PerspectiveGovernance1 min read
Why compliance programmes fail at evidence, not intent
Most organisations do the right things. Far fewer can prove it on demand. The difference is designing controls around the evidence they produce.
By ENKAYT Advisory
In supervisory inspections and certification audits, the question is rarely 'do you have a control?' It is 'show me that it operated, every time it should have, for the whole period.' Programmes that were designed around policies rather than evidence struggle to answer.
Design the evidence first
When a control is designed, decide what artefact proves it ran: a system log, an approval record, a report with a timestamp. If no natural artefact exists, the control is likely to be performed inconsistently and documented after the fact.
Collect once, reuse many times
A quarterly access review can satisfy information security, data protection and sector technology-risk requirements at the same time. Mapping the control to each obligation means the same evidence answers three auditors instead of being regenerated three times.
If the evidence has to be recreated for the audit, the control did not really operate the way you think it did.
Automate the routine
Configuration states, user lists and change tickets can be pulled directly from source systems. People should spend their time on judgement — reviewing exceptions and deciding what to do about them — not on screenshots.
Need this applied to your organisation?
Our team can turn this guidance into an action plan for your regulators, systems and timelines.
Book a consultationRelated reading
1 min read
Board risk reporting that leads to decisions
Directors don't need more data. They need to know what is outside appetite, why, and what decision is being asked of them.
1 min read
A practical roadmap for Sri Lanka's Personal Data Protection Act
Where to start, what to prioritise and how to show progress to your board — a phased approach to the PDPA for organisations that can't do everything at once.
1 min read
AI governance for regulated organisations: five first principles
Most AI risk in regulated firms comes from tools they buy, not models they build. A short set of principles to govern both.
Regulatory notes, monthly
New rules, enforcement themes and practical guidance. One email a month, no promotions.