What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discuss why AI-generated policies often fail in audits and incident reviews, and how to use AI for drafting without losing accountability.

Episode Transcript:

Today, Adam, we’re gonna talk about what compliance problems arise when AI is writing your policy.

So if AI wrote your security policy and no one really reviewed it, whose policy is it?

Adam Goslin:
I love the compliance problems. That was good.

Before I go there, every time that you’re like, “Hey, tell a few friends that may be interested in what we’re doing here,” I always had that thing. I don’t remember what the frick commercial it was back in the day, but it’s like, “And they too tell two friends, and they tell two friends, and so on and so on.”

I forget what the hell the topic was. It was like some PSA or something.

Todd Coshow:
Sounds like a pyramid scheme. I don’t know.

Adam Goslin:
Nah. I’m gonna be forced to go figure that out now.

Anyway, if you just go jam it into AI and it spits out a policy and nobody’s taken a look at it, whose policy is it?

AI is becoming a good productive tool for compliance teams.

It isn’t a problem to have AI go take a whack at the first draft.

The problem is, and quite honestly, this is the same issue that organizations have had now for some time.

For some time you’ve been able to go out to whatever, I’m just gonna make it up, like www.writemycompliancepolicyforme.com, and you too can fill in blanks and get some steaming pile of garbage as a policy.

Some people literally do.

I’ve been doing engagements, and we’re going through the policy for the annual review, etc., and there’s literally placeholders left in the damn policy for where things that they should have filled in, obviously.

They didn’t do anything other than take a half-hearted whack at find and replace a couple of times and called it a policy.

It’s really no different.

When you’ve got AI blasting out the first draft and then you just go ahead and put your signature on the dotted line, it’s not terribly useful.

Quite honestly, one of the biggest problems that poses when you’re trying to go through your engagement, the relationship between people going through compliance and the folks that are gonna be assessing compliance, it’s one where there is a certain amount of built-up trust that happens between those parties.

There is absolutely no better way to erode any notion of trust building when you’re just serving up what usually is one of the earliest things.

Normally when you go and sit down, you go through the overview of the company and what is the scope, and the assessor’s asking all sorts of questions so they can get their arms around it.

But the very first thing that they’re actually looking at generally is the policies.

Do you wanna start it off on completely the wrong foot?

Go have AI write the initial draft and put your signature on the bottom line, or go grab a template policy and you haven’t really reviewed it.

Policies are more than just well-written language.

It’s literally a written commitment about how the organization is actually operating.

If leadership is signing off on policies that aren’t reflective of reality, aren’t reflective of coverage for the various standards that you’re ostensibly going up against, if it isn’t reflecting how you’re actually doing what you’re doing, etc., you’re creating compliance risk in advance of your assessor walking in to bat you over the head.

It’s really not a good look when you’re sitting there at your annual assessment or onsite and running square into that wall.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Aug 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Aug 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Jul 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Jul 36min

Populært innen Teknologi

lydartikler-fra-aftenposten
tomprat-med-gunnar-tjomlid
energi-og-klima
teknisk-sett
nasjonal-sikkerhetsmyndighet-nsm
shifter
elektropodden
rss-alt-som-gar-pa-strom
rss-ai-forklart
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
smart-forklart
rss-ki-praten
digital-forretningsforstaelse
rss-bouvet-bobler
rss-larervarelset
kortslutning
rss-heis
rss-bak-skyen
rss-grenser-for-ki