When One Salesperson Can Distort Corporate Reality – What the WANdisco Case Teaches Us About the Next Step from GRC to Governance Intelligence

Last Updated on 29/08/2026 by 75385885

What the WANdisco Case Teaches Us About the Next Step from GRC to Governance Intelligence

Topics show

Sales fraud internal controls – Sales fraud can remain hidden even when an organisation has established internal controls, approval procedures and financial reporting controls. The WANdisco case provides a powerful illustration of a broader governance question: can GRC be enriched by connecting control evidence with Governance Reality to identify anomalies that deserve investigation?

A well-designed governance system can contain policies, approval procedures, segregation of duties, revenuerecognition controls, management reporting, internal audit and external audit. Individual transactions can pass through apparently legitimate processes. Risks can even have been identified correctly.

And yet the picture presented to management, the board and investors can still diverge dramatically from economic reality.

The WANdisco case provides a particularly interesting illustration of this problem.

In March 2023, British software company WANdisco announced that it had discovered what it described as “significant, sophisticated and potentially fraudulent irregularities” relating to purchase orders, revenue and bookings represented by one senior sales employee. The consequences were extraordinary. Revenue for 2022, previously expected to be approximately $24 million, could be as low as $9 million. The company withdrew confidence in its earlier revenue guidance, warned of a significant impact on cash and raised material uncertainty concerning its financial position. Trading in its shares on AIM was suspended.

Subsequent reporting on the independent investigation described an even larger problem in sales bookings. According to AAT’s account of the FRP Advisory investigation, more than $115 million of false sales bookings had been identified, while purchase orders associated with the senior employee were found to be illegitimate. The same report states that the other orders examined were legitimate.

It would be tempting to turn this into another familiar story about fraud, failed controls and the need for more compliance.

That would miss the more interesting governance question.

The case invites us to ask something different:

How can an organisation become so dependent on one representation of reality that a major divergence between reported commercial success and underlying economic activity remains insufficiently visible?

That question matters far beyond WANdisco.

It goes to the heart of how Governance, Risk & Compliance — GRC — may evolve as organisations become increasingly data-driven.


1. A historical case, not a reconstruction

An important qualification is necessary at the outset.

This article uses the publicly reported WANdisco case to illustrate a governance concept. It is not a reconstruction of the events, does not attempt to determine what particular individuals knew at particular moments and does not suggest that the analytical approach discussed below would necessarily have discovered or prevented the reported irregularities.

Nor should the article be read as criticism of WANdisco’s management, its auditors or other advisers based on information that became available only afterwards.

Hindsight is a remarkably powerful audit tool.

The more useful exercise is prospective: what can organisations learn from a case like this when designing the next generation of governance monitoring?

That distinction is important because the objective is not to build a machine that retrospectively labels transactions as fraudulent. It is to improve an organisation’s ability to recognise when different parts of its own operational reality cease to tell a coherent story.


sales fraud internal controls sales fraud, fake sales, revenue fraud, internal controls, GRC, Governance Intelligence, Governance Control Navigator

sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls sales fraud internal controls

2. One employee, an enterprise-wide consequence

There is something striking about the scale asymmetry in this case.

At one end was reportedly one senior sales employee. At the other end were revenue, bookings, cash expectations, financial reporting, investor information, the company’s share price and ultimately questions about financial viability.

Between those two points sat an entire organisation.

WANdisco was not a tiny business operating from a spreadsheet. It was a listed technology company with operations in Sheffield and California and more than 180 employees. Its software supported large-scale migration of data to the cloud. According to the AAT account, its customers included organisations such as Google and Amazon.

That makes the governance problem especially instructive.

A large commercial transaction does not normally exist only inside the sales department.

It has consequences.

A customer needs to exist. Commercial negotiations take place. A contract or purchase order is produced. Products or services must eventually be delivered. Implementation resources may need to be allocated. Revenue recognition criteria must be satisfied. An invoice may be raised. A receivable emerges. Cash should ultimately arrive. Forecasts change. Sales commissions may become payable. Customer support activity may follow.

The transaction creates what might be called an economic footprint across the enterprise.

