Audit, risk & compliance, made legible.
Regulatory news written from the day's enforcement actions, plain-English guides to the frameworks you actually get audited against, and a working glossary of the terms — kept current, automatically.
From the newsdesk
All news →A Slight Hiccup in the Financial Reporting Cycle
The press release likely framed it as a sophisticated cyberattack, an external predator breaching the perimeter to disrupt operations at Asahi Group Holdings. But if you follow the…
The gap between security and control
Asahi Group Holdings recently flagged a material weakness in its internal controls over financial reporting following a ransomware attack. For those who live in IT security, the in…
Framework hub
All frameworks →SOC 2
An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.
ISO 27001
The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.
PCI DSS
The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.
GDPR
The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.
NIS2
The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.
EU AI Act
The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.
Cyber Resilience Act
Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.
HIPAA
The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.
DORA
Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.
SOX
The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.
NIST CSF 2.0
The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.
SEC Cyber Disclosure
The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.
UK PSTI
The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.
ISO 42001
The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.
Auditen glossary
Full glossary →Recent wire updates
The Wire →The US Senate is moving toward confirming John Crews to the board of the National Credit Union Administration (NCUA).
DataShyre has launched an AI-powered cookie consent manager designed for GDPR compliance.
A Supreme Court decision has created new legal uncertainties regarding the transfer of data between the European Union and the United States.
The article discusses the need for firms to prepare and update their GDPR training in anticipation of the Data (Use and Access) Act.
Columbia Banking System appointed Simone Lagomarsino to its Board of Directors and the Audit and ERM Committees.
The FTC has sued Hims & Hers Health, Inc. for allegedly sharing sensitive health data without proper authorization.