Engineering and Manufacturing

Whose Product Are Your Obligations?

The rules you must obey are copyrighted products sold by the seat, so the people who need to read a clause sit outside the licence and your obligation map is a catalogue.

EraNorth Insights · 30 Aug 2026 · 14 min read

The rules an enterprise is legally obliged to obey are copyrighted commercial products sold under seat and copy licences, so the people who most need to read a clause sit outside the licence, and the enterprise's map of its own obligations is bought from a party whose commercial interest is catalogue breadth rather than currency.

Obligation is compulsory and universal. Access to the words that constitute it is neither. The duty to build, load, label and maintain to a published technical rule reaches every party that touches the work, down to the subcontractor's subcontractor who turns the last fastener. The document carrying that rule is a copyrighted commercial product, sold by the seat and metered by the copy. Everyone is bound. A small number may read.

Most enterprises have never examined that tension, because its two halves are held by different functions. The legal position sits with counsel and the board; the purchase sits with an engineering manager several layers down, renewed annually against a budget line small enough that nobody asks what it leaves out.

Take a hypothetical bulk chemical road transport operator. Whether it conforms is decided by a loading supervisor at a depot before dawn, a subcontracted driver checking a placard, a tank cleaner judging whether a residue has been purged, and a yard hand coupling a trailer. None holds a licence to the operative text. The licence sits on two named seats in a head-office engineering function, under terms limiting how many copies may be made and for how long.

So the enterprise does not operate to the rule. It operates to a paraphrase, written by whoever held the seat, from whatever edition was current then. That paraphrase is the real control document, and it has an author, a vintage and an error rate that in ERANORTH's judgement most enterprises cannot produce on request. That is half the exposure. The other half is prior and larger: knowing which obligations apply at all. That answer is also bought, from a party whose product is breadth of catalogue rather than accuracy of currency. Who supplies your map of your own legal duties, and what is their commercial interest?

The Strategic Context

An enterprise's compliance position rests on two purchases that governance papers never distinguish: access to the operative text, licensed to named users, and the map that says which clauses reach the enterprise's activities and under whose administration. The second is the more consequential and the less examined. A distributor supplies it, and its revenue rises with the number of documents in a bundle and the number of seats attached. Its natural optimisation is coverage. Currency is a cost to that party and a risk to the buyer, and the two do not sit on the same balance sheet.

There is nothing improper in this; the documents are expensive to maintain. The point is that the enterprise has outsourced the definition of its own duties to a supplier whose incentives are not aligned to the accuracy of that definition, and has never classified the arrangement as a dependency. It sits in no risk register, has no executive owner, and renews itself quietly.

Raised to enterprise level, compliance assertions travelling upward carry no provenance. A project reports conformance; a programme aggregates it; the portfolio, the only level at which the licensed population could be compared with the obligated one, records green against a regulatory line. Nowhere does anyone state which document, which edition, on whose advice, because the report format has no field for it.

What Leaders Commonly Misread

The first misreading is that a subscription is a compliance position; it is an access right. It says nothing about whether the bundle covers the enterprise's activities, whether its contents are current, or whether anything outside it applies. Ask the supplier to state in writing what the bundle does not contain; the answer, or more often the absence of one, is the finding.

The second is that the licence perimeter is an administrative detail. It is a design constraint on the enterprise's own control system, written by a third party for commercial reasons: copy and seat limits are why the operating line is governed by an unversioned summary rather than a clause. That is not a procurement matter but the architecture of how the enterprise knows what it must do.

The third is that seniority tracks need. Licences are allocated by grade: design authorities, principal engineers, the compliance lead. The decisions that determine conformance are made by people outside that population. The gap between who may read and who must decide is the enterprise's real compliance risk, and no instrument in general use measures it.

Reframing the Issue

Stop asking whether the enterprise is compliant. Ask who told it what compliance consists of, when they last checked, and what they were paid to do.

Two boundaries follow. Which edition an enterprise is actually bound to, and how an organisation that upgrades to the current edition can move itself out of compliance rather than into it, belongs to [Related article: The Law Pins the Edition; the Standard Moves On]; this article stops short of it at the prior question of who supplied the answer about which document to hold. The external variables that set what an asset must be built to withstand are the subject of [Related article: The Specification Was Set Outside Your Fence]; the concern here is the ownership, licensing and currency of the rule text itself, whatever it requires.

The Two Purchases Behind Every Compliance Assertion

The text, sold by the seat

The operative rule is not a public good in practice, whatever its status in principle. It is licensed, and the licence draws a perimeter: how many named users, producing how many copies over what period, with editing rights confined to appendices while the operative body may not be altered. Obtaining a text that can be worked on at all may require a separate approach to a licensing function.

For a large enterprise this is an inconvenience. For a hypothetical independent bookshop chain fitting out a new store it is decisive. The chain has no engineering function and no licence; it buys its obligation position from a designer or certifier who holds one, and receives a certificate rather than a clause. What that certificate attaches to, and why a later substitution quietly reopens the evidence behind it, is the subject of [Related article: The Certificate Describes an Assembly, Not a Product] and is not taken further here. Upstream of the certificate, the chain has never seen the rule, cannot see it, and has bought knowledge of its own duties from a party whose engagement ends at practical completion while the duty does not.

The map, sold by the catalogue

The map is the more valuable product and carries the weaker guarantee. It answers the question no clause answers: which of thousands of documents reach what this enterprise does. Because a distributor assembles it, it has the shape of that distributor's product line, gaps included. An obligation administered by a body whose documents the distributor does not carry never appears, and nothing indicates that it is missing.

