Shadow AI as Two Problems: Data Disclosure and Output Verification

Shadow AI names two failures: sensitive material leaving the organization and unreliable material entering it. The enterprise control layer has become genuinely good at the first and has nothing at all for the second. There is no data loss prevention rule for a fabricated citation, and no function owns the gap.

Two Incidents, Two Failure Modes

The New South Wales Reconstruction Authority published an account of its own data breach in 2025 that contains no attacker. Between 12 and 15 March, a former temporary employee uploaded a spreadsheet of ten columns and more than twelve thousand rows to an unauthorized third-party platform. The file held personal information on 2,031 participants in the Northern Rivers Resilient Homes Program: names, contact details, addresses, dates of birth, sensitive health information, and limited financial commentary. The authority stated plainly that this was not a cyberattack. It reported no evidence that the uploaded data was publicly available or had been accessed by a third party at this stage, and added, in its own words, that publication cannot be ruled out.

The people in that spreadsheet were disaster-recovery applicants. They had already lost something before their health information went into a prompt box.

Six months later, in another country, running the opposite direction, Deloitte Australia wrote to the Department of Finance about its review of the Targeted Compliance Framework, in a letter later released under freedom of information. The Department of Employment and Workplace Relations had consented to a ChatGPT-based toolchain, licensed by the department and hosted in its own Azure tenancy, for code analysis. The citation work happened elsewhere. Engagement staff, all of whom had received training on responsible use, employed MyAssist and ChatGPT to summarize proceedings and to complete and format references, and the letter records no departmental consent for that. Output was reviewed against source materials, and in the firm’s own words the review corrected some errors while not all were identified. Inaccurate citations reached a government client. Deloitte issued a corrected report and repaid the final instalment of the contract, a little over ninety-seven thousand Australian dollars on a contract of four hundred and forty thousand.

Two incidents, and the only thing they share is the heading they get filed under.

One honest note before the argument builds on them. Neither case contains a realized harm anyone has been able to point to. New South Wales has reported no evidence of publication or third-party access, Deloitte’s errors were corrected and the department has said the review’s substantive findings held, and the same is true of almost every incident in public circulation. An argument for moving governance attention toward this channel has to reckon with the channel it would move attention away from, and misdirected email remains the largest single category of notifiable breach in most regulators’ published data, including in the jurisdiction where this article opens. The case for taking the prompt box seriously is not that it has already done more damage than the alternatives. It is that the organization can see the email and cannot see the prompt, and that the second of the two failure modes has no detective control at all. In New South Wales, sensitive material left the organization. At Deloitte, unreliable material entered it and reached a client. A disclosure failure and a verification failure arise from different behavior, surface in different functions, and take different work to prevent.

That distinction matters more than it sounds, since the enterprise response to one of them is now genuinely formidable and the response to the other barely exists. The two also separate cleanly on everything an organization would need to manage them. They have different owners, since egress belongs to security and output reliability belongs to whoever signs the work. They have different detection paths, since one leaves a log and the other leaves a document that looks finished. They have different budget lines, one capital and one operating. And they fail on different clocks, since a disclosure is complete the moment the file uploads while an unverified assertion sits inert until somebody relies on it. A single governance response aimed at both will be built for whichever one the person designing it happens to fear more.

Where Enterprise Controls Reach

Any account of AI governance that describes it as training modules and acceptable-use policies is describing 2023. A serious program in 2026 has a technical control layer, most of it invisible to the employee and none of it dependent on what the employee knows.

Verified-domain capture stops a corporate address from creating a personal-tier account with a major provider. Single sign-on with conditional access binds the sanctioned assistant to a managed device. Secure web gateways classify several thousand generative endpoints by risk tier and block with a coach page rather than a dead end, naming the approved alternative and offering one click to reach it. Tenant restriction headers prevent authentication into a foreign tenancy of a product the organization has itself approved. Inline data loss prevention inspects prompt payloads and file uploads, not just mail and endpoints, and sensitivity labels drive the policy, so a file classified at the level the New South Wales spreadsheet would have carried cannot be posted to an unsanctioned endpoint no matter who is trying. Behind all of it sits an internal gateway in front of every model call, redacting in flight and logging per call.

