Tag: ISO 27001.
Why most ISMS templates fail when the auditor arrives
Anyone searching for ISMS examples will likely find generic templates, fictional firms and vague claims about "strong controls".
According to compliance platform Copla, that...
Stale risk registers leave EU firms exposed to regulators
For EU-regulated firms, managing technology risk is no longer just sound practice. Under DORA, NIS2 and ISO 27001, it is a legal or contractual...
FinTech provider Phoebus Software renews SOC 2 Type II attestation
Phoebus Software has renewed its SOC 2 Type II attestation following an independent assessment by KPMG, with the review covering 89 controls across a...
AI is raising the security stakes for tax compliance
RegTech firm TAINA has retained its ISO 27001 accreditation after recording what it describes as its strongest audit performance to date, highlighting the growing...
Why ‘compliance management system’ means different things
Ask ten people what a compliance management system actually is and expect three different answers, each correct within its own context.
According to Copla, the...
What is a GRC framework, and why does it matter now?
Governance, risk and compliance are already present in most organisations, but the difference between running them as a connected system and running them as...
Why continuous compliance keeps quietly failing firms
Continuous compliance is often confused with continuous control monitoring, but the two are not the same thing, and the difference is costing firms visibility...
Why Zero Trust is reshaping EU financial compliance
Compliance teams across the EU financial sector are increasingly being asked to justify not just what controls they have in place, but why those...
Why procurement tools can’t answer the risk question
Vendor management software and vendor risk management software are often bundled together in FinTech and RegTech conversations, but they solve fundamentally different problems.
According to...
The automation ceiling vendors won’t tell you about
Automated evidence collection has become a fixture of modern compliance programmes, pulling data from cloud consoles, identity providers, endpoint tools and code repositories on...










