It Gets Cleaner On The Way Up


A project team gets to a go-live meeting. Sign-off is on the agenda.

The supplier has already been told the enterprise controls aren’t sufficient. But there’s a payment milestone attached to that go-live, and the meeting isn’t really about whether it’s safe to proceed. It’s about whether it can be made to look safe enough to sign.

Nobody has to lie for that to happen. The scope just gets redrawn. The original assessment looked at enterprise-level controls, the ones that govern the whole environment the platform would sit inside. Those didn’t hold up. So the assessment quietly narrowed to the platform’s own controls, the ones built into the product itself, and those checked out fine. Same deployment, same underlying exposure, smaller assessment frame. What reached the decision-makers was technically accurate and materially misleading at the same time.

It reaches leadership as all good.

I didn’t see that meeting happen. I saw what came after it. Brought in later on a separate governance review, I was comparing what had been signed off against what was actually running, and the two didn’t match. The go-live assessment described a controlled platform. The environment around it told a different story. The enterprise controls that had been dropped from the original scope weren’t a paperwork gap. They were the controls that would have caught the way the platform was actually exposed once it was live.

By then it was in production. So it had to be reengineered in place, with the system already running and real data flowing through it, under time pressure that only existed because the milestone had been hit first. Everything that would have been a design decision before go-live became a retrofit after it. Slower, more expensive, and riskier than doing it once, properly, when someone still had the chance to say the controls weren’t ready. That chance existed. It was in that meeting. It just wasn’t taken, because taking it would have moved the payment.

Whether or not anyone set out to mislead, the commercial incentive and the narrowed scope produced the same result. The decision-makers got a technically accurate assessment that left out the controls most relevant to the real exposure.


Carillion was a vastly bigger failure. But the underlying governance problem was uncomfortably similar. In January and February 2026, the FCA fined former Carillion executives Richard Howson, Richard Adam and Zafar Khan a combined £609,400 over misleading market statements and failures to disclose serious financial problems. All three initially challenged the FCA’s findings and later withdrew those challenges.

By July 2017, Carillion announced an £845 million provision against its construction contracts after repeatedly telling the market it was meeting expectations. The problems behind that provision had not been apparent from any of the earlier updates. The shares fell almost 40% that day and kept falling sharply afterwards. Six months later, Carillion was in liquidation.

The most useful part of the FCA’s finding, from a governance point of view, isn’t about invented numbers. It’s about information that was known but didn’t travel. Serious problems and accounting judgments were known within the construction business, about how much revenue to recognise and how much risk to carry on troubled contracts. They were not adequately reflected in the information reaching the market, the Board or the Audit Committee. What travelled upwards was a more reassuring picture than the underlying position justified. The structure existed to move that information. It didn’t do it effectively.

That’s the part worth sitting with, because it’s not really a story about three men. On paper, the architecture of governance was there: a Board, an Audit Committee, reporting lines, financial controls and the machinery of a listed company.

None of it moved the information.


Leadership rarely sees what’s happening in the business directly. It sees what’s been written down, escalated, and put in front of it. Those are three separate steps, and each one is a place where an accurate picture can quietly become a defensible one.

Watch how it happens. A frontline team flags something as a real problem. The layer above writes it down, but softens the wording, because the raw version sounds alarmist and they think it’s probably being handled. The layer above that aggregates it into a status report, where one specific red issue becomes part of a general amber. The layer above that reads amber as “in hand” and doesn’t ask. By the time it reaches the top, the item is a line in a summary that says work is progressing. Nobody lied. Every step was defensible on its own terms. The problem is that the sum of a lot of small, defensible softenings is a version of reality that no longer describes the business. It just describes what everyone was comfortable sending up.

This same pattern shows up anywhere leadership depends on someone else’s summary to know what’s true.

A cyber team can report patching percentages and exception counts that are all individually accurate, while the one exception that matters most sits three reports back, reclassified as low priority months ago. Then, if it becomes the way in, the first leadership hears of it is the incident, not the exception that predicted the exposure.

An AI governance committee can have a policy, a register and an approval process, and still have no idea what’s actually been deployed through a SaaS tool nobody logged. The governance exists. The visibility doesn’t.

A data protection function can report DSAR volumes and completed DPIAs while repeated mishandling in one business process stays invisible, because each case is closed on its own and nobody aggregates the pattern. The metrics look healthy right up until the breach that was implicit in them the whole time.

None of it requires dishonesty. It just requires that nobody in the chain decides the uncomfortable version is worth the friction of sending it up.


So here’s a test, if you want to run it on something real. Pick one risk your leadership team currently believes is under control. Start with the paper that reaches them. Then find what the person who wrote it was actually given. Go down another layer to what the responsible function reported at working level. Then get to the people closest to the problem, the ones with no paper to write at all, and see what they know.

If the picture gets worse the closer you get to the work, you don’t have a reporting problem. You have a leadership team governing a version of the business that stopped existing a few layers down.

Pick one risk. Pull the thread.

Who actually owns this in your org?


References

Primary (FCA)

  1. FCA Final Notice: Carillion plc (in liquidation), 16 February 2026 — fca.org.uk/publication/final-notices/carillion-plc-in-liquidation-2026.pdf
    The core document. Contains the findings on procedures, systems and controls.
  2. FCA press release: “FCA fines former chief executive of Carillion plc (in liquidation)”, 16 February 2026 — fca.org.uk/news/press-releases/fca-fines-former-chief-executive-carillion-plc-liquidation
    Howson’s £237,700 fine, plus the Adam/Khan figures and the Steve Smart statement.
  3. FCA Final Notice: Richard Howson, 16 February 2026 (linked from the above press release)
  4. FCA press release and Final Notices: Richard Adam and Zafar Khan, January 2026 — £232,800 and £138,900 respectively
  5. FCA Primary Market Bulletin 62, April 2026 — fca.org.uk/publications/newsletters/primary-market-bulletin-62
    The most useful single source for the governance angle. Sets out the breaches and the procedural history.

Institutional secondary

  1. House of Commons Library: “Carillion collapse: what went wrong?”commonslibrary.parliament.uk/carillion-collapse-what-went-wrong/
    Named institutional source for the share price and the £845m provision.
  2. National Audit Office — the £148m estimated taxpayer cost, and the 450+ public contracts. Referenced via the Corporate Governance Institute piece below; worth pulling the NAO report directly if you cite the figure.

Contextual

  1. Corporate Governance Institute / Dan Byrne, “Carillion collapse: What failures led to FCA fines?”, March 2026 — governance-lens commentary, republished at int-comp.org
  2. Farrer & Co, March 2026 FCA enforcement update — confirms all three withdrew challenges; notes the £38m Carillion would have been fined but for liquidation

Discover more from Acceptable Risk (Documented)

Subscribe now to keep reading and get access to the full archive.

Continue reading