Why Asking the Right Questions Matters More Than Expanding Compliance Frameworks
The compliance programs that hold up aren't the largest ones. They're built on a short list of answerable questions.

Key points
- The strongest compliance programs run on a short list of answerable questions, not broad frameworks.
- Framework size correlates poorly with compliance effectiveness.
- Questions outlast model changes; rigid frameworks often don't.
Does size matter in compliance programs?
Bigger compliance programs are not better ones. The programs that hold up are built on a short list of questions that can actually be answered and stay true when circumstances shift. That's a harder discipline than assembling an impressive framework, and it's the one that matters.
We covered the same tension on 6 July 2026 in "Seven Cyber Risk Assessment Mistakes That Give Security Leaders False Confidence": organisations that confuse passing an audit with being secure tend to over-invest in framework size and under-invest in the questions the framework was meant to answer.
Why are questions more effective than frameworks?
A framework documents what you intend to protect. A question forces you to prove it. Compliance that reduces to box-ticking fails the moment the model changes, because the boxes were written for a model that no longer exists. Questions, if they're the right ones, survive that change.
Practically, this means an organisation needs to start by identifying what it is actually protecting, then work backwards to the smallest set of questions that tests those protections directly. The answer to each question should be a concrete action, not a policy reference.
| Compliance element | Approach | Outcome |
|---|---|---|
| Program size | Small, focused | Fewer gaps, less overhead |
| Frameworks | Essential questions only | Survives model changes |
| Review cycle | Tied to model changes | Continued relevance |
How can organizations build effective compliance programs?
Start with what you're protecting, not with a control catalogue. Write questions against those assets. If a question can't be answered with a clear action, rewrite it or drop it. Review the list when the business model changes, when regulators update their expectations, or when a significant incident reveals a gap the questions didn't catch.
The FedRAMP overhaul we reported on 23 July 2026 is a live example of this logic applied at scale: the annual PDF audit is being replaced with continuous, evidence-based controls, which is effectively a shift from framework volume to answerable, ongoing questions.
The judgement here: most organisations already know their compliance programs are too large. The harder step is cutting them down, because cutting requires accepting that some controls you paid to implement don't actually answer a question worth asking.
Common questions
What makes a compliance question effective?
An effective compliance question targets a specific protection, can be answered with a concrete action, and remains valid when the underlying model changes.
How often should compliance questions be reviewed?
Review them when the business model shifts, when regulation changes, or when an incident exposes a gap. A fixed annual calendar is itself a framework habit worth dropping.



