<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>3.5 Activity: Compliance response plan (RACQ) by Gia Instructor</title>
      <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm</link>
      <description>Accountability &amp; Compliance</description>
      <language>en-us</language>
      <pubDate>2025-09-18 04:24:11 UTC</pubDate>
      <lastBuildDate>2025-12-01 00:50:03 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>How the bank should assess and manage the compliance risk arising from the breach</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640300488</link>
         <description><![CDATA[<p>In order to adequately assess the risk, the bank requires a combination of suitability skilled risk and compliance professionals.  The professionals require skills inclusive of technology / data / privacy risk given the breach of customer information.</p><p><br></p><p>Investigation would be required to:</p><ul><li><p>determine the number of customers impacted</p></li><li><p>the type of data impacted</p></li><li><p>how the data breach occurred (e.g. human error or cyber-attack).  </p></li><li><p>when the attack occurred.</p></li></ul><p><br></p><p>As there was a delay in reporting to ASIC, it is assumed that the risk / compliance function either lacked skills / knowledge or capacity to thoroughly identify and report. It could be assumed those who first discovered the breach did not report it a timely manner to the risk / compliance function.  </p><p><br></p><p>The compliance risks impacted include, but not limited to:</p><p><br></p><p>Australian Privacy Principals</p><p>ASIC Act</p><p>CPS234</p><p>CPS220</p><p>CPSC230 (or CPS231 / CPS232)</p><p>CPS510</p><p><br></p><p><br></p>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-20 04:39:07 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640300488</guid>
      </item>
      <item>
         <title>What governance structures and reporting mechanisms should be implemented</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640305820</link>
         <description><![CDATA[<p>The bank requires the introduction of uplift of its compliance framework.  The framework would comprise of policies / procedures including, but limited to:</p><p><br></p><ul><li><p>Risk Management policy / procedure</p></li><li><p>Incident management policy / procedure</p></li><li><p>Risk assessment policy / procedure</p></li><li><p>Control testing procedures</p></li><li><p>3 lines of defense, with line 2 independent of line 1.  Line 3 (audit) independent of the business </p></li></ul><p><br></p><p>Reporting mechanisms could include:</p><ul><li><p>Monthly risk reporting forums that are presented to escalating levels of leadership, including senior and board</p></li><li><p>Enterprise Risk Management system</p></li><li><p>Dashboards</p></li><li><p>Reporting would include trends / observations and outcomes of incident management / internal audit actions.</p></li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-20 04:43:04 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640305820</guid>
      </item>
      <item>
         <title>How the bank can align its compliance framework with AS ISO 37301:2023 incorporating Amendment 1:2024.</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640316015</link>
         <description><![CDATA[<p>Whilst the bank is responsible for determining the needs of its compliance management approach, the standard provides recommend practices and would encourage the bank to develop in line with the recommendations following the PDCA (Plan Do Check Act) lifecycle.  The lifecycle ensures that compliance is ongoing and not a once off activity.  The uplifted framework would expect to see annual revision and approval of policies that support compliance.</p><p><br/></p><p>The standard requires the bank to comply with social / ethical values - given the type of breach (data) and delay in reporting, it appears that this is not adequately addressed or embedded in the business and requires uplift.</p><p><br/></p><p>The amendment requires the bank to integrate climate- related obligations and would expect that reporting produced to support compliance with the plan would include commentary and consideration of climate risks.  </p><p><br/></p><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-20 04:49:40 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640316015</guid>
      </item>
      <item>
         <title>What training and cultural initiatives should be introduced to prevent future breaches.</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640318077</link>
         <description><![CDATA[<p>Elearning modules</p><p>Classroom / virtual training</p><p>Leadership forums / Ask me anything</p><p>Incident review / calibration sessions</p><p>Tone from the top</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-20 04:50:49 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3640318077</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3659882044</link>
         <description><![CDATA[<p>Southern Horizon Bank should begin by mapping all relevant regulatory obligations (especially under the Privacy Act and ASIC rules), using a compliance risk register to identify and prioritise gaps in controls and processes exposed by the breach and delayed reporting. The board should establish a dedicated compliance committee and appoint an independent Chief Compliance Officer, ensuring direct reporting lines to the board and regular, transparent updates on compliance risks, breaches, and remediation actions.</p><p><br/></p><p>The compliance framework should be aligned with AS ISO 37301:2023 (Amendment 1:2024) by embedding compliance into leadership, policies, and culture—using the Plan-Do-Check-Act cycle, regular internal audits, and continuous improvement. Training must be tailored, interactive, and ongoing, focusing on privacy, breach reporting, and ethical conduct, with strong whistleblower protections and visible leadership commitment to foster a culture of accountability and openness.</p><p><br/></p><p>Additionally, they should:</p><ul><li><p>Use a compliance risk register and scenario planning for future risks.</p></li><li><p>Ensure board-level oversight and independent compliance reporting.</p></li><li><p>Integrate compliance into strategy, operations, and culture per AS ISO 37301:2023.</p></li><li><p>Deliver targeted, scenario-based training and promote a “speak up” culture.</p></li><li><p>Regularly review and improve compliance systems in response to incidents and regulatory changes.</p></li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2025-10-31 05:42:12 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3659882044</guid>
