently. More than three-quarters (77%) said the attack spread beyond where it started to other brand locations, corporate systems or shared vendor relationships.</span></p>
<p><span style="font-weight: 400;">More than half of respondents (51%) mandated a </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;"> policy across all locations, but 33% of companies allowed for discretion in implementing corporate guidelines while 15% left cybersecurity policy to the individual locations. </span></p>
<p><span style="font-weight: 400;">Almost nine out of 10 (88%) reported that ransomware attacks originating at individual locations or spread out from them have more frequent, more severe or both, and nearly an identical percent (87%) said that AI-generated phishing and deepfakes targeting location managers and frontline staff have gotten worse.</span></p>
<h2><span style="font-weight: 400;">C-suite diverge in disruption-readiness assessments</span></h2>
<p><span style="font-weight: 400;">Divides are brewing in the C-suite over companies’ disruption readiness. </span></p>
<p><span style="font-weight: 400;">More than half of CEOs are confident their firms could handle a major disruption compared to less than a third of CIOs, according to a </span><a href="https://learn.highspring.com/unexpected/" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by Highspring of 1,137 c-suite executives and VPs of US and Canadian companies that asked the officials about their ability to overcome disruption of 10 core business functions, such as supply chain, cybersecurity, </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> or workforce disruptions.</span></p>
<p><span style="font-weight: 400;">Of the CEOs surveyed, 52% said they were very confident that their companies could handle a major disruption in the functions. Among CIOs, only 30% reported high levels of confidence in being able to tackle a major disruption.</span></p>
<p><span style="font-weight: 400;">The survey also found that CFOs were twice as likely to consider their companies’ core business functions to be exposed than CEOs with about 8% of CFOs calling core functions exposed vs. about 4% of CEOs on average across the 10 functions.</span></p>
<p><span style="font-weight: 400;">CEOs and CFOs also disagreed about how well their companies stay aligned during uncertain conditions with 8% of CEOs saying leadership doesn’t stay aligned and 15% of CFOs reporting non-alignment when conditions become uncertain.</span></p>
<p><span style="font-weight: 400;">The survey also found that a vast majority of leaders (95%) reported that business was disrupted by something outside company control in the last year and 67% felt such disruptions twice or more.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-october-1-2026/">Company Leaders Wary Over AI-Related Labor Issues</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>‘There’s No Ethical Work Without Discomfort’</title>
		<link>https://www.corporatecomplianceinsights.com/theres-no-ethical-work-without-discomfort-scce-2026/</link>
		
		<dc:creator><![CDATA[Jennifer L. Gaskin]]></dc:creator>
		<pubDate>Wed, 30 Sep 2026 16:00:16 +0000</pubDate>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Culture of Ethics]]></category>
		<category><![CDATA[Whistleblowing]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68489</guid>

					<description><![CDATA[<p>Ethics, values &#038; speak-up culture take center stage at SCCE</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/theres-no-ethical-work-without-discomfort-scce-2026/">‘There’s No Ethical Work Without Discomfort’</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">At this week’s SCCE Compliance &amp; Ethics Institute, WorldCom whistleblower Cynthia Cooper told attendees her hands shook as she pursued the audit questions that would help bring down the company. CCI’s Jennifer L. Gaskin reports on the courage it takes to speak up and the values that hold when profit pulls the other way.</span></i></p>
</div>
<p><span style="font-weight: 400;">Cynthia Cooper didn’t set out to implode one of the world’s largest telecom companies, Wall Street and business media darling WorldCom. But as she made her way from office to office in the summer of 2002 seeking answers about what “prepaid capacity” meant in the company’s balance sheet, WorldCom’s vice president of </span><a href="https://www.corporatecomplianceinsights.com/internal-audit-news/" target="_blank" rel="noopener"><b>internal audit</b></a><span style="font-weight: 400;"> was helping set in motion a chain of events that would send the company into bankruptcy and its CEO to prison.</span></p>
<p><span style="font-weight: 400;">This year marked 25 years since the collapse of Enron (followed the next year by WorldCom) and, coincidentally, featured the 25th annual Compliance &amp; Ethics Institute hosted by SCCE, where Cooper detailed a </span><a href="https://www.corporatecomplianceinsights.com/tag/whistleblowing/" target="_blank" rel="noopener"><b>whistleblowing</b></a><span style="font-weight: 400;"> journey that would pit her against WorldCom’s CFO and the chair of its audit committee.</span></p>
<p><a href="https://www.cappscenter.ucsb.edu/news/extraordinary-circumstances-journey-corporate-whistleblower-cynthia-cooper" target="_blank" rel="noopener"><b>Cooper</b></a><span style="font-weight: 400;"> didn’t describe herself as fearless; in fact, quite the opposite. </span></p>
<p><span style="font-weight: 400;">&#8220;I can&#8217;t tell you I was this pillar of strength through this entire process. I wasn&#8217;t,&#8221; she told a session of conference attendees. In fact, at times, she says, her hands shook and her heart pounded. But she knew she had to find a way to push through.</span></p>
<p><span style="font-weight: 400;">The fear of speaking truth to power is one compliance professionals know, too, Cooper said, recalling advising a young compliance professional who reported being intimidated by executives with assertive and aggressive personalities: “You walk through that fear. You just do it anyway. And you ask the questions even if your voice is shaking.”</span></p>
<p><span style="font-weight: 400;">What carried Cooper through, she said, were her personal values, including her mother’s admonition to never feel intimidated. </span></p>
<p><span style="font-weight: 400;">Values were a theme in a general session earlier in the day, when Piergiorgio Pepe, former </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> and </span><a href="https://www.corporatecomplianceinsights.com/ethics-news/" target="_blank" rel="noopener"><b>ethics</b></a><span style="font-weight: 400;"> director at AbbVie in Paris, argued that </span><a href="https://www.corporatecomplianceinsights.com/why-ethics-matter-a-business-without-values-is-a-business-at-risk/" target="_blank" rel="noopener"><b>values matter in all types of corporate situations</b></a><span style="font-weight: 400;"> but often are obfuscated or (as in the example of WorldCom) totally ignored in the pursuit of profit.</span></p>
<p><span style="font-weight: 400;">He pointed to the rapidly evolving, or de-volving as the case may be, state of corporate DEI, which is quickly falling out of favor. What other conclusions should employees draw, given that just a few years ago, leadership was crowing about inclusion being a corporate value, he asked?</span></p>
<p><span style="font-weight: 400;">“You cannot tell me that this was a fundamental value and all of a sudden it&#8217;s disappeared from the code of conduct. How trustworthy are you as a leader?”</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68489_0_6abe8700de611   " data-unique="jnews_module_68489_0_6abe8700de611">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/business-ethics-is-discipline-not-disposition/" aria-label="Read article: Business Ethics Is a Discipline, Not a Disposition"><div class="thumbnail-container animate-lazy  size-500 "><img fetchpriority="high" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="business figure choosing personality face mask" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/business-figure-choosing-personality-face-mask-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/business-figure-choosing-personality-face-mask-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/business-figure-choosing-personality-face-mask-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/09/business-figure-choosing-personality-face-mask-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/ethics/">Ethics</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/business-ethics-is-discipline-not-disposition/">Business Ethics Is a Discipline, Not a Disposition</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/vera-cherepanova/">Vera Cherepanova</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/business-ethics-is-discipline-not-disposition/"><i class="fa fa-clock-o"></i> September 23, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>What does a board director need beyond a moral character? Plenty, writes Ask an Ethicist columnist Vera Cherepanova, who says we should start with understanding the roles business leaders play in society.</p>
                                    <a href="https://www.corporatecomplianceinsights.com/business-ethics-is-discipline-not-disposition/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68489_0_6abe8700de611 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"68413","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Durable values in a negotiable world</span></h2>
<p><span style="font-weight: 400;">The retreat from DEI is part of a broader shift in the business world from one that centers a variety of stakeholders to one in which “rules are flexible if inconvenient,” Pepe said, and where the short term is more important than the long term.</span></p>
<p><span style="font-weight: 400;">Compliance has sometimes played into the problem, Pepe argued, by focusing too much on making the case that compliance is a business advantage. True, he said, but only useful insofar as it helps open doors to more substantive conversations. It can’t be the final message, Pepe said.</span></p>
<p><span style="font-weight: 400;">The final message, he said, must be: “Doing the right thing is the right thing to do regardless of whether it makes money or not.”</span></p>
<p><span style="font-weight: 400;">For compliance and ethics practitioners, that means not simply </span><a href="https://www.corporatecomplianceinsights.com/why-are-your-policies-yelling-at-me/" target="_blank" rel="noopener"><b>explaining what the rules are but why they exist</b></a><span style="font-weight: 400;">, Pepe said. People who understand the underlying reasoning, linked to the company’s values, will begin to operate as if the reasoning is their own.</span></p>
<p><span style="font-weight: 400;">It also means elevating values to the same level as other mission-critical terms like financial targets — not relegating them to the bottom of the slide deck — and making sure leaders’ actions match their messaging. A year-end note about integrity rings hollow if two weeks later, a manager known for mistreating subordinates gets a shiny new promotion.</span></p>
<p><span style="font-weight: 400;">Mostly, though, making sure companies actually live up to their values is uncomfortable work, so E&amp;C professionals need to be OK with that, Pepe said.</span></p>
<p><span style="font-weight: 400;">&#8220;There&#8217;s no </span><a href="https://www.corporatecomplianceinsights.com/all-small-things-how-seemingly-minor-ethical-lapses-take-their-toll/" target="_blank" rel="noopener"><b>ethical work</b></a><span style="font-weight: 400;"> without discomfort, my friends,&#8221; he said.</span></p>
<h2><span style="font-weight: 400;">What whistleblowers need</span></h2>
<p><span style="font-weight: 400;">Cooper shared the stage with Jane Norberg, a former chief of the SEC’s whistleblower office, and Carrie Penman, now an executive at software company NAVEX, who was the first ethics officer at Westinghouse. Penman recalled answering the company’s hotline calls herself early in her career and hearing the fear in reporters’ voices.</span></p>
<p><span style="font-weight: 400;">“It is a very, very difficult decision for somebody to come forward and raise an issue,” Penman noted, urging session attendees to remember that when they engage with possible whistleblowers.</span></p>
<p><span style="font-weight: 400;">One of the biggest reasons employees don’t come forward, </span><a href="https://www.navex.com/en-us/blog/article/building-a-speak-up-culture-employees-trust/" target="_blank" rel="noopener"><b>research has shown</b></a><span style="font-weight: 400;">, is the fear of retaliation, but what companies do in the earliest moments can be everything. The first touchpoint with a reporter can “make or break the entire rest of the relationship,” Norberg said. She recommended acknowledging reports within 24 to 48 hours, thanking the reporter and, in cases where their identity is known, interviewing them before anybody else.</span></p>
<p><span style="font-weight: 400;">She also warned against a common corporate reflex: immediately sending the complaint to the person the complaint is about. Once the accused knows about the report, later actions regarding the reporting party can appear retaliatory, even if they’re not, Norberg said.</span></p>
<p><span style="font-weight: 400;">Still, Cooper said the negative consequences for whistleblowers are nearly universal in her experience, and she urged E&amp;C teams to keep in close contact with people who come forward.</span></p>
<p><span style="font-weight: 400;">“Empathize with the person. Independence or confidentiality doesn&#8217;t mean that there should be no communication with the whistleblower,” she said. “So don&#8217;t isolate them.”</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/theres-no-ethical-work-without-discomfort-scce-2026/">‘There’s No Ethical Work Without Discomfort’</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>That AI-Drafted Termination Memo Could Become Evidence</title>
		<link>https://www.corporatecomplianceinsights.com/that-ai-drafted-termination-memo-could-become-evidence/</link>
		
		<dc:creator><![CDATA[Hekim Colpan and Phillip Wikes]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 14:01:17 +0000</pubDate>
				<category><![CDATA[HR Compliance]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Wage Compliance]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68474</guid>

