Your board does not have an AI risk framework. If it did, someone would have asked about it in the last six months. Three in four boards have approved major AI investments. Fewer than half have set governance expectations for them. (Grant Thornton, 2026.) Usage is not the problem. Most companies already run AI somewhere — often in more places than the board has been told. Sit in a board meeting and you will hear adoption numbers and a slide about productivity gains. Everyone nods, and the agenda moves on. Adoption is not governance. Governance is the part where the board can answer who is accountable when an AI-driven decision goes wrong. Ask that in most boardrooms and you get a pause — then a look towards whoever manages IT. A real framework has five parts, and most companies have none of them: ✅ A model inventory: every AI system you actually run, including the tool your CMO bought on a credit card ✅ A human-in-the-loop policy: which decisions need a person to sign off, and which do not ✅ An incident playbook: what happens when the model misbehaves at 11pm on a Sunday ✅ Vendor accountability: when a third-party AI breaks, the accountability is still yours. PDPA does not let you contract it away ✅ A decision audit trail: could you reconstruct a customer-impacting AI decision if a regulator asked tomorrow · Frontier models change weekly. Your board meets quarterly. That maths only works if governance is structural: checked at every meeting, owned by a named director, stress-tested at least once a year. If you want a starting point that already exists, look at IMDA's Model AI Governance Framework. It now covers AI agents specifically. The boards that sort this out in 2026 are the ones not writing apology letters in 2027. Take those five into your next board meeting and count how many you can answer without leaving the room. Under three and you have an AI strategy with no governance underneath it. Tell me your number. #AIGovernance #BoardLeadership #AIRisk
Strategic Compliance Management
Explore top LinkedIn content from expert professionals.
-
-
TOGAF vs COBIT — Two Frameworks, One Goal: Aligning IT and Business TOGAF (The Open Group Architecture Framework) is an enterprise architecture framework that provides a methodology for designing, planning, implementing, and governing enterprise information architecture. COBIT (Control Objectives for Information and Related Technologies), developed by ISACA, is a framework for IT governance and management that provides control objectives, metrics, and best practices to ensure IT supports business goals effectively. In the world of enterprise transformation, organizations often ask: Should we use TOGAF or COBIT? The truth is that they complement each other. TOGAF gives you the architecture blueprint — the “how” to design and manage systems that align with your strategy. COBIT gives you the governance compass — the “why” and “who” to ensure IT delivers value, manages risk, and stays compliant. ✅️TOGAF builds the structure. ✅️COBIT governs the structure. TOGAF + COBIT synergy: TOGAF provides the architectural blueprint (processes, systems, data, and technology). COBIT provides the governance and accountability model to ensure those architectures deliver measurable business value under controlled risk. Together, they turn architecture into accountability and strategy into measurable outcomes. They bridge architecture design and IT governance, ensuring organizations not only build efficient systems but also manage them responsibly and strategically. Key takeaway: ✅️TOGAF = Design it right. ✅️COBIT = Govern it well. As organizations mature digitally, combining these frameworks ensures alignment, control, and agility across every layer from business goals to technology execution. #EnterpriseArchitecture #ITGovernance #COBIT #TOGAF #DigitalTransformation #RiskManagement #Leadership #Strategy #Governance #TechnologyAlignment
-
The DOJ consistently says that compliance programs should be effective, data-driven, and focused on whether employees are actually learning. Yet... The standard training "data" is literally just completion data! Imagine if I asked a revenue leader how their sales team was doing and the leader said, "100% of our sales reps came to work today." I'd be furious! How can I assess effectiveness if all I have is an attendance list? Compliance leaders I chat with want to move to a data-driven approach but change management is hard, especially with clunky tech. Plus, it's tricky to know where to start– you often can't go from 0 to 60 in a quarter. In case this serves as inspiration, here are a few things Ethena customers are doing to make their compliance programs data-driven and learning-focused: 1. Employee-driven learning: One customer is asking, at the beginning of their code of conduct training, "Which topic do you want to learn more about?" and then offering a list. Employees get different training based on their selection...and no, "No training pls!" is not an option. The compliance team gets to see what issues are top of mind and then they can focus on those topics throughout the year. 2. Targeted training: Another customer is asking, "How confident are you raising bribery concerns in your team," and then analyzing the data based on department and country. They've identified the top 10 teams they are focusing their ABAC training and communications on, because prioritization is key. You don't need to move from the traditional, completion-focused model to a data-driven program all at once. But take incremental steps to layer on data that surfaces risks and lets you prioritize your efforts. And your vendor should be your thought partner, not the obstacle, in this journey! I've seen Ethena's team work magic in terms of navigating concerns like PII and LMS limitations – it can be done!