Apply that stack to the first of the two incidents and it stops in three independent places, none of which cares what the temporary employee knew or had been trained on. This is a workflow control, and a good one. Netskope’s telemetry across its customer base shows organization-managed account use rising from 25 to 62 percent in a year, with personal-account use falling from 78 to 47 percent across an overlapping population, since the share of people moving between both account types more than doubled. Something in the enterprise response is moving the numbers, and much of it is this layer rather than licensing.

Now apply the same stack to the second incident. There is no data loss prevention rule for a fabricated citation. No gateway inspects a plausible-looking chronology for whether the authority it names says what the text claims. No classification label attaches to a summary that is fluent, correctly formatted, and wrong. Every control described above examines what leaves. The Deloitte failure is entirely a matter of what arrived, and the layer has nothing to say about it.

An output-side layer is not unimaginable, and parts of it exist. Retrieval grounded in a closed authoritative corpus narrows what the system can cite to documents the organization holds. Deterministic citation checkers resolve every reference against a source of record and fail the ones that do not resolve. Output evaluations measure an error rate on a fixed test set before a workflow goes live and again when the model version changes. Sampling with source tracing pulls a percentage of finished work and walks the assertions back to their origins, which is what audit has done for a century under a different name.

Almost none of that is deployed. The reason is not technical difficulty. Each of those controls costs time inside the workflow, where the egress layer costs money outside it, and every one of them makes the work slower at the point where the tool was adopted to make it faster. An organization that installs egress controls pays once, in a program budget, and the employee never sees the invoice. An organization that installs verification controls pays continuously, in the throughput of the people who were the reason for buying the tool. That is a harder purchase to make and a much harder one to defend when the productivity numbers are already booked.

The registry deserves a fairer hearing than it usually gets in this argument, and it belongs on the same side of the line. Judging an inventory by whether it prevents an incident is a category error, since no inventory has ever prevented anything: a general ledger does not prevent fraud, a configuration database does not prevent an outage. Inventory is the substrate other controls run on, which is why it sits at the front of the CIS controls, in the map function of the NIST AI Risk Management Framework, in Annex A of ISO 42001, and in the model inventories that have anchored model risk management since 2011. It is also mandatory rather than advisory for anyone inside the EU AI Act or DORA. The real criticism is narrower and sharper. Registers are mis-sold and mis-measured, boards receive a count of cataloged use cases as though enumeration were mitigation, and almost none of them carry the two fields that would make the record useful: which data classes the use case touches, and who owns verification of what it produces.

The Appeal of Person-Directed Interventions

Given a control layer that works on egress, the persistence of the training-and-attestation reflex takes some explaining, and the explanation has nothing to do with evidence.

A person-directed intervention is assignable, and it lands on a function that already exists. It is inexpensive, since an awareness module costs a fraction of what it costs to rebuild an ingestion path or renegotiate a model contract. It produces numbers a risk committee can receive, in completion rates and attestation percentages that improve reliably every quarter. And it allocates liability usefully, since an organization that documented a rule and trained people against it holds a defensible position when somebody breaks the rule. None of those four properties bears any relationship to whether the intervention reduces the behavior. Together they explain why it keeps getting chosen.

The economics run the same way one level up. A gateway with inline redaction, sensitivity labeling that actually reaches the file estate, and an internal assistant capable enough that people prefer it is a multi-year platform program with a standing team behind it. The module is procurable this quarter. When an organization reports the module and not the platform, it is usually making a budget decision rather than a diagnostic error, and the honest version of the criticism is that the budget decision is never presented as one.

One thing this argument should not do is treat the inadequate approved path as an accident. The ten-megabyte upload limit, the disabled file channel, the quarterly authorization cycle: each was set by someone, for a reason that was defensible when it was set, and usually by someone protecting against a specific exposure they could name. Pilots start narrow for good reasons. Model contracts get signed before anyone knows which use cases will matter. Residency posture constrains which model is available in which market, and that is a capacity and contracting fact, not a failure of nerve.

What follows from that is where the leverage actually sits. A constraint set for a good reason in March is not thereby a good constraint in September, and almost nothing in the governance calendar forces anyone to revisit it. The security function will not reopen a limit it set conservatively, since nothing rewards loosening a control and something punishes it. Procurement will not renegotiate a model contract nobody has complained about in the right forum. The people positioned to force that revisiting are the ones who can see the work on both sides of the constraint, which is a description of a program or transformation role and of almost nobody else.

