Compliance Unfiltered With Adam Goslin

Total Compliance Tracking

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

  1. Jul 30

    Making Sure Your Compliance Program Keeps Up - Episode 227

    Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party risk are accelerating compliance demands—and how siloed teams and compliance debt make it harder to keep up. Learn what an adaptive, continuously improving compliance program looks like, and why staying ahead starts with reducing redundancy, improving visibility, and building compliance into day-to-day operations. Episode Transcript: Today, Adam, we’re having a conversation about making sure your compliance program keeps up. Things are changing all over the place, so this is an important topic. How far behind is your compliance program, and how would you even know, Adam? Adam Goslin:My compliance program’s amazing. Todd Coshow:Answering the philosophical question, not being a smartass. Adam Goslin:A lot of organizations don’t know. Many of them have this roadmap that they’ve created. They’re measuring themselves against what they did last quarter, but in many cases, not looking ahead, not planning for the changes that are coming, not putting their ear to the ground, so to speak. Part of the problem is that the expectations are changing fast these days. You’ve got AI governance rules that are coming out. We’ve got accountability for cybersecurity ramifications expanding. You’ve got product security requirements tightening. You’ve got frameworks like PCI that could raise the bar on continuous control validation. In addition, you’ve got more and more organizations that, it’s the atypical, “We started with doing our SOC 2, and then somebody demanded that we go in, do an ISO 27001, and then somebody’s coming in and saying we need to layer this one on.” Whether it’s the existing ground shifting underneath, or brand-new stuff coming out that’s going to be applicable, as an organization, you can feel like, “We’re on track internally because we’re checking all the boxes that we planned to check back when we planned out the prior quarter, and we’re validating that we got all that stuff done.” But from the outside perspective, you’re starting off already behind the eight ball, if you will. Todd Coshow:It definitely feels that way. It also feels like regulations, especially around AI, cybersecurity, and data, are, for obvious reasons, accelerating. What’s actually driving that? Adam Goslin:Anytime you’ve got something new, especially AI, AI is new, makes people uncomfortable. Kind of a combination of boogeyman sense and Skynet vibes going on. Effectively, it’s a matter of risk is moving faster than regulators are comfortable with. AI makes changes as to how decisions are made, how data’s being used, how systems are behaving, and it’s left the regulators trying to play catch-up in real time. You’re seeing a lot of changes happening. Instead of waiting five years between big changes, you’re seeing these waves of tweaks, modifications, improvements, etc. AI governance expectations heading north. You’ve got stricter rules around breach accountability, expanded third-party risk requirements, evolving data privacy laws. It’s a lot of different things all simultaneously churning. It’s really not just this one thing is changing, this one regulation. It’s more of an overlapping and convergence of the various regulations that are out there. In many cases, it’s overwhelming teams in terms of being able to keep the finger on the pulse and keep up. Todd Coshow:Where do organizations tend to fall apart when responding to all of this change? Adam Goslin:A lot of times they’ll treat each regulation like a separate project. Over here, down aisle number one, I’ve got AI compliance stuff. Then in aisle number two is my PCI update, and aisle number three is my privacy workstream. In many cases, you’re seeing siloed efforts for folks trying to go through solving the same problems, access control, data governance, risk management, and doing it repetitively.

