Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.

Show Notes: Making Sure Your Compliance Program Keeps Up

Listen on Apple Podcasts
Listen on Google Podcasts

Quick Take

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up.

Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations.

Read The Transcript

So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.

Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.

Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the extra scoop of sugar in your compliance lemonade, Mr. Adam Goslin. How the heck are you, sir?

Adam Goslin:
I am doing just fabulous today, Todd. How about you?

Todd Coshow:
Not bad. Not bad at all.

As always, we’d like to take this time to say thank you to the listeners of this podcast and ask you a favor. Leave us a rating and a review on your podcast app of choice. It helps the podcast immensely.

Also, if you’d like to get in touch with us, please feel free to do so for any reason at [email protected].

Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic.

How far behind is your compliance program, and how would you even know, Adam?

Adam Goslin:
My compliance program’s amazing.

Todd Coshow:
Answering the philosophical question, not being a smartass.

Adam Goslin:
A lot of organizations don’t know.

Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak.

Part of the problem is that the expectations are changing fast these days.

You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation.

In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.”

Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.”

But from the outside perspective, you’re starting off already behind the eight ball, if you will.

Todd Coshow:
It definitely feels that way.

It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that?

Adam Goslin:
Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable.

Kind of a combination of boogeyman sense and Skynet vibes going on.

Effectively, it’s a matter of risk is moving faster than regulators are comfortable with.

AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time.

You’re seeing a lot of changes happening.

Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc.

AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws.

It’s a lot of different things all simultaneously churning.

It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there.

In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up.

Todd Coshow:
Where do organizations tend to fall apart when responding to all of this change?

Adam Goslin:
A lot of times they’ll treat each regulation like a separate project.

Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream.

In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.

The one thing that I’ve noticed is the larger the organization, the worse this problem becomes.

I was on the phone with an organization, talking with them last week, and we were talking through the running of their programs.

It literally was silos.

This group took care of this thing, and this group took care of that thing, and this group took care of the other thing.

The worst was that there was a lot of crossover between these various groups.

In the meantime, regulators are increasingly asking the same core questions across all of those different streams.

What is the scoped data? Do you understand your risk that’s involved? Are your controls actually working?

Organizations can chop up all of the various work into these silos, but regulators are pushing toward convergence, and a lot of synergy can be gained across these various silos.

It becomes a problem for the organizations that are dealing with it.

Todd Coshow:
It certainly does.

You’ve talked about compliance debt. What does that mean in this environment?

Adam Goslin:
Compliance debt’s all the things that you’ve shoved off into the corner.

Everybody that’s been on an engagement, especially when you’re going through the mad scramble of the annual assessment, there’s this big push to get everything wrapped up, get everything in the hands of the assessors, doing whatever heroics are needed to cross the hurdles.

In the wake of that, you’ve got elements that you’ve set off into the parking lot.

“We’ll come back to this.”

“We slapped a Band-Aid on this thing.”

“We flat out ignored this thing.”

The problem, and you and I have discussed this before, is that when organizations get to that end-of-compliance-cycle push, everybody walks into it with the best of intentions.

“We’re going to go back and clean all this stuff up and fix all these things up and dot our I’s and cross our T’s and make sure everything’s perfect.”

Yeah, right.

The day-by-day organization leaders are jumping up and down because they’re like, “Hey, we need you to go do fill in the blank.”

Of course, what gets left in the wake?

All the compliance debt that you just stacked up.

It’s all of those things that have been put off, Band-Aided, ignored, etc., over time.

It could be slowly becoming stale policies where we meant to go through and do a really detailed, deep-dive overhaul of the policies, but we just whitewashed it, made sure we didn’t have any big issues, but all the little issues were still there, and they’re starting to build up after year two, year three, year four, etc.

Manual processes that the organization has that aren’t capable of scaling, or controls that people haven’t been taking the time to validate properly.

Ownership of certain process, procedure, data, systems, applications, it’s not clearly defined.

Any one of these things that we’ve been talking through individually, it doesn’t feel like the end of the world.

But when you’ve got new regulatory requirements getting slapped on top of that shaky foundation, now you got an issue.

Instead of going through, making quick adaptations, etc., you’re trying to figure out, “How do I build this thing on the shaky foundation?”

You find yourself half solving the elements of that compliance debt that are necessary, and then leaving the rest because we don’t have time.

It really puts an organization in a direction of compliance not being difficult, but becoming unmanageable at that stage of the game.

It’s a real problem for organizations if they’re not keeping their finger on that pulse.

Todd Coshow:
Absolutely.

This is one of the most important questions that we can answer for a lot of folks out there, and that is: how is AI making that compliance debt problem worse?

Adam Goslin:
AI is accelerating the speed at which people, organizations, etc., are falling behind.

If you think about how quickly organizations are just winging AI in, often without any thought of any formal governance, you’ve got different teams with different tools, with different data, making decisions in new ways.

Every single one of those is introducing risks into the organization, whether it’s data exposure, third-party risk, model behavior, accountability gaps.

There’s a number of different arenas that are getting shoved, ostensibly shoved, to the forefront.

But in many cases, I’ve used the term AI zombie walk for a week or three.

Organizations really aren’t putting the appropriate consideration into their current stance, into the ripple impacts, into addressing those new risks as they’re introduced.

