News & Analysis as of

Risk Assessment Risk Management Regulatory Requirements

Robinson+Cole Data Privacy + Security Insider

CISO’s: Take a Look at CSC’s CISO Outlook 2025 Report

Cybersecurity firm CSC recently issued its CISO Outlook 2025 Report, which predicts cybersecurity challenges CISOs will face in the next year. The report, from a survey of 300 CISOs and cybersecurity professionals globally,...more

Sheppard Mullin Richter & Hampton LLP

North Dakota Passes New Data Security Law for “Financial Corporations”

North Dakota recently passed a law establishing new rules for certain financial companies operating in the state – specifically “financial corporations.” The new obligations will take effect on August 1, 2025. They will apply...more

White & Case LLP

AI Watch: Global regulatory tracker - Brazil (UPDATED)

White & Case LLP on

Brazil intends to regulate AI through Bill No. 2,338/2023 ("Brazil's Proposed AI Regulation"), although there are currently no specific codified laws, statutory rules or regulations in Brazil that directly regulate AI....more

Health Care Compliance Association (HCCA)

Healthcare Enterprise Risk Management

Risk assessments are not new in healthcare, and in specific regulatory areas are required. But, that doesn’t mean things aren’t changing. More and more organizations are embracing enterprise risk assessments (ERM) as a way...more

Venable LLP

A Closer Look at the Data Security Requirements in DOJ's Bulk Data Rule

Venable LLP on

As described in an earlier alert, the Department of Justice (DOJ) recently announced a 90-day pause in enforcement of the "Bulk Data Rule" for entities engaging in good faith compliance. That 90-day grace period ends on July...more

Bergeson & Campbell, P.C.

TSCA Section 21 Petition Seeks Reconsideration of 2024 Rule Regarding Procedures for Chemical Risk Evaluation

On May 15, 2025, the Center for Environmental Accountability (CEA) filed a petition under Section 21 of the Toxic Substances Control Act (TSCA) requesting that the U.S. Environmental Protection Agency (EPA) reconsider the...more

Mayer Brown

Country Classification, Updated FAQ and Guidance, Draft Delegated Regulation: EUDR Compliance Made Easier?

Mayer Brown on

On 22 May 2025, the European Commission (“Commission”) made public risk classification of countries under the EU Deforestation Regulation (“EUDR”)1 which assigned a low level of risk to 140 countries and high level of risk to...more

Alston & Bird

5 Things to Think About When Using AI

Alston & Bird on

What Happened? As the Trump Administration’s deregulatory, pro-innovation approach to emerging technology moves forward, the use of artificial intelligence has taken center stage, and it is clear that the Administration...more

SEC Compliance Consultants, Inc. (SEC³)

Top Compliance Program Mistakes (and How to Avoid Them) (Part 1 of 2)

Chief Compliance Officers face the challenge of running a comprehensive yet efficient compliance program that nimbly adapts to changing regulatory requirements and business practices. As compliance consultants, we see our...more

Mitratech Holdings, Inc

6 Overlooked Strategies That Strengthen ISO 22301 Compliance

When disruption strikes—be it a cyberattack, supply chain failure, or extreme weather—your systems and team’s ability to respond with speed, clarity, and confidence are tested....more

Osano

3 Ways GRC Pros Can Manage Privacy Risk (and Still Have Time to Sleep, Eat, and Relax)

Osano on

Governance, risk, and compliance (GRC) can feel like thankless work at times. You can’t ship risk mitigation to market. It's not usually reflected on your balance sheet. Only especially canny investors notice the absence of...more

Bergeson & Campbell, P.C.

Setting the Record Straight: New Chemical Review Needs Scientists

On May 2, 2025, U.S. Environmental Protection Agency (EPA) Administrator Lee Zeldin announced the “[n]ext phase of organizational improvements to better integrate science into agency offices.” As part of this reorganization...more

Miles & Stockbridge P.C.

