Words speak volume but are not controls
Aug 27, 2026
“We’ve Always Done It This Way” Is Not a Control
There are certain phrases that make an auditor's ears twitch.
"It's probably fine."
"Nobody has complained."
"The system won't let you do that."
"We've never had a problem before."
And the undisputed grand champion:
“We've always done it this way.”
Ah.
Well then.
Case closed.
Apparently, longevity has become evidence of effectiveness.
Except it isn't.
Doing something badly for fifteen years does not magically transform it into a good process. It simply means you've had a remarkably consistent relationship with a bad process.
When Was the Last Time Anyone Asked Why?
Organizations accumulate processes the way kitchen drawers accumulate mysterious objects.
You know the drawer.
Three batteries of questionable life expectancy. A key that doesn't appear to open anything you currently own. Seventeen rubber bands. A charger for a phone you haven't owned since 2014. One birthday candle.
And, inexplicably, a small screwdriver.
Nobody knows exactly where these things came from. Nobody is entirely certain why we're keeping them. But throwing them away feels strangely dangerous.
What if we need them someday?
Business processes can work exactly the same way.
A report is produced every Monday because it has always been produced every Monday.
Six people approve something because six people have always approved it.
A spreadsheet is manually reconciled because it has always been manually reconciled.
Someone prints a report, signs it, scans it and saves the PDF because that's what the procedure says.
A control exists because an auditor recommended it twelve years ago.
Ask why and someone eventually says:
"That's our process."
That tells me what you do.
It doesn't tell me why you do it.
Controls Have Expiration Dates Too
We recently talked about risk assessments having an expiration date.
Controls can have one too.
Yesterday's control may not address today's risk.
Systems change. People change. Regulations change. Business models change. Vendors change. Technology certainly changes.
And then there's AI, which appears to change while we're still holding the meeting about how much it changed last week.
Yet controls sometimes remain frozen while everything around them evolves.
Imagine a control designed ten years ago when a team manually processed 500 transactions a month.
Today, technology processes 50,000 transactions automatically.
But someone is still performing the same monthly manual review because:
“That's the control.”
Maybe it's still valuable.
Maybe it isn't.
The important question is:
What risk is this control supposed to address, and does it still address it?
Now we're getting somewhere.
More Controls Do Not Automatically Mean More Control
Here's another little trap.
Something goes wrong.
Add an approval.
Something else goes wrong.
Add a review.
Then a checklist.
Then another sign-off.
Then someone decides we need evidence that the sign-off occurred, so we add a second sign-off confirming the first person signed off.
Eventually seven people are approving a $500 transaction and nobody is entirely sure what any of them are actually checking.
But look at all those controls!
Surely we must be safe.
Not necessarily.
Controls have costs. They consume time, slow processes and use resources. Poorly designed controls can frustrate employees so much that people begin looking for ways around them.
The objective isn't to have the most controls.
It's to have the right controls for the right risks.
“The System Won't Let You” Is Also Not a Control Description
This one deserves special attention.
Ask how something is controlled and occasionally you'll hear:
"Oh, the system won't let you do that."
Really?
Wonderful.
Show me.
What exactly prevents it?
Who configured the rule?
Can anyone override it?
Who has administrator access?
What happens when there's an exception?
Does anyone review those exceptions?
Has the configuration changed?
When was it last tested?
Technology can provide excellent controls. Automated controls can be faster, more consistent and less vulnerable to ordinary human error than manual ones.
But assuming the system handles it is not the same thing as understanding the control.
And with more organizations adopting automation and AI-enabled processes, that distinction is becoming increasingly important.
The Control That Everyone Performs but Nobody Understands
This is where things get interesting.
Ask someone to explain a control they perform every month.
"I run this report, compare these two columns, highlight the differences and send it to my manager."
Great.
Why?
"Because that's the monthly reconciliation."
What risk are you looking for?
"I'm not sure."
What differences would concern you?
"Anything unusual."
What counts as unusual?
"Well..."
And suddenly we discover that someone has been faithfully performing a control for four years without understanding what the control is actually supposed to accomplish.
That's not necessarily the employee's fault.
Sometimes we teach people what to do without ever teaching them why it matters.
And when people don't understand the why, they are much less likely to recognize when the process stops making sense.
Give Your Controls a Job Interview
Here's a simple exercise.
Pick one longstanding control in your organization and pretend you're interviewing it for its own job.
Ask:
-
Why do you exist?
-
What specific risk do you address?
-
What evidence shows that you work?
-
Has that risk changed since you were created?
-
Could technology perform you better?
-
Are you duplicating another control?
-
What would happen if we removed you?
-
Does anyone actually use the information you produce?
You may discover the control is absolutely essential.
Wonderful.
Keep it.
You may discover it still serves a purpose but needs redesigning.
Excellent.
Improve it.
Or you may discover you've spent eleven years producing a report nobody reads.
In which case, perhaps we can finally set that poor spreadsheet free.
Internal Audit Should Be Asking This Too
Auditors aren't exempt from “We've always done it this way.”
We have our own traditions.
The same audit every three years.
The same testing approach.
The same sample size.
The same workpaper.
The same report format.
The same twenty-seven questions in the audit program because they've been there since someone named Bob created the template in 2009.
Risk-based auditing means more than changing the dates on last year's audit program.
If the business has changed, our audit approach may need to change too.
Sometimes auditors should turn that wonderful question back on ourselves:
Why are we doing this?
And if the only answer is:
"Because we always do..."
Perhaps it's time for another question.
Don't Confuse Familiar With Effective
Familiarity is comfortable.
We know the process.
We know the spreadsheet.
We know where to click.
We know which box to tick.
And because nothing terrible has happened, we assume the process works.
But absence of failure isn't always evidence of good control.
Sometimes we've been well controlled.
Sometimes we've been lucky.
Knowing the difference matters.
Learn. Question. Improve. Grow.
Good professionals don't challenge processes simply to be difficult.
They challenge them because curiosity is one of the most valuable tools we have.
Don't settle for:
“That's how we've always done it.”
Ask:
“Why do we do it this way?”
Then go one step further:
“Is this still the best way to do it?”
Those are small questions.
But small questions have a habit of opening very large doors.
At LG3, that's the kind of learning we want to encourage. Not simply learning another process, framework or formula, but understanding enough to question whether it still makes sense.
Learn. Question. Improve. Grow.
That's how we Learn and Grow with LG3.
Your turn...
What's something your organization does simply because “we've always done it this way”?
And the really interesting question:
Does anybody still remember why?
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.
We hate SPAM. We will never sell your information, for any reason.