Compliance Unfiltered With Adam Goslin

Total Compliance Tracking

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

  1. Sep 10

    Join TCT at the PCI-NACM in Vancouver - Episode 233

    PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain risk, and operational compliance are reshaping payment security. They explain why continuous evidence beats annual screenshots, what the PCI Community Meeting in Vancouver can offer, and how teams can turn compliance into practical, measurable risk reduction. Ideal for security leaders and compliance professionals worldwide. Episode Transcript: Adam, join us at the PCI North American Community Meeting in Vancouver, British Columbia, Canada. 20 years later, I have to ask you, Adam, has PCI actually made payments more secure? Adam Goslin:Oh, I mean, there’s no doubt it had a dramatic impact. You got to remember back in the day, it was the absolute Wild West. The card brands were just getting their asses handed to them, and something needed to be done. The level of change from when this whole adventure first started to now is pretty startling. I think in many ways it was necessary. I think that the card industry as a whole forced a lot of organizations to start leveling up, start taking this stuff seriously. I believe it was astronomically helpful as we’ve headed into this arena. Certainly, we’re seeing a lot of shifts in the marketplace where we’re moving away from a checkbox approach, etc. It’s hard to remember. I was looking up, when did PCI V1 officially get released? It was middle of December in 2004. Todd Coshow:Oh, wow. Adam Goslin:It was like the first version of it, type of a deal. It was 2006 that the PCI SSC was officially formed. Then they started to make enhancements. But there have been a whole myriad of different changes and modifications to the standards over that time. The payments arena really has made a fairly startling shift from just checking the box, annual validations, into more of a continuous security or, as we here at TCT like to call, operational mode, type of a deal. The acceleration of AI, both for the white hats and black hats, has enabled attackers to move as quickly as defenders. So it remains a very, very vibrant and exciting arena. Todd Coshow:No doubt. Well, what do you think the biggest conversations at this year’s community meeting will be? Adam Goslin:Yeah, I think there’s a lot. New and exciting things happening in the payment space will certainly be one. Bar none, a big participant will be a lot of topics surrounding AI. AI, its use and benefits and all that fun stuff. Honestly, I’m kind of hoping that somebody whips a little bit of realism in there about the dangers of AI as well. I think I’ve mentioned once or 80 times about AI zombie walk. I think there’s a lot of signs in the marketplace right now that the AI zombie walk mentality isn’t necessarily the best idea in the grand scheme of things. I think there’s a lot more reasonability starting to enter into the mix. That’s what I’m hoping at least. Certainly, a lot of discussions around operational compliance, automation of evidence collection, various ways to streamline your engagements, looking at threat intelligence and attack trends as they’re going. Certainly, one of the cool parts about being at the conference is getting updates direct from the council, what’s happening, what’s coming soon to a theater near us, all of that fun stuff. We’ve got all that coming our way as well. Todd Coshow:Indeed. What’s one thing every first-time attendee should do in Vancouver? Adam Goslin:Well, number one, I’m just gonna underscore this big time.

