For a bank's security AI, high risk begins where it can change state
An article reading China's AI guidance for banks and insurers puts the grading line at whether a security system can act, not at whether it touches money.
AI7 Sept 20264 min read
Library
Working methods and regulatory briefings for security governance, risk and compliance practitioners.
114 of 114
An article reading China's AI guidance for banks and insurers puts the grading line at whether a security system can act, not at whether it touches money.
AI7 Sept 20264 min read
The prohibited-practice list reads as a product problem. A security function's own tooling touches three of its points, and two more start in December.
AI6 Sept 20265 min read
Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.
Security practice6 Sept 20264 min read
Getting a manufacturer ready for the CRA: class, route, vulnerability handling, support period, the technical file, and a rehearsed reporting clock.
Governance6 Sept 20265 min read
Component due diligence under Article 13(5), the upstream vulnerability duty, open-source stewards, and the questions a component supplier has to answer.
Risk6 Sept 20269 min read
An Australian government report moves the governance object from the single agent to the relationship between them. The stop-point sits where control ends.
AI6 Sept 20264 min read
What the 2026 edition changed about remote auditing, and what the auditee decides: method, virtual locations, evidence over a channel, the agreement.
Compliance6 Sept 20269 min read
Twenty-eight entries joined the radar this month: guidance, codes, national acts, catalogue moves and seven dated privacy instruments beyond the EU.
5 Sept 20262 min read
Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.
AI5 Sept 20263 min read
An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.
AI5 Sept 20265 min read
Article 14 oversight and Article 12 logging as one evidence design: who oversees, what they may do, what the logs allow, and how long they are kept.
Compliance5 Sept 20269 min read
A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.
Compliance5 Sept 20263 min read
A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.
Compliance5 Sept 20263 min read
Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.
Risk5 Sept 202622 min read
A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.
Governance5 Sept 202622 min read
A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.
Governance5 Sept 202621 min read
Which Chinese instrument answers which EU instrument for vehicles and for personal data, where the two only partly meet, and where no counterpart exists.
Compliance5 Sept 202613 min read
A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.
Governance5 Sept 20263 min read
A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.
Governance5 Sept 202622 min read
A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.
Compliance5 Sept 20263 min read
A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.
Compliance5 Sept 202622 min read
Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.
Governance5 Sept 202622 min read
How a CRA support period is set, evidenced, published and closed: the Article 13(8) criteria, the duties that run over it, and who owns each.
Governance5 Sept 20269 min read
Assembling the Annex VII file, keeping it current for the retention period, and getting a declaration signed by a role that has read it.
Compliance5 Sept 202622 min read
Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.
Compliance5 Sept 20263 min read
Annex I Part II run as a process: the bill of materials, component due diligence, intake, triage, the security update, disclosure and the Article 14 record.
Risk5 Sept 202622 min read
Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.
Regulation and audit5 Sept 20265 min read
What NIS2, DORA and the CER Directive each ask of resilience, the objectives that come before plans, and the exercise a policy cannot replace.
Risk5 Sept 20269 min read
A method for turning DORA into a running programme: scope, framework, incidents, testing, third-party risk, and the register of information built last.
Compliance5 Sept 202622 min read
The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.
Compliance5 Sept 20269 min read
A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.
Compliance5 Sept 20263 min read
A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.
Governance5 Sept 202622 min read
AI governance as a table of decision rights: the three objects, a five-question test, who decides what an agent may do, and the evidence each decision leaves.
Governance5 Sept 20269 min read
Where product security decisions are actually taken: the decision rights, the risk assessment they run on, and the conformity evidence they leave behind.
Governance5 Sept 20265 min read
Seven patterns for automating compliance work, each with the evidence it produces, the place it breaks, and the requirement it actually serves.
Compliance5 Sept 202613 min read
IEC 62443 as a system of roles and decisions: which part binds which role, the concepts a governance reader must own, and where the series gets misread.
Governance5 Sept 20269 min read
A method for governing incidents end to end: declaration, decision records, the reporting clock across four regimes, and corrective action verified closed.
Governance5 Sept 202622 min read
Adding ISO/IEC 42001 to an existing ISMS as one system: scope and roles, the AI policy, AI risk, the impact assessment, Annex A and the certification route.
