Skip to content
← All articles

Operating GRC at AI Speed · Episode 5

April 26, 2026

Policies should follow controls, not the other way around

By Ben Draffin · Director of Security at Decagon

Most governance writing describes a single direction: policy defines what should be true, standards narrow it, procedures operationalize it, and controls prove it. That’s clean and useful, but for companies shipping AI products on weekly cadences, it’s only half of what’s actually happening.

In practice, the controls I work on often emerge from product reality first: a retention rule in infrastructure, a redaction path in the inference stack, an authorization check added after a pen test. Policy catches up later. The reverse happens too: policy exists, implementation lags behind. Both directions run at once. The useful question isn’t which direction is right; it’s which direction is dominant in your organization right now, and how to set up a healthy loop between them.

Policy and controls are where governance, engineering, and enterprise sales all meet. From what I’ve seen across AI-native security programs, the teams that close enterprise deals reliably are the ones running both directions on purpose, not a one-way cascade from policy to code.

Top-down dominant: strong narrative, thin evidence

Symptoms. The policy library is current. Control evidence is stale or scattered. Enterprise buyers and auditors get confident narratives that wobble when someone asks to see enforcement in production.

Where the gap shows up. Document reviews pass; implementation reviews surface gaps. The story on paper is ahead of the story in production.

Direction of travel. Policy → intended control → implementation (often delayed).

What helps. Coding-agent or scanner-assisted inventories, continuous evidence collection, and policy language that tracks what actually shipped, not what the team hopes will ship next quarter.

Bottom-up dominant: strong systems, weak external story

Symptoms. Technical controls are real. Policy coverage is thin or inconsistent. Different teams answer questionnaires differently. Institutional memory lives in Slack threads and merged PRs.

Where the gap shows up. The organization is often safer than it can prove. Deals stall when trust collateral doesn’t match what’s already running in production. The fix here is presentation, not engineering.

Direction of travel. Implementation → implicit control → policy (catches up).

What helps. Scheduled reconciliation against technical inventories, and a single owner for what the company claims externally.

The two-way loop: what “mature” looks like

Mature AI-native GRC doesn’t pick a single arrow. It runs a loop:

  1. Product and engineering reality changes.
  2. Technical control inventory updates (ideally agent- or scanner-assisted).
  3. Policy, standards, and external claims update to match what’s actually true, or narrow until they do.
  4. New requirements arrive from sales, audits, and vendors.
  5. Engineering closes the next gap, and the loop turns again.

Update policy based on controls when implementation leads. Update controls based on policy when commitments lead: new certification scope, new enterprise clause, new regulatory obligation.

The mature pattern is running both directions on purpose, on a cadence, instead of waiting for one direction to catch up to the other on its own.

The table below is a quick diagnostic.

Signal Likely dominant mode First fix
Policies refreshed annually; product ships weekly Top-down on paper, bottom-up in reality Inventory + reconcile
Questionnaire answers differ by team Bottom-up Single external claims owner
Audit findings cite “not operating effectively” Top-down narrative gap Evidence paths per control
Security review surprises despite “good” policies Bottom-up implementation without external sync Trust collateral refresh

A one-hour workshop exercise

You don’t need a transformation program to learn which mode you’re in.

  1. Pick five controls your largest customers asked about last quarter.
  2. For each, document where it lives in code or infrastructure, where it lives in policy, and how it appears in questionnaire answers.
  3. Mark whether implementation or policy came first.
  4. Agree on one reconciliation action per control.

Most AI-native companies are bottom-up before they intentionally install the loop. That isn’t a failure. It’s a normal stage of growth, and a strong starting position. The goal is to install the loop on your own schedule, not the one a customer audit hands you.

How this series fits together

Traditional GRC assumed controls and policies moved at human pace. AI-native companies move faster than that, and the operating model is changing in our favor. Redlines track maturity. Vendor contracts give you a free roadmap. Coding agents keep an inventory of reality. AI-assisted prep stress-tests narratives before auditors do. The two-way loop ties those pieces together.

Operating GRC at AI speed isn’t about doing old process faster. It’s about running governance that matches how AI products and enterprise buyers actually move, so policy and production describe the same company.


Previous: Audit prep in the age of AI · Series index

Series

Newsletter

Email when I publish.

You'll get a confirmation email first.

Share on LinkedIn · Pushback? LinkedIn is fine.