  2. Sep 3

    PCI Engagement Masterclass - Episode 232

    On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collection, QA bottlenecks, and annual audit scrambles. Learn how request lists, automated evidence mapping, and operational mode streamline PCI and multi-framework compliance while reducing human error. From year-round evidence collection to better assessor workflows, discover how the right platform and processes can save time, improve accountability, and make complex compliance engagements far less painful. Episode Transcript: Now, I have to ask, why did this topic speak to you, Adam? Adam Goslin:Well, we’re heading toward that time of year where we’re all gonna be heading over to the PCI community meetings, both in the US and the EU. The reality is a lot of people that are in the compliance arena, a lot of them tend to use a kind of rinse-and-repeat style approach. It’s almost like you get into your lane, right? I got my thing, and I do it this way, and I’ve always done it that way. For some of these organizations, “We have always done this this way since the dawn of time.” It’s cool to have a good, rock-solid process you can depend on, right? But in the same sense, I made this company to help people. I love helping people. I love making their lives better, giving them solutions that’ll actually help, all of that fun stuff. So we wanted to take the opportunity to go through some of the advanced capabilities that few assessors are really leveraging to their fullest capability. Hopefully, even if you’re a seasoned Compliance Unfiltered listener, I’d suggest thinking about your process, how you do what you do, some of the stuff we’re gonna bring up, where it could be applicable, and hopefully this particular session turns out to be helpful. Todd Coshow:Absolutely. Well, let’s start with telling the listeners more about request lists and some of the benefits when handling multiple certifications. Adam Goslin:Sure thing. I’m sorry, I got completely distracted by a shiny object. I went and did a quick lookup. “And they tell two friends, and so on.” It was not an STD, fans that are keeping score. It was a famous phrase from 1970s and ‘80s television commercials for Faberge Organics shampoo. So for those of you keeping score on Adam’s memory card, you can put the red mark on that side of the paper, shall we say. Anyway, sorry, I’m back now. Todd Coshow:So request lists. Adam Goslin:Yes, request lists. A lot of people tend to walk into this notion of the request list as, “My engagements aren’t all that challenging. They’re not all that difficult, so I don’t need a request list. I really only need my request list for these super complicated engagements, etc., and we don’t have engagements like that, so we’re not gonna bother.” But the reality is, I challenge the listeners to just think about it. Actually, now that I think of this, I’ll give a pro tip on this one too. When you go in and do an engagement on the TCT portal, for those that haven’t really inspected what happens, you can hit the full export button, and that will produce kind of a full export of the entire track, all the report texts, explanations, which attachments went where. One of the files that comes out of that is like a document spreadsheet. Basically, what it is, it’s a unique list of the documents that were leveraged on the engagement, and in the next column over, it tells you how many places was that document used. As a test, I would just suggest go do that for one of your recent engagements. Go look at that file because what you’re gonna see is that there are single pieces of evidence that are attached to multiple requirements, and in some cases, the evidence is attached to hundreds of items.

  3. Aug 27

    What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

    On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discuss why AI-generated policies often fail in audits and incident reviews, and how to use AI for drafting without losing accountability. Episode Transcript: Today, Adam, we’re gonna talk about what compliance problems arise when AI is writing your policy. So if AI wrote your security policy and no one really reviewed it, whose policy is it? Adam Goslin:I love the compliance problems. That was good. Before I go there, every time that you’re like, “Hey, tell a few friends that may be interested in what we’re doing here,” I always had that thing. I don’t remember what the frick commercial it was back in the day, but it’s like, “And they too tell two friends, and they tell two friends, and so on and so on.” I forget what the hell the topic was. It was like some PSA or something. Todd Coshow:Sounds like a pyramid scheme. I don’t know. Adam Goslin:Nah. I’m gonna be forced to go figure that out now. Anyway, if you just go jam it into AI and it spits out a policy and nobody’s taken a look at it, whose policy is it? AI is becoming a good productive tool for compliance teams. It isn’t a problem to have AI go take a whack at the first draft. The problem is, and quite honestly, this is the same issue that organizations have had now for some time. For some time you’ve been able to go out to whatever, I’m just gonna make it up, like www.writemycompliancepolicyforme.com, and you too can fill in blanks and get some steaming pile of garbage as a policy. Some people literally do. I’ve been doing engagements, and we’re going through the policy for the annual review, etc., and there’s literally placeholders left in the damn policy for where things that they should have filled in, obviously. They didn’t do anything other than take a half-hearted whack at find and replace a couple of times and called it a policy. It’s really no different. When you’ve got AI blasting out the first draft and then you just go ahead and put your signature on the dotted line, it’s not terribly useful. Quite honestly, one of the biggest problems that poses when you’re trying to go through your engagement, the relationship between people going through compliance and the folks that are gonna be assessing compliance, it’s one where there is a certain amount of built-up trust that happens between those parties. There is absolutely no better way to erode any notion of trust building when you’re just serving up what usually is one of the earliest things. Normally when you go and sit down, you go through the overview of the company and what is the scope, and the assessor’s asking all sorts of questions so they can get their arms around it. But the very first thing that they’re actually looking at generally is the policies. Do you wanna start it off on completely the wrong foot? Go have AI write the initial draft and put your signature on the bottom line, or go grab a template policy and you haven’t really reviewed it. Policies are more than just well-written language. It’s literally a written commitment about how the organization is actually operating. If leadership is signing off on policies that aren’t reflective of reality, aren’t reflective of coverage for the various standards that you’re ostensibly going up against, if it isn’t reflecting how you’re actually doing what you’re doing, etc., you’re creating compliance risk in advance of your assessor walking in to bat you over the head. It’s really not a good look when you’re sitting there at your annual assessment or onsite and running square into that wall.