      </item>
      <item>
         <title>Southern Horizon Bank data breach</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3693122367</link>
         <description><![CDATA[<ul><li><p>How the bank should assess and manage the compliance risks arising from the breach</p></li></ul><p>Southern Horizon Bank should assess and manage the breach of customer data and delayed breach reporting to ASIC by:</p><p>The breach has been assessed but reported late to ASIC, therefore this delay should have a breach assessment conducted on it, senior managers accountable and board should be notified in writing and this escalation documented and records, this notification should include details of the breach and remediation plan / management actions that should be tracked to closure.&nbsp; The Management actions / remediation may include enhancing information security policies and tightening controls, assurance over controls.</p><ul><li><p>What governance structures and reporting mechanisms should be implemented.</p></li></ul><p>IT, Risk, operational and compliance management frameworks, Privacy policies, data security policies. Incident management and breach reporting, management information reporting escalated up to board. APRA’s prudential standards, particularly CPS 220 (Risk Management) and CPS 510 (Governance).&nbsp;</p><ul><li><p>How the bank can align its compliance framework with AS ISO 37301:2023 incorporating Amendment 1:2024.</p></li></ul><p>ISO 37301:2021 is compliance management systems and amendment 1:2024 relates to provides a comprehensive set of requirements and guidelines for creating a compliance management system and is the leading international Standard organisations follow to construct and maintain effective compliance management systems.</p><p>Southern Horizon Bank should maintain good governance and transparency, ethical values, regularly assessing risks, screen contractors and suppliers, and effective communication on the policy to relevant stakeholders.</p><ul><li><p>What training and cultural initiatives should be introduced to prevent future breaches.</p></li></ul><p>Training should be enhanced on containing, data breaches and the assessment and reporting requirements for these as per the defined company policy and compliance framework. Training on how to monitor and assure compliance with data management.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-11-21 04:52:16 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3693122367</guid>
      </item>
      <item>
         <title>Compliance response plan for Southern Horizon Bank</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3700750701</link>
         <description><![CDATA[<p>Compliance Risk Assessment &amp; Management</p><ul><li><p>Conduct detailed root cause analysis.</p></li><li><p>Ensure transparent reporting consistent with ASIC RG 78 and ethical standards.</p></li><li><p>Identify regulatory, privacy, operational, reputational, and cultural risks arising from the breach.</p></li><li><p>Implement dashboards for breach and compliance metrics.</p></li></ul><p>Governance &amp; Reporting</p><ul><li><p>Activate the Risk &nbsp;and Compliance Committee.</p></li><li><p>Clarify roles for Board, Executive, and Compliance teams.</p></li><li><p>Strengthen delegations of authority for rapid breach escalation and reporting.</p></li><li><p>Conduct independent reviews, audits, and scenario testing.</p></li></ul><p>Aligning to compliance framework with AS ISO 37301</p><ul><li><p>Update policies, implement technical controls, and conduct mandatory training.</p></li><li><p>Strengthen monitoring, audits, and continuous improvement processes.</p></li><li><p>Proactively notify and cooperate with ASIC, APRA, and OAIC.</p></li></ul><p>Ethical Leadership &amp; Culture</p><ul><li><p>Reinforce a culture of transparency, early reporting, and accountability.</p></li><li><p>Leadership to communicate clear expectations and model ethical behaviour.</p></li><li><p>Embed ethical principles into decision-making and digital transformation activities.</p></li></ul>]]></description>
         <enclosure url="" />
         <pubDate>2025-11-27 07:35:46 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3700750701</guid>
      </item>
      <item>
         <title>Compliance Response Plan</title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3701910266</link>
         <description><![CDATA[<p>Assess and manage compliance risks arising from the breach via compliance assessment to determine impact, root cause and rectification/remediation required. </p><p>The Bank can align the compliance framework with AS ISO 37301:2023 incorporating Amendment 1:2024 by utilising the PDCA lifecycle.</p><p>Uplift of risk and compliance frameworks, including incident and issue management processes, risk and compliance reporting, supervision and monitoring. </p><p>Training should include the revised risk and compliance frameworks, how to raise issues and incidents, risk and compliance assessments and ongoing supervision and monitoring. </p><p> </p>]]></description>
         <enclosure url="" />
         <pubDate>2025-11-28 04:11:10 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/vccb59wjhmrkflgm/wish/3701910266</guid>
      </item>
   </channel>
</rss>
