Compliance Unfiltered With Adam Goslin

Total Compliance Tracking

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

  1. Aug 27

    What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

    On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discuss why AI-generated policies often fail in audits and incident reviews, and how to use AI for drafting without losing accountability. Episode Transcript: Today, Adam, we’re gonna talk about what compliance problems arise when AI is writing your policy. So if AI wrote your security policy and no one really reviewed it, whose policy is it? Adam Goslin:I love the compliance problems. That was good. Before I go there, every time that you’re like, “Hey, tell a few friends that may be interested in what we’re doing here,” I always had that thing. I don’t remember what the frick commercial it was back in the day, but it’s like, “And they too tell two friends, and they tell two friends, and so on and so on.” I forget what the hell the topic was. It was like some PSA or something. Todd Coshow:Sounds like a pyramid scheme. I don’t know. Adam Goslin:Nah. I’m gonna be forced to go figure that out now. Anyway, if you just go jam it into AI and it spits out a policy and nobody’s taken a look at it, whose policy is it? AI is becoming a good productive tool for compliance teams. It isn’t a problem to have AI go take a whack at the first draft. The problem is, and quite honestly, this is the same issue that organizations have had now for some time. For some time you’ve been able to go out to whatever, I’m just gonna make it up, like www.writemycompliancepolicyforme.com, and you too can fill in blanks and get some steaming pile of garbage as a policy. Some people literally do. I’ve been doing engagements, and we’re going through the policy for the annual review, etc., and there’s literally placeholders left in the damn policy for where things that they should have filled in, obviously. They didn’t do anything other than take a half-hearted whack at find and replace a couple of times and called it a policy. It’s really no different. When you’ve got AI blasting out the first draft and then you just go ahead and put your signature on the dotted line, it’s not terribly useful. Quite honestly, one of the biggest problems that poses when you’re trying to go through your engagement, the relationship between people going through compliance and the folks that are gonna be assessing compliance, it’s one where there is a certain amount of built-up trust that happens between those parties. There is absolutely no better way to erode any notion of trust building when you’re just serving up what usually is one of the earliest things. Normally when you go and sit down, you go through the overview of the company and what is the scope, and the assessor’s asking all sorts of questions so they can get their arms around it. But the very first thing that they’re actually looking at generally is the policies. Do you wanna start it off on completely the wrong foot? Go have AI write the initial draft and put your signature on the bottom line, or go grab a template policy and you haven’t really reviewed it. Policies are more than just well-written language. It’s literally a written commitment about how the organization is actually operating. If leadership is signing off on policies that aren’t reflective of reality, aren’t reflective of coverage for the various standards that you’re ostensibly going up against, if it isn’t reflecting how you’re actually doing what you’re doing, etc., you’re creating compliance risk in advance of your assessor walking in to bat you over the head. It’s really not a good look when you’re sitting there at your annual assessment or onsite and running square into that wall.

  2. Aug 20

    PCI FAQs When You’re Starting Your Compliance Program - Episode 230

    Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merchant versus service provider responsibilities. Learn why outsourcing payment processing doesn't eliminate your compliance obligations, how scope really works, and why treating PCI as a one-time paperwork exercise creates unnecessary risk. This episode is essential listening for merchants, service providers, and anyone navigating PCI compliance for the first time. Episode Transcript: Now, Adam, a long time ago in a land far, far away, there was a time where you asked the question, “What is PCI?” So bring the listeners up to speed on that. Adam Goslin:Everybody gets their start somewhere, and PCI was definitely mine. I had kinda made my way up the IT management ranks. Boss comes by. Don’t ask me why, he decided to print the entirety of the PCI standards, but literally drops a four-inch deck of paper on my desk and says, “Hey, we need to get compliant with this.” I’m looking at the cover page, and it says PCI on it, and I literally said, “What’s PCI?” So that was my entree into the land of security and compliance. I sat there staring at this volume of information and wondering, “What the hell do I do with this? Where do I go? How do I start?” etc. It’s part of why I decided to step into the space to help people, because I clearly remember just how overwhelming it felt to be looking at that much stuff, not having any clue what the hell it was, what it meant, what it’s for, does it even apply to us, etc. All the way around, it was very overwhelming to step into the compliance arena not already having been initiated. TCT has, both I and TCT have kinda specialized in PCI since our inception, and the consulting work that I was doing for folks in the space, the history of the consulting practice goes back even further than PCI’s existence. As we were sitting there and contemplating the types of things that organizations new to the space are facing, we decided to put together this almost like a frequently asked questions when you’re getting a compliance program off the ground. Frequently asked PCI questions when you’re getting a compliance program off the ground. Todd Coshow:Does PCI apply to merchants who outsource all payment processing? Adam Goslin:It’s one of the common questions that I’ll get. They’ll be like, “Oh, well, we don’t touch anything. We go ahead and outsource all of our payment stuff to blabbity-blah. That’s not my problem, and PCI doesn’t apply to us.” The answer is you’re wrong. Companies that are not storing, processing, transmitting, or receiving cardholder data, they still are subject to the PCI DSS. One of the biggest misunderstandings is, sure, there’s some technical elements of how you’ve done what you’ve done in terms of the connectivity. The devil’s always in the details. If you have a merchant account that is in any way, shape, or form receiving payments via credit cards, then you too get to fill out your PCI paperwork. That’s one of the biggest misunderstandings that organizations have. Honestly, a lot of the big names that have come out in the space over time, the Stripes, the Squares, the Intuits, if you will, back in the day, it was like the Wild West. “Well, I’ll just go get a Stripe account, so I don’t have to worry about this.” “Go process my stuff through Intuit, that way I don’t have to worry about it.” The unfortunate part is that those organizations were on this mad race to get people to jump over to their platform and process their stuff via their platform, but they weren’t really doing a great job with enforcing, mandating that people were actually following the PCI DSS. That kind of became a problem for a while because they were able to go in and easily turn it on, etc., and there wasn’t any enforcement arm that was coming at them.

