The Real Cost of Compliance Is the Change It Silently Displaces

Perspective·Giovanni Leonardi·October 2003·8 min read

The most expensive compliance work is often the change the organisation no longer has the capacity to make.

Beyond Audit Fees

The compliance programme has an approved budget of £4.2 million. The figure covers external advice, additional audit work, temporary staff, documentation tools and a central team of 18 people. It has been examined, challenged and approved.

It is also wrong.

Across the organisation, 37 finance and operational managers are spending between one and three days each week documenting controls, supplying evidence and agreeing remedial actions. Eleven change projects are borrowing specialists from the same functions. Five projects have quietly moved milestones because their business representatives are no longer available. A planned simplification of the month-end close has been deferred because nobody wants to alter a process while its controls are being documented and tested.

None of this appears in the compliance budget. The programme is reported as financially on track.

This is the cost nobody budgeted for: not the visible price of assurance, but the transformation capacity consumed, delayed or frozen in order to produce it.

The distinction matters because the present governance response is being managed as a finite compliance exercise. New obligations are translated into a workplan, staffed, funded and measured. Yet the work reaches into the same processes, systems and people that organisations are already trying to change. Compliance does not sit beside transformation. It competes with it — and usually wins without the competition being acknowledged.

The Budget Counts Purchases, Not Absorption

Conventional programme budgets are good at identifying bought cost. They capture advisers, contractors, software, travel and central headcount. They are far weaker at recognising absorbed cost: the time of existing managers, the decisions deferred and the change that becomes harder because the organisation is trying to prove the stability of today’s process.

A composite control programme illustrates the mechanism. The central team estimates that documenting and testing 900 controls will require 26,000 hours. That estimate covers the people assigned directly to the work.

It does not cover:

  • process owners preparing explanations before workshops;
  • finance teams retrieving invoices, reconciliations and approval records;
  • technology staff producing access reports and change histories;
  • managers negotiating whether a weakness is a finding or a documentation gap;
  • project teams revising designs to preserve newly documented controls;
  • repeated retesting after evidence proves incomplete.

The programme therefore measures the production of assurance but not the capacity required to feed that production.

This omission has a predictable effect. Central compliance remains on plan while local functions fall behind elsewhere. Transformation milestones slip for apparently unrelated reasons: a design decision takes two weeks longer, a test cycle lacks business attendance, or a process owner declines to change a procedure until the auditors have finished. The cost is scattered across other budgets and explanations, so no one sees the total.

The most expensive compliance work is often the change the organisation no longer has the capacity to make.

Control Work Freezes the Wrong Things

The hidden cost is not only labour. It is the way control documentation changes organisational behaviour.

When teams are asked to demonstrate that a process is controlled, they naturally seek a stable description. They name the steps, owners, approvals and evidence. Testing then assesses whether the described process operated as stated.

Transformation introduces the opposite condition. It changes steps, reallocates ownership, replaces systems and removes approvals that no longer add value. A process under redesign is difficult to document and test because its future state is not yet operating and its current state is already marked for retirement.

Faced with that tension, organisations often choose apparent prudence:

  • postpone the redesign until testing is complete;
  • document a temporary process as though it were permanent;
  • add controls around a weakness rather than remove its cause;
  • retain manual reconciliations because they produce familiar evidence;
  • exclude the change programme from the compliance scope and create a later assurance problem.

Each choice is understandable. Together they create a control environment that is easier to inspect and harder to improve.

The most damaging example is the preservation of manual work. A monthly reconciliation may require three people and two days, yet produce a signed sheet that auditors can readily examine. Replacing it with an integrated system control may be operationally superior, but during transition the evidence is unfamiliar, responsibility moves and the new control has no history of operation. The organisation can therefore appear safer by retaining the inefficient process.

Compliance has then stopped being a guardrail for transformation and become a reason not to transform.