					<description><![CDATA[<p>AI reproduces subjective phrasing across files, so language that looks neutral in one record can reveal a pattern across a whole workforce</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/that-ai-drafted-termination-memo-could-become-evidence/">That AI-Drafted Termination Memo Could Become Evidence</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">A performance review, warning or promotion decision can later become evidence in a discrimination dispute — and AI compliance analysts Hekim Colpan and Phillip Wikes warn that AI-assisted drafting can leave a record looking more polished than the evidence behind it.</span></i></p>
</div>
<p><span style="font-weight: 400;">The story of an employment decision does not end when a manager makes the call. A performance evaluation, warning, promotion decision or termination memorandum may later become evidence through which someone asks whether the stated reason was legitimate, consistently applied and supported by what was known at the time.</span></p>
<p><span style="font-weight: 400;">When </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> helps draft that evaluation, warning or memo, the </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;"> is not simply that the prose contains an error but that the record looks more polished than the evidence supporting it.</span></p>
<p><span style="font-weight: 400;">We call that gap “decision reconstruction risk”: a condition in which a consequential record can no longer show, on its own, why a decision was made. In employment matters, this is consequential because discrimination disputes can turn on the reasons an employer gives and the evidence surrounding them.</span></p>
<p><a href="https://www.law.cornell.edu/supremecourt/text/411/792" target="_blank" rel="noopener"><b><i>McDonnell Douglas Corp. v. Green</i></b></a><span style="font-weight: 400;"> established a burden-shifting framework. Where it applies, an employer may articulate a legitimate, nondiscriminatory reason for an employment action and the plaintiff may seek to show that reason is pretextual.</span></p>
<p><span style="font-weight: 400;">The US Supreme Court in that case did not hold that documentation quality determines whether discrimination occurred. Documentation can matter when the stated reason is tested against contemporaneous evidence, prior records and the consistency of the employer&#8217;s explanation.</span></p>
<p><span style="font-weight: 400;">Consider a </span><a href="https://www.corporatecomplianceinsights.com/what-workday-case-reveals-about-ai-hiring-records/" target="_blank" rel="noopener"><b>file where the underlying history</b></a><span style="font-weight: 400;"> includes emails, attendance records, completed work and prior feedback, while the final document contains a polished narrative that does not clearly connect its conclusions to those materials. </span></p>
<p><span style="font-weight: 400;">An employer in that position can articulate its reason, but what it may not be able to do is show the reason was the one it actually applied.</span></p>
<h2><span style="font-weight: 400;">The pattern may appear only across employees</span></h2>
<p><span style="font-weight: 400;">A single record is reviewed on its own terms. A workforce of records is reviewed together. That is where </span><a href="https://www.corporatecomplianceinsights.com/meet-your-new-colleague-already-making-decisions/" target="_blank" rel="noopener"><b>AI-assisted drafting introduces a risk</b></a><span style="font-weight: 400;"> most organizations do not currently measure.</span></p>
<p><span style="font-weight: 400;">AI-assisted drafting often reproduces language across performance reviews, disciplinary records and promotion decisions. A phrase that appears neutral in one file may take on a different significance when it recurs across a group. The reason this happens is straightforward: A drafting tool may reproduce phrasing when prompted with prior records, while a reviewer approving one record at a time may have no vantage point from which to notice the pattern.</span></p>
<p><span style="font-weight: 400;">Examples include &#8220;cultural fit,&#8221; &#8220;executive presence,&#8221; &#8220;not adaptable,&#8221; &#8220;communication style&#8221; and &#8220;struggles with change.&#8221; The issue is what happens when subjective language is repeatedly used to describe employees who share a protected characteristic and the organization cannot identify the evidence behind those descriptions.</span></p>
<p><span style="font-weight: 400;">Side-by-side review asks two questions: whether the same subjective standards are being applied across employees and whether the organization can identify the evidence supporting them. Disparate treatment and disparate impact remain distinct theories with different elements and proof structures. Recurring language can become relevant evidence when combined with surrounding facts, employment outcomes and decision history.</span></p>
<p><span style="font-weight: 400;">And banning particular phrases achieves little. What helps is requiring subjective conclusions to be connected to identifiable evidence before the record becomes final and reading across records rather than only at each one.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68474_1_6abe8700e5323   " data-unique="jnews_module_68474_1_6abe8700e5323">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/your-compliance-dashboard-tell-you-everything/" aria-label="Read article: Your Compliance Dashboard Can’t Tell You Everything About Employee Relations"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="dashboard 3d concept" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/05/dashboard-3d-concept-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/05/dashboard-3d-concept-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/05/dashboard-3d-concept-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/05/dashboard-3d-concept-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/hr-compliance/">HR Compliance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/your-compliance-dashboard-tell-you-everything/">Your Compliance Dashboard Can’t Tell You Everything About Employee Relations</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/deb-muller/">Deb Muller</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/your-compliance-dashboard-tell-you-everything/"><i class="fa fa-clock-o"></i> May 28, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>The first signal that you have a compliance problem is retaliation allegation rates</p>
                                    <a href="https://www.corporatecomplianceinsights.com/your-compliance-dashboard-tell-you-everything/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68474_1_6abe8700e5323 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"66897","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">What a defensible employment record should show</span></h2>
<p><span style="font-weight: 400;">A consequential employment record should allow an independent reviewer to answer four questions:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">What happened?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">What evidence supports the characterization?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Why did those facts matter?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Was the same reasoning applied consistently?</span></li>
</ul>
<p><span style="font-weight: 400;">&#8220;Not a strong cultural fit&#8221; is a conclusion. A record identifying specific conduct, dates, expectations and prior feedback gives a reviewer something that can be examined.</span></p>
<p><b>Before:</b><span style="font-weight: 400;"> &#8220;Attendance issues affecting the team.&#8221;</span></p>
<p><b>After:</b><span style="font-weight: 400;"> &#8220;Missed nine scheduled shifts between January and March. Attendance expectations were discussed in documented feedback on two occasions.&#8221;</span></p>
<p><b>Before:</b><span style="font-weight: 400;"> &#8220;Lacks professionalism.&#8221;</span></p>
<p><b>After:</b><span style="font-weight: 400;"> &#8220;Missed client deliverable deadlines on March 3, March 10 and March 17. Feedback was provided after each occurrence.&#8221;</span></p>
<p><span style="font-weight: 400;">The second versions make the basis of the judgment visible and give a later reviewer evidence against which the stated reason can be tested.</span></p>
<h2><span style="font-weight: 400;">A pre-finalization control can close the gap</span></h2>
<p><span style="font-weight: 400;">The control does not require a new platform or a wholesale redesign. It can be a structured review before a consequential employment record becomes final.</span></p>
<p><span style="font-weight: 400;">At minimum, the review should require the organization to:</span></p>
<ol>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify the human author and any AI tools used in drafting.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Preserve source evidence supporting material conclusions.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Link conclusions to verifiable source evidence rather than AI-generated assertions alone.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Document who reviewed the record, when and what substantive changes were made.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Define what drafting-layer material is preserved for consequential records and under which legal-hold triggers.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Review records across employees for recurring subjective language or inconsistent standards.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Confirm that the final explanation is consistent with documented history that existed before the decision.</span></li>
</ol>
<p><span style="font-weight: 400;">The organizing principle is preservation rather than retention — enough evidence to reconstruct and defend the record when its author is no longer available to explain it.</span></p>
<h2><span style="font-weight: 400;">A note for organizations operating in Europe</span></h2>
<p><span style="font-weight: 400;">In Europe, the same employment-record problem sits at the intersection of </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data protection</b></a><span style="font-weight: 400;"> and AI </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;">. </span><a href="https://gdpr-info.eu/art-5-gdpr/" target="_blank" rel="noopener"><b>GDPR&#8217;s accountability principle</b></a><span style="font-weight: 400;"> requires controllers to comply with the data-protection principles and to be able to demonstrate that </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;">. It does not require every prompt or draft to be retained. But where personal data support an AI-assisted evaluation, warning, promotion or termination record, gaps in provenance, factual verification or human review can undermine the organization&#8217;s ability to demonstrate compliance with the applicable data-protection principles.</span></p>
<p><a href="https://gdpr-info.eu/art-22-gdpr/" target="_blank" rel="noopener"><b>Article 22 adds a distinct safeguard</b></a><span style="font-weight: 400;"> where a decision is based solely on automated processing and produces legal or similarly significant effects. An employment record does not become an Article 22 case merely because AI helped draft it. That distinction makes meaningful human review more important; formal approval is weak evidence of human judgment if the reviewer cannot identify the underlying facts, verify material conclusions or explain why the AI-assisted characterization was accepted.</span></p>
<p><span style="font-weight: 400;">Employment is also an area the </span><a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj" target="_blank" rel="noopener"><b>EU AI Act</b></a><span style="font-weight: 400;"> treats expressly as sensitive. Annex III covers certain AI systems intended for recruitment and selection, decisions affecting promotion or termination, task allocation based on individual behavior or personal characteristics and worker monitoring or evaluation. </span></p>
<p><span style="font-weight: 400;">Whether a system falls within the </span><a href="https://www.corporatecomplianceinsights.com/eu-ai-act-wait-see-window-closing/" target="_blank" rel="noopener"><b>high-risk regime</b></a><span style="font-weight: 400;"> depends on its intended purpose, not simply on AI appearing in the drafting process. Under </span><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj" target="_blank" rel="noopener"><b>Regulation (EU) 2026/1744</b></a><span style="font-weight: 400;">, the relevant </span><a href="https://www.corporatecomplianceinsights.com/most-overlooked-risk-eu-ai-act/" target="_blank" rel="noopener"><b>high-risk requirements</b></a><span style="font-weight: 400;"> for Annex III systems are deferred until December 2027. Many employment-drafting workflows may therefore fall outside that regime. </span></p>
<p><span style="font-weight: 400;">But the governance question remains: when AI-assisted language becomes part of a permanent employment record, can the organization still show what evidence supported the characterization, what AI contributed, what a human verified and whether the same standard was applied consistently across employees?</span></p>
<h2><span style="font-weight: 400;">The employment record is part of the decision</span></h2>
<p><span style="font-weight: 400;">For compliance and HR leaders, the practical question is not whether AI should write employment records but whether the organization has any controls at the point where AI-assisted language becomes part of the permanent record.</span></p>
<p><span style="font-weight: 400;">A defensible record lets someone who was not present reconstruct the reasoning and test whether the stated explanation matches the documented history.</span></p>
<p><span style="font-weight: 400;">When employment records are reviewed side by side, the question may shift from an individual employee&#8217;s wording to whether the organization&#8217;s records reveal standards that were subjective, inconsistently applied or difficult to defend.</span></p>
<p><span style="font-weight: 400;">We use the shorthand &#8220;right to know why&#8221; for that governance principle. It is not a legal doctrine and not a claim of any new entitlement. How the drafting happens has changed, but the standard the record has to meet has not.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/that-ai-drafted-termination-memo-could-become-evidence/">That AI-Drafted Termination Memo Could Become Evidence</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might</title>
		<link>https://www.corporatecomplianceinsights.com/ai-governance-frameworks-wont-save-you-ethically-engaged-workforce-might/</link>
		
		<dc:creator><![CDATA[Caterina Bulgarella]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 11:02:16 +0000</pubDate>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Corporate Culture]]></category>
		<category><![CDATA[Culture of Ethics]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68476</guid>

