Welcome
Before we get into this weeks edition, a quick note on what I am building with Beyond the Lines™: my goal is to provide weekly, implementation grade insights, tools and templates to help audit, risk & controls leaders build real outcomes, in a Human + AI world.
I want this to be a place where practitioners can sharpen their judgement, learn practical mechanics that actually work, and feel part of a community that takes the profession seriously without taking itself too seriously.
My goal is simple: to build the highest-value community in the audit, risk and controls space globally. A community that spans the three lines, who care about doing this work properly, sharing what works, and raising the bar together. We have crossed 2,000 newsletter subscribers across LinkedIn and Beehiiv, which is a brilliant milestone.
Thank you for being part of it.
A quick ask from me
To make this newsletter better, I want its content to be driven by you. So my ask is simple, please reply to this edition with any specific topics, pain points, hurdles, challenges or anything else you would like me to discuss in future issues.
I spend hours each week researching, and applying my professional experience to the topics I cover, sharing insight and practical resources and frameworks you can use, so I want to make sure I’m covering things that are challenging real people in the field, today.
Stop preaching accountability. Start engineering ownership.
Week 2 of Risk Culture Month is all about, the mechanics that reduce repeat exceptions and calm the close.
Let me start with something you have probably experienced.
An exception is raised.
It is logged.
Everyone agrees it matters.
Then it just sits there, quietly ageing.
Not because people are lazy.
Not because nobody cares.
But because the organisation has built a system where ownership is negotiable.
This week’s point is simple.
Ownership and accountability are operating mechanics, not values.
If you want fewer surprises, fewer repeat exceptions, fewer aged actions, and a calmer close, you do not need another “accountability push”.
You need a few small design choices that make drift harder.
Now let’s get practical.
The moment most teams get wrong
Here is the moment that tells you whether you have a healthy control environment.
Someone says:
“We need to fix this.”
And the room responds with:
“Yes, we should.”
That is where things quietly go off track.
Because “we” is not an owner.
And when “we” owns something, nobody owns the outcome.
So work gets delegated.
But accountability dissolves.
Then the tracker grows.
Then the close gets tense.
Then audit becomes the chaser.
Then everyone rolls their eyes at “another repeat”.
Sound familiar.
The framework: the O - F - C loop
I use a simple loop because it works across finance, operations, audit, risk, IT, procurement.
Ownership
Friction
Closure
When all three are strong, you get calm and consistency.
When one is weak, you get drift and surprises.
Let’s break it down with the kind of detail you can actually use at work.
1) Ownership: one name, one outcome
Single point ownership is not about blame.
It is about clarity.
Shared ownership feels collaborative, but it creates a loophole.
Everyone can be involved. Nobody feels the cost.
What good ownership actually looks like
One named owner for the outcome
The owner has authority to remove blockers
The owner can delegate tasks, but not accountability
Practical scripts you can use this week
Use these in meetings and watch what happens.
“Who owns the outcome, single point, not the committee”
“Who has the authority to fix this, not just report it”
“If this crosses teams, who owns it end to end”
“What would stop this becoming a repeat next month”
Micro tip
If the owner name is only in the tracker, it is not real ownership.
Put the owner in:
The action title
The meeting note
The email subject line
Make it visible.
2) Friction: make exceptions feel like decisions again
Friction is not bad.
Unhelpful friction is bad.
Controls as Enablers means:
Friction where risk is real
Flow where it is not
Most organisations flip it.
Low risk work is heavy.
High risk exceptions are effortless.
That is how exceptions become “how we do things”.
The four part exception rule
If you want one simple standard, make every exception include:
Rationale
Conditions
Expiry date
Named owner
Practical scripts
“When do we stop accepting this as normal”
“If we approve this, what are we accepting, and for how long”
“What is the compensating action while this is open”
“If this repeats, what changes automatically”
Notice what these do.
They force the organisation to decide.
Not just nod.
3) Closure: stop closing actions, start closing outcomes
This is where repeat exceptions are born.
Most teams close actions with activity:
Updated guidance
Refreshed training
New checklist
Added a control step
Then the same issue returns.
Because the workflow never changed.
A simple definition of done
For any action, define “done” on day one:
What changes in the workflow
What evidence will exist without chasing
How you will know it is embedded
How you will know it does not recur
Practical scripts
“What will be different on a busy day when nobody is watching”
“What evidence should exist automatically if this is working”
“How will we prove this is fixed in the next two cycles”
“Who is signing off quality, not just completion”
If you use these consistently, you will cut remediation theatre quickly.
How does your organisation stack up?
If you want a benchmark of how strong these mechanics are in your organisation, the Risk Culture Scorecard produces a personalised PDF report. Click the image below:
Use it as a mirror. It will help you prioritise where to start.
A short example you will recognise
A month end approval control is bypassed because it is “too slow”.
An action is raised: remind people of the policy.
Next month, the bypass happens again.
Why it repeats:
No single owner fixes the approval workflow
The exception is frictionless, so it becomes normal
Closure is measured by reminders, not outcomes
A more effective fix:
Name the owner of the workflow
Set a time bound exception with conditions
Redesign the approval route so low risk items flow fast and high risk items get scrutiny
Define done as “no bypasses for two closes” not “guidance issued”
That is a control enabling the business.
Not slowing it down.
Do this in 30 minutes: the Drift Audit
If you want one practical exercise, do this today.
Open your actions list or recurring exceptions list.
Sort by oldest.
Pick the top 10.
For each, write one sentence answers to:
Who owns the outcome
What does done mean
What evidence proves it is embedded
If we are tolerating this, what is the expiry date
If it repeats, what changes automatically
Anywhere you cannot answer cleanly, you have found a culture problem.
Not because people are bad.
Because the system is unclear.
And unclear systems create repeat exceptions.
If you are only going to do one thing this week
Pick one repeat exception and do one upgrade:
Name one accountable owner for the outcome
Add an expiry date to any exception approval
Define done as an outcome, not an update
That is enough to change behaviour.
Want to learn more about Risk Culture?
I recently had the chance to sit down with Alejandro Orrego Santamaria on the Pirani Podcast to talk about what really makes risk management work inside organisations – beyond the frameworks and heatmaps.
We got into things like:
- Why “speak up” only works if people feel genuinely safe to do it
- How leadership signals shape risk culture more than any policy ever will
- Why blame kills learning – and what to do instead
If you care about risk culture, psychological safety and moving past checkbox governance, this one will be worth a listen.
Closing thought
Risk culture is not what your policies say.
It is what your operating mechanics allow.
Ownership
Friction
Closure
Build those, and the environment calms down.
Reply and tell me: what is the repeat exception in your world that everyone has quietly normalised, and what do you think it is really signalling?
Have a great week.
Best,
Creator Beyond the Lines™


