Skip to content

The Uncomfortable Truths Stakeholders Work Around

Information Synergy-iA
Information Synergy-iA
The Uncomfortable Truths Stakeholders Work Around
6:03

3. The Uncomfortable Truths Stakeholders Work Around

The Known-and-Not-Said Problems with Internal Audit, Risk Management, and Regulatory Compliance initiatives at your organization.

Every organization has a list of things it already knows. Not the unknown unknowns, and not the complicated analysis still in flight — the obvious things. The duplicate testing nobody wants to name. The material finding that lives in a spreadsheet instead of on the leadership calendar. The risk appetite statement that says nothing. The audit plan that has not moved in a year.

These are uncomfortable not because they are hard to discover, but because they are already discovered. Saying them out loud creates work for someone who is currently comfortable. As a result, organizations develop a quiet accommodation: they accept the conclusion, and the behavior does not change. Activity continues. The known-and-not-said becomes the operating model.

This blog is written for the three people who can end that accommodation.

  • The executive who owns the risk and may discover they do not actually own the decision.
  • The Board member who is receiving multiple reports and still cannot state the risk position.
  • The external audit partner who keeps finding what internal audit should have found first.

Each of these roles has the standing to name the uncomfortable truth. Few use it, usually because the system (corporate culture) rewards them for not doing so.

What follows is not a maturity model, a framework, or a transformation roadmap. It is a set of conditional statements. If the condition is true in your organization, the conclusion is already known there too. The only remaining question is whether anyone will say it or commit to making meaningful changes. Organizations work around these conclusions rather than face them.

  • If two or more functions test the same control and neither knows it, you are not managing risks; you are managing activity. The obvious conclusion is that assurance coverage is allocated once, centrally.
  • If a finding is genuinely material, its owner is a member of the leadership team, and its due date sits on the leadership calendar. Anything else is a tracking exercise. Material findings are managed as business projects, not as Governance, Risk, and Compliance (GRC) records.
  • If the Board needs multiple reports to understand the risk position, the reporting is broken (ineffective), not the Board. One consolidated assurance report with one prioritization logic is all that is required.
  • If risk appetite cannot be expressed as a number, a threshold, or an explicit trade-off, it does not exist operationally. Appetite must be written in the language of decisions, not principles.
  • If AI is in use and the governance forum cannot list it, governance is not 'emerging' — it is absent. Inventory first, then rationalize the framework.
  • If the audit plan has not changed in twelve months, the plan is not risk-based, whatever it is labeled.
  • If every finding is closed 'in progress' and none are ever closed 'not fixed, accepted by management', the register is not honest. An accepted-risk mechanism with named accountability is the answer.
  • If the external auditor is finding control problems internal audit did not, the internal audit function is either under-resourced or under-scoped — and both are governance failures, not audit failures.
  • If the function's success measure is cost as a percentage of revenue or utilization rate, it is optimizing the wrong thing. Measure risk coverage and outcome, not effort.
  • If the first line owns the risk while the second line makes the risk decision, the first line does not own the risk. Accountability cannot be delegated to oversight.

What to Do With a List Like This

None of the statements above require new technology, a reorganization, or a consultant. They require someone with authority to treat an obvious conclusion as a decision rather than an observation. Most of them invert a habit that feels like diligence: more reports, more tracking, more activity. The pattern across all ten is the same — work is being performed where ownership should exist.

Notice what is missing from the list. Nothing about headcount, tooling, or certification. Nothing about maturity scores. That is deliberate. Those are the things organizations buy when they are avoiding the uncomfortable truths, not the ones they buy after facing them. If a provider's proposal leads with any of them, it is answering a different question.

If you are in one of the three seats: executive, Board, or partner — and you are considering help, you are not shopping for a plan. You are shopping for someone who will tell you the thing you already suspect. Three questions separate practitioners who will from those who will not:

  1. Show me your combined assurance map for a client like us. Where did you find duplicated testing, and what did you remove? A real practitioner has eliminated overlap and can prove it. One that cannot will add more to your existing reports.
  2. Take the last ten findings you closed. How many ended up as 'not fixed, accepted by management,’ and who accepted them by name? An honest register includes accepted risks with named accountability. A register that closes everything as 'in progress' will stay dishonest, no matter whose software it runs on.
  3. List every AI system in our organization you can see today, and tell me which governance forum each one reports to. Inventory precedes framework. A practitioner who starts with the framework has never done the inventory.

The uncomfortable truths are uncomfortable because they point at decisions, and decisions have owners. Ask the above questions. The answers will tell you whether you have found a partner or purchased an audience.

To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com

Share this post