					<description><![CDATA[<p>The frameworks and safeguards that make boards feel AI risk is handled usually leave out the one defense that actually holds the line: employees. Social scientist Caterina Bulgarella explains why the uncertainty and job insecurity AI provokes erode the very resources that keep people vigilant and honest, making an ethically engaged workforce a strategic priority.</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/ai-governance-frameworks-wont-save-you-ethically-engaged-workforce-might/">AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">The frameworks and safeguards that make boards feel AI risk is handled usually leave out the one defense that actually holds the line: employees. Social scientist Caterina Bulgarella explains why the uncertainty and job insecurity AI provokes erode the very resources that keep people vigilant and honest, making an ethically engaged workforce a strategic priority.</span></i></p>
</div>
<p><span style="font-weight: 400;">The job apocalypse many predicted may be </span><a href="https://www.economist.com/finance-and-economics/2026/09/04/the-jobs-apocalypse-is-postponed-an-ai-jobs-boom-is-here" target="_blank" rel="noopener"><b>postponed</b></a><span style="font-weight: 400;">, but </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;"> is on pace to reshape both work and the workplace. Call it co-intelligence, hybrid execution, integration or </span><a href="https://www.corporatecomplianceinsights.com/where-in-loop-testing-ai-across-compliance-tasks/" target="_blank" rel="noopener"><b>human-in-the-loop</b></a><span style="font-weight: 400;">, the use of machines to replace, complement or, at best, supplement human performance is a vision that merely lacks scale. The only fuzzy point? Employees’ role in it. </span></p>
<p><span style="font-weight: 400;">Amid shiny promises and </span><a href="https://www.nytimes.com/2026/09/18/us/politics/trump-ai-safety-anthropic-openai-china.html?searchResultPosition=7" target="_blank" rel="noopener"><b>alarmed safety calls</b></a><span style="font-weight: 400;">, AI is already bringing change, not only to how people work but also to the values they share — each new prompt a rewrite of the human code we used to hold. The urgency of disruptive technology may shape the business agenda, but it doesn’t erase the need for alignment, not only between AI and what defines humanity but between humans and their moral compass. Even if senior leaders defer the question of </span><a href="https://www.corporatecomplianceinsights.com/how-you-handle-ai-agents-company-values/" target="_blank" rel="noopener"><b>what principles their business stands for</b></a><span style="font-weight: 400;">, a business without an ethical core is only as capable as an algorithm generating output it cannot understand. </span></p>
<p><span style="font-weight: 400;">Philosophy aside, it’s AI’s behavior that demands a full-court risk-and-ethics posture. In equal parts dangerously wondrous and disruptive, “artificial” intelligence </span><a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC11681264/" target="_blank" rel="noopener"><b>hallucinates</b></a><span style="font-weight: 400;">, </span><a href="https://www.technologyreview.com/2026/08/03/1141009/heres-why-ai-agents-lie-and-cheat-to-reach-their-goals/" target="_blank" rel="noopener"><b>fabricates</b><span style="font-weight: 400;">,</span><b> cheats</b></a><span style="font-weight: 400;">, </span><a href="https://spectrum.ieee.org/ai-agents-safety" target="_blank" rel="noopener"><b>breaks rules</b></a><span style="font-weight: 400;"> and </span><a href="https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-highlights?amp=&amp;amp=&amp;amp=&amp;stream=top" target="_blank" rel="noopener"><b>gets out of control</b></a><span style="font-weight: 400;">. Putting in place governance frameworks, implementing technological safeguards, even waiting for machines to control machines may give boards and organizations the impression that risk is under control. But without employees acting as the first line of defense, businesses’ exposure remains too high.  </span></p>
<p><span style="font-weight: 400;">If anything, in the AI era, creating an ethically engaged workforce is not only desirable but a top strategic priority. For without people discerning and anticipating the ripple effects of today’s change, no business moat can fill the gap of what we don’t yet know. </span></p>
<p><span style="font-weight: 400;">So, what does it take to build ethical engagement?  </span></p>
<p><span style="font-weight: 400;">At a time of weak shared values, eroding trust, dwindling attention and scarce empathy, organizations must start by managing the emotional blind spots, cognitive risks and cultural gaps weighing on employees.  </span></p>
<h2><span style="font-weight: 400;">Mitigating the emotional toll of change</span></h2>
<p><span style="font-weight: 400;">Three factors keep depleting people’s emotional resources: </span><a href="https://www.corporatecomplianceinsights.com/layoff-two-step-underscores-ai-limitations/" target="_blank" rel="noopener"><b>uncertainty, job insecurity and fear of irrelevancy</b></a><span style="font-weight: 400;">. Technological change is unfolding against the backdrop of broader geopolitical, economic and societal shifts. This means that, while AI is forcing people to constantly second-guess changes to their jobs and work environment, macro uncertainty is fueling a state of generalized anxiety. Among Gen Z, the newest entrants to the workforce, the toll couldn’t be higher — </span><a href="https://link.springer.com/article/10.1186/s12889-025-22124-5" target="_blank" rel="noopener"><b>low well-being</b></a><span style="font-weight: 400;"> combined with increasingly </span><a href="https://www.nytimes.com/2026/07/23/opinion/gen-z-ambition-millennials-career.html" target="_blank" rel="noopener"><b>pessimistic career expectations</b></a><span style="font-weight: 400;">.  </span></p>
<p><span style="font-weight: 400;">Uncertainty doesn’t simply consume employees’ emotional resources; it also reduces their ability to remain vigilant, discerning and willing to do the right thing. </span><a href="https://discovery.researcher.life/article/unethical-conduct-under-uncertainty-a-fear-based-perspective/e171e0ff0bc03a829ab50026dad8f86e" target="_blank" rel="noopener"><b>Studies</b></a><span style="font-weight: 400;"> show that uncertainty shifts attention to the short-term and heightens self-concern, two crippling conditions that increase the risk of unethical behavior.  </span></p>
<p><span style="font-weight: 400;">Even more dangerously, job insecurity creates </span><a href="https://www.cambridge.org/core/journals/business-ethics-quarterly/article/abs/exploring-the-impact-of-job-insecurity-on-employees-unethical-behavior/D7C2CD0A7F2074F5F90B9777B6D0E3F6" target="_blank" rel="noopener"><b>emotional exhaustion</b></a><span style="font-weight: 400;">, a form of depletion that, both directly and indirectly, boosts the risk of misconduct. On a different level, fear of becoming unemployed and/or potentially unemployable triggers not only shame but a genuine sense of </span><a href="https://pubmed.ncbi.nlm.nih.gov/33453740/" target="_blank" rel="noopener"><b>unfairness</b></a><span style="font-weight: 400;">, making it easier for employees to rationalize unethical conduct.  </span></p>
<p><span style="font-weight: 400;">When job insecurity is fueled by fear of irrelevancy — such as the loss of career prospects or the need for a career change — the perception of unfairness grows even deeper. Take, for example, reports that Gen Z employees have started </span><a href="https://fortune.com/2026/04/08/gen-z-workers-sabotage-ai-rollout-backlash/" target="_blank" rel="noopener"><b>sabotaging</b></a><span style="font-weight: 400;"> AI in the workplace. These statistics are not only a mirror of the negative emotions spreading across the workforce; they also document a willingness to break rules and norms at odds with organizations’ need for ethical engagement. </span></p>
<p><span style="font-weight: 400;">Though companies cannot control external sources of uncertainty, they have a plethora of tools to manage the emotional toll of change. They can use dialogue to build a climate of transparency and honesty. They can choose to stay away from promises they are unable to deliver. They can invest in behavioral integrity — showcasing how they walk the walk. They can structure the employee experience to help people navigate and manage change, from regular check-ins to effective feedback channels and design initiatives. Finally, they can help employees </span><a href="https://www.corporatecomplianceinsights.com/first-rung-matters-more-than-ladder/" target="_blank" rel="noopener"><b>develop and practice new skills</b></a><span style="font-weight: 400;">, transition into new roles and feel valued for their problem-solving and initiative-taking.  </span></p>
<p><span style="font-weight: 400;">These actions may not fully heal the negative consequences of change, but they can mitigate them, thereby rebuilding emotional resources. More importantly, they turn the employer from antagonist into ally, helping employees form a genuine </span><a href="https://www.corporatecomplianceinsights.com/telling-story-compliance/" target="_blank" rel="noopener"><b>sense of attachment</b></a><span style="font-weight: 400;"> and ownership toward the organization. </span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68476_2_6abe8700e8c4f   " data-unique="jnews_module_68476_2_6abe8700e8c4f">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/ceo-killing-window-perils-unfairness-leadership/" aria-label="Read article: From CEO’s Heinous Killing, a Window Into the Perils of Unfairness When People Crave Leadership"><div class="thumbnail-container animate-lazy  size-500 "><img decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="Luigi Mangione collage" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/01/Luigi-Mangione-collage-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/01/Luigi-Mangione-collage-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/01/Luigi-Mangione-collage-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/01/Luigi-Mangione-collage-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/ethics/">Ethics</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/ceo-killing-window-perils-unfairness-leadership/">From CEO’s Heinous Killing, a Window Into the Perils of Unfairness When People Crave Leadership</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/caterina-bulgarella/">Caterina Bulgarella</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/ceo-killing-window-perils-unfairness-leadership/"><i class="fa fa-clock-o"></i> January 29, 2025</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>The broad-daylight killing of UnitedHealthcare CEO Brian Thompson was stunning not just for its brazenness but for the public response, which in some corners seemed to celebrate Thompson’s murder. Social scientist Caterina Bulgarella explores the long-simmering dynamics that turned a murder on the streets of</p>
                                    <a href="https://www.corporatecomplianceinsights.com/ceo-killing-window-perils-unfairness-leadership/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68476_2_6abe8700e8c4f = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"63398","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Preparing for AI’s cognitive risks</span></h2>
<p><span style="font-weight: 400;">As AI keeps scaling across business, the </span><a href="https://www.corporatecomplianceinsights.com/line-between-offloading-work-ai-surrendering-your-thinking/" target="_blank" rel="noopener"><b>cognitive risks</b></a><span style="font-weight: 400;"> of continued and sustained AI use present organizations with both an ethical and talent dilemma. From an ethical standpoint, the long-term question is whether business should be held responsible for AI’s potentially harmful effects on employees. As of today, known risks include </span><a href="https://www.theguardian.com/technology/2026/mar/14/ai-chatbots-psychosis" target="_blank" rel="noopener"><b>hallucinations</b></a><span style="font-weight: 400;">, </span><a href="https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2025.1699320/full" target="_blank" rel="noopener"><b>cognitive offloading</b></a><span style="font-weight: 400;"> and </span><a href="https://today.usc.edu/remembering-the-human-encouraging-unique-voices-in-the-age-of-ai/" target="_blank" rel="noopener"><b>linguistic homogeneity</b></a><span style="font-weight: 400;">. Worse, as AI use becomes further entrenched in the workplace and scientific research advances, we may discover that its cognitive toll is far greater than currently understood.  </span></p>
<p><span style="font-weight: 400;">From a talent standpoint, AI’s negative cognitive effects not only represent a threat to business competitiveness but also run at odds with the goal of building workforce capacity, including ethical engagement.   </span></p>
<p><span style="font-weight: 400;">While the impact of hallucinating and cognitive offloading on ethical awareness and moral engagement is intuitive, linguistic and stylistic homogeneity pose risks as well. On the one hand, they create the appearance of rule-abiding conduct — irrespective of actual conduct. On the other, they may numb attention to language and behavior, two critical indicators of conduct risk.  </span></p>
<p><span style="font-weight: 400;">Unlike other challenges, organizations do not yet have a toolkit to address AI’s cognitive risks. What’s more, the solutions that have been floated so far not only fail to mitigate the threat but raise additional ethical questions. Take, for example, the suggestion that demonstrating </span><a href="https://www.theatlantic.com/ideas/2026/06/ai-open-ai-anthropic/687689/" target="_blank" rel="noopener"><b>intellectual curiosity</b></a><span style="font-weight: 400;"> is a precondition for surviving AI’s cognitive toll, or the proposition that some jobs should be </span><a href="https://www.cnbc.com/2026/08/26/why-we-need-human-reserved-jobs-bill-gates-ai-memo.html" target="_blank" rel="noopener"><b>reserved</b></a><span style="font-weight: 400;"> for humans.  </span></p>
<p><span style="font-weight: 400;">While both approaches assume that selectively preserving human value is a good enough solution, neither one is a tested mitigation strategy for cognitive risk. Nor does either proposition address the fact that continuing to expose entire swaths of the workforce to AI’s potentially harmful effects creates talent constraints, opens the door to new business risks and raises difficult ethical questions, starting with who should be in the cognitively preserved group — and why. </span></p>
<p><span style="font-weight: 400;">So, how can organizations manage AI’s cognitive risks at scale while entrenching AI use deep and wide into their operations? Instead of looking merely at workflows, companies should focus on the cognitive processes through which people engage with, consume and use information, problem-solve, experience authorship, learn and develop. Redesigning these aspects of work may not only prove the more effective way to put cognitive safeguards in place, but it may be the only way to ensure ethical AI adoption. </span></p>
<h2><span style="font-weight: 400;">Re-writing the psychological contract</span></h2>
<p><span style="font-weight: 400;">In introducing a technology that reshapes nearly everything, businesses must do more than tinker at the edges of the old psychological contract. Redesigning organizational processes and workflows is important, but it is not sufficient. What’s changing today is not only how we work but — more fundamentally — the expectations around work.  </span></p>
<p><span style="font-weight: 400;">Prognostications about who will and will not survive professionally in the age of AI are mere distractions and part of a faulty calculation. Before making any transfer to technology, organizations should first figure out the value of today&#8217;s human moat, whether and how they want to invest in human capital and what type of relationship they want to build with employees. In short, they should re-write the old psychological contract well ahead of the awaited job apocalypse.  </span></p>
<p><span style="font-weight: 400;">This is not a purely ethical or philosophical stance. As firms may increasingly discover, unlike past change cycles, AI adoption is poised to unleash a level of resistance proportional to its disruption, with costs for both </span><a href="https://www.corporatecomplianceinsights.com/culture-is-not-workstream/" target="_blank" rel="noopener"><b>business operations and corporate culture</b></a><span style="font-weight: 400;">. Consider the need for employee engagement, including ethical engagement, and the implications of failing to reframe the psychological contract first become immediately clear — from escalating tension between self and organizational interests to an increased risk of corporate failure.  </span></p>
<p><span style="font-weight: 400;">Indeed, for today’s organization, the question of whether the business can survive and thrive is deeply intertwined with its workforce, whether senior leaders want to acknowledge it or not.  </span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/ai-governance-frameworks-wont-save-you-ethically-engaged-workforce-might/">AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Feds: Cybercrime Is Getting Worse &amp; Compliance Can’t Treat It Like Someone Else’s Problem</title>
		<link>https://www.corporatecomplianceinsights.com/feds-cybercrime-is-getting-worse-compliance-cant-treat-it-like-someone-else-problem/</link>
		
		<dc:creator><![CDATA[Jennifer L. Gaskin]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 15:39:22 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Cyber Risk]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Data Breach]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68481</guid>

