Compliance Investment ROI

A client built the same data inventory twice in 18 months. The first one was for the auditor.
Version one was a spreadsheet. Someone spent 6 weeks interviewing teams and filling cells, and it passed. Then it sat in a folder while the systems around it kept changing.
A year later an incident hit and somebody asked which services touched customer data. Nobody trusted the file enough to answer from it. So they built it again, this time as a catalog the pipelines write to themselves. The second build cost more, because it was urgent and the budget had already gone once.
NIS2 and DORA are walking a lot of smaller EU teams into that same sequence. The deadline is real, the shortest path to passing is a document, and a document is a snapshot of a system that keeps moving.
The question I now ask about every item on a compliance list: what reads this when there’s no auditor in the building? A catalog the deploy checks. An owner field something queries. Incident timestamps your on-call already opens at 3am. If nothing consumes it, it starts going stale the day it’s signed off.
Some items genuinely are paperwork, and those you do cheaply. In most of the lists I’ve seen, they’re the minority.
Which part of your last compliance push would still answer a question tonight?
Fractional Data Architect helping startups and scaleups build data platforms that scale.
More about Thomas Nys →