Instead, there’s an allure to just leverage, “We’re going to leverage AI because it’s super cool.”

But governance doesn’t move that fast.

When your environment is making evolutions in weeks and your compliance program is trying to catch up, but it’s taking quarters, there you got your gap.

That’s where the risk nestles, if you will.

Todd Coshow:
So what does a compliance program look like if it’s actually built to keep up with this pace?

Adam Goslin:
You need something that’s adaptive, not reactive.

You don’t want to be waiting for regulation to come along and force your hand.

You want to be continuously evaluating current stance.

What do we have going on? Where we don’t have just documented controls, but we’re monitoring these controls. We’re evolving those controls, making tweaks, modifications, and morphing controls for continuous improvement.

When it comes down to things like evidence on a compliance engagement, moving into an arena where your evidence is current.

It’s not the point-in-time scramble to try to throw everything together and put your fingers on things in time for the onsite.

You’ve got compliance integrated into operations, not either running parallel to it or as some kind of oversight arm that’s just peering over people’s shoulders.

If your program only makes a shift in direction when some form of regulation is holding it over somebody’s head, then you’re going to be in a state of continuously being behind.

You don’t want the goal to be that we’re going to try to play catch-up here.

You want to stay aligned with the changes as they’re occurring.

To harken back to some of the earlier conversations, a lot of that has to do with not allowing that compliance debt to stack up on an engagement, because the demands of the compliance program are ever-increasing.

We’ve also had some discussions previously about how organizations can better structure their compliance engagement.

We’ve talked about making the program more adaptive, not reactive, and we talked about silos a little while ago.

Certainly, some of the things that we can do to dramatically improve the operational efficiency of the compliance program is to put a firm effort into reduction in redundancy that occurs on the engagement.

As we know that I have these various standards that we are going up against as an organization, optimizing those.

I’ve been having a fair number of conversations with really large international multi-billion-dollar companies where they too struggle with this.

It’s not just the little guys.

You think about the larger of those organizations and things just move slower. There’s more complexity. There are a billion times more silos.

In many cases, the roots run deep with those silos.

Somebody has had ownership of said silo for the past two decades.

Trying to integrate and morph and change, adapt, and grow the compliance program in that setting is not always easy.

Todd Coshow:
No.

Adam Goslin:
It really takes the organization having their head in the right spot and being dedicated to the program improvement, in addition to increasing their notion of adaptation and not continuing to take on that compliance debt.

Todd Coshow:
I wanted to ask about that.

Is that something you can train into your people? Does it require hiring new experts? As those things morph and change throughout the landscape, what does that look like?

Adam Goslin:
It’s a combination of things.

It depends on the skills of what you’ve got at your fingertips.

Just to give you an easy example, if I have the person that has been running the SSAE 16 slash SOC 2 style department since the ‘90s, they’ve got a thing that they’ve worked out. They got a way of doing things.

They know where to go ahead and grab and garner.

Meanwhile, in this other building, or maybe even in another state, I’ve got the group that is going in and doing the PCI work.

Over on the West Coast, I’ve got the people that are running the ISO program.

It’s weird, but it’s like these people don’t even talk to one another.

“I got my world and I’m doing my thing.”

I really give a tremendous amount of credit to the organizations where the light bulb’s gone off.

They’re seeing the opportunity to streamline, make changes, improve, etc.

The funniest part is that when you’re talking to the people in these siloed departments as part of the discovery activity, it’s almost like they’ve been forced to operate independently.

However, many of them, the ones with their head screwed on straight, will welcome a conversation about trying to make it better.

Nobody’s come to them in Lord knows how long.

These poor people have just been left to their own devices to go sort it all out themselves, and they’ve made it work.

Many times through sheer human effort and drive and determination.

In many cases, these folks would welcome some notion of synergy where data and information that’s appropriate for their program is being shared with them, just as information that they’re gathering and garnering is being shared with other programs.

Really synergizing the overall structure and makeup of the overall compliance program.

It’s fun watching the light bulbs go on with those organizations that have been doing what they needed to do for an extended period of time, but having enough wherewithal to see the light and to try to make their world better.

It’s awesome watching that unfold.

Todd Coshow:
No doubt.

Parting shots and thoughts for the folks this week, Adam?

Adam Goslin:
We’ve hit on it in a number of different ways, but the more that you have your compliance program in a state of readiness, we have things organized, we have our compliance management system, we have done the optimization that we need to do, we have adopted a continuous compliance mode, having our finger on the pulse.

Also very importantly, as an organization, not allowing the continuous increase of that compliance debt to build up.

That’s really what forces a lot of pain and strife when the organization, not if the organization, but when the organization needs to be able to adapt quickly.

It really forces a huge problem if you’re carrying a lot of leftover compliance debt into the process or a non-optimized program.

It makes the job of adapting to new and changing regulations, integrating a new compliance standard, or making sure that we have our finger on the pulse of our operational compliance program, all of that is just made markedly worse, harder, and more challenging and difficult when you’re not optimizing your program and taking it seriously.

Todd Coshow:
And that right there, that’s the good stuff.

That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.

Adam Goslin:
And I’m Adam Goslin.

Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.

KEEP READING...

You may also like