Pick up any forty-page control standard and read it as a detective would. Not for what it says — for what it's covering up.
The tell is always the same. Page 3 states the control plainly enough. Then come the exceptions. The carve-out for legacy systems that risk insisted on. The alternative process for the trading floor, negotiated after they escalated. The "risk-based approach" paragraph that means the second line and engineering never agreed on scope, so someone wrote a sentence vague enough for both to sign. Three appendices of edge cases, each one the fossil of an argument that ended in a workshop instead of a decision.
That's what the forty pages are. Not rigour — sediment. Every unresolved disagreement in the organisation, laminated and given a version number. The document is long precisely because nobody with authority ever said what the control was for and made it stick. Length is the confession.
Nobody works around a control they understand
Here's why this matters beyond tidiness. Controls don't fail in audits. They fail on a Tuesday afternoon, when someone with a deadline meets a requirement they can't see the point of.
A person who understands what a control protects will usually cooperate with it, even when it's inconvenient — people are not stupid, and nobody wants to be the cause of the breach. A person facing forty pages of qualified, contradictory prose doesn't get the chance to understand it. They ask a colleague, the colleague shrugs, and together they find the path of least resistance. The workaround isn't rebellion. It's the only rational response to an instruction nobody can parse.
A control your people can't explain isn't a control. It's a queue of workarounds that haven't happened yet.
So the forty-page document doesn't just record the organisation's confusion. It manufactures more of it, daily, at the exact moments the control was supposed to work.
The fix is a decision, not an edit
The tempting response is editorial: hire a technical writer, tighten the prose, get it down to twenty pages. Wrong tool. The problem was never the writing. The problem is that a decision was skipped, and the document grew to fill the space where the decision should have been.
The fix is to make the decision. Ask the control's owner to complete one sentence: this control exists so that ___. No sub-clauses, no "and also", no mention of the regulator — regulations are why you must have a control, never what it's for. If the owner can't produce the sentence, you've found the real finding, and it isn't a documentation gap. If two stakeholders produce different sentences, you've found the argument the forty pages were burying. Have it now, with someone empowered to end it, instead of relitigating it in every review cycle.
Then write down only what the sentence requires. Usually that's two or three pages: the point of the control, who does what, and what to do when it doesn't fit. The exceptions that survive are the ones the purpose justifies — the rest were never exceptions, just appeasements.
We watched this play out at a mid-sized regulated firm — details blurred, pattern intact. Their access-review standard ran to thirty-eight pages and three process variants, and reviews were completed late, by bulk approval, every quarter. Managers were rubber-stamping because the document never told them what a review was for. The rewrite began with one sentence: "this control exists so that when someone changes role, their old access dies." Four pages. The variants collapsed, because once the purpose was stated, two of the three processes were visibly theatre. Completion stopped being the metric; revoked access became the metric. The reviews started catching things.
Nothing about the control got weaker. It got shorter, which meant it finally got done.
That's the pattern, and it generalises. Short documents are not a style preference. They are proof that somebody decided something — and a decision, unlike an appendix, is a thing people can follow at speed, under pressure, without asking permission to understand it.
Next time a forty-page standard crosses your desk, don't ask who should update it. Ask what it's hiding.
The length of a control document measures the distance between your organisation and a decision it hasn't made yet.
