GRC Report Staff

Fed Chair Powell in Congressional Testimony: CFPB Sole Agency for Consumer Protection Enforcement

In his testimony before the Senate Banking Committee on Tuesday, Federal Reserve Chairman Jerome Powell faced a question that has been on the minds of many -What happens if the Consumer Financial Protection Bureau (CFPB), a critical agency tasked with consumer protection, faces diminished funding or is otherwise hindered in its operations?

EBA Refines Guidelines to Align with DORA, Bringing Clarity to ICT Risk Management

As of 17 January 2025, the Digital Operational Resilience Act (DORA) has officially begun to reshape how the financial sector addresses ICT risk management. In response, the European Banking Authority (EBA) has made a series of key adjustments to its Guidelines on ICT and security risk management. These revisions, aimed at cutting down on duplication and creating clearer expectations for the market, help ensure that financial institutions aren’t bogged down by overlapping regulations.

Five Data Protection Authorities Commit to Privacy-Protecting AI Governance

At the AI Action Summit in Paris this week, five global data protection authorities made an important pledge. On the 6th of February, a joint declaration was signed by officials from Australia, Korea, Ireland, France, and the UK—each committed to fostering an artificial intelligence ecosystem that doesn’t just innovate, but also respects privacy and safeguards fundamental rights.

SFC Flags Cybersecurity Incidents in Licensed Firms, Highlighting Risks to Business Continuity & Client Security

The reality of cybersecurity risks has hit home for many licensed corporations (LCs) in Hong Kong. The Securities and Futures Commission (SFC) recently unveiled findings from its latest 2023/24 Thematic Cybersecurity Review, shedding light on the alarming rise of material cybersecurity incidents in recent years. And the results? Not pretty.

The CNIL’s New AI Recommendations: Fostering Innovation While Protecting Privacy in the Age of AI

In a world where artificial intelligence is pushing boundaries and reshaping industries, the question of how to protect individuals' privacy has never been more pressing. Fortunately, the GDPR (General Data Protection Regulation) isn't just a barrier to innovation—it can be the very tool that enables responsible AI development. The French Data Protection Authority, or CNIL, has just issued new recommendations that take the best of both worlds: advancing AI while ensuring personal data is treated with the respect it deserves.

Brink’s Global Services Faces Penalties for Bank Secrecy Act Violations & Unlicensed Money Transmitting

Brink’s Global Services USA, Inc. (BGS), a well-known name in currency transport, is paying the price for serious compliance failures. The company has agreed to millions in penalties following multiple violations of the Bank Secrecy Act (BSA), a key piece of U.S. anti-money laundering (AML) law. This settlement includes a $37 million civil penalty levied by the Financial Crimes Enforcement Network (FinCEN) and a $50 million forfeiture linked to criminal charges for operating as an unlicensed money transmitter.

Lockheed Martin to Pay $29.74 Million Over Alleged Overpricing on F-35 Contracts

Lockheed Martin, the defense giant behind the F-35 fighter jet, has agreed to pay $29.74 million to settle allegations of inflating pricing on key contracts, marking another chapter in the ongoing scrutiny of government contracting. The payment comes on top of a prior reimbursement of $11.3 million to the Department of Defense (DOD) for similar violations involving undisclosed cost and pricing data.