-
𝐀𝐈 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞 & 𝐃𝐚𝐭𝐚 𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐋𝐚𝐰𝐬 𝐟𝐨𝐫 𝐆𝐞𝐧𝐀𝐈 𝐀𝐩𝐩𝐬 Building GenAI Apps for a Global Audience? Understanding Regional Data Protection and AI laws is not optional, it is foundational. Here is what you need to know: 1. UNDERSTANDING GLOBAL REGULATORY VARIANCE Building GenAI for a global audience requires understanding regional data protection and AI laws. Key Regulations by Region: • EU AI Act: Risk-based AI obligations for certain AI systems and transparency use cases • GDPR (EU): Transparency & Consent • DPDP (India): Digital Personal Data Protection • PIPL (China): Strict Data Localization • CCPA (California): Data Access & Opt-Out • LGPD (Brazil): Local Compliance Rules 2. IMPACT OF THESE REGULATIONS ON YOUR AI TRAINING DATA To build compliant GenAI apps, Ensure that data used for training AI models follows the regional rules: Data Collection → Processing → Model Training → Deployment Three Core Requirements: a. User Consent: Obtain explicit consent for data collection and use b. Data Minimization: Collect only necessary data for the intended purpose c. Anonymization: Remove personally identifiable information from training data 3. MITIGATING AI ETHICS AND BIAS RISKS AI systems must be fair and ethical, particularly in high-risk areas: a. Fairness: Ensure your AI models don't discriminate, especially in areas like recruitment or finance. b. Bias Mitigation: Regularly test and adjust your models to reduce bias in the outputs. 4. ENSURING TRANSPARENCY IN AI MODEL DEVELOPMENT Transparency is a cornerstone of compliance, especially when your AI impacts users directly: a. Explainability: Protect data in transit and at rest. b. Consent Management: Collect, track, and manage user consent. c. Privacy by Design: Embed privacy into every system layer. 5. MANAGING CROSS-BORDER DATA FLOW GenAI apps often rely on data from various regions, so it's critical to understand data sovereignty laws: a. Data Sovereignty: Follow local laws on where data is stored and processed. b. Data Transfer Agreements: Use SCCs or BCRs for compliant cross-border transfers. THE COMPLIANCE CHECKLIST Before launching GenAI globally, verify: 1. Regional Compliance: • GDPR for EU? (Transparency & Consent) • DPDP for India? (Data Protection) • PIPL for China? (Data Localization) • CCPA for California? (Access & Opt-Out) • LGPD for Brazil? (Local Rules) 2. Training Data: • User consent obtained? • Data minimized? • PII anonymized? 3. Ethics & Bias: • Fairness tested? • Bias mitigation in place? 4. Transparency: • Explainability documented? • Consent management system? • Privacy by design? 5. Cross-Border: • Data sovereignty compliance? • Transfer agreements (SCCs/BCRs)? Each region has different requirements. Build for the strictest, adapt for the rest. Which regulation applies to your GenAI app?
