Frequently Asked Questions

GRC Fundamentals & Communications Compliance

What is Governance, Risk, and Compliance (GRC) and how does it relate to communications compliance?

Governance, Risk, and Compliance (GRC) is an integrated enterprise framework that establishes accountability, identifies and mitigates risk, and ensures adherence to laws, regulations, and internal policies. In communications compliance, GRC connects regulatory obligations to day-to-day practices by integrating governance (policy setting and enforcement), risk management (identifying and mitigating threats), and compliance (operationalizing and evidencing regulatory requirements). Mature GRC programs unify these disciplines, enabling organizations to track obligations, manage audit trails, and provide unified dashboards for compliance officers. Note: GRC effectiveness depends on continuous monitoring and integration with surveillance and archiving systems. Source.

What are the three pillars of GRC and how are they applied in communications compliance?

The three pillars of GRC are Governance (policy setting and accountability), Risk Management (identifying, assessing, and mitigating threats), and Compliance (translating obligations into operational practice and evidencing adherence). In communications compliance, governance determines which channels employees can use and who owns surveillance programs; risk management addresses threats like unmonitored channels and excessive false positives; compliance tracks regulatory requirements and produces audit-ready records. Note: Effective GRC requires continuous review and integration with surveillance and archiving systems. Source.

Which regulatory frameworks intersect with GRC in communications compliance?

Key regulatory frameworks intersecting with GRC include COSO ERM Framework (internal control and risk management), ISO 31000 (risk management standards), MiFID II/MiFIR (EU communication recording and retention), Dodd-Frank Act (US trade reporting and conduct oversight), FINRA Rules 3110 & 4511 (US broker-dealer supervision and recordkeeping), HIPAA (US healthcare privacy and audit), FCA SYSC & MAR (UK conduct and market abuse), and SOX (US corporate governance and financial reporting). Note: Regulatory requirements vary by jurisdiction and business line; organizations must map each requirement to specific controls and workflows. Source.

Features & Capabilities

What are the key features of Shield's platform for communications compliance?

Shield's platform offers advanced AI-driven surveillance (97% reduction in false positives), comprehensive data coverage (over 100 data sources, including voice, email, chat, and social media), native language surveillance for 14 languages, on-demand translation for over 99 languages, proactive supervision, rapid eDiscovery, centralized data management, and adherence to global retention requirements. Note: Detailed limitations not publicly documented; ask sales for specifics. Source.

Which integrations and connectors does Shield support?

Shield supports integrations with Microsoft Teams, Zoom, WhatsApp (Business), Symphony, WeChat, Microsoft Exchange, Office 365, Gmail, SMS/MMS, Bloomberg IB and Mail, ICE Chat, FX Connect, and voice/turret communications. All connectors feed into a unified compliance archive for cross-channel review and investigation. Note: For a full list, visit Shield's Connectors Page. Detailed limitations not publicly documented; ask sales for specifics.

Does Shield offer an API for compliance data access?

Yes, Shield provides an enterprise-grade API suite called the Shield API Hub. It enables direct access to compliance data (alerts, policy violations, audit logs, communications metadata), integrates with BI and case management systems, and features two-layer JWT authentication for security. Note: API limitations not publicly documented; ask sales for specifics. Source.

Security & Compliance

What security and compliance certifications does Shield hold?

Shield is SOC 2 Type II and ISO 27001 certified, GDPR-aligned, and DORA-compliant. The platform employs zero trust architecture, end-to-end encryption, segregated multi-tenant environments, and undergoes yearly SOC 2 audits and independent penetration testing. Note: For more details, visit Shield's Security Page. Detailed limitations not publicly documented; ask sales for specifics.

How does Shield ensure customer data protection and privacy?

Shield ensures data remains in the customer's environment, with no transfer to third-party locations. It uses isolated, encrypted, and controlled environments, aligning with global regulatory requirements (Dodd-Frank, MiFID II, MAR). Note: Limitations regarding data residency or export not publicly documented; ask sales for specifics. Source.

Product Information & Use Cases

What products and services does Shield offer for communications compliance?

Shield offers Shield.Data Hub (centralized communication data archive), Shield.Discover (rapid eDiscovery), Shield.Surveillance (AI-driven compliance automation), Shield.Supervision (proactive supervision tools), and Shield.InfoBarriers (restricted list management). These products are designed for financial institutions, energy trading companies, and other highly regulated industries. Note: Product limitations not publicly documented; ask sales for specifics. Source.

Who is Shield's platform designed for?