An enterprise fed through one commercial channel therefore holds an obligation picture with no independent check on it — a single point of failure in an unfamiliar place.

The failure mode is silence, not error

The strongest available evidence is a body of professional compliance material assembled to prepare people who would later make conformance decisions. Its regulatory content derives, in its entirety, from one distributor's catalogue captured at a single moment. The distributor's own service descriptions — which bundles exist, which format permits which editing rights, how many copies a licence tier allows — appear in the same register as statements of what the law requires, so a reader cannot tell where the duty ends and the product offer begins.

It also carries, in its own text, notices that some documents it names have been superseded, and that one it treats as current is not the one the governing instrument refers to. The staleness was visible from inside and was never announced. As a compliance picture it is now more than a decade out of date, and nothing in its tone signals this: it still reads as authoritative, because catalogues carry no expiry date.

The corpus is simultaneously the evidence for this argument and a demonstration of its consequence. Nobody falsified it. It aged, as a purchased map ages, while being relied upon by people with no way to date it.

Decision Framework: The Obligation Source Audit

The obligation source audit is a single pass over the enterprise's compliance-critical documents, startable on Monday with a spreadsheet. For every obligation the enterprise asserts it meets, record six fields.

One — the two parties. Who published the rule text and who sold access to it, recorded separately. Where one name fills both, the enterprise has no independent view of its own duty.

Two — provenance of the map. Who told the enterprise this obligation applies to it. The answer takes one of four forms, each implying a different position.

Three — the licence perimeter. How many people may lawfully read the operative text, and how many operating roles make governed decisions from outside it. Record both counts.

Four — the derivation chain. For each work instruction implementing the obligation: source document, edition, date, author. A blank field is not a gap in the audit; it is the audit's finding.

Five — the currency trigger. The event that re-checks this entry, and the date it last fired. An annual review cycle is not a trigger; a trigger is an event with an owner's name against it.

Six — the coverage statement. What the bundle supplier has confirmed in writing is not included.

Who told us this obligation appliesWhat the enterprise holdsRequired action
An internal function that read the text and logged edition and dateA verified positionConfirm the currency trigger has an owner
An adviser paid to advise on the dutyAn opinion bounded by that adviser's briefObtain the brief; establish what it excluded
The party that sells access to the documentsA product recommendationTreat as unverified; commission an independent read
Nobody can sayNothingWithdraw the assertion until the obligation is mapped

Thresholds. An obligation with a blank derivation chain, or a provenance from either of the bottom two rows, is red and cannot support a compliance assertion. An obligation where roles outside the licence perimeter outnumber those inside is amber — for most operating enterprises, nearly all of them, which is the point the audit exists to make visible.

The governance test. No compliance assertion reaches the board unless the paper names, for each obligation, the document and edition relied upon, the date the enterprise last verified it was the right document, and who supplied that verification. An assertion without a provenance line is a statement about a purchase, not about the enterprise.

From Strategy to Execution

Immediately. Run the audit across the twenty obligations whose breach would stop operations or void insurance — not the twenty most frequently discussed. Ask the bundle supplier in writing what it excludes. Express the licence perimeter as a number beside the count of roles making governed decisions.

Over the next two to four quarters. Close the derivation chain: every operating instruction implementing an obligation acquires a source line of document, edition, date and author. Introduce a second supply channel or independent verification for the red obligations. Give the compliance map an executive owner and an entry in the risk register, described as what it is — a dependency on a commercial party with divergent incentives.

Over the longer term. Stop treating access as the deliverable and start treating currency as the deliverable: contract for it where it can be contracted, verify it where it cannot, and maintain the obligation map as an asset rather than renewing it as a document. The enterprises that handle the next decade of regulatory movement well will know, at any moment, the vintage of every rule they operate to.

Signals to Monitor

Watch the age distribution of derivation dates on work instructions, not the count of instructions reviewed. Watch how often an obligation is first identified by an external party — an auditor, an insurer, a customer's questionnaire — because each is a hole the map did not report. Watch whether a bundle renewal is ever accompanied by a question about what changed inside it. And watch the language of internal audit findings: a run of items called documentation currency issues is usually a run of unmapped obligations nobody has the vocabulary to name.

Questions for the Leadership Team

  1. Which party told us which obligations apply to this enterprise, what were they paid, and what does their engagement exclude?
  2. How many people hold a licence to read our compliance-critical documents, and how many make decisions governed by them?
  3. For the ten work instructions carrying the most operational risk, which document and edition was each derived from, on what date, and by whom?
  4. What has our compliance document supplier confirmed in writing is not included in what we buy?
  5. When an obligation last changed materially, how did we find out, how long after, and would that route have worked elsewhere in our estate?
  6. If our compliance map were a decade out of date, what inside this enterprise would tell us?

Closing Perspective

An enterprise can be entirely diligent, fully subscribed, audited annually and confidently non-compliant, because the diligence has been applied to the wrong object. The energy goes into obeying the map. Almost none goes into establishing who drew it, when, and for what commercial reason.

The responsibility now sitting with the leadership team is not to read more clauses. It is to accept that the enterprise's knowledge of its own duties is a supplied product with a vendor and a vintage, to name that vendor in the risk register, and to require that every assertion of compliance carries the provenance of the belief behind it. The alternative is not ignorance, which announces itself. It is confidence in a picture that stopped being true on a date nobody recorded.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.