• General Data Protection Regulation (GDPR) and Data Privacy management 

    General Data Protection Regulation (GDPR) and Data Privacy management 

    What is GDPR and Data Privacy management? The General Data Protection Regulation (GDPR) is the EU data protection law that governs how organizations collect, use, store, share, protect, and delete personal data. Data privacy management is the ongoing process organizations use to meet GDPR and other privacy obligations in practice. In governance, risk, and compliance…

    Read more: General Data Protection Regulation (GDPR) and Data Privacy management 
  • Compliance audit

    Compliance audit

    What is a compliance audit? A compliance audit is a structured review that checks whether an organization is meeting specific laws, regulations, standards, policies, contractual requirements, or internal controls. It helps confirm whether compliance requirements are understood, owned, evidenced, and operating in practice. In governance, risk, and compliance (GRC), a compliance audit matters because it…

    Read more: Compliance audit
  • Compliance reporting

    Compliance reporting

    What is compliance reporting? Compliance reporting is the process of collecting, analyzing, and presenting information that shows whether an organization is meeting its compliance obligations. It helps leadership, boards, auditors, regulators, and internal stakeholders understand compliance status, control effectiveness, issues, breaches, remediation, and areas needing attention. In governance, risk, and compliance (GRC), compliance reporting matters…

    Read more: Compliance reporting
  • Compliance management software

    Compliance management software

    What is compliance management software? Compliance management software is a digital system that helps organizations manage compliance obligations, controls, policies, evidence, issues, remediation, and reporting in 1 connected place. It gives compliance teams a clearer way to understand what requirements apply, who owns them, what actions are due, and what evidence proves compliance activity has…

    Read more: Compliance management software
  • Regulatory compliance including SCF compliance frameworks

    Regulatory compliance including SCF compliance frameworks

    What is regulatory compliance? Regulatory compliance is the process of meeting the laws, rules, standards, and requirements set by regulators, governments, and supervisory bodies. It helps organizations understand which external obligations apply, assign ownership, operate controls, collect evidence, and report when required. In governance, risk, and compliance (GRC), regulatory compliance matters because regulatory expectations rarely…

    Read more: Regulatory compliance including SCF compliance frameworks
  • Compliance

    Compliance

    What is compliance? Compliance is the process of meeting the laws, regulations, standards, policies, contractual requirements, and ethical expectations that apply to an organization. In simple terms, compliance helps organizations understand what they are required to do, assign ownership, operate controls, evidence activity, and respond when something goes wrong. In governance, risk, and compliance (GRC),…

    Read more: Compliance
  • UK Corporate Governance Code

    UK Corporate Governance Code

    What is the UK Corporate Governance Code? The UK Corporate Governance Code is the Financial Reporting Council’s corporate governance framework for listed companies in the UK. It sets out principles and provisions covering board leadership, company purpose, division of responsibilities, board composition, succession, evaluation, audit, risk, internal control, and remuneration. The Financial Reporting Council explains…

    Read more: UK Corporate Governance Code
  • AI governance

    AI governance

    What is AI governance? AI governance is the system an organization uses to direct, oversee, control, and evidence the way artificial intelligence is developed, bought, deployed, monitored, and used. It covers who can approve AI use, what risks need to be assessed, what data can be used, how outputs are reviewed, how decisions are documented,…

    Read more: AI governance
  • Board governance

    Board governance

    What is board governance? Board governance is the way a board of directors directs, oversees, and holds an organization accountable. It covers how the board sets strategic direction, challenges management, monitors performance, oversees risk and internal controls, and makes decisions in the interests of the organization and its stakeholders.  In governance, risk, and compliance (GRC), board governance…

    Read more: Board governance
  • Board oversight

    Board oversight

    What is board oversight? Board oversight is the process through which a board of directors monitors, challenges, and holds an organization’s leadership accountable. It helps directors understand whether strategy is being delivered, risks are being managed, controls are operating effectively, and issues are being escalated and resolved.  In governance, risk, and compliance (GRC), board oversight matters because directors cannot…

    Read more: Board oversight

Continue learning about the world of GRC

  • Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough 

    Key takeaways  Introduction: failure to go beyond filing a risk report leads to an AML conviction  In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office.  14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…

  • Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart 

    Key takeaways  How Fairlife’s cyberattack became a group governance issue  On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe.  A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…

  • The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere

    Key takeaways  Introduction: the AI compliance deadline GRC teams have been racing toward just moved  For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…