GRC Report Staff

AUSTRAC Sets Out Five Habits for Stronger AML Compliance

AUSTRAC has reduced good anti-money laundering compliance to five pieces of advice, and none of them is particularly exotic. Know which obligations apply to the business. Keep the regulator informed when basic company details change. Revisit the risks as the business changes. Make sure reports contain information somebody can actually use. Keep records good enough to explain the decisions made along the way.

Croatian Privacy Regulator Fines Gambling Operator €2.59 Million Over Fingerprint Collection

A gambling operator in Croatia offered its casino customers a shortcut. Instead of producing an identity card on every visit, players could use an RFID chip or their fingerprints to identify themselves more quickly. For 34,933 players, consent to biometric processing was recorded. But when Croatia’s Personal Data Protection Agency examined how that system actually worked, it found that the operator was collecting more than it said it was collecting.

Finnish Financial Regulator Updates Penalty Framework With Greater Credit for Early Cooperation

Finland’s Financial Supervisory Authority (FIN-FSA) has published updated principles on October 1 for determining the size of penalty payments and administrative fines. The principles themselves are not new. The authority published an earlier version in 2022, and the latest changes largely put greater precision around practices that have since become established.

Italy’s Privacy Regulator Fines IQVIA €7 Million Over Health Data of 1 Million Patients

Italy’s privacy regulator has fined IQVIA Solutions Italy €7 million over a database containing the health information of roughly 1 million patients, finding that data the company regarded as anonymous could, in fact, be traced back to individuals.

Basel Committee Takes on AI Risk in Push to Modernize Bank Supervision

The Basel Committee spent two days in Indonesia earlier this week looking at a banking system that is changing faster in some places than the rules written to govern it. Artificial intelligence was high on the agenda, but it was hardly alone. Cryptoassets, interest rate risk, liquidity, systemic banks, cyber risk and the quality of supervision itself all made the list.

Czech Competition Authority Imposes Record $89.7 Million Fine Over Cable Cartel

The Czech Office for the Protection of Competition has imposed fines totaling approximately $89.7 million (CZK 1.942 billion) on four companies after finding that six cable manufacturers coordinated the calculation of a “metal surcharge” used in the pricing of telecommunications and power cables containing copper or aluminum. It is a record fine for the Office. The decision, announced Oct. 1, is not yet final, and the parties can appeal to the Chairman of the Office.

AMLA Finalizes Three Standards for Private-Sector Anti-Money Laundering Controls

The EU's Anti-Money Laundering Authority said on October 1 that it has finalized three sets of regulatory technical standards covering customer due diligence, the treatment of business relationships and occasional transactions, and AML/CFT arrangements across corporate groups. The final drafts have been sent to the European Commission, putting them one step closer to becoming part of the rulebook that companies and professionals subject to the EU regime will have to follow.