Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225

Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225

On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status.

Episode Tracking:

Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet.

That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say.

Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it?

Adam Goslin:
If we’re talking about my engagement, how long would it take? Seconds.

But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit.

This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet.

I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.”

All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch.

“Hold on a second. I think it’s over here.”

They go and look over there.

“Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.”

No, it’s not there either.

“You know what? Evan knows exactly where it’s at. Give me one second.”

Ring, ring, ring, ring.

His phone went to voicemail.

“Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?”

It was an effing nightmare.

A lot of people think that they know where things are until they’re under the gun and have to prove it.

If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game.

It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it.

It really degrades their sense that the people they’re talking to actually have their act together.

Todd Coshow:
I can definitely appreciate that.

Spreadsheets are still everywhere in compliance, but why are they such a problem?

Adam Goslin:
Spreadsheets weren’t designed to manage living, breathing systems.

We’ve talked before about the levels of complexity that exist within these things.

A spreadsheet is static, and compliance isn’t.

There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against.

You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states.

If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane.

The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Syys 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Syys 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Elo 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Elo 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Elo 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Elo 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Heinä 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Heinä 36min