
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>News &amp; Press</title>
<link>https://members.agrc.org/news/default.asp</link>
<description><![CDATA[     Read about recent events, essential information and the latest AGRC community news! ]]></description>
<lastBuildDate>Thu, 23 Jul 2026 07:45:39 GMT</lastBuildDate>
<pubDate>Wed, 22 Jul 2026 11:26:00 GMT</pubDate>
<copyright>Copyright &#xA9; 2026 Association of Governance, Risk &amp; Compliance</copyright>
<atom:link href="https://members.agrc.org/news/news_rss.asp?cat=16983" rel="self" type="application/rss+xml"></atom:link>
<item>
<title>Data Centres: European Cybersecurity and Technology Law</title>
<link>https://members.agrc.org/news/news.asp?id=731637</link>
<guid>https://members.agrc.org/news/news.asp?id=731637</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Cybersecurity and operational resilience requirements are converging quickly – with real consequences for governance, incident response, and customer expectations.&nbsp;The European Union places particular focus on the second Network and Information Security Directive (“NIS2”), the Directive on the Resilience of Critical Entities (“CER”), as well as the Digital Operational Resilience Act (“DORA”).</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">NIS2 minimum cybersecurity standards</strong></span></span></p><ul class="wp-block-list" style="letter-spacing: normal; box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; list-style: none; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">EU harmonisation</strong>: NIS2 introduces a new minimum harmonisation of cybersecurity. EU member states are at various implementation stages.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">ICT risk-management</strong>: The Directive requires data centres to adopt an all-hazards approach and sound ICT risk-management. This includes registration requirements, incident reporting to the supervisory authority (24h, 72h, 1 month) and supply chain management.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Personal liability of management</strong>: The management body must undertake mandatory NIS2 training and will be personally liable for its implementation.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Data centre specific</strong>: As part of the digital infrastructure, data centres are subject to higher standards under the EU Commission implementing standards for cybersecurity risk-management measures. They are also subject to the main establishment rule.</span></li></ul><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">DORA’s direct and indirect effects</strong></span></span></p><ul class="wp-block-list" style="letter-spacing: normal; box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; list-style: none; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Evolving beyond outsourcing</strong>: Requirements for services to regulated customers in the EU have increased for ICT third-party risk, specifically in the financial and insurance sectors.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Contractual uplift</strong>: Customers are required to uplift their agreements to the new DORA standards, including specific termination and audit rights, business contingency measures, incident support, specific forms of penetration testing (TLPT) and significant subcontractor, and supply chain requirements.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Direct DORA oversight</strong>: ICT services which supply a majority of the EU financial sector have been designated as critical under the oversight framework. Currently 19 suppliers are under the direct supervision of the ...</span></li></ul><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/data-centres-european-cybersecurity-and-technology-law/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 22 Jul 2026 12:26:00 GMT</pubDate>
</item>
<item>
<title>False Positives and System Inefficiencies: Why More Controls Are Producing Less Insight</title>
<link>https://members.agrc.org/news/news.asp?id=731635</link>
<guid>https://members.agrc.org/news/news.asp?id=731635</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Modern organisations possess more data, control frameworks, governance procedures and compliance technologies than at any previous point in business history. Yet many executives argue that they have less visibility into the risks and opportunities that genuinely matter. The result is what might be called the “false positive economy”, where companies devote growing resources to investigating alerts, exceptions and reporting requirements that ultimately prove insignificant, while genuinely material threats remain obscured by administrative noise.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This challenge has become particularly acute across the UK and the European Union. Organisations face expanding sustainability reporting obligations under the Corporate Sustainability Reporting Directive (CSRD), increasing use of AI-enabled monitoring systems, more sophisticated anti-money laundering controls and heightened governance expectations. Ironically, the problem is no longer a shortage of information. It is the ability to separate meaningful signals from a flood of data, metrics and automated warnings. In many cases, complexity itself has become a source of risk rather than a solution to it.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">When Compliance Becomes Noise</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Compliance functions have expanded dramatically in response to growing regulatory scrutiny. Many organisations have responded by introducing increasingly complex control frameworks, generating larger numbers of alerts, exceptions and review processes. In some cases, internal audit, risk and compliance teams perform overlapping activities, creating duplication rather than greater protection.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This has created a compliance paradox. The more controls an organisation implements, the harder it can become to identify genuinely important risks. Employees often spend significant amounts of time demonstrating compliance instead of improving processes, serving customers or addressing operational weaknesses.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem is particularly evident in financial crime monitoring and anti-money laundering (AML) screening. Banks routinely investigate thousands of transactions flagged by automated systems, yet industry research suggests that the overwhelming majority of AML alerts are false positives. A legitimate cross-border payment or a customer whose name resembles that of a sanctioned individual may trigger an unnecessary investigation. Similar challenges arise in third-party supplier due diligence, where repeated low-risk alerts can overwhelm review teams.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">False positives consume resources, increase costs and contribute to decision fatigue. When staff are faced with a constant stream of warnings, there is a greater risk that genuinely significant threats will be overlooked amid the noise</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The ESG Data Deluge</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The arrival of new European sustainability reporting requirements has triggered an unprecedented expansion in ESG data collection. Under the CSRD and the European Sustainability Reporting Standards (ESRS), organisations must gather information across environmental, social and governance topics, often extending deep into their supply chains. This has led to a surge in reporting obligations, supplier questionnaires and assurance activities.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Many companies now collect hundreds or even thousands of ESG data points. Yet despite this abundance of information, they often struggle to answer fundamental strategic questions. Which sustainability risks are most significant? Which initiatives genuinely improve business performance? Where is long-term value being created ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/false-positives-and-system-inefficiencies-why-more-controls-are-producing-less-insight/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 22 Jul 2026 12:22:00 GMT</pubDate>
</item>
<item>
<title>Expert Interview with Shea Brown: The Next Frontier of AI Compliance </title>
<link>https://members.agrc.org/news/news.asp?id=730749</link>
<guid>https://members.agrc.org/news/news.asp?id=730749</guid>
<description><![CDATA[<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica; font-size: 14px;"><strong>The Next Frontier of AI Compliance:&nbsp;</strong></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica; font-size: 14px;"><strong>An interview with Shea Brown, Founder and CEO of BABL AI, USA</strong></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica; font-size: 14px;"><strong>&nbsp;</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica;"><span style="font-size: 13px;">The Association of Governance, Risk and Compliance (AGRC) and US-based leading algorithmic auditing firm BABL AI launched a Level 3&nbsp;<a href="https://agrc.org/product/certificate-in-ai-risk-management-compliance/" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">Certificate in AI Risk Management and Compliance</span></a>&nbsp;in March 2026. It is aimed at governance, risk, compliance, internal audit, legal and policy professionals who need to identify, categorise and control AI risk in their organisations. The Compliance Digest discussed AGRC’s ground-breaking certificate with BABL AI Founder and CEO Shea Brown, and its significance at a time when regulatory scrutiny is intensifying, accountability expectations are rising, and the cost of getting AI governance wrong is higher than ever.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">One thing you have spoken about quite directly is the way generative AI is now being used to produce the very policies that are supposed to govern it. Someone can ask a model to draft a compliance policy in 30 seconds. How does the certificate inoculate professionals against producing that kind of paper-tiger documentation, and what tells you in an audit that a policy was actually written by a human who understood it?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This is something we see constantly in practice. The temptation is huge. The EU AI Act is here, you have a deadline, and a generative model will give you a 40-page policy in two minutes. The problem is that those policies are typically generic. They use the right words, they reference the right articles, but they have no relationship to how that organisation actually builds, deploys or governs its AI.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">When we audit, you can tell almost immediately. The policy talks about controls that do not exist anywhere else in the organisation. It refers to a risk register nobody can show you. It references roles that have not been assigned to a real person. It says the AI governance committee will do something, and that committee has never met.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">What we have built into the curriculum of this certificate is essentially a defensive posture against this. We do not start by writing the policy. We start with inventory. Where does AI actually live in your organisation? What does it touch? How is the risk distributed? Only when you have done that work, does a policy have anything real to attach itself to. And then the policy is short, it is specific, and it points at things you can verify.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The other piece is that we teach people to read a policy the way an auditor would. So, if you do choose to use a generative tool as a starting point, which is fine, you have the skills to interrogate what came out and ask whether any of it is actually true for your business.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Many of the professionals taking this certificate sit inside the business they are auditing. They are internal risk and compliance, they are internal audit, they have a manager who has a manager who has a target to ship the AI product. What does the certificate give them when leadership wants to green light a system they have concerns about?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This is one of the most under-discussed problems in AI assurance. The independence question is taken very seriously in financial audit, less so in AI right now, and the people we partner with through AGRC are very often the ones absorbing the pressure.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The honest answer is that no certificate can give somebody the political cover they need to disagree with a senior leader. What we can do, and what we have tried to do, is give them the language and the evidence base to make that pushback defensible. So when a head of product wants to ship a tool that scores CV applications, the person sitting across the table from them should be able to say: here are the specific risks I have identified, here are the controls we do not yet have, here are the regulations this could trigger, and here is the precedent from other organisations that have got this wrong. That is a very different conversation from ‘I have a bad feeling about this’.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">We also spend time on documentation. If you raise a concern, it needs to be recorded. If your concern is overridden, that override needs to be recorded. Because the question that comes up six or 12 or 18 months later, when something has gone wrong, is who knew what and when. A professional who has done this certificate should be very clear on creating that paper trail without it becoming adversarial.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The longer answer is that organisations are going to need to think about this structurally. Where does AI risk reporting sit? Who does it report to? Does it report through the business it is auditing? These are questions a mature organisation needs to solve, and our learners are often the ones who have to start asking them.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Most current AI governance still assumes a system that makes a recommendation and a human who acts on it. With agentic AI now moving into production, that is changing. Systems are taking actions. They are sending emails, executing transactions, opening tickets. What specifically about the curriculum prepares people for that shift?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This is the frontier and I will be honest – we are all working it out as we go. The fundamental shift is that with a recommender system, you can put a human in the loop and that human is the last line of defence. With an agent, the action has already happened by the time you find out about it. Your controls have to move upstream.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">What we have tried to do in the curriculum is force people to think in terms of what we call the CIDA model: Context, Input, Decision, Action. Every AI system, agentic or not, sits in a context, takes an input, makes a decision, and produces some kind of action. With agents, the action piece is no longer mediated by a human, so the controls have to shift to constraining what actions the system is permitted to take, what tools it has access to, and what guardrails sit between its decision and its execution.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">For a compliance professional, that means asking different questions. It is not ‘did the human review the recommendation’. It is what is the agent allowed to do without authorisation, what is it not allowed to do under any circumstances, and how do you verify in production that those constraints are holding. Logging becomes critical. Reversibility becomes critical. The blast radius of a single agent action becomes a thing you have to assess before deployment.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The certificate does not turn anyone into a red teamer overnight. What it does is give people a vocabulary for these conversations and a structured way of thinking about where the controls need to live. We are going to keep iterating on this material because the technology is moving faster than the regulations are.