Imagine that your organization has a clear policy: Mustache Bandits are not permitted in the building.
You have a written procedure for verifying identities. Employees receive annual training. Access logs are retained. Your assessors can review evidence showing that the process exists and that people are performing the required steps. On paper, the control looks healthy.
Unfortunately, the Mustache Bandit has been walking through the front door every Tuesday for six months.
That is where compliance theater starts to become visible.
The problem is not that the organization has policies, procedures, training, logs, or evidence. All of those things matter. The problem is that the organization has become very good at proving that a control exists without being equally good at proving that the control is actually accomplishing what it was designed to accomplish.
That distinction matters, especially in complex compliance programs where hundreds of requirements may need to be documented, tested, assigned, monitored, and maintained. Over time, it is easy for the evidence package to begin feeling like the objective rather than what it really is: proof that a broader governance process is working.
Compliance Is Not the Villain
It is common to hear that “compliance does not equal security,” usually as part of a criticism of checkbox exercises. There is some truth in that, but the argument is often oversimplified.
Compliance frameworks exist because organizations need repeatable ways to translate risk into expectations, controls, responsibilities, and evidence. A strong compliance program provides discipline. It establishes who is supposed to do what and creates a common way to determine whether those things are actually happening.
The problem begins when the organization optimizes for the appearance of control instead of the outcome of the control.
If the purpose of our Mustache Bandit control is to prevent unauthorized access, then the policy is only one part of the story. The organization also needs a mechanism to enforce it, someone responsible for operating that mechanism, a way to detect when it fails, and a process for responding when failure occurs.
If all of those things exist but nobody notices the same unauthorized person entering every Tuesday, something important has been lost between the requirement and the actual risk.
The paperwork may still be excellent.
The Mustache Bandit is still inside.
Design, Execution, and Effectiveness Are Different Things
One reason compliance theater can be difficult to recognize is that several different questions often get bundled together.
First, is the control designed appropriately? Does the organization have a reasonable process that should address the identified risk?
Second, is the control actually being performed? Are people following the process? Are systems configured as intended? Are reviews taking place?
Third, is the control effective? Is it producing the outcome we expected?
Those questions are related, but they are not interchangeable.
Our organization may have designed a perfectly reasonable identity verification process. Security personnel may be checking credentials exactly as required. Logs may prove that those checks occurred. Yet perhaps exceptions are being granted so frequently that the process no longer meaningfully restricts access. Perhaps alerts are generated but nobody reviews them. Perhaps the threat has changed, and the Mustache Bandit has discovered a convincing fake beard.
In each case, the control exists and may even be performed consistently. What has failed is the connection between the activity and the intended outcome.
That is the point at which compliance starts to become theater: not because the activities are fake, but because the organization is measuring whether the activity occurred without asking whether the activity mattered.
FedRAMP and CMMC Make This Particularly Visible
Federal compliance programs provide especially useful examples because they force organizations to think beyond simply writing a policy and declaring the problem solved.
With FedRAMP, a substantial amount of effort goes into authorization. Controls have to be documented. Evidence has to be collected. Testing has to occur. Findings have to be remediated. Responsibilities have to be assigned, and processes have to be formalized.
But the system does not stop changing when the assessment ends. New vulnerabilities appear. Accounts change. Configurations drift. Personnel move into different roles. Software is updated. Exceptions accumulate. Threats evolve, and that is why continuous monitoring matters.
The real question is not simply whether the organization could demonstrate that a control worked during an assessment period. The question is whether the organization has enough visibility and governance to know when the control stops working later.
CMMC presents the same challenge from a different angle. An organization handling Controlled Unclassified Information can document required practices, establish policies, assign responsibilities, and prepare evidence for an assessment. But the objective is not simply to produce a convincing assessment package. It is to protect CUI throughout the organization’s actual operations.
If access restrictions exist on paper but sensitive data routinely ends up somewhere it should not, the Mustache Bandit has simply found another door.
Whether the framework is FedRAMP, CMMC, or something else, the underlying question remains the same: are we demonstrating activity, or are we demonstrating that the activity is actually managing the risk?
If the Mustache Bandit gets through the door six months after authorization or the day after a CMMC assessment, what happens?
Does anyone notice? Who owns the issue? Who investigates it? How long can it remain unresolved? Does the organization understand why the control failed, or does it simply document the incident and move on?
Those are governance questions as much as compliance questions.
Ask Whether the Mustache Bandit Got In
There is a simple way to test whether a control discussion has drifted too far toward theater: ask what would happen if the control failed tomorrow.
How would we know?
Who would care?
Who would be responsible for fixing it?
Would the failure change anything about how we operate?
Those questions move the conversation away from the existence of an artifact and back toward the purpose of the control.
That does not mean compliance teams should collect less evidence or spend less time documenting controls. Strong governance depends on good documentation, clear ownership, reliable monitoring, and useful evidence.
But those things are means, not ends.
The goal is not simply to demonstrate that the Mustache Bandit is prohibited. The goal is to make sure he does not get in, notice quickly if he does, understand why it happened, and improve the system so the same failure does not quietly repeat every Tuesday for the next six months.
If your compliance program can do that, the evidence is telling the story it was supposed to tell.
And if the Mustache Bandit happens to turn up later in a discussion about Zero Trust, identity governance, continuous monitoring, or risk management, at least now you know what to look for.