CCI staff share recent surveys, reports and analysis on risk, compliance, governance, infosec and leadership issues. Share details of your survey with us: editor@corporatecomplianceinsights.com.
Less than 10% can point out a sanctioned person
Just under 10% of compliance, legal and financial services professionals are fully confident they could spot a sanctioned individual hiding behind a shell company or a corporate web, a survey by VinciWorks concluded.
Asking 146 of these professionals how confident they were in spotting an indirect sanctions risk, only about 1 in 10 said they were “very confident.” At almost 46%, the biggest share said they were “fairly confident,” while another roughly 30% said they were “somewhat confident.” About 15% said they were not very confident or not confident at all.
“Ninety percent of compliance professionals telling us they lack full confidence in this area should concern any organization operating across borders,” Naomi Grossman, compliance manager at VinciWorks, said as part of the survey. “Sanctions regimes have grown far broader than a simple list of frozen bank accounts.”
The survey also found that about 60% reported that their escalation process for a sanctions match had not been tested recently. About 40% described their escalation process as clear and regularly tested.
Other key findings include:
- Compliance teams are more exposed on judgement-based checks than on basic screening with 55% saying that establishing ownership and control or understanding end users and supply chains is their greatest challenge.
- Only around 11% pointed to screening names and counterparties as their greatest sanctions risk identification challenge.
Small businesses more likely to reach security readiness standard
Data analysis by security and compliance software provider Drata found that enterprise organizations reach readiness for SOC 2 observation quicker than emerging companies but peak at a lower readiness percentage and often don’t reach full readiness.
The analysis based on data from thousands of Drata customers, concluded that enterprise organizations tend to plateau in SOC 2 readiness fastest — averaging 602 days to their peak readiness — but they also tend to plateau lower, capping out at just 30% average max readiness with only 5.5% ever reaching 100%.
Emerging and small- to mid-sized businesses take longer to hit their SOC 2 readiness ceiling at an average of 829 days but climb higher once they get there, averaging 55% max readiness. These businesses also reach 100% readiness 17% of the time. That’s three times more often than large enterprises.
“Essentially, if you’re a small business, don’t worry if you’re starting from scratch — you may take longer to plateau, but you’re more likely to actually get all the way there,” Drata said in the report.
AI finding cyber weaknesses ranks as top emerging threat
AI exploiting cyber vulnerabilities is the most concerning emerging risk facing companies worldwide, according to a survey by Gartner.
In a survey of 316 senior executives and risk managers from April to May about the top emerging risks, AI discovery of cyber vulnerabilities ranked the highest.
Geopolitical energy supply shocks ranked as the second highest emerging risk among those surveyed. Companies are seeing growing risk that geopolitical conflicts, sanctions and infrastructure disruption generate recurring supply shocks across production, distribution and logistics that increase price volatility, complicate planning and amplify broader macroeconomic instability, the report said.
Risks concerning agentic AI came in at No. 3, with respondents fearing that agentic AI could make decisions not aligned with organizational plans, leading to operational disruptions, compliance challenges and reputational harm.
Company leaders also ranked information integrity risk and AI workforce preparedness gap as emerging threats.