  4. Aug 20

    PCI FAQs When You’re Starting Your Compliance Program - Episode 230

    Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merchant versus service provider responsibilities. Learn why outsourcing payment processing doesn't eliminate your compliance obligations, how scope really works, and why treating PCI as a one-time paperwork exercise creates unnecessary risk. This episode is essential listening for merchants, service providers, and anyone navigating PCI compliance for the first time. Episode Transcript: Now, Adam, a long time ago in a land far, far away, there was a time where you asked the question, “What is PCI?” So bring the listeners up to speed on that. Adam Goslin:Everybody gets their start somewhere, and PCI was definitely mine. I had kinda made my way up the IT management ranks. Boss comes by. Don’t ask me why, he decided to print the entirety of the PCI standards, but literally drops a four-inch deck of paper on my desk and says, “Hey, we need to get compliant with this.” I’m looking at the cover page, and it says PCI on it, and I literally said, “What’s PCI?” So that was my entree into the land of security and compliance. I sat there staring at this volume of information and wondering, “What the hell do I do with this? Where do I go? How do I start?” etc. It’s part of why I decided to step into the space to help people, because I clearly remember just how overwhelming it felt to be looking at that much stuff, not having any clue what the hell it was, what it meant, what it’s for, does it even apply to us, etc. All the way around, it was very overwhelming to step into the compliance arena not already having been initiated. TCT has, both I and TCT have kinda specialized in PCI since our inception, and the consulting work that I was doing for folks in the space, the history of the consulting practice goes back even further than PCI’s existence. As we were sitting there and contemplating the types of things that organizations new to the space are facing, we decided to put together this almost like a frequently asked questions when you’re getting a compliance program off the ground. Frequently asked PCI questions when you’re getting a compliance program off the ground. Todd Coshow:Does PCI apply to merchants who outsource all payment processing? Adam Goslin:It’s one of the common questions that I’ll get. They’ll be like, “Oh, well, we don’t touch anything. We go ahead and outsource all of our payment stuff to blabbity-blah. That’s not my problem, and PCI doesn’t apply to us.” The answer is you’re wrong. Companies that are not storing, processing, transmitting, or receiving cardholder data, they still are subject to the PCI DSS. One of the biggest misunderstandings is, sure, there’s some technical elements of how you’ve done what you’ve done in terms of the connectivity. The devil’s always in the details. If you have a merchant account that is in any way, shape, or form receiving payments via credit cards, then you too get to fill out your PCI paperwork. That’s one of the biggest misunderstandings that organizations have. Honestly, a lot of the big names that have come out in the space over time, the Stripes, the Squares, the Intuits, if you will, back in the day, it was like the Wild West. “Well, I’ll just go get a Stripe account, so I don’t have to worry about this.” “Go process my stuff through Intuit, that way I don’t have to worry about it.” The unfortunate part is that those organizations were on this mad race to get people to jump over to their platform and process their stuff via their platform, but they weren’t really doing a great job with enforcing, mandating that people were actually following the PCI DSS. That kind of became a problem for a while because they were able to go in and easily turn it on, etc., and there wasn’t any enforcement arm that was coming at them.