There is a further asymmetry in what gets reported. Risk committees see awareness completion rates every quarter. They have never once seen a number for the pull those rates exist to offset.

Survey Evidence on Individual Behavior

Two peer-reviewed studies now sit under this, ten months apart, and both deserve to be read with their limits attached.

Silic, Silic and Kind-Trüller published a mixed-methods study in Strategic Change in June 2025, from 140 survey responses and ten executive interviews. Their contribution is conceptual. They frame the phenomenon as a sociotechnical governance failure, not as a compliance lapse, name the condition they find most often as a governance drift zone where formal policies exist without real-world traction, and locate the sharpest responsibility gaps in high-risk functions such as HR and legal.

Glorin Sebastian published digital shadow AI risk theory, or DART, in Technological Forecasting and Social Change in 2026, and that contribution is measurement. Three survey waves with employed professionals of 374, 179 and 220 respondents recruited through an online research panel, analyzed through factor analysis and covariance-based structural equation modeling, tested eight hypotheses across six constructs. Six were supported. The samples skew young, 79 percent between 18 and 35 in the first wave, and every measure is self-reported at a single point in time, which the author states himself. Nothing here establishes causation, and the paths below describe what varied together, which is a weaker claim than what produced what.

The associations still say something the remedy lists do not. Respondents who perceived these tools as more efficient reported more use of them for sensitive tasks, at a standardized coefficient of 0.531, the strongest of the organizational-level predictors in the model. Respondents who reported policy awareness and privacy training reported less disclosure, at roughly 0.18 and 0.19, the two smallest supported effects estimated. Training shows up. It shows up small, next to the reason the person reached for the tool in the first place.

The same first wave found 52 percent of respondents unaware of their organization’s AI policies and a further 18 percent unsure, so roughly seven in ten could not speak to one either way, while only one in four had received formal instruction on privacy or ethics in this context. Against that, 68 percent reported relying on these tools frequently for work and 32 percent acknowledged entering sensitive or proprietary information. Read the training coefficient against those figures and an awkward possibility appears that the study does not resolve. An intervention three-quarters of a sample never received cannot show much of an effect, so the small coefficient is at least as consistent with a treatment barely administered as with a treatment that does not work. Whichever reading holds, an organization reporting policy coverage as a control is reporting something its own people cannot confirm exists.

An objection to reading any of this as a capability shortfall deserves a hearing. Microsoft commissioned Censuswide to survey 2,003 UK employees in October 2025, and 41 percent said they use unapproved tools since it is what they are used to in their personal life, with 32 percent expressing concern about the privacy of company data entered into consumer tools. Habit explains that better than capability does, and habit prescribes friction, defaults and interception where capability would prescribe a wider approved envelope. Microsoft also sells the sanctioned alternative, which belongs beside the finding. Both mechanisms are plainly operating and no available study separates them, which matters less than it appears to, since a sanctioned tool that is slower, narrower and less familiar than the alternative loses on both counts at once.

One further association in the same study is worth reporting carefully, since it points somewhere counterintuitive and the evidence for it is thin. Respondents who found these systems more opaque reported less trust in them; those reporting more trust reported more comfort using them; and comfort was associated with more disclosure of sensitive material. Meanwhile heavier exposure showed no association with higher privacy concern, negative and non-significant across two waves, which the author reads as normalization, and not as any feedback loop that would make frequent users more careful.

That reading is an interpretation of a null result and nothing more. A non-significant coefficient does not establish habituation, and no organizational prescription should be built on one. What it does supply is a hypothesis worth testing where the data already exists. Every awareness program in circulation concentrates on new joiners, contractors and occasional users, on the reasonable assumption that unfamiliarity produces mistakes. If comfort sits closer to disclosure than ignorance does, that targeting is aimed at the wrong cohort, and an organization with prompt-level telemetry can check it this quarter by asking whether sensitive-content rates rise or fall with tenure and volume. The answer is not in any published study. It is in most large firms’ own logs, unexamined.

