Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Compliance & Ethics

UK Fines Sabre Global Technologies £1 Million Over Russia Sanctions Breaches

Sabre Global Technologies knew Ural Airlines had been sanctioned on the day the designation took effect. The travel technology company continued providing services to the Russian carrier for another seven months. Then, when its UK bank blocked payments over sanctions concerns, the company began looking for another way to get paid, which has now cost Sabre Global Technologies Limited (SGTL) £1,000,920.59.

Corpay, CEO Agree to Pay $100 Million to Resolve FTC Fuel Card Case

Corpay, formerly known as FleetCor Technologies, and CEO Ronald Clarke have agreed to pay $100 million to resolve a Federal Trade Commission administrative action stemming from the company’s fuel card practices, years after the agency first accused it of charging businesses hidden or unauthorized fees.

AUSTRAC Removes 45 Payments & Crypto Businesses in High-Risk Sector Sweep

Australia’s financial intelligence regulator has removed 45 remittance and virtual asset businesses from its registers over the past year, an unusually broad sweep through parts of the financial system where money can move quickly, cross borders easily and, when controls fail, become difficult to follow.

Nuvei to Pay $4.85 Million to Settle FTC Payment Processing Case

Global payment processor Nuvei has agreed to pay $4.85 million to settle Federal Trade Commission allegations that it provided payment services to merchants it knew or should have known were engaged in deceptive activity, including tech-support scams targeting U.S. consumers.

FRC Sets Out Growth-Focused Approach to UK Regulation

The UK’s Financial Reporting Council set out a revised approach to regulation Thursday that places greater emphasis on economic growth, proportionate oversight and earlier engagement with firms, as the regulator looks to make its supervision more responsive without loosening standards across audit, corporate reporting and governance.

Poland Puts Shrinkflation Under the Microscope After EU Court Ruling

Poland’s competition and consumer protection authority is examining whether some of the world’s largest consumer-goods manufacturers are doing enough to tell shoppers when that happens. The President of UOKiK has opened preliminary investigations involving Danone, Mondelez, Nestlé and Unilever, focusing on products whose weight, volume or quantity has been reduced while the packaging around them may give little indication that anything is different.

The Strange Afterlife of a Regulation

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.