Skip to content
TODD BROWN
« The Anatomy of Corruption and Corrigibility III — The Instruments · Chapter 8

The Telonic Audit

Picture this: you've just joined the board of an organization you have long admired. The mission statement is on the wall behind you at every meeting. The annual report opens with it. Everyone in the room, including you, could recite it from memory.

Three meetings in, you notice something smaller: a budget line, a staffing decision, a metric the executive director keeps returning to. It has nothing to do with the mission statement and everything to do with a number the board asked for last year. Nobody lied to you. Nobody is hiding anything, exactly. But the thing the organization visibly strains toward, meeting after meeting, is not quite the thing on the wall.

You ask about the budget line at the next meeting, carefully. The executive director has a good answer. It's always a good answer: a funder asked for it, a peer organization does it this way, the number will look better next quarter and open other doors. Every individual answer is reasonable. It's only the pattern, across a year of small reasonable answers, that points somewhere the mission statement doesn't.

You don't have a scandal. You have a feeling. What you need is not more outrage. It's a procedure: something repeatable, something you could hand to the next board member, something that doesn't depend on how sharp your instincts happen to be that day.

Call it the telonic audit: a short, repeatable set of questions for comparing what a system says it's for against what it actually does, and for checking whether the gap is getting better or worse. It doesn't require a scandal. It doesn't require this book's vocabulary either; you can walk a colleague through it without ever saying "telon" or "corrigibility." It requires documents, observation, and the nerve to keep asking after the first comfortable answer.

It also requires knowing, before you start, whether the organization in front of you can hear what you find.

Before the questions

Here's a scene that plays out more often than the tidy version of an audit suggests. A concerned employee, a new board member, or a journalist gathers evidence that an organization is optimizing something other than its stated purpose. They present it carefully, with documentation. The organization's response is not to investigate. It convenes a review of itself and announces, a few weeks later, that it found nothing wrong.

That isn't always a cover-up. Sometimes it's closer to a symptom: the organization has lost the capacity to process the finding as information rather than attack. Chapter 6 called that capacity corrigibility. A system that has lost it doesn't just fail to fix itself. It can absorb the evidence and use it as proof of its own soundness. "We reviewed ourselves, and we're fine" is sometimes exactly what a review process produces once the machinery that should find fault has been redirected to find reassurance.

So the audit opens with a question about its audience: can this system hear what I'm about to find? The test is the one from Chapter 6, and Chapter 9 sharpens it into a scoring rule. Ask the system to specify, in advance, the finding that would count against it. Not whether it welcomes feedback — every captured system says it welcomes feedback. What specific result would change its mind? A system that can answer is showing you, in the act of answering, that its machinery for updating still works. A system that deflects, or can only list reasons the finding couldn't apply, or treats the request as evidence of bad faith, is telling you that machinery is gone.

If the system passes, run the audit as a conversation: bring the questions to the people inside and expect them to engage. If it fails, run the audit anyway, but from outside, and don't expect your findings to be received as anything but ammunition. At that point you're not auditing so much as documenting. That's still useful. It's a different exercise for a different audience: regulators, the public, the next people to join the organization not yet knowing what it has become. Knowing which exercise you're running saves you from the particular exhaustion of arguing with a wall.

The difference shows up fast. Ask a manager whose team keeps missing its numbers what would convince her the current approach is wrong. A healthy answer names something specific: a customer metric that keeps falling for two more quarters despite the fixes, or an independent review that disagrees with her own. An unhealthy answer reroutes: it asks why you want to know, or explains that the numbers would be fine without outside interference, or offers a reason the approach is right that would survive any outcome. The second manager may believe every word. That's the point. Sincerity is not evidence of a working correction system. What you're listening for is whether an answer to "what would change your mind" exists at all.

The three questions

Once you know who can hear the answers, the audit itself is short: three questions, asked in order, each building on the last.

The gap. What does this system claim to be for, and what does it actually optimize? The first half is usually easy. It's on the wall, in the charter, in the mission statement, in the training objective if the system is a machine. The second half takes work: you have to watch what actually gets rewarded, resourced, and protected when something has to give. If a hospital says it exists to heal patients but every hard tradeoff gets resolved in favor of the readmission dashboard, the dashboard is closer to the revealed answer. The gap between the two, and whether it is widening or narrowing, is what you're measuring.

