top of page

Does your compliance keep you between the lines, ahead of risk, and on mission?

๐—›๐—ผ๐˜„ ๐—ช๐—ฒ ๐—™๐—ฟ๐—ฎ๐—บ๐—ฒ ๐—œ๐—ป๐˜๐—ฒ๐—น๐—น๐—ถ๐—ด๐—ฒ๐—ป๐—ฐ๐—ฒ ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ผ๐—น๐—ผ๐—ด๐˜† ๐—ช๐—ถ๐—น๐—น ๐——๐—ฒ๐˜๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฒ ๐—ช๐—ต๐—ฎ๐˜ ๐—œ๐˜€ ๐—•๐˜‚๐—ถ๐—น๐˜


The information technology era is ending, at least in part. It collected data and moved it to where it was needed. Intelligence technology is different.


What that era becomes is not settled. It is being decided now, in procurement decisions and architecture reviews, by the answers being given to questions like these.


๐Ÿ”ธ ๐—”๐—ฑ๐—ผ๐—ฝ๐˜๐—ถ๐—ป๐—ด ๐—”๐—œ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐—”๐—œ


Adoption selects a vendor and measures uptake. Engineering establishes that a system is safe, reliable, and capable of delivering benefits before it is used. We chose adoption, and the engineering phase was declared unnecessary rather than skipped. Whether an application demands engineering is a decision to make before procurement, not after an incident.


๐Ÿ”ธ ๐—›๐˜‚๐—บ๐—ฎ๐—ป ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—œ ๐—Ÿ๐—ผ๐—ผ๐—ฝ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐—”๐—œ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—›๐˜‚๐—บ๐—ฎ๐—ป ๐—Ÿ๐—ผ๐—ผ๐—ฝ


In one arrangement the person originates the work and the system assists. In the other the system originates and the person approves. The same phrase describes both, and most deployments claim the first while running the second. Name the act the human performs and you will know which loop you are in.


๐Ÿ”ธ ๐—ฆ๐—ฝ๐—ฒ๐—ฐ๐—ถ๐—ณ๐˜†๐—ถ๐—ป๐—ด ๐—ข๐˜‚๐˜๐—ฝ๐˜‚๐˜๐˜€ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐—ฆ๐—ฝ๐—ฒ๐—ฐ๐—ถ๐—ณ๐˜†๐—ถ๐—ป๐—ด ๐—ฃ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€


Outputs say what must be produced. Process says how, and process is where quality, safety, and security are made. Specify only the output and anything optimizing for it will remove the rest. Decide which parts of the process must stay before the work starts, because afterwards there is nothing left to regulate.


๐Ÿ”ธ ๐—š๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐—”๐—œ ๐—ฅ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป


Governance controls act once, at a boundary. Regulation acts on a system while it runs and corrects the difference. A guardrail restrains while a regulator steers. Ask what corrects the behaviour while it is happening. If the answer is a report read afterwards, nothing is being regulated.


๐Ÿ”ธ ๐—ฅ๐—ถ๐˜€๐—ธ ๐—”๐˜€๐˜€๐—ฒ๐˜€๐˜€๐—บ๐—ฒ๐—ป๐˜ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐—˜๐˜ƒ๐—ฎ๐—น๐˜‚๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐—จ๐—ป๐—ฐ๐—ฒ๐—ฟ๐˜๐—ฎ๐—ถ๐—ป๐˜๐˜†


A hazard is a source of uncertainty that creates the opportunity for risk. Risk assessment walks from hazard to failure mode to control, and with these systems that walk breaks at the first step, because how harm arises cannot be enumerated in advance. Evaluating uncertainty is different work: margin, reversibility, containment, and people close enough to notice.


๐Ÿ”ธ ๐——๐—ฎ๐˜๐—ฎ ๐—œ๐—ป๐˜€๐—ถ๐—ด๐—ต๐˜๐˜€ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—ฑ ๐—ž๐—ป๐—ผ๐˜„๐—น๐—ฒ๐—ฑ๐—ด๐—ฒ


In the old model, intelligence sits between knowledge and wisdom and operates on what is known. Today's AI is inference over data, used as a proxy for both knowledge and intelligence, with the layers between skipped. A proxy for knowledge is not knowledge. Without managing your own, the inference runs on what it learned from everybody else.


๐Ÿ”ธ ๐—›๐˜‚๐—บ๐—ฎ๐—ป ๐—ข๐—ป๐˜๐—ผ๐—น๐—ผ๐—ด๐—ถ๐—ฒ๐˜€ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐˜‚๐˜€ ๐— ๐—ฎ๐—ฐ๐—ต๐—ถ๐—ป๐—ฒ ๐—ง๐—ฎ๐˜…๐—ผ๐—ป๐—ผ๐—บ๐—ถ๐—ฒ๐˜€


We describe these systems in words borrowed from human cognition. This is anthropomorphism, and it points to a category failure. Memory names three unrelated mechanisms. Reasoning names token generation. An ontology of AI comes first, built from what these systems are and do. A proper taxonomy follows from it.


Most of these questions already have answers in use, carried over from the information era or supplied by vendors. Those answers were made for a different technology or for someone else's interests, and they are settling into practice unexamined.


The model, the platform, and the tooling can be bought. The engineering, the regulation, the organization's own knowledge, and the accountability cannot. They must be built.


๐—›๐—ผ๐˜„ ๐—ถ๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ณ๐—ฟ๐—ฎ๐—บ๐—ถ๐—ป๐—ด ๐—ถ๐—ป๐˜๐—ฒ๐—น๐—น๐—ถ๐—ด๐—ฒ๐—ป๐—ฐ๐—ฒ ๐˜๐—ฒ๐—ฐ๐—ต๐—ป๐—ผ๐—น๐—ผ๐—ด๐˜†, ๐—ฎ๐—ป๐—ฑ ๐˜„๐—ต๐—ผ ๐—ฐ๐—ต๐—ผ๐˜€๐—ฒ ๐˜๐—ต๐—ฎ๐˜ ๐—ณ๐—ฟ๐—ฎ๐—บ๐—ถ๐—ป๐—ด?


Raimund Laqua, P.Eng., PMP, is the founder of Lean Compliance Consulting and one of Ontario's first licensed software engineers. He works with organizations in highly regulated, high-risk sectors to build the operational capabilities needed to keep their promises, and is a national advocate for licensed professional digital engineering in Canada. He writes about compliance, engineering, and AI at leancompliance.ca.

bottom of page