					<description><![CDATA[<p>Federal officials say cybersecurity is squarely an ethics &#038; compliance concern</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/feds-cybercrime-is-getting-worse-compliance-cant-treat-it-like-someone-else-problem/">Feds: Cybercrime Is Getting Worse &#038; Compliance Can’t Treat It Like Someone Else’s Problem</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">A company that&#8217;s bad at cybersecurity isn&#8217;t really complying with any of the policies it works so hard to enforce — that&#8217;s the case federal investigators made to compliance leaders at this year’s SCCE Compliance &amp; Ethics Institute, CCI&#8217;s Jennifer L. Gaskin reports.</span></i></p>
</div>
<p><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>Compliance</b></a><span style="font-weight: 400;"> officers are accustomed to being labeled as their organizations’ internal cops (or much worse). Josh Goldfoot, a deputy assistant attorney general in the </span><a href="https://www.corporatecomplianceinsights.com/tag/doj/" target="_blank" rel="noopener"><b>DOJ’s</b></a><span style="font-weight: 400;"> Criminal Division, sees them differently: as “advisers and architects that are creating systems that help your organizations follow the law, behave ethically and head off problems.” That’s why he recommends they make sure they’re taking up a particular agenda item: </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cybersecurity</b></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">&#8220;If your organization is bad at cybersecurity, then ultimately, is it really complying with any of the policies you sought to enforce?&#8221; Goldfoot asked attendees this week at SCCE&#8217;s 2026 Compliance &amp; Ethics Institute in Orlando, the organization&#8217;s 25th annual event.</span></p>
<p><span style="font-weight: 400;">The question is becoming more urgent as fraudsters increasingly use </span><a href="https://www.corporatecomplianceinsights.com/tag/artificial-intelligence/" target="_blank" rel="noopener"><b>AI</b></a><span style="font-weight: 400;">-enabled tools to scale their reach and improve their tactics. </span><a href="https://www.fbi.gov/file-repository/2025_ic3report.pdf/view" target="_blank" rel="noopener"><b>In 2025, the FBI’s Internet Crime Complaint Center</b></a><span style="font-weight: 400;"> logged more than 1 million complaints for the first time, up from about 860,000 the year before, with losses of nearly $21 billion.</span></p>
<p><span style="font-weight: 400;">Gone are the days when antivirus protection would suffice, even for companies that don’t think of themselves as exposed, Goldfoot said. </span></p>
<p><span style="font-weight: 400;">&#8220;If you have money, and you&#8217;re connected to the internet, you are of interest to sophisticated hacking groups,&#8221; he told the assembled crowd of compliance leaders.</span></p>
<h2><span style="font-weight: 400;">AI is erasing the warning signs</span></h2>
<p><span style="font-weight: 400;">Much of the acceleration the FBI’s </span><a href="https://www.corporatecomplianceinsights.com/tag/cyber-crime/" target="_blank" rel="noopener"><b>cybercrime</b></a><span style="font-weight: 400;"> data highlights is being driven by AI, said Jason Cromartie, special agent in charge of the FBI&#8217;s Cincinnati field office, who opened the general session Monday. Phishing remains a leading way attackers get into networks, and generative AI tools have made messages appear more sophisticated than in years past. Bad grammar and spelling aren’t dead giveaways anymore. </span></p>
<p><span style="font-weight: 400;">&#8220;These tools reduce the traditional warning signs and allow attackers to exploit trust at a whole new level,&#8221; Cromartie said.</span></p>
<p><a href="https://www.corporatecomplianceinsights.com/can-you-spot-deepfake/" target="_blank" rel="noopener"><b>Deepfakes are becoming more realistic</b></a><span style="font-weight: 400;">, and voice cloning is on the rise. Cromartie described an FBI investigation involving a Fortune 500 company that lost $1 million after an employee acted on a cloned voicemail from the CFO, who was overseeing a merger at the time. </span></p>
<p><span style="font-weight: 400;">The next frontier is agentic AI, he said. AI agents can search for information, select targets, create believable personas and attempt exploitation continuously, making attacks harder to detect and disrupt.</span></p>
<p><span style="font-weight: 400;">&#8220;We&#8217;re all trying to play catch-up to the rapid advances in the technology,&#8221; Cromartie said.</span></p>
<p><a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:607b9590-38e0-4c91-b433-aa8a17f5b5e8/original/as/cost-of-a-data-breach-2025-full-report.pdf" target="_blank" rel="noopener"><b>IBM’s 2025 annual report on the cost of a data breach</b></a><span style="font-weight: 400;"> indicated that about one in six data breaches involved attackers using AI, most often via AI-generated phishing and </span><a href="https://www.corporatecomplianceinsights.com/cfo-calling-risk-answering/" target="_blank" rel="noopener"><b>deepfake impersonation attacks</b></a><span style="font-weight: 400;">.</span></p>
<h2><span style="font-weight: 400;">The role of compliance</span></h2>
<p><span style="font-weight: 400;">AI may be amplifying the problem, but it didn’t create the root cause of the issue, which often comes down to the human element. Organizations have spent years trying to train their way out of this problem. Annual cybersecurity modules and simulated phishing emails are standard fare across companies and organizations of all sizes and industries. </span></p>
<p><span style="font-weight: 400;">Still, business email compromise is the second-costliest category in the FBI’s 2025 report, accounting for more than $3 billion in losses. And IBM found that phishing was the most common attack vector, accounting for 16% of all </span><a href="https://www.corporatecomplianceinsights.com/tag/data-breach/" target="_blank" rel="noopener"><b>data breaches</b></a><span style="font-weight: 400;"> in their report.</span></p>
<p><span style="font-weight: 400;">&#8220;Humans do not always make the best decisions,&#8221; Cromartie said. &#8220;Threat actors are often using that as a vector.&#8221; And it doesn&#8217;t take much: &#8220;One person, one click can cause a lot of damage.&#8221;</span></p>
<p><span style="font-weight: 400;">For Goldfoot, that makes cybercrime an ethics and compliance issue: &#8220;How are the interests that you work for, the values and ethics that you want your organizations to uphold, how is that affected by the new cybercrime threat?&#8221; he asked.</span></p>
<p><span style="font-weight: 400;">Consider the checks and balances an organization builds around protecting patient information, he said. How much is that work worth if an attacker simply walks off with the data? That leads to a harder question about compliance&#8217;s place in the organization. How much influence, and how much oversight, should compliance have over cybersecurity practices? And if the organization isn&#8217;t assessing the threat correctly, is that something compliance can help fix?</span></p>
<p><span style="font-weight: 400;">Cromartie suggested compliance leaders are well positioned to try. &#8220;You have the responsibility to understand almost every aspect of the business operations that you&#8217;re with,&#8221; he said. &#8220;You have to see the big picture, you have to see what&#8217;s around the corner as well as over the horizon.&#8221;</span></p>
<p><span style="font-weight: 400;">That includes AI. Cromartie urged organizations adopting AI tools to establish governance with cross-functional ownership, map who uses the technology and what data it touches, measure for security flaws and bias and deploy firm guardrails, including routine human audits. He also recommended bringing in as many stakeholders as possible, including the CIO, the chief security officer, legal counsel and subject-matter experts.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68481_3_6abe8700ec3d1   " data-unique="jnews_module_68481_3_6abe8700ec3d1">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/cisos-boards-speak-same-language-cybersecurity/" aria-label="Read article: Why CISOs and Boards Must Speak the Same Language on Cybersecurity"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="neon handshake sign" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/neon-handshake-sign-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/neon-handshake-sign-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/neon-handshake-sign-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/02/neon-handshake-sign-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/cybersecurity/">Cybersecurity</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/cisos-boards-speak-same-language-cybersecurity/">Why CISOs and Boards Must Speak the Same Language on Cybersecurity</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/monica-landen/">Monica Landen</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/cisos-boards-speak-same-language-cybersecurity/"><i class="fa fa-clock-o"></i> February 4, 2025</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>Translating cyber risks into boardroom terms is essential for resilience</p>
                                    <a href="https://www.corporatecomplianceinsights.com/cisos-boards-speak-same-language-cybersecurity/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68481_3_6abe8700ec3d1 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"63470","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Why call the feds</span></h2>
<p><span style="font-weight: 400;">Despite the growing threat, many victims still don&#8217;t pick up the phone. When the </span><a href="https://www.justice.gov/archives/opa/pr/us-department-justice-disrupts-hive-ransomware-variant" target="_blank" rel="noopener"><b>FBI infiltrated the Hive ransomware group a few years ago</b></a><span style="font-weight: 400;">, investigators could see which companies the group was attacking, Goldfoot said. They warned targets and, in some cases, handed over decryption keys. They could also see how many victims had already contacted law enforcement on their own: only about 20%.</span></p>
<p><span style="font-weight: 400;">That is mirrored in IBM’s report, which found that among organizations that had a ransomware attack, the share of those contacting relevant authorities actually fell from 2024 (52%) to 2025 (40%).</span></p>
<p><span style="font-weight: 400;">Companies have reasons for hesitation, to be sure: embarrassment and </span><a href="https://www.corporatecomplianceinsights.com/threat-actor-tactics-cybersecurity-communications/" target="_blank" rel="noopener"><b>reputational damage</b></a><span style="font-weight: 400;">, namely, and many pay the ransom demand and hope the crisis ends there. But it often doesn’t end there. A </span><a href="https://www.crowdstrike.com/en-us/press-releases/ransomware-report-ai-attacks-outpacing-defenses/" target="_blank" rel="noopener"><b>2025 CrowdStrike survey</b></a><span style="font-weight: 400;"> found that 83% of organizations that paid a ransom demand were attacked again anyway, and 93% had data stolen.</span></p>
<p><span style="font-weight: 400;">The message from both Cromartie and Goldfoot is clear: Don’t pay.</span></p>
<p><span style="font-weight: 400;">&#8220;Blackmail does not end until the victim of the blackmail decides that it ends,&#8221; Goldfoot said. Cromartie agreed: Even after a second payment, &#8220;there is nothing that prevents them from having that data they&#8217;ve taken, selling it.&#8221; Goldfoot added that some ransomware groups are under US </span><a href="https://www.corporatecomplianceinsights.com/tag/sanctions/" target="_blank" rel="noopener"><b>sanctions</b></a><span style="font-weight: 400;">, which makes a payment a legal risk of its own.</span></p>
<p><span style="font-weight: 400;">Coming forward, by contrast, doesn&#8217;t put a company in the crosshairs, Goldfoot said. Law enforcement treats those who report as crime victims, not suspects: &#8220;You don&#8217;t go to a crime victim and start lecturing the crime victim about all the things they could have done to prevent being a crime victim.&#8221;</span></p>
<p><span style="font-weight: 400;">Investigators work through a company&#8217;s own forensics firm and receive only what the company agrees to share, he said. Court filings identify victims anonymously, and information stays in the criminal investigative file. &#8220;We&#8217;re not regulators,&#8221; Goldfoot said. He urged companies to build those relationships before an attack, including through the </span><a href="https://infragard.fbi.gov/" target="_blank" rel="noopener"><b>FBI&#8217;s InfraGard program</b></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">Goldfoot closed with a reminder that law enforcement can&#8217;t solve the problem alone. Every type of policing, he said, &#8220;only works when we have the support of the community that we&#8217;re trying to protect. And in our case, that means protecting everyone with a computer.&#8221;</span></p>
<p><span style="font-weight: 400;">&#8220;We&#8217;ve struck fear in the hearts of some ransomware actors,&#8221; he said. &#8220;But I want to do more of that.&#8221;</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/feds-cybercrime-is-getting-worse-compliance-cant-treat-it-like-someone-else-problem/">Feds: Cybercrime Is Getting Worse &#038; Compliance Can’t Treat It Like Someone Else’s Problem</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Standard Due Diligence May Not be Enough in Mexico</title>
		<link>https://www.corporatecomplianceinsights.com/standard-due-diligence-may-not-be-enough-mexico/</link>
		
		<dc:creator><![CDATA[Alejandro Ortega, Miguel Salcedo and David Williams]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 11:00:27 +0000</pubDate>
				<category><![CDATA[Risk]]></category>
		<category><![CDATA[Beneficial Ownership]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Office of Foreign Assets Control (OFAC)]]></category>
		<category><![CDATA[Sanctions]]></category>
		<category><![CDATA[Supply Chain]]></category>
		<category><![CDATA[Trade Compliance]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68439</guid>