-
Not all cyber threats are equal…. It is crucial for the Board & CXOs to ensure that investments in security are aligned with the organization's risk profile. This requires regular risk assessments & aligning the cyber security strategy with the organization's business goals. Simply put, far too many boards & CEOs see cybersecurity as a set of technical initiatives & edicts that are the domain of CIO, CISO, & other technical practitioners. In doing so, they overlook the perils of corporate complexity & the power of simplicity when it comes to cyber risk. In fact leaders who are serious about cybersecurity, need to translate simplicity & complexity reduction into business priorities that enter into the strategic dialogue of the board, the CEO, & the rest of the C-suite. Questions such as the following can help catalyze this conversation: • How does a full accounting of cyber risk affect our business model’s attractiveness, & does that suggest the need for a “simplification agenda”? • How transparent are the cyber risks and trade-offs associated with our external digital partnerships, & what would be the pros & cons of simplifying our ecosystem to make them more manageable? • How risky are our IT-enabled legacy processes, and how should we prioritize investments to secure, simplify, & transform them to achieve competitive advantage? Leadership teams which grapple with questions like these and embrace simplicity boost their odds of making the entire enterprise securable. Breakneck digitization in the smartphone era has exacerbated matters, as companies have increasingly created ecosystems with a variety of new partners to help expand their reach and capture new, profitable growth. They range from supply chain relationships across goods & services to partnerships for data, distribution, marketing, & innovation. Even more recently, the business challenges of COVID-19 pandemic have spurred faster adoption of digital solutions that rely on data, digital networks and devices that are often operated by companies outside the organization’s borders. Leaders seeking to strike a better balance can start with some basic principles. One is ensuring that strategic moves won’t increase complexity risk & make the current situation worse. Another is understanding that simplification of company, may require more than minor rewiring of systems, & instead may demand more fundamental & often longer-term modification to IT structures, to make them fit for growth. The challenges & opportunities fall into 3 areas. 1. Business models 2. External Partners 3. Internal Systems Reducing complexity while establishing a framework for governance & shared responsibility demands deliberate action, over the long & the short term. It also demands attention & energy of the CEOs & the boards who understand its value and are ready to invest in changing mindsets. Leaders who are ready to step up and set the tone will create a better blueprint for a securable enterprise.
-
I can tell the maturity of cybersecurity leaders based on how they position compliance within their programs. Why do we “do” compliance? What’s the reason behind these checks and control frameworks? The obvious answer is regulation. Laws, and corresponding agencies that enforce them, require us to. Most people stop there in their explanations. But the true reason we have compliance in security, like we have compliance in any industry, is because companies cannot be trusted to do the right thing on their own. When left to their own devices, companies would choose to prioritize profit. They would take larger risks with people’s data and ability to conduct their livelihoods for shareholder returns. The people who understand compliance’s true purpose—to make sure you’re adequately leveraging cybersecurity a cybersecurity strategy over your operations—don’t get excited by having “all the boxes checked.” Because they know that real, effective cybersecurity and the controls that are required to achieve it sometimes don’t fit into these one-size-fits-all control frameworks. They know that even the ones that have been around awhile have logical deficiencies when applied to the environment. Boxes will go unchecked by design. The best cybersecurity leaders focus on demonstrating real reduction of risk through a tailored strategy, then use compliance as a gut-check rather than the decider of what’s done. The same people leading cybersecurity programs that wave their perfect compliance marks in your face… …are often the ones who can’t tell you anything about their own company’s attack surface, and what the actual potential threats to their business operations are which they are securing against.
