Auditen
number of the day

The Half-Billion Dollar Error

$584 million.

That is the operating loss Coupang just posted for the quarter. It isn't because their business model collapsed or they mismanaged a merger. They got hit by privacy fines in South Korea, and the impact ripped straight through the P&L.

I’ve spent two decades watching people treat "compliance" as a side-desk activity for the legal team to handle with a few spreadsheets and a prayer. They call it a regulatory risk. I call it a failure of control design. When a fine moves from being a rounding error in a legal budget to a half-billion-dollar hole in your quarterly earnings, you aren't dealing with a "regulatory hurdle." You're dealing with a broken internal control.

Most firms treat privacy like a checklist. They fill out a vendor questionnaire, they appoint a DPO who spends most of their time in meetings about meetings, and they tell the board that everything is under control. That’s control theatre. It looks great on a slide deck, but it doesn't actually stop the data from leaking or the regulator from knocking.

Look at the Metropolitan Police this week. The ICO didn't just give them a slap on the wrist; they issued an enforcement notice because their data protection policies were "weak."

The word "weak" is doing a lot of heavy lifting there. In my world, weak means you’ve documented a process that doesn't actually happen in practice. It means your policy says "access is restricted to authorized personnel," but the actual access list hasn't been reviewed since 2019. If you can't prove who has access to what and why, you don't have a control. You have a wish list.

Some will argue that Coupang's loss is an outlier, a freak occurrence driven by specific Korean regulations. They’ll say it isn't representative of the broader market.

That's a dangerous way to think. The regulator doesn't care if you're an outlier; they only care if you've failed to protect the data. Once the precedent is set that privacy failures can trigger material financial losses, every CFO in the room should be sweating. If you can't quantify the potential cost of a control failure at year-end, your risk assessment is fiction.

The second-order effect here isn't just the fine. It's the ripple through the assurance chain. When a company takes a hit like that, the auditors who signed off on the internal controls suddenly look very nervous. The insurers who underwrote the cyber policy start rewriting their terms to exclude "weak policies." Suddenly, your inability to design a basic data retention control costs you more than just the fine; it costs you your insurability and your credit rating.

Then we have the consultants. Deloitte just launched an AI-driven suite called ControlCatalyst.AI to "enhance efficiency" in SOX and risk lifecycles.

I’ve seen this movie before. Back in the early 2000s, when SOX first hit, every vendor had a tool that promised to automate compliance. The problem was always the same: if you automate a bad process, all you've done is make your failure more efficient. You can't "AI" your way out of a fundamental design flaw. If your control doesn't actually prevent the risk, it doesn't matter if it's managed by a human with a clipboard or a neural network in the cloud. It's still a failed control.

TikTok lost their battle over a £12.7 million fine this week. For a company of that size, twelve million is a rounding error. It’s a cost of doing business. But Coupang has shown us a different ceiling.

The question for any Head of Controls isn't "Are we compliant with the law?" That's a legal question. The real question is: "If our primary privacy control fails tomorrow, does it stay in the legal budget, or does it hit the operating loss?"

If you don't know the answer to that, you aren't managing risk. You're just waiting for your turn to be an outlier.

Check your access logs before Monday.