Agent Assurance

Installment 3 · 22 July 2026

Chapter 3: Controls as Recorded Incidents

Governance from below

The bank requires two signatories on the company account and does not say why. The insurer's renewal form wants the date of the last fire-alarm test. The auditor asks for a fixed-asset register that nobody has opened since the last time the auditor asked. A new client's procurement department sends a security questionnaire, and somewhere past question eighty the questions stop having any visible connection to the work being bought. From below, governance is a stream of obligations that do not explain themselves. Each obligation arrives with the same shape: a requirement, a deadline, and no reason. The reason is not withheld out of secrecy. It is not part of the form.

On the other side of the same life, failures arrive as news. A bank is gone over a weekend. A building is down. A company writes to its customers to say their records have been circulating for some months. Told as news, these events read as sudden and singular. The reporting concentrates on the loss and the people responsible; it rarely has room for the specific missing rule that would have caught the problem while it was still a detail.

So governance, from below, is two disconnected phenomena. Unexplained paperwork on one side, unexplained failures on the other, and no visible relation between them. The connection is a causal chain with its middle missing: the failure reports do not name the absent control, and the controls do not name the failures that wrote them.

The cost of living on the paperwork side has been measured. A meta-analysis of the research on red tape, drawing on 44 separate effect sizes, finds a statistically significant negative effect of red tape on organizational performance, and a slightly larger negative effect on the people who work under it.1 The causal direction has been established by experiment. A randomized study of 354 Chilean school principals found that adding compliance paperwork to their role raised measured burnout, and that removing it gave back less than adding it had taken.2 The role is ordinary: someone running a working institution, filling in forms whose purpose they cannot see, for authorities they rarely meet. The burden is real, causal, and asymmetric: paperwork added costs more than paperwork removed returns.

The burden is not confined to people working inside someone else's organisation. A quarterly small-business index published in December 2024 found 51 percent of small businesses saying regulatory compliance was negatively affecting their growth and 47 percent saying their firm spends too much time on it.3 A separate survey of 1,188 small-business owners, fielded in February 2025, found 57 percent saying the business was being held back by regulatory red tape and compliance.4 The same index found 69 percent saying they spend more per employee on compliance than larger competitors do. That is arithmetic before it is anything else. A requirement written once costs about the same to read and answer whether ten people stand behind it or ten thousand.

What those surveys measure is the weight of the paperwork. None of them establishes what the people carrying it make of the rules underneath, and that is a harder question to put than it looks, because answering it means knowing what each requirement prevents. An operator filling in a form cannot tell a rule that is doing nothing from a rule whose reason was stripped out before it reached them. Both arrive as a requirement and a deadline, and neither says what it is for.

The missing middle

Almost every control the reader has ever been subject to was written after something happened. The paperwork strips out its own history at the moment of codification, so the connection has to be reconstructed from cases where the seam is still visible.

The seam is most visible when the interval is short. On June 29, 1995, the Sampoong Department Store collapsed in Seoul. On July 18, 1995, nineteen days later, Korea enacted a statute establishing a dedicated legal framework for human-caused disasters.5 The year before, in October 1994, the Seongsu Bridge had collapsed in the same city; the statute that followed it established a regime of structural safety oversight for public works.6 Two collapses, two statutes, and in the first case a gap of under three weeks between the failure and the control. At nineteen days, nobody could mistake the relation: the act is the incident, converted into law.

The conversion is permanent but the visibility is not. The Special Act did not lapse when the memory faded; a facilities manager completing a structural safety inspection under it today meets a schedule of requirements, not a bridge. The requirement survived codification and the reason did not. Statutes enacted within weeks of a disaster are the limiting case. Most controls congeal far more slowly, through examiner manuals, standards revisions, insurer questionnaires, and audit checklists, each document copying from the last. By the time a rule reaches an operator as line item forty-one of an onboarding pack, it has passed through enough intermediate paper that its origin is no longer recoverable from its text. The chain is real in both cases. In the fast case it is on public display; in the slow case it has to be dug for.

