top of page
Search

Compliance Was Always Risk Management. We Just Stopped Treating It That Way

For nearly thirty years I have looked at organizations the way an attacker looks at them, and the most important thing I can tell any leader right now has nothing to do with a specific tool or a specific threat. It is this. The upheaval is not temporary. We keep waiting for things to settle, for the disruption to pass, for some return to a calmer baseline. That baseline is not coming back. Whether you are staring at AI, at your IT controls, at the financial system, at crypto, or at a supply chain that breaks in a new place every quarter, the common thread is volatility that is now permanent. It is the climate, not the weather. And the cost of getting it wrong is no longer theoretical. IBM's 2025 Cost of a Data Breach Report put the average breach in the United States at a record 10.22 million dollars. The global average actually fell to 4.44 million, but in this country it went the other way, driven by regulatory fines and slow detection. That is the price of a single bad day.


When the environment is permanently uncertain, the question for every business stops being “are we compliant” and becomes “do we actually understand what could hurt us, and have we decided what to do about it.” That is risk management. And I would argue it is the single discipline that now has to sit above everything else a company does. Not as a department. As a lens. Security, IT, finance, legal, operations, vendor relationships, and yes, your compliance obligations, all of it belongs under one umbrella. The moment risk stops being the organizing principle and becomes one more line item, you start checking boxes instead of getting safer. Those are not the same activity, and confusing them is how well-audited companies still get destroyed.


Here is the part people forget. Compliance was never the enemy of risk management. Compliance was one of its first serious attempts to institutionalize itself. Go back to 2002. Enron and WorldCom had just vaporized shareholder value and trust on a scale that shook the entire market. Congress responded with Sarbanes-Oxley. Most people remember SOX as a compliance burden, the thing that made finance teams miserable every quarter. But look at what it actually did. Section 302 forced the CEO and CFO to personally certify the financial statements. Section 404 forced management to document, test, and attest to internal controls over financial reporting, with the outside auditor weighing in. It created the PCAOB to watch the watchers. It leaned on the COSO framework, which is, at its core, a risk and internal control model. Strip away the paperwork and SOX was a statement that executives own the risk of getting their numbers wrong, and they have to prove they have controls that manage that risk. That is risk management wearing a compliance uniform.


Now watch what happened to the cost. When SOX was being written, the SEC estimated that the new internal controls requirement in Section 404 would run about 91,000 dollars per company per year. That was the official projection. Two decades later, Protiviti's annual SOX survey finds most companies spending between one and two million dollars a year on SOX alone, with roughly a third of mature filers spending more than two million. Internal audit teams now pour close to half their total hours into it. The original estimate was not off by a little. It was off by more than ten times. And that is the cost of one framework, the one we understand best, after twenty years of practice. Keep that number in your head, because almost no company today carries only one.


This is where it gets expensive in a way most leadership teams never model honestly. Take a mid-sized firm that sells software into regulated industries. It needs SOC 2 to close enterprise deals. It touches cardholder data, so PCI DSS applies. It has health customers, so HIPAA is in scope. It wants to sell in Europe, so GDPR. It is chasing defense work, so now CMMC and NIST 800-171. It standardizes on ISO 27001 because a partner demanded it. That is six frameworks, and I have just described an ordinary company, not an outlier. Each one arrives with its own auditor, its own evidence requests, its own calendar, its own consultant. The Ponemon Institute pegged the average cost of compliance across major data protection regimes at around 5.5 million dollars a year, and for financial services firms closer to 31 million. Ninety percent of the organizations they studied named GDPR as the single hardest regime to satisfy. Stack several of these without a shared foundation and the costs do not add. They compound, because you are paying repeatedly to solve the same problem in slightly different dialects.