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Across most organisations, employees are now using AI tools that compliance and IT have never approved. ChatGPT, Claude, Copilot, and dozens of others. The official policy says one thing and the actual behaviour is another. Does the certificate give professionals a practical playbook for surfacing and governing the AI they do not yet know about?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Yes, and this is probably the single most common gap we see when we walk into an organisation. Leadership says ‘we do not really use AI yet’, but then you spend 10 minutes talking to the people who actually do the work and you discover that everyone in marketing is using a generative tool for first drafts, the HR team is summarising CVs with ChatGPT, finance is using something to format reports, and nobody has told anyone.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The first thing we teach is that this is normal and it is not going to be solved by a policy that says you cannot. People will use these tools because they are useful and because their job depends on getting things done. The intervention has to be different.&nbsp;</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">You need a discovery exercise. We give people a method for doing a structured walkthrough of every business function in the organisation and surfacing what is actually in use. You would be amazed how much shows up when you ask the right questions.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The second thing is risk triage. Most shadow AI use is probably low risk. Somebody using a tool to draft an email is not the same as somebody piping customer data into an unvetted model. You have to be able to separate those quickly, because if you treat them the same way you will lose the trust of the business, and they will just stop telling you what they are doing.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The third thing is creating sanctioned paths. People will respect a policy that says here are the tools you are allowed to use, here is how to ask for a new one, here is the answer turnaround. They will not respect a policy that just says no. The certificate is very practical on this point ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/the-next-frontier-of-ai-compliance-an-interview-with-shea-brown-founder-and-ceo-of-babl-ai-usa/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 8 Jul 2026 07:54:00 GMT</pubDate>
</item>
<item>
<title>From Disclosure to Due Diligence: ESG’s Compliance Problem</title>
<link>https://members.agrc.org/news/news.asp?id=730704</link>
<guid>https://members.agrc.org/news/news.asp?id=730704</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The End of ESG as a Reporting Exercise</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Environmental, Social, and Governance (ESG) is a framework used by investors and businesses to evaluate an organisation’s sustainability and ethical impact and assess long-term resilience, corporate accountability and societal value. The first wave of ESG was built on a simple idea: disclose more information and better business behaviour would follow.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Companies responded enthusiastically. Sustainability reports grew longer and more sophisticated, often running to dozens of pages packed with metrics, targets and commitments. ESG ratings agencies multiplied, while frameworks such as the Global Reporting Initiative (GRI), ISSB standards and the EU’s Corporate Sustainability Reporting Directive (CSRD) expanded the reporting landscape. Recent research suggests that corporate sustainability reports now average more than 80 pages in length, highlighting the sheer scale of the disclosure boom.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">However, a growing number of regulators, investors and governance experts are now questioning whether this flood of information has delivered meaningful change. Many organisations have become highly skilled at measuring and communicating ESG performance without necessarily reducing emissions, improving labour standards or strengthening governance. This phenomenon might be called “ESG inflation” – the accumulation of ever more disclosures, data points and narratives without equivalent real-world intervention.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Transparency remains valuable. However, reporting a problem is not the same as solving it. As ESG enters its next phase, stakeholders increasingly want evidence of action, not simply evidence of disclosure.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Why Regulators No Longer Trust Disclosure Alone</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The regulatory mood around ESG has now hardened considerably. A series of high-profile greenwashing controversies convinced policymakers that glossy sustainability reports and ambitious net-zero pledges are not enough. Regulators increasingly want companies to substantiate claims with verifiable evidence and demonstrate that risks are being actively managed rather than merely described.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In the UK, the Financial Conduct Authority’s (FCA) anti-greenwashing rule, which came into force in 2024, requires sustainability-related claims to be fair, clear and not misleading. Firms must be able to support marketing statements with credible evidence, creating a much higher compliance bar than in the past.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Meanwhile, the European Union is pushing even further. The CSRD expands reporting obligations, while the Corporate Sustainability Due Diligence Directive (CSDDD) shifts attention towards the environmental and human rights impacts companies create through their operations and value chains. Businesses are expected to identify, prevent and address adverse impacts, not simply disclose them.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The direction of travel is unmistakable. Regulators are moving away from asking companies to “Tell us what you know” and towards demanding, “Prove what you have done”. In modern ESG compliance, evidence increasingly matters more than aspiration.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Supply Chain Problem Nobody Has Solved</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Most ESG risks do not originate in corporate headquarters. They lurk deep within global supply chains, often several steps removed from the companies ultimately held accountable for them. A manufacturer may know its direct suppliers well, yet have little visibility into the subcontractors, labour providers and raw-material producers further down the chain.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">This creates a significant compliance challenge. Concerns over forced labour in regions linked to cotton production, allegations of human-rights abuses in parts of the mining sector and environmental damage associated with critical minerals have demonstrated how risks can emerge far beyond Tier 1 suppliers. Many firms can produce detailed emissions data for their offices and factories, yet struggle to identify ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/from-disclosure-to-due-diligence-esgs-compliance-problem/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Tue, 7 Jul 2026 17:09:00 GMT</pubDate>
</item>
<item>
<title>Dealing With Non-Financial Misconduct in Governance, Risk and Compliance</title>
<link>https://members.agrc.org/news/news.asp?id=730563</link>
<guid>https://members.agrc.org/news/news.asp?id=730563</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Hidden Risk Ledger</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In today’s highly scrutinised business environment, some of the most damaging corporate risks do not appear on a balance sheet. Non-financial misconduct—ranging from bullying, harassment and discrimination to abuses of power, retaliation against whistleblowers, and the misuse of personal data—can quietly erode organisational culture, undermine trust and inflict lasting reputational harm. As expectations of corporate accountability continue to rise, effectively identifying, managing and preventing such behaviour has become a critical challenge for governance, risk and compliance (GRC) professionals.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Worryingly, many firms still treat these issues as HR problems rather than governance risks, but that approach is becoming increasingly dangerous. A toxic manager who intimidates staff may never appear on a balance sheet, yet the resulting loss of talent, reduced innovation, legal claims and reputational damage can cost millions. The downfall of hedge fund manager Crispin Odey highlighted how allegations of inappropriate behaviour and weak governance can rapidly become a major regulatory and business issue.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Investors, employees and customers are also changing how they judge organisations. Corporate culture now influences recruitment, retention and brand value. In many sectors, a reputation for ethical leadership has become a competitive advantage. Conversely, workplace scandals can spread globally within hours through social media and have devastating effects.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Now, regulators are responding. The UK Financial Conduct Authority (FCA) has expanded its focus on non-financial misconduct, making clear that bullying, harassment and similar conduct can represent serious regulatory concerns. Across Europe, regulators are increasingly linking workplace culture to governance, risk management and organisational resilience. Behaviour is no longer viewed as a soft issue. It is becoming a measurable risk category in modern GRC.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Preventing Misconduct Before It Starts</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In many cases, organisations still rely heavily on policies, training programmes and annual declarations to tackle misconduct. Yet some of the biggest corporate scandals have occurred in businesses with extensive compliance frameworks. The reality is that rules alone rarely change behaviour. Increasingly, leading firms are treating culture as an operating system rather than a compliance programme. Their focus is shifting towards prevention rather than punishment. One important development is the growing use of psychological safety. Employees who feel comfortable raising concerns are more likely to report emerging problems before they become major risks.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Leadership behaviour is equally critical. Staff pay far more attention to what senior managers do than what a policy document says. As a result, many organisations now assess conduct alongside performance when making promotion and remuneration decisions. Several major UK financial institutions have strengthened links between behavioural standards and bonus awards under regulatory conduct frameworks.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Technology is also providing new ways to monitor organisational health. Employee sentiment surveys, anonymous feedback systems and workplace analytics can reveal early signs of ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/dealing-with-non-financial-misconduct-in-governance-risk-and-compliance/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Mon, 6 Jul 2026 10:22:00 GMT</pubDate>
</item>
<item>
<title>Addressing The Skills Gap in Modern Compliance Teams</title>
<link>https://members.agrc.org/news/news.asp?id=730562</link>
<guid>https://members.agrc.org/news/news.asp?id=730562</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Skills Gap Nobody Saw Coming</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">For years, executives complained about regulatory overload. Today, many UK and EU firms face a more dangerous problem: too few people can actually interpret fast-changing rules and apply them inside digitally driven businesses. The arrival of the EU AI Act, tougher scrutiny around ESG disclosures and rising concern over financial crime have transformed compliance from an administrative function into a strategic capability. Post-Brexit regulatory divergence has added further complexity for companies operating across borders. Increasingly, firms need compliance professionals who understand data governance, AI systems, operational resilience and commercial risk in equal measure. Modern compliance teams are no longer rulekeepers working quietly in the background. They are becoming risk architects shaping how organisations innovate, grow and protect trust.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Why Traditional Compliance Hiring Is Breaking Down</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">For decades, compliance recruitment focused heavily on legal qualifications, sector experience and regulatory certifications. That model now looks increasingly outdated. Modern compliance risks rarely sit neatly inside one discipline. A single investigation may involve AI governance, cybersecurity failures, behavioural analytics, sanctions exposure and supply-chain ethics at the same time. Yet many organisations still recruit as though it were 2015.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Large banks and fintech firms are now competing directly with technology companies for data analysts, AI specialists and digital investigators. HSBC and Barclays, for example, have expanded recruitment for financial crime technology and data-focused compliance roles as fraud monitoring becomes more automated and predictive. Meanwhile, Revolut and Monzo increasingly seek professionals who can interpret regulation while understanding machine-learning systems and digital customer behaviour.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem is cultural as well as technical. Younger professionals often view compliance as procedural and bureaucratic rather than innovative. That perception matters in a labour market where ambitious graduates are drawn towards cybersecurity, AI and digital strategy roles.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In fact, the real shortage is not compliance professionals, but adaptive thinkers who can combine regulation, technology and communication skills while operating comfortably in uncertain, fast-changing environments.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Rise of the Hybrid Compliance Professional</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The compliance officer of 2026 looks very different from the rule-focused specialist of a decade ago. Modern firms increasingly want hybrid thinkers who can interpret data, understand behavioural risk, manage AI governance and communicate commercial realities to senior leadership. Certifications still matter, but they are no longer reliable indicators of ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;"><strong>Read the<a href="https://thecompliancedigest.com/addressing-the-skills-gap-in-modern-compliance-teams/"> full article</a> in The Compliance Digest!</strong></span></p>]]></description>
<pubDate>Mon, 6 Jul 2026 10:05:00 GMT</pubDate>
</item>
<item>
<title>AI and Defence: The Role of Lawyers?</title>
<link>https://members.agrc.org/news/news.asp?id=730080</link>
