List your product on Stack Search

Get in front of thousands of GRC decision-makers

The Strange Afterlife of a Regulation

The Strange Afterlife of a Regulation

By
Key Takeaways
  • Compliance Artifacts Can Outlive Their Purpose: Records, controls, approval chains, and other requirements often persist long after the systems, risks, and circumstances that originally justified them have changed.
  • Regulatory Compliance Has a Second Life: Once the deadline and implementation scramble pass, regulations become embedded in everyday organizational processes, where their original rationale can gradually disappear from institutional memory.
  • Controls Can Become Ritual Rather Than Risk Management: Repeated testing can prove that a control still operates as designed without answering the more important question of whether the control still addresses a meaningful risk.
  • Regulation Also Creates Lasting Institutional Value: GDPR demonstrates how regulation can generate new professions, technologies, disciplines, and ways of thinking that extend far beyond the statute's explicit requirements.
  • Organizations Need to Revalidate, Not Just Maintain: Mature compliance programs should periodically ask not only whether an inherited control or record is being maintained, but whether it remains accurate, necessary, and connected to the risk it was created to address.
Deep Dive

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.

This is not, in any given company, a story about negligence. The person maintaining the record today is very likely conscientious, and so was whoever held the job before them. The problem is structural rather than personal. The artifact has outlived the conditions that gave it meaning, and no one currently responsible for it has the standing, the time, or the mandate to ask what it is actually for.

Every mature regulatory regime produces two histories that run in parallel and rarely speak to each other. The first is the history everyone remembers, the scramble, the outside counsel retained at emergency rates, the board briefed on exposure, the software purchased under deadline pressure with a signing bonus attached to the vendor relationship. This history has a beginning, a climax, and an ending, and the ending is the deadline itself. May 2018 for GDPR. The fiscal years following 2002 for Sarbanes-Oxley. Whatever date sits circled on the calendar of whichever regime a given reader lived through. It is a good story, dramatic and legible, and it gets told at conferences because it has the shape stories are supposed to have.

The second history has no ending, because it is still happening, and it has almost no narrator, because nobody is assigned to watch it. This is the history of what the regulation becomes once the deadline passes and the emergency budget dries up and the outside counsel moves on to the next client's emergency. The quiet sedimentation of a rule into approval chains, data fields, standing committees, quarterly certifications, training modules that new hires click through without absorbing, control descriptions that get copied from last year's audit workpapers because rewriting them from scratch would require someone to remember what the control was supposed to prevent.

A regulation, in its first life, is an event. In its second life, it is furniture. And furniture, once installed, tends to get walked around rather than examined, which is precisely how a segregation-of-duties control written to stop a very particular kind of accounting fraud in 2003 ends up, twenty years later, requiring three sign-offs on a purchase order for office chairs.

Sarbanes-Oxley is instructive here because its second life has been so much longer than its first. The statute was a response to specific catastrophes, invented earnings, captured auditors, a board that either didn't know or didn't ask, and the controls that followed were, in their first years, genuinely responsive to those failures. But controls, unlike the failures that occasion them, do not expire. They get tested, year after year, by internal audit teams whose job is to confirm the control still operates as designed, not to ask whether the risk it was designed against still exists in a form the control could catch. A company's revenue recognition process changes. Its ERP system gets replaced twice.

The specific fraud pattern that worried regulators in 2002 becomes almost quaint against a backdrop of algorithmic trading and instant global settlement. And still, every quarter, someone walks through the same twelve steps and initials the same eleven boxes, because the control exists, and a control that exists must be tested, and a control that has been tested for eighteen consecutive quarters without a finding acquires a kind of institutional immunity to the question of whether it should exist at all. Ritual, in the anthropological sense, is exactly this, an action that continues to be performed after its original justification has become inaccessible to the people performing it. SOX walkthroughs are, in more of the average public company than anyone likes to say out loud, ritual in this precise sense.

It would be too easy, though, to tell this only as a story of decay, of meaning leaking out of process until nothing is left but motion. Regulation's afterlife is generative as much as it is residual. GDPR did not simply calcify into a compliance checklist. It produced an entire profession, the data protection officer, a role that scarcely existed as a discrete career path before 2018 and now has its own certifications, salary surveys, and professional associations, along with a market for consent-management platforms, a discipline called privacy engineering, and a habit of thought, now spreading well beyond Europe and well beyond the letter of the GDPR itself, in which "what happens to this data if it leaks" has become a first-order design question rather than an afterthought bolted on before launch.

None of that was written into the statute. The statute created deadlines and penalties, and the profession, the tooling, and the instinct grew up around it the way a reef grows around a shipwreck, using the original structure as scaffolding for something the original structure never specified. The wreck and the reef are not the same thing, and confusing one for the other, mistaking a DPO's Tuesday morning workload for the actual text of Article 37, is its own quiet failure of institutional memory, just one running in the opposite direction from the Article 30 spreadsheet nobody has properly opened in years.

What makes a regulation's afterlife so hard to see clearly from inside an organization is that both processes, the calcification and the generativity, look identical from the outside. Both produce permanent fixtures, a role, a form, a committee, a control. Only time and a willingness to ask an uncomfortable question separate the fixture that still does work from the fixture that has become a fossil wearing the shape of its former function. And organizations are, almost by design, bad at asking that question, because asking it well requires someone with the authority to touch a control and the humility to admit they don't know why it's there, a combination the org chart rarely produces on purpose.

The person with authority over the Article 30 record inherited it, rather than designed it, and inheriting a thing is not the same as understanding it. The auditor who signs off on the SOX walkthrough is graded on whether the control operated as designed, not on whether the design still makes sense. Everyone involved is doing their job correctly, and the process drifts anyway, one faithfully copied quarter at a time.

Occasionally, someone opens the Article 30 record properly. They trace a phantom vendor relationship back to a contract that lapsed years earlier, delete the row, and feel the small, disproportionate satisfaction of having corrected something that had been wrong longer than they'd held the job. It rarely takes more than an hour. Almost no one is ever asked to do it, not because the question isn't worth asking, but because by the time a regulation has become furniture, the people who walk past it every day have generally stopped seeing it as something that could be asked about at all.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong