Compliance Should Protect the Public- Not Become the Work Itself

I have spent more than two decades in New York City government, and much of that career has involved compliance, whether or not the word appeared in my job title.
I have worked in capital budgeting, technology budgeting, procurement, contracts, and financial administration. Today, much of my work involves technology procurement and budget management.
That means rules are not an abstraction to me.
They are part of almost every workday.
Before public money gets spent, somebody has to determine whether funding is available, whether the expenditure is appropriate, which procurement method applies, whether competition is required, whether pricing is reasonable, whether the contract vehicle actually covers the requirement, whether the documentation supports the decision, and whether the transaction can survive review afterward.
I believe strongly in those controls.
But after doing this work for a long time, I have also developed a strong belief in something else:
Compliance should protect the public. It should not become the work itself.
I Have Never Viewed Compliance as Checking Boxes
When I receive a procurement requirement, I don't start with a desire to generate paperwork, yet somehow that paperwork finds me!
I begin by trying to understand what someone actually needs.
What are we buying?
Why do we need it?
When do we need it?
What does it cost?
What options are available?
What rules apply? NYC Comptroller Directive 10? Directive 30? NYC Procurement Policy Board Rules (a given!) Don't forget Appendix A - a summary of all the rules governing a procurement for the City of New York that vendors must follow, and the End User License Agreement? Cloud Service Agreement? Are we up to Attachment or Appendix Z yet?
What is the most appropriate path?
Those questions sound simple, but in public procurement the answers can send a transaction in very different directions.
No single universal checklist works for every purchase.
That is why I have never viewed compliance as merely completing forms.
The forms come later.
The more important work is reasoning through the transaction.
A procurement can contain every required attachment and still represent a poor decision.
Conversely, a strong procurement begins with a defensible answer to a much more fundamental question:
Why are we doing this this way?
That is the question I want someone to be able to answer years later if the file is ever reviewed.
My Career Has Taught Me to Ask “Why?”
Earlier in my career, I worked on capital budgets and technology budgets at the New York City Department of Health and Mental Hygiene.
That experience taught me that government decisions rarely exist in only one dimension.
A program may have a legitimate operational need.
Budget staff still need to determine whether money is available.
Capital staff may need to determine whether the expenditure qualifies for capital funding.
Procurement staff needs to determine how it can legally be purchased.
Legal staff may identify contractual concerns.
Technology staff may identify security or architectural issues.
Oversight agencies may have additional questions.
Everyone can be doing his or her job correctly, and the overall process can still become extremely complicated.
Over the years, my instinct has been to keep returning to the underlying purpose.
What are we protecting?
What risk are we managing?
What decision are we actually trying to make?
Those questions help distinguish legitimate compliance from accumulated process.
Rules Matter- But Judgment Matters Too
One misconception about compliance-heavy jobs is that employees simply follow predetermined rules.
That has never reflected my experience.
Rules create boundaries.
Professional judgment operates within them. Just today, one judgment question was, "Can we forgo proving liens were satisfied?" The company in question was larger, and it's bound to incur a lien here and there.
In procurement, for example, I may have several permissible approaches to a requirement.
The compliance question is whether an option is allowable.
The management question is which allowable option makes the most sense.
Those are different questions.
Suppose several purchasing mechanisms could potentially satisfy the same requirement.
One may offer broader competition.
Another may move faster.
Another may offer stronger contractual terms.
Another may provide better pricing.
Another may have significant administrative requirements that make it less practical for the specific purchase.
Compliance does not always tell me which one to choose.
Experience and judgment do.
That is why I resist the idea that government administration can simply be reduced to a series of checkboxes.
The rules matter.
So does reasoning.
The Price Is Part of Compliance Too
One area where my perspective has probably been shaped most strongly by experience is pricing.
Government can follow the correct procurement procedure and still pay too much.
I don't consider that a successful outcome.
Over the years, I have spent a great deal of time looking at quotes, contract pricing, renewals, competing products, service levels, and alternative purchasing options.
Sometimes the most important compliance question isn't whether the right form has been completed.
It is much more basic:
Is this a reasonable use of taxpayer money?
That can mean challenging a price.
It can mean asking for additional competition.
It can mean looking for another contract vehicle.
It can mean asking why a renewal changed.
It can mean questioning whether the organization still needs everything it is paying for.
None of that is inconsistent with compliance.
To me, it is part of compliance.
Protecting the taxpayer should not end once the procedural boxes have been checked.
