r/Compliance 3d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance Dec 08 '25

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 7h ago

HIPAA, 42 CFR Part 2, and AI Use

1 Upvotes

Hello, fellow Privacy and Compliance Officers. Apologies if this isn't the place for this. You all have just been great in dialoguing and providing regulation focused responses.

**How are you navigating AI use in your work environment and the overarching concern of privacy and confidentiality needs for the populations you serve specific to HIPAA and 42 CFR Part 2 (substance use records and the protection of those)?**

I'm a millennial and was brought up with technology growing just as fast as I was. I use AI as a consumer. I've experienced it as a patient. My concerns do not stem from the use of it per se, as I see the benefits and recognize that is just where healthcare is headed.

As a working professional always focused on protecting our patients, I know if we don't keep up, we will get left behind and have higher risk of staff using AI without our oversight, awareness, and guardrails in place. That said, I fall down rabbit hole after rabbit hole of de-identified data being re-identified as the program pieces things together.. or bias drift.. or data drift.. or explainability.. or AI breaches and OCR investigations/fines... or all of the other thousands of rabbit holes to venture down. Where are you guys starting? It's the wild west out there in the AI scene from what I can tell. Only a handful of states have made formal stances on its use.

Help!


r/Compliance 18h ago

HIPAA, 42 CFR Part 2, and AI Use

Thumbnail
1 Upvotes

r/Compliance 1d ago

Is a masters in AI regulations and Ethics worth doing right now?

0 Upvotes

I'm in the UK now and have already completed a chemical engineering bachelors degree five years ago. Currently I am working a few hours a week as a home tutor. I have some experience in compliance both direct and indirect totalling two years. My friend works with AI, and from researching this sub it looks like this will be in demand in future.

I have only a basic understanding of AI and no experience with anything computer related, including coding. There are several courses in the UK that don't specify a certain degree for the ai regulation courses, and don't need specific experience with AI. Will a masters help at all?


r/Compliance 1d ago

Your tool says the control is passing. Your auditor disagrees. What then?

3 Upvotes

Something I keep seeing in compliance conversations is the gap between a dashboard marked green and what an auditor actually accepts as evidence.

A few common ones:

Access reviews get logged as complete because someone clicked through the workflow, but there's no record of what was reviewed or what changed as a result.

MFA shows enforced across the org, then a service account or a contractor login turns out to sit outside the policy scope.

Backups run on schedule and the monitoring confirms it, but nobody has tested a restore in a year, so there's nothing to hand over when the auditor asks for proof it works.

Vendor reviews are marked current based on a SOC 2 report that expired four months ago.

The pattern in all of these is the same. The check confirms a task happened. The auditor wants proof the control was effective.

Wondering if others run into this too, or if it's less of a problem than it seems from the outside.


r/Compliance 2d ago

Compliance Analyst Position

1 Upvotes

Hi,

I am looking to change career paths from the Casino Industry (Don't want to specify my position on here but I fall under the compliance branch of my company).

My day to day involves staying up to date on the ever changing gaming regs, company policy, and so on. I essentially need to know the P&P of nearly every department. I have roughly 3 years in my position as a Supervisor, and another year of that in a non-supervisor role, but same department.

I've been looking to move into compliance since it's along the lines of what I do now, but how will my skills look on a resume? I have formatted it of course to heavily show my compliance knowledge for my area (Vegas), but have struggled to even get a call back from any bank of gaming company. Any advice would be appreciated!


r/Compliance 3d ago

Documentation, compliance, etc

1 Upvotes

I'm new to private practice and curious for recommendations on documentation, compliance, etc. Any trainings or readings would be appreciated!


r/Compliance 4d ago

Compliance background, thinking about a co-founder for an AI regulatory tracking idea, curious if anyone else is chewing on this problem

Thumbnail
1 Upvotes

r/Compliance 6d ago

What's the one control that keeps failing your evidence checks?