  2. Jul 23

    Ready to Get Serious About Compliance? - Episode 226

    Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right people, documented processes, and purpose-built technology make all the difference, how to avoid costly mistakes that delay audits, and why proper scoping is critical to long-term success. You'll also discover practical strategies for simplifying evidence collection, improving audit readiness, and transforming compliance into a business advantage instead of a business burden. Episode Transcript: Adam, today we are ready to get serious. That’s right, we are ready to get serious about compliance. If there’s anyone that I know that’s serious about compliance, it’s you, sir. Help set the stage on this one. Adam Goslin:For a lot of organizations, when they started going up against security and compliance, they didn’t have any clue when they started just how much of an investment it was going to end up being. Maybe the organization was initially hoping they could do a check-the-box approach to compliance. “Oh, if we just put all our crap there, everything magically happens,” or whatever the snake oil salesman was busy hawking your direction at the time. But if you actually care about the security posture of your organization, then you know that approach isn’t going to make the grade. You can rest assured your customers expect to see detailed proof that you are indeed taking security and compliance seriously. More and more, it’s becoming the standard or the norm that organizations will validate and vet the organizations that they choose to trust with their data. Your organization’s going to be no different. If your organization fits into this category and it’s time to take your compliance program to the next level, then it’s a major step forward for the organization. You’re going to need to get strategic about making sure you’re covering all the bases and evaluating and addressing several parts: people resources, the processes that you undertake, as well as where your existing technological approach to compliance stands in the grand scheme of things. All of those are going to come into play as you’re going through the process. If you fall into that category, you landed on the right podcast. Todd Coshow:Indeed. As part of an organization’s leveling up their compliance program, tell me more about the people they should be looking to have as part of their compliance strategy, and some of the pitfalls that organizations run into there. Adam Goslin:It’s all about having the right people. One of the big mistakes that I’ll see organizations make time after time when they say, “Okay, we’re going to take compliance seriously,” is that, no offense to the assessors of the world, they just go hire an assessor out of the gate. They think, “The assessor knows what they’re doing, and the assessor will be able to get the answers and help to get the company’s act together.” But I wouldn’t recommend that be step one. It doesn’t work well because the assessor, as weird as this sounds to articulate, isn’t responsible for sitting and guiding the company through a compliance engagement. They may be happy to charge you a hell of a lot more to hold your hand and walk you through it. But effectively, the organizations that do that become the problem children to the assessors. It’s like, “Oh my God, this is the never-ending engagement because these guys aren’t anywhere near ready to go.” For many assessors, they’ll have a readiness notion because they’ve been burned so many times with this exact thing happening. They’ll do an assessment up front of, “Is this organization actually ready to bring in an assessor or not?” You’ll be having conversations about the things that you don’t have in place with the person who is charged with assessing your organization’s current state of compliance. You end up revealing a whole ton of dirty laundry through the process.

  3. Jul 16

    Spreadsheets are the Biggest Risk to Your Compliance Program - Episode 225

    On this week's Compliance Unfiltered, Todd Coshow and Adam Goslin unpack why spreadsheets are one of the biggest risks to a compliance program. They share real-world stories of version chaos, scattered evidence, and audit-day scrambling, then explain how a centralized system gives teams real-time visibility, better control, and confidence in their compliance status. Episode Tracking: Today, we’re going to chat about the biggest risk, in my opinion, possibly in some other people’s opinion, to your compliance program, and that is, dun, dun, dun, the spreadsheet. That’s right. The spreadsheet is the biggest risk to your compliance program. It’s almost as difficult as it is for me to say. Now, Adam, if you were in the middle of your onsite and your assessor asked for specific evidence, how long would it take organizations to actually find it? Adam Goslin:If we’re talking about my engagement, how long would it take? Seconds. But for a lot of people that are rocking off spreadsheets, longer than anybody wants to admit. This goes back quite a ways, way back in the day when I was doing consulting before the existence of TCT and being forced to use that horrifying effing spreadsheet. I was in some onsite sessions with clients where the assessor was like, “Go ahead and show me this.” All of a sudden, it’s crickets. People are scrambling. They’re looking at their watch. “Hold on a second. I think it’s over here.” They go and look over there. “Okay, I’ll find it. If it’s not there, it’s got to be over here. Give me a couple more minutes.” No, it’s not there either. “You know what? Evan knows exactly where it’s at. Give me one second.” Ring, ring, ring, ring. His phone went to voicemail. “Anyway, look at the time. It’s 10:45 in the morning. Isn’t it about time we went and grabbed lunch?” It was an effing nightmare. A lot of people think that they know where things are until they’re under the gun and have to prove it. If I’ve got to scan across email threads, shared drives, different versions of documents that exist in 18 different spots, Slack messages, text messages, voicemails, network shares, and whatnot, you’re not just stepping up to the plate and proving a control out. You’re trying to reconstruct history at that point in the game. It’s astoundingly uncomfortable when the assessor is asking for stuff and you can’t just put your finger on it. It really degrades their sense that the people they’re talking to actually have their act together. Todd Coshow:I can definitely appreciate that. Spreadsheets are still everywhere in compliance, but why are they such a problem? Adam Goslin:Spreadsheets weren’t designed to manage living, breathing systems. We’ve talked before about the levels of complexity that exist within these things. A spreadsheet is static, and compliance isn’t. There could be one or more compliance standards I’m going up against. The organization could have one or more locations they’re going up against. The organization could have one or more applications they’re going up against. You could have workflows that flow from control owners to internal QA, over to a consultant, up to an assessor, to assessor QA, to complete. It could be in any of those states. If I start multiplying all the cross-sections, with a spreadsheet, literally one poor soul has to manage the sheet if you want to try to keep anything sane. The spreadsheet isn’t showing you what’s happening right now in your compliance program. It’s showing whatever the last person did that went and typed it in.

