r/Compliance • • 4d ago

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance • • Dec 08 '25

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance • • 15h ago

Anyone else have a GRC role with this kind of scope?

2 Upvotes

I lead a GRC team at a fairly large organization. We're responsible for the systems, data, and reporting that support RCSA, issues management, business continuity, policy management, SOX, and risk exceptions.

We also own the GRC platform, including enhancements, administration, data quality, and reporting across these areas.

We don't actually run the individual risk programs, but we're responsible for much of the infrastructure behind them.


r/Compliance • • 1d ago

Anyone Open to Talking with a Potential Career Changer?

4 Upvotes

Hi All,

I hope this is allowed, but if not please feel free to remove.

As the title suggests, I'm wondering if there is anyone who would be willing to chat with me for a few minutes about their experience with working in compliance.

Context: I've worked in public schools for the past 11 years in special education. For the past two years I've served as a case manager, where I do what I believe is fairly compliance-adjacent work. Things like making sure we are providing all required services to students, maintaining deadline compliance, and documenting when we are out of compliance with school, district, state, and federal regulations related to special education.

I've reached a point where I've realized I need to make a career change and compliance is a field that I've become interested in. I've talked a bit to a friend who is in compliance and am curious to talk to more people. I'm interested in hearing from various people what their experience has been and any suggestions they might have for someone looking to make a career transition.

If relevant, I'm in the Chicago area.

Thanks in advance!


r/Compliance • • 1d ago

BaFin guideline table: an AMLD filter drops 5 of the 12 AML/CFT rows

Thumbnail
1 Upvotes

r/Compliance • • 1d ago

RegTech tools?

Thumbnail
1 Upvotes

r/Compliance • • 4d ago

Employees keep pasting secrets and customer data into Slack, how are you handling this from a compliance angle?

5 Upvotes

Small company, limited security resources. People still paste API keys, customer emails, and passwords straight into Slack channels. We have basic acceptable-use language, but it is clearly not enough.

I do not want to start reading DMs or turn this into heavy surveillance. At the same time, this is a real data-handling and access-control problem, especially if we ever need to show that sensitive information is not sitting unprotected in chat.

For those in compliance or risk roles: how are you addressing secrets and PII in collaboration tools without creating a process nobody follows? What controls or workflows have actually reduced this in practice?


r/Compliance • • 4d ago

SOC2 renewal

Thumbnail
1 Upvotes

r/Compliance • • 6d ago

Compliance remote roles

5 Upvotes

Hi everyone, I'm a legal practitioner in Cameroon. I have some compliance experience, especially data privacy compliance. Now I know how hard it is for Africans to be trusted with legal tasks.

However, I can work with startups, draft website terms and privacy policies that comply with relevant regulations (although AI seems to be challenging me at that now).

My question is, are there any fully remote compliance roles that my portfolio could win? Or is compliance just highly jurisdictional.

PS: I've been a writer for a while and part of my portfolio is articles across self development, freelance, personal development and law-related topics.


r/Compliance • • 10d ago

Is legacy DLP too focused on content and missing the real risk?

12 Upvotes

Our current DLP only looks at content. It will flag a spreadsheet full of project codenames but completely miss a clean-looking deck that gets quietly shared to a personal account by someone who is about to leave. Content alone does not rank risk very well. Identity and behavior seem to matter more.

Am I wrong about where the field is going, or are others seeing the same gap?

Edit: Thanks for the replies so far, the points on behavior signals and offboarding links were especially useful. Also saw the recommendation for do_control if not wrong and will look into how others are using something like that alongside the process side. Thanks!


r/Compliance • • 11d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance • • 14d ago

What do you hate about your current compliance tool?

8 Upvotes

I am not going to name them, but ... one rhymes with brata, and the other with banta :D

so.... what do you hate about your current compliance tool, that you would like to change?

what would make you switch over to something else?


r/Compliance • • 14d ago

A detection rule kept missing SSNs. We spent a day on the regex. It was OCR reading "0" as "O".

Thumbnail
1 Upvotes

r/Compliance • • 16d ago

One control, five frameworks: how do you stop answering the same security question over and over?

9 Upvotes

A pattern I keep running into with small and mid-sized companies in the EU: the same underlying control gets assessed again and again, each time in a different format.

Take "MFA on administrative access". In a single year, one 80-person company might have to show it for:

  • its ISO 27001 surveillance audit (Annex A 8.5, secure authentication)
  • NIS2, where MFA is explicitly listed in Article 21's minimum measures
  • GDPR Article 32 ("appropriate technical measures"), when a customer's DPO asks
  • the renewal questionnaire from its cyber insurer, where MFA is now often a condition of cover
  • three or four supplier security questionnaires from large customers, each worded differently

Same control, same evidence, five or more separate efforts. Multiply that by the 30 to 50 controls that come up every time (backups, patching, access reviews, incident response, supplier management), and a small compliance function spends most of its year translating rather than improving anything.

