The maturity trap
I’ve spent half my career trying to convince boards that their compliance programmes aren't as mature as the slides suggest. Most executives love the word 'mature'. It sounds finished. It suggests they can stop worrying about it and move on to something else.
In an audit, 'mature' is usually a red flag. When a manager tells me a process is mature, I immediately want to know what they’d show me if I walked into their office on a Tuesday afternoon and asked for a random sample of evidence from last week. Not the policy document. Not the framework mapping. The actual evidence.
The gap between 'certified' and 'functional' has become a canyon. Look at tl;dv. They held a SOC 2 certification, yet just under 182,000 meeting records leaked because of a vendor failure. That’s the problem with treating certifications as trophies rather than tools. A SOC 2 report tells you that a company had some controls in place at a specific point in time. It doesn't tell you if those controls actually stopped a leak on a rainy Tuesday in August.
We’ve fallen into a trap where we trust the certificate more than the evidence.
Then there's the fraud side of the house. The SEC charging former Tricolor executives with falsifying loan documents isn't just about bad actors; it's a failure of the verification layer. When controls are described as mature, auditors often shift from 'testing for effectiveness' to 'checking for presence'. They see a signature on a document and tick the box. But if that signature is forged or the document is a fiction, the maturity score is irrelevant.
The PLDT situation is even more stark. Pulling audit opinions and amending a 20-F filing because of material control weaknesses is the ultimate admission that the internal narrative didn't match the reality. These firms likely had people with impressive titles overseeing 'mature' frameworks. Yet, when it came time for the external auditors to actually verify the numbers, the whole thing collapsed.
The argument usually goes like this: certifications provide a standardised baseline that reduces audit fatigue and ensures everyone is speaking the same language.
That’s fine for the people selling the certifications. For the person actually responsible for the risk, a baseline is just a floor. If you spend all your energy reaching that floor, you stop looking at the actual holes in your ceiling. Relying on a vendor's SOC 2 report to satisfy your own third-party risk management is essentially outsourcing your judgement to a piece of paper produced by a different auditor who wasn't looking for your specific risks.
The second-order effect here will be felt by insurers. We're already seeing GDPR fines hit north of €220 million in a single quarter. Insurers aren't blind. They've noticed that 'certified' companies still get hit by Medusa ransomware—which has already compromised over 500 critical infrastructure organisations.
Eventually, the insurance market will stop discounting premiums based on ISO or SOC 2 certificates. They’ll start demanding raw evidence of control execution. They won't want to see your AI management certification; they'll want to see the logs showing who accessed the model and why.
If you're running a compliance programme, stop asking if it's mature. Maturity is a vague, useless metric.
Instead, ask yourself: "If an auditor demanded a sample of my three most critical controls for last Tuesday, could I produce the evidence in ten minutes without calling a meeting?"
If the answer is no, your programme isn't mature. It's just well-documented.
The real danger is that we've built a compliance industry that rewards the appearance of control over the existence of it. We see it in the way firms chase new badges—like the recent rush toward AI certifications—before they've even figured out how to stop their current vendors from leaking 180,000 records.
I’ll change my mind when I see a certification that requires real-time evidence streaming rather than a point-in-time snapshot. Until then, treat every 'mature' label as a request for more sampling.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)