Kriski Inc. All articles
Compliance & Risk Management

Regulatory Blind Spots That Blindsided US Companies in 2024—And the Q1 Action Plan to Get Ahead of Them

Kriski Inc.
Regulatory Blind Spots That Blindsided US Companies in 2024—And the Q1 Action Plan to Get Ahead of Them

Photo by Photo by Sebastian Herrmann on Unsplash on Unsplash

The close of a fiscal year rarely arrives quietly. For compliance officers, general counsel, and operations leadership across the United States, the final quarter typically surfaces the unresolved residue of twelve months of regulatory evolution—policy updates that were noted but never fully implemented, reporting requirements that were partially addressed, and emerging enforcement priorities that caught entire industry verticals off guard.

2024 was no exception. In fact, by most measures, it was a particularly consequential year for regulatory exposure. Federal agencies increased enforcement activity, state-level legislation introduced new layers of complexity, and several high-profile settlements served as costly reminders that good intentions do not constitute good compliance.

At Kriski Inc., we work alongside organizations navigating exactly these pressures. What follows is a data-informed examination of the five compliance risks that most consistently created organizational vulnerability last year—along with the practical corrective steps that can meaningfully reduce exposure before Q1 audits begin.


1. Data Privacy Obligations Beyond HIPAA and PCI: The Expanding State Patchwork

For years, many US organizations treated data privacy compliance as a binary concern—either they handled protected health information (and therefore answered to HIPAA) or they processed payment card data (and therefore managed PCI-DSS obligations). That framework collapsed in 2024.

With comprehensive consumer data privacy laws now active in over a dozen states—including California, Virginia, Colorado, Connecticut, Texas, and Florida—the compliance calculus has grown substantially more complex. Organizations that operate across state lines but have not mapped their data flows to individual state statutes are carrying significant unaddressed exposure.

The most common failure pattern: companies that updated their privacy policies following California's CPRA amendments but did not conduct corresponding audits of their data retention schedules, vendor contracts, or consumer rights response procedures.

Corrective Action: Conduct a cross-state data inventory before Q1 closes. Identify which states your customers, employees, and vendors reside in, then map applicable statutes to your current data handling practices. Prioritize gap remediation in states with active enforcement histories.


2. ESG Reporting: Voluntary Frameworks Are Becoming Mandatory Benchmarks

Environmental, Social, and Governance (ESG) disclosures occupied a peculiar middle ground for much of the past decade. Institutional investors wanted them. Regulators encouraged them. But they were rarely legally required in ways that created acute enforcement risk.

That changed materially in 2024. The SEC's climate disclosure rules—while subject to ongoing litigation—prompted a significant number of publicly traded companies and their supply chain partners to accelerate reporting infrastructure. Simultaneously, California's SB 253 and SB 261 introduced mandatory climate disclosure requirements for large companies doing business in the state, regardless of where they are headquartered.

Organizations that treated ESG reporting as a communications function rather than a compliance function found themselves scrambling. Incomplete scope 3 emissions data, inconsistent methodology documentation, and the absence of third-party verification processes were among the most common deficiencies identified.

Corrective Action: Assign formal ownership of ESG reporting to a cross-functional team that includes finance, legal, and operations. Establish a baseline measurement methodology now, even if your full reporting infrastructure is not yet mature. Documentation of process and good-faith effort carries weight in regulatory contexts.


3. I-9 and Employment Eligibility Verification: Remote Work Created New Exposure

The shift to remote and hybrid work models introduced a compliance gap that many HR departments did not fully anticipate: the physical document inspection requirements embedded in Form I-9 employment eligibility verification.

DHS authorized a temporary virtual document review accommodation during the pandemic. When that accommodation expired in 2023, organizations were required to complete in-person reverification for employees who had been onboarded remotely. Audit activity in 2024 revealed that a meaningful percentage of employers either missed this deadline entirely or completed reverification inconsistently.

Fines for I-9 violations range from hundreds to thousands of dollars per violation, and they scale quickly across distributed workforces.

Corrective Action: Conduct an internal I-9 audit before Q1 enforcement cycles intensify. Identify any employees onboarded between March 2020 and the accommodation expiration who have not undergone compliant in-person reverification. Engage qualified legal counsel to manage any corrections through the proper procedural channels.


4. Financial Services: BSA/AML Program Deficiencies in the Digital Asset Space

Financial institutions—including banks, credit unions, money services businesses, and now a growing category of fintech platforms—continued to grapple with Bank Secrecy Act and Anti-Money Laundering obligations in 2024, particularly as digital asset activity intersected with traditional financial infrastructure.

FinCEN and the OCC both issued guidance updates during the year, and enforcement actions made clear that program deficiencies were not going unnoticed. The most common findings: inadequate customer due diligence (CDD) protocols for high-risk customer categories, insufficient transaction monitoring calibration, and Suspicious Activity Report (SAR) filing delays.

For organizations that added cryptocurrency-related products or services to their portfolio without conducting a corresponding AML program review, the exposure is significant.

Corrective Action: Schedule a BSA/AML program effectiveness review before Q1 examinations begin. Pay particular attention to whether your risk assessment has been updated to reflect any new product lines or customer segments introduced in the past 18 months. Independent review by a qualified compliance consultant is advisable for organizations that have experienced recent product expansion.


5. OSHA Recordkeeping: Electronic Submission Requirements Remain Widely Misunderstood

OSHA's electronic recordkeeping submission requirements—which mandate that establishments of certain sizes submit injury and illness data directly to OSHA's Injury Tracking Application—have been in place for several years. Yet enforcement data from 2024 indicates that non-compliance remains widespread, particularly among mid-sized manufacturers, logistics operators, and healthcare support organizations.

The confusion typically stems from misunderstanding which forms apply to which establishment sizes and how the March 2 annual deadline interacts with internal record-keeping calendars.

Corrective Action: Verify your establishment's submission obligations under 29 CFR Part 1904 before the next filing deadline arrives. Confirm that your OSHA 300 Log, 300A Summary, and 301 Incident Reports are current, accurate, and that your electronic submission credentials for the ITA are active and accessible.


Building a Proactive Compliance Infrastructure

The pattern underlying each of these five risk areas is consistent: organizations that approach compliance reactively—responding to enforcement actions rather than anticipating regulatory shifts—consistently find themselves absorbing costs that a more structured approach would have prevented.

At Kriski Inc., our perspective is straightforward. Compliance is not a legal department function that operates in isolation from the broader business. It is an operational discipline that requires cross-functional visibility, clear ownership, and a systematic process for monitoring the regulatory environment.

The organizations that navigated 2024 most effectively were those that had established governance structures capable of translating regulatory developments into operational action—not just policy documents that lived in a shared drive.

As Q1 audits approach, the most valuable investment an organization can make is an honest internal assessment: not of whether your policies say the right things, but of whether your operational practices reflect them.

Kriski Inc. partners with organizations across industries to conduct exactly that kind of assessment—and to build the infrastructure that transforms compliance from a recurring liability into a durable competitive advantage. Contact our team to discuss how a structured compliance review can be tailored to your industry and your organization's specific risk profile.

All Articles

Keep Reading

When Departments Don't Talk: The Profitability Drain Hidden Inside Your Own Organization

When Departments Don't Talk: The Profitability Drain Hidden Inside Your Own Organization