Governance by Post-Mortem
← Back to Articles

Governance by Post-Mortem

Risk appetite can price residual risk. It cannot cure structural incapacity. Why failure tolerance in AI governance cannot substitute for pre-execution authorization.

Governance by Post-Mortem

Why Risk Tolerance Cannot Substitute for Pre-Execution Authorization


A familiar argument in technology leadership goes like this: organizations must get better at accepting risk. The vocabulary varies. Measured risk. Risk appetite. Failure tolerance. Permission to experiment. The underlying proposition is largely sound: an organization that punishes every unsuccessful attempt eventually stops attempting, and broken processes can survive because leaving them untouched feels safer than trying to fix them.

We would add one sentence to that argument, and the sentence changes more than it appears to.

Before an organization decides how much risk it is willing to accept, it has to decide what kind of control a given consequence requires. Those are different questions. The first is a matter of appetite. The second is a matter of architecture. One pattern in AI governance is becoming difficult to miss: the second question is being answered with the vocabulary of the first. The result deserves a name: governance by post-mortem.

The runner at two in the morning

Picture someone at the edge of a highway at two in the morning. No crossing in sight, and the calculation is already running: traffic is thin, visibility is good, the far shoulder is maybe six seconds away. Rush hour would be out of the question. This is not rush hour. Maybe this time I won't get hit.

Here is the uncomfortable part: on a given crossing, the calculation may even be right. The reasoning is not irrational. It is recognizably risk reasoning: estimate the exposure, weigh the payoff, accept the residual.

But nothing in that calculation can stop a car. The runner's safety rests on an estimate that no car will arrive during the crossing, plus whatever capacity the runner has to react if the estimate fails. Nothing stands between the forecast and the consequence. The runner has not installed a control. The runner has accepted the possibility that the forecast will be wrong.

Now change one detail. The organization making the crossing decision is not the one on the road. It stands safely on the shoulder and sends something else into traffic, at scale, thousands of times a day, into lanes that contain other people. At that point "maybe this time" stops being a personal wager and becomes a governance posture.

That's the posture worth examining.

Failure is not one thing

The rhetoric around failure tolerance can compress very different events into a single category called failure. They should be separated before risk appetite enters the discussion.

Experimental failure. A prototype fails. A pilot does not produce the expected gain. A model underperforms and the approach is abandoned. This is the failure the innovation argument is actually about, and the argument is right: an organization serious about technology should tolerate this failure readily, and should prefer the fast version of it.

Bounded operational failure. A deployed system makes mistakes inside a blast radius that was deliberately limited in advance: a sandbox, an advisory workflow, a simulation, a transaction that can be reversed. The failure is real but contained by design. Accepting it can be a rational, priced decision. This is residual risk in the proper sense, and risk appetite is the correct instrument for deciding how much of it to carry.

Governance failure at a consequential execution boundary. An AI system can initiate an irreversible payment, disclose protected information, alter critical infrastructure, or release a consequential determination, and the mechanism relied upon to govern it watches, logs, scores, and alerts. When the prohibited action executes, the mechanism produces an excellent account of what happened.

The third category is not a larger version of the first two. It is a different kind of event. A failed experiment and an unauthorized irreversible action are not members of the same risk class merely because both are called failure. One is the cost of learning. The other is the discovery, after the fact, that nothing stood between a prohibited action and its execution.

Appetite is downstream of architecture

The sequencing matters more than the taxonomy.

An organization confronting a consequential AI action has two questions in front of it. What kind of control does this consequence require? And how much residual risk are we willing to accept? The questions have an order. Risk appetite becomes meaningful only after the required control function has been identified and a control capable of performing that function is in place. What remains can be accepted, transferred, mitigated further, or refused. But the absence of the required control function is not residual risk merely because someone has chosen to accept it.

Risk appetite statements are legitimate instruments. Using one to mark where experimentation is welcome is exactly right. The failure mode is subtler: invoking appetite at the wrong point in the sequence. When the requirement is that certain actions must not execute, and the control in place is structurally incapable of preventing execution, a declaration of higher risk appetite does not describe a braver organization. It describes an organization that has repriced a gap without closing it.

Risk appetite can price residual risk. It cannot cure structural incapacity.

Call this the control-sufficiency precondition: risk acceptance begins only after the control relied upon is capable of performing the function the consequence requires.

There is a linguistic tell worth flagging, because it's how the substitution survives review. "We have assessed this risk and accepted it" is a sentence that performs governance. It has the grammar of diligence. Applied to bounded operational failure, it is diligence. Applied to a consequential execution boundary guarded only by observation, the same sentence means something closer to: we have decided to find out afterward. The words did not change. The referent did.