Compliance5 Sept 202622 min read
One control set can serve both, but a certificate and an attestation report differ in object, criteria, examiner, output and period.
Compliance5 Sept 202613 min read
Leading indicators for eleven common security risks, each with the source of the number, the threshold, the role that acts, and where the indicator misleads.
Risk5 Sept 202613 min read
A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.
Governance5 Sept 20263 min read
One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.
Governance5 Sept 20263 min read
A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.
Security practice5 Sept 20263 min read
A method for turning a pile of documents into a tiered policy set with owners, review dates and exceptions, so a reader can find the rule that applies.
Governance5 Sept 202622 min read
A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.
Governance5 Sept 20263 min read
Running the cyber security management system UN R155 requires as an operating system rather than a document set, on the clause pattern an ISMS already follows.
Governance5 Sept 202622 min read
A five-sheet starter that mirrors the standard templates for the register of information, so the function, arrangement and provider data is collected once.
Compliance5 Sept 20263 min read
A method for turning "we accept that risk" into a dated record: a named approver, a residual level tested against criteria, compensating controls and an expiry.
Risk5 Sept 202622 min read
A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.
Risk5 Sept 20263 min read
Appetite written as decisions rather than adjectives, scales with sentence anchors, and acceptance thresholds a register applies and a board approves.
Risk5 Sept 202622 min read
Appetite per risk category, anchored consequence and likelihood scales, and a published lookup that says which level is accepted, treated or escalated.
Risk5 Sept 20263 min read
A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.
Compliance5 Sept 202622 min read
Fifteen to forty scenarios a committee can decide on: risk sources with a desired end state, consequences over time, likelihood with a stated basis, and owners.
Risk5 Sept 202622 min read
The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.
Risk5 Sept 20263 min read
A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.
Governance5 Sept 202622 min read
A method for writing down how security decisions are made: the functions, the decision rights, the three lines, the interfaces and the operating calendar.
Governance5 Sept 202622 min read
Where the security register meets the enterprise one: what must agree, what may differ, who owns aggregation, and which rules force the join.
Risk5 Sept 20269 min read
A method for turning business objectives, obligations and the risk picture into five to seven measured security objectives that fit on one approved page.
Governance5 Sept 202622 min read
A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.
Security practice5 Sept 20263 min read
A lifecycle method for supplier assurance: tier first, assess by tier, contract for the rights you will need, keep assurance running, and exit on plan.
Risk5 Sept 202622 min read
A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.
Risk5 Sept 20263 min read
Four sheets for Annex I Part II: an SBOM index by product version, a disclosure log, an update log, and a reporting clock with the two Article 14 anchors.
Risk5 Sept 20263 min read
Regulation (EU) 2024/2847 by product class: the scope test, the obligations by article, the conformity route, and what starts on 11 September 2026.
Compliance4 Sept 20269 min read
A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.
Compliance4 Sept 202622 min read
Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.
Governance3 Sept 20265 min read
Certifiable standard, outcome framework, attestation report or sector standard: what each GRC instrument produces, and which one a given driver calls for.
Governance3 Sept 20269 min read
A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.
Governance3 Sept 202622 min read
The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.
Compliance3 Sept 20265 min read
Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.
Compliance3 Sept 20269 min read
How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.
Compliance3 Sept 20265 min read
One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.
Compliance3 Sept 20265 min read
A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.
Risk3 Sept 20263 min read
Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.
Risk3 Sept 202622 min read
The Commission published the roadmap consultation feedback on 2 September 2026; the FAQ of 15 April 2026 answers the milestone and inventory questions.
2 Sept 20261 min read
Order No. 25 gives a processor under one hundred thousand people a five-year audit cycle, form-based impact assessments and six export exemptions.
1 Sept 20261 min read
NIST SP 1347 reached final status on 25 August 2026, covering what a CSF 2.0 informative reference is and which NIST tools serve the reference data.
25 Aug 20261 min read
Order No. 24 makes an annual risk assessment compulsory for important data processors, with the report filed within twenty working days.
20 Aug 20261 min read
The Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten entered into force on 15 August 2026, and the decree carries no transitional law.
15 Aug 20261 min read
The 2026 Unified Agenda moved the HIPAA Security Rule rewrite out of the final rule stage and projected final action in July 2027, with no day set.
