GRC Report Staff

EBA Opens Consultation on New ESG & Financial Disclosure Guidelines for Banks

The European Banking Authority (EBA) has opened a public consultation on proposed amendments to the European Commission’s Implementing Regulation on Pillar 3 disclosures under the CRR3. The consultation focuses on enhancing the transparency and consistency of disclosures related to environmental, social, and governance (ESG) risks, equity exposures, and the aggregate exposure to shadow banking entities.

Diligent Acquires Vault in AI-Powered Ethics & Compliance Push

Diligent has acquired Vault, an AI-powered ethics and compliance platform, to enhance its governance, risk and compliance capabilities. The deal comes as organizations continue to struggle with outdated ethics systems that fail to meet evolving regulatory requirements.

L3 Technologies Settles for $62 Million Over False Claims in Defense Contracts

L3 Technologies, a big player in military communications systems, has agreed to pay $62 million to settle allegations involving false cost and pricing data submitted in defense contracts. The case highlights the importance of transparency in government contracts, especially when taxpayer dollars are on the line.

Solocal Marketing Services Hit with Fine for Data Consent Failures

Recently, the French Data Protection Authority (CNIL) handed down a €900,000 fine to Solocal Marketing Services, accusing the company of mishandling personal data for commercial prospecting campaigns. The fine stems from Solocal's failure to secure proper consent from individuals and its unauthorized sharing of this data with third parties.

Irish DPC Provides Update on Meta's AI Training Plans & Data Protection Measures

The Data Protection Commission (DPC) has issued a detailed update on its ongoing engagement with Meta regarding its use of personal data to train Large Language Models (LLMs) in the EU/EEA. As AI technologies continue to evolve at a rapid pace, the DPC has been working with major technology companies to ensure that personal data is processed in compliance with the General Data Protection Regulation (GDPR). This regulatory oversight is essential in mitigating risks to individuals and protecting data subjects' rights within the context of cutting-edge AI development.

GoDaddy Reaches Settlement with FTC Over Data Security Failures

GoDaddy has finalized a settlement with the Federal Trade Commission (FTC) after the company faced allegations of failing to properly secure its customers’ websites and sensitive data. The FTC's investigation, which began in January 2025, highlighted that despite GoDaddy's claims of offering “award-winning security,” the company neglected basic data protection practices that left its users vulnerable to cyber threats.

Singapore Launches Guidebook to Support Sustainability Reporting

The Accounting and Corporate Regulatory Authority (ACRA) of Singapore recently introduced the Sustainability Reporting Body of Knowledge (SR BOK), a comprehensive guidebook designed to help training providers develop high-quality, ISSB-aligned sustainability reporting programmes. The initiative aims to address the growing demand for professionals skilled in preparing sustainability reports and climate disclosures, aligning with the Singapore Green Plan 2030 and global regulatory trends.