Sustainability in Supply Chains A guide for private markets investors 🌍 Private markets investors face increasing pressure to integrate sustainability into supply chain management. This guide by PRI explains why supply chain due diligence is essential and how investors can embed it across the investment cycle to safeguard assets, reduce risks, and capture value. Supply chain risks, ranging from human rights abuses to environmental violations, have become financially material issues with direct implications for investor performance, regulatory compliance, and reputation. Human rights concerns are significant. Forced labour affects an estimated 28 million people worldwide, with rising risks in major sourcing countries such as India, Vietnam, China, Mexico and the United States. Migrant workers are particularly vulnerable, while child labour remains prevalent in high-risk industries and regions. Working conditions also present serious challenges. Excessive hours, unsafe workplaces and poor wages undermine the stability of global supply chains. These issues are concentrated in industries such as apparel, electronics, food and agriculture, construction materials and mining where oversight is often limited. Environmental risks add complexity. Nearly half of global sourcing markets face high or extreme risk of violations related to waste management, emissions and hazardous materials. Biodiversity loss and deforestation linked to commodities such as palm oil, soy and timber increase exposure to both regulatory and operational disruptions. Regulatory requirements are tightening worldwide. The EU Corporate Sustainability Due Diligence Directive, the US Uyghur Forced Labor Prevention Act and the EU Deforestation Regulation compel companies and investors to identify, mitigate and report risks throughout their supply chains. Failure to comply carries financial consequences. Volkswagen shipments were detained at US ports, Shein faced delays in listing plans due to sourcing concerns and companies in Germany were investigated and fined for breaches of the Supply Chain Act. These examples show how supply chain management is now a strategic necessity. Proactive due diligence creates opportunities. Companies with strong supply chain transparency and risk management can secure contracts, improve resilience, reduce costs and strengthen their brand. Investors can leverage these practices to enhance portfolio performance and protect value at exit. The guide explains that due diligence should be present at every stage of the investment cycle. This includes governance and policies, early screening, detailed risk assessments, legal agreements, active engagement, monitoring and exit planning. Clear roles, data systems and training are critical. Integrating sustainability into supply chain due diligence strengthens both risk management and value creation. #sustainability #business #sustainable #esg
Compliance Training Management
Explore top LinkedIn content from expert professionals.
-
-
Compliance isn’t choosing one framework, it’s understanding how they work together. Many organizations view SOC 2, ISO 27001, and GDPR as competing obligations, but the reality is far more integrated. SOC 2 validates data security controls for US-based service providers voluntary but expected by enterprise clients. ISO 27001 provides a globally recognized ISMS foundation with comprehensive risk management and continuous improvement. GDPR legally enforces personal data protection for EU citizens with significant financial penalties for non-compliance. The strategic advantage lies in their overlap: access controls, incident response, vendor risk management, encryption, and breach notification requirements align across all three. Organizations that map controls once and satisfy multiple frameworks simultaneously reduce audit fatigue while strengthening their overall security posture. Rather than treating compliance as separate silos, mature GRC programs build unified control environments that address shared requirements, turning regulatory burden into operational excellence. What’s your approach to managing overlapping compliance frameworks? #GRC #SOC2 #ISO27001 #GDPR #Compliance #InformationSecurity #DataProtection
-