The coupling. Is what the system actually optimizes sustaining or consuming the people and resources it depends on? This is Chapter 5's coevolution question applied to institutions, and it's the hardest of the three. Plenty of systems have a gap between stated and revealed purpose and are still fine. A company that says "we put customers first" while quietly prioritizing margin isn't necessarily in trouble if margin and customer service still move together. The question is directional: as the system pursues what it actually optimizes, is what it depends on — trust, expertise, the health of its workforce, its suppliers and customers — getting stronger or thinner? A system can run a widening gap for a long time if the coupling holds. A growing gap together with a fraying coupling is what signals real trouble.

The standing. Who has the standing, the information, and the protection to ask the first two questions, and what happens to the people who do? This is often the fastest read on the other two, and in practice it's worth asking first even though it comes last logically. An organization where the people closest to a problem can raise it without risking their job or their place still has working correction machinery, whatever the dashboard says. An organization where raising the problem quietly ends careers has told you most of what you need to know before you've looked at a single metric.

One note on what this audit is not. It isn't a values audit. It doesn't ask whether the organization's goals are the right ones or hand down a verdict about what it should care about. The first two questions are checkable against documents and observed behavior: what the charter says, what the spending and staffing reward, whether the substrate is growing or shrinking. You can run it on an organization whose mission you admire and one whose mission you distrust, and the method doesn't change. It measures the distance between what a system says and what it does, and whether what it does is eating what it needs. What you do with the measurement is yours to decide.

Small institutions are where this is easiest to practice. Take a regional food bank. Stated purpose: get food to people who need it. Run question one, and you might find it has, over several years, started optimizing pounds of food distributed, a number easy to report to funders, over nutrition or proximity to the people who need it, because pounds are what the grant applications ask for. Run question two: is that substitution consuming anything? If the food bank hits its weight targets by taking more shelf-stable donations its clients don't want or use, the answer starts to look like yes. The substrate being consumed is the match between food and need, even while every number in the annual report climbs. Run question three, and you find out fast whether the staff member who keeps raising the mismatch is heard or quietly reassigned. It takes the same three questions, asked in the same order, on an institution most people would never think to distrust.

A worked case at higher stakes

The method is the point of this chapter, so this case is kept to a handful of facts that are on the public record, drawn from one official source. The details of what happened inside the company, and who knew what when, have been investigated, litigated, and disputed at length. None of those details is needed here.

The facts are these. The Boeing 737 MAX suffered two fatal crashes less than five months apart: Lion Air Flight 610 on October 29, 2018, which killed all 189 people aboard, and Ethiopian Airlines Flight 302 on March 10, 2019, which killed all 157 aboard. Within days of the second crash, regulators around the world had grounded the aircraft. A U.S. House committee investigation found that the plane's flight-control software, known as MCAS, was permitted to activate on input from a single angle-of-attack sensor, and that pilots were "largely unaware that the system existed." Releasing its final report in September 2020, the committee described the crashes as the culmination of "faulty technical assumptions," "a lack of transparency," and "grossly insufficient oversight."

That is enough to run the audit. Notice that it isn't a verdict on anyone's intent. It's a set of questions any reader can ask of any organization where a safety system is built, checked, and certified.

The gap asks what the system was for and what it actually optimized. The stated purpose of an aircraft program under certification is an airworthy aircraft that pilots can safely fly. The audit's question is what decisions got resolved in favor of when that purpose competed with other pressures — schedule, cost, training requirements, competitive position — and whether anyone could see, before the outcome, which way those decisions were breaking. A safety-critical function that depends on one sensor, in a system whose operators don't know the function exists, is the kind of fact that makes the question worth asking. The audit doesn't need to answer it from outside. It needs to make sure someone inside can.

The coupling asks what substrate the system depends on and whether it is being consumed. For an aircraft manufacturer, two are obvious. One is the internal engineering culture whose job is to be the last voice saying "not yet." The other is public trust that certification means what it says, which every airline, regulator, and passenger relies on. Neither shows up on a delivery schedule. Both can be drawn down for a long time before anyone notices, and both are slow and expensive to rebuild once they are.

The standing asks who was positioned to raise a problem, through what channel, and where that channel ended. The committee's findings about oversight point straight at this question. When the people checking a design report, in part, through the organization whose schedule the check might threaten, the channel for concern has to be unusually well protected to work at all. That is not an accusation against delegated oversight, which is common and often necessary. It is the shape of the third question: whose channel were concerns supposed to travel through, and what would it have cost to use it?

Laid out this way, the case teaches the method's main lesson. None of the three questions required hindsight to ask. Each could have been asked of any safety-critical program, by a board member, a regulator, or an engineer, before anything went wrong. The audit doesn't predict crashes. It tells you where to look while looking is still cheap.

The bootstrap problem

There's an obvious objection: what if the people inside a system can't run this audit on themselves? What if the machinery that would need to notice the gap is the exact thing that's been captured?

