🚀 Today I’m proud to share the first paper from The Policy Update community: “The Colorado AI Act: A Compliance Handshake Between Developers and Deployers.” The Colorado AI Act (SB 24-205) is the first comprehensive, enforceable U.S. state law on high-risk AI systems. It takes effect February 1, 2026, and sets clear obligations for both developers and deployers to prevent algorithmic discrimination. This paper, co-authored by an extraordinary group of practitioners and thinkers across law, auditing, design, strategy, and governance, offers: ⚖️ A breakdown of legal duties for developers and deployers 📑 Practical compliance checklists and templates 🤝 A “compliance handshake” model that shows how these obligations fit together 📈 Insight into why strong AI governance is not just regulation, but a driver of value creation I started The Policy Update as an outlet for "continuous learning in the age of AI", but found something bigger: an amazing interdisciplinary community of people committed to advancing responsible AI. This collaboration is proof of what happens when diverse expertise comes together with shared purpose. Read the full white paper, which is linked in the comments. #ColoradoAIAct #AIRegulation #ResponsibleAI #AIGovernance #AICompliance #AIandLaw Sheila Leunig, Edward F., Ezra Schwartz, Nadine Dammaschk, Dr. Cari Miller, Patrick Sullivan, Abhinav Mittal, Jovana Davidovic
Student Discipline Policies
Explore top LinkedIn content from expert professionals.
-
-
The Policy-Control Gap - Why Good Intentions Aren’t Enough Organizations often mistake policies for control. They draft guidelines, issue directives, and assume compliance will follow, without ensuring there is anything in place to enforce them. The result? A false sense of security and increased exposure to risk. Policies alone don’t drive behavior, while effective controls do. Internal audit and risk leaders can bridge this gap by embedding real, measurable mechanisms that detect and deter noncompliance. This would require moving beyond policy reviews and tick-box exercises to testing whether controls actually function in practice. Also assessing the organization’s culture of compliance by determining: - Are employees aware of the policy? - Do they understand the consequences of noncompliance? - Are there clear accountability measures in place? To me, a policy without enforcement is like a shop that sells only right-handed gloves. Strong governance means ensuring that what’s written on paper translates into action. This also means shifting from passive oversight to proactive assurance, testing effectiveness, challenging assumptions, and ensuring that policies don’t just exist but actually work. I welcome your thoughts. #InternalAudit #RiskManagement #theiia #Governance #Compliance #internalauditors #ERM
-
I audited a 180-employee company's POSH compliance last quarter. They had an Internal Committee. On paper. The external member had never attended a meeting. Two IC members had left the company eight months ago. Nobody updated the order. The annual report to the District Officer was never filed. The founder's response: "But we have a policy. It's on the intranet." A policy on the intranet is not compliance. Under the POSH Act, you need a properly constituted IC, a trained presiding officer, an active external member, annual filings, and documented awareness sessions. If a complaint lands tomorrow and your IC is defunct, the company is exposed. Fines up to Rs 50,000 for first offence, license cancellation for repeat. Check your IC composition today. Not your policy document. Your committee.
-
Confronting the Shadows – Staff Bullying in Schools I had this article published in Education Today -“Confronting the Shadows.” The article examines a deeply uncomfortable yet critical reality - staff bullying staff in our schools. https://lnkd.in/gxeXp7Sv The theme isn’t about students harassing each other. It is about adults, colleagues, teachers, leaders, undermining each other through - 🔴 Passive‑aggressive remarks and backhanded compliments 🔴 Withholding vital information, or social exclusion 🔴 Undermining professional authority and contribution These behaviours damage morale, erode trust, and strike at the heart of school culture. Why this matters - 💡 Power dynamics – hierarchies and unhealthy cultural norms can entrench bullying 💡 Wellbeing & retention – staff who feel bullied are more likely to leave the profession, often silently 💡 Cultural contagion – when staff treat each other poorly, it sends a ripple effect through the whole school community. What we can do - ✅ Recognise these behaviours as bullying, not ‘just staff politics.’ ✅ Develop clear anti-bullying policies that apply to all staff ✅ Foster a culture of transparent communication, accountability, and mutual support. ✅ Provide leadership training to identify, address, and prevent staff-to-staff bullying. If we truly value schools as communities of care, we must be willing to look not only at how adults care for students, but how we care for each other. Read more and reflect - https://lnkd.in/gxeXp7Sv Together, let’s shine a light on the shadows, and build healthier school cultures. #EducationalLeadership #SchoolCulture #Wellbeing #SchoolLeaders #StaffWellbeing #ProfessionalCulture #BullyingAwareness
-
