In many companies, compliance — the process of following rules and regulations — is managed by several different teams rather than a single person. This leads to a hidden problem: the same information is often collected and processed multiple times by different groups, even though it's essentially the same fact. Instead of using many tools to meet compliance obligations, it might be more efficient to establish a single source of truth and then view it from different angles depending on the needs of each team. For example, imagine a security information systems officer who was asked the same question five times in one year. Five different departments — data protection, internal control, internal audit, commercial direction, and a broker — all needed details about access to sensitive applications, such as who had access, when, and who approved it. Each department had its own schedule, format, and deadline, so the officer had to provide the same information five times, each time reconstructing the data. None of the departments knew that the others had made the same request, and no one felt the full impact of this duplication. This situation is counterintuitive because each department was acting correctly according to its own obligations. The repetition is not felt by any one person in its entirety — each requester only bears a small part of the burden, and the person providing the information is left with the task of answering multiple times without the authority to change the system. As a result, the same information is duplicated, increasing costs and potentially leading to inconsistencies. The key issue is that while the underlying fact — such as who has access to what — remains the same, the way it is interpreted can vary depending on the regulation or requirement. For instance, data protection laws may focus on the purpose and minimization of data, while network security standards may emphasize risk management. Each of these interpretations is valid and necessary, but they don't need to duplicate the same fact. Establishing a single fact once and then using it in different ways is both possible and more efficient than repeating the same task multiple times with different tools and formats. A recent survey by PwC, published in February 2025, found that nearly half of the executives surveyed use technology to manage eleven or more compliance activities. This doesn’t necessarily mean they are using many tools for the same task, but rather that each activity has its own tool and its own version of the facts. This approach results in multiple copies of the same information, which can lead to inefficiencies and potential inconsistencies. To check whether this duplication is happening in your company, you don’t need a major project or significant budget. You can start by selecting a common compliance activity, such as access management, and asking two departments that handled it this year to show you their most recent responses. Compare the formulations and the dates. If the responses are the same, your compliance framework is better managed than average. If they differ, the real issue is not which one is correct, but how many times people in your company have answered the same question separately without realizing it.