Skip to content
       

Blog

What a Regulator Sees That Your Dashboard Doesn't

What a Regulator Sees That Your Dashboard Doesn't

Your reporting looks good. The dashboard is clean, the numbers reconcile, the board pack goes out on time, and everyone who looks at it comes away confident. Internally, the question "what is the number" is answered well, and answered fast.

Then an auditor, a lender's diligence team, or a regulator arrives, and they are not asking what the number is. They are asking whether you can prove it. Show me the record behind this figure. Show me who entered it and when. Show me what it was before it was changed, and who changed it, and why. Show me that it could not have been quietly altered after the fact. And at that point many organizations discover that a number they were completely confident in internally cannot actually be defended to someone who assumes nothing, because internal confidence and external provability are different standards, and the dashboard was built for the first.

Two different questions about the same number

The gap here is not about accuracy. Your numbers can be entirely correct and still fail this test, because the test is not "is the number right." It is "can you prove the number is what you say it is, to someone who will not take your word for it."

Internal reporting is built to answer the first question. It aggregates, summarizes, and presents, so a decision-maker can see the figure and act. It assumes good faith, because everyone reading it is on the same side and nobody is trying to catch anyone.

External scrutiny operates on the opposite assumption. An auditor's or regulator's job is to not take your word for it, and their standard of what counts as a defensible record is correspondingly higher. The clearest articulation of that standard comes from heavily regulated industries like pharmaceuticals, where data integrity is codified into principles often summarized as ALCOA: a record must be attributable (traceable to who created or changed it), legible, contemporaneous (recorded when the event happened, not reconstructed later), original (the authoritative first record, not a re-keyed copy), and accurate, with later extensions adding complete, consistent, enduring, and available. Property companies are not bound by pharmaceutical regulations, but the principles describe exactly what any serious external party, auditor, lender, or trust-account regulator, is actually testing when they look at your records. And a dashboard, however polished, is designed to satisfy almost none of them.

What "provable" actually requires

The distinction becomes concrete when you look at what an evidentiary record needs that a report does not.

  • Attribution: A report shows a value. An evidentiary record shows who entered or changed that value, tied to a unique individual, not a shared login. Shared accounts fail this by definition, because "someone in accounting" is not an answer to "who made this change." If your systems use shared credentials anywhere near financial data, you have already failed the attribution test wherever they are used.

  • A preserved before-and-after: A report shows the current number. An evidentiary record shows what the number was before it was changed and what it became, with both values preserved. The governing principle in regulated environments is that a change must not obscure the previously recorded information. If your system overwrites the old value with the new one, leaving no trace of what was there before, the current figure may be correct and still be indefensible, because you cannot show it was not altered to say what you wanted.

  • Contemporaneous timestamps: A report shows a date. An evidentiary record shows precisely when each action occurred, from a reliable clock, so the sequence of events can be reconstructed. "Recorded sometime that month" does not let anyone reconstruct what actually happened in what order, which is exactly what an investigation needs.

  • Tamper-evidence: This is the one dashboards never address, and it is the one that matters most to a skeptical outsider. Can you demonstrate that the record has not been changed after the fact? A report presents a number as true. An evidentiary record carries proof that it is the same number that was originally generated and has not been quietly edited since. The blunt version, from practitioners in regulated fields: a record that can change without leaving a footprint is not evidence.

Why the dashboard clears none of these

None of this is a criticism of dashboards for what they are meant to do. It is that they were built for an entirely different purpose, and the qualities that make them good for that purpose are unrelated to provability.

A dashboard's job is to make a number legible and fast. It pulls from underlying data, aggregates it, and renders it cleanly, and in doing so it deliberately strips away exactly the detail that constitutes evidence: the individual records, the change history, the attribution, the timestamps, the sequence. A good dashboard hides all of that, because a decision-maker does not want it and it would clutter the view. The summarization that makes a dashboard useful is the same summarization that makes it useless as proof. So the polish of the dashboard tells you nothing about whether the evidence underneath it exists, and worse, it can create a false confidence that everything is in order, right up until someone asks to see the layer the dashboard was designed to hide.

This is a close relative of a distinction drawn in an earlier piece on how "real-time" gets oversold: a number can be current and still not be decision-ready. Here the point is adjacent, a number can look authoritative on a screen and still not be provable to someone who assumes nothing.

Where this bites a property company

Property does not operate under pharmaceutical regulation, but it faces skeptical external parties constantly, and each one applies some version of this evidentiary standard.

  • Trust and deposit account regulators: In most jurisdictions, security deposit and trust fund handling is regulated, and the regulator does not want to see a report saying the funds were separate. They want to see the record proving separation was maintained continuously, with an auditable trail of every movement. A summary that asserts compliance is not evidence of it.

  • Lender diligence: When a lender's team runs diligence, they are testing whether your reported numbers can be substantiated to source, and how much they have to untangle to do it. Records that reconstruct cleanly, with clear attribution and history, shorten diligence and build confidence. Records that require manual reassembly from spreadsheets raise exactly the doubt you do not want raised while someone is deciding whether to lend to you.

  • Investor and audit scrutiny: An institutional investor or an external auditor works from the assumption that the number must be proven, not presented. The organizations that survive this comfortably are the ones whose systems preserve the evidence as a byproduct of normal operation, so producing it is a query, not a project.