Shield's platform is designed for compliance teams, IT teams, legal teams, supervisory managers, Chief Compliance Officers (CCOs), and Heads of Surveillance in financial institutions, energy trading companies, and other highly regulated industries. Note: Suitability for other industries not publicly documented; ask sales for specifics. Source.

What business impact can customers expect from using Shield?

Customers can expect enhanced regulatory compliance (e.g., managing over 5.5 million daily communications for a Tier 1 Financial Group), operational efficiency (97% reduction in false positives, 0.15% alert rate for a US Energy Trading Company), improved risk mitigation, cost savings, faster investigations, and centralized data visibility. Note: Impact may vary based on organization size and requirements. Source.

Pricing & Implementation

How is Shield's pricing model determined?

Shield's pricing is tailored to each customer based on communication volume, required connectors, and monitored channels. It offers predictable pricing with no export or exit fees. For a customized quote, contact Shield's team. Note: Exact pricing details are not publicly documented. Source.

How long does it take to implement Shield's platform and how easy is it to start?

Shield's platform can be implemented in as little as 3 weeks, even for large organizations. It integrates seamlessly with existing systems, requires minimal technical resources, and provides dedicated Customer Success Managers and tailored training. Customers have access to a detailed knowledge base for technical documentation and troubleshooting. Note: Implementation time may vary based on complexity and requirements. Source.

Customer Proof & Success Stories

Who are some of Shield's customers and what results have they achieved?

Shield is used by organizations such as UBS, Credit Agricole, and FIS. Customers have achieved a 97% reduction in false positive alerts, faster investigations, and reduced compliance costs. For more details, visit Shield's customer success page. Note: Results may vary by organization and use case.

Can you share specific case studies or success stories of Shield customers?

Case studies include a global financial firm achieving unified monitoring for eComms and voice surveillance, a Tier 1 Financial Group managing over 5.5 million daily communications, a US Energy Trading Company achieving a 95% reduction in false positives and a 0.15% alert rate, and a Tier 2 investment bank using Shield's eDiscovery platform to manage 200,000 daily communications. For more, visit Shield's customer success page. Note: Case study outcomes may not be representative for all customers.

Technical Requirements & Support

What technical documentation and support resources are available for Shield's platform?

Shield provides a detailed knowledge base through the Shield Support portal, including technical documentation, FAQs, and troubleshooting guides. Customers also receive tailored training and dedicated Customer Success Managers. Note: Support resource limitations not publicly documented; ask sales for specifics. Source.

Shield Glossary

GRC

What Is Governance, Risk, and Compliance?

Governance, Risk, and Compliance (GRC) is the integrated enterprise framework through which organizations establish accountability structures, identify and mitigate risk, and ensure adherence to laws, regulations, and internal policies. Rather than treating these three disciplines as separate functions, a mature GRC program recognizes that they are deeply interdependent. Governance shapes the policies that define acceptable risk. Risk management informs compliance priorities, and compliance obligations feed back into governance structures.

GRC is the operational backbone that connects regulatory obligations to day-to-day communications compliance practice. It answers three fundamental questions: 

  • Are we making the right decisions? 
  • Are we managing what could go wrong? 
  • And are we doing what we’re required to do?

The Three Pillars of GRC

Governance

Governance is the system by which an organization directs and controls itself. It sets policies, assigns accountability, and aligns day-to-day decisions with strategic objectives. It determines who has authority, who is responsible, and how performance is measured.

In a communications compliance context, governance answers specific questions. 

  • Which channels can employees use? 
  • Who owns the surveillance program? 
  • How does senior management receive assurance that regulatory obligations are being met?

Effective governance does not simply document policies. It ensures those policies are owned, enforced, and reviewed as the regulatory landscape changes. Two frameworks are widely used to structure this work. The COSO Framework (Committee of Sponsoring Organizations) provides principles for internal control and enterprise risk management. ISO 31000 is the international standard for risk management principles and guidelines.

Risk Management

Risk management is the structured process of identifying, assessing, prioritizing, and mitigating threats to the organization. Those threats can be operational, regulatory, reputational, or financial.

In a communications compliance program, risk takes concrete forms. An employee conducting business over an unmonitored channel. A surveillance system drowning reviewers in false positives while genuine misconduct goes undetected. An archiving infrastructure that fails to capture a newly adopted collaboration tool.

A robust GRC approach goes deeper than point-in-time assessments. Risk must be monitored continuously as regulations change, new channels emerge, and employee behavior shifts. ISO 31000 risk management standards, provides a structured methodology for embedding this kind of ongoing risk thinking into organizational decision-making, rather than treating it as a periodic exercise.

Compliance

Compliance is the function that translates external regulatory obligations and internal policies into operational practice and provides evidence that those obligations are being met. For firms subject to communication oversight mandates, compliance encompasses the full lifecycle of a regulatory requirement, including understanding what is required, implementing controls that satisfy it, testing those controls, documenting the results, and producing audit-ready records on demand.

In communications compliance specifically, GRC platforms track obligations across multiple regulatory regimes simultaneously, such as MiFID II, Dodd-Frank, HIPAA, FINRA, and FCA, mapping each requirement to the specific controls and archiving workflows that address it, and surfacing gaps before regulators do.

GRC in Communications Compliance: How It Works in Practice

A GRC framework applied to communications compliance does more than maintain a policy document library. Mature implementations integrate directly with the archiving, surveillance, and eDiscovery infrastructure that captures and monitors employee communications. In practice, this means:

Regulatory Obligation Tracking 

GRC platforms maintain a live inventory of the regulatory requirements applicable to the firm by jurisdiction, business line, and communication channel. It maps each requirement to the specific controls designed to address it. When a regulation changes, the platform surfaces the gap between current controls and new requirements.

Audit Trail Management

Every surveillance review, supervision decision, policy exception, and escalation generates a record. GRC platforms consolidate these records into a coherent audit trail that demonstrates to an examiner or in litigation that the firm’s compliance program is designed correctly and operating effectively.

Compliance Officer Dashboards 

Rather than requiring compliance officers to manually aggregate data from disparate systems, GRC platforms provide unified visibility into program health all in one place. This includes alert rates, review completion rates, open cases, policy exceptions, and regulatory deadlines.

Integration with Archiving and Surveillance

The most effective GRC implementations treat archiving and surveillance systems as data sources feeding into the broader governance framework. Archived communications provide the evidentiary foundation; surveillance outputs generate the risk signals; GRC provides the structure for acting on those signals consistently, documenting the response, and demonstrating program effectiveness over time.

Examples of Governance Risks

Governance risks arise when the structures meant to direct and control an organization break down. In a communications compliance context, the most consequential include:

  • Off-channel communication adoption without policy response — Senior leadership or revenue-generating employees using personal devices or consumer apps for business communications, without compliance teams having visibility or the authority to address it
  • Accountability gaps in surveillance program ownership — Unclear lines of responsibility between compliance, legal, IT, and business line management for surveillance coverage, creating blind spots that only become visible during a regulatory examination
  • Policy frameworks that lag regulatory change — Internal communications policies that have not been updated to reflect new channel coverage obligations, revised retention periods, or expanded surveillance requirements under amended rules
  • Inadequate escalation structures — Surveillance alerts reaching reviewers without clear protocols for when to escalate, who has authority to close a case, and how decisions must be documented
  • Board and senior management information gaps — Governance failures at the executive level, where compliance program performance data is not surfaced in a form that enables meaningful oversight and accountability

GRC, DCGA, and AI: The Convergence

The convergence of GRC with AI-powered Digital Communications Governance and Archiving (DCGA) represents the current frontier of communications compliance. Where traditional GRC frameworks were largely manual, such as policy documents, periodic audits, and spreadsheet-based obligation tracking, modern platforms integrate AI surveillance directly into the governance layer.

AI-powered surveillance reduces the volume of communications requiring human review, but the GRC framework determines what happens next, including how alerts are triaged, who reviews them, what documentation is generated, and how the overall program is reported to senior management and regulators. Without a robust GRC structure, even the most sophisticated AI surveillance produces outputs that are difficult to act on consistently, defend in an examination, or improve over time.

Conversely, GRC frameworks without modern surveillance and archiving infrastructure are increasingly inadequate for the scale and complexity of digital communications in regulated firms. The firms best positioned for regulatory scrutiny are those that have unified these disciplines using AI to generate precision signals and GRC to ensure those signals are governed, documented, and defensible.

Key Regulatory Frameworks Intersecting with GRC

  • COSO ERM Framework — Enterprise risk management principles widely adopted in financial services governance programs
  • ISO 31000 — International standard for risk management principles, framework, and process
  • MiFID II / MiFIR — EU requirements for communication recording, retention, and reporting in investment services
  • Dodd-Frank Act — US financial reform legislation with broad implications for trade reporting, recordkeeping, and conduct oversight
  • FINRA Rules 3110 & 4511 — US supervision and recordkeeping obligations for broker-dealers
  • HIPAA — US healthcare communication privacy, security, and audit requirements
  • FCA SYSC & MAR — UK conduct, systems and controls, and market abuse requirements
  • SOX (Sarbanes-Oxley) — US corporate governance and financial reporting integrity requirements with communication record implications