This is where the distinction between control evidence and governance reality begins to matter.

Read more in the Guardian on: Software firm WANdisco suspends shares amid ‘fraudulent irregularities’.


3. Traditional GRC was asking the right questions

The easiest conclusion from a case involving false sales would be:

The controls failed.

But that statement is too crude to be analytically useful.

Traditional GRC has brought enormous discipline to organisations. Risks are identified and assessed. Controls are assigned to risks. Control owners are established. Policies define required behaviour. Segregation of duties reduces inappropriate combinations of authority. Compliance requirements are mapped. Exceptions are recorded. Controls are tested. Internal Audit provides independent assurance.

These mechanisms are indispensable.

Indeed, one detail in the WANdisco case makes simplistic criticism particularly inappropriate.

According to AAT, BDO’s 2021 independent auditor’s report had identified specific risks of fraud and error concerning inappropriate revenue recognition because of the nature of the group’s customer contracts. The auditor also referred to the risk of manipulation of revenue through manual journal entries.

In other words:

The risk itself was not necessarily invisible.

This changes the governance discussion.

The question is no longer merely whether the organisation had identified revenue recognition as a risk.

The more interesting question is whether governance technology can go further and continuously compare the different manifestations of economic reality that should accompany reported commercial activity.

That is not a replacement for GRC.

It is an extension of what GRC has already made possible.


4. The difference between a valid control and a valid reality

Consider a simplified sales process.

A company may require a purchase order before recognising a transaction. The purchase order is present. The document contains the expected fields. The appropriate employee has processed it. Required approvals appear to have occurred.

From a control perspective, those observations are relevant evidence.

But imagine that the organisation simultaneously contains other information:

The customer has almost no previous commercial history.

No corresponding implementation project has started.

No delivery resources have been reserved.

Billing is substantially delayed.

Receivables associated with a particular salesperson are ageing differently from the rest of the portfolio.

Cash conversion is materially below that of comparable customers.

Customer-support activity is absent.

Reported bookings attributable to one salesperson have increased dramatically while the operational organisation supporting those bookings has hardly changed.

None of these observations individually proves anything.

There may be perfectly legitimate explanations for every one of them.

Large contracts can have unusual payment schedules. Software companies can sign deals months before implementation. Enterprise customers may have complicated procurement structures. Revenue and cash rarely move in perfect synchronisation.

That is precisely why governance intelligence should not behave like a fraud detector.

Its role is more subtle.

It asks whether the combined evidence remains sufficiently coherent to support the reality being reported.


5. Follow the transaction beyond Finance

Traditional financial analysis often ends up following transactions towards the general ledger.

That makes sense. The financial statements ultimately emerge from the accounting system.

But economic activity moves in the opposite direction.

It starts in the business.

Consider a simplified value chain:

Customer → Opportunity → Contract → Purchase Order → Booking → Delivery → Revenue → Invoice → Receivable → Cash

Not every business will follow this exact sequence, and software businesses can have particularly complex contractual and revenuerecognition structures.

Nevertheless, genuine commercial activity usually leaves multiple traces.

This gives us a powerful governance principle:

The larger the reported economic event, the more organisational evidence we should normally expect it to generate.

A $10 million booking should not merely produce a $10 million number in a sales report.

Somewhere in the organisation there should normally be a customer, commercial correspondence, contractual obligations, delivery expectations, operational consequences, financial consequences or future cash expectations consistent with that booking.

Governance therefore becomes partly a question of relational integrity.

Do the different parts of the organisation recognise the same underlying economic event?


6. From individual transactions to populations

This leads to another important distinction.

Many controls assess individual transactions.

Was this order authorised?

Was this journal approved?

Was this customer created correctly?

Was the appropriate contract documentation present?

Was revenue recognised in accordance with the applicable accounting policy?

These are necessary questions.

But organisational behaviour exists at another level as well: the population.

Suppose Sales Executive A produces 400 transactions.

Each transaction, viewed individually, looks plausible.

Now compare the complete population with those of other sales executives.

