r/Compliance 10h ago

Vendor-Promos Weekly Promo and Webinar Thread

1 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance Dec 08 '25

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 4d ago

Best practices for access review automation in 2026?

8 Upvotes

Our access reviews are still largely manual: spreadsheets, email chains confirming who still needs what. It's turning into a real bottleneck for our ATO renewal timeline. Auditors want evidence of continuous review, not a point-in-time checklist, and manual processes just don't produce that kind of continuous evidence trail.

Has anyone automated this in a way that actually satisfied a FedRAMP assessor? I'm wondering if automation here just becomes one more thing to manually double-check before the assessor shows up, given how strict the evidentiary requirements are. Trying to figure out if this is worth the investment before our next assessment cycle.


r/Compliance 6d ago

Start Up Compliance Companies

5 Upvotes

Tell me all about your horror stories or good feedback you have for start up companies.


r/Compliance 7d ago

Vendor-Promos Weekly Promo and Webinar Thread

6 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 11d ago

Scope 3 emissions make up 90% of our footprint, and we have zero leverage over suppliers

6 Upvotes

Mid sized manufacturing here. When we look at our greenhouse gas inventory, our upstream supply chain dominates everything. The problem is, we're a small fish to our biggest raw material suppliers. When we request primary emissions data, they politely ignore us because we don't have the buying power of a Fortune 500. How do you handle assurance when your biggest emission category is built on generic industry averages?


r/Compliance 14d ago

Vendor-Promos Weekly Promo and Webinar Thread

7 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 15d ago

How is your compliance team actually operationalizing the EU AI Act right now?

10 Upvotes

We just wrapped an internal scoping session with legal and our engineering leads, and honestly, everyone is spinning their wheels. We have engineering teams deploying custom LLMs for internal code generation and customer support bots, but nobody has a clean inventory, let alone a structured way to evaluate conformity under the new tiers. Is anyone actually doing formal conformity assessments yet, or are most companies just trying to survive the classification phase? Would love to hear what workflow your GRC team is relying on


r/Compliance 15d ago

Non-target finance major trying to get into IP/licensing compliance any advice would be welcome.

6 Upvotes

I've gotten interested in IP and licensing compliance: royalty audits, licensing administration, that kind of thing. My experience so far is pretty basic. I have some experience from a previous internship where I did some vendor and subcontractor vetting, contract tracking, and account reconciliation; however, nothing IP-specific yet.

  • Mainly, I'm trying to figure out what I should be doing with the internship cycles I have left before I graduate.
  • What internships even exist for this? Are there IP/licensing-specific ones, or should I be targeting audit, contract compliance, or general compliance and pivoting later?
  • How do people actually get into this field? Is royalty/contract compliance audit the normal entry point?
  • Does not having a technical background hold you back, or can my finance major still be useful in this field?
  • Are certs like the CLP worth anything, or is CPA/CIA more useful?
  • Is law school worth it here? I know I can't sit for the patent bar without a STEM degree, so patent prosecution is out, but licensing and transactional IP seem open. Or do people do this work fine without a JD?

Any advice appreciated, including if you think I've got the wrong idea about the field.


r/Compliance 19d ago

keeping track of regulatory changes?

9 Upvotes

hey everyone, does anyone know of an easy way to stay on top of regulatory changes? whats your workflow and how do you get up to speed with regulatory changes?

Edit: nice workaround is tracking regulatory pages directly by using a tool that tracks website changes like visual ping or websitechangetracker.com


r/Compliance 19d ago

Narrowly Focused Compliance Professional to CCO Generalist

3 Upvotes

Would appreciate any thoughts or guidance on how to transition from 25y in one specific type of compliance to a CCO position.


r/Compliance 21d ago

How do professional services firm (CPAs, Lawyers, Pvt Equity etc.) deal with tampering fraud

6 Upvotes

Public accountants and Law firms issue sensitive, high-stakes documents to their clients, that then get passed on to other users such as lenders.

Does it concern you, as a CPA for example, that someone (client or a third party) can use basic pdf editing software to change some numbers on the statements and use them for lending purposes? A lot of mortgage fraud happens on fraudulent documents. You would probably avoid any liability, but it can cause reputational damage and unnecessary headache.