I Like Documentation- Up to a Point
I have produced enough government documentation over my career to fill more filing cabinets than I care to imagine, although today most of those filing cabinets are electronic.
Government loves documentation.
I understand why.
If public money is being spent, there should be a record.
If a decision is challenged, somebody should be able to reconstruct what happened.
If an auditor reviews a transaction years later, the reasoning shouldn't depend entirely on whether the original employee still works there.
Those are legitimate objectives.
But documentation has a point of diminishing returns.
I have always been much more attracted to the philosophy behind Nike's famous slogan:
Just do it.
Not recklessly.
Not without controls.
Not without documentation.
But once we understand the issue, evaluate the alternatives, satisfy the legitimate requirements, and reach a defensible decision, the government eventually has to act.
A perfectly documented procurement that arrives after the operational need has passed is not a success.
One of the Best Compliance Lessons I Ever Received Was Simple
A former supervisor once gave me advice that has remained with me throughout my career.
I am paraphrasing, but the principle was essentially:
Assume every decision you make could appear in the New York Post tomorrow. Would you be comfortable explaining it?
That may be one of the simplest compliance tests I have ever encountered.
Would I be comfortable explaining why I selected this vendor?
Why was this amount paid?
Why competition was or was not conducted?
Why an exception was made?
Why I recommended one course of action over another?
The test does not mean everyone must agree with the decision.
Reasonable people can disagree.
It means I should be able to explain the facts, the reasoning, and the public purpose behind it without embarrassment.
That standard has always meant more to me than simply being able to say:
“The form was completed.”
Compliance Should Make Errors Harder to Commit
My work in technology also makes me increasingly impatient with controls that depend unnecessarily on human memory.
If a contract has an expiration date, a system should remind us.
If an invoice exceeds an authorized amount, technology should flag it.
If information already exists in one authoritative system, employees should not have to type it into several others.
If a purchasing option is not available under a particular set of circumstances, the system should help identify that before someone spends hours traveling down the wrong path.
For years, government has often digitized paperwork without fundamentally redesigning it.
We took the paper form and made it a PDF.
Then we built a system where the PDF could be uploaded.
Sometimes someone else downloads the PDF and enters the information somewhere else.
Technically, we modernized.
Operationally, we may have accomplished very little.
The next generation of compliance technology should be different.
Controls should increasingly be built into the process itself.
AI Could Make Compliance More Intelligent
This is one area where I believe artificial intelligence could genuinely change government administration.
Procurement rules are complicated because the correct path depends upon the facts of each transaction.
Historically, software workflows needed humans to answer every decision point.
Is this above a particular threshold?
Is there an existing contract?
Does that contract cover the requirement?
Is competition necessary?
Are additional approvals triggered?
The workflow could route the transaction only after the employee supplied the answers.
AI may increasingly help employees reason through those questions.
Not by replacing professional judgment, but by helping identify applicable requirements, missing information, and potential alternatives.
That could be transformative.
Imagine compliance that helps an employee get something right at the beginning instead of identifying everything that was wrong at the end.
That is the model I want.
I Have Learned Not to Fear the Question
After many years in government, one of the biggest differences experience makes is that you become less defensive about questions.
Why did you choose this approach?
Why does this cost so much?
Why isn't there more competition?
Why wasn't this done differently?
Those questions can feel adversarial when you are new.
I increasingly view them as useful.
If I cannot answer them, perhaps I need to rethink the decision.
The best compliance culture is not one where employees are afraid to make decisions.
It is one where employees expect to explain them.
There is an enormous difference.
Fear produces paperwork.
Accountability produces reasoning.
Compliance Is Ultimately About Trust
The longer I work in government, the more I believe compliance is fundamentally about maintaining public trust.
Taxpayers should be able to trust that we are careful with their money.
Businesses should trust that public procurement provides a fair opportunity to compete.
Employees should understand the boundaries within which they can operate.
Auditors should be able to determine why decisions were made.
Managers should be able to accomplish the mission without treating every routine action as an administrative emergency.
Getting that balance right is difficult.
I have spent much of my career operating inside it.
And the conclusion I have reached is fairly simple:
A good compliance system should help good employees make good decisions.
Every control should protect something worth protecting.
Every approval should have a purpose.
Every document should contribute something.
Use technology when technology can enforce the rule more consistently.
Apply greater scrutiny where the risk is greater.
Ask questions.
Document the reasoning.
Challenge the price.
Protect competition.
And when the requirements have been satisfied and the decision can be publicly defended, move.
Because government does not ultimately exist to produce a perfect file.
It exists to serve the public—and compliance should help us do that better.