Audit, risk & compliance, made legible.
Regulatory news written from the day's enforcement actions, plain-English guides to the frameworks you actually get audited against, and a working glossary of the terms — kept current, automatically.
From the newsdesk
All news →Tomorrow the AI fines begin
August 2 is the date. That's when the EU begins hitting generative AI firms with fines for non-compliance with the AI Act. The most critical bit for anyone actually running a busin…
Is Your API Provider Your Compliance Officer?
The EU AI Act's chatbot disclosure rules hit this Sunday. For a small firm, the instinctive move is to ping the account manager at your LLM provider and ask why they haven't added …
The API Is Compliant. The Customer Is Not.
If you think your SaaS agreement is a shield against regulatory fines, you’re in for a very expensive surprise.…
Framework hub
All frameworks →SOC 2
An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.
ISO 27001
The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.
PCI DSS
The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.
GDPR
The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.
NIS2
The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.
EU AI Act
The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.
Cyber Resilience Act
Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.
HIPAA
The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.
DORA
Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.
SOX
The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.
NIST CSF 2.0
The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.
SEC Cyber Disclosure
The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.
UK PSTI
The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.
ISO 42001
The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.
Auditen glossary
Full glossary →Recent wire updates
The Wire →Eisner Advisory Group has agreed to settle a class action lawsuit for $1.05 million following a data breach.
KT faces a penalty of 54 billion won due to data breaches and unauthorized payments.
Coupang was found liable for compensation in a South Korean data breach mediation process.
Amazon announced its Q2 2026 financial results and SEC filings.
The EU AI Act has been updated with eight finalized compliance changes via the Digital Omnibus.
RTG is projecting US$100 million in revenue following a strong half-year financial performance.