In February 2023, the SEC fined a major asset manager $35 million for ESG-related misstatements — not because the firm's ESG practices were deficient, but because they could not substantiate their claims with verifiable, auditable evidence. The regulators did not dispute the company's intent. They disputed its proof.
This is the emerging shape of regulatory risk in the compliance era: it is no longer enough to be compliant. You must be demonstrably, verifiably, and continuously compliant. The difference between those things is larger than most compliance programmes currently acknowledge.
Trust scores — whether they represent cybersecurity posture, ESG performance, third-party risk, or financial resilience — are increasingly part of regulatory conversations. How you present them, and what you can show behind them, determines whether those conversations go smoothly or become investigations.
What regulators actually want to see
Regulatory examiners are not looking to be impressed by large numbers. They are looking for three specific things, in roughly this order of priority:
- Provenance. Where does the data come from? Is the source reliable and verifiable?
- Methodology. How is the score calculated? Can it be replicated? Is the weighting defensible?
- Continuity. Is this score current? How often is it updated? What triggers a recalculation?
A single number — even a high one — answers none of these questions on its own. What regulators want is the number plus the chain of evidence that produced it. Without that chain, a score is an assertion. Assertions invite scrutiny. Evidence closes it.
"The moment you can explain your trust score to a regulator, you've changed the conversation entirely. You move from defence to demonstration."
The layers of a defensible trust posture
Over the course of working with enterprises across financial services, healthcare, and critical infrastructure, we have identified a consistent pattern in the compliance postures that hold up best under regulatory examination. They share three properties:
1. The score is honest about what it actually measures
The biggest credibility risk in a trust score is not a low number — it is a number that cannot withstand the question "how was this calculated, and from what?" A score built almost entirely from things a company can simply acquire — certificates, policy documents, signed attestations — is vulnerable under questioning, because an examiner can reasonably ask whether the underlying practice matches the paperwork.
This is why we built SignalScore™ around a single governing rule: score what a company cannot buy from an auditor. Every input is sorted into one of three classes by how hard it would be to fabricate — credentials a company can acquire or write, behavioral evidence of what it actually did (remediation speed, disclosure, maintenance cadence), and externally observable signal it never gets to author at all. Credentials are the floor. They are necessary, never sufficient, and they are deliberately capped from dominating the number. A score where the largest share comes from things you can purchase is a score that invites exactly the scrutiny you're trying to avoid.
2. Every score-affecting input is attributable, time-bound, and disputable
Regulators do not want a single number. They want to know what moved it. A defensible score breakdown names the exact event or finding behind every point gained or lost — "minus four points: open critical vulnerability in a named subprocessor" — rather than a vague reference to "external risk factors." Each penalty should display its own decay schedule, so an examiner can see not just what happened but how and when it resolves.
Just as importantly, the rated company needs a real channel to dispute an input it believes is wrong — a misattributed finding, an already-patched vulnerability, a stale subprocessor relationship. Opening a dispute should suspend that input's effect on the score pending review, not just log a complaint into a void. This is not a courtesy feature. It is closely aligned with the U.S. Chamber's Principles for Fair and Accurate Security Ratings and with FCRA-style rated-entity rights, and building it in from the start is the difference between a rating system regulators trust and one they investigate.
3. Disclosure is the rewarded path, not the risky one
The most counterintuitive — and most defensible — property of a well-built score is that it does not treat "zero findings" as the maximum possible result. A company that discloses a pentest finding and closes it quickly should outscore a company that shows nothing at all. Concealment should earn, at most, partial credit for coverage; it should never earn the credit for speed or candor. When you can show a regulator that your own scoring model structurally rewards disclosure over silence, you have pre-empted the most common line of regulatory suspicion before it is raised: that a clean-looking number is hiding something.
Before any regulatory conversation, ask yourself: if an examiner asked me to reconstruct exactly how we arrived at our current score — which inputs, what class each belongs to, what decayed and what didn't — could I do it in this room, today, without preparation? If the answer is not a confident yes, your posture needs work.
Preparing for a regulatory conversation: a practical sequence
- Classify your own signals Sort every input feeding your trust score into attested, behavioral, or verified. If attested credentials make up the majority of your score, that imbalance is itself a finding worth fixing before a regulator points it out.
- Document your methodology in plain language Write a one-to-two-page description of how your score is calculated: which signals carry what weight, how disputed inputs are handled, and who is responsible for maintaining the methodology. This document should survive personnel changes.
- Make every penalty attributable and time-bound Every score-affecting event should name itself in the breakdown and carry a visible decay schedule. A regulator should never have to ask what an unexplained deduction was for.
- Stand up a real dispute path Give the rated entity — yourself, or your vendors, depending on which side of the conversation you're on — a way to flag an input as inaccurate, with the input's effect suspended pending review. Log every dispute.
- Produce a Dossier for regulatory audiences Create a structured, audience-controlled document that presents your trust posture to regulators specifically — with the appropriate level of evidence detail, access controls, and supporting artefacts attached to each claim.
- Run a pre-examination dry run Simulate the conversation. Have someone unfamiliar with the day-to-day of your compliance programme ask the questions a regulator would ask. Where the answers feel thin or require preparation, that is where to invest.
What changes when you can actually show your work
Organisations that have invested in a score built this way report a consistent shift in the character of their regulatory interactions. Examinations become shorter. Requests for additional documentation decrease. The conversation shifts from the regulator seeking to establish what you cannot prove, to the regulator reviewing what you have already provided.
This is not regulatory theatre. Examiners are experienced readers of compliance documentation. They know the difference between a posture that was assembled for the examination and one that is maintained as a live operational practice. The former invites further questioning. The latter tends to close conversations.
The regulatory environment around trust, compliance, and third-party risk is tightening. The SEC's climate disclosure rules, the EU's DORA requirements for financial services, and evolving guidance under GDPR all point in the same direction: assertions are insufficient; evidence is required; and the evidence must be continuous, not retrospective.
Building a trust posture that is genuinely defensible under scrutiny is not a compliance project. It is an operational investment with commercial returns — in faster sales cycles, fewer procurement delays, and regulatory conversations that close rather than escalate.
Show your work. Not because a regulator asked you to. Because doing so is what separates the organisations that trust creates value for from those that compliance creates costs for.