					<description><![CDATA[<p>KYC screening does not always reveal ownership connections</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/standard-due-diligence-may-not-be-enough-mexico/">Standard Due Diligence May Not be Enough in Mexico</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Two Mexican business owners were sanctioned this summer by US authorities who say they helped a drug cartel smuggle fuel across the border. Combined with last year’s designation of cartels as terrorist groups, traditional due diligence may not cut it anymore in Mexico, write Alejandro Ortega, Miguel Salcedo and David Williams of FTI Consulting.</span></i></p>
</div>
<p><span style="font-weight: 400;">In June, the </span><a href="https://www.corporatecomplianceinsights.com/tag/ofac/" target="_blank" rel="noopener"><b>Office of Foreign Assets Control (OFAC)</b></a><span style="font-weight: 400;"> targeted and sanctioned two individuals and seven </span><a href="https://www.corporatecomplianceinsights.com/year-after-designation-cartels-risk-landscape-mexico/" target="_blank" rel="noopener"><b>companies in Mexico</b></a><span style="font-weight: 400;"> for facilitating the </span><a href="https://www.corporatecomplianceinsights.com/when-cartel-head-falls-money-keeps-moving/" target="_blank" rel="noopener"><b>Cartel Jalisco Nueva Generación (CJNG)</b></a><span style="font-weight: 400;">, a cross-border fuel smuggling network. The </span><a href="https://home.treasury.gov/news/press-releases/sb0545" target="_blank" rel="noopener"><b>designated companies included</b></a><span style="font-weight: 400;"> a </span><a href="https://www.corporatecomplianceinsights.com/financial-services-news/" target="_blank" rel="noopener"><b>financial services</b></a><span style="font-weight: 400;"> company, freight and transportation firms and a real estate company, all owned or controlled by the same individual. None of the sanctioned individuals or companies had previously appeared on </span><a href="https://sanctionssearch.ofac.treas.gov/" target="_blank" rel="noopener"><b>OFAC’s specially designated nationals</b></a><span style="font-weight: 400;"> and blocked persons list prior to the June 30 action.</span></p>
<p><span style="font-weight: 400;">This highlights a broader challenge for companies conducting business in high-risk environments: Criminal networks </span><a href="https://www.europol.europa.eu/cms/sites/default/files/documents/Europol_report_-_Leveraging_legitimacy_-_How_the_EU_most_threatening_crim_networks_abuse_legal_business_structures.pdf" target="_blank" rel="noopener"><b>increasingly rely</b></a><span style="font-weight: 400;"> on legitimate commercial structures and </span><a href="https://www.corporatecomplianceinsights.com/tag/supply-chain/" target="_blank" rel="noopener"><b>supply chains</b></a><span style="font-weight: 400;"> to facilitate illicit activity. In today&#8217;s Mexican regulatory environment, the question is no longer, &#8220;Is this company sanctioned?&#8221; but rather, &#8220;Should this company be doing the business it claims to perform and who ultimately benefits from it?&#8221;</span></p>
<h2><span style="font-weight: 400;">Why traditional Know Your Client checks falls short</span></h2>
<p><span style="font-weight: 400;">Conventional due diligence practices are built primarily around </span><a href="https://www.corporatecomplianceinsights.com/tag/sanctions/" target="_blank" rel="noopener"><b>sanctions</b></a><span style="font-weight: 400;"> and watchlist screening procedures conducted during an onboarding procedure. Historically, these methods were designed to </span><a href="https://wolfsberg-group.org/news/19" target="_blank" rel="noopener"><b>identify counterparties</b></a><span style="font-weight: 400;"> that have been named by a regulator or law enforcement agency. However, they were not designed to detect facilitators before that designation occurred, or to identify relationships between counterparties that appear unrelated.</span></p>
<p><span style="font-weight: 400;">One of the two individuals designated controlled six Mexican companies in three sectors, including one based in the UK. Viewed individually, none of the designated companies would have appeared to be connected. It was only by examining the ultimate beneficial ownership of these companies that the individual emerged as the common link connecting the network.</span></p>
<p><span style="font-weight: 400;">The man was designated by OFAC for providing services, material and financial assistance to CJNG. Through his role, he facilitated fiscal fuel theft schemes by using a network of companies. In a traditional </span><a href="https://www.corporatecomplianceinsights.com/tag/know-your-customer/" target="_blank" rel="noopener"><b>Know Your Client (KYC) review</b></a><span style="font-weight: 400;">, none of these characteristics would have been identified through standard sanctions and watchlist screening because, in part, before the June 30 designation, neither he nor his companies appeared on the OFAC’s sanctions list, and their operations were dispersed across different industries and jurisdictions, giving little indication that they formed part of the same network. The common link appeared only when the companies were viewed collectively through their ownership structure rather than as independent legal entities.</span></p>
<p><span style="font-weight: 400;">This illustrates the fundamental limitation of traditional due diligence: Screening can identify counterparties that have already been designated, but it is far less effective at revealing commercial networks, ownership structures and facilitators that remain hidden. The need for a more comprehensive approach is reinforced by the evolving US enforcement landscape.</span></p>
<p><span style="font-weight: 400;">The June designations came just over a year after </span><a href="https://www.state.gov/designation-of-international-cartels/" target="_blank" rel="noopener"><b>six Mexican cartels</b></a><span style="font-weight: 400;">, including CJNG and Sinaloa, were designated as foreign terrorist organizations (FTOs), which means that companies with </span><a href="https://www.corporatecomplianceinsights.com/state-fcpa-enforcement-fewer-cases-risk-remains/" target="_blank" rel="noopener"><b>Mexico-related business activities</b></a><span style="font-weight: 400;"> operating in or with exposure to high-risk sectors face legal, regulatory and </span><a href="https://www.corporatecomplianceinsights.com/tag/reputation-risk/" target="_blank" rel="noopener"><b>reputational risks</b></a><span style="font-weight: 400;"> associated with commercial relationships that may directly or indirectly benefit designated organizations.</span></p>
<p><span style="font-weight: 400;">Reliance on basic sanctions screening alone may no longer provide a sufficient understanding of counterparty </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;">, and organizations operating in Mexico should instead adopt a risk-based approach that considers the nature of the industry, the jurisdictions in which a counterparty operates, the complexity of its ownership structure, its regulatory authorizations and the broader supply chain. Depending on the level of exposure, companies should also evaluate whether enhanced due diligence measures are needed to identify hidden risks before they become regulatory, financial or reputational liabilities. </span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68439_4_6abe8700ef624   " data-unique="jnews_module_68439_4_6abe8700ef624">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/fcpa-changes-terrorist-designations-cartels-latin-america/" aria-label="Read article: FCPA Changes &#038; Terrorist Designations for Cartels Create Dangerous New Math in Latin America"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="fcpa latin america drug cartel" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/03/fcpa-latin-america-drug-cartel-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/03/fcpa-latin-america-drug-cartel-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/03/fcpa-latin-america-drug-cartel-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2025/03/fcpa-latin-america-drug-cartel-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/fcpa/">FCPA</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/fcpa-changes-terrorist-designations-cartels-latin-america/">FCPA Changes &#038; Terrorist Designations for Cartels Create Dangerous New Math in Latin America</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/matteson-ellis-james-tillen-maria-lapetina/">Matteson Ellis, James Tillen and Maria Lapetina</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/fcpa-changes-terrorist-designations-cartels-latin-america/"><i class="fa fa-clock-o"></i> March 19, 2025</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>As the Trump Administration takes aim at Latin American cartels with foreign terrorist organization designations, the legal landscape for businesses has dramatically shifted.</p>
                                    <a href="https://www.corporatecomplianceinsights.com/fcpa-changes-terrorist-designations-cartels-latin-america/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68439_4_6abe8700ef624 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"63804","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"23","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Why beneficial ownership matters more than ever</span></h2>
<p><span style="font-weight: 400;">This case underscores why the beneficial ownership analysis is no longer a secondary step in Mexican due diligence. Screening a company’s registered name, listed directors or filing address may not reveal whether the same individual ultimately owns or controls multiple entities operating across different sectors or jurisdictions. </span></p>
<p><span style="font-weight: 400;">Mexico provides a significant amount of publicly available corporate information, but accessing that information is not the same as retrieving a complete ownership structure from a centralized commercial database. Corporate records are maintained through the Public Registry of Commerce, whose offices operate locally across Mexico’s states and jurisdictions. The availability and format of historical filings can vary, and reconstructing ownership may require reviewing multiple corporate acts over time rather than relying on a single current record. Where shareholders, affiliates or related entities extend beyond Mexico, the analysis may also require consulting foreign corporate registries and tracing ownership across different disclosure regimes.</span></p>
<p><span style="font-weight: 400;">For companies conducting due diligence, the implication is significant: Identifying beneficial ownership is not simply a matter of confirming the names disclosed by a counterparty. It may require piecing together corporate records across jurisdictions, identifying common shareholders or controllers and assessing those relationships collectively. This type of analysis can reveal connections that conventional KYC screening may overlook and, in higher-risk environments, help companies understand not only who their immediate counterparty is, but the broader network behind it.</span></p>
<p><span style="font-weight: 400;">But a company’s name and ownership are a part of the picture. Even where beneficial ownership is fully mapped, a due diligence review can still miss a company that is operating outside the bounds of its own regulatory authorization, simply because that information sits in a different place entirely; not a corporate registry but a sector-specific regulator.</span></p>
<p><span style="font-weight: 400;">Every regulated industry in Mexico has its own authority, and its own disclosure requirements. For example, non-bank financial companies (SOFOMes) are supervised by the National Banking and Securities Commission (Comisión Nacional Bancaria de Valores or CNBV), and publicly listed companies are subject to disclosure requirements through both the CNBV and the Mexican Stock Exchange (Bolsa Mexicana de Valores or BMV). In each case of these industry examples, the relevant information exists and is often publicly accessible but only if the reviewer knows which regulator governs that specific industry.</span></p>
<h2><span style="font-weight: 400;">Knowing where to look in a high-risk jurisdiction</span></h2>
<p><span style="font-weight: 400;">The cases of the sanctioned individuals illustrate that due diligence can no longer be limited to confirming that a counterparty does not appear on a sanctions list. Regulatory information in Mexico is frequently fragmented across multiple government repositories and published in formats that are not easily searchable or structured for commercial databases. Therefore, identifying the relevant permits, registrations or enforcement actions often requires more than a simple database search. It requires an understanding of Mexico&#8217;s regulatory framework, familiarity with the authorities overseeing each industry and the ability to interpret the significance of the information in the context of a due diligence review.</span></p>
<p><span style="font-weight: 400;">Effective due diligence in high-risk jurisdictions like Mexico requires organizations to understand who ultimately owns a business, whether it operates within its regulatory authorizations and how it fits into a broader commercial network. As criminal organizations increasingly use legitimate business structures, this broader perspective helps organizations identify potential legal, financial and reputational risks before they become enforcement issues.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/standard-due-diligence-may-not-be-enough-mexico/">Standard Due Diligence May Not be Enough in Mexico</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>10 Questions for Focusing Your Technology Modernization Investments</title>
		<link>https://www.corporatecomplianceinsights.com/10-questions-focusing-your-technology-modernization-investments/</link>
		
		<dc:creator><![CDATA[Jim DeLoach]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 11:00:17 +0000</pubDate>
				<category><![CDATA[Risk]]></category>
		<category><![CDATA[Board of Directors]]></category>
		<category><![CDATA[Board Risk Oversight]]></category>
		<category><![CDATA[Enterprise Risk Management (ERM)]]></category>
		<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68454</guid>