The Price of Trust Is Real

The strongest objection is that these costs are unavoidable. Recent failures of corporate reporting have demonstrated what happens when controls are assumed rather than evidenced. If managers must devote time to ownership, documentation and testing, that is the legitimate price of restoring trust. Complaining about the burden risks repeating the complacency that made stronger governance necessary.

That argument is substantially right. Assurance cannot be produced without effort, and some organisations are discovering basic responsibilities they should have understood long ago. The answer is not to weaken the work or treat transformation as an excuse for incomplete control.

But unavoidable cost and unmanaged cost are not the same. The direct effort required to establish reliable controls is a governance necessity. The duplication, delay and process freezing created by poor integration are organisational choices.

A compliance team that documents controls without understanding the change portfolio will repeatedly stabilise processes scheduled for replacement. A transformation team that redesigns processes without building auditable control into the future state will force duplicate work later. Both programmes can meet their individual plans while the organisation pays twice.

The serious response is therefore to manage compliance and transformation as claims on the same scarce capacity and the same process architecture.

Put the Hidden Cost on the Decision

The hidden cost becomes manageable only when it is made visible at the point of decision.

Every material compliance workstream should identify three forms of demand:

  • Direct cost — external spend and dedicated internal resources.
  • Absorbed capacity — time required from process owners, operators, finance, technology and management.
  • Displaced change — projects delayed, redesigned or abandoned because the same people or processes are committed to assurance work.

This does not require artificial precision. A credible range is more useful than a false exact number. If 37 managers are expected to contribute an average of one day a week for six months, the programme should show roughly 1,000 manager-days of absorbed capacity. If that contribution affects eleven projects, the steering committee should see which milestones and benefits are exposed.

The governance forum should then make explicit choices:

  1. Which control work is mandatory now?
  2. Which existing change should be accelerated because it removes the control weakness?
  3. Which changes must pause, and what benefit is being deferred?
  4. Where can one body of evidence serve both compliance and programme assurance?
  5. Which temporary controls have an expiry date and named removal owner?

These questions convert hidden cost into accountable trade-off.

The same discipline should apply to scope. Controls should not be documented simply because they exist. They should be prioritised by the material risk they address. A catalogue of 900 controls may create more work and less insight than a smaller set organised around the critical assertions, systems and judgement points that could materially misstate performance.

Compliance Should Finance Better Change

The present investment in governance can produce more than binders and test results. It is exposing duplicate approvals, undocumented workarounds, concentrated access, inconsistent definitions and manual reconciliations. Those findings are a map of transformation demand.

Yet many programmes treat remediation as a list of local actions: update the procedure, add a signature, conduct another review. That response closes the finding while preserving the mechanism that created it.

A better response distinguishes between:

  • evidence failure — the control may work but cannot be demonstrated;
  • execution failure — the designed control is not consistently performed;
  • design failure — the control cannot reliably address the risk;
  • process failure — the underlying operation creates the risk repeatedly.

The first two may justify documentation, training or supervision. The latter two should feed the transformation portfolio. If six business units maintain separate supplier records and reconcile them manually, the long-term answer is not six better reconciliation folders. It is a deliberate decision about common data, ownership and systems.

This is where compliance can repay part of its cost. The evidence gathered for assurance can identify where change will remove recurring control effort. But that value appears only if remediation funding, transformation priorities and control findings are considered together.

The Cost We Choose

Stronger governance is not free, and it should not be. Reliable reporting and accountable management require investment. The mistake is to believe that the approved compliance budget describes that investment.

The real cost includes the managers taken from delivery, the redesign postponed, the manual process preserved and the benefit deferred. When those consequences remain outside the business case, leaders cannot distinguish necessary assurance from avoidable organisational friction.

The solution is not a smaller compliance programme by default. It is an honest one: a programme that measures absorbed capacity, records displaced change, aligns evidence with the future process and turns structural weaknesses into transformation priorities.

Organisations will pay for stronger control one way or another. They can pay through deliberate investment in better processes and clearer accountability, or through years of duplicated effort, frozen change and hidden delay.

Only the first cost belongs in a credible governance response.


More from Transformation