-
Sensitive data isn't always what many think it is. Most people presume it’s limited to financial or health data. Or credit card and social security numbers. Then privacy laws came along and changed all of that. Redefining sensitive data with varying definitions across different regulations. And depending on the law, sensitive data may now include religious beliefs, over-the-counter med purchases, or precise geolocation data. Different definitions, different requirements under different privacy laws.... And these discrepancies can lead to serious compliance risks and costly liabilities for businesses if data is not handled correctly within each jurisdiction. It sure is confusing. Yet, your company can manage sensitive data with these 4 steps: 1. Understand Your Data → Start by conducting a data inventory → Update the data inventory when new vendors, data processing activities, or technologies are introduced → Regularly assess whether current data collection aligns with business needs and legal requirements 2. Implement Privacy by Design Principles → Build privacy into your products or business systems proactively → Make privacy the default setting → Ensure security, transparency, and respect for user privacy 3. Be Proactive About Privacy Impact Assessments (PIAs) → Conduct a PIA to flag risks before new processes or technologies roll out → Meet legal requirements while enhancing efficiency, compliance, documentation, and transparency with governmental and public bodies → PIAs also help businesses address potential issues with cross-border data transfers 4. Take a Close Look at Your Data Retention Policies → Retain data only as long as needed → Document clear policies for how sensitive data will be deleted or anonymized when no longer needed → Address how privacy rights will be managed Keep in mind: → Sensitive data needs to have a business purpose to be processed. → Sensitive data collection (and its purposes) need to be disclosed in privacy notices. → And some regulations have specific disclosure requirements around this. 🎉 Bonus tip: Align a likely security focused sensitive data policy with your privacy definitions of sensitive data! This is a common miss among companies and then what is sensitive data internally is confusing! Read our blog for more insights on sensitive data and how you can manage it. Link in the comments 👇
-
You want to balance Security and Trust imperatives when running your GRC programs? 6+1 tips to better align your program with both Security and Go-To-Market stakeholders. 1️⃣ Make company security the baseline, not frameworks Stop implementing "SOC 2 controls" and start implementing "our security baseline" that happens to satisfy SOC 2. When security is the goal and compliance is the byproduct, you shift focus from checking boxes to securing systems. Your framework should be an output, not an input. 2️⃣ Implement risk-based KPIs alongside sales metrics Balance "deals unblocked" with "critical risks mitigated" and "mean time to remediation". When your performance depends equally on sales enablement AND security improvement, priorities naturally align. What gets measured gets managed - so measure what matters for security. 3️⃣ Build remediation-driven compliance Make remediation the centrepiece of your program. Every finding should have an owner and timeline. Every certification project should be measured by issues fixed, not just paper collected. Celebrate remediation velocity like you celebrate deal velocity. Evidence collection is a means, not an end. Find ways to help owners get further on the remediation side. 4️⃣ Develop automation-first GRC programs When use-cases are custom, easy or complex, invest in building rather than buying. This doesn't just save money - it puts technical capability at the heart of your GRC function, ensuring you speak the same language as engineering and can evaluate vendor claims critically. Your GRC team should also own some code, not just spreadsheets. 5️⃣ Converge GRC and security engineering Break down the divides. Embed GRC people in security engineering teams and vice versa. Make knowledge transfer explicit and continuous. When "Trust" people understand the technical reality and engineers understand the compliance requirements, both sides make better decisions. 6️⃣ Value actual security outcomes over compliance artefacts Start celebrating actual security improvements. Did your controls actually reduce the attack surface? Did your risk management identify and address a real threat? The true measure of your program is effectiveness, not documentation. A successfully defended system is worth more than a perfectly documented one. BONUS: 7️⃣ Celebrate security-driven business decisions Redefine success to include deals you shaped for better security outcomes, not just those you rubber-stamped. Recognise team members who improved contract terms, strengthened vendor security requirements, or helped sales understand realistic compliance timelines. Security still shouldn't just be about saying "no" - it should be about finding secure paths to more "yes." Trust and security aren't opponents; they're partners. Engineers who respect your GRC program and customers who recognise your security maturity—that's the sweet spot. Time to build both, not sacrifice one for the other.