Despite Reduced Enforcement Risks, Businesses Should Invest in Corporate Compliance

Some early actions by the Trump administration have led corporate legal departments to question the extent to which they need to invest in ethics and compliance at this time, based on a perceived reduction in enforcement...more

Carlton Fields

NAIC Big Data Working Group Continues Building a Regulatory Structure

Carlton Fields on

During the NAIC Spring National Meeting, the Big Data and Artificial Intelligence (H) Working Group reviewed its blueprint to build an overarching regulatory edifice to oversee insurers’ use of artificial intelligence...more

Osano

How to Shift Data Privacy Left

Osano on

The 1:10:100 rule—coined in 1992 by George Labovitz and Yu Sang Chang, the rule describes how much bad data costs. Preventing the creation of bad data at its source costs $1. Remediating bad data costs $10. Doing nothing...more

White & Case LLP

NERC Tees Up Plan to Assess Grid Risks Associated with Data Centers

White & Case LLP on

The North American Electric Reliability Corporation (NERC) outlined forthcoming activities to identify and address the potential impacts to reliability as a result of the rapid expansion of data centers and other large...more

Husch Blackwell LLP

Effective Dates Draw Near for Insurance Industry to Comply with NYDFS's Cybersecurity Rules

Husch Blackwell LLP on

As part of a multiyear rollout, the New York Department of Financial Services (NYDFS) has established May 1, 2025, and November 1, 2025, as effective dates for certain amendments to its cybersecurity regulations. These...more

Ankura

Generative AI Risks: Legal and Compliance Insights - Part 2

Ankura on

The Bottomline: Five Practical Steps for Generative AI Risk Management - As the first line of defense, employees within business operations must own and manage risks related to the business, including risks resulting from...more

K2 Integrity

A Collaborative Approach to Customer Risk Assessment

K2 Integrity on

Unlock a New Era of Customer Risk Assessment - Legacy customer risk rating (CRR) models—built on static KYC data and subjective judgment—are no longer sufficient in a world of dynamic threats and tightening regulatory...more

Gardner Law

From Paper to Practice: Compliance Policies that Work

Gardner Law on

In the FDA-regulated industry, a compliance program isn’t just a formality—it’s a critical tool for protecting your business, patients, and reputation. Still, too many companies treat compliance policies as static...more

Opportune LLP

Litigation Trends: Navigating Legal Risks for Midstream Oil & Gas

Opportune LLP on

The midstream oil and gas industry, a vital artery of the energy sector encompassing crucial transportation and storage infrastructure, operates within a highly competitive and intensely scrutinized market. Beyond the usual...more

Ankura

Remediation Happens: How To Identify, Mitigate and Resolve Related Risks

Ankura on

Remediation occurs for a host of reasons. You may identify remediation risk from internal activities (e.g., an audit, a control break) or external activities (e.g., a complaint, a regulatory exam, a lawsuit). Sometimes a...more

Mitchell, Williams, Selig, Gates & Woodyard,...

Water Risk and Resilience Organization: Congressman Rick Crawford (Arkansas) Introduces Legislation to Address Risk/Resilience...

Congressman Rick Crawford of Arkansas’ First District introduced H.R. 2594 which is titled: Establishment of the Water Risk and Resilience Organization. The Bill would establish a Water Risk and Resilience...more

NAVEX

Preparing for the Compliance Challenges of Agentic AI

NAVEX on

Artificial intelligence keeps improving at all sorts of things – including how to challenge corporate ethics and compliance programs. Even while you may still be struggling to tame the risks of generative AI, its more...more

Quarles & Brady LLP

New York Cybersecurity Regulation Requires Submission of Compliance Certification or Acknowledgement of Noncompliance Next Week

Quarles & Brady LLP on

On April 3, 2025, the New York State Department of Financial Services (“DFS”) issued reminders about upcoming implementation and reporting deadlines related to its cybersecurity regulations. Upcoming deadlines require...more

128 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide