OOPS, we put the obligations in the wrong place.
- Raimund Laqua

- Jun 24
- 5 min read

For years I've watched the same thing happen across every regulated sector I've worked in.
The obligations are documented. The controls are implemented. The audit gets passed. And still, when something goes wrong, you find that no one — not one identifiable person, not one accountable part of the organization — was holding the thing that failed.
It's tempting to call this negligence: managers handing their responsibilities off to consultants, departments, and auditors. There is some truth to that. But the cause runs deeper, and it is structural.
The obligations went unowned because the organization gave them away. It assigned them to a function — compliance — and a function cannot own an obligation it's not responsible to meet.
The Structural Mistake
Somewhere along the way, organizations decided that compliance obligations belong to the compliance department. The decision sounds reasonable. However, as it turns out, it is the source of the problem.
The compliance function doesn't run the plant, treat the patient, write the code, approve the loan, or ship the product. It reports on whether those who do appear to be following the rules. But the obligation isn't met in the report. It's met in the work — in operations, on the line, in the decisions managers make every day. Put ownership of the obligation in a function that only observes the work, and you separate ownership from the place the obligation lives.
That separation is the structural mistake. The people doing the work treat compliance as someone else's concern, because structurally it is. The compliance function documents and escalates, but it cannot make the obligation true.
Custody Is Not Ownership
This is the difference between custody and ownership.
Custody asks: can I show the requirement was met? Ownership asks: do I have the capabilities to meet our commitments?
The first is satisfied by evidence. The second is satisfied only by capability — a system that does what the obligation requires, under real conditions, whether or not anyone is auditing it that week.
A compliance function can hold perfect custody. It cannot hold ownership, because ownership lives where the work lives. When the organization assigns obligations to compliance, what it creates is custody without ownership — a documented record that the requirement was addressed, sitting next to an operation where no one is accountable for the capability to meet it.
You can have perfect custody and no ownership. Most organizations do. This is not a scandal. It is the predictable result of putting the obligation in the wrong place.
Why Telling Managers to Own It Fails
So the answer would seem obvious: tell the managers to take ownership. Push it back to the line.
But you cannot fix a structural problem with an exhortation. Tell a line manager to own compliance and they hear "do more compliance tasks." Tasks are the only form of compliance the structure has ever shown them. The compliance function holds the obligation; the manager only ever receives fragments of it to carry out. So when you ask them to own the outcome, they hear more work, not more ownership.
Owning the capability to meet an obligation is not in their vocabulary, because the structure was never built to put it there. This is not a motivation gap. It is a structural one. And it does not close because someone gave a speech about accountability.
AI Exposes the Latency
For many compliance programs, this misplaced ownership is a latent risk. The deficiency was always there. Nothing had triggered it yet. The procedure existed, the box was checked, and the gap between custody and capability sat dormant. It might surface years later. It might never surface at all. Organizations lived with it not because it was safe, but because the bill came due slowly, if at all.
That is changing. In a growing number of domains, AI among them, an unowned obligation no longer waits to become a problem. The risk shows up earlier and it costs more.
Organizations are routing their obligations — privacy, safety, quality, financial integrity, legal and ethical commitments — through AI systems that act faster than anyone can supervise. An AI cannot own any of them. It cannot accept responsibility when an obligation is unmet. It can generate the documentation, pass the check, and give you better custody than you have ever had. It cannot give you ownership.
Deploying AI into an organization that already put ownership in the wrong place does not close the gap. It widens it, and faster. "The system didn't flag it" becomes the new "the auditor didn't catch it" — one more place to send accountability that belongs to those responsible for the work.
The Shift That Matters Most
The shift is not from reactive to proactive, or from manual to automated, or from one framework to a better one. It is structural: from compliance owning the obligations to the organization owning them.
In practice, that means moving from compliance management to managed obligations.
Today we manage the compliance function — the program, the reporting, the audit calendar. What needs managing is the obligation itself: the commitment the organization has made, managed by the person with managerial accountability for the work that meets it. The obligation moves from a function that reports on it to a manager who is answerable for it.
Compliance does not disappear in this shift. It stops being the owner and becomes what it should always have been: the function that coordinates, assures, and holds the organization to what it has committed to. Not the place obligations go to be reported on. The function that makes sure the real owners are meeting them.
Once obligations are managed by those accountable for the work, the operational questions can be answered — because only the owners can answer them. What did we commit to? What capability does meeting it require? Do we have it? None of these are answered by a function reporting from the side. They are answered where the obligation lives, by the manager accountable for meeting it. Until ownership moves, those questions have no one to answer them.
This is the realization that changed our consulting practice.
We began with operational compliance — making obligations work in operations rather than on paper. That was right, but it did not go far enough. Operations are where obligations are met, but they are not where obligations are owned.
Ownership belongs to the organization: its leadership, its management, its accountable lines of work. So the practice had to align to that. We changed from operational compliance to organizational compliance, because that is where the obligations live.
The obligations were always the organization's. The wrong structure just made it easy to forget.



