Sveriges mest populära poddar
Compliance Unfiltered With Adam Goslin

Making Sure Your Compliance Program Keeps Up - Episode 227

22 min30 juli 2026

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up. Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations.

Episode Transcript:

Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic.

How far behind is your compliance program, and how would you even know, Adam?

Adam Goslin:
My compliance program’s amazing.

Todd Coshow:
Answering the philosophical question, not being a smartass.

Adam Goslin:
A lot of organizations don’t know.

Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak.

Part of the problem is that the expectations are changing fast these days.

You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation.

In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.”

Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.”

But from the outside perspective, you’re starting off already behind the eight ball, if you will.

Todd Coshow:
It definitely feels that way.

It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that?

Adam Goslin:
Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable.

Kind of a combination of boogeyman sense and Skynet vibes going on.

Effectively, it’s a matter of risk is moving faster than regulators are comfortable with.

AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time.

You’re seeing a lot of changes happening.

Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc.

AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws.

It’s a lot of different things all simultaneously churning.

It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there.

In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up.

Todd Coshow:
Where do organizations tend to fall apart when responding to all of this change?

Adam Goslin:
A lot of times they’ll treat each regulation like a separate project.

Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream.

In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.




Fler avsnitt av Compliance Unfiltered With Adam Goslin

Visa alla avsnitt av Compliance Unfiltered With Adam Goslin

Compliance Unfiltered With Adam Goslin med Total Compliance Tracking finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.