<guid>https://members.agrc.org/news/news.asp?id=730080</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica;"><span style="font-size: 13px;"><a target="_blank" href="https://www.chathamhouse.org/" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">Chatham House</span></a>&nbsp;can’t have known that their event&nbsp;<span style="color: #0d654c;"><a target="_blank" href="https://www.chathamhouse.org/events/all/standard-event/ai-and-national-security-whos-really-control" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; transition: 0.15s;">“AI and National Security: Who’s Really in Control?”</a>&nbsp;</span>would take place as Anthropic both launched Claude Mythos and attended talks at the White House to resolve their dispute with the US Government, but it does show their foresight that this is the crucial topic in defence at the moment. As panellist General Sir Richard Barrons, a Senior Consulting Fellow at the Royal Institute of International Affairs put it:</span></span></p><blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow" style="letter-spacing: normal; box-sizing: border-box; margin: 0px 0px 25px; padding: 10px 10px 10px 20px; line-height: 1.8rem; order: 0; font-style: italic; border-color: #ef233c; overflow-wrap: break-word; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><p class="wp-block-paragraph" style="box-sizing: border-box; margin-bottom: 0.6em; padding: 0px; line-height: 1.8rem; order: 0; font-size: 1.3em;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">“<em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">AI unleashed will destroy civilisations</strong></em>“.</span></span></p></blockquote><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">How then, the event considered, should AI be leashed and to whom?</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Lawyers in the (metaphorical) battle-space</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">For our clients and for us as lawyers, the question is existential in different senses. How should government contract with the private sector, and the private sector within itself, in these extraordinary times and with this extraordinary technology, to achieve commercial certainty and preserve national security? Get it wrong and damages will be the least important measure of loss.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">On the night, much was made of the power of the new technology. The General cited the US 1000+ missions a day in Iran, the “digital kill-map” in action. AI selects targets and deploys crewed, uncrewed and autonomous systems – the last with the power to bomb and shoot without human intervention. As well as its application at the sharp end, AI will organise logistics, such as supply and casualty evacuation. He warned of a military establishment, conservative in its views without the mindset to adopt to the new way of fighting in principle, let alone in practice as billions and billions of dollars worth of investment transform the technology at an almost literally unbelievable pace. And even if ‘our’ soldiers, sailors and airmen get on top of this new kit, “the enemy gets a vote”. All this is being deployed in an oppositional environment where ‘they’ will use ‘their’ AI to destroy ‘ours’ and ‘us’: and of course vice-versa: a digital arms race on an unprecedented scale.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Quis custodiet ipsos milites?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">His faith is in humanity, in statesmanship to pull us and our systems back from the brink. Query is any other model of governance possible? John Thornhill, Innovation Editor at the FT, and recently back from Silicon Valley set out that in US tech circles there is no ‘debate’ as such but a multiplicity of views: few believe that AI companies should be a “handmaiden of the state” but just how many competing approaches to governance and ethical use questions can the eco-system sustain? Dr Yasmin Afina, a Researcher in Security and Technology in UNIDIR’s Security and Technology Programme, talked of the work being done outside the EU/UK/US, where government drives much more of the R&amp;D so query the extent of role of the private sector in governance. At the same time, these governments are looking for reliable commercial partners whose delivery against political constraints will be certain and predictable.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Thornhill referenced the so called ‘6th Domain’: the first five are land, sea, air, space and cyber; and now there is the interface between private and public sectors in the field of AI and tech innovation. It is Ukraine’s success in this last that is enabling it to launch drone strikes 500 miles into Russia and why it is becoming a prime partner in contracting with European and Gulf states to augment their security in aspects of drone warfare.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">How do commercial lawyers adopt to all of this? We should not look to nation states to impose any sort of effective governance. Article 22 of the London Naval Treaty of 1930, purported to prevent submarines sinking merchant vessels without first securing the safety of passengers and crew. Germany acceded in 1936. Doenitz was put on trial at Nuremburg for breaking this rule only for Allied sub-mariners to warn they would appear as witnesses for the defence, so roundly ignored was the law in practice. Any treaty on AI will surely go the same way. It’s been said in relation to this tech there are thousands of Oppenheimers, only now without two superpowers with a mutual interest in a terrifying status-quo to keep the World from burning.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Docusign to delivery</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Our role is therefore to help find the balance between the state’s interest in control and the suppliers in both sales and development. Those interests are not always in competition: it is in the interests of Ukraine, for example, that it is seen as a dependable partner who to the extent it restricts use of its technology does so on a rational and consistent basis. Lawyers may help government and industry to produce and work to a framework – which must in turn be rapidly adaptable to keep pace with the tech – that means that agreements can be rapidly ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/ai-and-defence-the-role-of-lawyers/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Fri, 26 Jun 2026 11:55:00 GMT</pubDate>
</item>
<item>
<title>At a Glance: Cybersecurity Best Practices in the UK</title>
<link>https://members.agrc.org/news/news.asp?id=730079</link>
<guid>https://members.agrc.org/news/news.asp?id=730079</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><span style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><em style="letter-spacing: normal; box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Recommended additional protections</span></em></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Do the authorities recommend additional cybersecurity protections beyond what is mandated by law?</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Enhanced cybersecurity protections, beyond those mandated by law, are recommended by numerous authorities, with guidance notes and advice widely available.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The National Cyber Security Centre is an organisation within the UK government that provides advice and support for the public and private sector to promote cybersecurity. The central pillar of its advice is&nbsp;<a target="_blank" href="https://www.ncsc.gov.uk/cyberaware/home" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">‘Cyber Aware’</span></a>, which provides a set of guidelines built around six key actions. In addition, it also maintains&nbsp;<a target="_blank" href="https://www.ncsc.gov.uk/collection/10-steps" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">‘10 Steps to Cyber Security’</span></a>, guidance aimed at medium-sized to large organisations that employ cybersecurity professionals, and a&nbsp;<a target="_blank" href="https://www.ncsc.gov.uk/collection/small-business-guide" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">‘Small Business Guide: Cyber Security’</span></a>. On top of this, the Centre publishes various focused guides on passwords, ransomware, phishing, devices, personal data malware, operational security and the cloud.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Other authorities also recommend enhanced protections. The Global Cyber Alliance, Action Fraud, the Information Commissioner’s Office (ICO) and the Financial Conduct Authority (FCA) are among other authorities that also recommend protections beyond those strictly mandated by law.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">While industry and regulatory codes or guidance do not constitute protections mandated by law, failure to follow such codes may still give rise to adverse consequences. For example, the ICO states, in its Regulatory Action Policy, that failure to follow an approved or statutory code of conduct is an aggravating factor when it considers sanctions. On 9 December 2022, the UK government published a Code of Practice for app developers and app store operators, which sets out practical steps designed to protect users. Parts of the Code were developed in conjunction with the ICO, and certain principles contained therein are mandated through existing legislation.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;">Government incentives</em></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">How does the government incentivise organisations to improve their cybersecurity?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">On 19 January 2022, the government published the policy paper titled “2022 Cyber Security Incentives and Regulation Review”. In that it noted that it was for the market to incentivise better security practices for organisations, but recognised that those incentives (eg, consumer pressure and competitive advantage) have not yet formed effectively. To mitigate this, the government planned to take a more interventionalist approach through guidance, further market participation and strengthening of UK cyber legislation. In June 2023, the government published a research paper titled <span style="color: #0d654c;">‘<a target="_blank" href="https://researchbriefings.files.parliament.uk/documents/CBP-9821/CBP-9821.pdf" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; transition: 0.15s;">Cybersecurity in the UK<a target="_blank" href="https://www.ncsc.gov.uk/cyberaware/home" rel="noreferrer noopener" style="color: #ef233c; caret-color: #000000; font-family: Helvetica; font-size: 13px; letter-spacing: normal; box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; transition: 0.15s;"><span style="color: #0d654c;">’</span></a></a></span>, which in part supplements the 2022 policy paper.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">At the CyberUK 2024 conference, the UK government unveiled initiatives as part of its £2.6 billion National Cyber Strategy to enhance artificial intelligence (AI) model security, aiming to set a global benchmark against hacking and sabotage. These efforts, emphasising the secure development and operation of AI, were supported by research and a public consultation on AI cybersecurity from May to July 2024, highlighting the government’s commitment to leading in cyber technology and ensuring AI’s safe utilisation.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The UK government continues to incentivise organisations to improve cybersecurity through commercial drivers, financial support, and practical resources.</span></span></p><ul class="wp-block-list" style="letter-spacing: normal; box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; list-style: none; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;">Commercial incentives: mandatory Cyber Essentials certification for government contracts and requirements from major private-sector suppliers encourage compliance with baseline security standards.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;">Financial support and grants: programmes such as Cyber Local, CyberASAP funding for academic startups, and expert security reviews for small and medium-sized enterprises (SMEs) help protect intellectual property and strengthen resilience.</span></li><li style="box-sizing: border-box; margin: 0px 0px 1rem 15px; padding: 0px; line-height: 1.8rem; order: 0; list-style: outside;"><span style="font-family: Helvetica; font-size: 13px;">Direct resources: services from the National Cyber Security Centre, such as Active Cyber Defence, the Cyber Advisor scheme, and tools like Exercise in a Box and the Cyber Essentials Readiness Tool, allow organisations to test and improve their cyber defences.</span></li></ul><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The Cyber Security and Resilience (Network and Information Systems) Bill will expand regulatory obligations for Managed Service Providers and critical suppliers, including stricter incident reporting and potential fines. While regulatory in nature, these developments effectively incentivise investment in cybersecurity by linking compliance with legal accountability.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;">Industry standards and codes of practice</em></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Identify and outline the main industry standards and codes of practice promoting cybersecurity. Where can these be accessed?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica;"><span style="font-size: 13px;">The National Cyber Security Centre publishes a guide dealing with issues such as cyber defence, threat and ransomware. The Centre’s <span style="color: #0d654c;">“<a target="_blank" href="https://www.ncsc.gov.uk/files/2021-10-steps-to-cyber-security-infographic.pdf" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; transition: 0.15s;">10 Steps to Cyber Security</a>” </span>sets out a number of key areas for medium-sized to large organisations to ensure that technology, systems and information are protected against cyberattacks. In doing so the guide emphasises the need to take a risk-based and proactive approach to cybersecurity ...</span></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/at-a-glance-cybersecurity-best-practices-in-united-kingdom/">full article </a>in The Compliance Digest!</strong></p>]]></description>
<pubDate>Fri, 26 Jun 2026 11:40:00 GMT</pubDate>
</item>
<item>
<title>Expert Interview with Sarah Corley: The Compliance Cost Challenge</title>
<link>https://members.agrc.org/news/news.asp?id=729989</link>
<guid>https://members.agrc.org/news/news.asp?id=729989</guid>
<description><![CDATA[<p style="margin-bottom: 2px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 16px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-size: 14px; font-family: Helvetica;"><b>The Compliance Cost Challenge:&nbsp;</b></span><b style="font-family: Helvetica; font-size: 14px; letter-spacing: 0.3px;">An Interview with Sarah Corley, CEO,&nbsp;Alliance of Digital Finance and Fintech Associations (Alliance DFA),&nbsp;UK</b></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal; min-height: 15px;"><span style="font-family: Helvetica;">&nbsp;</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal; min-height: 15px;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;"><strong>Compliance costs remain a significant challenge for smaller fintechs and start-ups, particularly as regulatory expectations continue to increase globally. Where are smaller firms feeling the greatest pressure today, and what practical steps could regulators and industry bodies take to make compliance more proportionate and accessible for smaller firms?</strong></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">What our members consistently tell us is that compliance itself is not the problem. The challenge is that compliance obligations are not always proportionate to the risks involved, and the cost of meeting those obligations can be significant for smaller providers. A start-up and a large financial institution may ultimately be required to meet many of the same regulatory requirements, but they do not have the same resources, specialist expertise, or operational capacity to do so.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Smaller fintechs understand the importance of requirements such as Know Your Customer (KYC), Know Your Business (KYB), Anti-Money Laundering (AML), and Countering the Financing of Terrorism (CFT) requirements and recognise the role they play in protecting consumers, maintaining trust in financial systems, and supporting broader economic stability.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">There is a perception that innovation and regulation are in tension. Innovation seeks to create new products, services, and business models, while regulation seeks to ensure safety, security, and consumer protection. Both are necessary. The challenge is not whether regulation should exist, but how it can be designed and implemented in a way that enables innovation while effectively managing risk.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">One of the biggest pressures we hear about is regulatory complexity. Financial Service Providers (FSPs) are often navigating requirements from multiple authorities, such as central banks, securities regulators, telecommunications regulators, and data protection agencies. While each regulator has an important role to play, the cumulative effect can be overlapping requirements, duplication, and uncertainty. For firms operating across multiple markets, these challenges are amplified by differences in regulatory approaches between jurisdictions.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Our members also regularly highlight the pace of regulatory change. Keeping track of new requirements, interpreting legal language, and implementing changes can require significant investment in compliance and legal expertise. For smaller FSPs, these costs can have a direct impact on growth and scalability.</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">We also see examples of over-compliance. Many FSPs take a more conservative approach than regulators may actually require because they are concerned about regulatory scrutiny, penalties, or the risk of losing their licence. While understandable, this can increase compliance costs without necessarily delivering better outcomes.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">From our perspective, the answer is not less regulation but smarter regulation. Regulators can help by adopting proportionate, risk-based approaches that reflect the size, complexity, and risk profile of FSPs and activities. Greater coordination between regulatory authorities can also help reduce fragmentation and conflicting requirements.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Clearer guidance is equally important. Many requirements are still communicated through lengthy legal documents that can be difficult for smaller FSPs to interpret. Increasingly, regulators should be looking at ways to make requirements easier to understand and integrate into compliance systems, including more standardised and machine-readable approaches.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Industry associations also have an important role to play by:</span></p>
