Every Organization Runs Two Systems
Somewhere in your organization there is a documented management system. It has procedures, a defined scope, an org chart with responsibilities assigned to roles, and a folder structure someone set up during implementation. It passed an audit.
Somewhere else in the same organization, the work is getting done.
Most of the time those are not the same system. And the distance between them is quietly setting the ceiling on everything the system was built to deliver.
The gap does not announce itself
This is what makes the problem durable: you cannot see it by looking at either system alone.
Read the documentation and it looks fine. It was probably written by someone competent, or bought as a template from someone competent. Watch the work and that looks fine too — people are busy, output is going out the door, customers are mostly satisfied.
The gap exists only as a comparison. It lives in the space between the documented system and the observed one, which means you have to hold both at the same time to see anything at all.
That is what a walkthrough is for. Ask someone to walk you through how the process actually runs, then follow the records as verification. Not “do you follow the procedure” — that question has one socially acceptable answer. Walk the work, then check whether the evidence trail matches what you just watched.
What the walkthrough surfaces
Two tells show up early.
People do not recognize their own documented system. Not resistance — unfamiliarity. You reference a procedure and get a blank look, or a polite version of “is that what it says?” The document describes a process the person performing it has never run. This is common where documentation was inherited from a template and never tailored to how the organization actually operates. The split was manufactured at install. It did not drift into existence.
The records get updated all at once. Entry dates marching in lockstep down a column. A risk review that re-stamps the original list with a new date and adds nothing. A log with eleven months of silence and one dense afternoon of entries. That is reconciliation, not maintenance, and it tells you the system is being run backwards from the audit date rather than forward from the work.
The tells are layer-dependent
Past those two, what you find depends on which layer you are looking at and how much the organization defined in the first place. There is no universal signal — only the comparison.
At the risk layer: synchronized review dates, no entries added since implementation, an annual or nominally quarterly review that re-stamps the current list and closes the item.
At the operational layer: defined KPIs that are not consistently measured, or measured but not reported, or reported into a meeting where nothing is decided against them.
At the documentation layer: procedures written to a generic structure rather than to the organization’s, which is the condition that produces most of the above. This is why ISO 9001 documentation structure work is worth doing properly rather than importing, and the same expectation carries in an information security system where ISO 27001 documentation requirements are evaluated for operating effectiveness, not existence. A document that does not describe your operation cannot be followed by the people in it.
Two objects, two problems
When you find the gap, it shows up at one of two objects. They come from the same split, but they are different problems and they take different fixes.
Capability is who can do the work.
The documented system assigns the responsibility to a role. In practice a small number of specific people carry it. The org chart says the process owner runs the review; three people who understand the requirements actually run it — plus the corrective actions, plus the internal audit program, plus the management review pack.
The organization has training records. What it does not have is a defensible answer to who is qualified to do a given piece of work. Records prove attendance. Competence is a different claim, and every modern management standard asks for the second one. The ISO training requirements are explicit about the distinction: competence has to be defined, achieved, and verified — not attended.
Execution is how the work gets managed.
There is a defined routine — a review cadence, a set of things a manager is supposed to look at, an output that is supposed to come out the other side. In practice the routine runs differently depending on who is running it. Or it runs from memory. Or it runs the month before the audit. Where the routine was never defined at all, each manager runs the operation from their own habits, and the team relearns how to be managed every time the chair changes. A well-built ISO 9001 quality management system assumes leadership oversight is a designed activity, not a personal one.
Both objects are unclaimed. Neither is written down anywhere you can inspect, transfer, or improve. That is what they have in common, and it is why the org chart is not a description of your operation.
Who is actually holding it together
Usually a handful of people. The ones more in tune with the requirements than everyone else, absorbing the gap with duct tape — running the corrective actions, assembling the management review, keeping the internal audit program alive, cleaning up records before the certification body arrives.
This is not a motivation problem, and it is rarely a competence problem in the people doing it. People maintain the status quo by default. Without authority to change how things work, or without an articulated picture of what better would even look like, the environment gets sustained exactly as it was inherited. That is a rational response to the conditions.
Which means the small few are not the failure. They are the compensating control. And a compensating control nobody designed is one that fails without warning.
The ledger nobody finishes
Name this to leadership and the objection is usually about cost: building competence and awareness at the layer where the system actually gets implemented takes time and money, and both are scarce.
That is true. It is also one side of the ledger.
The other side is already being paid and appears on no budget line. Delays. Internal inefficiency. Work done twice. The annual scramble to reconcile a system that should have been maintained continuously — which frequently costs more in concentrated effort than distributed ISO 9001 maintenance would have cost across the year. And beneath that, the impacts nobody traces back to source: schedule slip, frustration, dips in customer satisfaction, risk carried by employees, attrition.
An ineffective system does not fail loudly. It leaks.
One clarification, because it cuts against the instinct: the undocumented system may be running well. Sometimes better than what is written. That is not a reason to leave it alone. A system you cannot see is one you cannot inspect, transfer to the next person, defend in an audit, or improve on purpose. Effectiveness you cannot account for is not an asset. It is exposure.
The diagnostic
You do not need a project to find out where you stand. You need one process and two hours.
Pick a process that matters — one with real operational consequence, not the easiest one to document.
Pull the current documented version. Read it before you talk to anyone.
Ask the person who performs it to walk you through how it actually runs. Do not correct them. Do not reference the document.
Follow the records as verification. Look at when entries were made, not only whether they exist.
Write down every place the walkthrough and the document diverge.
Then sort the divergences into the two buckets. Capability: the documented role is not the person doing the work. Execution: the documented routine is not the routine being run, or the routine changes with the manager.
For a structured version of this across a full system rather than a single process, that is what a gap assessment is for — this guide on how to perform an ISO gap assessment walks the clause-by-clause method. If you would rather have the comparison run by someone who does not already know what the answer is supposed to be, that is a large part of what our ISO consulting work is. Where several standards are in scope at once, the comparison usually has to run across all of them together, which is the case for integrated management system consulting.
Either way, the first honest finding is usually the same one. The org chart describes a system. Your operation is running a different one. Nobody has claimed the difference.