  4. Jul 9

    Q3 Security Insights 2026 - Episode 224

    In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions. The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds. If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you. Episode Transcript: It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026. As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy. As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly. Also, feel free to reach out to us at complianceunfiltered@totalcompliancetracking.com. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us. Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more. Adam Goslin:In the grand scheme of things, it is a capability that some organizations struggle with. Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no? When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request. There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof. This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy. It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly. Certainly, safeguarding internal reports is one arena we’re going to get into. As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports. There’s a myriad of information within them that external entities don’t have any right or reason to see. In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution. The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those. Only issuing your externally appropriate summary of your security posture to third parties is appropriate. The next arena I want to touch on is a centralized distribution channel. One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.

  5. Jul 2

    Building AI Agents Securely - Episode 223

    AI agents are driving efficiency, but also introducing serious, often unseen security risks. As adoption accelerates, unvetted access, prompt injection, and poorly controlled environments can expose sensitive data and disrupt operations. This episode of Compliance Unfiltered breaks down the key threats and shows how to mitigate them using proven principles like least privilege, input validation, and isolated execution. Learn how to secure AI deployments and turn a growing risk into a resilient advantage. Episode Transcript: You’ve been talking about the AI zombie walk for some period of time now. What perils are folks walking into with AI agents? Adam Goslin:We’ve got the democratization of agentic AI on the march. Anybody can get the latest tools and create these incredible AI agents that can do almost anything you can imagine. It’s part of the main reason why the agentic AI move can be a substantive risk for the organization as well. One of the big problems they’re having right now is that, while security and compliance folks understand the risks of AI, there are a ton of frontline users that are just clicking buttons and building tools and making things automated and better. There isn’t, in a lot of cases, any thought to the security implications of what they’re in the process of doing. Thinking about security isn’t an element of day-by-day workflow, and that’s where this notion of agentic AI comes in riskiest, if you will. Leveraging platforms for building these AI agents without a security background, I’d liken it to giving a three-year-old an arc welder. It might be able to figure out how to turn it on, but can you imagine the untold damage that they could do with it? You put a powerful AI tool in the hands of people that don’t know about protecting data, layers of security, and how to appropriately restrict access. They’re not going to know how to use it safely. There are a lot of considerations when it comes down to building AI agents in a secure fashion. But most of it honestly comes down to security principles. It’s possible for employees to build those safely, but there needs to be that marrying of the security and compliance-style mindset in conjunction with what’s going on. Todd Coshow:What type of efficiency risks are folks running into? Adam Goslin:AI agents are often used for personal efficiency and internal workplace functions. To give some examples: consolidating, summarizing, and filtering across multiple email accounts; automated execution of auto-replies; analyzing workflows and calendars for identifying efficiencies; gathering up data; and preparing written summaries of client projects. These things may seem harmless, but just consider the risk of letting the AI agent loose on your calendar. How much data did you just expose as a result of clicking, “Sure, you’re going to have full access to my calendar”? The agent has access to your client lists, client contacts, emails, signatures, phone numbers, and cell phone numbers. All of that starts to come into play as you’re granting blind access to Office 365, as an example. Maybe that extends to OneDrive and SharePoint. Maybe, depending on the user and their access levels, they could be granting a ton of access. Even things that seem innocent, such as tracking birthdays or anniversaries, could similarly produce greater levels of exposure than you were even considering. The company needs to consider what is the data and information that’s exposed to the AI engine, how do we want to use it, and whether or not that data is secluded from other things. If you’re moving from a free version to a paid version of AI, your users may still be jammed into some gigantic public pool of data storage. Even when the AI vendors are claiming, “We don’t hand your data over to public AI models,” you need to look closely at what they are doing, such as utilizing the information that’s gleaned from the individual users when it comes to training their engines.