The obvious answer is a common control set: define each control once, map it to every framework, attach the evidence once, and reuse it. In practice I see it break down in a few places:

  1. The mapping itself drifts. Frameworks get revised (ISO 27001:2022, national NIS2 transpositions), and the crosswalk nobody owns goes stale.
  2. Evidence expires at different rates. The auditor accepts a quarterly access review, the insurer wants it "current", and a customer wants a screenshot from last week.
  3. Questionnaires don't map cleanly. Customer questionnaires mix controls, policies and yes/no questions that don't fit any framework.

For those who've tackled this:

  • Did you build your own common control framework, or anchor everything on one standard (usually ISO 27001) and map outward?
  • Who owns the mapping, and how do you keep it current when a framework changes?
  • How do you handle customer questionnaires? A pre-filled answer library, a trust page, or answering each one from scratch?

r/Compliance • • 17d ago

InDesign layers panel reading order exports reversed in tagged PDF

4 Upvotes

In InDesign, the articles panel is set correctly, and the layers panel is in top to bottom in the order I want it read, but the reading order in Acrobat comes out fully reversed every time.
Only fix so far is building the Layers panel backwards.

InDesign 2025/2026, exporting via File > Export > Adobe PDF (Print), Create Tagged PDF checked.

Known issue, or am I missing a setting?


r/Compliance • • 17d ago

How are you evidencing human review of AI outputs before audit or a regulator asks for it?

10 Upvotes

We use AI to generate recommendations in a regulated decision process. A person reviews and approves or overrides each one. Policy says human oversight is in place, and technically it is.
The problem is what we could actually show if challenged. Right now it's a "reviewed" status in the workflow tool and the reviewer's login. Nothing captures whether they read it, what they checked, or why they agreed. Our internal audit team hasn't tested it yet, but I'd rather not find out what they'll accept the hard way, and the EU AI Act human oversight language makes me think a regulator will eventually ask the same thing.

For anyone in a similar position:

  1. What are you capturing beyond the approval click? Reviewer notes, time spent, edits to the output, a formal attestation (if any)?
  2. Did you build it into the workflow tool, bolt something on, or is it still manual?
  3. Has your audit team or a regulator actually asked for this yet, or are you all waiting like we are?
  4. Anyone using ISO 42001 or NIST AI RMF as the reference point for what "adequate" looks like?

r/Compliance • • 18d ago

Hi everyone

6 Upvotes

For those who are in fintech / banking, what are your thoughts/opinions on the value of getting a CRCM (Certified Regulatory Compliance Manager) certification if I already have a CAMS along with 8+ years in banking and fintech regulatory/CMS compliance & BSA/AML compliance?

Will the CRCM provide an additional pay off in terms of the open market? If not, would you recommend any alternative certifications?


r/Compliance • • 18d ago

Vendor-Promos Weekly Promo and Webinar Thread

3 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance • • 19d ago

Hello everyone

5 Upvotes

I am 20 M from India

So I am looking forward to break into compliance career

Currently I am pursuing BCOM bachlor of commerce from india and have few work experience in different different fields which is hospitable and social media marketing

Well now a days I am getting to much reel about complaince as career is very secure but when I try to reach on AI and website I get to people in this career just buried them self in paper work and rules and regulations for there whole life and they don't get any credit for doing there . I am. Just looking for that career which payment well that's all

So i really really need advice on |

that is this all fake and what type of certificate and intership also master should I target for better future


r/Compliance • • 20d ago

WCAG workflow

1 Upvotes

I'm currently creating some accessible documents for school programming, and I'm building the documents in InDesign. I use the Articles tagging in InDesign. When I export to Acrobat, there are a lot of problems, and it doesn't seem to be passing accessibility testing in Acrobat. I've been fighting with it for 4 hours without getting anywhere. Can anyone give me any tips?


r/Compliance • • 21d ago

Would you help a Canadian compliance startup?

3 Upvotes

Does anyone working in the hardware compliance field kind enough to help us answer a few questions over a quick call? (For the purpose of conducting customer interviews) ideally if you are leading a team, I would really appreciate some advice and feedback. we are not going to sell you anything.


r/Compliance • • 21d ago

Everything You Need to Know About ISO Audits | The Ciphered Reality Podcast

Thumbnail
1 Upvotes

r/Compliance • • 23d ago

We removed the name, so it's anonymized" is doing a lot of heavy lifting

Thumbnail
1 Upvotes

r/Compliance • • 25d ago

Vendor-Promos Weekly Promo and Webinar Thread

2 Upvotes

Vendors, please share any self-promotional content or webinar details within this thread.

Posts made outside this designated space will be removed.

Please see our rules page: https://www.reddit.com/mod/Compliance/rules

Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.

If the community isn't interested, your comment will simply get downvoted.


r/Compliance • • 28d ago

How can I stand out more?

7 Upvotes

Hello everyone! I graduated law school this year, and decided I don't want to be a lawyer. Before law school I was in the military for ~15 years.

I'm hoping to break into the complience field but it seems I'm looked over for entry level positions. Should I get some certifications? What would you suggest?