In this episode of Compliance Unfiltered, The CU Guys breakdown one of the most important compliance skills: learning how to say no to customers. Adam explain why organizations should protect internal security documents, route all requests through a centralized process, and use NDAs when prospects start asking detailed technical questions. The conversation also covers the value of using a portal to manage compliance work, keep evidence organized, and streamline future engagements. Plus, they review major security news, including recent breaches, critical vulnerabilities, and a cautionary AI mishap that deleted production data in seconds. If you want practical guidance on protecting sensitive information without hurting relationships, this episode is for you.


Episode Transcript:

It is that time again. That’s right, ladies and gentlemen, security reminder time for Q3 of 2026.

As always, Adam, we’d like to tell the folks at this point in the conversation that we appreciate them. We’re thankful for their time and their energy.

As always, we say, give us a rating or review on your favorite podcast app of choice, Spotify, Apple, whatever it happens to be. Let the folks know that you like us. It helps the podcast greatly.

Also, feel free to reach out to us at complianceunfiltered@totalcompliancetracking.com. Give us your ideas for show topics, your perspective on the things that we are or aren’t doing that you love, and anything else you would like to share with us.

Adam, for Q3 security reminders, we are getting started with learning to say no to customers. Tell us more.

Adam Goslin:
In the grand scheme of things, it is a capability that some organizations struggle with.

Our focal topic this time around is compliance reporting. What do you not want to share with your customers and, more aptly put, telling them no?

When a customer is asking for proof you’re compliant with a particular standard, you need to make sure you’re providing the right information to satisfy their request.

There’s a ton of your information that nobody outside of your company has any right to see. It’s critical that the listeners and their personnel understand exactly what to share and what not to share when third parties are asking for various elements of proof.

This issue comes up all the time. A lot of organizations just straight hand over whatever they ask for and keep their big clients happy.

It’s important that folks know their rights, educate their employees, know what to provide, protect the company, and do things properly.

Certainly, safeguarding internal reports is one arena we’re going to get into.

As an example, if you’re going up against PCI DSS and doing a full Report on Compliance, or a ROC, or going through a Self-Assessment Questionnaire D, those are internal reports.

There’s a myriad of information within them that external entities don’t have any right or reason to see.

In PCI’s case, they provide an externally facing summary report that’s known as the Attestation of Compliance, or AOC, which summarizes the compliance posture and is very well suited for external distribution.

The same general premise applies for every compliance standard. If you’ve got detailed reports revealing granular details about the internal environment, tools you’re using, how your systems are configured, etc., don’t distribute those.

Only issuing your externally appropriate summary of your security posture to third parties is appropriate.

The next arena I want to touch on is a centralized distribution channel.

One of the problems folks have is managing those inbound inquiries appropriately and making sure that there is a central function to handle any of those inquiries and for distributing any of your security and compliance documentation.

Podden och tillhörande omslagsbild på den här sidan tillhör Total Compliance Tracking. Innehållet i podden är skapat av Total Compliance Tracking och inte av, eller tillsammans med, Poddtoppen.