  6. Jun 25

    AI-Powered Attacks: Is Your Compliance Program Already Obsolete? - Episode 222

    In an era of evolving AI-driven cyberattacks, traditional compliance programs are falling dangerously behind. Static controls create a false sense of security while attackers leverage AI to move faster, exploit vulnerabilities, and bypass defenses. On this week's Compliance Unfiltered, Todd Coshow and compliance expert Adam Goslin explore how AI is reshaping threats, why checkbox compliance is obsolete, and how organizations must shift to continuous, real-time assurance to stay resilient, protect data, and keep pace with modern adversaries. Episode Transcript: Today, we’re going to talk about the nefarious. That’s right, the artificially nefarious. In fact, AI-powered attacks. Is your compliance program already obsolete? But before we do so, Adam, as always, we want to say a special thank you to listeners of this podcast. Tell your compliance friends, if they’re not listening to us already, let them know that it’s something that you enjoy doing, and they might as well. Also, if you have any questions, topics, or general compliments you want to send our way, please do so at ComplianceUnfiltered@TotalComplianceTracking.com. As I mentioned, Adam, AI-powered attacks are something that’s on everybody’s mind these days. I guess the question is: if AI is fundamentally changing how attacks are executed—faster, smarter, more adaptive—are most compliance programs already outdated? Adam Goslin:In a lot of cases, yeah. It’s not because of some type of poor design, but a lot of the programs that exist now were founded in advance of the advent of AI, built in a different time, if you will. A lot of the compliance programs have certain assumptions baked in: stability, known systems, predictive behavior, human-driven threats. AI is really putting a gaping hole in that assumption, if you will. You’ve got attacks these days that can adapt midstream. They can mimic a legitimate user and scale with a speed that wasn’t possible before. Compliance is still, in many cases, measuring control effectiveness and measuring controls being in place at fixed points in time. It isn’t necessarily that the compliance is wrong, but it’s operating on a timeline that’s not matching up to today’s newfangled AI-world reality. Todd Coshow:Fair enough. Where do you see the biggest disconnect today between what compliance frameworks validate and what’s actually happening inside an environment? Adam Goslin:One of the biggest gaps is between existence and effectiveness. Frameworks are good at confirming controls exist. There is a policy. Here it is. There’s a process, and there’s evidence. But they’re not consistently validating that the control is working under real-world conditions, and quite frankly, the real world is changing under our feet, if you will, especially when it comes to these AI-driven attacks. You’ve got organizations that hold up their piece of paper and say, “Hey, big green checkbox, we’re compliant.” But the controls, in some cases, are bypassed shortly after the validation that, at that point in time, they were working. In many cases, the controls aren’t getting tested against how attack patterns are really behaving in the real world these days. Todd Coshow:You’ve talked about organizations having a false sense of their own state of compliance. How does AI make that problem even worse? Adam Goslin:AI accelerates the drift and buries it, if you will. Controls have a tendency to degrade over time. Access reviews get stale. Monitoring gets noisy and ignored. That type of stuff was already happening. But AI allows for the exploit of those gaps faster than many organizations are set up to detect them. Now you’re sitting here with a situation where, on the one side, I’m technically compliant because of my last audit. But operationally, I’m not compliant because the environment has modified or changed, and the attackers are jumping on those gaps immediately.

Ratings & Reviews

5
out of 5
2 Ratings

About

Compliance Unfiltered is a Podcast Dedicated to Making Compliance Suck Less

You Might Also Like