July 22, 2026|7 min read

Every Control Has an Off Switch. Who's Holding Yours?

Regulators are handing discretion back to companies — from SEC reporting choices to shrinking agencies. Here's why that raises internal control stakes.

Every Control Has an Off Switch. Who's Holding Yours?

Photo by Vitaly Gariev on Unsplash

The most expensive compliance failure of the summer didn't involve a breach, a novel exploit, or a foreign adversary. On June 30, EagleBank agreed to pay more than $9.7 million to resolve a Bank Secrecy Act investigation, and the mechanism is what should keep governance professionals awake. For more than a decade, the bank's anti-money-laundering program didn't collapse because it was absent. It collapsed because executives with the authority to run it worked around it — quietly accommodating a check-kiting scheme run by a father-and-son pair with a personal relationship to the bank's own former chairman. The control existed. Someone with a key turned it off.

That detail — a working control switched off from the inside by someone entitled to touch it — is the quiet thread running beneath a week of governance news that otherwise looks scattered. And it lands at an uncomfortable moment, because regulators are preparing to hand a great many more of those keys back to the companies they supervise.

The off switch was always the real vulnerability

Auditors have a term for the EagleBank pattern: management override of controls. Every serious fraud framework treats it as the risk that defeats all the others, because the people with the authority to design a control are usually the people with the authority to bypass it. You cannot buy your way out of it with more software. It is a governance problem, not a tooling problem.

Look past the headlines and the same shape repeats. In South Africa, the finance minister is moving to remove the chairman of the Public Investment Corporation — the state pension-fund manager already "wracked by corruption and instability" — a reminder that a board seat is itself a set of keys. In the UK, the founder of a self-styled "ethical" fintech was revealed to have tried to help Jan Marsalek, the Wirecard executive later exposed as a fraudster and spy, raise $2.75 billion to buy Russian military technology. The label said ethics; the conduct said otherwise.

The common denominator across these stories is not incompetence or a missing rule. It is authority turned against its own purpose:

  • The control was present but disabled by someone entitled to disable it.
  • The failure originated inside the trust boundary, not outside it.
  • No external attacker was required — legitimate access did the damage.

The referee is stepping back — deliberately

Here is why that pattern matters more now than it did a year ago. The external checks that historically welded those off switches shut are being loosened, on purpose.

In May, the Securities and Exchange Commission proposed letting domestic issuers file financial reports semiannually rather than quarterly — and, critically, the choice would rest with the firm itself, meaning its board. Reporting cadence, long a mandatory external discipline, becomes a matter of internal discretion. Around the same time, SEC Chair Paul Atkins used a Small Business Capital Formation Advisory Committee meeting to signal a posture tilted toward easing the path to capital, not tightening it.

The judiciary is pulling in the same direction. Legal commentators are now describing an administrative law "conceptual revolution," as the Supreme Court rejects long-settled understandings of how much authority agencies actually hold. The Court's decision green-lighting Temporary Protected Status terminations for Haiti and Syria tested the limits of judicial review over executive action, further reshaping who gets to decide what. Even for companies simply entering the US market, there is no single federal privacy standard to comply with — only a patchwork of state laws each business must navigate and interpret for itself.

Read together, these are not isolated events. They describe a migration of discretion — from the external enforcer to the governed. The whistle is being handed to the players.

Lighter regulation is not lighter governance

It is tempting to read all of this as relief: fewer filings, friendlier regulators, narrower agencies. That reading is a trap. When the external forcing function weakens, it does not vanish — it relocates onto your own internal controls. The burden doesn't shrink; it moves closer to home.

Two of this week's stories show what discretion looks like without discipline. A Financial Times examination of prediction platforms warned that "without tough enforcement," these venues become "fertile ground for manipulation" by those holding inside information — a clean illustration of what happens when access is high and oversight is low. And the murky accounting of roughly $13 billion in Venezuelan oil money, where even the US government has offered "diverging accounts" of where the funds went, shows how quickly opacity fills any space that oversight vacates.

If your company opts to report to the market twice a year instead of four times, the market learns about problems later — which means your board must learn about them earlier and more reliably on its own. Self-selected transparency only works if internal transparency more than compensates. Otherwise you have simply bought yourself a longer runway to an EagleBank-shaped outcome.

Build governance that survives its own executives

The strategic response to an era of optional oversight is not to lobby against it. It is to make your controls override-resistant — durable enough that no single insider, however senior, can quietly switch them off. That means treating "who can turn this off, and would we notice?" as a first-class governance question for every material control.

Practically:

  • Separate the authority to execute a process from the authority to modify or disable its controls, so no one person holds both keys.
  • Make every exception and override generate an immutable, time-stamped record — the change itself becomes evidence.
  • Escalate override events to the board directly, not just the outcomes those overrides eventually produce.
  • Where you accept lighter external reporting, deliberately tighten internal reporting cadence to close the gap.
  • Map your control inventory to the roles that could bypass each one, and pressure-test the controls concentrated in too few hands.

What this means for the next few years

The direction of travel is now set. Expect more discretion returned to companies — over disclosure, over interpretation, over how much of the rulebook applies and when. Boards will increasingly get to hold the dial. The organizations that come out ahead will be the ones that understand what that gift actually is: not a holiday from governance, but a transfer of enforcement responsibility onto their own shoulders.

EagleBank's $9.7 million is the price of assuming the referee will always catch the override. As the referee steps back, that assumption gets more expensive by the quarter — or, soon, by the half-year. When oversight becomes optional, integrity has to become infrastructure. The off switch on your most important controls is about to be entirely in your own hands. The only question worth answering now is who, inside your walls, is allowed to reach it.

Sources

ManagementOverrideSegregateOverrideAuthorityImmutableOverrideLogEscalateToBoardDiscretionaryReporting reduces detects mitigates amplifies
As regulators return discretion via lighter reporting, override-resistant controls must contain management override risk.

Related governance guides