Business
Collaborate to overcome data privacy obstacles

By Bob McCarter, Chief Technology Officer at NAVEX
Restricted budgets and an increasing number of compliance and data privacy laws and regulations create hurdles for business leaders to manage risks, particularly for third parties.
An organisation must handle several types of risks across multiple areas of the business in a quick, effective, and compliant way. In addition to environmental and external information security threats, organisations must be aware of employee-related risks as well as those that can impact the extended enterprise via third and fourth parties. According to the international industry body, ISACA, over half of cyber professionals are not confident in their organisation’s privacy team’s ability to ensure data privacy and achieve compliance with new privacy laws and regulations. That is why cross-functional collaboration is critical.
With the expanding threat landscape, businesses need to develop a cybersecurity playbook that mitigates risks. It should include training, company-wide discussions, and awareness programmes. Some of the reasons why it is so hard to overcome governance, risk, and compliance (GRC) challenges is because there is a lack of business support, clarity on roles and responsibilities, as well as visibility. To better understand and present the company’s risk posture to the board, digital transformation is imperative. NAVEX’s 2023 State of Governance, Risk, and Compliance Management Report found that GRC programs that were described as “significantly” or “comprehensively” automated are more likely to be managed by a single department compared to GRC programs that have not undergone a digital transformation (45% versus 28%).
An effective programme forms the foundation for creating a culture and work environment that emphasise the importance of outstanding quality and business outcomes.
Avoiding silos
Efforts to improve quality processes, assess and manage risk and control activities, and comply with environmental, safety and other industry-specific regulations are challenged by organisational silos, a focus on proximal needs, and a reliance on point solutions. A siloed approach introduces considerable inefficiencies and, in the worst case, risk management gaps.
NAVEX’s 2023 State of Risk and Compliance Report revealed that integrated risk management remains a work in progress as only about one-quarter of respondents (27%) said their organisation has a centralised integrated risk management program run by senior management. Another third (31%) said they have integrated some, but not all, of their capabilities. However, this percentage is expected to increase as more organisations adopt GRC information systems (GRC-IS) that bring the different functions of risk and compliance into a single platform.
As global regulations continue to evolve, many companies are rushing to ensure they are fully compliant. However, silos pose a great challenge for IT decisionmakers as some businesses are still managing hotlines, training, third parties and speak-up across different departments. More mature businesses are adopting a single view of GRC, rather than a tick box procedure.
What next?
A holistic approach to managing risk requires full visibility. Utilising GRC as a strategy can enable businesses to make informed decisions that fundamentally change the way they manage risk and compliance. However, GRC cannot be managed effectively in silos as it is both impractical and ineffective. This could be detrimental to the business – it increases the likelihood of a data breach, reputational damage, and loss of trust.
For the foreseeable future, there will be a surge in data privacy roles as well as opportunities for existing employees to upskill. Cybersecurity is an ongoing process so there needs to be sustainable measures in place. The same NAVEX report highlighted that nearly one-third (30% in 2023 vs. 22% in 2022) of respondents said their organisation experienced a data privacy/cybersecurity breach in the past three years. Considering this real-world challenge compliance professionals are facing, cybersecurity (60%) and data privacy (57%) are two of the three most chosen topics respondents said their organisation will train on in the next two-to-three years.
Companies should plan ahead and consider investing in a Chief Compliance Officer or Chief Risk Officer. It would be one of their core responsibilities to implement effective risk management solutions and the necessary collaborative approach that is critical to success.
A strong ethics and compliance programme ought to be built on an organisation’s values, people, and principles. This would involve a robust security infrastructure that aligns with the organisation’s compliance posture. One way to achieve this and manage risk across the business is by deploying GRC-IS that gives companies a full view of:
• Front-line employees, who are the organisation’s human security system.
• A reporting system that allows them to report issues as they occur.
• The back office via sanctions management, third party management, and more.
The key to success is to nurture good habits such as open communication, collaboration, and agreed protocols across departments. This is particularly essential for managing data privacy and third-party risks, where there are several personas involved – the CISO/CIO, the supply chain, and the legal/compliance teams. Each with their own priorities, it is ineffective working in silos. At the end of the day, there are many overlapping goals shared between the legal, IT, and security teams. By working together, workload will be distributed and reduced.
You may like
Business
What can the West learn from the Arabian Gulf’s payments revolution?

