top of page
BLOG
Compliance Principles, Practices, & Insights


What Organizations Desperately Need: Compliance Streams, Not Compliance Documentation
If you're a compliance director or manager in a highly regulated industry, you know this frustration: Your organization has procedures, training records, audit schedules, and risk assessments. You pass audits. Your management systems are certified. But violations still surprise you. You're constantly firefighting. And when leadership asks "are we actually meeting our obligations?" you can't answer with complete confidence. The problem isn't your competence. It's that most com


How to Prove Your Compliance Actually Works: A Practical Guide to Building Confidence
If you're responsible for compliance, you've probably faced this uncomfortable question: "How do you know you're actually compliant?" Most organizations point to policies, training records, and audit reports. But there's often a nagging gap between having documentation and having genuine confidence that your obligations are truly being met. This is where Goal Structuring Notation (GSN ) and claim trees become game-changers. They're tools borrowed from safety-critical industr


Jidoka and AI: Lessons for Compliance
As someone working in compliance during this wave of AI adoption, I've been thinking about how we approach automation differently than other industries. The compliance field is naturally cautious about new technology—and for good reason. When we fail to meet regulatory standards, performance targets, or outcome requirements, the consequences extend far beyond operational inefficiency. Recently, I've been reflecting on Jidoka, Toyota's manufacturing principle that emerged over


Why Line of Business (LOB) Managers Should Own Compliance
Why Business Managers Should Own Compliance There's a persistent practice in organizational management where compliance is separated from...


Safety Design Principles for AI Adoption in Organizations
How do we deliver safe AI? This is the question every organization grappling with AI adoption must answer. Yet too often, discussions...


The Lean Compliance Way
When mission success requires compliance success Every organization is on a journey. Ahead lies your vision—the total value you're...


Why GRC Should be GRE
What GRC Should BE Traditionally, GRC activities were centered around integrating the siloed functions of Governance , Risk , and Compliance (GRC). While this is necessary, it is based on an old model where meeting obligations (the act of compliance) is a checkbox activity reinforced by audits. Similarly, risk management was building risk registers and heat maps, and governance was providing oversight of objectives completed in the past. All this to say: This was all reactiv


The Compliance Charter: Your Roadmap to Compliance Operability
The Compliance Charter In project management, we don't start without a charter. Yet in compliance—where the stakes are often higher and...


Managing Compliance Demands: When to Pull, When to Push
The Dual Nature of Compliance Over the years working with companies in highly-regulated industries, I've observed that organizations...


Why Risk Assessments Should Begin with Uncertainty
By Raimund Laqua, Founder of Lean Compliance Why Risk Assessments Should Start with Uncertainty Walk into most organizations today, and you'll find risk management teams armed with comprehensive checklists, detailed taxonomies, and colour-coded matrices that promise to capture every conceivable threat. These frameworks are seductive in their apparent completeness—neat categories for operational risks, financial risks, strategic risks, compliance risks. Everything has its plac


AI Risk Containment in Industrial Systems
AI Risk Containment Architecture Industrial leaders in safety-critical, highly regulated sectors like energy, chemical processing,...


What Creates Risk Opportunities in Your System?
By Raimund Laqua, P.Eng. - The Lean Compliance Engineer Uncertainty Creates the Opportunity for Risk I've sat through countless meetings...


Time to Poka-Yoke Your Compliance
By Raimund Laqua, Lean Compliance Engineer Mistakes aren't failures—they’re lessons. You see this quote everywhere. LinkedIn....


Why Your IT Playbook Won't Work for AI Systems
Organizational leadership faces a critical decision: apply familiar commodity IT approaches to AI development or invest in systematic...


Have We Reached The End of Software Engineering?
By Raimund Laqua, P.Eng The End of Software Engineering? I've spent over three decades practising engineering in both Canada and the...


Why AI Isn't Ready for Commoditization
Technology Life-cycle As I observe the current state of Artificial Intelligence (AI) and the rush surrounding its deployment, I find...
bottom of page
