Controls at real world speed fail where culture is weak
Last issue teased something practical: designing controls that work at real world speed, and evidence by design.
Here’s the bridge that matters.
Controls fail first where culture is weak.
Evidence by design is not a tooling problem.
It is an ownership and challenge problem.
Before we redesign controls, we need to diagnose the culture mechanics that decide whether controls operate under pressure.
This week kicks off Risk Culture Month with a simple proposition:
Risk culture is visible in control outcomes.
Culture is the mechanics of ownership, challenge, accountability and escalation in the flow of work.
If you’re a CFO, FD, Group FC, CAE, Head of Controls, Head of Risk, or an Audit, Risk or Controls Practitioner, this isn’t a theory piece. It’s about a practical reality: the numbers and the control environment only stay credible if the organisation can surface truth early, make decisions quickly, and produce evidence without theatre.
Before you read on, if you’re seeing controls fail under pressure, this is a useful starting point: take my free Risk Culture Scorecard and get a personalised PDF report showing where ownership, challenge, accountability and escalation are weakening control outcomes (more details further down in this issue).
What “real world speed” actually means
When we talk about controls at real world speed, we’re really talking about one question:
Do controls still operate when it’s inconvenient?
Because the moment you add pressure, three things happen:
People compress timelines and skip steps
Teams trade quality for speed
The system starts rewarding the behaviours that reduce immediate pain, even if they increase long-term risk
And that’s where culture shows up.
Not in values. In outcomes.
The uncomfortable truth about repeat failures
Most organisations don’t have a knowledge problem. They have a repeat problem.
The same issues keep returning because the system has learned to cope, not fix.
It looks like:
Close pressure that never improves, even after “process improvements”
Controls that exist on paper, but operate inconsistently
Evidence created late, rebuilt, or “found”
Overrides that become normal because they keep work moving
Actions that sit open for weeks, then close quickly right before reporting
Escalations that happen late, when the options are worst and the cost is highest
Micro example: an aged action stays open for weeks. Then it gets closed quickly just before the audit committee pack or the steering committee update. The status looks clean. But the underlying risk is still sitting there, waiting for the next cycle.
That one behaviour tells you a lot:
The organisation values presentation
The organisation has weak ownership under pressure
The organisation delays escalation
Accountability arrives late, not early
That’s culture, made visible.
Why “culture” is a control environment issue first
When people say “risk culture”, it often turns into one of two unhelpful conversations:
A moral conversation: “people need to care more”
A brand conversation: “we need better values and comms”
But if you’re responsible for control outcomes, those conversations don’t move the work.
CFOs and FDs don’t need culture slogans. They need:
fewer surprises
cleaner evidence
faster escalation
clearer decisions
fewer repeat findings
That’s why I keep coming back to this framing:
Risk culture is a control environment issue before it’s a people issue.
Because the control environment is where culture becomes operational:
who owns what
who can challenge what
what gets escalated
how quickly decisions get made
what behaviour is rewarded when pressure hits
Fix those mechanics, and you change outcomes without launching a “culture programme”.
The four pillars we’re focusing on this week
For Risk Culture Month, I’m using seven pillars overall. But this week is about the four pillars that show up fastest in control outcomes:
Tone in action
Ownership mindset
Challenge safety
Clarity of accountability
If these are weak, you can redesign controls all year and still get the same failures, just dressed up in new templates.
Want to access free Risk Culture Scorecard? Click the image to start the assessment:
Pillar 1: Tone in action beats tone at the top
Tone at the top is what leaders say.
Tone in action is what leaders consistently do, especially when it’s inconvenient.
Tone in action is the daily signal that teaches people:
what gets prioritised
what gets tolerated
what gets challenged
what gets escalated
who gets protected
If you want to know whether tone in action is weak, look for these patterns:
Bad news travels slowly
Issues surface late, usually via audit
Leaders ask for updates, not evidence
Exceptions become normal
People avoid escalation because it feels like conflict
Micro example: a manual override is used to “keep things moving”. Nobody asks for rationale because it worked. Nobody asks who approved it because the team is under pressure. It becomes normal, and the organisation learns a quiet rule: delivery matters more than control intent.
That is tone in action.
And it’s why tone at the top doesn’t matter if tone in action is weak.
Pillar 2: Ownership mindset is the foundation of evidence by design
Evidence by design is often positioned as a tooling conversation.
Sometimes it is.
But most of the time, tooling is not the first constraint.
The first constraint is ownership.