<ul>
<li style="margin: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Representing the perspectives of the industry, including the smaller financial service providers, during regulatory consultations.&nbsp;</span></li>
<li style="margin: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Translating complex regulatory requirements into practical guidance and training for industry participants.&nbsp;</span></li>
<li style="margin: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Identifying common compliance challenges and presenting evidence-based recommendations to regulators.&nbsp;</span></li>
<li style="margin: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Facilitating collaboration between firms to explore shared approaches, including RegTech solutions and shared compliance utilities that can reduce costs while maintaining robust standards.&nbsp;</span></li>
</ul>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Ultimately, effective regulation and innovation should not be seen as competing objectives. The goal should be regulatory frameworks that protect consumers and financial systems while remaining practical, proportionate, and accessible for FSPs of all sizes.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong><span style="font-family: Helvetica;">To what extent can technology-driven solutions, such as shared utilities, digital identity frameworks, or RegTech partnerships, help reduce the compliance burden on smaller fintech firms while improving risk management standards?</span></strong></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">We believe technology has a critical role to play in making compliance more efficient, more effective, and ultimately more accessible for smaller FSPs.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">One of the recurring themes we hear from members is that a great deal of compliance activity is duplicated across the industry. Multiple FSPs are often conducting similar customer due diligence, sanctions screening, and verification processes independently. Shared utilities have the potential to reduce this duplication, allowing FSPs to access trusted information while maintaining appropriate oversight and accountability.</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">&nbsp;</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">Digital identity frameworks are particularly important. In markets where robust digital identity infrastructure exists, onboarding can be faster, more secure, and significantly less costly. This benefits not only providers but also consumers, especially those who may previously have faced barriers to accessing formal financial services.</span></p>
<p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;">RegTech is also changing the equation for smaller providers. Historically, sophisticated compliance capabilities were often only available to larger institutions with substantial compliance teams. Today, cloud-based solutions, software-as-a-service models, and specialist providers are enabling smaller FSPs to access ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><span style="font-family: Helvetica;"><strong>&nbsp;</strong></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the<a href="https://thecompliancedigest.com/the-compliance-cost-challenge-an-interview-with-sarah-corley-ceo-alliance-of-digital-finance-and-fintech-associations-alliance-dfa-uk/"> full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Thu, 25 Jun 2026 15:03:00 GMT</pubDate>
</item>
<item>
<title>Using Artificial Intelligence, With or Without Compliance</title>
<link>https://members.agrc.org/news/news.asp?id=729639</link>
<guid>https://members.agrc.org/news/news.asp?id=729639</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">A Dangerous Assumption</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Artificial intelligence (AI) has undoubtedly moved beyond the experimental stage. Businesses are no longer merely testing AI tools in isolated departments. Instead, they are embedding AI into banking, healthcare, retail, logistics, law, education and government services. The arrival of agentic AI — systems capable of acting autonomously and making decisions without constant human supervision — has accelerated this transformation dramatically. Yet amid the excitement, a dangerous assumption continues to grow: that organisations can adopt AI successfully without investing equally in AI compliance, governance and ethical oversight. That assumption may yet become one of the most expensive business mistakes of the decade.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Ignoring Responsibilities</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The issue is no longer whether AI creates value. It clearly does. The real question is whether organisations can continue benefiting from AI if they ignore the responsibilities that come with it. Increasingly, regulators, economists and business leaders are reaching the same conclusion: AI without compliance will eventually undermine resilience, damage sustainability and erode public trust. The stark truth is that the evidence is already emerging.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In banking, AI systems are now assessing creditworthiness, identifying fraud, reviewing legal documents and even validating payments. Global investment in AI banking technology is expected to rise sharply throughout 2026 and beyond. However, many institutions remain stuck in pilot phases because they cannot prove that their AI systems are trustworthy, transparent or properly governed. Worse still, AI-enabled fraud is rising rapidly. Criminals are using generative AI to create convincing scams, synthetic identities and highly personalised phishing attacks. Organisations that deploy AI without strengthening compliance frameworks are effectively escalating an arms race they may not be prepared to control.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Introducing Agentic AI</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The risks become even greater with agentic AI. Traditional AI systems mainly generated outputs or recommendations. Agentic AI systems can independently execute tasks, access tools, make decisions and interact with external systems. In practical terms, this means an AI assistant could autonomously approve transactions, alter workflows or communicate with customers without direct human approval. That level of autonomy introduces a completely different category of risk.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Imagine a financial institution deploying an autonomous AI onboarding system to improve efficiency. Without sufficient governance, the system may unintentionally discriminate against applicants from particular demographic groups because its training data reflected historical bias. Alternatively, an autonomous compliance-monitoring tool might incorrectly flag legitimate customer activity as suspicious, freezing accounts and damaging customer trust. In more severe cases, a poorly governed AI agent could make operational decisions that violate regulations entirely. Already we can see that the consequences are not just theoretical. Regulators across Europe are preparing for precisely these scenarios.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">What Will Regulation Do?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The EU AI Act represents one of the most ambitious attempts anywhere in the world to regulate AI responsibly. From August 2026, organisations using high-risk AI systems in areas such as lending, employment, healthcare and anti-money laundering will face strict obligations surrounding transparency, accountability, human oversight and risk management. Failure to comply could lead to penalties reaching millions of euros. More importantly, businesses that cannot demonstrate responsible AI practices may lose ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/using-artificial-intelligence-with-or-without-compliance/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Mon, 22 Jun 2026 08:34:00 GMT</pubDate>
</item>
<item>
<title>Insights from the FCA’s Latest Customer Due Diligence Review</title>
<link>https://members.agrc.org/news/news.asp?id=729638</link>
<guid>https://members.agrc.org/news/news.asp?id=729638</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">United Kingdom</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">On 8 April, the Financial Conduct Authority (FCA) published&nbsp;<span style="color: #0d654c;"><a target="_blank" href="https://www.fca.org.uk/publications/good-and-poor-practice/firms-customer-due-diligence-processes-and-controls-our-findings" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; transition: 0.15s;">a report</a>&nbsp;</span>focusing on due diligence controls within a wide range of regulated firms. As usual, it found a mix of good and sensible practices alongside things some firms could do better.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Thematic reviews of specific aspects of financial crime prevention controls are not new, but regulatory expectations and regulated firms’ sophistication around knowing your customer for anti-money laundering (AML) purposes have come a very long way. No longer do we have the old “tick box” approach that seemed simply to require new customers to provide “one item from List A and one from List B” in order to open a bank account or sign up for another requlated product or service.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">As AML legislation has evolved to make it clear that firms must know not only who their customer is, but also why they are doing business with the firm and how they are going to fund it, regulatory expectations have perhaps moved even faster.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The basis of the review</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Financial crime prevention is always a hot topic with the FCA and is a priority in&nbsp;<a target="_blank" href="https://www.fca.org.uk/publications/good-and-poor-practice/firms-customer-due-diligence-processes-and-controls-our-findings" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">its 2025-30 strategy</span></a>. So in 2025 it carried out a broadly scoped review of the approach regulated firms take to their policies, procedures, processes, compliance monitoring and audit in relation to customer due diligence (CDD) and enhanced due diligence (EDD). Its review covered firms in the asset management, crowdfunding, wholesale banking, contracts for difference and non-bank lending sectors, but the FCA stressed that all authorised and registered firms should read its conclusions and assess their own practices against the recommendations.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">While CDD and EDD are concepts enshrined in AML legislation, the FCA was not solely reviewing them against the requirements of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (the MLRs), but also against its own requirements in the Financial Crime Guide and Senior Management Arrangements, Systems and Controls Sourcebook, the Government approved Joint Money Laundering Steering Group guidance and the international guidance from the Financial Action Task Force. It has always been clear that firms should be looking across the entire range of guidance applicable to their business.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">When the FCA finds good practice, this is invariably behaviour that goes beyond what is required by law and regulation, and shows that firms have applied the spirit of the requirements in a way that practically relates to their business. Inherently, the risks of the customer base and products of some industry sectors are higher than others, and the FCA will want to see that firms have assessed this in their business wide risk assessment that the MLRs require as well as in their more granular assessments of each customer.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Policies and procedures</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Understanding what CDD entails and requires, and identifying when and how to carry out EDD are fundamental to MLR compliance. Except in very limited circumstances, CDD must be conducted on all customers, and is the mechanism that allows firms to understand who the customer is, who owns and controls corporate customers, what their business is and how they pay for the transactions they undertake with or through the regulated firm.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">EDD is a top-up of this, required in a range of defined scenarios that present a higher inherent risk of money laundering, including when a firm is dealing with a politically exposed person (<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">PEP</strong>). It has long been established that deciding to carry out EDD on all customers, even where no high-risk trigger is present, is not the way to comply with the MLRs – firms must take a risk-based approach, which involves applying the requirements of the MLRs sensibly to their business. A key part of evidencing this approach is having policies and procedures that clearly explain why the firm has taken certain decisions – for instance there may reasonably be factors that means that a customer or transaction that one firm would regard as requiring EDD would be less alarming to another.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The FCA reviewed the policies and procedures of the firms in its sample. Most firms had procedures (it would be hard to evidence compliance with the MLRs without them), but what distinguished the good ones from those that could be improved was their detail and practicality.&nbsp;</span></span><span style="font-family: Helvetica; font-size: 13px;">The best ones did clearly distinguish between ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/insights-from-the-fcas-latest-customer-due-diligence-review/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Mon, 22 Jun 2026 08:29:00 GMT</pubDate>
</item>
<item>
<title>Compliance Team: Capacity v. Burnout</title>
<link>https://members.agrc.org/news/news.asp?id=729429</link>
