The thesis
The gap between compliant and defensible.
The gap between compliant and defensible is not a legal abstraction. It is an operating condition.
Compliance shows that rules were followed.
Defensibility shows what the organisation knew, what it decided, and why.
A compliant organisation may be able to produce policies, procedures, certificates and audit records. A defensible organisation can also reconstruct the product story across its lifecycle: the signals it received, the decisions it made, the evidence it retained and the authority under which it acted.
Why the distinction matters
When an incident, claim or regulator arrives, the question is rarely limited to whether a document existed.
The harder questions are:
- What did the organisation know at the time?
- Which signals were available?
- Who had authority to act?
- How were conflicting assessments resolved?
- What decision was made?
- What evidence supports that decision?
- Can the sequence be reconstructed reliably under scrutiny?
These questions cross traditional organisational boundaries. Product safety, quality, legal, regulatory, cybersecurity, software, procurement, engineering, customer service and post-market activity may each hold part of the relevant evidence.
Defensibility depends on connecting those parts before an incident forces the reconstruction.
From records to evidence
Records become defensible evidence when they are:
- accurate;
- attributable;
- contemporaneous;
- connected to the relevant product and decision;
- retained for the necessary lifecycle;
- accessible when required;
- understood in their organisational context.
More documentation does not necessarily create greater defensibility. A large volume of disconnected records can make the underlying decision harder to establish.
The objective is not simply to retain more data. It is to preserve the evidence needed to explain what happened and why.
From signals to intelligence
Most organisations do not lack product data. They lack the ability to connect it.
A complaint may sit in customer service. A vulnerability may sit in cybersecurity. A supplier deviation may sit in quality. A field issue may sit in service. A regulatory interpretation may sit in legal.
Individually, each signal may appear below the threshold for action.
Together, they may describe a materially different product risk.
Product intelligence is the organisational capability to identify those relationships, interpret their significance and place them before the people with authority to decide.
Governance before dashboards
The first governance question is not which dashboard to build.
It is:
- who owns the product story;
- who can see across functions;
- who decides when evidence is incomplete;
- who resolves conflicts between commercial, technical, legal and safety priorities;
- who records the decision;
- who ensures that the evidence remains available.
Technology can support that operating model. It cannot substitute for it.
The Readiness Directive position
The Readiness Directive examines what organisations must be able to see, govern, evidence and defend across the product lifecycle.
Its central proposition is straightforward:
Compliance shows that rules were followed. Defensibility shows what the organisation knew, what it decided, and why.
This does not replace legal, regulatory, technical or compliance advice. It provides an analytical framework for understanding the organisational capabilities increasingly required by product-safety, cybersecurity, AI and product-liability regimes.