Your engineers may be performing controls that don’t need to exist. The paper shows how to trace each one to its source and redesign it. Download the three-page field guide excerpt below.
In one case documented in the paper, every production change went to a committee that met every two weeks, minor bug fixes included. The average change took six months to ship.
No framework required that committee. Not SOX, not SOC 2, not ISO 27001. What they require is authorization by someone other than the person making the change. An engineering director traced the requirement back, moved approval into the ticket and cut approval time from four weeks to under an hour. It has held through SOC 2 and HITRUST audits since.
Panna Royal, one of the leaders interviewed for the paper, inherited 118 open IT audit findings when she joined Greenfield Savings Bank. She didn’t get a new framework, a bigger budget or a new auditor. She changed the posture, then put every finding in one place with an owner and a due date.
You wouldn’t hand off your system architecture because it’s hard. Control design is no different.
Tracing back to the requirement works on any control.
Every requirement lands in one of four places.
Required · Worth doing anyway
Hard floor
A framework or fraud-risk
objective requires it.
Meet it with the least friction.
Not required · Worth doing anyway
Sound practice
Nothing requires it.
Skipping it is unwise.
Your call.
Make it on purpose.
Required · Evaluate carefully
Customer contract
A contract or security
questionnaire requires it.
Meet it for that deal.
Not required · Evaluate carefully
Myth
Nothing requires it.
Habit says it does.
Push back.
Appendix C of the paper puts the whole field guide on three pages, so you can start this quarter without reading all sixty first.
From Clare Hawthorne, lead author
Tell me who you are and the download starts right away.
I never share your details. And unless you tick the box, I won’t add you to any list.
If it didn’t start, download the Field Guide here.
Bring one control that’s slowing delivery or generating repeat findings. I’ll help you find where the requirement comes from and what’s open to redesign.
Talk through one costly controlI’m Clare Hawthorne, the paper’s lead author and the founder of OxerLine Advisory. I’ve sat on both sides of the audit.
If you’ve just inherited an audit finding, or your engineers are carrying controls nobody can explain, I help you trace each requirement, redesign the control and cut what it costs to run, without weakening the audit outcome.
Bring one control that’s slowing delivery or generating repeat findings. I’ll help you find where the requirement comes from and what’s open to redesign.
Talk through one costly controlPublished in IT Revolution’s Enterprise Technology Leadership Journal, Fall 2026. Read Deliberate Compliance: A Field Guide to Owning Your IT Controls.
Read the full paper© 2026 OXERLINE LLC • ALL RIGHTS RESERVED