top of page
BLOG


Anatomy of Compliance Risk
Everything happens in the presence of uncertainty, and this uncertainty creates the opportunity for risk.


Are You Neglecting Your Compliance Boundary?
When it comes to compliance there is a boundary that exists between what is inside an organization and what is outside. This compliance...


Taming the Dragon of Uncertainty
When it comes to business, life, and of course compliance, there are dragons that come across our path that cannot or should not be...


A New Year and A New Framework for Risk Management
Over the last several years what is traditionally called risk management has undergone significant criticism from professionals,...


Obligation’s Hierarchy of Needs
Not all obligations are the same or require the same capabilities or approaches to satisfy. Knowing the differences can help you better...


Surprise me now, surprise me later, but never say I am not surprised.
When it comes to risk & compliance no one wants to be surprised. That’s why organizations put in place controls of various kinds to avoid...


How to Make Compliance Soar
Compliance is often considered as a hindrance more than a help. Many organizations believe that they might do better if they were less...


The Taxonomy of an Obligation
When it comes to improving compliance it is important to know not only what your obligations are but also how each obligation has been designed to perform the regulation function. Knowing this will help organizations better understand what is needed to meet their obligations by understanding: The level of compliance rigour required. The level of support needed from leadership and management Controls that may need to be established Who is accountability for which part (self, i


Finding Good Dragons
Compliance at its core is about contending with risk. For the most part this has taken the form of addressing the negative side to...


Are Your Risk Measures Valid?
In this article we take a look at the nature of risk reduction controls through the lens of barrier analysis. This is a common practice...


The Cost of Obligation Debt
The notion of debt or more specifically technical debt has proven to be a helpful metaphor when discussing financial costs with respect...


How Do We Manage Cyber Safety - Part 3
This blog post continues our series on Cyber Safety where we have explored various standards, frameworks and guidelines to address management vulnerabilities with respect to achieving cyber safety objectives. In this week's post we consider steps you can take to select which approach is best for you to start improving your cyber safety. Steps to Strengthen your Defences 1. Evaluate Defences & Develop Improvement Roadmap The framework or standard you choose depends on the ri


An Objective View of Obligations
ISO 19600 and 37301 define compliance as the outcome of meeting a company's obligations. These obligations arise from such things as...


How Do We Manage Cyber Safety - Part 2
This blog post is a continuation in our series on Cyber Safety. In this article we explore several guidelines, standards, and frameworks available to help organizations realize their cyber safety goals. We will begin with a framework from The Canadian Centre for Cyber Security followed by three from the US, and one from the International Standards Organization (ISO). Let’s start with the Canadian program. CyberSecure Canada Program The Canadian Centre for Cybersecurity is a


Manage Legal Risk with ISO 31022:2020
Earlier this year (May 2020) the International Standards Organization (ISO) published their legal risk management guidelines, ISO...


Seeing Compliance as a Whole
When it comes to compliance many believe that it all comes down to integrity. When it comes to integrity, according to Dr. Henry Cloud,...
bottom of page