14 Aug 20261 min read
Order No. 176 replaces the 2018 internet inspection rules, holds routine on-site checks to one a year, and reuses another regulator's inspection result.
7 Aug 20261 min read
The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.
27 Jul 20261 min read
C(2026) 5252 and its annex set out how the Commission reads scope, substantial modification, support periods and the reporting duties.
27 Jul 20261 min read
The Code of Practice on Transparency of AI-generated Content closed on 10 June 2026, and the Commission's Article 50 guidelines followed on 20 July 2026.
20 Jul 20261 min read
Promulgated 17 July 2026, the amending act adds a surcharge regime; one tranche is in force from 17 January 2027 and the rest await a Cabinet Order.
17 Jul 20261 min read
Order No. 21 reaches AI that sustains emotional interaction, with a security assessment at a million registered users and algorithm filing verified each year.
15 Jul 20261 min read
Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.
14 Jul 20261 min read
R155 mandates the framework; ISO 21434 describes how to build it. Treating them as interchangeable is where most first-time audits go sideways.
Compliance10 Jul 20265 min read
A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.
Compliance10 Jul 20268 min read
ISO/IEC 27000:2026 was published on 3 July 2026 and ISO 19011:2026 in May 2026, withdrawing the editions an older audit file cites.
3 Jul 20261 min read
A voluntary three-star label rates a connected product's security, filed with a designated body and scannable to the test report and conformity declaration.
1 Jul 20261 min read
GB/T 46903-2025 took effect on 1 July 2026, giving the compliance audit already required of large processors a published national method.
1 Jul 20261 min read
Thirty-two items put AI in banks and insurers under a board committee, a graded application inventory, and risk committee approval for high-risk uses.
18 Jun 20261 min read
Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.
11 Jun 20261 min read
NIST IR 8374 Revision 1 was published in June 2026 and supersedes the 2022 ransomware profile, which predates the six-Function Core.
11 Jun 20261 min read
In force since 22 January 2021; amended by ECE/TRANS/WP.29/2025/142, binding on applying Contracting Parties from 4 June 2026 per the UN depositary record.
4 Jun 20261 min read
Thirty-eight tasks for AI agents: a registration platform carrying digital identity, a permission boundary, anomaly tooling and graded sector treatment.
8 May 20261 min read
Two opinions adopted on 15 April 2026 approve an updated European Data Protection Seal and, separately, one usable as an Article 46(2)(f) transfer tool.
15 Apr 20261 min read
Act No. 21445, promulgated 10 March 2026, is in force from 11 September 2026, with a ten per cent turnover tier and a board resolution for the privacy officer.
10 Mar 20261 min read
Eight departments set nine export exemptions for automotive data, scenario rules for judging important data, and three-year tamper-proof log retention.
30 Jan 20261 min read
Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.
15 Jan 20261 min read
Presidential Order No. 61 adds an artificial intelligence article to the Cybersecurity Law and sets the top penalty on an operator at ten million yuan.
1 Jan 20261 min read
China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.
1 Jan 20261 min read
Issued on 31 December 2025 and in force the next day, the decree sets the dossier forms, widens the transfer exemptions and repeals Decree 13/2023.
31 Dec 20251 min read
G.S.R. 846(E) splits commencement three ways: part on publication, consent managers a year on, and the working obligations eighteen months on.
13 Nov 20251 min read
The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.
31 Oct 20251 min read
Order No. 20 gives the certification route its own rules: who may use it, a three-year certificate, and a bar on splitting volumes to dodge the assessment.
14 Oct 20251 min read
Approved on 22 September 2025 and effective 1 January 2026, the package dates ADMT compliance at 2027, first audit reports at 2028 and later.
22 Sept 20251 min read
The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.
7 Jul 20251 min read
Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.
2 Jul 20251 min read
Law No. 91/2025/QH15, passed on 26 June 2025, took effect on 1 January 2026 and caps cross-border transfer fines at five per cent of turnover.
26 Jun 20251 min read
The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.
10 Jan 20251 min read
Published on 13 December 2024, the law rewrites Chile's data protection regime and creates a supervisory agency, in force from 1 December 2026.
13 Dec 20241 min read
The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.
26 Feb 20241 min read
Article 29 bars any switching charge for cloud and other data processing services from 12 January 2027, and already caps the reduced charges allowed until then.
13 Dec 20231 min read