					<description><![CDATA[<p>These questions create the foundation for a framework suited for the investment climate of today</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/10-questions-focusing-your-technology-modernization-investments/">10 Questions for Focusing Your Technology Modernization Investments</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">Past experience with the cost and risks of technology modernization projects is driving boards and executives to be more selective about allocating capital and has increased the emphasis on the certainty of delivering tangible value. Protiviti’s Jim DeLoach offers 10 questions to guide these tough conversations.</span></i></p>
</div>
<p><span style="font-weight: 400;">Technology modernization is a topic that has found its way into every C-suite and boardroom. In recent years, significant investments have been made by companies recognizing a need to modernize to avoid losing market share to “born digital” entrants to the market. Banks and insurers, for example, were concerned that failure to modernize would result in loss of market share to fintechs — indeed, a competitive threat that framed a potential winner-take-all scenario.</span></p>
<p><span style="font-weight: 400;">More recently, however, the narrative has shifted, with less emphasis on hype and FOMO (fear of missing out). In </span><a href="https://www.corporatecomplianceinsights.com/financial-services-news/" target="_blank" rel="noopener"><b>financial services</b></a><span style="font-weight: 400;">, the “winner takes all” view has softened as fintechs carved a role in the market that did not crowd out incumbents, largely because they did not want to be regulated. Their choice to coexist with incumbent financial institutions lessened the threat. More broadly, for companies across all sectors, the initial return on investment (ROI) associated with new technologies underdelivered, elevating healthy skepticism. And, most importantly, the cost of capital has gone up, raising the hurdle rate for all investments.  </span></p>
<p><span style="font-weight: 400;">Thus, CEOs, executive teams and </span><a href="https://www.corporatecomplianceinsights.com/tag/board-of-directors/" target="_blank" rel="noopener"><b>boards</b></a><span style="font-weight: 400;"> are now faced with evaluating investments in transformation programs amid a new narrative. Proponents of technology modernization, digital transformation and strategic IT initiatives need to articulate a stronger, more compelling business case for delivering value with less </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;">. </span></p>
<p><span style="font-weight: 400;">Of course, there are costs associated with </span><i><span style="font-weight: 400;">failing</span></i><span style="font-weight: 400;"> to modernize. A</span><a href="https://www.protiviti.com/us-en/global-technology-executive-survey" target="_blank" rel="noopener"> <b>global survey</b></a> <span style="font-weight: 400;">of more than 1,000 CIOs, CTOs, CISOs and other technology executives and leaders revealed that 70% of organizations view technical debt as a major drag on their ability to innovate. Over time, this leads to inability to execute strategy, increased operating costs, lost revenue, poor customer experience, inability to retain and attract top talent and the attendant effects of losing competitive advantage, market share and shareholder value. Thus, both sides of the coin are relevant.</span></p>
<h2><span style="font-weight: 400;">10 important questions about technology investments</span></h2>
<p><span style="font-weight: 400;">Accordingly, an evaluation of the organization’s framework for navigating technology investments relative to other business priorities is in order. What is needed is a framework that emphasizes maximizing value and </span><a href="https://www.corporatecomplianceinsights.com/balancing-risk-reward-perfect-dance-changing-times/" target="_blank" rel="noopener"><b>minimizing financial risk</b></a><span style="font-weight: 400;">. Nothing new about that, but leaders and directors may benefit from considering the following questions that underpin a practical framework that is fit for purpose in today’s investment climate:</span></p>
<h3><span style="font-weight: 400;">1. Do we have a clear understanding of the lessons learned from our modernization investments over the past five years? </span></h3>
<p><span style="font-weight: 400;">Understand the extent to which promised returns were delivered and, most importantly, why or why not. What is working, what is not? Can we do better? Over and over, management must examine and adapt. Best practices and mistakes should be identified through a post-mortem and improvements made to the business case development process and project management approach.</span></p>
<h3><span style="font-weight: 400;">2. Have we balanced our long- and short-term perspectives? </span></h3>
<p><span style="font-weight: 400;">The long-term narrative should define the direction of IT investments, address emerging technologies that could create a need for modularity and flexibility and envision what the enterprise is expected to look like in, say, five years. It provides a contextual framework for evaluating whether proposed modernization initiatives and technology partnerships are directionally compatible with the strategy and vision going forward. In the short term, management should articulate principles that enable business agility and continuous modernization, such as modular architecture for ease of updates, support for agile deployment, real-time and event-driven processes to enhance responsiveness, scalable and secure architecture, a unified </span><a href="https://www.corporatecomplianceinsights.com/tag/data-governance/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> repository to establish a single version of the truth, a seamless customer experience-driven environment and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> sensitivity.</span></p>
<h3><span style="font-weight: 400;">3. Do we have the right partners? </span></h3>
<p><span style="font-weight: 400;">Senior leaders and directors should consider being more selective in evaluating whether the technology in question fits a use case for modernization and how that decision is supported. Most importantly, they should understand how and why a particular vendor is selected. For example, the company may have a single cloud provider or a hybrid environment. Many organizations have discovered — some the hard way — that choosing among cloud providers like Amazon Web Services, Microsoft Azure and Google Cloud Platform can be a complex task, as each offers unique advantages and has different approaches with respect to similar issues. Because they may or may not align with a company’s specific needs and strategic objectives, it is important to understand these differences and, importantly, what specific services the company needs. The key is to balance a vendor’s innovation path with the company’s overall strategy. If they are incompatible, a change in vendors is needed.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68454_5_6abe8700f2e43   " data-unique="jnews_module_68454_5_6abe8700f2e43">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/bored-directors-how-make-sure-board-materials-contributing-value/" aria-label="Read article: Bored Directors? How to Make Sure Board Materials Are Contributing Value"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="packets for meeting on desk" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/packets-for-meeting-on-desk-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/packets-for-meeting-on-desk-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/packets-for-meeting-on-desk-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/packets-for-meeting-on-desk-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/featured/">Featured</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/bored-directors-how-make-sure-board-materials-contributing-value/">Bored Directors? How to Make Sure Board Materials Are Contributing Value</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/jim-deloach/">Jim DeLoach</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/bored-directors-how-make-sure-board-materials-contributing-value/"><i class="fa fa-clock-o"></i> August 26, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p></p>
                                    <a href="https://www.corporatecomplianceinsights.com/bored-directors-how-make-sure-board-materials-contributing-value/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68454_5_6abe8700f2e43 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"68036","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h3><span style="font-weight: 400;">4. Do we have the right skills, and are we connecting with the business? </span></h3>
<p><span style="font-weight: 400;">Building capabilities without the skillsets needed to leverage modernization investments and maximize their value over time is a common issue. Internal resources are especially important when embracing a tailored approach for modernization. Global capability and delivery centers can be useful in deploying the organization’s entire technology talent pool so that there is cost-effective collaboration across geographies. Transforming the company to a product- or platform-centric organization can break down silos and facilitate resource mobility. Large-scale reskilling and </span><a href="https://www.corporatecomplianceinsights.com/tag/training/" target="_blank" rel="noopener"><b>training</b></a><span style="font-weight: 400;"> programs may be necessary. External resources can be hired to bring to bear specialized knowledge that address internal gaps. As for connecting with the business,</span><a href="https://www.businesswire.com/news/home/20200528005186/en/74-Of-Organizations-Fail-to-Complete-Legacy-System-Modernization-Projects-New-Report-From-Advanced-Reveals" target="_blank" rel="noopener"> <b>one study</b></a><span style="font-weight: 400;"> noted that 74% of organizations that have started a legacy system modernization project failed to complete it and that one of the largest obstacles to a successful modernization project is a disconnect of priorities between technical and leadership teams. It is imperative that this issue be ironed out before commencing a tech modernization project.</span></p>
<h3><span style="font-weight: 400;">5. Do we buy, build or deploy a hybrid approach? </span></h3>
<p><span style="font-weight: 400;">When it comes to modernizing infrastructure, the decision to buy or build is a critical one. Beyond the obvious factors like the organization’s specific needs, resources, skills and strategic objectives, other considerations include cost, extent of required customization, scalability of design, ongoing maintenance and support and speed to market. In addition, the decision isn’t always either/or. In many cases, a hybrid approach combining purchased and custom-built solutions offers the best balance of cost, flexibility and speed.</span></p>
<h3><span style="font-weight: 400;">6. Can we break down massive investments into discrete components? </span></h3>
<p><span style="font-weight: 400;">Much less willing to cut the $100 million check, companies are leaning more into discrete investments to generate value from smaller increments of work. Breaking down complex projects into more manageable components within the context of the longer-term plan enables project teams to learn and fail fast, focus on the customer, build a superior user experience, invest for flexibility and speed, and think modular and agile. It also helps avoid wasted effort. For example, the physical hardware of the iPhone needed to exist before developers could create apps specifically designed to run on it. Accordingly, technology infrastructure investments must be appropriately sequenced.</span></p>
<h3><span style="font-weight: 400;">7. Do we have the data we need to sustain a strong customer focus? </span></h3>
<p><span style="font-weight: 400;">Companies have learned that to put the customer first, they need real-time data. Without it, how can management know whether the customer experience is achieving the expected results? This is the hard part of fostering sustainable change and must be addressed to avoid making small adjustments in one part of the process that create undesirable impacts on the customer experience in other parts of the process.</span></p>
<h3><span style="font-weight: 400;">8. Are we thinking creatively? </span></h3>
<p><span style="font-weight: 400;">Fostering internal competition among candidate projects encourages creativity and out-of-the-box thinking on framing how and why projects should be undertaken. Stepping out of the confines of the traditional sandbox in which technology executives play can make a difference. For example, some organizations may see the benefit of starting from a digital-first, clean slate to deploy new infrastructure based on modern technologies — separate and apart from the legacy environment — to support new products or markets. This strategy may entail establishing a new legal entity because the complexities of the legacy enterprise may make achieving the full architectural vision too difficult. Some companies that try to transform their legacy infrastructure are losing hundreds of millions of dollars. </span></p>
<h3><span style="font-weight: 400;">9. Have we raised the business-case bar to the right level? </span></h3>
<p><span style="font-weight: 400;">It’s not enough to pursue technology modernization based on the allure of new features and functionality. If decision-makers fail to see clear, measurable value from investments in new tech capabilities, they should select other opportunities that are more likely to deliver value for customers and shareholders. This makes it incumbent on the company’s technology modernization leaders not only to present to the board a compelling business case for a project but also to execute it with precision and a strong focus on delivering to expectations. Business-case development should begin with the premise that an organization (and its investors) can earn attractive rates with an inflation-adjusted bond with minimal risk, and the business case must present the rationale why the ROI expected from the proposed technology investment will exceed these minimal-risk returns. Thus, the business case supporting selected use cases must help answer the why, when and what questions:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">When is the right time to invest? Why do we need to make this investment now? Why not six months, 12 months, 18 months from now?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">What is the opportunity cost of moving forward at this moment?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Is there an external event driving the proposal? </span><a href="https://www.corporatecomplianceinsights.com/company-unleashing-full-power-innovation/" target="_blank" rel="noopener"><b>Does it involve an innovation</b></a><span style="font-weight: 400;"> that presents an attractive market opportunity?</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">What is the expected outcome and projected ROI, and how long will it take to realize the expected value?</span></li>
</ul>
<h3><span style="font-weight: 400;">10. Are we undertaking the best approach to modernize? </span></h3>
<p><span style="font-weight: 400;">Once the value proposition is defined and the business case approved, navigating the technology modernization journey requires a meticulously charted course that incorporates due diligence, discovery and the establishment of waypoints to ensure key milestones are achieved. The technology modernization process often involves adopting a standardized approach that addresses specific organizational needs while remaining flexible enough to integrate various solutions. The most common components of a standardized technology modernization process are upgrading to new versions or features of existing software, building new applications from scratch, acquiring new software and migrating data and processes and acquiring another company with a modernized application stack.</span></p>
<p><span style="font-weight: 400;">With the longer-term strategic narrative and ROI the primary focus for go-forward decisions on technology modernization projects, it is critical to focus on four interrelated drivers that can deliver the expected value — lowering costs, gaining more flexibility and power in deals with strategic vendors, overcoming the inability to build new functionality into current applications and meeting regulatory compliance requirements. These drivers are fundamental to defining and communicating a clear value proposition to executive management and the board.</span></p>
<h2><span style="font-weight: 400;">A tough conversation</span></h2>
<p><span style="font-weight: 400;">Technology modernization can present a tough strategic conversation in the C-suite and boardroom. The discussion boils down to the opportunity cost of allocating capital, a cost that is as high as it has been in 15 years. Consistent with their responsibility to company shareholders, senior management and directors should ensure that the organization defines the overall investment objectives clearly, specifies opportunities for improvement, identifies the right technologies and lines up the necessary resources to undertake the project successfully.</span></p>
<p><span style="font-weight: 400;">Most importantly, proposed investments in selected use cases presented to the executive team and board must be supported by a compelling business case demonstrating that value and ROI will be delivered, all within the context of a longer-term journey explained in plain English.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/10-questions-focusing-your-technology-modernization-investments/">10 Questions for Focusing Your Technology Modernization Investments</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GRC Business Roundup: Dow Jones, Casepoint, Onspring, Ethyca, Sweep &amp; More</title>
		<link>https://www.corporatecomplianceinsights.com/grc-business-roundup-dow-jones-casepoint-onspring-ethyca-sweep-more/</link>
		
		<dc:creator><![CDATA[Corporate Compliance Insights]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 15:02:26 +0000</pubDate>
				<category><![CDATA[GRC Vendor News]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68450</guid>

					<description><![CDATA[<p>The business of GRC is ever-expanding, GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest from across the industry. New products &#38; platforms Dow Jones launched the WSJ Geopolitical Risk Council, an invitation-only executive community to support corporate decision-makers as they prepare for geopolitical [&#8230;]</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/grc-business-roundup-dow-jones-casepoint-onspring-ethyca-sweep-more/">GRC Business Roundup: Dow Jones, Casepoint, Onspring, Ethyca, Sweep &#038; More</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">The business of GRC is ever-expanding, GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest from across the industry.</span></i></h6>
<h2><span style="font-weight: 400;">New products &amp; platforms</span></h2>
<p><a href="https://www.dowjones.com/" target="_blank" rel="noopener"><b>Dow Jones</b></a><span style="font-weight: 400;"> launched the </span><a href="https://leadershipinstitute.wsj.com/geopoliticalrisk/" target="_blank" rel="noopener"><b>WSJ Geopolitical Risk Council</b></a><span style="font-weight: 400;">, an invitation-only executive community to support corporate decision-makers as they prepare for geopolitical risks.</span></p>
<p><span style="font-weight: 400;">Communications compliance platform </span><a href="https://www.casepoint.com/" target="_blank" rel="noopener"><b>Casepoint</b></a><span style="font-weight: 400;"> announced new agents for Casepoint IQ, including the Relevance Determination Agent and the Issue Coding Agent, the first of a set of forthcoming specialized AI agents for government, legal and compliance teams.</span></p>
<p><span style="font-weight: 400;">Sustainability intelligence platform </span><a href="https://www.sweep.net/" target="_blank" rel="noopener"><b>Sweep</b></a><span style="font-weight: 400;"> unveiled an expansion of its agentic AI Sweepy, which allows it to run sustainability workflows across compliance, risk and performance reporting.</span></p>
<p><a href="https://www.cloudrangecyber.com/" target="_blank" rel="noopener"><b>Cloud Range</b></a><span style="font-weight: 400;">, a cyber readiness and validation system, launched AI Validation Range and Cloud Range AI Readiness Framework to put AI models and agents through SOC scenarios and cyberattacks in a contained environment before making them operational.</span></p>
<p><span style="font-weight: 400;">Infrastructure management provider </span><a href="https://www.meshiq.com/" target="_blank" rel="noopener"><b>meshIQ</b></a><span style="font-weight: 400;"> released AgentIQ, which can govern AI agents across enterprises and give visibility and control over agents as well as create audit records.</span></p>
<p><a href="https://www.bizora.ai/" target="_blank" rel="noopener"><b>Bizora</b></a><span style="font-weight: 400;">, a tax research platform, launched Audit Research, which answers questions across PCAOB, AICPA, GASB standards and the GAO Yellow Book with citations to source text.</span></p>
<p><span style="font-weight: 400;">AI insurance claims platform </span><a href="https://claraanalytics.com/" target="_blank" rel="noopener"><b>CLARA Analytics</b></a><span style="font-weight: 400;"> launched Agentic Intelligence for its CLARAty.ai system to examine insurance claim files and surface litigation risk and potential fraud.</span></p>
<h2><span style="font-weight: 400;">Personnel</span></h2>
<p><a href="https://www.ethyca.com/" target="_blank" rel="noopener"><b>Ethyca</b></a><span style="font-weight: 400;">, a runtime governance company, appointed Danny Weitzner, the Obama Administration’s deputy CTO for internet policy, as chief strategy officer.</span></p>
<p><span style="font-weight: 400;">Fintech and financial services consultant </span><a href="https://www.fsvector.com/" target="_blank" rel="noopener"><b>FS</b> <b>Vector</b></a><span style="font-weight: 400;"> named Mike Santoro to the newly created role of chief growth officer.</span></p>
<h2><span style="font-weight: 400;">Partnerships &amp; integrations</span></h2>
<p><span style="font-weight: 400;">GRC software provider </span><a href="https://onspring.com/" target="_blank" rel="noopener"><b>Onspring</b></a><span style="font-weight: 400;"> announced an integration with </span><a href="https://www.trustero.com/" target="_blank" rel="noopener"><b>Trustero</b></a><span style="font-weight: 400;">, an AI compliance platform, bringing autonomous AI for evidence management and control testing into the Onspring platform.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/grc-business-roundup-dow-jones-casepoint-onspring-ethyca-sweep-more/">GRC Business Roundup: Dow Jones, Casepoint, Onspring, Ethyca, Sweep &#038; More</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Only 10% of Companies Could Live up to UK Bill’s Hack Reporting Rules</title>
		<link>https://www.corporatecomplianceinsights.com/news-roundup-september-25-2026/</link>
		
