GRC Report Staff

EBA Finalizes Third-Party Risk Guidelines With Focus on Critical Functions

The European Banking Authority has finalized its Guidelines on third-party risk management, concentrating the new framework on the outside relationships that matter most when something goes wrong.

Denmark Sends Revised Public-Sector AI Authorization Law for Consultation

Denmark has returned to a difficult question in its plans for public-sector AI, sending a revised bill for consultation that would give public authorities a general legal basis to process personal data when developing and using AI systems.

UK Fines Sabre Global Technologies £1 Million Over Russia Sanctions Breaches

Sabre Global Technologies knew Ural Airlines had been sanctioned on the day the designation took effect. The travel technology company continued providing services to the Russian carrier for another seven months. Then, when its UK bank blocked payments over sanctions concerns, the company began looking for another way to get paid, which has now cost Sabre Global Technologies Limited (SGTL) £1,000,920.59.

Corpay, CEO Agree to Pay $100 Million to Resolve FTC Fuel Card Case

Corpay, formerly known as FleetCor Technologies, and CEO Ronald Clarke have agreed to pay $100 million to resolve a Federal Trade Commission administrative action stemming from the company’s fuel card practices, years after the agency first accused it of charging businesses hidden or unauthorized fees.

EU Firms Redesign Supply Chains as Geopolitical Risk Becomes the New Normal

The problems that kept European supply-chain managers awake a few years ago have become considerably less troublesome. Raw materials are easier to secure, semiconductors are less scarce, goods are moving, but the trouble has migrated elsewhere.Between 2023 and 2025, the share of EU firms reporting raw materials as a supply-chain obstacle fell from 27% to 8%, according to a new study from the European Investment Bank (EIB) and European Commission. Semiconductor concerns dropped from 15% to 3%, while logistics obstacles fell from 28% to 12%.

FCA Clarifies Regulatory Perimeter Ahead of UK Crypto Authorization Opening

The FCA’s new crypto regime does not take effect until October 2027, but firms will have to start making decisions much sooner. With the authorization gateway opening on Sept. 30, the regulator has published guidance explaining which cryptoasset activities fall within the new framework and where FCA authorization may be required.

CISA Turns to Cyber Decoys to Catch Attackers Inside Critical Infrastructure Networks

An attacker who has stolen legitimate credentials and learned to use the tools already sitting inside a network can be remarkably difficult to spot. There may be no conspicuous malware announcing the intrusion, no obviously malicious account and, for a time, little to distinguish the attacker from someone who belongs there. CISA wants critical infrastructure operators to give such intruders something they cannot safely touch.