GRC Report Staff

KPMG Survey Finds Compliance Chiefs Facing a Wider Risk Mandate

KPMG asked 725 chief ethics and compliance officers where they expect to put additional money. The answer was not subtle. Among respondents anticipating budget increases, 77% pointed to data analytics and 75% to cybersecurity and data privacy. AI or large language models came next at 50%, followed by process automation at 49%. Upskilling talent, at 34%, trailed considerably further behind.

Chemours, DuPont & Corteva Reach $455 Million Settlement Over North Carolina PFAS Claims

Chemours, DuPont and Corteva have agreed to pay $455 million over 15 years to settle a collection of North Carolina lawsuits over PFAS contamination, resolving claims that reach back through years of discharges from Chemours’ Fayetteville Works facility and extend to contamination the state says originated elsewhere.

EU Cyber Resilience Act Reporting Requirements Take Effect

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.

Federal Regulators Propose Risk-Based Overhaul of Third-Party Management Guidance

The Federal Reserve Board, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency on Friday requested comment on proposed guidance for managing risks associated with third-party relationships. The proposal draws on the agencies’ supervisory experience and what they have learned examining financial institutions’ third-party risk management practices.

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

Italy’s Data Protection Authority has fined Banco Bilbao Vizcaya Argentaria Italia (BBVA) more than €5.5 million after finding that the bank continued sending promotional messages to a customer who had objected to receiving them, an enforcement action that exposed wider problems in how the bank managed privacy requests across its systems.

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.

DOJ, EPA Reach Proposed $125 Million Agreement to Advance Lower Passaic River Cleanup

The Justice Department and Environmental Protection Agency have reached a proposed agreement requiring Environmental Resource Holdings to perform an estimated $125 million in work intended to move the long-running cleanup of New Jersey’s Lower Passaic River toward construction.