Hassan Zebdeh, Financial Crime Advisor at Eastnets
A decade ago, paying for coffee at a small café in Riyadh meant fumbling with cash – or, at best, handing over a plastic card. Today, locals casually wave smartphones over terminals, instantly settling the bill, splitting it among friends, and even transferring money abroad before their drink cools.
This seemingly trivial scene illustrates a profound truth: while the West debates incremental upgrades to ageing payment systems, the Arabian Gulf has leapfrogged straight into the future. As of late 2024, Saudi Arabia achieved a remarkable 98% adoption rate for contactless payments in face-to-face transactions, a significant leap from just 4% in 2017.
Align financial transformation with a bold national vision
One milestone that exemplifies the Gulf’s approach is Saudi Arabia’s launch of its first Swift Service Bureau. While not the first SSB worldwide, its presence in the Kingdom underscores a broader theme: rather than rely on piecemeal upgrades to older infrastructure, Saudi Arabia chose a proven yet modern route, aligned to Vision 2030, to unify international payment standards, enhance security, and reduce operational overhead.
And it matters, because in a region heavily reliant on expatriate workers whose steady stream of remittances powers whole economies. The stakes for frictionless cross-border transactions are unusually high. Rather than tinkering around the edges of an ageing system, Saudi Arabia opted for a bold and coherent solution, deliberately aligning national pride and purpose with practical financial innovation. It’s a reminder that infrastructure, at its best, doesn’t merely enable transactions; it reshapes how people imagine the future.
Make regulation a launchpad, not a bottleneck
Regulation often carries the reputation of an overprotective parent – necessary, perhaps, but tiresome, cautious to a fault, and prone to slowing progress rather than enabling it. It’s the bureaucratic equivalent of wrapping every new idea in bubble wrap and paperwork. Yet Bahrain has managed something rare: flipping the narrative entirely. Instead of acting solely as gatekeepers, Bahraini regulators decided to become collaborators. Their fintech sandbox isn’t merely a regulatory innovation; it’s psychological brilliance, transforming a potentially adversarial relationship into a partnership
Within this curated environment, fintech firms have launched practical experiments with striking results. Take Tarabut Gateway, which pioneered open banking APIs, reshaping how banks and customers interact. Rain, a cryptocurrency exchange, tested compliance frameworks safely, quickly becoming one of the Gulf’s trusted crypto players. Elsewhere, startups trialled AI-driven identity verification and seamless cross-border payments, all under the watchful yet adaptive guidance of Bahraini regulators. Successes were rapidly scaled; failures offered immediate lessons, free from damaging legal fallout. Bahrain proves regulation, thoughtfully applied, can genuinely empower innovation rather than restrict it.
Prioritise cross-border interoperability and unified standards
Cross-border payments have long been a maddening puzzle – expensive, sluggish, and unpredictably complicated. Most Western banks seem resigned to this reality, treating the spaghetti-like mess of correspondent banking relationships as a necessary evil. Yet Gulf states looked at this same complexity and saw not just inconvenience, but opportunity. Instead of battling against the tide, they cleverly redirected it, embracing standards like ISO 20022, which neatly streamline data exchange and slash friction from global transactions.
Examples abound: Saudi Arabia’s adoption of ISO 20022 through its Swift Service Bureau will notably accelerated cross-border transactions and improve transparency. The UAE and Saudi Arabia also jointly piloted Project Aber, a digital currency initiative that significantly reduced settlement times for interbank payments. Similarly, Bahrain’s collaboration with fintechs has simplified previously burdensome remittance processes, reducing both cost and complexity.
Target digital ecosystems for financial inclusion
One of the most intriguing elements of the Gulf’s payments transformation is the speed and enthusiasm with which consumers embraced new technologies. In Bahrain, mobile wallet payments surged by 196% in 2021, contributing to a nearly 50% year-over-year increase in digital payment volumes. Similarly, Saudi Arabia experienced a near tripling of mobile payment volumes in the same year, with mobile transactions accounting for 35% of all payments.
The West, by contrast, still struggles with financial inclusion. In the U.S., millions remain unbanked or underbanked, held back by distrust, geographic isolation, and high fees. Digital solutions exist, but widespread adoption has lagged, partly because major institutions view inclusion as a long-term aspiration rather than an immediate priority. The Gulf shows that when digital tools are made integral to daily life, rather than optional extras, the barriers to financial inclusion quickly dissolve.
The road ahead
As the Gulf region continues to refine its payment systems experimenting with digital currencies, advanced data protection laws, and AI-driven compliance the ripple effects will be felt far beyond the GCC. Western players can treat these developments as an external threat or as a chance to rejuvenate their own approaches.
Ultimately, if you want a glimpse of where financial services may be headed towards integrated platforms, real-time international transactions, and widespread digital inclusion – the Gulf experience is a prime example of what’s possible. The question is whether other markets will step up, follow suit, and even surpass these achievements. With global financial landscapes evolving at record speed, hesitation carries its own risks. The Arabian Gulf has shown that bold bets can pay off; perhaps that’s the most enduring lesson for the West.
Business
Unlocking business growth with efficient finance operations

