The Governance of No: How the Audit Committee Became Transformation’s Quiet Veto

Essay·Giovanni Leonardi·May 2002·13 min read

A control philosophy built entirely on prevention has no vocabulary for a risk worth taking.

The paper that waits

There is a particular silence that falls in a boardroom when a transformation programme comes before the audit committee. The programme director has prepared for weeks. The pack is thorough: the business case refreshed, the risk register scrubbed, the dependencies mapped, the assurance opinion appended. And then, after the questions have been asked and the concerns noted, the decision is not a decision at all. It is a deferral. We would like to see this again once the control environment is clearer. The programme leaves the room exactly as it entered it, minus a month.

I have watched this sequence often enough to stop treating it as an accident of personality — the cautious chairman, the sceptical non-executive, the finance director having a difficult quarter. It is not personality. It is structure. The body we have asked to protect the organisation from harm has, in a great many organisations, quietly become the body that protects it from change. In the present climate — with the audit profession under a scrutiny it has not known in a generation, and the wreckage of at least one company once held up as the model of the new economy still being picked over in the financial press — that instinct is only hardening. This essay is an attempt to understand why, and to separate the part of it that is wisdom from the part that is merely fear wearing the costume of prudence.

How oversight acquired its remit

It is worth remembering how recent the modern audit committee is, and how quickly its territory has grown. A little over a decade ago it was, in most listed companies, a modest thing: a subcommittee that met a few times a year, received the external auditor, reviewed the annual accounts, and went home. The reforms that followed the governance debates of the early nineties gave it a firmer footing and a clearer purpose — independence from management, a majority of non-executives, a defined responsibility for the integrity of financial reporting.

Then the remit widened. The successive codifications of good practice, and in particular the guidance on internal control that now sits at the heart of how boards think about risk, handed the audit committee a much larger brief. It was no longer only the guardian of the numbers. It was, increasingly, the board’s instrument for satisfying itself that the whole apparatus of internal control was sound — financial, operational, and, in the language now current, the management of business risk in the round. On paper this is unarguable. A board must know that its controls work. Someone must hold that question.

The difficulty is what happens when a body defined by the integrity of the existing system is asked to pass judgement on changing it. Transformation is, by its nature, the deliberate dismantling and rebuilding of parts of the control environment. A new finance platform rewrites the reconciliation controls. A shared-service consolidation moves the boundaries of accountability. An outsourcing arrangement places part of the process — and part of the risk — beyond the organisation’s own walls. Every one of these is, from the vantage point of assurance, a period of elevated exposure. And the committee whose entire orientation is the soundness of control is being asked to bless a plan whose first act is to disturb it.

The audit committee was designed to ask whether the system is sound. Transformation asks it to bless a plan whose opening move is to make the system, for a time, less sound. The two questions are not the same, and confusing them is the origin of the problem.

Why the reflex persists

If this were merely a matter of individual temperament it would resolve itself as committees changed their members. It does not resolve, and that tells us the causes are structural. Several forces sustain the pattern, and they reinforce one another.

  • The asymmetry of blame. A committee that waves through a transformation which later fails will be asked, pointedly, why it did not look harder. A committee that delays or dilutes a transformation which the organisation genuinely needed will almost never be called to account, because the cost of the change that did not happen is diffuse, deferred, and easy to attribute to the market. The incentives are not balanced. One kind of error is visible and career-ending; the other is invisible and nobody’s fault.
  • The literacy gap. Audit committees are, by design, composed of the financially literate — former finance directors, career auditors, the numerate and the prudent. This is exactly what the assurance of financial reporting requires. It is not what the assessment of a transformation requires. A member fluent in the reading of a balance sheet may have no instinct at all for whether a programme’s delivery approach is sound, whether its benefits case is credible, or whether the risk it is running is the intelligent kind or the reckless kind. Faced with a domain they cannot read, prudent people default to the answer that feels safe: not yet.
  • The cadence mismatch. Assurance runs on a slow, periodic rhythm — the quarterly cycle, the annual opinion. Transformation runs on the rhythm of delivery, which is faster and far less forgiving of pause. When a programme’s momentum meets a committee’s calendar, the calendar wins, and each deferral to the next cycle costs weeks that the delivery plan never recovers.
  • The conflation of control with prevention. This is the deepest of the forces, and the one most worth naming. Somewhere in the maturing of the discipline, control came to be understood as the prevention of things going wrong, rather than as the informed governance of things that might. Once that equation is made, every change is a threat, because every change carries the possibility of something going wrong. A control philosophy built entirely on prevention has no vocabulary for a risk worth taking.

Consider a composite that will be familiar in outline. A mid-sized institution proposes to replace an ageing set of ledger and reconciliation systems — a genuine necessity, the old platform being both fragile and expensive to keep alive. The business case is sober: some eighteen million pounds over three years, the larger part of the benefit coming not from headcount but from the retirement of a sprawl of manual workarounds that themselves represent a standing control risk. The programme comes to the audit committee for endorsement. The committee, entirely reasonably, asks about the risk to the control environment during cutover. The answers are good but not perfect, because at that stage they never are. The endorsement is deferred for one cycle, then a second, while further assurance is commissioned. By the time it is given, two things have happened: the delivery window has slipped past the point where the original sequencing works, and the manual workarounds — the actual live control risk — have run for another five months. The committee has diligently reduced the risk of the change and, in doing so, silently extended the risk of the status quo. Nobody in the room intended this. The structure produced it.