<guid>https://members.agrc.org/news/news.asp?id=729429</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Hidden Corporate Exhaustion Crisis</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Compliance departments were once quiet oversight functions operating largely in the background. Today, they are expected to police AI ethics, ESG disclosures, sanctions compliance, cyber risk, workplace conduct and anti-money laundering controls simultaneously. Across the EU and UK, new regulatory frameworks including the EU AI Act, the Corporate Sustainability Reporting Directive and the FCA’s Consumer Duty rules are dramatically expanding corporate reporting obligations. Compliance teams are therefore becoming operational shock absorbers for organisational anxiety, absorbing pressure from regulators, investors and reputational fears alike. The central problem is no longer simply legal compliance. It is whether businesses can continue increasing oversight demands without exhausting the people responsible for enforcing them daily.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">When the Watchdogs Collapse</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Compliance departments are increasingly suffering from exhaustion, attrition and cognitive overload precisely when regulators expect more vigilance than ever before. In many banks, fintech firms and multinational companies, compliance has evolved into an “always-on” function involving sanctions monitoring, cyber reporting, ESG disclosure checks and anti-money laundering investigations around the clock. Following the Wirecard collapse, European regulators intensified scrutiny across Germany and the wider EU, dramatically increasing reporting expectations for already stretched teams. Meanwhile, UK banks facing large anti-money laundering penalties have expanded monitoring operations without always increasing staffing proportionately.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The result is a dangerous secondary risk. Experienced compliance officers are leaving because the role now combines policing, legal interpretation, reputational defence and crisis management simultaneously. Recruitment firms in London, Frankfurt and Dublin increasingly report shortages of senior compliance specialists willing to remain in permanently high-pressure environments. Burnout itself is therefore becoming a governance threat. The people responsible for organisational resilience are becoming psychologically fragile, raising the likelihood of missed warnings, poor judgement and silent internal failures.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Endless Alert Machine</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern compliance departments operate inside a permanent storm of alerts, dashboards and reporting updates. Employees receive constant notifications covering conduct rules, cyber threats, ESG disclosures, sanctions risks and whistleblowing obligations. Yet compliance teams increasingly spend more time filtering noise than identifying genuine danger. The concept of “alert fatigue”, originally associated with healthcare and cybersecurity, now defines large parts of corporate governance.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">After Brexit, many firms found themselves managing overlapping EU and UK reporting frameworks simultaneously, particularly around sustainability disclosures and financial services regulation. Anti-money laundering systems provide another example. Banks routinely process enormous volumes of automated transaction alerts, many involving low-risk or entirely legitimate behaviour. Third-party monitoring platforms also generate excessive false positives that consume time without necessarily improving judgement.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The deeper problem is psychological rather than technical. Excessive compliance signals can weaken ethical thinking because employees begin responding mechanically instead of critically. HR compliance systems often add further procedural overload through endless training modules and policy confirmations. Increasingly, businesses are becoming procedurally defensive rather than strategically intelligent, mistaking activity for awareness and documentation for genuine organisational resilience ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/compliance-team-capacity-v-burnout/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 17 Jun 2026 13:46:00 GMT</pubDate>
</item>
<item>
<title>FCA Consults on Perimeter Guidance for Cryptoasset Activities</title>
<link>https://members.agrc.org/news/news.asp?id=729428</link>
<guid>https://members.agrc.org/news/news.asp?id=729428</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">United Kindom</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">The FCA has published a&nbsp;<a target="_blank" href="https://www.fca.org.uk/publication/consultation/cp26-13.pdf" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">consultation paper</span></a>&nbsp;(CP) on proposed guidance clarifying the scope of the new regulated cryptoasset activities introduced by the&nbsp;<a target="_blank" href="https://www.legislation.gov.uk/uksi/2026/102/contents/made" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">F</span><span style="color: #0d654c;">inancial Services and Markets Act 2000 (Cryptoassets) Regulations 2026</span></a>&nbsp;(the Cryptoasset Regulations). The consultation closes on 3 June 2026.</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">From 25 October 2027, the Cryptoasset Regulations will bring new regulated activities for cryptoassets within the FCA’s regulatory perimeter. Those carrying on these regulated cryptoasset activities by way of business in the UK will require FCA authorisation. Authorised firms will be subject to the rules and guidance in the FCA Handbook (once finalised).</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">The CP sets out the FCA’s proposals to clarify the scope of the new regulated cryptoasset activities and when permission is needed, and should be considered alongside the FCA’s other recent consultations on proposed rules for the new cryptoasset regime.</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">In addition, it aims to provide clarity for firms transitioning from the FCA’s current cryptoasset regime (ie under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017) (MLRs) to the new cryptoasset activities under the Financial Services and Markets Act 2000.</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">The proposed guidance is prepared in a Q&amp;A format in a new chapter in the FCA’s Perimeter Guidance Manual (PERG), at PERG 19. If there are further legislative changes before the finalisation of the proposed guidance, the FCA will reflect the changes, as appropriate.</p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;">Areas covered by the proposed new guidance include when activities are carried on by way of business, territorial scope – when activities are considered to be in the UK, what constitutes new specified investments and new regulated cryptoasset activities together with corresponding exclusions, as well as consequential changes to other parts of PERG including that covering the financial promotion perimeter ...</p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/fca-consults-on-perimeter-guidance-for-cryptoasset-activities/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 17 Jun 2026 13:40:00 GMT</pubDate>
</item>
<item>
<title>The Breakdown Between Policy and Practice</title>
<link>https://members.agrc.org/news/news.asp?id=729427</link>
<guid>https://members.agrc.org/news/news.asp?id=729427</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Modern companies rarely suffer from a shortage of policies. They publish ESG commitments, AI ethics frameworks, wellbeing charters and anti-burnout pledges with impressive regularity. Yet many employees describe workplaces dominated by surveillance software, contradictory targets and relentless productivity pressure. Microsoft’s recent workplace AI research found growing anxiety among staff who fear being left behind by generative AI, even while firms promise healthier working cultures. Meanwhile, return-to-office battles at companies such as Amazon and Apple have exposed the widening gap between official flexibility policies and operational reality. Social media has intensified the problem because businesses now manage reputational crises in public and at speed. The result is a strange corporate contradiction. Organisations talk constantly about ethics, trust and inclusion, but frequently reward behaviour that undermines all three. In modern business, policy often functions as branding rather than behavioural control.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Phantom Rulebook</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern corporations increasingly treat values as branding tools rather than operational rules. Annual reports celebrate sustainability, inclusion and employee wellbeing, yet everyday decisions are often driven by quarterly earnings, shareholder expectations and competitive pressure. Employees quickly learn which policies genuinely matter and which exist mainly for reputational protection.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The recent retreat from ambitious ESG targets illustrates the problem clearly. Several multinational firms, including major oil and consumer brands, have quietly reduced climate commitments as investors demand stronger short-term returns. At the same time, many companies continue advertising themselves as ethical market leaders. Hybrid working has exposed similar contradictions. Businesses publicly praise flexibility, but staff who spend more time in the office frequently receive better visibility, stronger networking opportunities and faster promotion prospects.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This gap between rhetoric and reality creates what management experts increasingly call “compliance theatre”. Formal policies remain highly visible, while unofficial incentives reward entirely different behaviour. Executives may endorse ethical leadership in presentations, but aggressive sales targets and relentless productivity metrics often tell employees another story altogether. When hidden incentives become stronger than formal rules, policy slowly turns into performance art.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">AI Compliance, Human Chaos</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Businesses are racing to introduce AI ethics boards, automated compliance systems and algorithmic oversight tools, yet many are discovering that technology cannot solve deeply human organisational problems. Instead, AI often amplifies them. Companies in logistics, finance and customer service now use algorithms to monitor productivity, predict performance and even assess employee behaviour. Amazon’s warehouse systems, for example, have faced criticism for creating relentless performance pressure through automated monitoring and target-setting.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The rapid spread of generative AI has made governance even harder. Many firms officially restrict the use of public AI tools because of confidentiality risks, yet employees regularly bypass these rules through unofficial “shadow AI” practices to save time or improve output. Samsung famously banned ChatGPT internally after sensitive company data was reportedly uploaded by staff.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The core problem is that AI systems inherit the contradictions already embedded in corporate culture. Leadership teams demand innovation, speed and cost reduction while simultaneously promoting ethical caution and responsible governance. The result is machine-speed decision-making powered by human-level confusion. AI does not remove organisational dysfunction. It scales it rapidly across entire systems before management fully understands the consequences.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Middle Management Dead Zone</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Middle managers increasingly occupy one of the most uncomfortable positions in modern business. Senior leadership demands growth, innovation and tighter cost control, while employees expect flexibility, wellbeing support and realistic workloads. The result is a permanent balancing act between contradictory priorities that cannot easily coexist ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/the-breakdown-between-policy-and-practice/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 17 Jun 2026 13:37:00 GMT</pubDate>
</item>
<item>
<title>UK Introduces Sanctions End‑Use Controls</title>
<link>https://members.agrc.org/news/news.asp?id=729195</link>
<guid>https://members.agrc.org/news/news.asp?id=729195</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica;"><span style="font-size: 13px;">The UK Government has introduced the Sanctions (EU Exit) (Miscellaneous Amendments) Regulations 2026 (the “<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Regulations</strong><em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;">“</em>), which will come into force on 12 May 2026 (see&nbsp;<a target="_blank" href="https://www.legislation.gov.uk/uksi/2026/443/contents/made" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">here</span></a>).</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The Regulations introduce Sanctions End-Use Controls (“<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">SEUC</strong>“), a new licensing requirement which the UK Government can use to impose licensing requirements on exports where it considers there is a high risk of the goods or related technology being diverted to a sanctioned person or destination.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">What are Sanctions End‑Use Controls?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">SEUC are a new licensing requirement for exports to a non-sanctioned third country where the exporter has been informed by the government that there is a risk of ultimate diversion of the goods or related technology, via that route, to a sanctioned destination.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The controls will only apply to goods, and related technology, that are not otherwise subject to export controls. The measures are intended to complement existing “making available” prohibitions by enabling authorities to intervene before goods leave the UK, rather than relying solely on post‑export enforcement.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">When do SEUC apply?</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">SEUC do not introduce blanket licensing requirements. A licence is required only once an exporter has been formally “informed” by the Office of Trade Sanctions Implementation (“<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">OTSI</strong>“) or HM Revenue and Customs (“<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">HMRC</strong>“) that a specific export is at high risk of diversion.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">When being informed, exporters will receive information on how to apply for a licence. If an exporter has been informed, exporting without a licence will be in breach of UK sanctions and the goods in question may be detained at the border, or returned to the exporter, pending a licensing decision ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/uk-introduces-sanctions-end-use-controls/">full article</a> in The Compliance Digest!</strong></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>&nbsp;</strong></p>]]></description>
<pubDate>Fri, 12 Jun 2026 12:19:00 GMT</pubDate>
</item>
<item>
<title>The Danger of Overload: Data Overload vs Effective Decision-Making</title>
<link>https://members.agrc.org/news/news.asp?id=729130</link>
