Baarool — Oversight research
Has a measure ever changed a decision before the thing it measured became a problem?
Most organisations cannot name a single instance in two years. Not because the signals were absent, but because the information that reaches the people who decide is structurally incapable of surprising them.
The distinction
Position, not quality
The argument about cyber and risk reporting is almost always about whether the measures are good — leading or lagging, the right indicators, a better dashboard. That argument is about quality. The problem is position.
Output
Produced, selected, aggregated and framed for consumption. It has passed through the people whose performance it reflects. It arrives as a finished account of a settled state. It can reassure, demonstrate diligence, and satisfy a regulator. It cannot change a decision, because the decisions it bears on have already been made.
Input
Arrives while the decision is still open, with a threshold attached, in a form that makes clear what would change if the number moved. Often crude. Frequently external, because a signal generated outside the organisation has not been filtered by anyone whose performance it reflects.
Why it persists
This is not a broken system. It is a stable one.
An executive who surfaces a developing concern early, while it is still ambiguous, takes a career risk for an uncertain benefit. A board's quarterly rhythm cannot carry information at the speed the risk moves. And when the failure finally comes, the question did we know? has two possible answers — that the organisation could not see, or that the board was managed rather than informed — and no way to choose between them from the boardroom.
Every participant has a local reason to maintain the arrangement. That is why it survives each new framework, each new tool, and each newly appointed expert director. You cannot fix an equilibrium by improving the inputs to it.
Four jurisdictions are currently attempting to legislate these conditions into existence. NIS2 and DORA place ICT risk on the management body and attach personal consequences to neglecting it. The SEC forces a materiality determination on a clock. The Delaware oversight line turns on whether a board had an information system that would surface the problem at all. These are cadence and inescapability interventions in everything but name — and whether they work is an empirical question being answered right now.
Measurement
The Input Ratio
A periodic measure of how many organisations can name one instance, in the past two years, where a measure they produced functioned as an input to a decision that was still open.
Writing
Recent
-
10 August 2026
Why the P&L Works and the Risk Report Doesn't
The same board, on the same morning, receives two kinds of information about the organisation it governs. One of them changes decisions. The other never has.
-
15 June 2026
Why the Board Is Always the Last to Know
There is a meeting that happens after every serious cyber incident, and it is always the same meeting.