Living Artifacts, Not Scripture
When boilerplate becomes "the way we do it now."
I inherited IT governance and controls work at a publicly traded company, and the org chart told a familiar story. Technology sat on one side of the house. Internal control over financial reporting sat in Finance.
My predecessors in Tech had treated that distance as a firewall. ICFR and internal audit were trying to point out our failures and get Tech in trouble.
Their perspective: The less we told them the better. If they come to us with questions, deflect and argue. Don’t ask them for help, because that will show them where we’re vulnerable and they’ll exploit that knowledge down the road.
As a trained auditor, I knew the difference between ICFR and our external auditor. I spent the first two or three weeks resetting the relationship. Trading war stories with the Chief Accounting Officer. Virtual coffee with the head of ICFR. Honest conversations with our internal audit colleagues about what we actually ran versus what the documentation said.
I knew the most valuable thing I could do was build trust. We were already in April and had a laundry list of deficiencies to clean up. I needed all the help I could get.
The payoff showed up in my first in-person meeting with our VP of ICFR.
We had immediate rapport. She’d watched me show up as a partner, not a defendant, and she was willing to meet me halfway.
I told her what I was seeing on the tech side: remediation after remediation, and it all felt disconnected from how engineers actually shipped and operated systems. “It just feels like these process narratives have nothing to do with what the team actually does.” It felt like a confession.
She didn’t blink. Instead, she floated a hypothesis she might not have shared with someone still playing defense.
“Clare, they probably don’t…”
Then she walked me through what she had pieced together the year before when she first joined. Years prior, before the IPO, a Big-4 firm was brought in for readiness advisory work. Our company had asked that firm to create a full suite of process narratives. (They were not our external auditors.)
Over a few months, the firm delivered sensible boilerplate: best-practice language, recognizable tools, reasonable-looking steps. Exactly the kind of artifact you file when you’re pre-IPO and getting ready for a more formal control environment.
But when the VP dug into financial controls, she realized no one on the accounting team had worked with the firm to tailor the process narratives to how work actually happened. The team took the boilerplate as gospel. They implemented it as written.
Her hypothesis: the same thing had happened on the technology side with IT general controls. The written tests and narratives described a company that didn’t exist.
I stared at her in disbelief. “But… you always need to adjust what the consultant writes down. They never get it right the first time.”
She nodded sadly. “Clare, they didn’t know. They just thought ‘this is how we have to do it now’ and implemented those controls and processes.”
That sentence is the whole pattern.
Nobody was cynically faking compliance. They were tying themselves into knots trying to do the right thing.
Tech team members inherited consultant boilerplate as requirements, never learned that tailoring is normal, and closed the decision. No one with operating knowledge redrew the map.
And it compounded. Audit findings didn’t reopen the design. They added duct tape. Another workaround. Another exception. Another control on top of a process that was wrong on paper from day one.
The knot got tighter and tighter.
Come audit season, the team was always reacting. Tech and controls had never really translated for each other — so when findings showed up, we patched. We didn’t go back and ask whether the written process reflected the way the team actually managed the risk.
A lot of teams read “independence” as “don’t get too close.” Don’t help ICFR design the narrative. Don’t invite them into how work actually runs. The documents from the readiness project stayed frozen. Engineering lived inside process descriptions it didn’t write (and often hadn’t read). Even though those documents were intended to be management’s story, not the consultant’s.
I don’t think that Big-4 firm intended to write the permanent constitution. I think they wrote a starting draft. The failure was on our side of the table: nobody owned the edit loop between “reasonable template” and “this is how we operate.”
If you lead technology, finance or internal audit, you’ve seen the symptoms even if you haven’t had this exact conversation. Surprise in-scope systems. Remediation that adds steps without redrawing the process. Control language that doesn’t match how code moves. Audit findings as proof the process isn’t working instead of proof the description is stale. Narratives should describe your company, not a hypothetical one.
The fix is not another layer of controls. It’s permission to treat process narratives and controls as living artifacts, not scripture. Someone with operating authority has to sit in the room when narratives are written, and stay in the room when they’re implemented to connect the dots.
The villain is not finance, not internal audit, not the firm that drafted the first version. The villain is the quiet misunderstanding that tailoring is out of bounds.
I’m Clare Hawthorne. I founded OxerLine Advisory to fix friction at the seam between technology and the business. If this is something you’re facing, let’s chat.


