Category: Operating Models Author: Cody Swidler Tags: policy management, audit findings, compliance debt, policy language, attestation, governance

The worst audit finding I ever helped a client absorb didn't come from a framework, a regulation, or a contract. It came from their own access management policy, page six, one sentence: "Access reviews shall be performed quarterly for all systems." They performed access reviews annually, on the systems that mattered, and did it well. The auditor didn't have to argue that annual was inadequate — the client had already argued it for him, in writing, years earlier. We went looking for who wrote the sentence. Nobody knew. The best theory was a policy review meeting circa four revisions ago, where someone — a well-meaning, thorough, promotion-adjacent someone — suggested that "quarterly" sounded more rigorous than "periodic," and the room nodded, and the word went in. The someone had since left the company. The word stayed. Words always stay.

The military has a name for that someone: the Good Idea Fairy, the creature who hovers over planning sessions sprinkling suggestions that are individually reasonable and collectively fatal. Soldiers fear her because her ideas are never obviously bad — bad ideas die in the room, while good ideas get adopted and then eat the mission. But at least a battle plan gets abandoned at first contact. The fairy's most durable work in corporate life happens somewhere far more dangerous than a planning meeting: inside policy documents. Because a policy doesn't die at first contact. A policy is the one genre of corporate writing where first drafts become law, and the fairy is its most prolific author.

Auditors Grade You Against Your Own Fairy Dust

Here's the mechanism that makes an aspirational policy sentence expensive: auditors, examiners, and customer security reviewers all start from the same move. Before they test you against a framework, they test you against yourself. Your policy is the first requirements document they open, and every commitment in it is a test they will run. "All vendors shall be assessed annually" — congratulations, you've just outlawed the risk-based cadence your TPRM team actually runs, the one I argued for in reassessment cadence should be earned, and converted your smartest operational decision into a nonconformity. "Disaster recovery tests shall be conducted annually for all systems" — the word "all" just enrolled four hundred applications nobody has ever recovered into your test program. "Encryption shall be applied to all data in all states" — somewhere there's a legacy batch job that would like a word. None of these sentences was required. Each one is a finding you wrote for a future auditor, gift-wrapped, with a bow.

This is compliance debt in its purest form: commitments issued with no funding attached. And unlike technical debt, it compounds invisibly, because policy language is almost never costed at write time. A "shall" is free to type. It's only priced at audit time, and by then the author is two jobs away.

How She Gets Into the Document

The fairy has several doors into a policy, and it's worth knowing them because they all look like diligence. There's benchmark envy — someone downloads a Fortune 100's published security policy, or a maximalist template, and adopts commitments scaled for an organization with forty times the headcount. There's the review-cycle ratchet: every annual policy review invites five stakeholders, and each proves their engagement by adding a sentence, because in a policy review, adding language reads as rigor and deleting language reads as negligence. Nobody's performance review ever suffered for inserting a "shall." There's the auditor-appeasement reflex, where last year's finding gets remediated by strengthening the policy language rather than the practice — treating the document as the control, the exact confusion I wrote about in a control that isn't tested is a hope. And there's the purest form: the fairy's favorite word, "all." "All systems." "All employees." "Immediately." "At all times." Quantifiers feel like leadership when you write them and function as liabilities when you're graded on them. Every "all" in a policy is a promise to boil the ocean, made by someone who will not be holding the kettle.

The Exorcism: Every "Shall" Gets a Bill

The fix is not better wordsmithing. It's an intake discipline, the same one that works everywhere else the fairy feeds: no commitment enters the document without its cost attached. Concretely, every "shall" in a policy must map, before publication, to three things — a control that implements it, an owner who performs it, and an evidence source that proves it happened. If you cannot name the report, the log, the register row that would satisfy an auditor asking "show me," then the sentence doesn't ship. It gets downgraded to risk-based language you actually mean, moved to a standard where the specifics can change without executive re-approval, or deleted. This is policy written at the altitude of evidence, and it's the document-layer expression of the connected model I keep returning to: a policy statement should sit at the top of a traceable chain — policy to control to test to evidence — not float above the program like a mission statement with legal exposure.

Run the same test on the stock as well as the flow. A policy refresh should include a fairy audit: search the current documents for "all," "always," "immediately," "any," and "quarterly," and for each hit ask the only question that matters — do we do this, and can I see it? You will find sentences nobody can source, describing practices nobody performs, surviving review after review because deleting a promise feels like lowering the bar. Count them. That number — commitments with no mapped control and no evidence — is your policy debt, and it's a better predictor of your next audit's finding count than any control-gap analysis.

Deleting a Promise Is Not Lowering the Bar

The cultural unlock is getting your organization to believe that sentence. A policy that promises quarterly-everywhere and delivers annually-somewhere is not a rigorous policy; it's a confession with a letterhead. Regulators and auditors consistently treat a modest policy that's demonstrably followed as stronger than an impressive one that isn't — because the first shows a management system that knows itself, and the second shows a management system that writes fiction. The bar isn't the adjective in the document. The bar is the practice, evidenced. Writing "risk-based" where you operate risk-based isn't retreat; it's the only version of the sentence that was ever true.

And here's the asymmetry that makes the modest policy strictly better: a policy is graded in one direction only. Nobody has ever received an audit finding for exceeding their own policy. Commit to annual access reviews and run them quarterly on your critical systems, and the auditor writes down "conforms" — the extra rigor costs you nothing and is yours to flex, scale back, or redirect as the risk picture changes, no document revision, no executive re-approval, no policy exception process. Commit to quarterly and deliver annually anywhere, and you've bought a finding. Performance can always exceed the document; the document can never exceed the performance without penalty. So write the floor you will clear every single time, in every audit, on your worst quarter — and manage the practice above it. The policy is where you make promises. The operating model is where you show off.

My client's remediation, in the end, was two changes. The practice got a genuine upgrade — quarterly reviews on the systems whose risk actually earned it. And the policy lost one word and gained a defensible one: "quarterly for all systems" became "at a frequency commensurate with system risk, per the access management standard." The next audit tested the sentence, found the tiering methodology behind it, and moved on. The Good Idea Fairy still attends every policy review — she's tenured. But now every sentence she proposes comes with an invoice: name the control, name the owner, show me the evidence. It's remarkable how many of her ideas she withdraws once they cost something. The good ones — and she does have them — pay the bill and go in the document, where, for once, they belong.

Cody Swidler is the founder of PivotRisk and Head of Platform Resiliency at Apex Fintech Solutions. He has built and scaled GRC, resilience, and risk programs across Microsoft, Twilio, Box, Zayo, and Miro.

Cody Swidler is the founder of PivotRisk and Head of Platform Resiliency at Apex Fintech Solutions. He has built and scaled GRC, resilience, and risk programs across Microsoft, Twilio, Box, Zayo, and Miro.

Give every "shall" its bill

The Integrated Risk & Control Register gives every commitment a control row with an owner, a test date, and issue tracking that degrades effectiveness until gaps close — so a policy sentence can't outrun what you can prove.

Browse the Templates