Samsung’s semiconductor division supplies the most cited illustration of the pull, and it rests on press reporting, not on disclosure. On 30 March 2023 the Korean magazine Economist described three incidents inside the division: source code from a database download program entered for troubleshooting, code for identifying defective equipment submitted for optimization, and a recorded meeting converted to text for automatic minutes. Samsung has not confirmed those accounts. What the company did confirm, through an internal memo reported in May 2023, was a restriction on generative tools across company devices and internal networks while it built a secure internal environment. If the reporting is accurate, the motives are the notable part, since troubleshooting, optimization and taking minutes describe three people solving three ordinary problems rather than anyone taking a risk. It is also worth dating the case honestly: in early 2023 that division had no approved instrument at all, which makes it an argument for provisioning something, and no evidence at all about an inadequate approved path.

Review and Verification as Separate Controls

Return to Deloitte, since the second failure mode has almost no literature and one very good case.

Every variable a person-directed program optimizes was already set. The staff were trained. Review of output against source materials was required and performed. What the letter records is that the review corrected some errors and missed others, and that the misses surfaced only when a journalist asked.

The word review was carrying two different tasks. One asks whether the output looks right: is it coherent, is it formatted correctly, does it say the sort of thing the section should say. The other asks whether the underlying source says what the text claims it says, which means opening the source. A fabricated or misdescribed citation passes the first without difficulty and fails the second immediately, and the two tasks take very different amounts of time. Almost no workflow distinguishes between them, budgets separately for each, or names who owns the second.

The Deloitte case carries one more lesson that cuts against a comfortable reading of it. The tools that produced the errors were not the approved ones. The department had consented to a toolchain in its own tenancy for code analysis, and the citation work ran through tools brought to the task by a trained team inside a governed engagement. That is scope creep, not defiance, and it is what the second failure mode usually looks like: somebody extending a sanctioned practice one step past where anyone had thought about it.

Professional practice already has the vocabulary for this and has had it for decades, which suggests the problem is transfer, not invention. Auditors distinguish analytical review, which asks whether a number is plausible against expectations, from substantive testing, which goes to the underlying record. Law firms run cite-checking as a distinct task with a distinct owner, historically a junior associate whose entire job for a week was pulling every case. Both professions learned, expensively, that the plausibility check and the source check are different work and that only one of them catches a fabrication.

Naming an owner for the second is not a governance abstraction. It means a person, identified before the work starts, whose sign-off is required before an AI-assisted assertion leaves the organization, with time allocated for it in the engagement plan rather than absorbed into somebody’s evening. It means a threshold, since verifying every sentence is not affordable and nobody should pretend otherwise: assertions that reach a client, a regulator or a board get verified, and internal drafts do not. And it means a record, so that the question of how a document was produced has an answer that does not depend on anyone’s memory. None of that is expensive. It is merely unassigned, which in a professional-services firm or a bank is a strange thing for an accountability question to be.

Mata v. Avianca makes the verification point in a setting where the consequences were formal. Judge Castel sanctioned two lawyers and their firm in June 2023 after a filing cited nonexistent judicial opinions with fabricated quotations, and he was careful about what he was punishing. He wrote that there is nothing inherently improper about using a reliable artificial intelligence tool for assistance, and that the record would look quite different had counsel come clean when the citations were first challenged. The bad faith he found lay in continuing to stand behind the opinions afterward. The initial error was a verification failure. The sanction attached to what happened after nobody had verified.

The Off-Channel Communications Precedent

Financial services has already run this experiment, in a different technology, at a scale that produced numbers.

In September 2022 the Securities and Exchange Commission charged fifteen broker-dealers and one affiliated investment adviser over widespread and longstanding failures to preserve business communications, with penalties exceeding 1.1 billion dollars, and the Commodity Futures Trading Commission ordered eleven institutions to pay more than 710 million the same day. The SEC respondents included entities of Barclays, Goldman Sachs, Morgan Stanley, Citigroup, UBS and Deutsche Bank, each of which admitted the facts in its order and acknowledged that the conduct violated the recordkeeping provisions. Those orders describe employees at multiple levels of authority, supervisors and senior executives among them, conducting business over personal messaging applications for years.

The reading that suits a governance argument is that strict rules failed. The more useful reading is that during the conduct window the compliant equivalent did not exist in usable form. Clients wanted encrypted mobile messaging, and mobile-native archiving was not deployed at most of these firms. The behavior was not evasion of a working channel so much as movement toward the only channel that did the job, by people who knew the rule and had a client on the other end.

