Site navigation

Report: Most Firms Are Struggling To Keep Up With New Regulations

Tom Quinn

,

infosec compliance concerns
A new survey reveals that firms are struggling to comply with DORA, NIS2, and the AI Act, with many yet to implement key compliance measures.

Almost all IT, InfoSec and risk management professionals are concerned that the weight of new regulations will negatively impact their workload, and potentially lead to a greater risk of noncompliance, according to fresh research from AuditBoard. 

The cloud-based audit, risk, and compliance platform surveyed over 270 decision-makers in these fields across the UK and EU, and found that 90% are worried conformance with DORA, the NIS2 Directive, and the EU’s AI Act will hinder their operations as teams struggle to stay afloat with daily tasks.

According to AuditBoard’s report, Unlock Regulatory Compliance With DORA, NIS2, and the EU AI Act, InfoSec professionals feel the weight of compliance efforts the most, with 38% expecting to be impacted to a great extent, compared to 29% of risk management professionals and 28% of those in IT.

Compliance with NIS2 is reported to be among the highest priorities for organisations (61%), however, despite the directive’s deadline having passed only 52% of organisations report being compliant, while another 44% plan to meet these requirements by the end of next year.

Organisations are also still scrambling to meet the requirements of DORA, which came into force last month. To ensure compliance with these regulations, firms must monitor the use of third parties, however the survey revealed that 14% of those who claim their organisation is already in compliance have not yet implemented this critical element. 

Even those claiming to already be in compliance with the EU AI Act are missing essential elements of compliance that could leave them vulnerable. 

While 63% reported being compliant with the Act and having transparency measures in place, only 55% say they have implemented risk management frameworks, and just over half (51%) are performing comprehensive risk assessments, essential criteria under the new regulations.

The data shows a major stumbling block for the majority of organisations is the difficulty in navigating multiple, often overlapping rules. Over 80% of those AuditBoard surveyed reported having to comply with at least two of these major regulatory requirements, with almost half (47%) having to comply with all three.

To deal with the impact of new regulations, more firms are turning to AI. Professionals across industries agreed that the most valuable applications of AI in governance, risk, and compliance was in identifying and evaluating risks (70%), detecting fraudulent activities (68%), automating responses to incidents and breaches (64%), and for testing their adherence to the rules (57%).


Recommended reading


With 45% of organisations having already allocated significant resources to their compliance efforts, and another 45% planning to do the same in the next six months, any tools which eases the pressures on decision-makers will become highly valuable as more compliance deadlines approach. 

“We found that by leveraging purpose-built technology, professionals in all levels and functions can make more effective decisions and more efficiently execute efforts required to maintain compliance,” said Jason Sechrist, director of product solutions, EMEA at AuditBoard. 

“Whether in early stages of compliance or actively working to maintain it, organisations can use the findings in this report to build a framework for their journey and help future-proof their conformance strategies.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data