The word structural is doing real work here, and it deserves precision. An adequate control that occasionally malfunctions is a reliability problem; you engineer against it, and residual risk is the honest name for what remains. A control that could never perform the required function is not a reliability problem. A control whose operative function is observation can be exceptional at detecting, explaining, and reconstructing behavior and still be structurally incapable of supplying pre-execution authorization. It may tell us with extraordinary precision what the system did. That does not answer the boundary question: may this specific proposed action execute?

When prevention is the requirement, the relevant question is not how sophisticated the observation is. It is whether execution depends on a verdict rendered before execution. We have made the structural argument formally elsewhere;² the short version is that a signal produced by an action cannot govern the action that produced it. No amount of appetite changes the direction of that arrow.

The post-mortem, properly named

A post-mortem is the most thorough examination its subject will ever receive. It is performed with rigor, documented meticulously, and reviewed by experts. Its findings improve outcomes for the next case. It has never once changed the outcome for the subject on the table. That is not a criticism of pathology. It is the definition of the genre: the examination exists because the outcome is settled.

Hence the term.

Governance by post-mortem occurs when an organization relies on post-execution observation as the operative control for a requirement that depends on pre-execution authorization.

The defect is temporal and functional. The organization may detect quickly, reconstruct completely, and investigate rigorously. But if the prohibited action did not depend on authorization before execution, none of those capabilities could have prevented that execution.

The definition is meant to be testable rather than rhetorical, so test it. An autonomous payment agent is deployed to initiate transfers subject to defined conditions. One day it proposes a transfer outside them. Suppose the observability stack flags the transfer within two hundred milliseconds and reconstructs the full decision path, flawlessly. If settlement has already been initiated, none of that is the relevant governance fact. Detection latency is an impressive number attached to the wrong question. The question that decides the case is whether execution of that specific transfer depended on a pre-execution authorization artifact. Here it did not. The two hundred milliseconds are the post-mortem, arriving early enough to look like a control.

The definition does not condemn monitoring, logging, anomaly detection, or incident review. Those functions are valuable, and in some settings indispensable: detection, diagnosis, learning, assurance, evidence. Aviation keeps flight recorders for exactly these reasons. Where takeoff clearance is required, a flight recorder cannot substitute for it. The recorder answers what occurred. The clearance answers what was permitted before occurrence. Both have legitimate functions. Only the second can condition the act before it occurs.

FERZ doctrine states the underlying distinction in two sentences: "Monitoring creates evidence of what occurred. Runtime authorization creates evidence of what was permitted before occurrence."¹

Governance by post-mortem is what happens when an organization possesses only the first kind of evidence, needs the second, and covers the difference with risk language. The tell is always the same: the governance story is entirely about what the organization will know afterward. All of it sincere, and all of it downstream. No improvement in the quality of the recording changes when the recording arrives.

The case for the test track

None of this is an argument against risk. It is closer to the opposite.

Nobody accuses a test track of being anti-speed. The track exists so the speed can be extreme. The barriers, the runoff, the boundary between the course and the public road are not the constraint on the experiment. A bounded environment can support more aggressive experimentation precisely because the boundary separates experimental freedom from uncontrolled external consequence. The boundary is an enforced fact, not a forecast.

So the resolution of the risk-and-failure conversation is not less appetite. It is appetite applied at the right point in the sequence.

Take risk in what the system attempts. Do not take avoidable risk in whether prohibited actions can execute.

An organization that adopts that ordering can be more tolerant of failure than its cautious peers, not less, because its failures have been confined by architecture to the categories where failure is affordable. What it refuses to do is use production as the instrument for discovering that its controls were inadequate. That discovery already has a name, and the name is the point. It is a post-mortem: the most rigorous examination there is, performed exactly one action too late.


References

  1. Meyman, E. From Monitoring to Authorization. FERZ, Inc. Concept DOI: 10.5281/zenodo.18743974. Edition relied upon: v1.0.
  2. Meyman, E. On the Impossibility of Observability-Based Authorization. FERZ, Inc. DOI: 10.5281/zenodo.19647542. Edition relied upon: Technical Note v1.4.0.

Cite as: Meyman, E. Governance by Post-Mortem: Why Risk Tolerance Cannot Substitute for Pre-Execution Authorization. FERZ, Inc. v1.0. DOI: 10.5281/zenodo.21997074.