What happened afterward is the part worth taking. The industry did not respond with more attestation. It captured the channel people were actually using, named an accountable owner with a budget, usually a head of communications surveillance reporting into compliance, and backed the rule with monitoring, where the old control had been a signature at the end of a training module. Behavior moved. It took approximately 1.8 billion dollars in penalties to get there.

Anyone waiting for the equivalent enforcement wave before naming an owner for the generative equivalent should at least be waiting on purpose.

Ownership and Measurement Gaps

The prescriptions in the literature are sound and belong to the people who wrote them. Sebastian recommends phased risk-based targeting of high-risk roles, workflows and data types over uniform rollout, policy translated into cues inside the workflow such as in-application banners and redaction prompts, explainability protocols and auditable logs treated as core requirements, and explicit intellectual property language, which was the one deterrent that showed a meaningful association in his model. Silic and colleagues recommend registries, role-specific training, internal audits and escalation protocols.

The gap none of them names sits one level up, and it is less of a vacancy than it is usually described as. Large enterprises do have an owner for the internal assistant, usually a platform product owner under the technology or data function, running it with a roadmap, an intake queue and adoption targets. What that role owns is adoption, measured in seats, monthly active users and prompt volume. Nobody owns sufficiency, meaning the distance between what the platform can do and what the work actually requires, and nothing measures displaced demand, meaning the work that quietly leaves. A dashboard shows what arrived. Nothing shows what walked.

Sufficiency has a specification, and it can be written into a requirement. The approved path accepts the file formats the work arrives in. It handles the data classes the role routinely touches. It runs on a model close enough to the public frontier that the output is worth having. And it authorizes a new use in days rather than quarters. Miss any one of those and the path loses on a Friday afternoon to a browser tab that costs nothing.

Two honest constraints belong beside that specification. The first is price: a path meeting all four is a platform program with a standing team, not a configuration change, and an organization choosing the module over the platform should at least know it is making a purchase decision. The second is that some capability cannot be granted at all. Special-category health data, privileged material, a jurisdiction where the frontier model is not deployed, a decision that triggers model validation under supervisory expectations. For those, the correct answer is that the capability will not be provided, and the control is detection and consequence rather than a wider envelope. A governance argument with no category of legitimate refusal is not a governance argument.

Which leaves four things a transformation or program leader can put into a portfolio dashboard next quarter, all of them inside an existing remit. Time from request to authorization for a new use, reported alongside the completion rates. Format and data-class coverage of the sanctioned path against the roles that actually use it. Displaced demand, estimated from egress telemetry the security function already collects. And named verification ownership for any workflow whose output reaches a client, a regulator or a board, recorded in the register that already exists.

Two of those four will meet resistance, and it is worth knowing where from. Time from request to authorization is uncomfortable to report, since it makes visible a queue that several functions contribute to and none owns, and the first response to publishing it is usually a dispute about how the clock should be defined. That dispute is the useful part. Displaced demand is harder still, since estimating it requires the security function to share egress telemetry with people who have never asked for it, and the request lands better when framed as demand signal than as compliance monitoring.

What this displaces is worth stating plainly, since a portfolio is finite. Adding these four means something else comes off the governance agenda, and the candidate is the reporting line that currently consumes the most committee time for the least information, which in most organizations is the awareness completion rate. Retiring it will be resisted on the grounds that a regulator expects to see it. Usually a regulator expects to see a control, not that particular metric, and the substitution is available to anyone willing to make the argument once.

Fairness requires one more thing, since this article has spent several sections asking what evidence supports the incumbent remedy. The argument made here is not itself evidenced in the way it demands of others. No published study shows that reducing authorization latency lowers disclosure, that format coverage predicts platform preference, or that assigning verification ownership reduces error rates in delivered work. The provisioning cases available, JPMorganChase’s internal suite at more than two hundred thousand employees and Bankinter’s move of the capability inside its own perimeter, are design decisions whose outcomes nobody has published. An argument that criticizes unmeasured remedies and then proposes unmeasured remedies has not earned much.