<guid>https://members.agrc.org/news/news.asp?id=729130</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">When Intelligence Becomes Interference</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern businesses are drowning in information while starving for clarity. Across the UK and EU, executives now spend entire days buried in dashboards, performance trackers, ESG reporting updates and AI-generated forecasts, yet many admit decision-making has become slower, not sharper. Harvard Business Review recently described this growing condition as “digital exhaustion”, where constant streams of data create mental overload and declining judgement.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem is not simply volume. It is what that volume does to behaviour. Many organisations have developed a kind of dashboard addiction, measuring everything because technology allows it. Middle managers in retail, logistics and financial services increasingly spend more time interpreting reports than making decisions. Strategic focus disappears beneath layers of KPIs that often duplicate or contradict one another.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The result is “decision latency”. Leaders delay action because they believe another dataset might provide certainty. Businesses become trapped in what some analysts now call “data obesity” by consuming endless information without converting it into meaningful insight or competitive advantage.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Tyranny of Real-Time Everything</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern business culture increasingly treats every fluctuation as an emergency. In many UK and European firms, leaders now monitor live sales dashboards, Slack channels, Teams alerts and customer analytics with the intensity of air-traffic controllers. The result is not sharper strategy but perpetual reaction. Microsoft’s 2024 Work Trend Index found employees are interrupted every two minutes on average by meetings, messages or emails, creating what researchers called a “constant state of digital urgency”.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This obsession with real-time visibility encourages companies to chase short-term movement instead of long-term direction. Retailers frequently adjust pricing several times a day based on hourly consumer behaviour, only to confuse customers and erode trust. Supply-chain businesses across Europe made similar mistakes after pandemic disruptions, overreacting to temporary demand spikes and creating costly inventory imbalances months later.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The deeper problem is psychological. Constant alerts fragment attention and make reflective thinking feel unproductive. Strategic judgement requires periods of silence, distance and slower analysis. Yet many workplaces now treat uninterrupted thinking as suspiciously idle rather than commercially essential.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">From Insight to Noise</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern organisations increasingly suffer from a strange problem. They possess enormous quantities of information yet struggle to identify what actually matters. In many UK and EU businesses, managers are buried beneath automated reports, AI-generated summaries and compliance dashboards that produce endless weak signals but very little clarity. According to Gartner research on digital workplace fatigue, employees now spend substantial parts of their day simply processing internal information flows rather than acting on them.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem becomes even worse when different departments generate competing datasets that each claim to represent the truth. Sales figures contradict customer analytics. ESG reporting metrics clash with operational performance targets. Instead of insight, organisations create internal informational mistrust.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">European firms face additional pressure from expanding disclosure obligations linked to sustainability and governance reporting. Many companies now measure hundreds of indicators simply because regulation demands it, not because those indicators improve decisions.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The smartest businesses are responding by practising what some consultants now call “signal discipline”. They intentionally reduce reporting complexity and focus attention on a handful of decision-critical measures that genuinely influence strategic direction and commercial performance...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/the-danger-of-overload-data-overload-vs-effective-decision-making/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Thu, 11 Jun 2026 14:37:00 GMT</pubDate>
</item>
<item>
<title>Year in Review: Anti-Bribery and Anti-Corruption in United Kingdom</title>
<link>https://members.agrc.org/news/news.asp?id=729126</link>
<guid>https://members.agrc.org/news/news.asp?id=729126</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The year 2025 was marked by significant developments in the UK bribery and corruption landscape, both in enforcement activity and legislative developments. Nevertheless, the future landscape is difficult to chart, with longstanding question marks about UK regulators’ ability to enforce the jurisdiction’s seemingly robust enforcement toolkit.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Historically, the US has been a major partner to the UK in the investigation and enforcement of suspected complex and international bribery and corruption offences. For instance, the UK collaborated with the US in relation in relation to several high-profile DPAs and related enforcement actions in circumstances in which the US Department of Justice and/or the US Securities and Exchange Commission were running parallel or coordinated actions. These include the DPAs reached with Airbus, Standard Bank and Rolls Royce. However, since President Donald Trump’s pause on enforcement of the US Foreign Corrupt Practices Act in February 2025,<sup style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><a target="_blank" href="https://www.lexology.com/library/detail.aspx?g=25e1f386-5bff-4b83-9d96-2d18838bbfe6#footnotes_entry_41426839153893424" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">1</span></a></sup>&nbsp;it is expected that the UK will have to become less reliant on trans-Atlantic corruption investigation collaboration, and attention has turned closer to home. While the UK has looked to improve enforcement collaboration with European nations (indeed, the SFO joined a new International Anti-Corruption Prosecutorial Taskforce with France and Switzerland in March 2025),<span style="color: #0d654c;"><sup style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><a target="_blank" href="https://www.lexology.com/library/detail.aspx?g=25e1f386-5bff-4b83-9d96-2d18838bbfe6#footnotes_entry_6378876828568293" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">2</span></a></sup>&nbsp;</span>its strategic recalibration will necessarily also involve greater introspection and a refocus on domestic enforcement.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The SFO has committed to delivering at least one successful outcome in over 80% of its cases (including at least one conviction or DPA) and securing, by jury or guilty plea, a 60% conviction rate of defendants, both corporate and individuals, in its “Strategic Plan for 2022-2025” paper published in April 2022.<sup style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><a target="_blank" href="https://www.lexology.com/library/detail.aspx?g=25e1f386-5bff-4b83-9d96-2d18838bbfe6#footnotes_entry_48955623970802065" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">3</span></a></sup>&nbsp;In its “SFO Strategy 2024-29” paper published in May 2024,<sup style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><a target="_blank" href="https://www.lexology.com/library/detail.aspx?g=25e1f386-5bff-4b83-9d96-2d18838bbfe6#footnotes_entry_9175153890897049" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">4</span></a></sup>&nbsp;the SFO admitted that “justice delayed is justice denied” and restated its ambition to build compelling cases in shorter timescales.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Nevertheless, the SFO has faltered in its prosecution of individuals. The SFO failed in its prosecution of individuals from Serco Geografix and G4S, notwithstanding the DPAs which it entered into with the corporates, while the convictions it secured against two former Unaoil executives and a former SBM Offshore executive were overturned by the Court of Appeal. The common theme across each of these cases was the SFO’s disclosure failings. In particular, an independent review into the SFO’s handling of the Unaoil case conducted by Sir David Calvert-Smith identified “a significant number of fundamental failures”, which had to be addressed if the SFO was to learn from the case.<sup style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;"><a target="_blank" href="https://www.lexology.com/library/detail.aspx?g=25e1f386-5bff-4b83-9d96-2d18838bbfe6#footnotes_entry_44863224702278404" rel="noreferrer noopener" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">5</span></a></sup></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">This has been a continuing theme. In a further blow to the agency, it was announced in February 2026 that the SFO was discontinuing its decade-long prosecution of three individuals connected with...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/year-in-review-anti-bribery-and-anti-corruption-in-united-kingdom/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Thu, 11 Jun 2026 11:30:00 GMT</pubDate>
</item>
<item>
<title>Building a Sustainable and Thorough Compliance Culture: Why Tone from the Top isn’t Enough</title>
<link>https://members.agrc.org/news/news.asp?id=729125</link>
<guid>https://members.agrc.org/news/news.asp?id=729125</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Most compliance failures do not happen because leaders say the wrong things. They happen despite saying all the right ones. Across the UK and EU, organisations face intensifying scrutiny, from ESG reporting requirements to the EU Whistleblowing Directive and ongoing enforcement by the Financial Conduct Authority (FCA). Yet scandals continue to emerge in firms with polished codes of conduct and confident boardroom messaging. According to the FCA Annual Report (2023) and European Commission compliance guidance (2022), the gap between policy and practice remains stubborn. The problem is not tone from the top. It is what happens in the messy middle, where targets, pressure and ambiguity collide. Sustainable compliance is not built through rhetoric. It is built through behaviour.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Middle Managers are the Real Compliance Gatekeepers</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Most compliance strategies look impressive at the top and unravel in the middle. Middle managers are expected to translate policy into practice, yet they are rarely equipped or incentivised to do so. This creates what might be called a “compliance translation gap”. Senior leaders issue clear principles, but by the time they reach frontline teams, they are filtered through competing pressures.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In UK financial services, this tension is particularly visible. Managers are expected to meet ambitious sales targets while also adhering to strict conduct expectations under FCA. In practice, many quietly prioritise what is measured. Employees tend to follow the behaviour they see rewarded locally rather than formal corporate messaging. The result is a set of informal norms that carry more weight than official policy. Teams quickly learn what really matters. If deadlines and revenue are prioritised, compliance becomes secondary.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The solution is not more guidance from the top. It is targeted investment in middle managers, giving them clarity, support and accountability to act as genuine gatekeepers of behaviour.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Performative Compliance Undermines Real Integrity</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Many organisations are exceptionally good at looking compliant. They produce detailed policies, complete mandatory training and pass audits with confidence. Yet this often amounts to what can be described as “compliance theatre”. The activity signals control without genuinely changing behaviour.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem is particularly visible in the wake of GDPR. Across the EU and UK, firms rushed to update privacy notices and consent forms, creating an impression of rigour. However, enforcement actions by regulators show that underlying practices often lag behind documentation. The European Data Protection Board Annual Report (2023) highlights repeated failures in how data is actually handled, despite formal compliance structures being in place. This gap exists because documentation is easier to produce than behavioural change. Employees learn quickly that completing training or signing policies is what matters, not how decisions are made under pressure.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Leaders often respond by adding more rules, more reporting and more audits. This only deepens the problem. Real integrity cannot be measured through paperwork alone. It requires attention to what people actually do when faced with trade-offs, deadlines and competing priorities.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Incentives Don’t Lie</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Organisations rarely set out to encourage misconduct, yet their incentive systems often do exactly that. The tension between revenue targets and compliance obligations creates what can be called “shadow incentives”. These are the unspoken signals about what really matters.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">In sales-driven environments, the pattern is familiar. A bank may promote strong conduct values, yet reward teams primarily on growth. It is no surprise that employees focus on hitting targets. Past mis-selling scandals in UK financial services showed how easily this imbalance can distort behaviour. Even with the introduction of the Senior Managers and Certification Regime, accountability still depends on...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/building-a-sustainable-and-thorough-compliance-culture-why-tone-from-the-top-isnt-enough/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Thu, 11 Jun 2026 11:26:00 GMT</pubDate>
</item>
<item>
<title>Why is Traditional AML Struggling Against Modern Financial Crime?</title>
<link>https://members.agrc.org/news/news.asp?id=729124</link>