  5. Aug 13

    The Control Worked Yet The Company Still Got Breached - Episode 229

    Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls can pass every audit yet still fail to stop modern attacks, and why continuous validation is replacing point-in-time evidence. Discover how organizations should test resilience through penetration testing, red teaming, tabletop exercises, backup recovery, and control effectiveness—not just documentation. If you think "audit passed" equals "risk reduced," this episode will change the way you measure security forever. Episode Transcript: Today’s topic, Adam, is one that I feel like too many folks are familiar with, and that is the company still got breached despite all of your controls working. So what happens when every box is checked, every control passes the audit, and the attacker still gets in? Adam Goslin:Controls can operate as designed, but still end up failing to protect the organization. Compliance is measuring whether or not a control exists and if that control was executed. Security measures whether that control actually reduced the risk. One of the earlier euphemisms that you would hear a lot is compliance doesn’t equal security. What those people were getting at is that just because I have checked this box that says this thing’s in place doesn’t mean I’m actually secure. The control working doesn’t necessarily mean the organization’s protected. We need to make a shift from control execution to control effectiveness so that we can gain risk mitigation. There’s also the possibility, and this happens to fewer of those organizations, but there’s a possibility that you’ve got a zero day out there. But even in the case of a zero day, you’ve got a myriad of other controls that ought to be effective, where those detection mechanisms still have the ability to identify, “Hey, Houston, you got a problem.” Whether it’s identifying control bypass through monitoring of central logging, unusual user activity with behavioral analytics, file integrity monitoring if you’re seeing files changing within the environment, failed attempts from inside the network as attackers are trying this, trying that, and trying the other thing. There’s a reason why, even with zero days, it ends up seeing the light of day. It’s about mitigating the amount of time between, “Houston, we got a problem,” and knowing that you have a problem. Todd Coshow:What’s the difference between a control operating as designed and a control actually being effective? Adam Goslin:When it’s operating, you’re checking the box. This thing happened. But when a control is effective, it means that the risk was meaningfully reduced. You can have every single person in your organization going and attending security awareness training and seeing their quarterly security reminders and the piece of paper that’s taped up on the inside of the bathroom door, and yet employees still fall for phishing attempts. Maybe you’ve got a situation where an organization went in, ran their vuln scans, but they left vulnerabilities unpatched for a period of time. There’s gonna be some period of time between recognition that I have a vulnerability and getting it cured, and depending on how long of a span that is. It doesn’t necessarily have to be just critical vulnerability. A lot of people will obviously focus in on critical vulnerabilities. But what they seem to miss in their vulnerability management is that oftentimes I can take two or three medium-level vulnerabilities and conjoin them to create something that’s far more impactful.

  6. Aug 6

    Government AI Regulations That Could Impact Your Company - Episode 228

    AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement and the growing patchwork of U.S. state laws to California’s sweeping AI legislation and the EU AI Act. Learn why AI compliance is now a business-critical issue, how third-party AI doesn’t shift liability, and what organizations must do to avoid enforcement, reputational damage, and costly mistakes. Essential listening for compliance, security, legal, product, and business leaders. Episode Transcript: Today, Adam, we are going to do a deep dive specifically about government AI regulations that could apply to your company. There are a lot of moving parts related to AI these days. Get us started on this one, Adam. Adam Goslin:Sure thing. As AI has left the barn and is starting to become a barn burner of sorts, it’s more integrated into our lives. Government entities are realizing that they need to regulate the use for both consumer and citizen safety. There’s new government laws that are constantly being introduced. Organizations are gonna find themselves trying to accommodate a bunch of different laws that aren’t aligned with one another. This reminds me a lot of how breach notification laws started splaying out within the US, with having state-level regulations and there being a ton of complication coming into that arena. We’re heading down the same path with the AI arena. Both in the US and EU, there have been AI laws and regulations that have been enacted that will affect businesses today, even if you aren’t located within those jurisdictions. The problem is that failures for complying with those regulations could result in millions of dollars in fines for a given company. It’s definitely something that the folks out there are gonna wanna pay attention to and keep their ear to the ground on. Todd Coshow:What do we have in the US at the federal level right now related to AI? Adam Goslin:Some, not a ton. There isn’t yet a federal-level law that’s regulating AI. But there’s two different governing arms of AI regulation in the US, namely coming into play in terms of there’s a federal executive order out there. There’s also a Federal Trade Commission, or FTC. Those two are laying the foundation for the eventual federal AI. The FTC isn’t exactly taking prisoners, so to speak. We’ll start with the executive order. There was an executive order put out that just came out on June 2nd of ’26, promoting advanced artificial intelligence innovation security. That’s the closest thing we have to really a federal-level edict at this point in the game. The key provisions within that directive included a frontier model framework that was directing federal agencies, including NSA, CISA, to put together classified benchmarks for advanced AI. It also establishes a voluntary process for developers to grant the government early access to covered frontier models for up to 30 days in advance of the public release. For those that aren’t in the know, what’s an AI frontier model? It’s a really large general-purpose AI system that represents the bleeding edge or state-of-the-art in AI technology. The frontier models are trained on vast data sets. It often costs organizations either tens to hundreds of millions of dollars to develop. Those systems will possess advanced reasoning and planning capabilities for predictive work, multi-step workflows, debugging code, solving complex novel problems. They can also act as digital agents that use external tools, otherwise known as APIs, and trigger autonomous action. That executive order is pushing for the creation of an AI cybersecurity clearing house. It’s a voluntary collaboration with the AI industry and critical infrastructure operators to coordinate vulnerability scanning, patch distribution, threat validation, creating a central repository that’s fed into by a bunch of different organizations.

About

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less