Rob Israch, President at Tipalti
The UK economy has faced a turbulent couple of years, meaning now more than ever, businesses need to stay agile. With Reeves’s national insurance hikes now fully in play and global trade tensions casting a shadow over the landscape, the coming months will present a crucial opportunity for businesses to decide how to best move forward.
That said, it’s not all doom and gloom. The latest official figures show that the UK’s economy unexpectedly grew at a rate of 0.5% in February – a welcome sign of resilience. But turning this momentum into sustainable growth will hinge on effective financial management – essential for long term success.
Although many are currently prioritising stability, sustainable growth is still within reach with the right approach. By making use of data and insights from the finance team, companies can pinpoint efficient paths to expansion. However, this relies on having real-time information at their fingertips to support agile, well-timed decisions.
While achieving growth may be tough to come by this year, businesses can stay on track by adopting a few essential strategies.
Improving efficiency by eliminating finance bottlenecks
Growth is the ultimate goal for any business, but it must be managed carefully to ensure long-term sustainability. Uncertain times present an opportunity to eliminate inefficiencies and build a strong foundation for future success.
A significant bottleneck for many businesses is the finance function’s reliance on manual processes for invoice processing, reporting and reconciliation. These tasks are not only time-consuming but also introduce errors, delays and inefficiencies. As a result, finance teams become stretched thin. Our recent survey found that, on average, over half (51%) of accounts payable time is spent on manual tasks – severely limiting finance leaders’ ability to drive strategic growth.
Repetitive tasks such as data entry, reconciliation, and approvals require considerable time and effort, slowing down decision-making and increasing the risk of inaccuracies. Given the critical role that finance plays in guiding business strategy, these inefficiencies and errors create significant roadblocks to growth.
The pressure on finance leaders is therefore immense and while 71% of UK business leaders believe CFOs should take a central role in corporate growth initiatives, they are simply lost in a sea of manual processes and number crunching. In fact, 82% of finance leaders admit that excessive manual finance processes are hindering their organisation’s growth plans for the year ahead. To remedy this, businesses must embrace automation.
Achieving sustainable growth with automation
By replacing manual spreadsheets with automated solutions, finance teams can eliminate administrative burdens and focus on strategic initiatives. Automation simplifies critical finance tasks like bank feeds, coding bookkeeping transactions and invoice matching. Beyond this, it can also help alleviate the strain of more complex and time-intensive responsibilities, including tax filings, invoices and payroll.
The benefits of automation extend far beyond time saving, to accuracy, improving business visibility and enabling real-time financial insights. With fewer errors and faster-data processing, finance leaders can shift their focus to high-value tasks like driving strategy, identifying risks and opportunities and determining the optimal timing for growth investments.
Attracting investors with operational efficiency
Once businesses have minimised time spent on administrative tasks, they can focus on the bigger picture: growth and securing investment. With access to cheap capital becoming increasingly difficult, businesses must position themselves wisely to attract funding.
Investors favour lean, efficient companies, so demonstrating that a business can achieve more with fewer resources signals a commitment to financial prudence and sustainability. By embracing automation, companies can showcase their ability to manage operations efficiently, instilling confidence that any new investment will be spent and used wisely.
Economic uncertainty provides an opportunity to reassess business foundations and create more agile operations. Refining workflows and eliminating bottlenecks not only improves performance but also strengthens investor confidence by demonstrating a long-term commitment to financial health.
Additionally, strong financial reporting and effective cash flow management are crucial to standing out to investors. Clear, real-time insights into financial health demonstrate resilience and highlight a business’ resilience and readiness for growth.
The growth journey ahead
Though the landscape remains tough for UK businesses, sustainable growth is still achievable with a clear and focused strategy. By empowering finance leaders to step into more strategic and high-level decision making roles, organisations can stay resilient and agile amid ongoing economic headwinds.
UK businesses have fought to stay afloat, so now is the time to rebuild strength. By embracing more strategic financial management to build resilience, they can set the stage for long-term, sustainable growth, whatever the economic climate brings.
Business
The Consortium Conundrum: Debunking Modern Fraud Prevention Myths

