top of page

Who Regulates the Organization?

10 hours ago
3 min read


Every organization is regulated. The question worth asking this Sunday is by whom.


Most organizations would answer by naming an external body. A safety regulator. A privacy commissioner. A certification body that audits their management system. These bodies impose obligations and specify the instruments they will audit against. They are real regulators, and their oversight matters.


They are also limited. An external regulator touches the organization only where its instruments apply. Everything outside those touch points is regulated by the organization itself, or it is not regulated at all.


This is where compliance often fails. Here are the patterns I see most often.


1. Self-regulation stops at the external obligation


Many organizations build enough regulation to meet the obligations imposed by external bodies. Procedures are written for the rules. Records are kept for the audit. Controls are designed around the instruments the regulator will check.


Then it stops. Obligations without an external auditor receive little attention. The organization regulates what is inspected and leaves the rest to chance.


2. Compliance means meeting the regulator


In these organizations, compliance is defined as meeting the obligations set by external bodies. That definition is narrower than the one most of them claim to follow. ISO 37301 defines compliance as meeting all of the organization's compliance obligations, both mandatory and voluntary.


Customer commitments, internal policies, safety goals, sustainability pledges and promises made to communities are all compliance obligations. When compliance is limited to the external regulator, these become optional. This is where obligation debt accumulates.



3. The organization resists obligations it expects others to keep


Some organizations carry a culture that pushes back on external regulation. Leaders speak of red tape and regulatory burden. Obligations from outside are treated as something to minimize, negotiate or delay.


The same organizations expect employees, suppliers and contractors to meet the obligations the organization imposes. Policies are to be followed. Targets are to be met. Commitments are to be kept.


People notice the conflict. When an organization treats obligations from outside as negotiable, its people learn that obligations are negotiable. A culture that resists obligation will struggle to keep its own promises.


4. Governance is expected to regulate, but it is not operational


Every organization is expected to regulate itself from outcomes down to means. Governance sets direction and decides what the organization commits to. Programs build the capability to deliver those commitments. Systems keep operations stable. Processes do the work.


In many organizations this exists on paper. Policies are approved. The board receives reports. The structure is described in the management system manual. What is missing is the operational capacity to regulate. Governance receives information and has little ability to act on it.


5. Compliance for the regulator builds nothing for the organization


That system does not build the apparatus the organization needs to regulate itself. It does not build ownership of obligations at governance. It does not build programs that develop capability. It does not build systems that keep variation within limits. It does not build promises that people choose to keep.


Over time, the organization becomes dependent on the external regulator because it has no other regulator. External regulators were never designed for that role. Their instruments are minimal by necessity. Following OSHA 1910.119, ISO 9001, or license to operate rules meets the minimum a regulator can specify and audit. The obligation to be safe extends well beyond that minimum.


The duty of care stays with the organization


The duty of care belongs to the organization. It always has and always will. No regulator, standard or auditor can carry it on the organization's behalf.


Meeting that duty requires the organization to own all of its obligations and translate them into promises across governance, programs, systems and processes. Governance has to act as the top-level regulator. External regulators then become one source of obligations among many, and the outermost check on whether the organization's own regulation is working.


A question for this week


Many organizations may lack the capacity to regulate themselves, never mind those that come from external regulatory bodies. That deserves honest reflection.


Here is the question I am leaving with you this week: 


if the external regulator disappeared tomorrow, what in your organization would still be regulated?

About the Author


Raimund (Ray) Laqua, P.Eng., PMP, is the Founder and Principal Consultant of Lean Compliance Consulting, Inc. He defined the practice of Lean Compliance, which helps organizations in highly regulated, high-risk industries meet their obligations by operationalizing them into promises they have the capability to keep. Ray is one of the first licensed software/digital engineers in Canada. He chairs the Digital Engineering Committee for Engineers for the Profession (E4P), serves on OSPE's AI in Engineering Task Force, and advocates nationally for Professional Digital Engineering licensure. Learn more at leancompliance.ca.

bottom of page