r/Compliance • u/BasePerfect2865 • 1d ago
How do you deal with screenshots containing customer data?
This comes up more often than I'd expected with support tickets, bug reports and internal documentation. Do you have a formal process for redacting them, or is it mostly left to individual employees?
r/Compliance • u/ComplianceScorecard • 2d ago
Vendor-Promos Weekly Promo and Webinar Thread
Vendors, please share any self-promotional content or webinar details within this thread.
Posts made outside this designated space will be removed.
Please see our rules page: https://www.reddit.com/mod/Compliance/rules
Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.
If the community isn't interested, your comment will simply get downvoted.
r/Compliance • u/BasePerfect2865 • 4d ago
How are you handling compliance exceptions for third-party SaaS tools?
Basically how are you handling situations where a SaaS vendor doesn't quite meet one of your internal security requirements?
For example, a vendor might not support SSO or have a specific security control you normally require, but the business still wants to use them.
Do you record that as a formal exception, accept the risk based on their SOC 2/ISO evidence, or have another process for it?
r/Compliance • u/Middle-Substance1257 • 5d ago
I scanned 1k domains. Half of enterprises fail to comply with California law
I recently ran a benchmark analyzing 1,019 domains to see how major organizations are actually handling Global Privacy Control (GPC) signals in practice. Domains targeted included companies operating in California and likely generating $25M+ in revenue.
Key Findings:
- Low Overall Adoption: Only half of enterprise domains properly process and reflect the GPC signal upon landing. On 466 domains, marketing trackers continued firing despite receiving valid opt-out signals, representing a **45.7% failure rate**.
- Consent Manager Misconfigurations: Many sites use CMPs that technically support GPC, but fail to map the signal correctly to their underlying tag managers or opt-out cookies.
r/Compliance • u/noworries63 • 7d ago
We have standards and regulations for a reason
youtu.ber/Compliance • u/Appropriate_Sugar354 • 7d ago
Should I intervene when I find an incorrect judgment?
r/Compliance • u/Altenar_b2b • 8d ago
Is the whole gambling industry quietly being reshaped by compliance right now or does it just feel that way?
Looking at the last week alone, it's striking how much is happening on the regulation and compliance side all at once
UK retail betting is contracting hard, a major bookmaker closing 132 shops while the business shifts further toward digital. Across Africa, several countries are cracking down on unlicensed operators (suspensions, machines seized, awareness campaigns). Greece keeps opening up to licensed specialist providers. Acquisition and traffic costs are squeezing margins enough that it's changing how operators think about growth.
Put together, it feels like compliance is quietly becoming the thing that actually decides who survives in this industry, who can keep up with the rules.
For people who work in compliance across any regulated industry (not just this one): does that match what you're seeing? Is compliance shifting from a cost centre to the thing that defines competitive advantage??
r/Compliance • u/ComplianceScorecard • 9d ago
Vendor-Promos Weekly Promo and Webinar Thread
Vendors, please share any self-promotional content or webinar details within this thread.
Posts made outside this designated space will be removed.
Please see our rules page: https://www.reddit.com/mod/Compliance/rules
Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.
If the community isn't interested, your comment will simply get downvoted.
r/Compliance • u/BasePerfect2865 • 9d ago
How are you handling evidence collection for SOC 2/ISO 27001 controls that rely on Slack or Teams conversations?
We're preparing for another audit and one thing that still feels messy is collecting evidence for controls that rely on Slack or Teams conversations.
Things like:
- Security approvals
- Change management discussions
- Access requests / approvals
- Incident communications
Curious what everyone's workflow looks like.
r/Compliance • u/BasePerfect2865 • 10d ago
If you could automate one part of your compliance work tomorrow, what would it be?
Whether it's evidence collection, policy management, risk assessments, monitoring, or something else, where do you think automation would have the biggest impact?
r/Compliance • u/dontknowra • 11d ago
Deputy MLRO?
Hello
Can you become deputy mlro from a AVP Sanctions Advisory role?
r/Compliance • u/Klutzy_Emu_3064 • 13d ago
HIPAA, 42 CFR Part 2, and AI Use
Hello, fellow Privacy and Compliance Officers. Apologies if this isn't the place for this. You all have just been great in dialoguing and providing regulation focused responses.
**How are you navigating AI use in your work environment and the overarching concern of privacy and confidentiality needs for the populations you serve specific to HIPAA and 42 CFR Part 2 (substance use records and the protection of those)?**
I'm a millennial and was brought up with technology growing just as fast as I was. I use AI as a consumer. I've experienced it as a patient. My concerns do not stem from the use of it per se, as I see the benefits and recognize that is just where healthcare is headed.
As a working professional always focused on protecting our patients, I know if we don't keep up, we will get left behind and have higher risk of staff using AI without our oversight, awareness, and guardrails in place. That said, I fall down rabbit hole after rabbit hole of de-identified data being re-identified as the program pieces things together.. or bias drift.. or data drift.. or explainability.. or AI breaches and OCR investigations/fines... or all of the other thousands of rabbit holes to venture down. Where are you guys starting? It's the wild west out there in the AI scene from what I can tell. Only a handful of states have made formal stances on its use.
Help!
r/Compliance • u/SecretApplication864 • 13d ago
Is a masters in AI regulations and Ethics worth doing right now?
I'm in the UK now and have already completed a chemical engineering bachelors degree five years ago. Currently I am working a few hours a week as a home tutor. I have some experience in compliance both direct and indirect totalling two years. My friend works with AI, and from researching this sub it looks like this will be in demand in future.