By Husnain Bajwa, SVP of Product, Risk Solutions, SEON
As digital threats escalate, businesses are desperately seeking comprehensive solutions to counteract the growing complexity and sophistication of evolving fraud vectors. The latest industry trend – consortium data sharing – promises a revolutionary approach to fraud prevention, where organisations combine their data to strengthen fraud defences.
It’s understandable how the consortium data model presents an appealing narrative of collective intelligence: by pooling fraud insights across multiple organisations, businesses hope to create an omniscient network capable of instantaneously detecting and preventing fraudulent activities.
And this approach seems intuitive – more data should translate to better protection. However, the reality of data sharing is far more complex and fundamentally flawed. Overlooked hurdles reveal significant structural limitations that undermine the effectiveness of consortium strategies, preventing this approach from fulfilling its potential to safeguard against fraud. Here are several key misconceptions about how consortium approaches fail to deliver promised benefits.
Fallacy of Scale Without Quality
One of the most persistent myths in fraud prevention mirrors the trope of enhancing a low-resolution image to reveal more explicit details. There’s a pervasive belief that massive volumes of consortium data can reveal insights not present in any of the original signals. However, this represents a fundamental misunderstanding of information theory and data analysis.
To protect participant privacy, consortium approaches strip away critical information elements relevant to fraud detection. This includes precise identifiers, nuanced temporal sequences and essential contextual metadata. Through the loss of granular signal fidelity required to anonymise information to make data sharing viable, said processes skew data while eroding its quality and reliability. The result is a sanitised dataset that bears little resemblance to the rich, complex information needed for effective fraud prevention. Further, embedded reporting biases from different entities can likewise exacerbate quality issues. Knowing where data comes from is imperative, and consortium data frequently lacks freshness and provenance.
Competitive Distortion is a Problem
Competitive dynamics can impact the efficacy of shared data strategies. Businesses today operate in competitive environments marked by inherent conflicts, where companies have strategic reasons to restrict their information sharing. The selective reporting of fraud cases, intentional delays in sharing emerging fraud patterns and strategic obfuscation of crucial insights can lead to a “tragedy of the commons” situation, where individual organisational interests systematically degrade the potential of consortium information sharing for the collective benefit.
Moreover, when direct competitors share data, organisations often limit their contributions to non-sensitive fraud cases or withhold high-value signals that reduce the effectiveness of the consortium dynamics.
Anonymisation’s Hidden Costs
Consortiums are compelled to aggressively anonymise data to sidestep the legal and ethical concerns of operating akin to de facto credit reporting agencies. This anonymisation process encompasses removing precise identifiers, truncating temporal sequences, coarsening behavioural patterns, eliminating cross-entity relationships and reducing contextual signals. Such extensive modifications limit the data’s utility for fraud detection by obscuring the details necessary for identifying and analysing nuanced fraudulent activities.
These anonymisation efforts, needed to preserve privacy, also mean that vital contextual information is lost, significantly hampering the ability to detect fraud trends over time and diluting the effectiveness of such data. This overall reduction in data utility illustrates the profound trade-offs required to balance privacy concerns with effective fraud detection.
The Problem of Lost Provenance
In the critical frameworks of DIKA (Data, Information, Knowledge, Action) and OODA (Observe, Orient, Decide, Act), data provenance is essential for validating information quality, understanding contextual relevance, assessing temporal applicability, determining confidence levels and guiding action selection. However, once data provenance is lost through consortium sharing, it is irrecoverable, leading to a permanent degradation in decision quality.