So it is worth saying what would show this wrong. If an organization reduced its time from request to authorization by an order of magnitude, brought the sanctioned path to format and data-class parity for a given population, and saw no change in that population’s egress to unsanctioned endpoints, the capability argument would be substantially refuted and the habit explanation would take the field. If verification ownership were assigned and timed on client-facing workflows and the error rate in delivered work did not move, the review-versus-verification distinction would be a distinction without a consequence. Both tests are runnable inside a single business unit in two quarters, at a cost far below what either full remedy would take. That nobody has run them is the more interesting fact, and it is the same fact this article has been describing throughout: the variable is unowned, so nobody is measuring it, so the question stays open while everyone keeps buying the intervention that reports well.

The sentence that opens this in a governance forum is short. Somebody asks how a document was produced, and either a name exists or it does not.

An underwriter at a commercial insurer, working a forty-page claim bundle against a Monday reserve committee, is a composite rather than a reported incident, and the useful version of the scene is not the one where the upload succeeds. In a well-controlled firm the upload fails, correctly, and the file never leaves. The work is still due Monday. The organization has spent real money to ensure that the wrong thing does not happen and has assigned nobody at all to the question of what happens instead.

In New South Wales, that question had no owner until it had already been answered badly. At Deloitte, review had an owner and verification did not, which turned out to be the same thing.

References

Bankinter. (2023, July 17). Bankinter marca un hito en innovación al integrar la versión empresarial de ChatGPT garantizando la confidencialidad de los datos [Bankinter sets a milestone in innovation by integrating the business version of ChatGPT, guaranteeing data confidentiality].

Board of Governors of the Federal Reserve System & Office of the Comptroller of the Currency. (2011). Supervisory guidance on model risk management (SR 11-7; OCC Bulletin 2011-12). [Rescinded 17 April 2026 and replaced by SR 26-2; OCC Bulletin 2026-13; FDIC FIL-15-2026.]

Center for Internet Security. (2024). CIS critical security controls (Version 8.1).

Deloitte Touche Tohmatsu. (2025, September 2). [Letter to A. Avakian, First Assistant Secretary, Commercial Division, re: Targeted Compliance Framework Final Report dated 4 July 2025] (Document 1, FOI 25-26-084). Australian Government Department of Finance.

Gurman, M. (2023, May 2). Samsung bans staff’s AI use after spotting ChatGPT data leak. Bloomberg.

Information and Privacy Commission NSW. (n.d.). Statement relating to the NSW Reconstruction Authority data breach. Retrieved September 9, 2026.

International Organization for Standardization & International Electrotechnical Commission. (2023). Information technology — Artificial intelligence — Management system (ISO/IEC 42001:2023).

Jeong, D. [정두용]. (2023, March 30). [단독] 우려가 현실로…삼성전자, 챗GPT 빗장 풀자마자 ‘오남용’ 속출 [[Exclusive] Fears become reality: Misuse erupts at Samsung Electronics as soon as the ChatGPT ban is lifted]. 이코노미스트 [Economist].

Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023).

Microsoft. (2025, October 13). Rise in “shadow AI” tools raising security concerns for UK organisations. Microsoft UK Stories.

National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1

Netskope. (2026). Cloud and threat report: 2026.

NSW Reconstruction Authority. (2026, March 26). Resilient Homes Program data breach. NSW Government.

Piepszak, J. (2025). Future-proofing the company and our operations. In JPMorganChase, Letters to shareholders from line of business CEOs, Chief Operating Officer and Head of Corporate Responsibility (pp. 1–3).

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector, OJ L 333, 27.12.2022, pp. 1–79.

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024.

Sebastian, G. (2026). Digital shadow AI risk theory (DART): A framework for managing data disclosure and privacy risks of AI tools at work. Technological Forecasting and Social Change, 229, Article 124697. https://doi.org/10.1016/j.techfore.2026.124697

Silic, M., Silic, D., & Kind-Trüller, K. (2025). From shadow IT to shadow AI–Threats, risks and opportunities for organizations. Strategic Change. Advance online publication. https://doi.org/10.1002/jsc.2682

U.S. Commodity Futures Trading Commission. (2022, September 27). CFTC orders 11 financial institutions to pay over $710 million for recordkeeping and supervision failures for widespread use of unapproved communication methods (Release No. 8599-22). U.S. Securities and Exchange Commission. (2022, September 27). SEC charges 16 Wall Street firms with widespread recordkeeping failures (Press Release No. 2022-174).


Discover more from Adolfo Carreno

Subscribe to get the latest posts sent to your email.

← Previous El Cierre de una Transformación no Distingue la Suspensión de la Resolución