Control as prevention Control as informed risk-taking
Asks: what could go wrong if we change? Asks: what is the risk of changing weighed against the risk of not?
Treats stability as the goal Treats the organisation’s viability as the goal
Reads every disturbance as exposure Reads disturbance as sometimes necessary, and governs it
Rewards deferral Rewards good decisions, taken in time
Blind to the cost of the status quo Prices the status quo as one option among others

The case for caution — taken seriously

It would be too easy, and quite wrong, to treat the cautious committee as simply mistaken. The strongest version of the opposing case deserves to be met head on, because it is genuinely strong, and never more so than now.

The argument runs like this. The last few years have been a lesson in the price of enthusiasm. Organisations poured extraordinary sums into transformation on the promise of the new economy, and a great deal of it was value destroyed — systems that never delivered, ventures that never made a return, business cases that were exercises in optimism dressed as analysis. The correction has been brutal and is still being felt. And now, on top of that, the integrity of the numbers themselves — the very foundation on which every business case rests — has been called into question by failures that have shaken confidence in audit itself. In such a moment, is not a hard, sceptical, change-resistant audit committee exactly what shareholders should want? Is not restraint the responsible posture? If the committee errs, surely it should err towards saying no.

This deserves a real answer, not a dismissal. And the answer is not that caution is wrong. It is that undirected caution is a failure of governance as surely as reckless enthusiasm is. A committee that says no to everything is not exercising judgement; it is declining to exercise judgement, and hiding the abdication behind the respectable word prudence. The lesson of the failures is not that change is dangerous and stability safe. It is that judgement was absent — that boards approved what they did not understand and assured what they had not examined. The remedy for absent judgement is present judgement, not a blanket reflex in the other direction. A committee that reflexively defers has learned exactly the wrong lesson from the crisis: it has concluded that the problem was action, when the problem was action without understanding.

“A committee that says no to everything is not exercising judgement. It is declining to, and calling the refusal prudence.”

There is, too, a hard truth buried in the current crisis that cuts the other way. Several of the organisations now held up as cautionary tales were not brought down by reckless transformation. They were brought down, in part, by a failure to change — by clinging to models and practices that the world had moved past, and by control cultures that were superb at policing the known and blind to the emerging. The status quo is not the safe harbour it presents itself as. It is simply the risk that does not have to be argued for.

Governing the quality of risk, not its absence

If the diagnosis is that the audit committee has confused control with prevention, then the reframe is to restore the older and truer meaning of control: the informed governance of risk, including the risk that is worth running. This is not a softening of oversight. In many ways it is a hardening of it, because it asks harder questions than is this safe?

The committee that governs the quality of risk asks, of any transformation, a different set of questions. Not what could go wrong alone, but what is the risk of this change set against the risk of standing still, and have both been honestly priced? Not is the control environment undisturbed, but is the disturbance understood, sequenced, and time-boxed, and is there a credible plan to restore control on a known horizon? Not can we defer this to be sure, but what does deferral itself cost, and who is accounting for it? These are not comfortable questions. They demand that the committee hold the cost of inaction on the table alongside the cost of action, which is precisely the discipline the prevention mindset removes.

Return to the composite institution and its ledger replacement, and imagine the committee posed the second set of questions. It would still probe the cutover risk — rightly, and hard. But it would also insist that the five-month life of the manual workarounds be entered on the risk register as a live exposure with an owner, so that every deferral had a visible price. It would ask for the disturbance to be sequenced and time-boxed rather than open-ended, and it would treat a credible plan to restore control by a named date as an acceptable answer, rather than demanding the impossible certainty that no risk exists. The change would proceed, governed rather than blocked — and the committee would have done more, not less, for the integrity of the organisation.

  1. The first move is to make the cost of the status quo visible — to require that any decision to defer names what deferral costs and who owns that cost.
  2. The second is to insist that transformation risk be bounded — sequenced, time-boxed, with a defined return to a steady state — so that the committee is governing a period of managed exposure rather than an open-ended one.
  3. The third is to close the literacy gap honestly — to recognise that assessing a transformation requires a competence the committee may not hold, and to bring that competence to the table rather than substituting caution for it.

None of this is a checklist to be applied and forgotten. It is a change of posture — from the guardian who protects the system by keeping it still, to the steward who protects the enterprise by governing how it moves.

The committee we actually need

Picture the boardroom again, and the programme director with the pack, and the silence. In the version we began with, the silence ends in deferral, and the programme leaves minus a month, and everyone in the room feels they have been responsible. In the version we might build, the silence ends in something harder: a genuine interrogation of the risk on both sides of the ledger, a decision priced against the cost of not deciding, and — where the case holds — a yes with conditions and a date. That is not a less rigorous committee. It is a far more rigorous one, because it has taken on the question it was quietly avoiding: the risk of standing still.

The corporate failures of this season will, quite rightly, drive a tightening of oversight, and much of that tightening will be welcome. But there is a wrong lesson available to be learned, and it is the easy one: that the task of governance is to resist. It is not. The task of governance is to enable the organisation to do difficult and necessary things well, and to know that it is doing them well. An audit committee that only ever says no has not solved the problem the crisis exposed. It has merely found a respectable place to hide from it. The organisations that come through the next decade in good order will not be the ones whose committees were hardest to persuade. They will be the ones whose committees learned, in a fearful season, to tell the difference between prudence and paralysis.


More from Transformation