Compliance Is a Process
Could you show it, not just say it?
The idea
Obligations are met by what an organisation actually does and can evidence, not by holding a policy document.
In the real world
A data policy that describes retention limits nobody applies.
Going deeper
Obligations are met by what an organisation does and can evidence, not by the existence of a policy. Regulators generally look for operational traces โ logs, records, decisions actually taken on dates.
A complete policy set with no evidence of application can be worse than an incomplete one, because it documents a standard the organisation demonstrably did not meet. The useful test is to take one policy and try to find the evidence that it was followed last month. Where that evidence does not exist, the policy is describing an intention rather than a practice.
Where it stops applying
Documentation is still required and policies are not pointless โ they establish the standard. The failure is treating the document as the deliverable.
Why it matters
It changes what you build: records and routines rather than documents.
Try this today
Pick one policy you hold and find the evidence that it was followed last month.
Test yourself
An organisation has a full set of policies and cannot show they were followed. What position is it in?
Show the answer
Largely undefended. Policies describe intent and regulators generally look for evidence of practice โ logs, records, decisions actually taken. A document with no operational trace behind it can even highlight the gap between the stated standard and reality.
Learn this in the feed Answering from memory, then again days later, is what makes it stick.