Perhaps Executive A generates:

  • an unusually high proportion of very large contracts;
  • significantly shorter sales cycles;
  • unusually high quarter-end bookings;
  • substantially lower conversion from bookings into invoices;
  • longer delays between contracting and implementation;
  • much lower subsequent cash conversion.

The individual transactions may still appear ordinary.

The collective behaviour is not.

This is an important governance insight:

A population of individually plausible transactions can collectively describe an implausible organisational reality.

Traditional control testing and population analysis therefore answer different questions.

One asks whether the transaction complies with the expected control.

The other asks whether the behaviour emerging from thousands of transactions remains consistent with the organisation’s expected economic model.

Both matter.

Also reda this: How one individual’s dishonesty can undermine an entire business on aatcomment.org.uk (The Association of Accounting Technicians).


7. The Three Governance Realities

This distinction can be formalised through three different views of governance.

Governance Design

This is the organisation as intended.

Policies, procedures, delegated authorities, risk frameworks, internal controls, system configurations, segregation of duties and accounting policies define how business should be conducted.

Governance Design answers:

How are we supposed to operate?

Governance Execution

This is evidence that the governance design is actually being performed.

Were approvals completed? Were reconciliations executed? Were exceptions investigated? Were access rights reviewed? Were controls tested?

Governance Execution asks:

Did we perform the governance activities we designed?

Collective Governance Behaviour

This is the reality that emerges when the organisation actually operates.

Customers behave. Employees make decisions. Contracts accumulate. Orders flow through systems. Products are delivered. Services are performed. Receivables age. Cash arrives. Exceptions cluster. Overrides occur.

Collective Governance Behaviour asks:

What does the organisation’s actual behaviour tell us?

The three should broadly reinforce each other.

But they are not identical.

An organisation can have excellent Governance Design and substantial evidence of Governance Execution while still developing patterns of Collective Governance Behaviour that deserve attention.

That is the space in which the concept of Governance Reality becomes valuable.


8. What might Governance Reality have asked at WANdisco?

We need to be careful here.

We do not have the underlying WANdisco datasets and therefore cannot claim that any particular analytical signal existed before the irregularities were discovered.

But we can use the case to construct a theoretical governance analysis.

Imagine that a governance system had access — subject to appropriate permissions and data governance — to CRM data, customer master data, contracts, purchase orders, sales bookings, implementation activity, invoices, receivables, cash receipts and perhaps sales commissions.

Instead of searching for “fraud”, the system compares relationships.

It might ask:

Do bookings attributed to each salesperson convert into operational activity at broadly explainable rates?

Do customers associated with exceptionally large bookings subsequently display the economic characteristics expected of customers of that size?

Does revenue growth correspond with growth elsewhere in the enterprise?

Are concentrations emerging around particular employees, customers, periods or transaction types?

Are there transactions whose documentary evidence exists but whose wider operational footprint is unexpectedly weak?

These are not accusations.

They are management questions generated from organisational evidence.

And that difference is fundamental.


9. An anomaly is the beginning of an investigation, not its conclusion

Suppose an analytical system finds that one salesperson accounts for an exceptionally large proportion of new bookings.

There is nothing inherently wrong with that.

The salesperson may simply be outstanding.

Now suppose those bookings have unusually little subsequent implementation activity.

Still not evidence of wrongdoing.

Perhaps the salesperson specialises in long-term contracts.

Suppose cash conversion is also substantially lower.

Again, there may be an explanation.

Then suppose the relevant customer relationships are relatively new, sales cycles are unusually short and order values are materially larger than comparable transactions.

The individual observations remain inconclusive.

But together they form a pattern.

A well-designed governance-intelligence system should not display a flashing red screen saying:

FRAUD DETECTED.

It should say something much more useful:

The commercial activity associated with this population differs materially from comparable activity and is not yet fully supported by the expected operational and financial evidence. Management review is recommended.

Then it should show why.

That final requirement is crucial.

If an algorithm cannot show the evidence behind its conclusion, governance has merely replaced human opacity with technological opacity.


10. Evidence to investigate, not evidence to convict

This brings us to perhaps the most important lesson from the WANdisco case for the future development of GRC technology.

An anomaly is not proof of misconduct.