<guid>https://members.agrc.org/news/news.asp?id=729124</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Illusion of Control</strong></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Across Europe and the UK, financial institutions spend billions each year on anti-money laundering systems, yet scandals and enforcement actions continue to surface with unsettling regularity. Pressure is intensifying from regulators such as the Financial Conduct Authority (FCA), while the EU is moving towards centralised oversight through the new Anti-Money Laundering Authority (AMLA). On paper, AML has never looked more sophisticated. In practice, it often feels brittle and slow. Why does a system so heavily resourced appear so ineffective? The uncomfortable answer is structural. Traditional AML frameworks were built for a slower, more contained financial world. Today’s criminal networks operate across borders, platforms and technologies, exposing a widening gap between regulatory design and criminal reality.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Chasing Shadows</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Traditional AML systems are built on rules. Transactions are flagged when they breach set thresholds or resemble known suspicious patterns. This approach worked when financial crime followed predictable routes, but today’s networks are far more fluid. Criminal groups now layer transactions across multiple jurisdictions, often moving funds through shell companies, crypto wallets and payment apps in rapid succession. The National Crime Agency has highlighted how UK-based laundering networks routinely restructure to evade detection, making static rules increasingly ineffective.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">A striking example is the use of “money mule” networks recruited online, allowing criminals to disperse funds through hundreds of low-value transfers that fall below reporting thresholds. Europol has also reported the growth of laundering “as-a-service”, where specialist groups handle financial flows for other criminals, constantly adapting methods to avoid detection.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In the EU, fragmented supervision between member states creates further blind spots, while many UK banks still depend on legacy monitoring systems. The result is a widening gap. AML systems are designed to catch known risks, yet modern criminals thrive by inventing new ones. The future lies in behavioural analytics and network-based detection that can uncover hidden relationships rather than isolated transactions.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Data Rich, Insight Poor</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern AML systems are drowning in data. Banks now collect vast streams from KYC checks, transaction monitoring, sanctions screening and open banking feeds. In theory, this should sharpen detection. In practice, it often obscures it. Many institutions report false positive rates above 90 per cent, leaving analysts overwhelmed and genuine threats buried in noise. The National Crime Agency has repeatedly noted the sheer volume of Suspicious Activity Reports (SARs) submitted each year, many offering limited intelligence value.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This has fuelled a culture of defensive compliance. Firms prioritise filing reports to satisfy regulators rather than stopping criminal activity at source. In the UK, the SARs regime has been criticised for inefficiency, while across the EU fragmented systems and data silos continue to limit effectiveness despite efforts at harmonisation.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">A more promising direction is emerging. Leading institutions are shifting from simple data accumulation to data orchestration, integrating and prioritising information to create meaningful insight. Tools such as graph analytics and AI-driven entity resolution are beginning to map hidden relationships, helping firms move beyond isolated alerts towards a deeper understanding of financial crime networks...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/why-is-traditional-aml-struggling-against-modern-financial-crime/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Thu, 11 Jun 2026 11:06:00 GMT</pubDate>
</item>
<item>
<title>AGRC and Auren Institute Partner to Bring Internationally Accredited GRC Programmes to Malta</title>
<link>https://members.agrc.org/news/news.asp?id=728409</link>
<guid>https://members.agrc.org/news/news.asp?id=728409</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Auren Institute, the compliance training provide in Malta, has entered into a partnership with the Association of Governance, Risk and Compliance (AGRC) to deliver AGRC’s internationally accredited programmes to professionals across the Maltese financial services sector.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Under the agreement, Auren Institute becomes the route to market in Malta for AGRC’s full suite of certifications, spanning Anti-Money Laundering, compliance, risk management, ESG, corporate governance, financial crime prevention, and related disciplines. Maltese professionals will be able to access globally recognised credentials locally, supported by Auren’s delivery infrastructure and sector specialism.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The partnership lands at a point of sustained regulatory pressure in Malta. Local compliance teams are working through obligations under the Prevention of Money Laundering Regulations, FIAU implementing procedures, the EU AI Act, and a steady stream of guidance from regulators in both Malta and the wider European Union. Demand for verifiable, board-ready compliance credentials has risen accordingly.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Mateo Jarrin Cuvi, Global Manager for Partners and Media at AGRC, said:</span></span></p><blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow" style="letter-spacing: normal; box-sizing: border-box; margin: 0px 0px 25px; padding: 10px 10px 10px 20px; line-height: 1.8rem; order: 0; font-style: italic; border-color: #ef233c; overflow-wrap: break-word; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><p class="wp-block-paragraph" style="box-sizing: border-box; margin-bottom: 0.6em; padding: 0px; line-height: 1.8rem; order: 0; font-size: 1.3em;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;">“Malta’s financial services sector is one of Europe’s most dynamic, and its professionals deserve access to world-class GRC education. Our partnership with Auren Institute brings AGRC’s internationally accredited programmes in AML, compliance, risk management, ESG, corporate governance, financial crime prevention, and more, directly to the Maltese market. Together, we are committed to equipping professionals across the region with the tools and credentials they need to meet the demands of an increasingly complex regulatory environment and to position Malta as a centre of excellence in governance, risk, and compliance.”</em></span></span></p></blockquote><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Stefan Gauci Scicluna, Managing Director of Auren Institute, said:</span></span></p><blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow" style="letter-spacing: normal; box-sizing: border-box; margin: 0px 0px 25px; padding: 10px 10px 10px 20px; line-height: 1.8rem; order: 0; font-style: italic; border-color: #ef233c; overflow-wrap: break-word; caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 15px;"><p class="wp-block-paragraph" style="box-sizing: border-box; margin-bottom: 0.6em; padding: 0px; line-height: 1.8rem; order: 0; font-size: 1.3em;"><span style="font-family: Helvetica; font-size: 13px;"><em style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0;">“Malta’s financial services sector is under real regulatory pressure right now. MLR, FIAU AML obligations, the EU AI Act, all landing on the same compliance teams. This partnership with AGRC brings their accredited programmes into the Maltese market through Auren Institute. The aim is practical: give Maltese professionals credentials that hold up in front of regulators, boards, and clients, and help Malta keep its standing as a serious place to do regulated business.”</em></span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>&nbsp;</strong></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>&nbsp;</strong></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://agrc.org/auren-institute-and-agrc-partner-to-bring-internationally-accredited-grc-programmes-to-the-maltese-market/">full press release here</a>!</strong></p></blockquote>]]></description>
<pubDate>Tue, 2 Jun 2026 14:19:00 GMT</pubDate>
</item>
<item>
<title>Dealing with Cryptojacking, Cyber Extortion and Cyber Espionage</title>
<link>https://members.agrc.org/news/news.asp?id=728407</link>
<guid>https://members.agrc.org/news/news.asp?id=728407</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Europe and the UK now rank among the world’s most heavily targeted cyber regions, with attacks rising sharply as geopolitical tensions deepen and digital dependence accelerates (ENISA). Organisations face a growing triple threat. Cryptojacking enables silent theft of computing power, cyber extortion drives direct monetisation through ransomware, and cyber espionage allows strategic infiltration of sensitive data. Together, these risks are reshaping the business environment. Cyber risk is no longer a narrow IT concern. It now sits firmly at board level, influencing competitiveness, operational resilience, and even national security. This urgency is reflected in tougher frameworks such as the EU’s NIS2 Directive and the UK’s proposed Cyber Security and Resilience Bill, which are redefining how organisations must prepare and respond. This article takes a close look at the three threats and asks what can actually be done to begin safeguarding institutions.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Cryptojacking: The Invisible Drain</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Cryptojacking is the unauthorised use of computing resources to mine cryptocurrencies. Unlike ransomware, it rarely announces itself. It operates quietly, often embedded in compromised websites, cloud workloads or software supply chains, and can persist for months without detection.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The damage is subtle but significant. Instead of dramatic shutdowns, businesses face creeping costs such as inflated cloud bills, rising energy consumption and sluggish system performance that undermines productivity. The scale is growing alongside wider crypto-related crime, which has reached billions globally (Chainalysis). In Europe, SMEs are particularly exposed due to poorly configured cloud environments. A well-known example involved attackers exploiting misconfigured Docker instances to deploy mining malware across enterprise servers, draining resources without triggering alarms.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The threat is evolving. Fileless cryptojacking now runs directly in memory, leaving little forensic trace. Attackers are also targeting Kubernetes clusters, which are widely used across European firms, and are deploying AI-driven techniques to evade detection. These developments make traditional perimeter defences increasingly ineffective.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Gradually, practical responses are improving. Organisations are deploying cloud workload protection platforms and AI-based monitoring tools that detect unusual processing spikes in real time. The adoption of Zero Trust architectures is gaining traction across Europe, limiting lateral movement within networks. At a regulatory level, the EU’s NIS2 Directive is pushing firms to strengthen detection and reporting capabilities. Together, these measures are helping to expose what was once an almost invisible drain on business performance.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Cyber Extortion: The Industrialisation of Fear</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Cyber extortion involves the use of digital threats, most commonly ransomware or distributed denial-of-service attacks, to force organisations into paying money. It has evolved rapidly. Early attacks simply encrypted data, but today criminals steal information and threaten to publish it, a tactic known as double extortion. More recently, triple extortion has emerged, where attackers also pressure customers, partners or regulators to increase leverage.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The scale of the threat across Europe is severe. According to ENISA, ransomware remains one of the most damaging cyber risks facing European organisations. Attacks that once took weeks to unfold can now cripple systems within hours. The 2023 attack on the NHS supplier Advanced forced widespread disruption to healthcare services, illustrating how quickly operations can grind to a halt. Businesses face not only downtime but also potential General Data Protection Regulation (GDPR) fines, reputational damage and cascading supply chain failures.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">New trends are accelerating the problem. Ransomware-as-a-Service platforms allow less skilled criminals to launch sophisticated attacks. AI-driven phishing emails are harder to detect and deepfake audio is increasingly used to impersonate executives. There is also growing evidence of collaboration between criminal gangs and state-linked actors, blurring traditional boundaries.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">In response, organisations are shifting from pure prevention to resilience. Secure offline backups and rapid recovery capabilities are now essential. Regular incident response exercises help teams react under pressure. AI-based detection tools can identify suspicious behaviour earlier, while stronger legal frameworks in the UK and EU are improving coordination. Many organisations are also refusing to pay ransoms, working instead ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/dealing-with-cryptojacking-cyber-extortion-and-cyber-espionage/">full article </a>in The Compliance Digest!</strong></p>]]></description>
<pubDate>Tue, 2 Jun 2026 14:16:00 GMT</pubDate>
</item>
<item>
<title>Why Ethics Programmes Fail Without Accountability</title>
<link>https://members.agrc.org/news/news.asp?id=728406</link>
<guid>https://members.agrc.org/news/news.asp?id=728406</guid>
<description><![CDATA[<p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Finance has never been more tightly regulated, yet misconduct refuses to disappear. Across the EU and UK, post-crisis reforms, from the UK’s Senior Managers and Certification Regime (SMCR) to expanding ESG disclosure rules, have created dense layers of oversight. New frameworks for AI governance are now emerging, promising even greater control. And yet, scandals continue to surface. The uncomfortable truth is that ethics programmes have multiplied faster than accountability. Firms have more policies, more data and more reporting, but not more responsibility. Ethics frameworks rarely fail because of weak rules. They fail because no one is clearly, personally accountable when those rules are bent, ignored or quietly reinterpreted under pressure.</span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Compliance as Camouflage</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">EU and UK financial institutions now operate within dense regulatory frameworks, from MiFID II conduct rules to expanding ESG disclosure regimes. On paper, this should strengthen ethical behaviour. In practice, it often produces the opposite effect. Ethics programmes are frequently designed to satisfy regulators rather than shape day-to-day decisions. Staff complete training modules, sign attestations and feed dashboards, yet behaviour remains unchanged.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Recent enforcement cases illustrate the gap. Several European banks have faced fines for mis-selling or weak controls despite extensive compliance systems already in place. The issue is not a lack of rules, but a lack of ownership.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The rise of RegTech and AI-driven monitoring tools risks reinforcing this pattern. Automated alerts and reporting can create the impression of control while distancing individuals from responsibility. Ethics becomes a system output rather than a personal obligation. Without clearly assigned accountability, compliance functions may document risk but rarely prevent it.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Incentives vs Integrity</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">In finance, incentives still speak louder than values. Despite years of reform, revenue-driven bonus culture remains dominant across banking and asset management. Firms promote long-term responsibility, yet continue to reward short-term performance. The EU introduced bonus caps after the financial crisis, while the UK has since relaxed these limits to enhance competitiveness. Behavioural patterns, however, have barely shifted.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Deferred pay and clawback mechanisms were meant to strengthen accountability. In practice, they are used inconsistently and often avoided in high-performing teams. The result is a system where misconduct can still be quietly tolerated if profits are strong.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">More subtle forces are at work too. Internal league tables, deal visibility and promotion pathways create powerful “shadow incentives”. Employees quickly learn what truly drives advancement. Behavioural economics suggests people respond to actual rewards, not stated principles.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The lesson is clear. Ethics programmes that ignore incentive structures are largely symbolic. Without accountability embedded in pay and progression, integrity becomes optional rather than expected.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Complexity Without Ownership</strong></span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Modern finance operates through webs of shared responsibility. A single transaction may involve front office teams, risk managers, compliance officers, legal advisers and external partners. In theory, this creates checks and balances, but in practice, it often blurs accountability. Matrix structures mean decisions are collectively shaped but rarely individually owned.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Past mis-selling scandals in the UK illustrate the problem. Payment Protection Insurance failures involved sales teams, product designers and compliance functions, yet responsibility was widely diffused. Similar patterns appear in complex derivatives trading, where risks are distributed across desks and oversight functions.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The issue is intensifying with platform finance and embedded finance models. Banks now operate alongside fintech partners, data providers and third-party platforms. Responsibility stretches across organisational and technological boundaries.</span></span></p><p class="wp-block-paragraph" style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Ethics programmes assume clear lines of ownership. Modern finance does not provide them. When everyone contributes to a decision, accountability becomes collective in theory and absent in practice ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/why-ethics-programmes-fail-without-accountability/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Tue, 2 Jun 2026 14:03:00 GMT</pubDate>
