Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Compliance Framework topic
No spam. Unsubscribe anytime.
University proposes centralized compliance structure, elevates Chief Compliance Officer role
Summary
University leaders proposed shifting from a decentralized compliance model to a hub‑and‑spoke system that would elevate the Chief Compliance Officer, add a Chief Privacy Officer, recharter governance committees and formalize cross‑unit compliance partners and affinity groups.
Get email alerts on the Compliance Framework topic
No spam. Unsubscribe anytime.
The Audit and Compliance Committee of the University of Minnesota Board of Regents heard a proposal in April 2026 to centralize the institution’s compliance functions, elevate the Chief Compliance Officer and create a Chief Privacy Officer to consolidate privacy and data governance responsibilities.
Executive Vice President for Finance and Operations Greg Goldman told the committee the initiative "is not a response to any specific incident, issue, or finding of fraud" but is "a proactive effort to align the University with evolving institutional best practices." Goldman said the current decentralized model leads to information flowing "vertically within silos rather than horizontally" and limits visibility into system‑wide risks.
Under the proposed framework, the Chief Compliance Officer would be elevated from an operational role to a strategic leader who works directly with chancellors and other senior leaders to coordinate compliance across campuses. Reporting to the CCO, the University would create a Chief Privacy Officer position to bring HIPAA, European GDPR obligations and other privacy functions under the Office of Institutional Compliance and to coordinate with FERPA responsibilities in the Provost’s office.
Goldman described a revamped Compliance Partner Network and Cross‑Functional Affinity Groups that would connect subject‑matter experts across units to a formal Institutional Strategic Risk and Compliance Group convened by the CCO. Those groups, Goldman said, are intended to "identify emerging risks and translate them into actionable information for leadership," with clear escalation paths when trends emerge.
The proposal calls for rechartering the Executive Oversight Committee and the President’s Policy Committee so senior leaders can review system‑wide risk and ensure administrative policies receive focused review before finalization. Goldman said the University will launch a national search for a new Chief Compliance Officer and hire a Dedicated Privacy Officer, with a progress update expected at the Committee’s December meeting and core elements operational by the end of the calendar year.
Chief Auditor Gaalswyk highlighted a related recommendation in the compliance landscape analysis about the Chief Auditor’s administrative reporting line, noting best practices would place administrative reporting with the President while preserving functional reporting to the Audit and Compliance Committee. Gaalswyk said the current arrangements rely in part on informal practices—"a gentleman’s handshake"—and that codifying the administrative line could formalize expectations without eroding audit independence.
Regents asked how the new structure would handle public‑facing units. Regent Mohammed urged that the University consider surrounding communities and the general public as part of affinity‑group risk thinking; Goldman responded that affinity groups will evolve and that units such as UMPD could be incorporated to bring public interaction expertise into the framework. Regent Huebsch pressed for attention to research compliance and athletics, which Goldman acknowledged as high‑priority areas for coordinated oversight.
The committee did not take any formal votes on the framework at the meeting; Goldman said the presentation represents a roadmap for governance and staffing changes to be pursued by administration and returned to the Committee for updates.

