Expect More From Your Whistleblowing Solution

Lean teams hunting for compliance solutions face numerous challenges. Manual spreadsheets stall investigations, evidence becomes hard to pinpoint, and regulatory deadlines—like the EU Whistleblower Directive—loom large. In the meantime, executives expect immediate visibility when a compliance allegation surfaces while HR or legal, doubling as compliance, scramble to stitch data together. The result - culture confidence erodes and costs climb. This is where the right whistleblowing ...

New DOJ FCPA Guidelines: What it Means for You

On June 9, 2025, the Department of Justice (DOJ) issued new DOJ FCPA guidelines that reshape how—and when—the Foreign Corrupt Practices Act (FCPA) will be enforced. The update follows a 180-day pause under Executive Order 14209, which directed prosecutors to stop initiating new FCPA investigations unless tied to national security, cartel activity, or competitive harm to U.S. companies. What is the FCPA? The FCPA prohibits ...

10 Ethics & Compliance Training Challenges – And How to Overcome Them

Ethics & Compliance (E&C) program management can feel like a maze—complex, high pressure and ever-changing. On top of that, many organizations struggle with low employee engagement. But these challenges are not insurmountable.  Below, we outline 10 common barriers to an effective E&C program and show how SAI360 helps organizations cut through the complexity, embed a culture of integrity, and drive lasting impact. Challenge #1: "Our ...

By |2025-07-07T15:21:40+00:00July 7th, 2025|Ethics & Compliance Learning|

How to Build Compliance Teams That Thrive Under Pressure

Tasked with managing risk, navigating uncertainty, and leading with clarity, compliance officers and their teams need to be able to operate under pressure and respond decisively. According to Fabiana Lacerca-Allen, JD, LLM, Chief Compliance Officer at Cipla USA and author of The Crisis Capable Leader, and Brenda Crabtree, former U.S. Naval officer turned Director of Compliance at Vaxcyte, these traits are best honed by leaning ...

By |2025-07-07T13:26:21+00:00July 7th, 2025|Compliance, Governance, Risk & Compliance: GRC|

What CPS 230 Means for Your Supply Chain Security

The Australian Prudential Regulation Authority’s (APRA) CPS 230 mandates critical supply chain risk management updates. Financial institutions reliant on third-party services must pay close attention to this mandate. Why? Supply chain security breaches remain a critical issue, actually now affecting over 75% of software supply chains and involving recent high-profile incidents.   CPS 230 therefore aims to act as a shield to better safeguard organizations. To ...

By |2025-07-02T17:46:48+00:00July 2nd, 2025|Governance, Risk & Compliance: GRC, Regulatory Change|

How to Create a Code of Conduct Policy and Living Code Microsite

Compliance training should not stop at Ethics & Compliance courses alone. Adding both a Code of Conduct Policy and a Living Code Microsite takes it to the next level by making it easier for employees to find relevant information while ensuring ongoing alignment. What is a Living Code of Conduct Microsite? A Living Code turns your policy into an interactive digital environment. It aligns with ...

What is Provision 29? The New UK Internal-Controls Declaration is Here

Does your risk management and internal framework really work? Some companies working in the United Kingdom will need to start proving it. Starting with accounting periods that open either on or after 1 January 2026, every company in either the FCA’s commercial companies or closed-ended investment fund categories must make a statement in its annual report confirming whether its risk management and internal control framework ...

Modern GRC is Keeping Companies Ahead

A cyberattack can catch an organization off guard, creating chaos as teams rush to respond. Executives struggle with outdated spreadsheets, while compliance officers juggle siloed point solutions. Without a clear, coordinated approach, important risks can be overlooked. This scenario is all too real for organizations relying on legacy processes. When dashboards run slow and manual spreadsheets fall short, new gaps emerge out of thin air ...

What Is Integrated Enterprise Risk Management and Why Do You Need It?

Integrated enterprise risk management unites every strand of risk. From strategic, operational, financial, regulatory, cyber, to third-party, all forms of risk become streamlined under one data architecture. When things become more centralized, a streamlined workflow ensues. Instead of juggling separate spreadsheets, dashboards, and point solutions, teams instead tap into a shared information hub featuring a single source of truth. One that feeds real-time insight to ...

Amid Cyber Breaches, Operational Safety Saves the Day

When ransomware halts production lines and phishing attacks cripple control systems, cybersecurity alone isn’t enough. It's merely a start. What's next? Organizations need operational safety as their last line of defense. Operational safety ensures that people, processes, and equipment alike keep running effectively and efficiently, even under attack. From regulatory shocks to climate events to supply-chain failures, operational safety protocols shore up continuity when IT ...

By |2025-07-01T18:29:34+00:00June 24th, 2025|Governance, Risk & Compliance: GRC|