</item>
<item>
<title>Data Is the New Control: But Poor Data Governance Undermines Compliance</title>
<link>https://members.agrc.org/news/news.asp?id=727602</link>
<guid>https://members.agrc.org/news/news.asp?id=727602</guid>
<description><![CDATA[<p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Businesses like to believe that more data means more control, sharper insight and greater power, however, the reality is far less reassuring. Data without strong governance often creates exposure, confusion and regulatory risk. Imagine an AI system denying a customer service, only for a regulator to demand an audit trail. The organisation cannot explain where the data came from or how it was used. Control, it turns out, is an illusion.</span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Across the EU and UK, regulators are now tightening expectations around accountability, from the EU AI Act to evolving General Data Protection Regulation (GDPR) enforcement. This is no longer about tidy databases. It is about governing data in a world of AI, real-time decisions and constant scrutiny.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Shift</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Data no longer simply fuels decisions; it is now the subject of regulation itself. Under frameworks such as the GDPR and the EU AI Act, organisations must demonstrate where data comes from, how it is used and who is accountable. This is a marked shift from earlier compliance models that focused mainly on storage and consent.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Consider a bank using AI to assess loan eligibility. It must now evidence training data sources and explain outcomes to regulators. Similarly, retailers deploying personalised pricing must show that customer data is processed fairly and transparently. In the UK, proposed reforms such as the Data Protection and Digital Information Bill signal a slightly more flexible approach, yet accountability remains central.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Data has become infrastructure for compliance. Mishandled, it transforms quickly from strategic asset to regulatory liability.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Explosion Problem</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Data volumes are expanding faster than most organisations can govern them. AI and machine learning pipelines ingest vast datasets, often pulled from multiple internal and external sources. At the same time, SaaS platforms and third-party ecosystems generate continuous streams of customer and operational data. Real-time analytics only accelerates this flow. The result is a growing mass of “shadow data” that sits outside formal controls.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">A retailer, for instance, may use separate tools for marketing, pricing and logistics, each holding overlapping customer data with little central oversight. When regulators ask how that data is used, answers are often incomplete. Legacy governance models struggle because they rely on static policies, while data now moves constantly across systems.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Even regulators have highlighted this visibility gap under the GDPR, which requires firms to know and document their data processing activities. In practice, many organisations no longer have a clear picture of what data they actually hold.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">The Governance Gap</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The real problem is not a lack of rules but a failure in how organisations are structured to apply them. First, as we have just seen, ownership is fragmented. Data is spread across legal, IT, risk and product teams, yet no single function holds full accountability. A bank, for example, may have compliance policies in place but still struggle to trace how customer data moves between departments.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Second, many firms engage in what can only be described as compliance theatre. Policies exist and privacy notices are published, yet they are rarely embedded into day-to-day operations. Regulators such as the Information Commissioner’s Office have repeatedly fined organisations for failing to ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/data-is-the-new-control-but-poor-data-governance-undermines-compliance/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 20 May 2026 12:42:00 GMT</pubDate>
</item>
<item>
<title>The Compliance Leader’s Dilemma: Commercial Pressure vs Regulatory Reality</title>
<link>https://members.agrc.org/news/news.asp?id=727601</link>
<guid>https://members.agrc.org/news/news.asp?id=727601</guid>
<description><![CDATA[<p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">Growth is the mantra of modern business, yet in the EU and UK it now collides daily with tightening regulation. Since the 2022 invasion of Ukraine, sanctions regimes have forced banks such as HSBC and Deutsche Bank to rethink client relationships and exit revenue streams. At the same time, new rules on ESG disclosures and the EU AI Act are expanding the compliance burden into uncharted territory.</span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This is no longer a back-office function of ticking boxes. Compliance has moved to the frontline, shaping strategy in real time. The old idea that business drives growth while compliance slows it down is breaking apart. What follows challenges that assumption and explores a more uncomfortable truth.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">When Sales Targets Collide with Sanctions Lists</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Few tensions are as stark as the clash between revenue ambition and sanctions compliance. Relationship managers are measured on growth, yet sanctions rules can instantly turn a profitable client into a prohibited one. After Russia’s 2022 invasion of Ukraine, banks such as UniCredit and Raiffeisen Bank International faced intense pressure to scale back Russian exposure despite significant earnings tied to the region.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Inside organisations, this creates friction. Front-office teams see lost deals and shrinking pipelines, while compliance insists on strict adherence to rapidly evolving EU and UK sanctions lists. The reality is that these decisions are no longer purely legal. They are geopolitical, shifting with each new package of restrictions.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Sanctions compliance has become a live strategic exercise, not a static checklist. Leaders must navigate uncertainty in real time, balancing commercial urgency with regulatory risk in a landscape where yesterday’s acceptable client may be today’s liability.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Innovation vs Oversight in the Age of Instant Business</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Speed has become a competitive weapon, but in regulated sectors it can just as easily become a liability. Fintech firms pride themselves on rapid launches and frictionless onboarding, yet regulators are increasingly questioning whether controls can keep up. In the UK, the Financial Conduct Authority (FCA) has raised concerns about weaknesses in anti-money laundering systems at fast-growing firms, including scrutiny of onboarding processes at Revolut.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The problem is structural. Products are built to scale quickly, while compliance is often bolted on afterwards. That model no longer holds. Regulators now expect “compliance by design”, where controls are embedded from the outset rather than retrofitted under pressure.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This shift changes the role of compliance entirely. It must move at the same pace as innovation, not trail behind it. In today’s environment, speed without control is not impressive. It is risky. The winners will be those who can deliver both simultaneously.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Tone at the Top, Tension on the Ground</strong></span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Senior leaders rarely fail to talk about ethics. The difficulty is what happens when incentives tell a different story. In the UK, the FCA has repeatedly highlighted cases where firms had well-written policies but weak cultures of challenge, notably in its reviews of banking conduct and governance.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">A striking example emerged in enforcement actions against banks where aggressive sales targets undermined stated values, contributing to misconduct despite formal compliance frameworks. Employees understood what was rewarded, not what was written.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">This is the uncomfortable shift. Culture is no longer a vague aspiration. Regulators increasingly treat it as something observable and assessable through behaviour, escalation patterns and decision-making.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The risk is performative ethics, where organisations signal virtue externally but tolerate pressure internally. For compliance leaders, the real task is aligning incentives with intent ...</span></p><p style="margin-bottom: 0px; font-style: normal; font-variant-caps: normal; font-width: normal; font-size: 13px; line-height: normal; font-family: 'Helvetica Neue'; font-size-adjust: none; font-kerning: auto; font-variant-alternates: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; font-variant-emoji: normal; font-feature-settings: normal; font-optical-sizing: auto; font-variation-settings: normal;"><strong>Read the <a href="https://thecompliancedigest.com/the-compliance-leaders-dilemma-commercial-pressure-vs-regulatory-reality/">full article</a> in The Compliance Digest!</strong></p>]]></description>
<pubDate>Wed, 20 May 2026 12:36:00 GMT</pubDate>
</item>
<item>
<title>Call for Participants: Dialogue-to-Action Series on the Cost of Compliance for MSM-FSPs</title>
<link>https://members.agrc.org/news/news.asp?id=727018</link>
<guid>https://members.agrc.org/news/news.asp?id=727018</guid>
<description><![CDATA[<p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-family: Helvetica; font-size: 13px;">The cost of regulatory compliance is becoming an increasingly significant challenge for micro-, small- and medium-sized financial service providers (MSM-FSPs), particularly those operating in emerging markets. As regulatory frameworks evolve in response to rapid technological innovation, many providers face growing complexity linked to licensing requirements, reporting obligations, supervisory expectations, and differing approaches across jurisdictions. For MSM-FSPs operating across multiple markets, fragmented and sometimes inconsistent regulatory requirements can increase operational costs, duplicate compliance efforts, and slow expansion into new markets.</span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">These dynamics can create disproportionate burdens for MSM-FSPs, affecting their ability to compete, innovate, and scale sustainably. Elevated compliance costs may also contribute to reduced market competition, higher costs for consumers, and constraints on the expansion of inclusive financial services.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">To support practical dialogue and industry-informed recommendations on these issues, the&nbsp;<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Alliance of Digital Finance and Fintech Associations (AllianceDFA)</strong>&nbsp;and the&nbsp;<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Association of Governance Risk &amp; Compliance (AGRC)</strong>&nbsp;are launching a Dialogue-to-Action Series on the Cost of Compliance for MSM-FSPs. The project will combine three components: a series of expert roundtable discussions, a quantitative survey of AllianceDFA and AGRC members, and the development of a public White Paper outlining key findings and recommendations.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">The Dialogue-to-Action Series will convene industry leaders, compliance experts, fintech operators, RegTech specialists, and ecosystem stakeholders from across emerging markets to participate in three virtual roundtables. The discussions will explore the common challenges and impacts of regulatory compliance costs, identify practical approaches and recommendations to reduce the cost and complexity of regulatory compliance, and examine how compliance costs affect market competition, innovation, scalability, and consumer costs.</span></span></p><p style="letter-spacing: normal; box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0; font-family: Montserrat; caret-color: #000000; color: #000000; font-size: 15px;"><span style="font-size: 13px;"><span style="font-family: Helvetica;">Alongside the roundtables, AllianceDFA and AGRC will conduct a quantitative survey of their members to gather broader industry perspectives and evidence on compliance costs, operational impacts, and emerging priorities. Insights from both the discussions and survey findings will inform the White Paper, which will be released publicly in September 2026. More details about the project can be found in the&nbsp;<strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;"><a href="https://agrc.org/wp-content/uploads/2026/05/Cost-of-Compliance-Working-Group_Terms-of-Reference.pdf" style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; text-decoration: none; color: #ef233c; transition: 0.15s;"><span style="color: #0d654c;">Terms of Reference</span></a>.&nbsp;</strong></span></span></p><p style="box-sizing: border-box; margin-bottom: 1.6em; padding: 0px; line-height: 1.6em; order: 0;"><span style="caret-color: #000000; color: #000000; font-family: Montserrat; font-size: 13px; letter-spacing: normal;"><span style="font-family: Helvetica;"><strong style="box-sizing: border-box; margin: 0px; padding: 0px; line-height: 1.8rem; order: 0; font-weight: bold;">Join the discussion:&nbsp;</strong></span></span><span style="font-family: Helvetica; font-size: 13px; color: #000000;"><span style="caret-color: #000000; letter-spacing: normal;">Applications are now open for participants interested in contributing to the Dialogue-to-Action Series. For more information and to apply, <strong><a href="https://thecompliancedigest.com/call-for-participants-dialogue-to-action-series-on-the-cost-of-compliance-for-micro-small-and-medium-sized-fsps/">follow this link</a>.</strong></span></span></p><br class="Apple-interchange-newline" style="caret-color: #000000; color: #000000; letter-spacing: normal;" />]]></description>
<pubDate>Tue, 12 May 2026 13:57:00 GMT</pubDate>
</item>
</channel>
</rss>