The professional reading

A control is compressed incident history. A checkbox is shorthand for a disaster that already happened, to someone, somewhere, and was expensive enough to generate a rule. The book calls this reading controls as recorded incidents.

The requirement survives; the incident is discarded. Nothing in the two-signatory mandate mentions a theft. Nothing in the fire-alarm test date mentions a fire. Rules whose reasons have been stripped are experienced as rules without reasons, and a burden without a visible reason is resented even by people who accept, in general, that reasons exist.

Perceived injustice in a rule system generates cynicism and lowers the felt obligation to comply, and employees in some organizations treat security policy as guidelines rather than instructions, choosing non-compliance for convenience in day-to-day work.7 A rule whose reason has been stripped is not merely resented. It is discounted, which means the compression that loses the incident also loses part of the protection.

Some paperwork is exactly what it appears to be: burden without function, a rule that was copied from another rule and no longer traces to any failure at all, or never did. Not every control earns its cost. But every control makes a claim about incident history, and the claim can be checked. The checkable difference between a control and an empty ritual is whether the chain can be reconstructed, and reconstructing it is a skill.

Tracing in both directions

The skill runs the chain both ways.

Forward, from control to failure class: given any control, name the class of failures it exists to prevent, not the single incident behind it. The two-signatory rule does not encode one theft; it encodes the entire class of losses available to a single person who can move the firm's money alone. A practitioner shown an unfamiliar control reconstructs its failure class from its shape; where none can be reconstructed, the control is a candidate for ritual.

Backward, from failure to control: given any failure, name the control that would have caught it, and locate where that control should have been standing. This is the direction examiners, auditors, and accident investigators work in professionally, and their working documents are where the middle of the chain is preserved in public. An enforcement order that says a firm lacked adequate controls for a named activity is the chain written down: failure, arrow, missing control, in one citable document.

Chapter 2 recorded attorneys filing briefs that cited judicial decisions which did not exist, fabrications that passed the reading of the professionals who filed them. The failure was fabricated authority reaching a court, and the control that would have caught it is straightforward to name. A verification step, tracing every cited authority to the source it claims to come from, performed before filing by someone, or something, other than whatever generated the brief. Chapter 2 also recorded the investment firm whose clients spent three years paying fees on an impaired product. The trace runs to a durable record of changes made to the system doing the work, reviewable by someone whose interests are not served by silence. Neither control is exotic, and reconstructing them takes minutes. What the operator of chapter 1 lacks is the habit of reading a failure and naming the control it calls for.

People who do this for a living stop experiencing governance as two disconnected phenomena. Paperwork and failures resolve into one population, seen at different points in its life cycle: a failure is a control that did not exist yet, and a control is a failure that is not currently happening. The question in front of any given form stops being why must I do this and becomes what happened, which turns out to be answerable, from the public record, more often than the form's tone suggests.

Dual control

The reader has met this control at their own bank: the account that requires two signatures, the payment above a threshold that waits for a second approver. In a small firm it is met as friction, one more person to chase before a supplier gets paid.

The Federal Reserve's examination manual defines dual control as "requiring two different people to perform one sensitive task, such as opening the vault or signing checks". It gives the reason in the next sentence. When two individuals must act in collusion to commit fraud, it is much less likely to occur.8 Collusion is the far end of the failure class. The near end is ordinary: a number typed once, checked by nobody, released. What the rule closes is everything one unaccompanied person can do, the honest mistake included, and it does one further thing for the person it inconveniences: where only one person holds the vault, every discrepancy in the vault belongs to them alone. The manual goes on to operationalize the rule for cash handling, down to the requirement that vault combinations change when the people holding them change. This is the control as it stands today: rationale attached, incident absent. No examination manual records which clerk, at which bank, in which year, first demonstrated what a single person with sole access to the vault could do. The banking version of the rule survives with its logic intact and its history lost.

