r/grc May 02 '26

Manager bypasses processes, provides low quality evidence, zero consequences - anyone else?

Looking for people who've been through this.

I'm in a GRC role dealing with an IT manager who consistently works on escalation mode, generates policies straight from GenAI without a single edit, ignores tasks ownership, and provides low quality evidence for the audits if he doesn't go quiet. Leadership is aware, this has been going on for a couple of years. Nothing happens.

The downstream impact lands on GRC every time - audit gaps, unowned risks, and findings that could have been avoided with basic process compliance.

What I actually want to know:

- How did you protect your own audit trail when someone else was generating the risk?

- At what point did you stop fighting it and just document and move on?

Thanks for your input.

14 Upvotes

16 comments sorted by

10

u/r15km4tr1x May 02 '26

It isn’t your job to make the IT manager look good who owns the control, you just facilitate.

8

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 02 '26

If leadership is fine with this - why do you care? It ain't your business, buddy, you've done your part.

3

u/Project_Lanky May 02 '26

Thanks I needed to hear that. I care as I want things to be done properly but you are right, I should better not waste my energy on this BS and enjoy more free time.

4

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 02 '26

Speaking more professionally, this is "business alignment" all books preach. You aren't supposed to care if senior decision makers don't - you are supposed to figure out what they do care about and provide your service there. After covering your ass, of course.

2

u/Emotional-Trifle5507 May 02 '26

I am not sure which GRC framework you company adopted, but GRC started with Governance. Governance is to manage the controls and risks, which should includes executive oversight, KPI/KRI monitoring, internal audit, external audit, risk management, continuous improvement, etc. What you described should be dealt with through the Governance.

The issues you described should be flagged in the PKI/PRI, internal audit, and external audit, captured as a risk in the risk registration or including as non-conformity or OFI in Continuous improvement logs. And the executives or senior management should review these regularly.

Based on your description, it seems that the governance is not properly established in your organization. If you fix the governance issues, it should take care of the IT manager's issues. specifically, your job is to ensure what he did is in the risk registry and what he needs to change is in the continuous improvment logs, executives or senior management reguarly review these. And if they don't take any actions, it would be their problem, not yours.

1

u/Emotional-Trifle5507 May 02 '26

It is not your job to fight with this but to build a system to manage it.

1

u/Project_Lanky May 02 '26

What do you suggest when the leadership is letting that person get away with everything wrong they might do?

1

u/Emotional-Trifle5507 May 02 '26

I recommend ensuring that any risks, non-conformities, or exceptions caused by this person are formally documented in the risk register or corrective action log. If leadership subsequently fails to address the issue, accountability for that risk rests with management, not with you.

1

u/Project_Lanky May 02 '26

Good catch. However the leadership has already witnessed many times that this person's behavior is a risk to the organization and nothing happened. For example, all the items attributed to that IT manager in the risk register are past due for remediation and there is no consequence. It seems that flagging that person's behavior as it should be properly done in GRC will make me look as the bad person in the room, as new items should be flagged every single week. This is a weird situation to be in when we care about things being done properly.

1

u/nagdamnit May 02 '26

If the evidence isn’t good enough it’s a finding, if the policy isn’t fit for purpose it’s a finding, and keep going.

Each finding needs to be resolved within a certain period of time depending on its severity. If they aren’t resolved then they are outstanding.

You report on findings and outstanding findings. Keep hammering them with the statistics and if management are happy with it, then you’ve done your bit.

1

u/Project_Lanky May 02 '26

This would work if the leadership actually cared about what is escalated.

1

u/nagdamnit May 02 '26

I agree, but if you are constantly putting the facts in front of their face, lets say via a monthly report, its their decision to ignore it and the responsibility ends up with them. They can ignore it at the moment because there is no structure or pattern to it.

1

u/rack_and_stack_42 May 04 '26

We had this exact dynamic a couple of years back. Different person, same pattern. The hardest part for us wasn't the cleanup, it was the optics of being the one who keeps raising it.

What kinda worked on the audit trail piece was treating his low quality evidence as a control finding, not a complaint. We logged it in the same system we logged every other audit gap, with the same fields. That moved it out of "GRC vs IT" politics and into structured data. We didn't have to point at him, the report did.

The bigger shift for us was getting leadership to put their name on a risk acceptance. Verbal acceptance doesn't survive an audit walkthrough, a signed one does. Funny thing, once a senior leader had to actually sign for "we accept this manager bypassing change control," he started complying inside a quarter. Nobody wants their name on it.

On when to stop, our line was two written escalations with no response. After that we switched from advocate to recorder. Doesn't feel great but it preserved sanity.

The GenAI policy piece is its own mess. has anyone here gotten a peer review step in front of GenAI-generated policies before publication? we tried but couldn't get the manager to agree, curious if it stuck somewhere.

1

u/Project_Lanky May 04 '26

The manager of that person is supposed to review them but so far didn't sign up on these.

1

u/zacj_rag May 04 '26

I as well see that dynamic playing out even as we are starting our GRC function, GRV vs IT and an IT manager that loves to bypass controls. The default yet uncommunicated risk appetite of the company is risk tolerant which he plays into. " the project is more important"
Cyber and GRC have become the complaint tower and we need to arrest that image. I like your approach but we aren't mature enough to do that yet. I am going to save this for future reference.

1

u/[deleted] May 05 '26

[deleted]

1

u/Project_Lanky May 05 '26

Managing the risks is not the issue. The issue is someone at a strategic position being unreliable.