Thematic Reviews and the Governance Visibility Gap in Cryptographic Risk

Compliance frameworks tell organisations what controls to implement. They do not tell leadership whether those controls operate as intended across systems, vendors, and decision chains. This distinction is where governance failures take root, and where a thematic review provides visibility that periodic audits cannot.
The gap is structural, not accidental. Audits assess controls against criteria. Thematic reviews examine how a specific risk theme behaves across an organisation's full operational surface. In post-quantum cryptography and broader cryptographic governance, that distinction carries material consequences.
Point Audits Assess Controls. Thematic Reviews Assess Behaviour.
A SOC 2 assessment examines whether key management controls meet defined criteria at a point in time. A FIPS 140-3 validation confirms that a cryptographic module operates within a tested boundary. Neither examination is designed to answer the question that boards and regulators increasingly ask: does the organisation's cryptographic posture hold up when examined laterally, across functions, vendors, and inherited dependencies?
This is the question a thematic review is built to answer.
The UK Financial Conduct Authority pioneered the thematic review model in financial supervision precisely because point-in-time assessments missed systemic patterns. Their post-2008 thematic work on conduct risk revealed failures that no single firm-level audit surfaced. The same structural logic applies to cryptographic governance: the risk is not that one control fails, but that governance gaps compound across boundaries nobody examines together.
NIST's Cybersecurity Framework 2.0 expanded its Govern function to address this directly: the organisational context in which technical controls operate. Profile alignment requires understanding not only what controls exist but how they interact with governance structures and supply chain dependencies. A control that passes its own validation but sits within a governance structure that cannot detect its failure provides assurance on paper only.
What a Thematic Review of Governance Visibility Requires
SITG-Consulting's Thematic Reviews follow a five-phase model: scope, collect, analyse, report, and executive playback. The distinction from conventional audit lies in the collection and analysis phases. Where an audit collects evidence against predetermined criteria, a thematic review collects evidence across a defined theme, following the risk wherever the evidence leads.
Six examination areas structure the inquiry: governance (how decisions are made and challenged), risk visibility (whether leadership understands actual exposure), vendor capability (whether supplier claims hold under examination), control effectiveness (whether controls operate as intended in practice), operational behaviour (how teams work versus how documentation says they work), and evidence integrity (whether conclusions rest on verifiable foundations).
That final area, evidence integrity, deserves particular attention.
Evidence Integrity as a Leading Indicator
The credibility of any assurance output depends entirely on the evidence chain supporting it. A thematic review that examines evidence integrity across an organisation's cryptographic governance will surface patterns that individual control assessments structurally cannot: vendor validation reports cited but never independently verified, compliance artefacts copied forward between review periods without re-examination, and risk registers that describe theoretical exposures rather than observed conditions.
In post-quantum migration specifically, evidence integrity failures carry compounding risk. An organisation relying on a vendor's claim of PQC readiness, without independent examination of what that claim covers, inherits the vendor's risk posture without understanding it. SITG-Consulting's FIPS 140-3 Gap Analysis work routinely surfaces discrepancies between vendor-stated capabilities and what the CMVP certificate record actually validates.
The pattern is consistent: the gap is not between the control and the standard, but between what leadership believes and what the evidence supports.
Standards Alignment Without Structural Dependency
Thematic reviews derive their value from independence. The reviewer holds no vendor alignment, no platform incentive, and no commercial interest in the finding going one way rather than another. This is a structural requirement, not a preference. The moment the reviewer's commercial model depends on the outcome, the review ceases to function as independent assurance.
SITG-Consulting's thematic review methodology aligns with recognised frameworks, including SOC 2, NIST CSF 2.0, FIPS 140-3, and the Quantum Cryptographic Assurance Standard (QCAS), without depending on any of them as the sole basis for findings. Standards provide the reference architecture. The evidence provides the findings. Where these diverge, the thematic review reports the divergence rather than accommodating it.
This matters for organisations subject to overlapping regulatory expectations. DORA's ICT risk management framework requires financial entities to manage and report ICT-related incidents in ways that demand cross-functional visibility. The EU Cyber Resilience Act imposes similar obligations on manufacturers. Neither regime accepts that individual controls passing their own tests constitutes organisational assurance. Both require evidence that governance structures detect failures crossing organisational boundaries.
From Findings to Accountability
The final phase of a thematic review, the executive playback, exists because findings without ownership are findings without consequence. A well-structured thematic review produces a prioritised set of observations, each tied to evidence, each assigned to an accountable owner, and each carrying a remediation pathway with a verifiable endpoint.
This is where thematic reviews connect to board-level decision-making. Leadership does not need to understand algorithm selection. Leadership needs to know whether governance structures provide reliable visibility into cryptographic risk, whether vendor dependencies are managed, and whether evidence supporting current assurance claims is sound.
A Discovery Sprint can establish baseline visibility in a concentrated timeframe. A thematic review goes further: it examines whether that visibility is maintained, governed, and challenged over time.
The question is not whether an organisation has cryptographic controls. It is whether anyone has examined, independently and with evidence, how those controls actually behave.
Brian Couzens - CEO




Comments