GRC Report Staff

OCC Flags Elevated Credit, Cyber, & Compliance Risks in Spring Risk Report

The Office of the Comptroller of the Currency (OCC) has released its Spring 2025 Semiannual Risk Perspective, highlighting a growing list of pressures on the federal banking system, from rising commercial credit and refinance risks to increasingly sophisticated cyberattacks and compliance challenges tied to fraud and digital innovation.

Europe’s Supervisors Want to Put ESG Risk to the Test

Europe’s financial watchdogs are drawing a sharper line on how banks and insurers prepare for climate, social, and governance shocks, and they’re inviting everyone to weigh in.

SFO Deepens Global Anti-Corruption Alliances with US & International Partners

The UK’s Serious Fraud Office (SFO) has stepped up its efforts to combat cross-border corruption by officially joining the International Anti-Corruption Coordination Centre (IACCC), an elite global law enforcement alliance housed within the UK’s National Crime Agency.

Meta Faces Fresh EU Threat of Daily Fines Over Pay-or-Consent Model

Meta is back in the hot seat in Brussels, just months after it was slapped with a €200 million fine for breaching the EU’s Digital Markets Act (DMA). This time, the European Commission is warning that Meta could face daily penalty payments if its updated “pay-or-consent” model still fails to meet the bloc’s legal standards.

Danish Data Watchdog Highlights AI, Children’s Privacy, & Breach Prevention in 2024 Report

Denmark’s data protection authority, Datatilsynet, has released its 2024 annual report, spotlighting a year defined by record case volumes, deepened international collaboration, and a proactive push into fast-evolving areas like artificial intelligence and children’s online safety.

AI in Audit Gets a Reality Check with FRC’s New Guidance

The UK’s Financial Reporting Council (FRC) has recently published its first formal guidance on how artificial intelligence should be used, and documented, in audit. The guidance, released today, doesn’t lay down the law. Instead, it offers something arguably more valuable, clarity.

ENISA Publishes Technical Guidance to Help Companies Comply with NIS2 Cybersecurity Rules

The EU Agency for Cybersecurity (ENISA) has issued its first technical guidance to help digital infrastructure and managed service providers implement the cybersecurity measures required under the EU’s new NIS2 Implementing Regulation. The non-binding guidance aims to make compliance with the NIS2 Directive’s technical and methodological requirements more practical, consistent, and achievable for companies operating in critical sectors across the EU.