Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up. Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations.

Episode Transcript:

Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic.

How far behind is your compliance program, and how would you even know, Adam?

Adam Goslin:
My compliance program’s amazing.

Todd Coshow:
Answering the philosophical question, not being a smartass.

Adam Goslin:
A lot of organizations don’t know.

Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak.

Part of the problem is that the expectations are changing fast these days.

You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation.

In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.”

Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.”

But from the outside perspective, you’re starting off already behind the eight ball, if you will.

Todd Coshow:
It definitely feels that way.

It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that?

Adam Goslin:
Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable.

Kind of a combination of boogeyman sense and Skynet vibes going on.

Effectively, it’s a matter of risk is moving faster than regulators are comfortable with.

AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time.

You’re seeing a lot of changes happening.

Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc.

AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws.

It’s a lot of different things all simultaneously churning.

It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there.

In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up.

Todd Coshow:
Where do organizations tend to fall apart when responding to all of this change?

Adam Goslin:
A lot of times they’ll treat each regulation like a separate project.

Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream.

In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.




Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Syys 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Syys 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Elo 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Elo 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Elo 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Elo 29min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Heinä 36min