GRC Report Staff

Dutch Regulator Finds Governance Gaps Behind Otherwise Mature Fund Manager Controls

The Dutch Authority for the Financial Markets (AFM) has identified several areas where fund managers should strengthen their compliance and internal audit functions, despite finding that many firms have those functions broadly well organized.

Trust Is Becoming the Real AI Battleground for Banks

Banks have spent centuries refining a single business model. They borrow trust, transform it into financial activity, and spend every day trying not to lose it. That is what makes a recent reflection from Bank of Ireland more interesting than it first appears. On its surface, it reads like another executive essay about artificial intelligence, full of familiar references to fraud detection, customer service, compliance monitoring, and operational efficiency. Those examples are almost expected now. Every large financial institution has a similar catalogue of use cases.

FRC Uses Annual Enforcement Review to Push Faster Audit Accountability

In its Annual Enforcement Review 2026, the UK's Financial Reporting Council does more than catalog another year's worth of enforcement activity. It draws a line from the mistakes uncovered in investigations to the weaknesses the regulator continues to see in financial reporting, audit quality, and firms' internal systems of control. Just as importantly, it explains how those cases are shaping the FRC's supervisory work and the standards it expects the profession to meet.

Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

Poland's Data Management Act took effect Thursday, completing a piece of legal architecture that has been waiting for its final support. The European Union's Data Governance Act has applied across the bloc since 2023. What entered into force now is the national legislation that gives the regulation a fully functioning home inside Poland's legal system.

Google Hit With €890 Million DMA Fine as EU Targets Search Bias & Play Store Restrictions

In two decisions under the European Union's Digital Markets Act (DMA), the Commission fined Google a combined €890 million, finding that the company unlawfully favored its own services in Google Search while also preventing app developers from freely steering customers toward alternative purchasing channels outside Google Play. The penalties amount to €460 million for Google's search practices and €430 million for its Play Store policies.

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

TAB Pays $1.76 Million After Australian Regulator Finds Widespread Telemarketing & Spam Breaches

The Australian Communications and Media Authority found that Tabcorp Holdings' wagering business repeatedly breached Australia's telemarketing rules while marketing to VIP customers. The regulator identified 351 calls made to numbers listed on the Do Not Call Register without consent, 82 calls placed outside legally permitted hours, and nearly 4,000 calls in which TAB failed to properly identify itself, the purpose of the call, or both.