Values → Principles → Behaviors: A Practical Breakdown for Culture Design When I facilitate workshops on code of conduct, values, or culture, I often see organizations spending too much time choosing the right value word—and not nearly enough time developing the principles and behaviors that bring those values to life. But here’s the truth: ✅ Behaviors are what matter most. They are where values and principles show up in everyday actions—and they are the clearest indicator of a healthy culture. 🔍 Definitions: What’s the difference? Let’s break down the core concepts and how they interrelate: Values are your core beliefs — the things that matter most. E.g., Integrity, Growth, Respect Principles are the guiding rules that make values actionable in context. E.g., "We always tell the truth, even when it’s uncomfortable." Behaviors are the visible actions that show your principles in real life. E.g., Admitting a mistake, calling out misalignment, actively listening. This flow is sequential and reinforcing: Values → Principles → Behaviors Each layer builds on the one before it—and when done well, they create clarity and accountability. 📌 Example Cascades 🟢 Value: Integrity Principle: We always tell the truth, even when it’s uncomfortable. Behaviors: “I made an error in the client report — I’ll correct it and let them know.” “This recommendation might be effective, but it doesn’t align with what we promised. Can we revisit it?” 🔵 Value: Respect Principle: We listen actively and speak with care, even when we disagree. Behaviors: In meetings, we don’t interrupt others. We ask clarifying questions before responding. We give credit publicly and provide feedback privately. When I design or review a code of conduct, this is the structure I use: Start with values, but don’t stop there. Move beyond the posters and into real practices. If this post gave you a new insight or reminded you of something insightful, drop a comment below —I’d love to hear your take (and yes, I read every comment myself — no AI automation here! :)
-
IFRS 18: A New Era for Financial Reporting The International Accounting Standards Board (IASB) has released IFRS 18 : Presentation and Disclosure in Financial Statements (April 2024), reshaping how organizations present and communicate their financial performance. The focus is clear: greater clarity, comparability, and transparency. While the standard doesn’t alter how profit is measured, it transforms how it’s told; standardizing structure, improving disclosure, and aligning global reporting practices. Key developments to note: 1️⃣ Structured income statement – All income and expenses must be classified into five categories: operating, investing, financing, income taxes, and discontinued operations. 2️⃣ New mandatory subtotals – Companies must now present operating profit or loss and profit or loss before financing and income taxes. 3️⃣ Management-defined performance measures (MPMs) – Non-GAAP figures like “adjusted EBITDA” must be disclosed transparently, reconciled to IFRS subtotals, and explained in detail. 4️⃣ Aggregation & disaggregation – IFRS 18 raises the bar for how items are grouped and presented, ensuring material information is clear and not lost in the fine print. 5️⃣ Effective date – Applicable for periods beginning on or after 1 January 2027, with restated comparatives and early adoption permitted. This isn’t just a compliance update, it’s a strategic opportunity for finance leaders to enhance reporting quality, strengthen investor confidence, and align performance communication with global best practices.
-
How To Handle Sensitive Information in your next AI Project It's crucial to handle sensitive user information with care. Whether it's personal data, financial details, or health information, understanding how to protect and manage it is essential to maintain trust and comply with privacy regulations. Here are 5 best practices to follow: 1. Identify and Classify Sensitive Data Start by identifying the types of sensitive data your application handles, such as personally identifiable information (PII), sensitive personal information (SPI), and confidential data. Understand the specific legal requirements and privacy regulations that apply, such as GDPR or the California Consumer Privacy Act. 2. Minimize Data Exposure Only share the necessary information with AI endpoints. For PII, such as names, addresses, or social security numbers, consider redacting this information before making API calls, especially if the data could be linked to sensitive applications, like healthcare or financial services. 3. Avoid Sharing Highly Sensitive Information Never pass sensitive personal information, such as credit card numbers, passwords, or bank account details, through AI endpoints. Instead, use secure, dedicated channels for handling and processing such data to avoid unintended exposure or misuse. 4. Implement Data Anonymization When dealing with confidential information, like health conditions or legal matters, ensure that the data cannot be traced back to an individual. Anonymize the data before using it with AI services to maintain user privacy and comply with legal standards. 5. Regularly Review and Update Privacy Practices Data privacy is a dynamic field with evolving laws and best practices. To ensure continued compliance and protection of user data, regularly review your data handling processes, stay updated on relevant regulations, and adjust your practices as needed. Remember, safeguarding sensitive information is not just about compliance — it's about earning and keeping the trust of your users.