  3. Aug 13

    The Control Worked Yet The Company Still Got Breached - Episode 229

    Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls can pass every audit yet still fail to stop modern attacks, and why continuous validation is replacing point-in-time evidence. Discover how organizations should test resilience through penetration testing, red teaming, tabletop exercises, backup recovery, and control effectiveness—not just documentation. If you think "audit passed" equals "risk reduced," this episode will change the way you measure security forever. Episode Transcript: Today’s topic, Adam, is one that I feel like too many folks are familiar with, and that is the company still got breached despite all of your controls working. So what happens when every box is checked, every control passes the audit, and the attacker still gets in? Adam Goslin:Controls can operate as designed, but still end up failing to protect the organization. Compliance is measuring whether or not a control exists and if that control was executed. Security measures whether that control actually reduced the risk. One of the earlier euphemisms that you would hear a lot is compliance doesn’t equal security. What those people were getting at is that just because I have checked this box that says this thing’s in place doesn’t mean I’m actually secure. The control working doesn’t necessarily mean the organization’s protected. We need to make a shift from control execution to control effectiveness so that we can gain risk mitigation. There’s also the possibility, and this happens to fewer of those organizations, but there’s a possibility that you’ve got a zero day out there. But even in the case of a zero day, you’ve got a myriad of other controls that ought to be effective, where those detection mechanisms still have the ability to identify, “Hey, Houston, you got a problem.” Whether it’s identifying control bypass through monitoring of central logging, unusual user activity with behavioral analytics, file integrity monitoring if you’re seeing files changing within the environment, failed attempts from inside the network as attackers are trying this, trying that, and trying the other thing. There’s a reason why, even with zero days, it ends up seeing the light of day. It’s about mitigating the amount of time between, “Houston, we got a problem,” and knowing that you have a problem. Todd Coshow:What’s the difference between a control operating as designed and a control actually being effective? Adam Goslin:When it’s operating, you’re checking the box. This thing happened. But when a control is effective, it means that the risk was meaningfully reduced. You can have every single person in your organization going and attending security awareness training and seeing their quarterly security reminders and the piece of paper that’s taped up on the inside of the bathroom door, and yet employees still fall for phishing attempts. Maybe you’ve got a situation where an organization went in, ran their vuln scans, but they left vulnerabilities unpatched for a period of time. There’s gonna be some period of time between recognition that I have a vulnerability and getting it cured, and depending on how long of a span that is. It doesn’t necessarily have to be just critical vulnerability. A lot of people will obviously focus in on critical vulnerabilities. But what they seem to miss in their vulnerability management is that oftentimes I can take two or three medium-level vulnerabilities and conjoin them to create something that’s far more impactful.

  4. Aug 6

    Government AI Regulations That Could Impact Your Company - Episode 228

    AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement and the growing patchwork of U.S. state laws to California’s sweeping AI legislation and the EU AI Act. Learn why AI compliance is now a business-critical issue, how third-party AI doesn’t shift liability, and what organizations must do to avoid enforcement, reputational damage, and costly mistakes. Essential listening for compliance, security, legal, product, and business leaders. Episode Transcript: Today, Adam, we are going to do a deep dive specifically about government AI regulations that could apply to your company. There are a lot of moving parts related to AI these days. Get us started on this one, Adam. Adam Goslin:Sure thing. As AI has left the barn and is starting to become a barn burner of sorts, it’s more integrated into our lives. Government entities are realizing that they need to regulate the use for both consumer and citizen safety. There’s new government laws that are constantly being introduced. Organizations are gonna find themselves trying to accommodate a bunch of different laws that aren’t aligned with one another. This reminds me a lot of how breach notification laws started splaying out within the US, with having state-level regulations and there being a ton of complication coming into that arena. We’re heading down the same path with the AI arena. Both in the US and EU, there have been AI laws and regulations that have been enacted that will affect businesses today, even if you aren’t located within those jurisdictions. The problem is that failures for complying with those regulations could result in millions of dollars in fines for a given company. It’s definitely something that the folks out there are gonna wanna pay attention to and keep their ear to the ground on. Todd Coshow:What do we have in the US at the federal level right now related to AI? Adam Goslin:Some, not a ton. There isn’t yet a federal-level law that’s regulating AI. But there’s two different governing arms of AI regulation in the US, namely coming into play in terms of there’s a federal executive order out there. There’s also a Federal Trade Commission, or FTC. Those two are laying the foundation for the eventual federal AI. The FTC isn’t exactly taking prisoners, so to speak. We’ll start with the executive order. There was an executive order put out that just came out on June 2nd of ’26, promoting advanced artificial intelligence innovation security. That’s the closest thing we have to really a federal-level edict at this point in the game. The key provisions within that directive included a frontier model framework that was directing federal agencies, including NSA, CISA, to put together classified benchmarks for advanced AI. It also establishes a voluntary process for developers to grant the government early access to covered frontier models for up to 30 days in advance of the public release. For those that aren’t in the know, what’s an AI frontier model? It’s a really large general-purpose AI system that represents the bleeding edge or state-of-the-art in AI technology. The frontier models are trained on vast data sets. It often costs organizations either tens to hundreds of millions of dollars to develop. Those systems will possess advanced reasoning and planning capabilities for predictive work, multi-step workflows, debugging code, solving complex novel problems. They can also act as digital agents that use external tools, otherwise known as APIs, and trigger autonomous action. That executive order is pushing for the creation of an AI cybersecurity clearing house. It’s a voluntary collaboration with the AI industry and critical infrastructure operators to coordinate vulnerability scanning, patch distribution, threat validation, creating a central repository that’s fed into by a bunch of different organizations.

