Skip to content

Decision guide · Compliance and audit readiness

Not every compliance pitch is a legal obligation. Some are.

Privacy law, client contracts, and insurance requirements create real obligations - so does a vendor selling a framework nobody asked for. The decision is telling the two apart, then naming who owns the evidence.

An audit finding is really a question nobody assigned an owner to answer.

Compliance pressure arrives from several directions at once: a privacy law that applies because of where customers live, a clause buried in a client contract, a cyber-insurance renewal that assumes certain controls exist, or a vendor pitching a framework with genuine but optional value. Treated as one undifferentiated pile, organizations either over-invest in whatever was pitched most recently, or under-invest because nothing has visibly failed yet.

The more useful move is triage: which obligations are actually created by law or contract, which are best practice worth adopting anyway, and - for each real obligation - who owns keeping the evidence current, so the answer exists before a client, insurer, or regulator asks for it.

This is deliberately distinct from the site's governance guide. Governance sets the internal cadence for deciding; this page is about the external substance of the obligation itself, and who can prove it's being met.

Boundary

This is a leadership decision-advisory lens for triaging obligations and naming an evidence owner. It does not replace a qualified legal opinion, a certified audit, or a specialist privacy assessment, which remain separately scoped.

Obligation sources

Where a real obligation actually comes from.

SourceWhat actually creates the obligationTypical trigger to actCommon blind spot
Privacy legislationA statutory duty tied to the data you actually hold.A new jurisdiction, customer base, or data type.Assuming a policy document alone satisfies the law.
Client or partner contractA signed clause, not a preference.A security questionnaire or a new master agreement.Nobody reads the clause until the client asks about it.
Cyber-insuranceRenewal terms that assume specific controls are in place.A renewal, or a claim.Coverage assumed on controls nobody actually verified.
Industry standard or frameworkOptional, unless a contract or regulator requires it.A partner mandates it, or leadership wants credibility.Treating "adopting a framework" as equivalent to passing an audit.

Decision lenses

Six questions before the next compliance pitch.

  • Legal basisIs this obligation created by statute, contract, or preference - and can that be named?
  • Evidence ownerWho is accountable for producing proof this is being met, on short notice?
  • Renewal & review timingWhen does this obligation get re-tested, and by whom?
  • Client-facing exposureWould a client's security questionnaire expose a gap here today?
  • Gap severityIs the shortfall cosmetic, or does it carry real legal or contractual consequence?
  • Independent verificationDoes this genuinely require a certified audit, or an internal evidence owner?

Working process

Triage before you invest in proving anything.

  1. List every claimed obligation

    Include what a vendor has proposed, not only what's already written into a contract.

  2. Separate law and contract from best practice

    Name the actual source for each item - the response is different depending on which it is.

  3. Name the evidence owner

    One accountable role per real obligation, responsible for producing proof, not just believing it.

  4. Set the review point

    Before the next renewal, audit, or questionnaire - not after it lands.

Governance sets the cadence; this page names what the cadence has to actually prove

Hypothetical pattern

A security questionnaire nobody could answer confidently

A client's annual security questionnaire asks for evidence of a control the company genuinely believes it has. Nobody can produce that evidence quickly, and the response deadline is a week away. The useful decision isn't a rushed scramble to document everything at once - it's deciding, in advance, who owns producing that proof for each real obligation, long before the questionnaire arrives.

See how a regulatory clock starts during a real incident

Next step

Bring the obligation nobody has confirmed is actually real.

A focused brief can turn a vendor pitch or a client clause into a triaged list with a named evidence owner.