The same control exists at the highest stakes the modern state has, and there the record is better. United States procedural security for nuclear weapons mandates a two-person rule. No authorized access to a nuclear weapon takes place without at least two cleared, certified, task-knowledgeable individuals present. Each is required to be capable of detecting incorrect or unauthorized actions pertaining to the task being performed.9 It is the bank's rule, transposed: the failure class is whatever one unaccompanied person might do, and the control is the permanent presence of a second pair of qualified eyes.

And in the nuclear branch, unusually, a birth certificate survives. In May 1962, the president's science adviser, Jerome Wiesner, sent Kennedy a memorandum, attached to a national security action memorandum. It proposed that the weapons themselves be fitted with an "electro-mechanical lock which would have to receive a preset numerical code in order to make the weapon operable".10 The principle that no single individual should be able to act alone, cast into hardware, with a date, an author, and an addressee. Most controls lose their origins in the copying. Occasionally the paper survives, and when it does, the reader can watch a rule being written: a specific man, in a specific month, describing the failure class he intends to close.

Segregation of duties

The person who raises an invoice is not the person who approves its payment. The bookkeeper who reconciles the account is not a signatory on it. In a five-person firm the rule can feel like it exists mainly to slow the firm down, since everyone trusts everyone and the same two people end up approving each other's work in a circle anyway.

Audit questionnaires tend to explain the rule as fraud prevention, and it serves there. In an honest firm it earns its keep on different grounds. The person who built a piece of work is the person least equipped to see what is wrong with it. Where builder and checker are the same person, the work has no checker. The failure class is not theft. It is the error that nobody is positioned to catch.

The Metro Bank notice cited in chapter 1 is a segregation story from end to end, and a governance finding rather than a dishonesty finding. The bank's capital requirements rested on risk weightings assigned to its loans, and the interpretations of the regulatory rules that determined those weightings were documented nowhere except inside the spreadsheets and working papers themselves. The calculation was largely manual, spread across many spreadsheets, with no automated validation of the underlying data; such checking as occurred was manual too, and depended on the small number of individuals familiar with those spreadsheets. The calculation, the checking of the calculation, and the reasoning behind both lived with the same few people, inside the same files. The weightings were wrong for certain commercial loans. The correction, when it came, was an announcement to the market of a roughly 900 million pound adjustment to the bank's risk-weighted assets. A regulator's fine followed of over five million pounds for the governance around the reporting.11 Nothing was hidden and nobody profited. The arrangement had simply grown into one where the only review available was review by the same small group who built the files. An audit questionnaire compresses all of this into one dry line, the question whether the people who prepare a figure also approve it.

Change control

Change control is mostly met in its absence: the software update that breaks the thing that worked yesterday. In a small firm the absence has a familiar texture. The live system is the only system, changes are made directly on it, and the person making the change is also the person who decides the change is fine. Larger firms interpose paperwork here, a change process with approvals and a test environment, and that paperwork is resented in the terms this chapter opened with.

The incident that paperwork records, in its clearest public instance, took forty-five minutes. On August 1, 2012, the trading firm Knight Capital deployed new code to its equity order router. The deployment reactivated a defunct function whose code had been left in place since a relocation in 2005; the new code went out without the old code being removed. In the forty-five minutes after the market opened, the router sent over four million orders into the market while attempting to fill just 212 customer orders, trading some 397 million shares. The firm lost over 460 million dollars.12 Knight's own annual filing put the figure at 468.1 million dollars in trading losses and related costs, and described the event as the installation of trading software into production systems. It recorded that the firm had commenced an internal review of the event and the associated controls.13

The Securities and Exchange Commission did not charge Knight with losing money. It charged that the firm "did not have adequate controls and procedures for code deployment and testing for its equity order router".12 Failure and missing control, named in the same order: the chain with its middle intact, on the public record, citable by anyone. When a change-management form asks who tested a release, who approved it, and how it will be rolled back, the form is recording Knight Capital's forty-five minutes.