		<dc:creator><![CDATA[Staff and Wire Reports]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 14:54:28 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Cyber Risk]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68446</guid>

					<description><![CDATA[<p>Plus: Almost 9 in 10 companies don’t fully assess third parties</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-september-25-2026/">Only 10% of Companies Could Live up to UK Bill’s Hack Reporting Rules</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h6><i><span style="font-weight: 400;">CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: </span></i><a href="mailto:editor@corporatecomplianceinsights.com"><b><i>editor@corporatecomplianceinsights.com</i></b></a><i><span style="font-weight: 400;">.</span></i></h6>
<h2><span style="font-weight: 400;">Just 1 in 10 UK organizations could meet proposed breach reporting standards</span></h2>
<p><span style="font-weight: 400;">Only 10% of UK enterprises are confident they could meet cyber breach reporting deadlines proposed in a bill working its way through Parliament, according to a </span><a href="https://vinciworks.com/blog/24-hour-cyber-breach-reporting/" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by VinciWorks.</span></p>
<p><span style="font-weight: 400;">The survey of 156 IT, </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> and security professionals found just one in 10 organizations were confident they could meet the </span><a href="https://www.gov.uk/government/collections/cyber-security-and-resilience-bill" target="_blank" rel="noopener"><b>Cyber Security and Resilience Bill</b></a><span style="font-weight: 400;">’s 24-hour and 72-hour breach reporting deadlines, a duty that would fall on managed service providers and data centers.</span></p>
<p><span style="font-weight: 400;">The bill is in a House of Lords committee, and if it becomes law, in-scope organizations would be required to send an initial notification to their regulator within 24 hours of becoming aware of a reportable </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-news/" target="_blank" rel="noopener"><b>cyber</b></a><span style="font-weight: 400;"> incident followed by a full report in 72 hours.  </span></p>
<p><span style="font-weight: 400;">Most organizations surveyed believe they could meet the deadlines, but that </span><a href="https://www.corporatecomplianceinsights.com/cybersecurity-tabletop-exercises/" target="_blank" rel="noopener"><b>confidence hasn’t been tested yet</b></a><span style="font-weight: 400;">. Almost two-fifths (38%) of compliance and security professionals said they would meet the 24-hour and 72-hour deadlines in theory, but had never actually tested the process. Just over a quarter (26%) said they weren’t sure if they could meet those reporting requirements, while 17% said they were working toward it. About 9% admitted they could not currently meet the deadlines.</span></p>
<p><span style="font-weight: 400;">“</span><a href="https://www.corporatecomplianceinsights.com/inside-turkey-new-cybersecurity-regulation/" target="_blank" rel="noopener"><b>Cyber incidents</b></a><span style="font-weight: 400;"> rarely happen in office hours, on a good day, with everyone available,” Nick Henderson-Mayo, head of compliance at VinciWorks, said in a statement. “An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes.”</span></p>
<p><span style="font-weight: 400;">The survey also found that 68% of organizations said they were fairly to very concerned about cyber attacks disrupting business, and 51% reported staff must complete cybersecurity </span><a href="https://www.corporatecomplianceinsights.com/tag/training/" target="_blank" rel="noopener"><b>training</b></a><span style="font-weight: 400;"> once a year.</span></p>
<h2><span style="font-weight: 400;">Vast majority of companies don’t assess all third parties</span></h2>
<p><span style="font-weight: 400;">Nearly nine in 10 companies don’t look into every third party they work with in a time when not doing such examinations is the most perilous, according to a </span><a href="https://drata.com/blog/state-of-tprm-2026" target="_blank" rel="noopener"><b>survey</b></a><span style="font-weight: 400;"> by security software provider Drata. </span></p>
<p><span style="font-weight: 400;">In a survey of 309 IT and security leaders and practitioners in the US, UK and Canada, 87% reported that they don’t assess all third parties, and staffing and tools play a big role.</span></p>
<p><span style="font-weight: 400;">More than three-quarters (78%) reported they have limited capacity to complete </span><a href="https://www.corporatecomplianceinsights.com/relationship-owner-goals-why-half-your-tprm-red-flags-stay-hidden/" target="_blank" rel="noopener"><b>thorough assessments on all third parties</b></a><span style="font-weight: 400;">. About half (49%) rated their ability to cover all third parties as less than good. That limited capacity comes as 85% reported that their companies experienced at least one third-party incident in the past 12 months, and 75% said their concern about </span><a href="https://www.corporatecomplianceinsights.com/rethink-benchmark-tprm/" target="_blank" rel="noopener"><b>third-party risks</b></a><span style="font-weight: 400;"> has increased over the past two years.</span></p>
<p><span style="font-weight: 400;">A large proportion of the third-party assessment issues for companies is a lack of people, with 59% citing insufficient staff as the greatest obstacle to effective </span><a href="https://www.corporatecomplianceinsights.com/tag/third-party-risk/" target="_blank" rel="noopener"><b>third-party risk management (TPRM)</b></a><span style="font-weight: 400;">. The survey also revealed a contradiction. More than two-thirds (69%) expanded their third-party risk management teams but are still having trouble keeping up, while only 11% said they plan to add to their headcount in the next year, despite insufficient staffing ranking as the most significant barrier to examining risk with third parties.</span></p>
<p><span style="font-weight: 400;">Evidence highlights that more people and assessments help companies manage third-party risks. Of the companies that experienced six or more third-party incidents, 90% agreed that people or tool limits are constraining their assessments, compared to 60% that had no third-party incidents.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/news-roundup-september-25-2026/">Only 10% of Companies Could Live up to UK Bill’s Hack Reporting Rules</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>With New EU EmpCo Rules, Greenwashing Moves From Reputation Risk to Compliance Risk</title>
		<link>https://www.corporatecomplianceinsights.com/with-empco-greenwashing-moves-from-reputation-risk-ccompliance-risk/</link>
		
		<dc:creator><![CDATA[Andreas Pyrcek]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 11:00:34 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Corporate Communication]]></category>
		<category><![CDATA[ESG]]></category>
		<guid isPermaLink="false">https://www.corporatecomplianceinsights.com/?p=68434</guid>

					<description><![CDATA[<p>Seemingly innocuous wording could bring fines under new EU framework</p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/with-empco-greenwashing-moves-from-reputation-risk-ccompliance-risk/">With New EU EmpCo Rules, Greenwashing Moves From Reputation Risk to Compliance Risk</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="intro-text">
<p><i><span style="font-weight: 400;">The EU’s new anti-greenwashing rules turn sustainability claims into a matter of legal exposure, governance and corporate reputation. Compliance leaders should ensure that environment-related communications can be substantiated before they reach the market, writes Andreas Pyrcek of EY Germany.</span></i></p>
</div>
<p><span style="font-weight: 400;">For years, the European sustainability debate has centered primarily on reporting. Companies have focused on what they must disclose, which </span><a href="https://www.corporatecomplianceinsights.com/tag/data-analytics/" target="_blank" rel="noopener"><b>data</b></a><span style="font-weight: 400;"> they must collect and how evolving requirements may affect their </span><a href="https://www.corporatecomplianceinsights.com/tag/esg/" target="_blank" rel="noopener"><b>ESG</b></a><span style="font-weight: 400;"> reporting obligations. The EU’s </span><a href="https://eur-lex.europa.eu/eli/dir/2024/825/oj/eng" target="_blank" rel="noopener"><b>Empowering Consumers for the Green Transition Directive</b></a><span style="font-weight: 400;">, commonly referred to as EmpCo or sometimes ECGT, takes a different approach. Rather than determining what companies must report, it regulates what businesses may say to consumers about the environmental and social characteristics of their products, services and operations.</span></p>
<p><span style="font-weight: 400;">EmpCo amends the </span><a href="https://commission.europa.eu/law/law-topic/consumer-protection-law/unfair-commercial-practices-and-price-indication/unfair-commercial-practices-directive_en" target="_blank" rel="noopener"><b>EU Unfair Commercial Practices Directive and the Consumer Rights Directive</b></a><span style="font-weight: 400;">. Its provisions are intended to address misleading environmental claims, unreliable sustainability labels and other practices that may prevent consumers from making informed purchasing decisions. EU member states were required to transpose the directive by March 27, 2026, and must apply their national implementing rules from Sept. 27, 2026.</span></p>
<p><span style="font-weight: 400;">This makes EmpCo a landmark in European sustainability regulation, introduces explicit anti-greenwashing rules into EU consumer law and identifies specific sustainability practices that may either be prohibited outright or assessed as misleading based on their context. </span></p>
<p><span style="font-weight: 400;">Greenwashing has become more than a reputational concern; it is now a defined legal and </span><a href="https://www.corporatecomplianceinsights.com/compliance-news/" target="_blank" rel="noopener"><b>compliance</b></a><span style="font-weight: 400;"> risk in the European Union.</span></p>
<h2><span style="font-weight: 400;">What the new rules require</span></h2>
<p><span style="font-weight: 400;">EmpCo does not impose one general obligation to obtain advance approval for every environmental statement. Instead, it combines specific prohibitions with broader rules governing misleading commercial practices.</span></p>
<p><span style="font-weight: 400;">Some practices will be added to the </span><a href="https://eur-lex.europa.eu/EN/legal-content/summary/unfair-commercial-practices.html" target="_blank" rel="noopener"><b>EU’s “blacklist”</b></a><span style="font-weight: 400;"> of commercial practices considered unfair in all circumstances. Other claims will be assessed case-by-case, including whether they contain false information, deceive the average consumer or materially influence a purchasing decision.</span></p>
<p><span style="font-weight: 400;">One of the most significant changes concerns generic environmental claims. Broad expressions like “environmentally friendly,” “eco-friendly,” “green,” “climate-friendly,” “sustainable” or “responsible” may no longer be used merely because a company can point to some positive environmental activity. A generic environmental claim must be supported by recognized excellent environmental performance that is relevant to the claim. Alternatively, the company must clearly and prominently specify the claim on the same medium, such as the packaging, advertisement or online sales interface.</span></p>
<p><span style="font-weight: 400;">This distinction is important. A statement like “climate-friendly packaging” may be regarded as a generic environmental claim. A more specific statement explaining that all energy used to produce the packaging comes from renewable sources may fall outside that particular prohibition, although it must still be accurate and must comply with the general rules against misleading practices.</span></p>
<p><span style="font-weight: 400;">EmpCo also prohibits companies from presenting an environmental benefit relating to only one aspect of a product as though it applied to the entire product or business. A company should not, for example, create the impression that a whole product consists of recycled material if only its packaging does. Similarly, an isolated sustainability initiative cannot be used to imply that the company’s overall operations meet the same environmental standard.</span></p>
<p><span style="font-weight: 400;">Further, under the directive, companies may not claim that a product has a neutral, reduced or positive impact on the environment in terms of greenhouse-gas emissions when that claim is based on offsetting. The EU legislature considers such statements misleading because they can create the impression that the product itself, or its production and supply, does not have an adverse climate impact.</span></p>
<p><span style="font-weight: 400;">Companies may continue to communicate investments in environmental initiatives or carbon-credit projects, provided that the information is presented in a way that is not misleading. The critical requirement is that those investments must not be used to make a prohibited product-level neutrality claim.</span></p>
<p><span style="font-weight: 400;">And where companies compare products based on environmental or social characteristics, durability, repairability or recyclability, consumers must be given information about the comparison method, the products and suppliers included and the measures used to keep the comparison current.</span></p>
<p><span style="font-weight: 400;">The objective is to ensure that comparisons are based on products serving the same function, use a common methodology and address material and verifiable characteristics.</span></p>
<p><span style="font-weight: 400;">This means that claims like “greener,” “more sustainable” or “better for the environment” require more than an internal assessment. Companies must understand what is being compared, whether the methodology is consistent and whether the comparison remains accurate over time.</span></p>
<p><span style="font-weight: 400;">These requirements are all meaningful for compliance teams. A statement does not need to be entirely false to create legal </span><a href="https://www.corporatecomplianceinsights.com/risk-news/" target="_blank" rel="noopener"><b>risk</b></a><span style="font-weight: 400;">. A factually correct statement may still be misleading if its presentation, scope or context creates an inaccurate overall impression. And the rules around climate neutrality create a significant review obligation for businesses that have integrated neutrality language into packaging, product descriptions, websites or advertising campaigns. Compliance teams will need to distinguish carefully between communications about corporate climate initiatives and claims about the environmental impact of a specific product.</span></p>
<div class="cci-promo"><center><div  class="jeg_postblock_12 jeg_postblock jeg_module_hook jeg_pagination_disable jeg_col_2o3 jnews_module_68434_6_6abe870105097   " data-unique="jnews_module_68434_6_6abe870105097">
					
