GRC Report Staff

EU Banks See Highest Cost of Risk Since 2021 as Sector Stays Resilient

The European Banking Authority’s (EBA) first-quarter 2025 Risk Dashboard shows the EU/EEA banking sector holding steady on capital and profitability, but with a notable rise in the cost of risk to its highest level in over three years.

California Privacy Watchdog Seeks Court Order to Compel Tractor Supply to Comply with CCPA Probe

The California Privacy Protection Agency (CPPA) has taken the unusual step of going to court to enforce an investigative subpoena against Tractor Supply Company, marking the agency’s first public disclosure of an ongoing investigation and its first judicial action to compel compliance with an investigative request.

EBA Moves to Redraw the Rulebook on Bank Governance

The European Banking Authority (EBA) has launched a public consultation on proposed revisions to its Guidelines on internal governance under the Capital Requirements Directive (CRD), reflecting recent legislative changes and evolving supervisory priorities. The consultation, which runs until 5 October 2025, is limited to the proposed amendments and invites feedback from stakeholders across the financial sector.

Google Uncovers Widespread Salesforce Data Theft & Extortion Campaign

It all starts with a phone call. Not a suspicious link. Not malware. Just a convincing voice on the other end of the line, claiming to be IT support. Before long, a well-meaning employee is clicking through a Salesforce setup page and, unwittingly, handing over the keys to their company’s data kingdom.

Assurance IQ & MediaAlpha to Pay $145 Million for Misleading Health Insurance Consumers, FTC Says

Two major lead generation companies, Assurance IQ and MediaAlpha, have recently agreed to pay a combined $145 million to settle Federal Trade Commission (FTC) charges that they misled millions of consumers seeking comprehensive health insurance and exposed them to a barrage of telemarketing calls and robocalls. The settlements, announced August 7, come in the form of two separate stipulated court orders that will also impose long-term bans on misleading health insurance marketing tactics.

FINTRAC’s New Penalty Policy Wants You to Learn, Not Just Pay

FINTRAC doesn’t want to play the villain in your compliance story. That’s the unmistakable message behind Canada’s financial intelligence agency’s newly updated policy on administrative monetary penalties (AMPs). While penalties are still on the table, some of them quite hefty, the focus is firmly on education, behavioral change, and long-term compliance rather than finger-wagging or financial punishment.

EBA Puts ESG Disclosure Pressure on Hold While Brussels Rewrites the Rules

The European Banking Authority (EBA) has issued a no-action letter signaling a temporary pause on enforcement of important ESG disclosure requirements. The decision comes as financial institutions across Europe brace for yet another wave of sustainability reporting reforms, and the regulators themselves admit things are in flux.