Here is the absurd part. These frameworks overlap enormously. Access control, encryption, logging, incident response, vendor management, the same handful of fundamental controls show up in every single one of them. Multi-factor authentication does not mean something different to SOC 2 than it does to CMMC. Yet most organizations design that control once for each framework, document it once for each auditor, and test it once for each cycle, as if they were five unrelated requirements. That is compliance fatigue, and it is largely self-inflicted. The way out is not fewer frameworks, because you do not get to opt out of HIPAA or CMMC. The way out is to flip the hierarchy. You put risk management on top, you build one risk-driven control environment, and you map that single set of controls once to every framework you have to satisfy. The industry even has a name for it now. A common controls framework. Hyperproof's latest benchmark found that 56 percent of organizations have adopted one, and it has quietly become standard practice for exactly this reason. Comply once, satisfy many. The work goes down and the actual security goes up, because the controls finally exist to reduce risk rather than to generate a clean report.


Step back and the logic is obvious, because every one of these regimes is the same instinct pointed at a different danger. SOX is financial reporting risk. PCI is payment data risk. HIPAA is health data risk. SOC 2 is the risk of trusting a service provider. CMMC and NIST 800-171 are the risk of leaking defense information through the supply chain. The NIST AI Risk Management Framework, the EU AI Act, and ISO 42001 are that same instinct aimed at AI, which is exactly where the next wave of loss is already showing up. That same IBM report found that one in five breaches now involves shadow AI, the unsanctioned tools employees adopt without telling anyone, and that those incidents add about 670,000 dollars to the cost of a breach. Ninety-seven percent of the organizations that suffered an AI-related breach had no access controls around their AI at all. Healthcare breaches averaged 7.42 million. None of these are compliance failures in the narrow sense. They are risk failures that a checkbox would never have caught.


And if the cost of compliance makes a CFO wince, the cost of not doing it should make the whole board sit up. The same Ponemon research found that non-compliance runs about 2.71 times the cost of compliance, roughly 14.8 million dollars against 5.5 million, once you count business disruption, lost productivity, lost customers, fines, and cleanup. That is a gap of more than nine million dollars a year, on average, between the companies that invest in this properly and the ones that gamble. And the most useful finding buried in that research is the cheapest lever of all. The single biggest source of savings was not a tool. It was centralizing and standardizing the compliance function instead of running it in silos. Which is precisely the argument for putting risk management at the center.


This matters more now than at any point in my career, because the macro environment is removing the margin for error. We are deep into a phase where supply chains are fragile by default and reorganize under stress with no warning. Companies are consolidating at a pace I have rarely seen, with private equity rolling up entire professional service sectors and merging firms faster than they can integrate their controls, their systems, or their cultures. Every merger is a risk event. The GRC professionals surveyed by Hyperproof flagged exactly this, that rapid growth through acquisition drags in disparate systems and the attitude of “we will deal with that later,” which is how the gaps get baked in. Every new vendor is an inherited attack surface. Every AI tool quietly adopted by a team that did not tell IT is shadow risk you are now carrying whether you measured it or not. The companies that survive this are not the ones with the most certifications on the wall. They are the ones that made risk the foundation and built everything else on top of it. Tellingly, in that same Hyperproof data, the organizations that took an integrated, automated approach to risk were measurably less likely to be breached.


A certification is a snapshot. Risk is continuous. If your program only wakes up when an audit is scheduled, you are defending yourself one photograph at a time while the threat moves in video.


So here is my gut check for you. If you laid out every compliance obligation your organization carries, added up what each one costs you in dollars and hours, and then asked one simple question of each, “does this actually make us harder to hurt, or does it just make us easier to audit,” how many could honestly answer the first one? And if you have never mapped those obligations down to a single underlying set of risks and controls, you are almost certainly paying several times over for protection you are not fully getting. That is not a failure. That is the most valuable place to start.

 
 

Recent Posts

See All
My Top Ten AI Attack Vectors

Everyone is watching the IPOs, the mega mergers, and the giant data centers. I have been in those conversations as much as anyone. For months the argument was whether AI security was a real concern.

 
 

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page