-
A viral image of an ATM in Ludhiana recently caught my attention - a dangerously steep ramp ending abruptly at a glass door, with a staircase running alongside that leads nowhere. A perfect reminder of a hard-earned lesson in fintech: "Compliance isn’t just a checkbox." Product Managers: You don't want to miss saving 💾 this post for your future reference. This ramp was technically "compliant" - yes, there was a wheelchair access ramp. But it completely missed the purpose of accessibility. People had angry comments on social media about the apathy with which wheelchair-bound customers were treated and how the bank had made a mockery of accessibility. No amount of regulation can account for 'compliance as a checkbox' implementations that are designed to meet the regulation but not serve their intended purpose. It's the same trap I've seen countless fintech products fall into - implementing regulations as mere checkboxes rather than embracing them as design principles. I've experienced regulatory hurdles umpteen times in product launches; in fact, I've never experienced a straightforward implementation that hasn't hit a regulatory roadblock. BUT I can say this confidently: Compliance-first design is the secret sauce that makes the battle easier and less arduous, and inarguably 'faster' IF You just stick to the first principles of building this into your product strategy from day one . Regulations can either slow you down or become your competitive edge. To make compliance your strategic advantage, here's my 3-step playbook: 1/ Design Integration: Make regulatory adherence a natural part of the user experience rather than an afterthought ↳Embed compliance requirements into your initial product design ↳Get feedback from legal and compliance teams, and even the regulator if needed ↳Validate, Test, Iterate, Repeat 2/ Cross-Functional Collaboration: Build bridges between product, legal/compliance teams from day one ↳Involve them early ↳Make compliance & legal stakeholders brainstorm and provide feedback ↳Balance innovation with regulatory requirements using case studies and data to back up assertions instead of getting into crosshairs with them 3/ Validate Early, Validate Often: ↳Test with real scenarios ↳Get early feedback from regulators ↳Regular compliance assessments, no matter what stage of development you are in One golden tip - document everything, err on the side of caution when it comes to building and fostering trust with legal and compliance counterparts. The lesson in one line? Build WITH compliance, not around it. Instead of working around regulations, let's build with them. Because when you design within the right guardrails, innovation doesn't just survive—it scales. What's your strategy for managing fintech compliance? Share below. 👍 LIKE this post, 🔄 REPOST this to your network and follow me, Monica Jasuja
-
Do you think Data Governance: All Show, No Impact? → Polished policies ✓ → Fancy dashboards ✓ → Impressive jargon ✓ But here's the reality check: Most data governance initiatives look great in boardroom presentations yet fail to move the needle where it matters. The numbers don't lie. Poor data quality bleeds organizations dry—$12.9 million annually according to Gartner. Yet those who get governance right see 30% higher ROI by 2026. What's the difference? ❌It's not about the theater of governance. ✅It's about data engineers who embed governance principles directly into solution architectures, making data quality and compliance invisible infrastructure rather than visible overhead. Here’s a 6-step roadmap to build a resilient, secure, and transparent data foundation: 1️⃣ 𝗘𝘀𝘁𝗮𝗯𝗹𝗶𝘀𝗵 𝗥𝗼𝗹𝗲𝘀 & 𝗣𝗼𝗹𝗶𝗰𝗶𝗲𝘀 Define clear ownership, stewardship, and documentation standards. This sets the tone for accountability and consistency across teams. 2️⃣ 𝗔𝗰𝗰𝗲𝘀𝘀 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 & 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 Implement role-based access, encryption, and audit trails. Stay compliant with GDPR/CCPA and protect sensitive data from misuse. 3️⃣ 𝗗𝗮𝘁𝗮 𝗜𝗻𝘃𝗲𝗻𝘁𝗼𝗿𝘆 & 𝗖𝗹𝗮𝘀𝘀𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻 Catalog all data assets. Tag them by sensitivity, usage, and business domain. Visibility is the first step to control. 4️⃣ 𝗠𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴 & 𝗗𝗮𝘁𝗮 𝗤𝘂𝗮𝗹𝗶𝘁𝘆 𝗙𝗿𝗮𝗺𝗲𝘄𝗼𝗿𝗸 Set up automated checks for freshness, completeness, and accuracy. Use tools like dbt tests, Great Expectations, and Monte Carlo to catch issues early. 5️⃣ 𝗟𝗶𝗻𝗲𝗮𝗴𝗲 & 𝗜𝗺𝗽𝗮𝗰𝘁 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀 Track data flow from source to dashboard. When something breaks, know what’s affected and who needs to be informed. 6️⃣ 𝗦𝗟𝗔 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁 & 𝗥𝗲𝗽𝗼𝗿𝘁𝗶𝗻𝗴 Define SLAs for critical pipelines. Build dashboards that report uptime, latency, and failure rates—because business cares about reliability, not tech jargon. With the rising AI innovations, it's important to emphasise the governance aspects data engineers need to implement for robust data management. Do not underestimate the power of Data Quality and Validation by adapting: ↳ Automated data quality checks ↳ Schema validation frameworks ↳ Data lineage tracking ↳ Data quality SLAs ↳ Monitoring & alerting setup While it's equally important to consider the following Data Security & Privacy aspects: ↳ Threat Modeling ↳ Encryption Strategies ↳ Access Control ↳ Privacy by Design ↳ Compliance Expertise Some incredible folks to follow in this area - Chad Sanderson George Firican 🎯 Mark Freeman II Piotr Czarnas Dylan Anderson Who else would you like to add? ▶️ Stay tuned with me (Pooja) for more on Data Engineering. ♻️ Reshare if this resonates with you!