					<div class="jeg_block_container">
                    
                    <div class="jeg_posts jeg_load_more_flag"><article class="jeg_post jeg_pl_lg_card format-standard">
                    <div class="jeg_inner_post">
                        <div class="jeg_thumb">
                            
                            <a href="https://www.corporatecomplianceinsights.com/greenwashing-reckoning-is-not-about-marketing/" aria-label="Read article: The Greenwashing Reckoning Isn’t About Marketing"><div class="thumbnail-container animate-lazy  size-500 "><img loading="lazy" decoding="async" width="750" height="375" src="https://www.corporatecomplianceinsights.com/wp-content/themes/jnews/assets/img/jeg-empty.png" class="attachment-jnews-750x375 size-jnews-750x375 lazyload wp-post-image" alt="greenwashing painting white bottle concept" sizes="(max-width: 750px) 100vw, 750px" data-src="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/greenwashing-painting-white-bottle-concept-750x375.jpg" data-srcset="https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/greenwashing-painting-white-bottle-concept-750x375.jpg 750w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/greenwashing-painting-white-bottle-concept-360x180.jpg 360w, https://www.corporatecomplianceinsights.com/wp-content/uploads/2026/08/greenwashing-painting-white-bottle-concept-1140x570.jpg 1140w" data-sizes="auto" data-expand="700" /></div></a>
                        </div>
                        <div class="jeg_postblock_content">
                            <div class="jeg_post_category">
                                <span>
                                    <a href="https://www.corporatecomplianceinsights.com/category/governance/">Governance</a>
                                </span>
                            </div>
                            <h3 class="jeg_post_title">
                                <a href="https://www.corporatecomplianceinsights.com/greenwashing-reckoning-is-not-about-marketing/">The Greenwashing Reckoning Isn’t About Marketing</a>
                            </h3>
                            <div class="jeg_post_meta"><div class="jeg_meta_author"><span class="by">by</span> <a href="https://www.corporatecomplianceinsights.com/author/sandhya-sabapathy/">Sandhya Sabapathy</a></div><div class="jeg_meta_date"><a href="https://www.corporatecomplianceinsights.com/greenwashing-reckoning-is-not-about-marketing/"><i class="fa fa-clock-o"></i> August 24, 2026</a></div></div>
                                <div class="jeg_post_excerpt">
                                    <p>A bold public target and a cautious financial model can contradict each other inside the same annual report</p>
                                    <a href="https://www.corporatecomplianceinsights.com/greenwashing-reckoning-is-not-about-marketing/" class="jeg_readmore">Read more<span class="screen-reader-text">Details</span></a>
                                </div>
                        </div>
                    </div>
                </article></div>
                    <div class='module-overlay'>
				    <div class='preloader_type preloader_dot'>
				        <div class="module-preloader jeg_preloader dot">
				            <span></span><span></span><span></span>
				        </div>
				        <div class="module-preloader jeg_preloader circle">
				            <div class="jnews_preloader_circle_outer">
				                <div class="jnews_preloader_circle_inner"></div>
				            </div>
				        </div>
				        <div class="module-preloader jeg_preloader square">
				            <div class="jeg_square">
				                <div class="jeg_square_inner"></div>
				            </div>
				        </div>
				    </div>
				</div>
                </div>
                <div class="jeg_block_navigation">
                    <div class='navigation_overlay'><div class='module-preloader jeg_preloader'><span></span><span></span><span></span></div></div>
                    
                    
                </div>
					
					<script>var jnews_module_68434_6_6abe870105097 = {"header_icon":"","first_title":"","second_title":"","url":"","header_type":"heading_6","header_background":"","header_secondary_background":"","header_text_color":"","header_line_color":"","header_accent_color":"","header_filter_category":"","header_filter_author":"","header_filter_tag":"","header_filter_cpt_ctl-stories":"","header_filter_cpt_wpm-testimonial-category":"","header_filter_text":"All","sticky_post":false,"sticky_post_filter":false,"post_type":"post","content_type":"all","sponsor":false,"number_post":"1","post_offset":0,"unique_content":"disable","include_post":"68005","included_only":"true","exclude_post":"","include_category":"","exclude_category":"","include_author":"","include_tag":"","exclude_tag":"","exclude_visited_post":false,"ctl-stories":"","wpm-testimonial-category":"","sort_by":"latest","date_format":"default","date_format_custom":"Y\/m\/d","excerpt_length":"45","excerpt_ellipsis":"","force_normal_image_load":"","main_custom_image_size":"default","pagination_mode":"disable","pagination_nextprev_showtext":"","pagination_number_post":4,"pagination_scroll_limit":0,"ads_type":"disable","ads_position":1,"ads_random":"","ads_image":"","ads_image_tablet":"","ads_image_phone":"","ads_image_link":"","ads_image_alt":"","ads_image_new_tab":"","google_publisher_id":"","google_slot_id":"","google_desktop":"auto","google_tab":"auto","google_phone":"auto","content":"","ads_bottom_text":"","el_id":"","el_class":"","scheme":"","column_width":"auto","title_color":"","accent_color":"","alt_color":"","excerpt_color":"","block_background":"","css":"","paged":1,"column_class":"jeg_col_2o3","class":"jnews_block_12"};</script>
				</div></center></div>
<h2><span style="font-weight: 400;">Future promises &amp; sustainability labeling</span></h2>
<p><span style="font-weight: 400;">EmpCo also addresses forward-looking claims, including commitments to achieve climate neutrality, net zero or another environmental objective by a future date.</span></p>
<p><span style="font-weight: 400;">Such claims may be considered misleading if they are not supported by clear, objective, publicly available and verifiable commitments and targets. A company must have a detailed and realistic implementation plan showing how the targets will be achieved, including the allocation of resources. Progress must also be verified regularly by an independent third-party expert whose findings are made available to consumers.</span></p>
<p><span style="font-weight: 400;">This requirement has implications well beyond marketing. An environmental promise may depend on investment decisions, technological developments, operational transformation and emissions reductions across several business units. Examine not only the wording of the claim but also whether the organization has a sufficiently credible plan, ownership structure, resources and monitoring process to support it. A corporate ambition should not be presented to the market as an achievable commitment if the underlying organization has not established a realistic route to delivery.</span></p>
<p><span style="font-weight: 400;">EmpCo also tightens the rules governing sustainability labels. Companies will generally be prohibited from displaying a sustainability label unless it is based on a certification scheme or has been established by a public authority.</span></p>
<p><span style="font-weight: 400;">A qualifying certification scheme must satisfy minimum standards of transparency and credibility. This includes objective monitoring by a competent third party that is independent of both the scheme owner and the company using the label. The relevant conditions of the scheme must also be publicly available.</span></p>
<p><span style="font-weight: 400;">This provision is particularly relevant to proprietary green labels and self-created environmental symbols. A company cannot establish its own sustainability mark and use it to imply independent environmental quality if the mark is not supported by a qualifying certification framework.</span></p>
<p><span style="font-weight: 400;">Review not only the wording of written sustainability claims but also seals, icons, logos, color schemes and other visual devices that may communicate an environmental message.</span></p>
<h2><span style="font-weight: 400;">Legal consequences extend beyond regulatory fines</span></h2>
<p><span style="font-weight: 400;">The consequences of noncompliance arise through the consumer-protection and unfair-commercial-practices regimes into which EmpCo is integrated. The precise procedures and </span><a href="https://www.corporatecomplianceinsights.com/tag/sanctions/" target="_blank" rel="noopener"><b>sanctions</b></a><span style="font-weight: 400;"> depend on national implementing law, but companies can face orders to stop using a claim, removal or amendment of advertisements and packaging, claims brought by competitors or consumer organizations, consumer redress and financial penalties.</span></p>
<p><span style="font-weight: 400;">For widespread infringements with an EU cross-border dimension, the existing </span><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019L2161" target="_blank" rel="noopener"><b>European consumer-law enforcement framework</b></a><span style="font-weight: 400;"> requires member states to provide for maximum fines of at least 4% of the trader’s annual turnover in the member states concerned. Where turnover information is unavailable, national law must provide for a maximum fine of at least €2 million. The application of sanctions in an individual case remains subject to the relevant national implementation and enforcement process.</span></p>
<p><span style="font-weight: 400;">The economic exposure may extend well beyond a fine. A prohibited claim may require a company to stop a campaign, revise websites and sales materials, change product packaging or defend litigation across several jurisdictions. Misleading claims may also create disputes with customers and business partners and increase scrutiny of related sustainability disclosures.</span></p>
<p><span style="font-weight: 400;">Reputational consequences can be even more severe. Greenwashing allegations directly challenge the credibility of the organization. If a company cannot support a public sustainability promise, stakeholders may question not only the claim itself but also the reliability of management, the effectiveness of internal controls and the integrity of the broader sustainability strategy.</span></p>
<h2><span style="font-weight: 400;">Why EmpCo belongs on the compliance agenda</span></h2>
<p><span style="font-weight: 400;">Sustainability communications are often developed across marketing, corporate affairs, product management, legal and sustainability teams. Without a common </span><a href="https://www.corporatecomplianceinsights.com/governance-news/" target="_blank" rel="noopener"><b>governance</b></a><span style="font-weight: 400;"> framework, no single function may have a complete view of the claims being made, the evidence supporting them or the assumptions on which they depend.</span></p>
<p><span style="font-weight: 400;">That is where compliance can add value.</span></p>
<p><span style="font-weight: 400;">Compliance does not need to become the technical owner of every environmental data point. It should, however, help establish the governance through which claims are identified, risk-assessed, substantiated, approved and monitored. The relevant control framework should cover statements on packaging, websites, advertising, social media, investor-facing materials and other consumer communications.</span></p>
<p><span style="font-weight: 400;">Before publication, the organization should be able to demonstrate what evidence supports a claim, whether the wording accurately reflects the scope of that evidence, who has approved it and how changes in data or business performance will be monitored. Higher-risk claims, particularly climate-neutrality statements, future targets, generic environmental language and comparative claims, should receive enhanced scrutiny.</span></p>
<p><span style="font-weight: 400;">This is not merely a documentation exercise. It is a question of whether the company can defend the claim if it is challenged by a regulator, consumer organization, competitor or court.</span></p>
<p><span style="font-weight: 400;">EmpCo marks an important development for compliance and </span><a href="https://www.corporatecomplianceinsights.com/ethics-news/" target="_blank" rel="noopener"><b>ethics</b></a><span style="font-weight: 400;"> leaders. It brings sustainability communication firmly into the legal accountability framework. Environmental claims can no longer be treated as aspirational messaging that sits outside the company’s compliance management system.</span></p>
<p><span style="font-weight: 400;">The central question is no longer simply whether a sustainability statement is attractive or broadly consistent with corporate ambitions. The question is whether it is legally permissible, factually supportable and capable of withstanding external scrutiny.</span></p>
<p>The post <a href="https://www.corporatecomplianceinsights.com/with-empco-greenwashing-moves-from-reputation-risk-ccompliance-risk/">With New EU EmpCo Rules, Greenwashing Moves From Reputation Risk to Compliance Risk</a> appeared first on <a href="https://www.corporatecomplianceinsights.com">Corporate Compliance Insights</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>