It is not even proof that a control has failed.

It is evidence that something deserves explanation.

That distinction should be embedded in the architecture of governance technology.

A Governance Control Navigator-type analysis should therefore produce a traceable chain:

Observed signal → underlying transactions → connected business objects → expected relationship → observed divergence → management question

For example:

Sales Executive X represents an unusually high proportion of new bookings.

That statement alone is weak.

But the system could subsequently show that the signal arises from 37 identified bookings, associated with 12 customers, of which a defined proportion lacks the operational patterns normally observed within a specified period after comparable bookings.

Management can inspect the underlying transactions.

Perhaps the explanation is completely legitimate.

If so, the governance process has worked.

The objective was never to catch someone.

The objective was to make an unexplained divergence visible, traceable and investigable.

And that is where Governance Reality begins to add something genuinely different to the established GRC architecture.


A governance anomaly is not evidence of fraud. It is not necessarily evidence that somebody has breached a policy. It may not even indicate that a control has failed.

It is evidence that something in organisational reality deserves an explanation.

That distinction matters because it changes the purpose of governance technology. Instead of trying to automate the judgement of Internal Audit, Compliance, Finance or management, technology can help those functions see relationships that are difficult to recognise when controls and transactions are assessed separately.

The WANdisco case provides a powerful illustration. Public reporting describes irregularities concerning purchase orders, bookings and revenue represented by one senior sales employee. The eventual consequences extended far beyond Sales into financial reporting, expected cash and the company’s financial position.

The lesson is therefore not simply that sales controls should have been stronger.

The deeper question is:

How can governance connect what Sales says happened with the evidence produced by the rest of the organisation?

That takes us from control assurance towards Governance Intelligence.


11. Accounting controls cannot establish economic reality on their own

Finance has traditionally occupied a privileged position in corporate control.

For good reason.

Double-entry bookkeeping creates discipline. Reconciliations force balances to connect. Period-end procedures create structure. Revenuerecognition policies determine when commercial activity can enter the income statement. Internal and external audit provide further challenge.

But the general ledger has an important limitation.sales fraud internal controls

It records the accounting representation of economic events.

It does not independently prove that the economic event itself occurred exactly as represented.

Consider a simple sale.

The accounting records may contain revenue and a corresponding receivable. The journal balances perfectly.

Debit receivables.

Credit revenue.

There is no mathematical error.

A reconciliation between the subledger and general ledger can also work perfectly. The receivable exists in both.

A revenue report can agree exactly with the ledger.

Management reporting can subsequently agree exactly with the financial records.

We could therefore have several internally consistent layers of information.

And still need to ask:

What economic event caused this accounting?

That is why supporting evidence exists.

Contracts, customer purchase orders, proof of delivery, service records and other documentation connect accounting to business activity.

Traditional GRC recognises this perfectly well.

The opportunity for further development lies in making those connections systematic and continuous, rather than primarily dependent upon individual control procedures, periodic reconciliations or samples.


12. Corporate reality exists across systems

A modern organisation rarely has one source containing its entire economic reality.

Sales may live in CRM.

Contracts may be maintained in a contract-management platform.

Customer master data may reside in ERP.

Project delivery may be recorded elsewhere.

Invoices and receivables sit in Finance.

Cash enters through banking systems.

User identities may be controlled through Identity & Access Management.

Customer support may operate in another application altogether.

Every system sees part of the elephant.

Traditional controls quite reasonably focus on ensuring that each part functions correctly and that important interfaces are reconciled.

Governance Reality asks another question:

What happens when we reconstruct the elephant?

Imagine connecting a reported sale to its associated business objects:

Salesperson → Opportunity → CustomerContract → Purchase Order → Booking → Delivery → Invoice → Receivable → Cash

Now the sale is no longer simply a number.

It has relationships.

Those relationships create expectations.

A contract does not necessarily produce an invoice immediately.

An invoice does not necessarily produce cash within 30 days.

A large software booking may precede implementation by months.

Nothing about these relationships should therefore be reduced to simplistic rules such as:

No cash after 30 days = suspicious.

That would produce enormous numbers of false positives and tell management very little.