The pattern across all three: the moment an outside party assumes nothing, the dashboard becomes irrelevant and the evidentiary layer underneath becomes everything, and that layer either exists or it does not. You cannot create it retroactively, because contemporaneous, attributed, tamper-evident history is precisely the thing that cannot be reconstructed after the fact. Either it was captured as events happened, or it is gone.

The honest part

Several qualifications keep this from tipping into alarmism.

Property companies genuinely are not subject to the pharmaceutical data-integrity regime, and importing its full apparatus would be wildly disproportionate. The ALCOA principles are useful here as a description of what provability means, not as a compliance obligation to adopt wholesale. The right level of evidentiary rigor for a mid-size property company is far below a drug manufacturer's, and pretending otherwise would be its own error.

Most of the time, the evidence is never tested. The overwhelming majority of numbers on your dashboard will never be challenged by anyone, and building fortress-grade provability around every figure would be a poor use of money. The discipline is to know which records actually need to be defensible, the trust accounts, the figures lenders and auditors examine, the compliance-sensitive data, and ensure the evidentiary layer is sound there, rather than everywhere.

And a good system gives you much of this for free. Modern platforms that keep proper audit trails preserve attribution, change history, and timestamps as a normal byproduct of operation, which means the goal is often not a new project but confirming that the capability is switched on and being used where it matters. The failure is rarely a decision to have no evidence. It is never having checked whether the evidence exists for the records where it counts.

The question to ask before someone else does

The practical move is to stop evaluating your reporting only by how it looks and start asking whether it would survive someone who assumes nothing. Take the numbers that actually have to be defensible, the trust funds, the figures in front of lenders and auditors, the regulated data, and ask four questions of each:

  1. Attribution: Can you show who created and last changed this, as a specific person rather than a shared account?

  2. History: Can you show what it was before it was changed, with the prior value preserved rather than overwritten?

  3. Timing: Can you show precisely when each action happened, well enough to reconstruct the sequence?

  4. Integrity: Can you demonstrate the record has not been altered since, or would you simply be asking them to trust that it wasn't?

Where the answers are yes, the number is not just correct, it is provable, and you will handle audits, diligence, and regulatory review as routine rather than crisis. Where the answers are no, you have a number that is true on your dashboard and indefensible the moment someone tests it, which is the most dangerous kind, because you will not discover the gap until the exact moment it costs you the most. The dashboard was built to answer what the number is. The question that decides your audits and your diligence is whether you can prove it, and those were never the same question.

FAQs

Q1. Isn't a correct number good enough?
Not for external scrutiny. Auditors, regulators, and lenders do not test whether the number is right, they test whether you can prove it is what you say it is, without taking your word for it. A number can be entirely accurate and still be indefensible if you cannot show who produced it, what it was before any change, when each action occurred, and that it was not altered afterward. Correctness and provability are different standards.

Q2. What does ALCOA mean and does it apply to property?
ALCOA is a data-integrity standard from regulated industries: records should be attributable, legible, contemporaneous, original, and accurate, with later additions for complete, consistent, enduring, and available. Property companies are not bound by the pharmaceutical regulations that codify it, but the principles precisely describe what any serious external party is actually testing. It is useful here as a definition of provability, not as a compliance obligation to adopt in full.

Q3. Why doesn't our dashboard satisfy this?
Because a dashboard is built to make a number legible and fast, which it does by aggregating and summarizing away exactly the detail that constitutes evidence: individual records, change history, attribution, and timestamps. The qualities that make a dashboard useful for decisions make it useless as proof. Its polish reflects presentation, not the existence of the underlying evidentiary layer, which it was designed to hide.

Q4. What does a provable record need that a report doesn't?
Four things. Attribution to a specific individual rather than a shared login. A preserved before-and-after so a change does not obscure the previous value. Contemporaneous timestamps precise enough to reconstruct the sequence of events. And tamper-evidence, the ability to demonstrate the record has not been altered since it was created. Reports show the current value; evidence shows its full, defensible history.

Q5. Where does this matter most for a property company?
Wherever a skeptical outside party assumes nothing: trust and deposit account regulators who want proof of continuous separation rather than a report asserting it, lender diligence teams substantiating your numbers to source, and institutional investors or auditors who treat figures as claims to be proven. These are the records where the evidentiary layer must be sound, as opposed to every number on the dashboard.

Q6. Can we produce the evidence after we're asked for it?
Generally no, which is what makes this urgent. Contemporaneous, attributed, tamper-evident history is precisely the kind of record that cannot be reconstructed after the fact, because its value comes from having been captured as events happened. Either the system recorded it in real time or it is gone. Retroactive reassembly from memory and spreadsheets is exactly what fails an evidentiary test.

Q7. Does this mean we need pharmaceutical-grade controls?
No, and that would be disproportionate. Property companies need far less rigor than a drug manufacturer, and the ALCOA framework is useful as a description of what provability means rather than a regime to adopt wholesale. The discipline is to identify the limited set of records that genuinely must be defensible and ensure the evidentiary layer is sound there, not to apply fortress-grade controls to every figure.

Q8. How do we know if we already have this?
Often you have more than you think, because modern platforms with proper audit trails preserve attribution, change history, and timestamps as a normal byproduct of operation. The task is usually to confirm the capability is enabled and actually used for the records that matter, rather than to build something new. The real failure is not a decision to keep no evidence, it is never having checked whether it exists where it counts.