This is the hard case, and it deserves a straight answer. A system whose correction machinery has been suppressed cannot audit itself from inside. Not because its people are dishonest, but because suppression, experienced from within, doesn't feel like suppression. It feels like loyalty, or focus, or professionalism, or just how things are done here. Asking a captured system to notice its own capture is asking it to use the faculty that has gone missing.

The resolution has three parts, and none needs the system's permission.

The first is external. The markers of a healthy correction system — does it update on evidence, does it tolerate dissent, can it say what would change its mind — are observable from outside. You don't need the organization's cooperation to watch what happens to people who raise concerns, or to compare what a metric was adopted to track against what it's used for now. An outside auditor, a journalist, a regulator, a former employee with documents: all can run this audit without the system's buy-in, because the evidence is in the record and the behavior.

The second is social. This is why communities built to sustain their members' honest self-assessment matter: a working scientific field, a serious engineering review board, any group where challenging a colleague's work is normal rather than a career risk. These work as external correction that individual organizations can plug into, because they sit partly outside any one chain of command. An engineer who also answers to a professional licensing board has a second loyalty the org chart doesn't fully own.

The third is residual, and it's the most practically important, because suppression is almost never total. Even inside organizations that look thoroughly captured, some corrective capacity usually survives: an engineer who still keeps careful notes, a junior employee who hasn't yet learned that asking is costly, an internal audit function not yet hollowed out. Repair doesn't require restoring the whole system at once. It requires finding wherever the capacity to notice still exists, and building outward from there.

All of this scaffolding protects one small, ordinary sentence, one most people can say honestly about themselves most days: if I believed something wrong, I would want to know. Where a system, or a person, can no longer say it and mean it, the audit tells you where to look next.

Who pays for asking

The third question deserves widening, because in practice it's where audits succeed or fail. The people with the clearest view of a problem — the line worker, the junior engineer two levels below the decision — routinely have the least power to act on it and the most to lose by saying it out loud. The people with the power to act tend to be furthest from the problem, insulated by layers of reporting that filter out exactly the details that would tell them something is wrong.

Call this the inverse-distribution problem: responsibility and corrective capacity run in opposite directions. It's close to the default shape of any system with more than a few layers, because information degrades and risk concentrates as it moves through a hierarchy. Naming it changes where you look for the fix. The obligation to act can't land on the people who see the most. It has to land on people positioned to see less but risk less: boards, regulators, funders, senior insiders who have kept enough of their identity outside the organization that a hard question doesn't feel like self-destruction. Chapter 14 picks up that thread when the question turns from institutions to the individuals inside them.

Think about what an anonymous reporting line is for. In two organizations it sits on the same page of the employee handbook. In one, a report triggers an investigation with a visible outcome, and the person who filed it is still promotable five years later. In the other, reports go into a file nobody reopens, and everyone already knows which reports are safe to file and which end careers. The line looks identical from outside. The inverse-distribution problem is solved by whichever version an organization actually built, not by the one it put in writing. And that, more than any management preference, decides whether an audit like this gets run before a newspaper has to run it instead.

The instrument

Strip the chapter down to what you carry out of the room, and it fits on one page.

The precondition: can this system specify what evidence would change its mind? If yes, audit as a conversation. If no, audit from outside, and treat the findings as documentation rather than dialogue.

The three questions:

  • What does it claim to be for, and what does it actually optimize?
  • Is what it optimizes sustaining or consuming what it depends on, and is that trending better or worse?
  • Who can ask the first two questions safely, and what happens to the people who do?

And underneath all three, the one to ask first if you only have time for one: who pays for asking?

For a board member, this works nearly unchanged. Request the charter and the last three years of budget and staffing decisions side by side, and ask what happened to the last person who raised a hard question in the room. Ask, too, what evidence the board itself would accept as proof the organization is off course. A board that can't answer has the same problem the organization does, one level up.

For someone with no formal power, running the audit on the place they work rather than the place they govern, the version is quieter but no less real. Notice what actually gets rewarded when a tradeoff comes up. Notice who stopped speaking in meetings, and when. And ask yourself honestly what you would do with evidence that the answer to question one is worse than you'd like. You don't need a title to run this audit. You need to be willing to sit with the answer once you have it, which often takes more nerve than the asking.

Close

The audit tells you whether a system is drifting from what it claims to be for, and where the drift comes from. What it doesn't tell you, on its own, is how to catch a system that has learned to pass the audit without changing: one that says the right things about welcoming correction while the machinery underneath stays closed. That harder problem is where Chapter 9 goes: the markers that don't lie, even when everything else about a system has learned to.

Sources