Skip to content

Capture Risk Audit

Periodic audit — instantiates Capture-Resistant Institutional Design

Periodically assesses where and how strongly the institution is exposed to capture — mapping the channels of influence and scoring them against a defined risk threshold — so drift can be caught as a pattern before it becomes the culture.

Individual mechanisms watch single channels; Capture Risk Audit is the periodic sweep that puts them together. It enumerates the pathways through which the regulated class can bend the institution — information supplied only by industry, privileged access, budget dependence, shared career paths, friendly framing, borrowed legitimacy — and rates each on how much dependence, leverage, and invisibility it carries. Those ratings are then scored against a pre-set risk threshold: a line, agreed in advance, above which exposure is treated as unacceptable and must be remediated. Its distinctive move is synthesis. Where the access log holds raw contacts and the enforcement dashboard watches one lens, the audit answers the whole question — how captured are we, through which channels, and is any of them past the line we drew?

Example

A national air-quality standards body runs its capture-risk audit every second year. This cycle it inventories the channels one by one. Most sit in the green: advisory seats are balanced, meeting logs look symmetric. Two do not. Nearly all the emissions-measurement data the body relies on comes from the very manufacturers it regulates — a near-monopoly on evidence. And a rising share of its operating budget comes from permit fees paid by those same firms.

Scored against the threshold the board set years earlier, both channels land in the red. The audit's output is not a verdict of corruption but a rated map: twelve channels, two over the line, each with the dependence that put it there. That map is what lets leadership prioritize — diversify the data sources first, buffer the funding next — instead of debating capture in the abstract.

How it works

The audit's character is that it is comprehensive and periodic, not continuous:

  • Channel enumeration. It works from an explicit taxonomy of capture pathways — informational, access, financial, career, cultural, legitimacy — so no route is assessed by whether someone happened to worry about it.
  • Evidence pulled from the other mechanisms. It reads the access log, the enforcement dashboard, funding records, and staffing histories rather than gathering fresh data; it is the layer that integrates them.
  • Rate against a threshold. Each channel is scored on dependence × leverage × invisibility and compared to the agreed risk line, converting scattered signals into a small set of over-threshold flags.
  • Recommend, don't enforce. The audit hands a prioritized map to whoever can act; it diagnoses, it does not remediate.

Tuning parameters

  • Channel-taxonomy breadth — how many pathways are enumerated: the obvious money-and-meetings, or the subtle cultural and cognitive channels too. Broader catches quiet capture but adds noise and soft judgments.
  • Threshold calibration — where the acceptable-risk line sits. A conservative line catches drift early but cries wolf; a permissive one avoids false alarms but lets exposure build.
  • Cadence — fixed-interval versus event-triggered (after a major rule, a leadership change, a merger in the regulated sector). More frequent means earlier warning at higher overhead.
  • Auditor independence — self-audit versus an external assessor. External is more credible but less informed about the institution's real workings.
  • Scoring model — a qualitative red/amber/green versus a weighted quantitative index. Numbers enable trend lines but invite false precision over channels that resist measurement.

When it helps, and when it misleads

Its strength is that it turns diffuse unease into a rated, comparable map, catches capture as an accumulating pattern rather than a single act, and tells leadership which channel to close first. It is the natural feeder for an independent review when a channel goes red.

Its sharpest failure mode is that a self-audit grades its own homework: a genuinely captured institution is exactly the one that will score itself green, and its softest channels — cultural and cognitive capture — are the ones a tidy index flatters most.[1] The audit is also easily run backwards, assembled to certify an independence leadership has already decided to claim rather than to test whether it holds. The discipline that guards against this is to give the audit real independence (or an adversarial reviewer), to carry the un-scorable channels explicitly instead of rounding them to green, and to publish the map so the score can be contested.

How it implements the components

Capture Risk Audit fills the diagnostic-synthesis slice of the archetype:

  • capture_channel_map — it produces the map: the enumerated, rated set of pathways by which influence can flow.
  • capture_risk_threshold — it defines the line above which a channel's exposure is unacceptable and scores each channel against it.

It does not hold the raw contact record it draws on — that is the Privileged Access Log — nor track enforcement outcomes in detail (the Enforcement Pattern Dashboard), nor anchor the mandate it measures drift against (Sunset and Reauthorization Review).

Notes

The audit is only as good as the mechanisms that feed it: with no access log and no enforcement data, its channel scores rest on impressions, and its credibility is weakest precisely when capture is worst. Pairing it with an independent reviewer is what stops a captured institution from quietly auditing itself clean.

References

[1] The audit is built to catch what Marver Bernstein's life-cycle account of regulatory commissions describes — capture that accrues gradually as an agency ages and settles into the worldview of the industry it oversees, rather than arriving as a single takeover.