Assurance Isn't About Compliance
Assurance Isn't About Compliance
I've often thought that assurance suffers from an image problem. For many people, the word immediately brings to mind audits, inspections, compliance obligations and checklists. It is often associated with demonstrating conformance against legislation, standards, procedures and organisational requirements. Those activities are undoubtedly important. Organisations have legal obligations, regulators require accountability and management systems need to be evaluated against defined criteria.
Over the years, I've come to wonder whether this strong focus on compliance sometimes causes us to overlook the real purpose of assurance.
To me, assurance has never primarily been about proving compliance. It has always been about understanding whether the things we depend upon are functioning as intended and whether the confidence we place in them is genuinely justified.
That distinction may appear subtle, but I believe it changes the questions we ask and, ultimately, the value assurance can provide.
Throughout my career, whether working in investigations, emergency management, security, safety, risk or assurance, I have rarely been interested in whether something simply exists. What has consistently interested me is whether it works. A procedure may be exceptionally well written, training records may indicate that workers have completed the required courses, critical controls may be recorded in a register, inspection reports may show no outstanding defects and emergency response arrangements may be documented and approved. None of those things, however, necessarily demonstrate that risk is being effectively managed. They demonstrate that particular activities have occurred. Assurance begins when we ask what those activities actually tell us about organisational capability.
The conversation becomes much more interesting when we begin asking different questions. Do people understand why a control exists and can they apply it under realistic operational conditions? What assumptions have been made and how regularly are they tested? What has changed since the control was last reviewed? If a critical control failed tomorrow, how quickly would the organisation know, and how confident are we that the consequences could still be managed? These are the kinds of questions that move assurance beyond compliance and toward understanding.
The International Organization for Standardization (ISO) defines auditing as a systematic, independent and documented process for obtaining evidence and evaluating it objectively against defined criteria. At its core, auditing is not simply about identifying non-conformances. It is about gathering evidence that supports informed conclusions and organisational confidence.
That focus on evidence has always resonated with me.
Good assurance is fundamentally an evidence-based activity. It seeks to understand whether confidence is warranted, where uncertainty exists and whether decisions are being made based upon an accurate understanding of reality. In that respect, assurance has much more in common with investigation, risk management and scientific inquiry than it does with administrative compliance.
This is one reason I have become increasingly interested in approaches such as Critical Control Management, Human and Organisational Performance (HOP), Learning Teams, Safety-II and Resilience Engineering. Although these concepts differ in their origins and emphasis, they share a common thread. Each encourages organisations to understand how work is actually performed rather than relying solely upon assumptions about how work is intended to occur.
Critical Control Management, for example, places considerable emphasis on verification. The objective is not merely to confirm that controls exist, but to obtain evidence that the controls relied upon to prevent or mitigate significant events are available, effective and capable of performing when required. The focus shifts from asking whether a control is present to asking how we know it is working.
That is fundamentally an assurance question.
A similar philosophy appears throughout Human and Organisational Performance, Safety-II, Learning Teams and Resilience Engineering. Rather than concentrating exclusively on failure, these approaches encourage organisations to understand operational reality, recognise variability, learn from success and explore how systems function under everyday conditions. Viewed through this lens, assurance becomes less about inspection and more about inquiry. The focus shifts from demonstrating compliance to developing understanding, and from proving that people have followed a process to determining whether organisational systems are genuinely supporting successful outcomes.
Risk management and assurance therefore address different, but closely connected, aspects of uncertainty. Risk management seeks to understand what could happen, what the consequences might be and what controls exist to prevent or mitigate harm. Assurance tests whether there is sufficient evidence to justify confidence in those controls and in the decisions being made about risk. One identifies uncertainty while the other tests confidence, and neither is particularly effective without the other.
In many respects, assurance functions as a test of organisational confidence.
Sometimes the evidence confirms that confidence is justified. Sometimes it reveals uncertainty that has not previously been recognised. Occasionally, it identifies a more uncomfortable possibility: that confidence has exceeded evidence.
In my experience, some of the most valuable assurance activities are those that challenge assumptions that have quietly become accepted as fact. Controls that were once effective may no longer be operating as intended. Procedures may no longer reflect operational reality. Organisational changes may have altered risk profiles in ways that have not been fully recognised. These findings should not be viewed as failures. They are opportunities to learn and improve.
That is why I have never been particularly attracted to the view that assurance exists primarily to identify deficiencies or catch people doing the wrong thing. Good assurance should leave an organisation with a better understanding of itself than it had beforehand. Sometimes that understanding confirms that existing arrangements are working well. Sometimes it identifies opportunities for improvement. Sometimes it highlights areas requiring further investigation. All of these outcomes create value because all of them improve understanding.
I also wonder whether assurance deserves a broader definition than it often receives. Perhaps assurance is not solely about providing confidence to boards, executives, regulators or external stakeholders. Perhaps it is equally about providing confidence to the people doing the work.
When workers know that equipment has been maintained, emergency arrangements have been tested, critical controls have been verified and leaders are genuinely interested in understanding operational reality, assurance becomes something people experience rather than something organisations simply report. It contributes to trust, confidence and organisational learning because people can see that the systems they rely upon are being actively monitored, tested and improved.
None of this diminishes the importance of compliance. Organisations should understand and satisfy their legal, regulatory and organisational obligations. Compliance, however, is rarely the ultimate objective. The real objective is confidence supported by evidence; confidence that critical controls will function when required, that emergency arrangements will operate effectively under pressure, that information provided to decision-makers accurately reflects operational reality and that risks are being managed in the manner intended.
Ultimately, I do not think good assurance asks:
"Are we compliant?"
It asks:
"How do we know?"
And in safety, risk and assurance, that may be one of the most valuable questions an organisation can ask.