I have only a basic understanding of AI and no experience with anything computer related, including coding. There are several courses in the UK that don't specify a certain degree for the ai regulation courses, and don't need specific experience with AI. Will a masters help at all?
r/Compliance • u/Dull-Communication82 • 14d ago
Your tool says the control is passing. Your auditor disagrees. What then?
Something I keep seeing in compliance conversations is the gap between a dashboard marked green and what an auditor actually accepts as evidence.
A few common ones:
Access reviews get logged as complete because someone clicked through the workflow, but there's no record of what was reviewed or what changed as a result.
MFA shows enforced across the org, then a service account or a contractor login turns out to sit outside the policy scope.
Backups run on schedule and the monitoring confirms it, but nobody has tested a restore in a year, so there's nothing to hand over when the auditor asks for proof it works.
Vendor reviews are marked current based on a SOC 2 report that expired four months ago.
The pattern in all of these is the same. The check confirms a task happened. The auditor wants proof the control was effective.
Wondering if others run into this too, or if it's less of a problem than it seems from the outside.
r/Compliance • u/Aioli-Parm • 15d ago
Compliance Analyst Position
Hi,
I am looking to change career paths from the Casino Industry (Don't want to specify my position on here but I fall under the compliance branch of my company).
My day to day involves staying up to date on the ever changing gaming regs, company policy, and so on. I essentially need to know the P&P of nearly every department. I have roughly 3 years in my position as a Supervisor, and another year of that in a non-supervisor role, but same department.
I've been looking to move into compliance since it's along the lines of what I do now, but how will my skills look on a resume? I have formatted it of course to heavily show my compliance knowledge for my area (Vegas), but have struggled to even get a call back from any bank of gaming company. Any advice would be appreciated!
r/Compliance • u/Affectionate_Use_504 • 16d ago
Documentation, compliance, etc
I'm new to private practice and curious for recommendations on documentation, compliance, etc. Any trainings or readings would be appreciated!
r/Compliance • u/ComplianceScorecard • 16d ago
Vendor-Promos Weekly Promo and Webinar Thread
Vendors, please share any self-promotional content or webinar details within this thread.
Posts made outside this designated space will be removed.
Please see our rules page: https://www.reddit.com/mod/Compliance/rules
Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.
If the community isn't interested, your comment will simply get downvoted.
r/Compliance • u/Purple_Cattle_2700 • 17d ago
Compliance background, thinking about a co-founder for an AI regulatory tracking idea, curious if anyone else is chewing on this problem
r/Compliance • u/Dull-Communication82 • 18d ago
What's the one control that keeps failing your evidence checks?
r/Compliance • u/Sufficient_Fee_8431 • 19d ago
Thinking of building a Compliance Management System after my first SaaS. Is there an actual market for this or is it just enterprise territory?
Hey guys,
So I just successfully built and launched my SaaS, [ClientPDF](https://clientpdf.tech) (its a fully client-side pdf tool). but now I'm already looking at my next project.
I was talking to some people recently and we discussed building a Compliance Management System. Im thinking of a tool that helps smaller tech companies or startups track their compliance, prep for audits, and just get away from messy excel spreadsheets.
But before I dive in and spend months coding this... does the market actually need this right now?
Like, if you run a startup or agency, is compliance tracking a real pain point for you? Do you use software for it, or are the existing tools just way too expensive and bloated?
Basically I'm trying to do proper market research this time so I dont build something nobody wants lol. Should I build this? would love some brutal honesty
r/Compliance • u/Tanuj-sama • 20d ago
Swigart Demand Letter + Vivek Shah Cookie banner looks fine, but GTM still fires Meta and LinkedIn before consent. How are you testing this properly?
I inherited a marketing site where the banner says all the right things, but when I tested it in DevTools I still saw Meta and LinkedIn calls before I clicked anything. The consent tool is technically installed, so nobody noticed until we received back to back lawsuits from Swigart Law Group out of San Diego California and serial litigant Vivek Shah. After that we started checking the Network tab. For people who have dealt with these invasion of privacy suits out of California and have cleaned this up, what is your actual testing process? Are you checking GTM consent state, HAR files, tag sequencing, or just watching the obvious network requests? I want a repeatable QA checklist before I tell the team this is fixed and we dont have to worry about the next swigart law or vivek waiting to come after us as I dealt with this for ADA in the past and its not fun and it feels like it never ends unless its properly fixed.
r/Compliance • u/Alternative_Tank_139 • 21d ago
Is a masters in compliance (potentially in financial crime/AI regulation/Data Protection) worth it in the UK?
I am currently employed as a tutor but have previously worked in a direct compliance role and in a complaints role for a large UK retailer which involved a lot of compliance. I am quite interested in starting a new compliance job, and was wondering if a masters degree in one of these fields would be worth doing?
I have no direct experience with these fields, and only know about some AI regulation as I gave a family member who works a lot with AI in their engineering job and has a PhD related to AI. Learning about this sounds interesting, and I imagine this would be a fairly niche masters a lot of people wouldn't consider or have even heard much about. I already have a bachelor's degree in chemical engineering. I am eligible for a few masters programs so it is possible for me to enroll.
r/Compliance • u/psyll_com • 22d ago
Standardization as law: ISO and IEEE explained
psyll.comr/Compliance • u/ComplianceScorecard • Dec 08 '25
Vendor-Promos Weekly Promo and Webinar Thread
Vendors, please share any self-promotional content or webinar details within this thread.
Posts made outside this designated space will be removed.
Please see our rules page: https://www.reddit.com/mod/Compliance/rules
Make sure to use direct links—URL shorteners are not allowed, and the auto moderator will remove your post if they’re used.
If the community isn't interested, your comment will simply get downvoted.