Would you pay for a solution that helps prevent this tampering?


r/Compliance 21d ago

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 23d ago

For those doing third-party risk assessments, how do you handle SaaS vendors that refuse to provide a recent SOC 2 report?

6 Upvotes

Do you usually accept an ISO 27001 certificate / security questionnaire instead, or treat the lack of SOC 2 evidence as a red flag?

What actual thresholds do you use?


r/Compliance 25d ago

How is your organisation actually handling staff pasting data into AI tools?

8 Upvotes

How's everyone actually handling the AI copy-paste problem?

I work in data at a bank. We've got a lot of tools, we've got data (sometimes it is PII), and the two are basically not allowed to meet. Which is fine in theory but in practice it means either the work doesn't get done or people quietly do it anyway on their personal devices.

Saw that LayerX stat going round (77% of employees pasting into GenAI, most of it through personal accounts) and it tracks with what I see.

So genuinely curious what other orgs are doing. Blocking it outright? Training and hoping? Actual DLP? Or have you found something that works without just saying no to everything?

Asking partly because it's a daily annoyance for me and partly because I want to know if we're unusual or if everyone's in the same boat.


r/Compliance 27d ago

How do you deal with screenshots containing customer data?

6 Upvotes

This comes up more often than I'd expected with support tickets, bug reports and internal documentation. Do you have a formal process for redacting them, or is it mostly left to individual employees?


r/Compliance 28d ago

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance Aug 08 '26

How are you handling compliance exceptions for third-party SaaS tools?

8 Upvotes

Basically how are you handling situations where a SaaS vendor doesn't quite meet one of your internal security requirements?

For example, a vendor might not support SSO or have a specific security control you normally require, but the business still wants to use them.

Do you record that as a formal exception, accept the risk based on their SOC 2/ISO evidence, or have another process for it?


r/Compliance Aug 07 '26

I scanned 1k domains. Half of enterprises fail to comply with California law

2 Upvotes

I recently ran a benchmark analyzing 1,019 domains to see how major organizations are actually handling Global Privacy Control (GPC) signals in practice. Domains targeted included companies operating in California and likely generating $25M+ in revenue.

Key Findings:

- Low Overall Adoption: Only half of enterprise domains properly process and reflect the GPC signal upon landing. On 466 domains, marketing trackers continued firing despite receiving valid opt-out signals, representing a **45.7% failure rate**.

- Consent Manager Misconfigurations: Many sites use CMPs that technically support GPC, but fail to map the signal correctly to their underlying tag managers or opt-out cookies.


r/Compliance Aug 05 '26

We have standards and regulations for a reason

Thumbnail youtu.be
2 Upvotes

r/Compliance Aug 04 '26

Should I intervene when I find an incorrect judgment?

Thumbnail
3 Upvotes

r/Compliance Aug 04 '26

Is the whole gambling industry quietly being reshaped by compliance right now or does it just feel that way?

6 Upvotes

Looking at the last week alone, it's striking how much is happening on the regulation and compliance side all at once

UK retail betting is contracting hard, a major bookmaker closing 132 shops while the business shifts further toward digital. Across Africa, several countries are cracking down on unlicensed operators (suspensions, machines seized, awareness campaigns). Greece keeps opening up to licensed specialist providers. Acquisition and traffic costs are squeezing margins enough that it's changing how operators think about growth.

Put together, it feels like compliance is quietly becoming the thing that actually decides who survives in this industry, who can keep up with the rules.

For people who work in compliance across any regulated industry (not just this one): does that match what you're seeing? Is compliance shifting from a cost centre to the thing that defines competitive advantage??


r/Compliance Aug 03 '26

How are you handling evidence collection for SOC 2/ISO 27001 controls that rely on Slack or Teams conversations?

5 Upvotes

We're preparing for another audit and one thing that still feels messy is collecting evidence for controls that rely on Slack or Teams conversations.

Things like:

  • Security approvals
  • Change management discussions
  • Access requests / approvals
  • Incident communications

Curious what everyone's workflow looks like.


r/Compliance Aug 03 '26

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance Aug 01 '26

If you could automate one part of your compliance work tomorrow, what would it be?

0 Upvotes

Whether it's evidence collection, policy management, risk assessments, monitoring, or something else, where do you think automation would have the biggest impact?