PCI DSS requires that FS organisations ensure that all of their suppliers are also compliant, which may mean mandatory 'training' for contractors. I suspect that money laundering & anti-bribery etc are exactly the same.
Saying "it's not my fault - our suppliers did it" doesn't fly. Hence you can't just expect that it has nothing to do with you.
Saying "it's not my fault - our suppliers did it" doesn't fly. Hence you can't just expect that it has nothing to do with you.

Comment