In corporate life, this presents a serious operational risk. The “Telephone effect” is rarely more pronounced, or more impactful, than in the governance, risk, and compliance space.
Data protection and information security specialists gather intelligence about organisational risk continuously. Yet, by the time that information reaches senior leadership or the board, it has been so thoroughly filtered, sanitised, and subjected to corporate Darwinism that it often bears little resemblance to reality.
We’ve all seen it in practice, so why is this pattern so difficult to break?
Compliance distortion
The journey from operational intelligence to board-level reporting suffers from at least three distinct types of distortion:
- Fear of bad news: We are disincentivised from escalating unvarnished risk. Technical findings like “Our databases lack basic access controls” become “We are evaluating access management enhancements” in the monthly report. By the time senior leadership receive it, it reads: “Identity governance remains a strategic priority.” The urgent threat has been tempered into a bland statement without priority or impact.
- Jargon: Compliance teams speak in legal frameworks, technical standards, and controls. Executives speak in outcomes, capital allocation, and reputation. When we bridge this gap without proper translation, the core message can get buried in jargon. Leadership doesn’t understand, missing the critical exposure completely.
- Ticking the box: Standardised reporting templates often promote metrics that look good on paper over metrics that measure actual security posture. A dashboard showing 98% e-learning completion creates a false sense of security, maybe burying the fact that critical third-party data processing agreements remain unaddressed for the third quarter in a row.
The cost of diluted risk intelligence
When senior leadership receives sanitised or misconstrued risk data, two things happen - neither good:
- Decisions are made on fiction: Boards allocate budget to high-visibility, low-impact initiatives because those were the ones presented in polished slide decks, while glaring vulnerabilities remain unfunded.
- Accountability disappears: When the incident inevitably occurs (such as a data breach, a regulatory fine, or a service failure) leadership expresses genuine surprise. Technical teams insist they reported the risk months ago, while executives point out that the report claimed the risk was “being proactively managed.”
Both sides are telling the truth, but the “Telephone effect” has impacted the translation.
Stop playing Telephone
Meaningful reporting requires more from everyone involved than just better standard reports and slides:
- Be direct and jargon-free: Translate complex technical and regulatory requirements into clear business impacts without diluting the urgency.
- Show unbiased risk quantification: Evaluate your operational controls objectively, avoid internal corporate politics and the desire to make status dashboards look green.
- Actionable governance frameworks: Make the conscious move away from passive monitoring; establish and promote clear pathways for rapid executive decision-making.
- A “no blame” culture: The message isn’t always perfection. Senior leadership must nurture an environment where bad news can be heard and treated fairly.
Bridging the gap
Identifying risks is only the first step; ensuring risks are communicated clearly enough to drive decisive action is where many compliance programs lose traction.
Whether navigating shifting regulatory expectations, untangling complex data flows, or struggling to present an unvarnished picture of your security posture, clear and honest communication is the strongest and most ethical approach.