GRC Report Staff

MFSA Recasts Financial Crime Supervision Ahead of Europe's AML Overhaul

The Malta Financial Services Authority has published a new strategy for financial crime compliance, and what stands out is not what it asks firms to do differently today. It is how the regulator intends to supervise them tomorrow.

Australian Energy Regulator Issues Guidance on Auto-Bidding & Third-Party Compliance Services

The bids arriving in Australia's wholesale electricity market increasingly have no trader behind the keyboard. They are generated by software following predefined instructions, often reacting to changing market conditions before a person has time to intervene. The technology has become common enough that the Australian Energy Regulator decided it was time to address not the software itself, but the responsibilities that survive its use.

Complete Health to Pay $14.1 Million Over Alleged Medicare Advantage Risk Score Inflation

The Justice Department says Complete Health Partners Holdings crossed the line between documenting illness and manufacturing reimbursement. The Jacksonville, Florida-based management services organization has agreed to pay $14.1 million to resolve allegations that it caused false diagnosis codes to be submitted to inflate Medicare Advantage payments between 2020 and 2023. The settlement resolves claims brought under the False Claims Act and does not include an admission of liability.

SEC Wins Default Judgment Against Adamant Stone After Alleged False Adviser Filings

The U.S. Securities and Exchange Commission has secured a default judgment against Adamant Stone Limited after alleging the purported investment adviser built its regulatory profile on claims it could not support.

Europe Starts Enforcing Key Provisions of the AI Act

On Aug. 2, the European Commission's AI Office, working alongside national authorities, began enforcing key provisions of the AI Act. The same date also marked the start of new transparency obligations requiring certain AI systems to disclose when users are interacting with artificial intelligence rather than a human being. AI-generated or AI-altered content must now carry machine-readable markers that make it easier to detect, while deepfakes (images, audio, or video) must be clearly labeled.

Italian Privacy Watchdog Fines TIM €9.5 Million Over Telemarketing and Privacy Violations

Italy's data protection authority has fined telecommunications provider TIM €9.516 million, concluding that failures in the company's telemarketing operation extended well beyond nuisance calls. According to the regulator, unauthorized call centers funneled unlawfully obtained customer information into TIM's legitimate sales network, exposing weaknesses in the company's oversight of third-party partners and turning illegally obtained contacts into apparently valid customer contracts.

Access DX Agrees to $36.4 Million Settlement Over Alleged Genetic Testing Kickback Scheme

For two years, according to federal prosecutors, the business model at Access DX Laboratory rested on finding more patients, ordering more genetic tests, and billing the government. The methods, the Justice Department alleges, included paying marketers for referrals, compensating telemedicine providers for fraudulent physician orders, breaking genetic tests into separately billable components, and sending Medicare and Medicaid the bill for testing that was not medically necessary. That alleged scheme has now produced a $36.4 million resolution.