Independent technical judgment is most valuable when incentives diverge.
A serious technical situation is rarely a two-party affair. The internal team, the response firm, counsel, the insurer, the board, and sometimes an acquirer or a major customer are all working from the same facts and answering different questions. None of them has to be dishonest for their conclusions to be shaped by position. That is the condition under which an outside technical view earns its cost, and the value comes from structure rather than from any claim to superior knowledge.
Same facts, different questions
The parties to a consequential technical situation are usually described as if they share an objective: find out what happened. In practice each is accountable for something narrower.
- The internal team is determining what happened and what to fix, while also being the group whose prior decisions are part of the subject matter.
- The response firm is determining what its engagement scope requires it to determine, within an agreed budget and timeline, and its report will accurately describe what it examined.
- Counsel is concerned with what is defensible, what obligations arise, and how the record will read later. What must be disclosed and when is a legal question and belongs with counsel, not with a technical adviser.
- The insurer or broker is concerned with whether the matter falls within coverage and what the quantum looks like.
- The board is deciding whether to accept a conclusion and what exposure the company is carrying.
- An acquirer or investor, where a transaction is involved, is deciding whether any of this changes price or timing.
Each of these is a legitimate question. They are not the same question, and the same evidence can support materially different emphases depending on which one is being answered.
How conclusions get shaped without anyone lying
The mechanism is not fabrication. It operates through choices that are individually defensible and collectively directional.
Scope is the largest of them. What gets examined is decided early, under time pressure, by people with a view about where the answer probably lies. A scope that excludes a subsidiary, a legacy environment, or a third-party platform will produce a report that is accurate and silent about them, and silence reads as clean unless someone insists on stating the boundary. Sufficiency is the second: the judgment that enough has been established to conclude is a judgment, and the threshold tends to sit lower for the party who wants the matter to end. Emphasis is the third: which unknowns are named prominently and which are recorded in an appendix, a compression problem examined at length in Evidence Gaps Are Findings.
There is also a straightforward asymmetry worth naming. The person best positioned to notice that a conclusion is thin is frequently the person whose work produced it, and raising it costs them time, budget, or standing. This is not a character flaw. It is a predictable feature of asking any party to grade the sufficiency of its own output, and it is the reason entire professions have built structural independence requirements rather than relying on individual integrity.
Independence is a position, not a credential
The financial reporting world settled this question decades ago and settled it structurally. Auditor independence rules do not ask whether a particular auditor is honest. They constrain economic and employment relationships, and they require independence both in fact and in appearance, on the reasoning that reliance depends on the absence of interest rather than on assurances about character.
The same logic transfers to technical conclusions and is applied far less often. A technical adviser's usefulness in a contested situation depends on whether their conclusion is load-bearing for anyone's position. If it is not, they can say the inconvenient thing at no cost to themselves, which is the entire product.
This gives the buyer a sharp test, and it is a better test than credentials: could this reviewer return a finding that costs the person who hired them, and would anything bad happen to them if they did? A firm whose larger relationship depends on the engagement continuing, a vendor evaluating its own architecture, or a team assessing the adequacy of work it performed can all be entirely competent and still fail that test.
When to buy an outside view, and when not to
Independence is not free and it is not always warranted. The conditions that justify it are reasonably specific:
- The conclusion will be relied upon by someone outside the group that produced it: a board, a regulator, an insurer, a customer, an acquirer.
- Revising the conclusion would be costly for whoever produced it, in budget, timeline, or standing.
- Competent people are producing materially different technical answers, and the disagreement is not resolving.
- The decision is difficult to reverse: a disclosure, a closure, a price, a signed commitment.
- The scope of what was examined was set by a party with an interest in where it ended.
Where none of these hold, an outside view is usually a waste. If the technical answer is uncontested, if the stakes are ordinary, or if the internal team has no stake in which way the answer comes out, the internal answer is likely the best available and buying a second one purchases reassurance rather than information.
The claim has to be testable in both directions
An adviser who sells independence is making a claim about themselves, and by the standard of this corpus a claim is not evidence. Three things make it checkable rather than rhetorical.
Disclosure of anything that could bear on the conclusion, including commercial relationships and prior work with any party, stated before the engagement rather than discovered during it. Declining the work where independence cannot honestly be maintained, which is the only version of the commitment that costs anything. And a demonstrated willingness to return conclusions that satisfy nobody, including "the evidence does not support this conclusion yet, and here is what would be required." An adviser whose findings always align with what the commissioning party appeared to want is providing a service, and it is not this one.
The strongest objection
The credible objection is that outsiders lack context. The internal team knows the architecture, the history, why decisions were made, and which oddities are normal for this environment. An outsider arrives without that and can produce findings that are technically defensible and practically naive, at real cost in time and credibility.
That is correct and it constrains how independence should be used. Independence is not a substitute for competence or context; an uninformed outside opinion is worse than an informed inside one, and an independent reviewer who cannot follow the engineering discussion adds noise. The argument is that the two are different inputs and the inside view is structurally constrained in one specific respect: it cannot neutrally assess its own sufficiency. The useful arrangement is not replacing the internal analysis but testing the parts of it that the internal position makes hardest to test, which is a narrower and more respectful engagement than it is often assumed to be.
What good looks like
In situations handled well, several things are visible. The boundary of what each party examined is written down and known to the people relying on it. Somebody has explicitly asked which question each party was answering, rather than assuming a shared one. Where an independent view was commissioned, its scope was set by the party carrying the accountability rather than by the party whose work is under review. And the possibility that the outside conclusion will be unwelcome was accepted at the outset, which is the only condition under which a favorable conclusion means anything.
Conclusion
Multi-party technical situations do not fail because someone lies. They fail because several honest parties answer several different questions from the same evidence, and the composite gets read as if it answered one. The value of an independent technical view is that its conclusion is not load-bearing for any of those positions, which is why it can be wrong in the expensive direction without consequence to the person delivering it. That property is structural, it is testable before the engagement starts, and it is worth paying for precisely when revising the current answer would be costly for whoever produced it.
Related: The Incident Is Contained. That Does Not Mean It Is Closed., on the specific decision where these divergent questions most often collide.
Being asked to accept someone else's conclusion?
The Incident Closure Review is the version of this built for incidents: an independent examination of the investigation record, the scoping decisions, the evidence behind each conclusion, and what remains open, delivered as a written determination the board can rely on. Typically $20,000 to $30,000+ depending on scope. The same structure applies to contested technical conclusions in transactions and disputes.
Know a GC or director weighing a technical conclusion produced by a party with something riding on it? Send them this note.
Sources
- U.S. Securities and Exchange Commission, Regulation S-X, Rule 2-01, Qualifications of Accountants. Cited for the established principle that independence is assessed structurally, through relationships and interests, and is required both in fact and in appearance rather than being satisfied by assurances of integrity.
- National Institute of Standards and Technology, SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management, April 2025. Cited for the role of coordination among internal and external parties during incident response, including legal and third-party involvement.
Nothing in this note is legal advice. Questions of disclosure obligation, privilege, and regulatory exposure belong with qualified counsel.