This loss of provenance becomes even more critical at the moment of decision-making. Without the ability to verify the freshness of data, assess the reliability of its sources or understand the context in which it was collected, decision-makers are left with limited visibility into preprocessing steps and a reduced confidence in their signal interpretation. These constraints hinder the effectiveness of fraud detection efforts, as the underlying data lacks the necessary clarity for precise and timely decision-making.
The Realities of Fraud Detection Techniques
Modern fraud prevention hinges on well-established analytical techniques such as rule-based pattern matching, supervised classification, anomaly detection, network analysis and temporal sequence modelling. These methods underscore a critical principle in fraud detection: the signal quality far outweighs the data volume. High-quality, context-rich data enhances the effectiveness of these techniques, enabling more accurate and dynamic responses to potential fraud.
Despite the rapid advancements in machine learning (ML) and data science, the fundamental constraints of fraud detection remain unchanged. The effectiveness of advanced ML models is still heavily dependent on the quality of data, the intricacy of feature engineering, the interpretability of models and adherence to regulatory compliance and operational constraints. No degree of algorithmic sophistication can compensate for fundamental data limitations.
As a result, the core of effective fraud detection continues to rely more on the precision and context of data rather than sheer quantity. This reality shapes the strategic focus of fraud prevention efforts, prioritising data integrity and actionable insights over expansive but less actionable data sets.
Evolving Into Trust & Safety: The Imperative for High-Quality Data
As the scope of fraud prevention broadens into the more encompassing field of trust and safety, the requirements for effective management become more complex. New demands, such as end-to-end activity tracking, cross-domain risk assessment, behavioural pattern analysis, intent determination and impact evaluation, all rely heavily on the quality and provenance of data.
In trust and safety operations, maintaining clear audit trails, ensuring source verification, preserving data context, assessing actions’ impact, and justifying decisions become paramount.
However, the nature of consortium data, which is anonymised and decontextualised to protect privacy and meet regulatory standards, cannot fundamentally support clear audit trails, ensure source verification, preserve data context, and readily assess the impact of actions to justify decisions. These limitations showcase the critical need for organisations to develop their own rich, contextually detailed datasets that retain provenance and can be directly applied to operational needs to ensure that trust and safety measures are comprehensive, effectively targeted, and relevant.
Rethinking Data Strategies
While consortium data sharing offers a compelling vision, its execution is fraught with challenges that diminish its practical utility. Fundamental limitations such as data quality concerns, competitive dynamics, privacy requirements and the critical need for provenance preservation undermine the effectiveness of such collaborative efforts. Instead of relying on massive, shared datasets of uncertain quality, organisations should pivot toward cultivating their own high-quality internal datasets.
The future of effective fraud prevention lies not in the quantity of shared data but in the quality of proprietary, context-rich data with clear provenance and direct operational relevance. By building and maintaining high-quality datasets, organisations can create a more resilient and effective fraud prevention framework tailored to their specific operational needs and challenges.

What can the West learn from the Arabian Gulf’s payments revolution?

Unlocking business growth with efficient finance operations

The Consortium Conundrum: Debunking Modern Fraud Prevention Myths

Stealthy Malware: How Does it Work and How Should Enterprises Mitigate It?

Future-proofing the workforce for AI innovations with continuous learning
