Three Units, Three Rules, and Nobody Compared
When an organization comes under scrutiny, each part of it quietly decides for itself what now needs sign-off from above. Every one of those decisions is reasonable, and nobody notices that they do not match.
It usually starts with a period of attention. An audit is underway, a regulator has asked questions, a complaint has gone public, or a new executive has made it known that they are watching a certain kind of decision closely. Nobody issues a new policy, because nothing about the policy has changed. What changes is how carefully everyone is handling it.
Over the next few weeks, each group in your area makes its own adjustment. One team starts sending every exception up for approval, including the small ones it used to handle without asking. Another keeps handling routine exceptions itself but now sends up anything that involves money. A third decides nothing has really changed for them and carries on as before. Each group made its choice in good faith, for sensible reasons, based on what it understood the risk to be. And each one believes, if you asked, that it is doing what everyone else is doing.
Caution is local
The mechanism is simple once you see it. When scrutiny rises, people become more careful, and being careful means deciding what counts as sensitive. That judgment is made inside each group, by the people closest to the work, using whatever signals reached them. Those signals are rarely the same. One team heard about the audit in a staff meeting where a senior person sounded worried. Another read a memo that emphasized financial controls. A third heard nothing at all, because their manager did not think it concerned them.
So the organization ends up with several working rules for one category of decision. None of them is written down, because none of them was ever formally adopted. Each exists only as a habit that formed in a particular group over a few anxious weeks. And because nobody compares them, nobody knows they differ. The groups do not see each other's decisions in enough detail to notice, and you see only what reaches you, which is a skewed sample. The team sending everything up looks diligent. The team sending nothing looks quiet. Neither looks like evidence of a problem.
This is not the same thing as a team that has learned to escalate out of self-protection. That is one group's relationship with its leader. This is several groups, each with a different reading of the same moment, and no one positioned to notice that the readings disagree.
What the divergence costs
The same request gets different answers depending on where it lands. Someone outside your area who deals with two of your teams will notice before you do. A request that one team approves in a day takes three weeks in another, because it went up for sign-off and sat in a queue. To the person on the receiving end, that does not look like caution. It looks arbitrary, and when it is explained, each team's account of its own rule makes the other team look careless or obstructive.
The review you were worried about finds exactly this. Periods of scrutiny tend to end with someone looking at how decisions were actually made. What they find is rarely one group doing something reckless. It is a pattern of inconsistency: similar cases handled differently, with no documented reason for the difference. Inconsistency is often harder to defend than a single mistake, because a mistake can be explained and corrected, while inconsistency suggests nobody was in charge of the standard.
The rules outlast the reason for them. The scrutiny eventually passes, but the habits do not reset on their own. The team that started sending everything up is still doing it a year later, long after anyone remembers why, and the extra layer of approval has become part of how the work is done. The team that never adjusted may still be operating on assumptions that were quietly retired elsewhere. Each group's version hardens precisely because it was never looked at.
Three moves
Ask each group what it currently sends upward, and compare the answers in one room. This is the whole diagnostic, and it takes a single meeting. Do not ask what the policy says; everyone will give you the same answer. Ask what they actually send up for approval right now, what they decide themselves, and when that changed. Put the answers side by side. In most organizations under recent scrutiny, the differences will be visible within the first twenty minutes, and the people in the room will be as surprised as you are.
Pick one standard and say it out loud, with the reason attached. Once the differences are visible, choose the rule that fits the actual risk, not the most cautious rule and not the least. Then state it plainly to every group at once, along with why it is the rule, what counts as an exception, and who decides the exceptions. A standard delivered separately to each team will drift the same way the old habits did, because each team will interpret it through its own signals again.
Set a date to check whether the standard held, and set one to retire the extra caution. Consistency does not maintain itself, especially while attention stays high. Plan a short follow-up in a month to see whether the groups are still applying the same rule. And if part of the new standard exists only because of the current scrutiny, decide now when you will revisit it, so that temporary caution does not become permanent overhead without anyone choosing it.
The part that is about you
It is easy to read the divergence as a failure of the groups, as if one of them should have checked with the others. But the groups had no reason to think they needed to. They were each doing what careful people do under pressure, and the comparison they did not make is one that only someone above all of them is in a position to make.
That is uncomfortable, because during a period of scrutiny your attention is usually on the thing being scrutinized, not on how your own teams are reacting to it. Yet the reaction is part of what will eventually be reviewed. The consistency of your area's decisions is not something the groups can see from where they sit. It is only visible from where you sit, and only if you ask.
Three questions
If you asked each group you lead what it currently sends up for approval, how confident are you that the answers would match?
Which of your current approval steps started during a period of heightened attention, and does anyone remember what it was?
When someone outside your area deals with two of your teams on the same kind of request, would they get the same answer and the same timeline from both?