  5. Jul 30

    Making Sure Your Compliance Program Keeps Up - Episode 227

    Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up. Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations. Episode Transcript: Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic. How far behind is your compliance program, and how would you even know, Adam? Adam Goslin:My compliance program’s amazing. Todd Coshow:Answering the philosophical question, not being a smartass. Adam Goslin:A lot of organizations don’t know. Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak. Part of the problem is that the expectations are changing fast these days. You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation. In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.” Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.” But from the outside perspective, you’re starting off already behind the eight ball, if you will. Todd Coshow:It definitely feels that way. It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that? Adam Goslin:Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable. Kind of a combination of boogeyman sense and Skynet vibes going on. Effectively, it’s a matter of risk is moving faster than regulators are comfortable with. AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time. You’re seeing a lot of changes happening. Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc. AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws. It’s a lot of different things all simultaneously churning. It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there. In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up. Todd Coshow:Where do organizations tend to fall apart when responding to all of this change? Adam Goslin:A lot of times they’ll treat each regulation like a separate project. Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream. In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.

  6. Jul 23

    Ready to Get Serious About Compliance? - Episode 226

    Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success. You'll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden. Episode Transcript: Adam, today we are ready to get serious. That’s right, we are ready to get serious about compliance. If there’s anyone that I know that’s serious about compliance, it’s you, sir. Help set the stage on this one. Adam Goslin:For a lot of organizations, when they started going up against security and compliance, they didn’t have any clue when they started just how much of an investment it was going to end up being. Maybe the organization was initially hoping they could do a check-the-box approach to compliance. “Oh, if we just put all our crap there, everything magically happens,” or whatever the snake oil salesman was busy hawking your direction at the time. But if you actually care about the security posture of your organization, then you know that approach isn’t going to make the grade. You can rest assured your customers expect to see detailed proof that you are indeed taking security and compliance seriously. More and more, it’s becoming the standard or the norm that organizations will validate and vet the organizations that they choose to trust with their data. Your organization’s going to be no different. If your organization fits into this category and it’s time to take your compliance program to the next level, then it’s a major step forward for the organization. You’re going to need to get strategic about making sure you’re covering all the bases and evaluating and addressing several parts: people resources, the processes that you undertake, as well as where your existing technological approach to compliance stands in the grand scheme of things. All of those are going to come into play as you’re going through the process. If you fall into that category, you landed on the right podcast. Todd Coshow:Indeed. As part of an organization’s leveling up their compliance program, tell me more about the people they should be looking to have as part of their compliance strategy, and some of the pitfalls that organizations run into there. Adam Goslin:It’s all about having the right people. One of the big mistakes that I’ll see organizations make time after time when they say, “Okay, we’re going to take compliance seriously,” is that, no offense to the assessors of the world, they just go hire an assessor out of the gate. They think, “The assessor knows what they’re doing, and the assessor will be able to get the answers and help to get the company’s act together.” But I wouldn’t recommend that be step one. It doesn’t work well because the assessor, as weird as this sounds to articulate, isn’t responsible for sitting and guiding the company through a compliance engagement. They may be happy to charge you a hell of a lot more to hold your hand and walk you through it. But effectively, the organizations that do that become the problem children to the assessors. It’s like, “Oh my God, this is the never-ending engagement because these guys aren’t anywhere near ready to go.” For many assessors, they’ll have a readiness notion because they’ve been burned so many times with this exact thing happening. They’ll do an assessment up front of, “Is this organization actually ready to bring in an assessor or not?” You’ll be having conversations about the things that you don’t have in place with the person who is charged with assessing your organization’s current state of compliance. You end up revealing a whole ton of dirty laundry through the process.

Ratings & Reviews

5
out of 5
2 Ratings

About

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

You Might Also Like