Controls that stop binding

A control is a recorded incident, but the record does not maintain itself. A control can be correctly derived from a real failure, installed, and watched, and still stop binding over the years, with nobody deciding to remove it. The control drifts back toward the failure it was written to prevent, one reasonable step at a time.

Investigating the loss of the space shuttle Columbia in 2003, the Columbia Accident Investigation Board adopted the sociologist Diane Vaughan's term for the pattern, the normalization of deviance. It is the acceptance of events that are not supposed to happen, treated as normal because they have happened before without harm.14 NASA had come to treat repeated foam shedding, a deviation the vehicle was never designed to tolerate, as routine. The board described the drift in decision terms. No single waiver was reckless; each was reviewed and accepted on its own, each acceptance making the next departure look ordinary, until the cumulative effect was catastrophic.

The same drift has a formal statement in the safety literature: under cost and efficiency pressure, work migrates toward the boundary of acceptable performance, and if crossing that boundary is irreversible, an accident is what marks it.15 The pressure is the ordinary pull of getting the work done with the time and the people available, and nothing pushes back until the boundary is crossed.

Metro Bank's capital calculation was a reasonable interim arrangement that grew, unremarked, into the only review available, and held for years. Chapter 1's other regulated case ran on the same logic: Nationwide Building Society's customer risk-assessment system, acknowledged from the start as an interim solution, held its post for roughly five years because it worked well enough that replacing it never became urgent. Each was reasonable at every step; the years it held are what did the damage.

The settings that erode are specific and dull: how often a sample is actually pulled, how promptly a reconciliation is run, how wide a control's exceptions have been allowed to grow. Chapter 9 returns to them directly, where the question is not whether a control was designed but whether it still binds after a year of reasonable waivers.

The model the book assumes

The rest of the book assumes the reading just exercised. Part II applies it at the scale of whole industries: chapter 4 records how entire assurance regimes, inspection, certification, audit, formed as the recorded incidents of steam, rail, and electricity, and chapter 5 records the economics of why the pattern recurs. Part III applies it prospectively. The agent-era controls of chapters 7 through 10 are each presented paired with the failure class behind them, so that the middle of the chain ships visible instead of being stripped in the usual way. Where the incident record for an agent-era control already exists in public, the pairing cites it; chapter 2's courtroom record was an early installment.

Some of those failure classes will be closed by their control, the way older safety codes eventually closed the hazards that produced them. Others, the ones chapter 1 marked as irreducible, are managed by their control rather than removed, because the failure they answer to does not go away. Either way the population is never finished: new capability writes new incidents faster than old controls retire, and a control once written can drift back toward the failure it names, so reading a control back to that failure never completes. It is the standing skill the rest of this book teaches.

The machinery that converts incidents into paperwork has, meanwhile, already started on this book's subject. In October 2023, a United States executive order directed the Department of Homeland Security to produce safety and security guidelines for the use of artificial intelligence in critical infrastructure within 180 days, incorporating the national AI risk-management framework. The guidelines arrived the following April, with three named categories of AI risk.16 Sooner or later, derivatives of documents like these will reach the operator of chapter 1 in the usual form, as line items on a questionnaire, stripped of their reasons. Those forms will not explain themselves; this chapter is the instruction for reading them.