Instead, the organisation can learn what normal relationships look like for different types of transactions.

Enterprise contracts may behave differently from smaller customers.

Subscription contracts may behave differently from perpetual licences.

New customers may behave differently from renewals.

Different geographies may have different payment cycles.

Once those distinctions are understood, Governance Intelligence can start identifying material deviations from comparable populations.

The objective is not standardisation for its own sake.

It is explainability.


13. The missing footprint can be as informative as the transaction itself

This brings us back to the hypothetical analysis inspired by WANdisco.

Imagine a salesperson reporting exceptionally strong bookings.

Traditional management reporting might celebrate the result.

That may be entirely appropriate.

But Governance Intelligence can ask what else should gradually become visible if those bookings represent genuine commercial activity.

Perhaps new implementation projects should appear.

Perhaps customer onboarding activity should increase.

Perhaps invoices should eventually follow.

Perhaps receivables should emerge.

Perhaps cash should arrive.

Perhaps customer-support activity should increase.

Perhaps the sales pipeline should show a credible history preceding the transaction.

The absence of one of those elements means little.

The absence of several may mean more.

And the systematic absence of several across a population of unusually large bookings begins to create an important governance question.

This gives us a useful concept:

the missing economic footprint.

It is not necessarily an error.

It is certainly not automatically fraud.

It is the difference between the organisational evidence we would reasonably expect and the evidence we actually observe.

That difference is Governance Divergence.


14. From anomaly detection to explainable evidence

There is a danger here.

Modern technology makes it relatively easy to create anomaly scores.

Machine-learning models can identify unusual transactions. Dashboards can rank employees, customers and suppliers by deviation from statistical norms.

But a number saying:

Risk score: 87%

is of surprisingly limited governance value.

Why 87%?

Which transactions caused it?

Against which population were they compared?

Which relationships were unusual?

What business rule or governance expectation was relevant?

Has the pattern existed for two days or two years?

Can management reproduce the conclusion?

Can Internal Audit challenge it?

Can the person responsible for the process explain it?

If those questions cannot be answered, the organisation has created another black box.

That is the opposite of good governance.

A GCN-type approach therefore needs to be evidence-led rather than score-led.

Suppose a governance observation states:

Commercial bookings associated with a defined population show materially lower subsequent operational and financial conversion than comparable bookings.

Management should be able to move immediately from that observation to the underlying evidence.

Which bookings?

Which customers?

What comparison group?

What was the expected relationship?

Which delivery activity was found?

Which invoices followed?

What cash was received?

What period was analysed?

Only then does an anomaly become actionable governance information.


15. Evidence to investigate, not evidence to convict

This principle deserves emphasis because it determines how Governance Intelligence should be used.

Imagine that the analysis identifies a salesperson whose bookings differ significantly from colleagues.

The worst possible organisational response would be:

The system says this employee is suspicious. Investigate the employee.

That risks turning governance monitoring into employee surveillance.

It also confuses correlation with causation.

There may be many legitimate explanations.

Perhaps this salesperson handles the largest strategic accounts.

Perhaps contractual structures are different.

Perhaps implementation deliberately occurs much later.

Perhaps invoices are raised through another legal entity.

Perhaps the customers use unusually long procurement cycles.

Perhaps the organisation itself has a data-quality problem.

The correct first question is therefore not:

What did this employee do wrong?

It is:

Why does this population behave differently?

That distinction protects both the organisation and the individual.

The unit of analysis should initially be the governance relationship, not the person.

Only when investigation establishes that individual conduct is relevant should the focus move towards personal responsibility.

This is particularly important when AI and advanced analytics enter governance.

Algorithms should not quietly become automated disciplinary mechanisms.

Their role should be to make evidence accessible to professional judgement.


16. The investigation itself becomes part of governance

Now suppose management reviews the anomaly.

The explanation turns out to be legitimate.

That should not be considered a failed alert.

It is valuable information.

Perhaps a new type of customer contract behaves differently from the historical population. The governance model can then be updated.

Perhaps a recently introduced commercial model creates a six-month delay between booking and implementation. That becomes part of the expected relationship.

