Your policies are killing your business.

Every standard you comply with has a material business cost, an accounting fact rather than an opinion.

The question is not whether to comply. The question is whether the policy that implements the standard was written to minimise the cost to the business, or to minimise the risk to the compliance officer. Those are different objectives. They produce different policies. Most organisations have never asked which one they are optimising for.

A surgical policy knows what it is cutting. It is derived from a clear understanding of what the business is for, what the standard actually requires, and where the two are in tension. It treats the standard as one constraint among several, weighted by its actual material cost to the business, not as the purpose itself.

The obvious objection is that a compliance officer minimising their own risk is not self-interest dressed as policy. It is a reasonable proxy, since they are often the person closest to what the standard actually requires and what happens when it is missed. That is true, and it argues for keeping compliance expertise in the room, not for handing the room over to it. The derivation this piece is arguing for still needs someone who understands the standard. It also needs someone accountable for what the standard costs, and today that second person is usually absent from the conversation entirely.

Most compliance programmes never do the derivation at all. They take the standard at face value, write policies that serve it, and hand the bill to the business in the form of inefficiency, friction, and work that exists only to satisfy an audit rather than to protect anything real.

The business is in its own business, not the compliance business. The standard is an instrument. The policy should serve the business first and the standard second. When that order inverts, the business pays.

This is a human problem, and we face it today without AI anywhere near it. But as AI systems begin acting on governance documents rather than interpreting them, the human layer that absorbed the bluntness of a poorly written policy disappears. A thoughtful compliance officer reads between the lines. An AI agent does not. The lazy policy becomes the actual constraint, enforced at machine speed across every system it touches.

The cost of imprecision does not stay the same. It compounds.