Ownership mindset means:
one named owner for each key control
a clear definition of what “done” means
time protected to operate the control properly
evidence created at the point of activity, not reconstructed later
the owner has authority to remove blockers
When ownership is soft, evidence becomes archaeology.
People “find” documents. They rebuild packs. They recreate narratives. They chase sign-offs. It looks like work, but it’s not control operation.
Micro example: a reconciliation is marked complete to protect the close timetable. Evidence is thin, so it’s rebuilt later. The close moves on, the risk stays hidden, and when it surfaces you’re already into explanation and justification.
That’s not a spreadsheet problem. It’s a control ownership problem.
Pillar 3: Challenge safety is how you stop exceptions becoming normal
Challenge safety is not a “nice to have”. It’s the mechanism that surfaces risk early.
If challenge is unsafe, people will wait until:
the audit raises it
the regulator forces it
the issue becomes public
the pressure becomes unbearable
By then, the organisation pays in rework, reputational risk, and leadership credibility.
Weak challenge safety looks like:
people wait for audit or risk to raise issues
challenge is labelled negative
meetings reward certainty more than truth
escalation feels career limiting
Strong challenge safety looks like:
assumptions questioned early without blame
peer challenge normalised
escalation treated as judgement, not disloyalty
leaders protect challengers
The practical test is simple:
Who can disagree with the most senior person in the room, and still be seen as helpful?
Pillar 4: Clarity of accountability removes politics
Politics is what happens when the system won’t decide.
When decision rights are unclear and escalation routes are vague:
meetings become negotiations
owners drift
issues get “socialised” endlessly
accountability becomes inconsistent
challenge becomes personal
Micro example: a repeated reconciliation break is discussed every week. Everyone agrees it matters. But nobody owns the decision to fix upstream, stop the workaround, or accept the risk explicitly. So it drifts until it becomes urgent, and then suddenly it’s a drama.
Clarity of accountability means:
explicit decision owner
explicit evidence expectation
explicit deadline
explicit escalation trigger
consistent consequences
This is where CFO and FD credibility is won or lost because it determines whether issues surface early or arrive late.
Why I built the Risk Culture Scorecard and personalised report
I built the Scorecard for a very practical reason:
“Risk culture” is one of the most overused terms in our space, and it’s become too easy to talk about it without changing anything.
It often turns into:
a survey score
a set of posters
a governance statement
a debate about tone
Meanwhile, the same control outcomes keep repeating.
I wanted a way to do three things:
Turn culture into observable mechanics in the flow of work
Connect culture directly to control outcomes so it stays CFO credible
Give a practical starting point for action, not a vague conclusion
That’s why the output matters.
You don’t just get a number. You get a personalised PDF report that points to where:
ownership is weakening
challenge is unsafe
accountability is unclear
escalation is late
And most importantly, it shows how those weaknesses are likely driving the outcomes you’re seeing: late evidence, repeat findings, overrides, and surprises.
Optional helpful next step if you want a structured baseline:
Take the Risk Culture Scorecard and get a personalised PDF report showing where ownership, challenge, accountability and escalation are weakening control outcomes.
A one week reset you can run without launching a formal programme
If you want to make this operational immediately, run this one-week reset.
It’s designed to surface culture mechanics using real work, not opinions.
1) Pick the top 10 repeat issues
Choose the ten things that keep coming back in close, audit, and remediation.
2) Assign true decision owners
Not task owners. People with the authority to change outcomes.
3) Set escalation ladders
Define what escalates at day 2, not day 20, and to whom.
4) Make challenge routine
Use “evidence before opinion” as a meeting discipline.
5) Track time to escalation
Measure days from issue identified to escalated to the right level.
That one metric will tell you more than most culture surveys.
A quick update: Beyond the Lines™ is moving to weekly issues.
This is driven by reader feedback and demand, and a commitment to deliver:
more practical value
more tools you can lift straight into your organisation
more free resources that reduce rework and increase credibility
Weekly gives me the rhythm to deliver that properly.
Do this this week
If you do nothing else, do these:
Pick one repeat control failure and write it in plain language
Name the decision owner with authority to change the outcome
Define what “good evidence” looks like at source
Agree what escalates at day 2, not day 20
Start one meeting with evidence before opinions
Publicly thank early escalation once this week
Track time to escalation and treat it as a performance signal
Final thoughts
If you reply to this email with your most stubborn repeat control failure, I’ll tell you which pillar it most likely maps to and what I’d test first.
Replies influence future editions and resources developed, so feel free to reach out to me any time with feedback or requests.
Thanks for reading, and have a great week ahead.
Creator Beyond the Lines™


