GRC Report Staff

Federal Regulators Propose Risk-Based Overhaul of Third-Party Management Guidance

The Federal Reserve Board, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency on Friday requested comment on proposed guidance for managing risks associated with third-party relationships. The proposal draws on the agencies’ supervisory experience and what they have learned examining financial institutions’ third-party risk management practices.

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

Italy’s Data Protection Authority has fined Banco Bilbao Vizcaya Argentaria Italia (BBVA) more than €5.5 million after finding that the bank continued sending promotional messages to a customer who had objected to receiving them, an enforcement action that exposed wider problems in how the bank managed privacy requests across its systems.

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.

DOJ, EPA Reach Proposed $125 Million Agreement to Advance Lower Passaic River Cleanup

The Justice Department and Environmental Protection Agency have reached a proposed agreement requiring Environmental Resource Holdings to perform an estimated $125 million in work intended to move the long-running cleanup of New Jersey’s Lower Passaic River toward construction.

Canada’s Privacy Commissioner Sets New Expectations for Third-Party Privacy Due Diligence

Privacy Commissioner of Canada, Philippe Dufresne, released new guidance for organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), laying out how businesses should assess the privacy practices of prospective third-party service providers. The guidance applies when an outside product, service, or technology will involve the collection, use, or disclosure of personal information, whether the provider is processing information directly, supplying technology that handles it, or working somewhere further down the chain.

Deloitte Finds Cyber Confidence Is Outpacing Readiness

Deloitte’s latest global cybersecurity survey begins with a number most CISOs would probably be pleased to see. Eighty-five percent of respondents say they are somewhat or very confident in their organization’s cybersecurity strategy.

Dompé U.S. to Pay $32 Million Over Medicare Co-Pay Kickbacks

Dompé has agreed to pay $32 million to resolve allegations that it used patient assistance foundations to cover Medicare beneficiaries’ co-pays for Oxervate, its prescription drug, turning what appeared to be charitable assistance into what federal authorities alleged were unlawful inducements to purchase the company’s product.