Perhaps two systems use different customer identifiers, causing apparently missing connections. Then the analysis has exposed a master-data weakness.

The cycle becomes:

Observe → Question → Investigate → Explain → Improve → Monitor

But suppose the explanation is not convincing.sales fraud internal controls

Then the evidence can be escalated.

Finance may review the accounting.

Commercial management may contact the customer.

Legal may examine the contract.

Internal Audit may independently assess the process.

Compliance may become involved.

If necessary, specialist forensic expertise can follow.

The important point is that the initial governance observation remains separate from the eventual conclusion.

GCN provides a decent evidential basis for asking the question.

Professional functions determine the answer.

This preserves accountability where it belongs.


17. Internal Audit gains a map, not an autopilot

The same principle applies to Internal Audit.

Governance Intelligence should not replace Internal Audit.

Internal Audit performs something fundamentally different: independent professional assessment.

But consider the practical reality of an audit universe containing hundreds of processes, entities, systems and risks.

Resources are finite.

Traditional risk assessment helps determine where audit attention should be directed.

Governance Reality can add another dimension:

Where is actual organisational behaviour moving away from expected behaviour?

An audit team could potentially see that:

commercial activity in one region has changed unusually quickly;

manual interventions in a process are increasing;

exceptions cluster around particular transaction types;

a previously resolved divergence is returning;

the relationship between sales, delivery and cash is changing;

one process is becoming increasingly dependent upon overrides.

These observations do not tell Internal Audit what conclusion to reach.

They help determine where asking questions may create the most value.

GCN therefore gives Internal Audit a better map.

It does not drive the car.


18. The same applies to external audit

There is also an obvious connection with financial-statement audit, although boundaries must remain clear.

The WANdisco case is particularly instructive because inappropriate revenue recognition was reportedly already recognised as an audit risk.

Governance Intelligence does not remove the need for audit procedures.

Nor does an internal GCN observation constitute audit evidence merely because management has generated it.

Auditors must determine the relevance and reliability of information used in their work and perform procedures appropriate to the audit.

Nevertheless, richer internal governance information can change the quality of the conversation.

Instead of management merely presenting a revenue number and explaining the controls surrounding it, management may increasingly be able to demonstrate how reported revenue relates to broader operational reality.

That could include relationships between contracts, customer activity, fulfilment, invoices, receivables and cash.

The principle is simple:

The stronger the connection between reported numbers and observable economic activity, the stronger management’s own understanding of its reporting reality becomes.

That is valuable before an auditor ever enters the room.


19. From GRC software to Governance Intelligence

This is where the broader technology question becomes interesting.

GRC platforms have become sophisticated repositories of organisational governance.

They contain risks.

Controls.

Policies.

Control owners.

Test results.

Incidents.

Issues.

Remediation actions.

Audit findings.

Regulatory requirements.

That information describes an important part of Governance Design and Governance Execution.

But operational systems contain another enormous body of governance information.

ERP knows what was booked.

CRM knows what was sold.

Procurement knows what was ordered.

Production knows what was manufactured.

Service systems know what was installed or maintained.

HR knows which roles exist.

Identity systems know which accounts exercised particular access rights.

Banking data knows where cash moved.

The opportunity is not to replace the first group with the second.

It is to connect them.

A control in the GRC system says:

Purchase orders above threshold X require approval.

Operational evidence can establish how those purchase orders actually behaved.

A risk says:

Revenue may be recognised without sufficient economic substance.

Governance Reality can analyse the relationships between bookings, contracts, delivery, invoicing, receivables and cash.

A remediation action says:

Management has strengthened customer-order verification.

Continuous monitoring can subsequently ask:

Did the relevant behavioural pattern actually change?

That is the transition from documenting governance to learning from governance.


20. GRC should not become a bigger checklist

There is a tempting reaction to every corporate scandal.

Add another control.

Require another signature.

Introduce another reconciliation.

Create another policy.

Add another dashboard.

Sometimes that is exactly what is required.

But controls impose cost and complexity.

More importantly, controls can create the illusion that governance improves automatically as the number of control activities increases.

It does not.

A control should exist because it addresses a meaningful risk.