A ₹5 crore ($570k) fine. One of the biggest in IRDAI's history. That’s what landed on Policybazaar’s desk. India’s leading online insurance aggregator. The reason? A list of violations that could’ve been avoided: • Conflicts of interest - senior leaders holding unauthorised directorships elsewhere • Products promoted as "best" or "top" without independent verification • Irregular outsourcing payments • Sales calls not mapped to authorised verifiers • Premium payments delayed to insurers But the part other companies need to hear: This isn’t just about Policybazaar. It’s a warning. If you’re building in a regulated space - like fintech - you can’t treat compliance as an afterthought. Because regulators are watching. And they’re stepping up scrutiny. The founders who’ll sleep well in 5 years are reading cases like this now. And making changes before the knock on the door comes. Now here's what you, as a fintech founder, can learn from Policybazaar's ₹5 Crore Penalty 1) Governance Must Be Strong • Get regulatory approval for ANY external directorship or advisory role for key management • Document and disclose all potential conflicts upfront • Review your leadership team’s external commitments quarterly 2) Product Promotions Need Transparent Backing • Never rank products without clear, disclosed methodology • Use independent, verifiable data for any product comparisons • Include disclaimers explaining your ranking criteria • Avoid language that implies regulatory endorsement 3) Premium/Payment Handling is Sacred • Set up automated systems to ensure 24-hour premium transfers • Never use customer funds for operational cash flow • Build redundant payment processes with real-time monitoring • Document every payment flow for audit trails 4) Record-Keeping Cannot Be "Good Enough" • Tag every single transaction to a responsible person • Maintain complete audit trails for all customer interactions • Set up systems that allow instant regulatory access to records • Run regular internal audits to catch gaps before regulators do 5) Outsourcing Agreements Need Crystal Clear Terms • Define exact services, deliverables, and pricing in all vendor contracts • Ensure all outsourcing complies with regulatory guidelines • Regularly audit third-party relationships • Document how outsourced services relate to your core business 6) Commission and Fee Structures Must Stay Within Limits • Set up automated controls to prevent over-limit payments • Reconcile monthly, not annually • Document all fee structures clearly • Build buffers to stay below regulatory maximums The companies that survive in regulated spaces don’t just follow rules. They build compliance into their DNA from day one. Start now. Before the inspection. Before the penalty. Because in regulated industries, the cost of “fixing later” isn’t just money - it’s your entire business. --- ✍ Tell me below: What’s one compliance process you’ve delayed that could cost you big in the future?
-
Dear IT Auditors, Auditing Data Loss Prevention (DLP) Process Data is every organization’s crown jewel. yet it’s Data is constantly in motion, either they are emailed, uploaded, shared, and stored in the cloud. Every movement creates a potential leak point. That’s why Data Loss Prevention (DLP) is vital. It’s both a cybersecurity tool and a control framework that protects sensitive information from unauthorized disclosure. For auditors, the challenge is confirming that DLP isn’t just deployed, but truly effective and enforced. 📌 Understand the DLP Objective: DLP solutions monitor and control how data is used, shared, and transferred. Auditors must confirm whether the DLP strategy aligns with data classification policies, protecting PII, PHI, financial data, and intellectual property across endpoints, networks, and cloud services. 📌 Policy Design and Coverage: Review whether DLP rules are comprehensive and risk-based. For example, are policies configured to detect credit card numbers, personal identifiers, or confidential files leaving the organization? Ensure separate rules exist for email, USB devices, and cloud storage. 📌 Data Classification Integration: DLP is only as smart as the data classification behind it. Auditors should assess whether data is correctly tagged and categorized. If sensitive data isn’t labeled, DLP tools can’t protect it. 📌 Incident Response and Escalation: What happens when DLP detects a violation? Validate that alerts trigger the right response workflows, from notification and triage to investigation and resolution. Review whether these incidents are logged, analyzed, and used for policy refinement. 📌 Testing and Tuning: False positives can frustrate users and weaken compliance. Confirm whether the organization periodically tests and tunes DLP rules to balance detection accuracy with business usability. 📌 Coverage Across Channels: DLP should extend beyond on-premises email. Check if it covers endpoints, mobile devices, cloud storage, and collaboration tools like Teams or Slack. Incomplete coverage equals incomplete protection. 📌 User Awareness and Training: DLP can’t succeed if users don’t understand its purpose. Verify that employees are trained to handle data responsibly and recognize DLP warnings as guardrails, not obstacles. 📌 Audit Evidence: Key evidence includes DLP policy configuration screenshots, incident reports, alert logs, and exception approvals. Evidence should show both proactive prevention and responsive remediation. Effective DLP auditing ensures that sensitive information stays where it belongs, inside trusted boundaries. When done right, it transforms data protection from a technical checkbox into a culture of digital responsibility. #DataLossPrevention #CyberSecurityAudit #ITAudit #RiskManagement #CyberVerge #CyberYars #InformationSecurity #GRC #DataProtection #Compliance #InternalAudit #Assurance
-