Notes

  1. Meta-analysis of red tape research, Public Administration Review, 2021: population effect size r = -.108 across 44 effect sizes for organizational performance (z = 3.44, p < .01), with a similar, slightly larger negative effect across 39 effect sizes for employee outcomes. Ledger: ch03-e22.
  2. Randomized vignette survey experiment with 354 Chilean school principals, fielded November 2018 to January 2019 (Fuenzalida et al., 2024): experimentally increasing compliance red tape raised emotional exhaustion by an average 0.59 points (p < 0.01, roughly 0.4 standard deviations) and raised all three burnout dimensions; decreasing it lowered emotional exhaustion by 0.34 points (p < 0.1). Ledger: ch03-e25.
  3. MetLife and U.S. Chamber of Commerce Small Business Index, Q4 2024, published 16 December 2024: 51 percent of small businesses said navigating regulatory compliance requirements was negatively impacting their growth, 47 percent said their business spends too much time fulfilling them, and 69 percent said they spend more per employee to comply with regulations than larger competitors. Published by a business membership organisation, which is an interested party on the question. Ledger: ch03-e35.
  4. Goldman Sachs 10,000 Small Businesses Voices survey of 1,188 small-business owners, fielded 10 to 17 February 2025, released 5 June 2025: "Fifty-seven percent said their business is being held back by regulatory red tape and compliance." Ledger: ch03-e36.
  5. Korea's Disaster Management Act, enacted July 18, 1995, following the Sampoong Department Store collapse of June 29, 1995. The source, an academic history of Korean disaster management, renders the statute's name in one passage as the Disaster Control Act. Ledger: ch03-e01.
  6. The Special Act on the Safety Control of Public Structures, following the Seongsu Bridge collapse of October 1994. Ledger: ch03-e02.
  7. Both findings are reported secondhand, in literature reviews of the compliance and security-policy research (citing Clair, 2015, on perceived injustice and cynicism; Herath and Rao, 2009, on policy treated as guideline). Ledger: ch03-e12, ch03-e13.
  8. Federal Reserve, Branch and Agency Examination Manual, section on cash accounts: dual control and joint custody requirements, including signed vault registers and combination changes on change of custodian. Ledger: ch03-e17.
  9. US Department of Defense, Nuclear Matters Handbook (2020 revision), chapter 8, on procedural security. Ledger: ch03-e14.
  10. Memorandum from Jerome Wiesner to President Kennedy, May 1962, attached to National Security Action Memorandum 160; the device family it proposed became the permissive action link (PAL). Ledger: ch03-e16.
  11. Prudential Regulation Authority, Final Notice to Metro Bank plc, 21 December 2021, cited in chapter 1 for the improvised system and here for the arrangement around it. Ledger: ch01-e04 (the adjustment and fine), ch01-e05 (manual calculation, no independent validation, key-person dependency), ch01-e06 (rule interpretations documented only inside the spreadsheets and working papers).
  12. US Securities and Exchange Commission, administrative order and press release in the matter of Knight Capital Americas LLC, October 2013. The reactivated code related to the router's handling of orders under the NYSE Retail Liquidity Program. Ledger: ch03-e06.
  13. Knight Capital Group, Form 10-K for the fiscal year ended December 31, 2012. Ledger: ch03-e07.
  14. Report of the Columbia Accident Investigation Board, Volume I, August 2003, a US government board that adopted the term as a causal finding. On the term: "The acceptance of events that are not supposed to happen has been described by sociologist Diane Vaughan as the 'normalization of deviance.'" On the incremental shape: "Each decision, taken by itself, seemed correct, routine, and indeed, insignificant and unremarkable. Yet in retrospect, the cumulative effect was stunning." Ledger: ch03-e32, ch03-e33.
  15. Jens Rasmussen, "Risk Management in a Dynamic Society: A Modelling Problem", Safety Science 27 (1997), the migration model formalizing the same drift: work under efficiency pressure produces "a systematic migration toward the boundary of functionally acceptable performance and, if crossing the boundary is irreversible, an error or an accident may occur." Ledger: ch03-e34.
  16. Executive Order 14110, October 30, 2023; Department of Homeland Security, safety and security guidelines for critical-infrastructure owners and operators, April 2024, incorporating the NIST AI Risk Management Framework (AI 100-1) and naming three risk categories: attacks using AI, attacks targeting AI systems, and failures in AI design and implementation. Ledger: ch03-e11.