And when organisational data already contain evidence of how a process behaves, the better solution may sometimes be better visibility rather than another approval.

This is where GCN can enrich GRC.

Not:

more control.

But:

more understanding of what existing controls actually produce in organisational reality.

That is a fundamentally different proposition.

Read more cases for the GovernanceControlNavigator in our blog: GRC versus GCN: When the Four-Eyes Principle Exists but Nobody Is Really Looking.


21. Continuous monitoring should lead to continuous improvement

Suppose Governance Intelligence identifies that a particular sales process repeatedly produces bookings without the expected downstream evidence.

Management investigates.

The cause is not misconduct.

The CRM-to-ERP interface is poor.

Sales enters contracts using one customer identifier while Finance uses another. The automated relationship reconstruction therefore fails.

Management fixes the master-data process.

What happens next?

Traditional issue management might record:

Action completed. Issue closed.

Governance Intelligence can go one step further.

It continues observing the process.

Do customer relationships now connect correctly?

Has the apparent divergence disappeared?

Are manual corrections declining?

Has the downstream conversion pattern normalised?

If yes, the organisation has evidence that the improvement worked.

If not, the problem has not really been solved.

This produces a much stronger governance cycle:

Signal → Understand → Improve → Authorise → Measure → Learn

Governance becomes less about closing findings and more about demonstrating that organisational reality actually improved.

Read more on a case on the largets bank in the USA: JPMorgan and Weak Internal Controls: When Governance Design Is Not Enough.


22. The board does not need another dashboard

Boards already receive enormous amounts of information.

Risk dashboards.

Compliance dashboards.

Internal Audit reports.

Financial reports.

Cybersecurity dashboards.

ESG metrics.

Operational KPIs.

Adding another screen containing hundreds of anomaly indicators would probably make governance worse rather than better.

The board needs synthesis.

For a material governance divergence, the relevant information might be remarkably compact:

What did we expect?

What actually happened?

How material is the difference?

What evidence supports that conclusion?

Has management investigated it?

What was the explanation?

What improvement has been authorised?

Did the improvement work?

That is governance information.

The board does not need to become a forensic data-analysis department.

It needs sufficient evidence to challenge management intelligently.

Read more in our blog: Weak Internal Controls or Weak Governance Intelligence?


23. The real lesson from WANdisco

The WANdisco case eventually resulted in dramatic corrections to the picture previously presented by the company. The March 2023 announcement said that reported bookings and expected revenue had been materially overstated and that the discovery had significant implications for cash and the company’s financial position.

The lesson should not be reduced to:

Watch your salespeople more carefully.

Nor:

Revenue controls need to be stronger.

Those may be reasonable conclusions in particular circumstances, but they are too narrow for the wider governance question.

The more important lesson is that corporate reality exists across organisational boundaries.

Sales sees one part.sales fraud internal controls

Operations another.

Finance another.

Cash another.

GRC another.

Internal Audit another.

Each may contain perfectly legitimate evidence.

But governance ultimately needs to understand whether those pieces still describe the same enterprise.

That is why the WANdisco case is so useful when thinking about the evolution of GRC.

Traditional GRC asks an indispensable question:

Do governance controls appear to be operating as designed?

Governance Intelligence adds another:

Is organisational reality still aligned with that governance design?

And in a sales environment, that question can become remarkably practical:

If the commercial success we are reporting is real, where else in our organisation should we be able to see its footprint?

If the answer is visible across customers, contracts, delivery, invoicing, receivables and cash, that provides additional confidence.

If the expected footprint is missing, that does not prove wrongdoing.

It provides evidence to investigate the divergence.

And that may be the most important distinction of all.

GCN does not need to tell management that someone committed fraud.

It needs to make the discrepancy sufficiently transparent that management can ask the right question, inspect the underlying evidence and determine the explanation.

That is not a replacement for Governance, Risk & Compliance.

It is what becomes possible when GRC is connected to Governance Reality.

And it changes the final board question from:

“Have our controls been performed?”

to the more demanding question:

“Does the evidence across our organisation still support the reality we believe we are governing?”

sales fraud internal controls