-
Your enterprise client sent you a 47-question DPDP compliance questionnaire. You have 7 working days. Your privacy expert is on holiday. You have never done this before. Here is the exact sprint to get through it without losing the contract: DAY 1: READ THE QUESTIONNAIRE END TO END Do not start answering. Categorise every question into three buckets: questions you can answer right now with confidence, questions that require internal investigation, and questions you genuinely do not know the answer to. This triage determines your entire strategy for Days 2 to 7. DAY 2: BUILD YOUR DATA INVENTORY (FAST VERSION) You need to know: what personal data your company holds, where it is stored, what it is used for, and which vendors touch it. You do not need a perfect data map — you need a workable one. A spreadsheet with five columns (data type, location, purpose, legal basis, vendor) completed in one afternoon is better than a perfect mapping project that takes three weeks. DAY 3: LOCATE YOUR EXISTING LEGAL DOCUMENTS Gather your current privacy policy, any data processing agreements with vendors, your Terms of Service, and any previous compliance certifications or audit reports. These are your evidence base for answering policy-related questions. If they do not exist — Day 3 is when you start writing a one-page summary of current practices as an interim document. DAY 4: ANSWER THE EASY QUESTIONS FIRST Work through your Bucket 1 questions. Write clear, specific, honest answers. Enterprise questionnaires are designed to identify vague or evasive responses. An answer that says 'we store customer data in AWS ap-south-1 with AES-256 encryption and access limited to three named engineers' is worth ten times more than 'we maintain appropriate security measures.' DAY 5: TACKLE THE INVESTIGATION QUESTIONS Work through Bucket 2 with your engineering and operations leads. For each question, document what your current practice actually is — then check whether it satisfies the requirement. Where it does not, note the gap and the remediation plan. Clients do not expect perfection. They expect honesty about current state and a credible plan. DAY 6: HANDLE THE UNKNOWNS PROFESSIONALLY For Bucket 3 questions — the ones you genuinely cannot answer — do not leave them blank and do not fabricate. Write: 'This requirement is under active review. We will provide a documented response within [X] days of contract signature.' This is professional. It is also honest. Most enterprise legal teams respect it more than a confident wrong answer. DAY 7: REVIEW, PACKAGE, AND SEND Review for consistency. Make sure your answers to related questions do not contradict each other. Package any supporting documents as clearly labelled attachments. Send with a brief cover note acknowledging the questionnaire and offering a follow-up call if needed. Has a compliance questionnaire ever delayed or cost your startup a deal? Drop Yes/No in the comments! (1:1 Discussion link in comment)
-
All Above Board: Great Governance for the Government Sector (second edition) by Julie Garland McLellan, is a comprehensive guide focused on corporate governance specifically within government-owned organizations. It covers various aspects of governance and how directors can effectively manage these organizations while balancing public policy, financial objectives, and social responsibilities. Key Themes in the book: - Corporate Governance Definition: Governance in the government sector refers to how organizations are directed and managed, including setting objectives, monitoring risks, and optimizing performance. There's an emphasis on balancing commercial goals with broader public policy objectives. - Differences Between Private and Government Boards: Government-owned entities often have a single shareholder (the government) and their goals go beyond financial returns, focusing on social and policy outcomes. Boards in this sector must navigate political and public interests, requiring a balance between profit motives and community responsibilities. - Director's Roles and Responsibilities: The book emphasizes the importance of understanding legal frameworks and regulations specific to the public sector, along with fiduciary duties. Directors are accountable to their government shareholder and must ensure that their organizations meet public expectations while minimizing risks. - Public Policy and Planning: A significant part of the book explores how government boards align their strategies with public policy goals, manage stakeholder expectations, and handle financial planning in a highly regulated environment. - Risk Management: The risks in the public sector are often higher due to regulatory complexities and public scrutiny. The book provides examples of government-owned organizations that have faced challenges and offers strategies for managing these risks effectively. - Ethics and Transparency: Ethical behavior, transparency, and accountability are critical in maintaining public trust. The book offers guidance on promoting responsible decision-making and fostering a culture of openness on government boards. Case Studies: The book includes practical case studies, such as the management of the New South Wales Grain Board and the challenges of providing services in monopoly situations (e.g., electricity supply), demonstrating how directors can navigate complex governance issues. This guide is tailored for both aspiring and current directors of government-sector boards, helping them to understand the specific challenges of the public sector and offering insights into effective governance practices.