🚨 The 2:00 AM Call: "We have a public S3 bucket." It's every Platform Engineer's nightmare. A compliance scan just flagged a critical security breach: S3 buckets across multiple environments are set to public read. How do you find the root cause, identify the blast radius, and push a fix across your entire estate before the auditors arrive? Most teams face a weekend of firefighting: ❌ Manually tracking down the source configuration. ❌ Calling developers to ask them to update their module versions. ❌ Patching environments one by one. ❌ Hoping no one introduces the same bug again. The Orchestrated Fix: 15 Minutes to Global Remediation; Here is how a self-hosted Platform Orchestrator (like Humanitec) handles this at scale, turning a multi-day incident into a 15-minute fix: 1.) AI Pinpoints the Issue: Using an HCTL CLI integration, we immediately query the orchestrator's state to see exactly which environments are affected by the public ACL module. 2.) Root Cause Found: The orchestrator reveals the single, centralized module definition that mistakenly set the ACL to public-read. 3.) Global Policy Enforcement: The Platform Team updates the module (ACL set to private) and pushes it back to the orchestrator. 4.) Auto-Remediation: The system flags all affected environments for a pending update. We trigger a single fleet deployment, and the orchestrator forces the new, compliant configuration across all affected environments—guaranteeing compliance and eliminating the risk. This process shifts security policy management from slow manual patching to centralized, instant policy enforcement at the infrastructure layer. We built this for high-security, high-compliance environments (Finance, Defense) where speed and auditable compliance are non-negotiable. #PlatformEngineering #Security #Compliance #DevOps #S3
-
Oga Compliance, drop that regulation and go learn the business! Too many compliance professionals hide behind regulations without understanding the business they support. They recite rules they can’t apply, enforce, or defend and then wonder why they don't generate IMPACT. Regulations are open-source. Anyone can read them. Your value lies in applying them effectively and guiding the business on compliant execution which requires deep operational and technical knowledge. If you’re in fintech, you MUST understand: 1. Product management – How products are designed, launched, and iterated. 2. InfoSec – Data security, fraud prevention, and infrastructure risks. 3. Dispute & settlements – How transactions flow, chargebacks work, and liabilities are assigned. If you’re in Traditional Finance (banking, etc.), you MUST understand: 1. Branch & Treasury Operations – The nuts and bolts of transaction processing and internal workflows. 2. Trade finance – How cross-border deals, LC issuance, and supply chain financing work. 3. Relationship & Private Banking – Processes for engaging clients, structuring deals, and manage portfolios. 4. ERM – The fundamentals of lending, risk assessment, and risk appetite. My ideology is that we don’t just "enforce" compliance, we co-create solutions. - We don’t just say NO. We offer better, more compliant alternatives. - We don’t reject business from a distance. We sit with the business/their customer, discuss, and align. (If you know your stuff, everyone leaves that meeting convinced, even the customer.) - We champion initiatives, co-own projects and provide firm risk-aware postulations/advisory that enable Executives support decisions with less worry of negative outcomes. - We iterate. We modify our compliance programs as many times as needed to adapt to new ventures and initiatives the Business are interested. Yes, compliance is about adherence but its not a spectator sport and businesses speak in acquisitions, turnover, and strategy. Drop the "regulation recitation" mindset and start mastering the language of the business you support, tie your advisory to risk-reward dynamics, and drive home the ultimate goal: Cost-saving and strategic enablement.
-
An employer lost in the tribunal after dismissing a hotel manager for using their facilities to drunkenly party with a junior colleague. How does this happen when there is clear wrongdoing? Yet again, a flawed process tripped up the business: ❌ The same manager dealt with the investigation stage and disciplinary hearing. Whilst this will not automatically mean unfair dismissal, here there were other managers available, an external HR advisor and a US parent company. ACAS guidance here isn't just for show - tribunals refer to it. ❌There was evidence that this manager had a difficult relationship with the employee being disciplined and was also a family friend of the junior employee involved. It was this that really meant him dealing with both stages was not reasonable given the potential impact on judgment. ❌Although a different individual dealt with the appeal, they were close to the initial investigation (discussing both with the external HR and the manager who chaired the disciplinary). The final nail was correspondence sent before the appeal which suggested the appeal chair didn't exactly have an open mind. The tribunal flagged that if it was just the same person dealing with the investigation and disciplinary, without anything else, the dismissal would have been fair. Everything together, however, meant it was too flawed a process to be reasonable. That meant the only conclusion was an unfair dismissal. I walk clients through these processes every week, so employers heed this: ✅ The size of your business matters. A tiny SME is far likely to be forgiven for using the same manager for more than one stage of a disciplinary than a huge employer with numerous managers. If you have managers available, use them! ✅ Maintaining independence is key: if there is background beef between an employee and a manager, get someone else to deal with a formal process if possible. That will involve looking at an external HR professional if you have the resources (something our clients can take advantage of). ✅Disciplinary stages and appeals should be separate, distinct and fully independent. Whoever deals with things like appeals should not be involved in the prior stages and any suggestion of a pre-determined decision is a death-knell for fairness. Whilst compensation was £0, the employer will have spent thousands in legal fees, had months of tribunal preparations and then managers out of the business to give evidence at a hearing that went on for five days. Process is as legally important as the reason you are taking action in the first place - get it right from the off and you'll save yourselves time, money and hassle. #TeamHowarths