Audit Fatigue and How to Effectively Navigate It - Episode 220

Audit Fatigue and How to Effectively Navigate It - Episode 220

Caught in a cycle of audit requests, evidence chaos, and burnout? Discover a way out in this episode. Compliance Expert Adam Goslin joins Todd Coshow to reveal the hidden causes of audit fatigue and share strategies to lighten your load. Learn why audit fatigue is intensifying and how fragmented compliance efforts fuel chaos. Uncover tactics to centralize evidence, reduce duplication, and implement improvements. Tune in to reclaim control over your compliance universe.


Episode Transcript:

So today we’re going to talk about audit fatigue. But before we do, I want to, as always, thank all the fine listeners to this podcast. Let you know that we greatly appreciate your time and your input.

With that in mind, if you have a topic, a comment, a favorite recipe, or something you want to share, please do reach out to us at complianceunfiltered@totalcompliancetracking.com. We’d love to hear what you have to say.

Adam, audit fatigue. Talk to me about why it’s getting worse and what to do about it. Let’s be honest. Compliance teams of companies undergoing compliance everywhere are exhausted. Audit fatigue feels like it is at an all-time high right now. Why does it seem like this problem is getting worse year over year instead of better?

Adam Goslin:
It’s a real issue. One would think that with better tooling and a program going into its year two, year three, etc., things would start getting easier, but it almost feels like the opposite’s happening for a lot of organizations.

Honestly, there’s been very few organizations that I’ve worked with over the years where everything just stayed static. You’ve got growing scope. You’ve got new requests for additional frameworks that need to get folded in. Expectations of assessors continue to go up, not down.

So, in a lot of cases, instead of going through just one audit, there are teams that feel like they’re on this never-ending circular bicycle track, where it’s a continuous, never-ending cycle of audits, evidence requests, and follow-ups. You get done with one, another one pops up. I feel like we’re playing assessment whack-a-mole. That would be a good way to put it.

Todd Coshow:
That’s pretty fair. But the question is, what’s really driving that? Is it just more frameworks like PCI and SOC or ISO, or is there something deeper going on?

Adam Goslin:
That’s a big part of it. The bigger issue that underlies the real problem is fragmentation.

You’ve got a lot of organizations that are managing compliance in silos. There’s different frameworks, different teams, different tools, and at the end of the day, all of that leads to duplicated effort. You’re proving out the same control in five different ways to five different audiences.

You got spreadsheets. You got shared drives. You’ve got crap spread all over Hell’s Half Acre.

I’ve talked about that ad nauseam in the past, where you’ve got stuff coming at you through email, text messages, meetings, hallway conversations, people swinging by your desk. For whatever reason, I had somebody back in the day printing their effing evidence out. They printed it out on the printer, walked by, and dropped it on my desk.

You’ve got network drives. You’ve got SharePoints. You’ve got the assessor systems. It’s an effing nightmare.

There are a lot of organizations that end up with different assessors through this process. Let’s say you got one organization. They start out and get somebody to evaluate them against HIPAA. Then all of a sudden, the business says, “Wait a second. We’ve got to throw PCI into the mix.”

Now, when they have to go to PCI, they go back to their HIPAA assessor: “Do you guys do PCI?” Nope. Then we’ll go look and find a PCI assessor. So they throw a PCI assessor into the mix. Now I got two.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Aug 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Aug 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Aug 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Jul 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Jul 36min

Populært innen Teknologi

lydartikler-fra-aftenposten
energi-og-klima
tomprat-med-gunnar-tjomlid
nasjonal-sikkerhetsmyndighet-nsm
shifter
elektropodden
teknisk-sett
rss-alt-som-gar-pa-strom
rss-ai-forklart
kortslutning
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
smart-forklart
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
digital-forretningsforstaelse
rss-ki-praten
rss-larervarelset
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis
rss-bak-skyen