Auditen
enforcement wrap

Why Fight a Subpoena?

The SEC is suing ISS because the firm refused to hand over documents. This is the most consequential move of the week. It isn't about the specifics of proxy advising; it’s about the sheer arrogance of thinking you can ignore a federal subpoena and come out unscathed.

In my early SOX days, I watched plenty of controllers try to hide deficiencies behind "privileged" labels that had no basis in law. They thought they were being clever. They weren't. When the regulator asks for a file, the only correct answer is the file itself. If you start arguing about the scope of the request while the clock is ticking, you aren't managing risk—you're inviting an enforcement action.

The argument from the ISS camp is likely that the SEC is overreaching into a space where it doesn't belong. That might be true in a vacuum. But in the real world, non-compliance is a trigger. Once you refuse to produce evidence, the regulator stops looking for the original error and starts looking for everything else you've hidden.

This creates a nasty second-order effect for every other proxy advisor and consultant in the sector. Their internal audit teams can no longer mark "Regulatory Compliance" as a green cell on a spreadsheet if their document retention policies are based on "we'll decide what to give them when they ask." The auditors for these firms are now exposed; they've been signing off on governance structures that clearly don't hold up under pressure.

It's an expensive lesson in ego.

Then we have the CNIL hitting a French hospital with a fine of half a million euros after a breach leaked over 700,000 records. I don't care about the fine—half a million is a rounding error for some and a tragedy for others. What matters is what this costs you at year-end. The forensic cleanup, the mandatory notifications, and the inevitable lawsuits from those 700,000 people will dwarf the fine. This is a failure of basic access controls. If your staff can get into records they don't need for their specific job function, you don't have a security system. You have a suggestion box.

The SEC is also moving to scrap the "Pay-to-Play" rule regarding political donations by investment advisers. On the surface, it looks like a win for those tired of red tape. I disagree.

Removing a bright-line regulatory rule doesn't remove the risk of corruption; it just shifts the burden to internal ethics committees. Most of these committees are toothless and lack the backbone to tell a senior partner that their donation to a state treasurer is a conflict of interest. By removing the rule, the SEC hasn't simplified things—they've just made the "conflict of interest" finding much more subjective and harder to defend during an audit.

The only thing that saves a firm in these scenarios is design. Not "theatre," where you have a policy manual that looks great but nobody reads. I mean actual, hard-coded controls that prevent the action from happening in the first place. If you rely on a "culture of integrity" to stop a partner from making an illegal donation or a nurse from snooping through patient files, you've already lost.

I'll be watching to see if the SEC uses this ISS suit to set a new precedent for document production timelines. If they start benchmarking "reasonable time to produce" as something shorter than thirty days, every compliance officer in the city is going to have a very bad quarter.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Why the SEC Should Repeal Its Climate Disclosure Rule - The National Interest Compliance Week (Google News)
  2. CNIL Fines French Hospital €500K, 727K Records Hit [2026] - tech-insider.org Data Privacy (Google News)
  3. SEC Moves to Nix Rule on Investment Adviser, Political Donations - bloomberg.com Compliance Week (Google News)
  4. ISS Faces SEC Enforcement Action Over Document Refusal - coinfomania.com Compliance Week (Google News)
  5. Thailand’s SEC finalizes crypto Travel Rule, effective February 2027 - Bitget Compliance Week (Google News)
  6. Nutex Health Confirms Sensitive Data Stolen in August Cyberattack - The HIPAA Journal InfoSec Compliance (Google News)
  7. ICE plans for robodogs met with concern by privacy experts - FedScoop Data Privacy (Google News)
  8. SEC Moves to Scrap the Pay-to-Play Rule - thewealthadvisor.com Compliance Week (Google News)

How stories are selected and assessed