Own your IT controls. Don’t bury your engineers.

Your engineers may be performing controls that don’t need to exist. The paper shows how to trace each one to its source and redesign it. Download the three-page field guide excerpt below.

Or read the full paper at IT Revolution.

Controls that pass the audit can still wreck your team.

In one case documented in the paper, every production change went to a committee that met every two weeks, minor bug fixes included. The average change took six months to ship.

No framework required that committee. Not SOX, not SOC 2, not ISO 27001. What they require is authorization by someone other than the person making the change. An engineering director traced the requirement back, moved approval into the ticket and cut approval time from four weeks to under an hour. It has held through SOC 2 and HITRUST audits since.

Panna Royal, one of the leaders interviewed for the paper, inherited 118 open IT audit findings when she joined Greenfield Savings Bank. She didn’t get a new framework, a bigger budget or a new auditor. She changed the posture, then put every finding in one place with an owner and a due date.

118
Open IT audit findings, 2019
7
Low-risk findings, most recent audit
You wouldn’t hand off your system architecture because it’s hard. Control design is no different.

Tracing back to the requirement works on any control.
Every requirement lands in one of four places.

Required · Worth doing anyway

Hard floor

A framework or fraud-risk
objective requires it.

Meet it with the least friction.

Not required · Worth doing anyway

Sound practice

Nothing requires it.
Skipping it is unwise.

Your call.
Make it on purpose.

Required · Evaluate carefully

Customer contract

A contract or security
questionnaire requires it.

Meet it for that deal.

Not required · Evaluate carefully

Myth

Nothing requires it.
Habit says it does.

Push back.

The Field Guide at a Glance

Appendix C of the paper puts the whole field guide on three pages, so you can start this quarter without reading all sixty first.

  • The operating sequence: align, scope, design, validate, execute
  • “Required by what?” How to trace every requirement to its real source
  • Seven design decisions to apply to any control
  • Putting one control to work, and where to start this quarter

Get the 3-page guide

From Clare Hawthorne, lead author

Tell me who you are and the download starts right away.

I never share your details. And unless you tick the box, I won’t add you to any list.

Page two of the Field Guide: the Operating Sequence and Table 4, Requirement Source Tracing, which sorts every requirement into hard floor, myth, sound practice or customer contract.
Excerpted from Hawthorne, Grinnell, Nugent and Warner, Deliberate Compliance: A Field Guide to Owning Your IT Controls, Enterprise Technology Leadership Journal, Fall 2026, IT Revolution. Used with permission.

Who I am

I’m Clare Hawthorne, the paper’s lead author and the founder of OxerLine Advisory. I’ve sat on both sides of the audit.

Audit
CPA, former EY auditor
Operating
Datavant, Oscar Health, Namely, Bloomberg, Citi
Education
Harvard Business School MBA

How I can help

If you’ve just inherited an audit finding, or your engineers are carrying controls nobody can explain, I help you trace each requirement, redesign the control and cut what it costs to run, without weakening the audit outcome.

Bring one control that’s slowing delivery or generating repeat findings. I’ll help you find where the requirement comes from and what’s open to redesign.

Talk through one costly control

Published in IT Revolution’s Enterprise Technology Leadership Journal, Fall 2026. Read Deliberate Compliance: A Field Guide to Owning Your IT Controls.

Read the full paper

© 2026 OXERLINE LLC • ALL RIGHTS RESERVED