-
Oga Compliance, drop that regulation and go learn the business! Too many compliance professionals hide behind regulations without understanding the business they support. They recite rules they can’t apply, enforce, or defend and then wonder why they don't generate IMPACT. Regulations are open-source. Anyone can read them. Your value lies in applying them effectively and guiding the business on compliant execution which requires deep operational and technical knowledge. If you’re in fintech, you MUST understand: 1. Product management – How products are designed, launched, and iterated. 2. InfoSec – Data security, fraud prevention, and infrastructure risks. 3. Dispute & settlements – How transactions flow, chargebacks work, and liabilities are assigned. If you’re in Traditional Finance (banking, etc.), you MUST understand: 1. Branch & Treasury Operations – The nuts and bolts of transaction processing and internal workflows. 2. Trade finance – How cross-border deals, LC issuance, and supply chain financing work. 3. Relationship & Private Banking – Processes for engaging clients, structuring deals, and manage portfolios. 4. ERM – The fundamentals of lending, risk assessment, and risk appetite. My ideology is that we don’t just "enforce" compliance, we co-create solutions. - We don’t just say NO. We offer better, more compliant alternatives. - We don’t reject business from a distance. We sit with the business/their customer, discuss, and align. (If you know your stuff, everyone leaves that meeting convinced, even the customer.) - We champion initiatives, co-own projects and provide firm risk-aware postulations/advisory that enable Executives support decisions with less worry of negative outcomes. - We iterate. We modify our compliance programs as many times as needed to adapt to new ventures and initiatives the Business are interested. Yes, compliance is about adherence but its not a spectator sport and businesses speak in acquisitions, turnover, and strategy. Drop the "regulation recitation" mindset and start mastering the language of the business you support, tie your advisory to risk-reward dynamics, and drive home the ultimate goal: Cost-saving and strategic enablement.
-
One of the recurring challenges we face in Cybersecurity is enforcing security policies and making sure people actually understand and follow them. When I was heading CISO function in an organization, we had dozens of policies, standards, SOPs, guidelines, and playbooks. We knew that most employees had never read the policies. [ This is true in most organizations] And why would employees read it? - A single policy was 10+ pages long. - It was written in compliance jargon. - It didn’t speak their language or reflect their daily work. When I was part of disciplinary committee , we had cases where individuals were DLP violation. They had shared a file via email. When we asked about it, they looked surprised and said: "But I didn’t know I wasn’t supposed to do that. No one told me." Our ISO 27001 ( or any other standard for that matter) implementation was successful on paper. We had all the documentation. But in real life? It wasn't working. Policies need to be simple, role-specific guides. They should be replaced wit visual infographics, short videos, and scenarios. Additionally, regular awareness campaigns can further help enforce them. Today as part of vCISO engagement, I advise customers to make policies live where people work. Policies should speak their language. Show them what they need to know — not just what the auditor needs to read.” #policies #ISO27001 #NIST #GRC #RiskManagement #SOC2 #CISSP #audit #compliance #databreach #cyberattack CYTAD Rivedix
-
Great example of sustainability communication that doesn't really celebrate success but rather failure Oatly's latest sustainability report offers a great example of a board-level risk governance. Instead of sanitising results, they transparently disclosed a 15% increase in corporate climate footprint, 30% jump in packaging emissions, and 24% rise in ingredient emissions. It is understandable to prefer to communicate only reached goals but sometimes the process of implementing a sustainability agenda takes time and changes course. For companies across all industries, this approach demonstrates several critical governance principles that extend far beyond sustainability reporting. Regulatory preparedness: As disclosure requirements change globally businesses that establish transparent reporting cultures today protect their organisations from future compliance failures and penalties. Stakeholder trust management: Investors, customers, and employees value authenticity over perfection. Companies that acknowledge operational challenges while demonstrating systematic measurement build stronger long-term relationships than those that present unrealistic success narratives. Litigation risk mitigation: Recent settlements in greenwashing cases have reached hundreds of millions when public claims don’t align with internal data. Boards that insist on accurate disclosure protect shareholder value and personal director liability. Strategic decision-making: Honest sustainability data, including unfavorable trends, enables better resource allocation and strategic planning. Boards cannot provide effective oversight with incomplete or misleading information. Sustainability communication is not always about celebrating successes. The most effective reports directed at consumers or board oversight acknowledge that complex operational changes involve tradeoffs, unintended consequences, and sometimes temporary setbacks that require transparent explanation to stakeholders. Whether the topic is cybersecurity, supply chain resilience, or climate impact, health and safety, the governance principle remains consistent: transparent measurement following the science and honest disclosure protect long-term enterprise value. #board #governance #directorduties #riskoversight #esggovernance #esg #insights #corporategovernance #fudicialduties