Auditen

Audit, risk & compliance, made legible.

Regulatory news written from the day's enforcement actions, plain-English guides to the frameworks you actually get audited against, and a working glossary of the terms — kept current, automatically.

From the newsdesk

All news →

Framework hub

All frameworks →
AICPA Tier 1

SOC 2

An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.

11 guides
ISO/IEC Tier 1

ISO 27001

The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.

10 guides
PCI Security Standards Council Tier 1

PCI DSS

The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.

12 guides
European Union Tier 1

GDPR

The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.

10 guides
European Union Tier 1

NIS2

The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.

10 guides
European Union Tier 1

EU AI Act

The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.

14 guides
European Union Tier 1

Cyber Resilience Act

Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.

10 guides
US HHS Tier 1

HIPAA

The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.

9 guides
European Union Tier 1

DORA

Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.

10 guides
US Congress / SEC / PCAOB Tier 1

SOX

The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.

10 guides
NIST Tier 1

NIST CSF 2.0

The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.

10 guides
US SEC Tier 1

SEC Cyber Disclosure

The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.

8 guides
UK Government / OPSS Tier 1

UK PSTI

The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.

8 guides
ISO/IEC Tier 1

ISO 42001

The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.

9 guides

Auditen glossary

Full glossary →

Featured glossary guide

From the glossary

Inherent risk

Inherent risk is the level of risk that exists in a process or system before any controls are implemented to mitigate it. It represents the natural susceptibility of an asset or activity to a threat based on its intrinsic characteristics. This baseline measurement allows practitioners to determine where the most significant vulnerabilities exist regardless of existing safeguards.

Read the full entry →

Recent wire updates

The Wire →
CORRECTION: Senate Moves Closer To Confirming John Crews To NCUA Board - CU Today

The US Senate is moving toward confirming John Crews to the board of the National Credit Union Administration (NCUA).

DataShyre Launches AI-Powered Cookie Consent Manager GDPR - openPR.com

DataShyre has launched an AI-powered cookie consent manager designed for GDPR compliance.

Supreme Court Decision Raises New Questions for EU-US Data Transfers - Skadden, Arps, Slate, Meagher & Flom LLP

A Supreme Court decision has created new legal uncertainties regarding the transfer of data between the European Union and the United States.

GDPR Training in 2026: Is your firm equipped for the Data (Use and Access) Act? - todaysconveyancer.co.uk

The article discusses the need for firms to prepare and update their GDPR training in anticipation of the Data (Use and Access) Act.

Columbia Banking System appoints Simone Lagomarsino to its Board, to join Audit and ERM Committees - TradingView

Columbia Banking System appointed Simone Lagomarsino to its Board of Directors and the Audit and ERM Committees.

FTC Sues Telehealth Firm Hims & Hers Over Data Sharing - BankInfoSecurity

The FTC has sued Hims & Hers Health, Inc. for allegedly sharing sensitive health data without proper authorization.