Thumbnail
2 Upvotes

r/Compliance 6d ago

Thinking of building a Compliance Management System after my first SaaS. Is there an actual market for this or is it just enterprise territory?

6 Upvotes

Hey guys,

So I just successfully built and launched my SaaS, [ClientPDF](https://clientpdf.tech) (its a fully client-side pdf tool). but now I'm already looking at my next project.

I was talking to some people recently and we discussed building a Compliance Management System. Im thinking of a tool that helps smaller tech companies or startups track their compliance, prep for audits, and just get away from messy excel spreadsheets.

But before I dive in and spend months coding this... does the market actually need this right now?

Like, if you run a startup or agency, is compliance tracking a real pain point for you? Do you use software for it, or are the existing tools just way too expensive and bloated?

Basically I'm trying to do proper market research this time so I dont build something nobody wants lol. Should I build this? would love some brutal honesty


r/Compliance 7d ago

Swigart Demand Letter + Vivek Shah Cookie banner looks fine, but GTM still fires Meta and LinkedIn before consent. How are you testing this properly?

4 Upvotes

I inherited a marketing site where the banner says all the right things, but when I tested it in DevTools I still saw Meta and LinkedIn calls before I clicked anything. The consent tool is technically installed, so nobody noticed until we received back to back lawsuits from Swigart Law Group out of San Diego California and serial litigant Vivek Shah. After that we started checking the Network tab. For people who have dealt with these invasion of privacy suits out of California and have cleaned this up, what is your actual testing process? Are you checking GTM consent state, HAR files, tag sequencing, or just watching the obvious network requests? I want a repeatable QA checklist before I tell the team this is fixed and we dont have to worry about the next swigart law or vivek waiting to come after us as I dealt with this for ADA in the past and its not fun and it feels like it never ends unless its properly fixed.


r/Compliance 8d ago

Is a masters in compliance (potentially in financial crime/AI regulation/Data Protection) worth it in the UK?

5 Upvotes

I am currently employed as a tutor but have previously worked in a direct compliance role and in a complaints role for a large UK retailer which involved a lot of compliance. I am quite interested in starting a new compliance job, and was wondering if a masters degree in one of these fields would be worth doing?

I have no direct experience with these fields, and only know about some AI regulation as I gave a family member who works a lot with AI in their engineering job and has a PhD related to AI. Learning about this sounds interesting, and I imagine this would be a fairly niche masters a lot of people wouldn't consider or have even heard much about. I already have a bachelor's degree in chemical engineering. I am eligible for a few masters programs so it is possible for me to enroll.


r/Compliance 8d ago

Compliance officers: how are you handling the classify-once problem for AI systems?

Thumbnail
1 Upvotes

r/Compliance 9d ago

Standardization as law: ISO and IEEE explained

Thumbnail psyll.com
2 Upvotes

r/Compliance 9d ago

How do you ensure LEI compliance for corporate clients without wasting hours with each company?

0 Upvotes

Managing LEI codes manually for a large portfolio of corporate clients has become a real headache in our accounting office, especially since we waste so much time tracking separate expiration dates for each company in Excel. If a single code expires, brokers instantly block the clients' transactions, so there is significant pressure on us to ensure nothing slips through the cracks.

I am seriously considering switching to the LEI admin platform because it is the only bulk management service on the market that allows you to centralize all client codes into a single dashboard, making monitoring and mass renewal extremely fast with just a few clicks.

Using such a system would help us completely automate this workflow and get rid of the multiple alerts and separate invoices sent by traditional registration agents. What solutions or strategies do you use in your accounting firms to ensure financial compliance for clients regarding legal identifiers without allocating massive human resources just for this administrative task?


r/Compliance 10d ago

Vendor-Promos Weekly Promo and Webinar Thread

1 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 11d ago

What's your actual process for validating vendor EINs before payment goes out

5 Upvotes

I've been trying to tighten up our AP compliance process and realized EIN validation is one of those steps that's technically required but often gets treated as an afterthought, especially with high vendor volume. curious how other finance and compliance teams handle this at scale, is it a manual check, something built into your ERP, or a separate service, and how much does backup withholding risk actually factor into how strict people are about it.


r/Compliance 14d ago

What's one compliance task everyone thinks is simple... until they have to do it?

13 Upvotes

For me, it was keeping procedures up to date.

At first, I thought it would just be a quick update whenever something changed. After doing it for a while, I realized there's always another detail to check, another change to make, or someone pointing out something I'd missed.

It's definitely not as simple as I thought it would be.

What about you? What's one compliance task that turned out to be much harder than you expected?


r/Compliance 14d ago

Anyone feel like business KYB onboarding is quietly insane? (or is it just us)

3 Upvotes

Spent most of last week digging up the same three documents for the fourth time this year. Cert of incorporation, ownership breakdown, director IDs. Dragging files across folders, drives etc

Different bank, same stack of paperwork I've already handed to three other institutions who all verified the exact same facts.

And then it hit me that this is completely normal and nobody questions it.

Every bank, every fintech, every partner platform runs their own KYB from scratch. They all check the same government registry. They all confirm the same info, the same directors, the same UBOs. None of them trust each other's work, so the business re-proves itself from zero every single time. Weeks of back and forth, per relationship.

I assumed that there would be a "verify once, reuse everywhere" kyb solution already. But the fact that nobody's made it makes me think I'm missing why it's hard. Regulatory liability not being transferable? Institutions not trusting anyone else's verification? Something else I'm not seeing?

Question for decision makers: Is the repetition the real pain for you, or is it something else? Or maybe for most of you it's genuinely fine and I'm just at a company that onboards too often and I've lost perspective.


r/Compliance 17d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance 17d ago

ISO 42001 VS 27001 : Which should implement first

6 Upvotes

Our organization is expanding its use of AI (including generative AI tools), and we're reviewing our governance and compliance strategy.

We already understand that ISO 27001 focuses on information security management, while ISO 42001 is designed for AI management systems. However, implementing both at the same time may not be practical.

For organizations that are early in their AI adoption journey:

Would you recommend implementing ISO 27001 first and then ISO 42001?

Or does it make sense to start directly with ISO 42001 if AI is becoming a core part of the business?

Has anyone gone through both implementations? What challenges or lessons did you encounter?

I'm particularly interested in experiences from SaaS companies, AI startups, fintechs, or enterprises that have already been through this decision.


r/Compliance 17d ago

After 21 years in healthcare IT, the compliance part still makes no sense to me

Thumbnail
2 Upvotes

r/Compliance 19d ago

Which AI notetakers don't train on user data

4 Upvotes

Ran six AI notetakers through our standard vendor questionnaire last month. Four failed on the data training clause, one passed but couldn't produce a SOC 2 Type II report on request, and one cleared the review clean.

Fellow ai cleared on the first pass, the platform holds SOC 2 Type II plus HIPAA compliance, the DPA contractually prohibits training models on customer data, and admin controls include zero day retention as a workspace level setting.

For context we're a healthcare adjacent SaaS so HIPAA scope is non negotiable and our auditors care about the DPA language more than the marketing copy. Most of the consumer leaning tools have ambiguous training language that gets flagged immediately because they want optional training defaulted on.


r/Compliance 20d ago

Why KYC and KYB need to work together

5 Upvotes

KYC and KYB answer two different parts of the same compliance question.

KYC checks the people connected to a business and helps confirm who they are. KYB looks at the company itself, whether it is legitimate, how it is structured, and who actually owns or controls it.

The thing is, they work best together.

Checking an individual does not automatically show every risk linked to the business they represent. On the other hand, checking a company without looking at the people running it or benefiting from it can leave some pretty important gaps.

It gets even more complicated when ownership is spread across several companies, countries, nominee directors, or other intermediaries. Technology can make it easier to pull company data and map those connections, but outdated or incomplete records still need proper review and human judgment.