Skip to content

Cumulative Discretion Review

A governance review — instantiates Tolerance Stack Management

Reviews a whole population of individually-reasonable discretionary decisions as one shared pool of spent latitude, so that many locally-defensible exceptions do not compose into a system-level breach.

In any system that runs on human judgment, decision-makers are handed bounded discretion — an override, a waiver, an exception, a "use your judgment within policy." Each such call is examined only against its own case, where it looks defensible. Cumulative Discretion Review is the periodic governance step that stops looking at cases one at a time and instead pools the entire population of discretionary decisions, then asks whether their accumulation has pushed the system past a policy, risk, or fairness limit that no single decision violated. Its defining move is that it never re-judges any individual call as right or wrong; it treats latitude as a shared, depletable budget and holds someone accountable for the total. It is the composition problem made into a standing meeting.

Example

A consumer lender lets underwriters override the automated decision within written policy — approving a borrower slightly past the debt-to-income cutoff when compensating factors are documented. Every override is logged and, taken alone, reasonable. Over a quarter, though, overrides cluster in one product and one region, and the aggregate book quietly drifts riskier than the stated risk appetite — while every file still passed. The Cumulative Discretion Review convenes, pulls all ~600 overrides for the quarter, and buckets them by product, region, and compensating-factor type. It finds one product's override rate has consumed most of the portfolio's risk latitude. It reverses nothing. Instead it tightens the override guidance for that product, sets an aggregate override-rate ceiling, and names a portfolio owner accountable for the total going forward — turning a diffuse drift that no individual caused into an owned, bounded quantity.

How it works

The review works at the level of the population, not the case. It gathers every discretionary decision in a window, aggregates them along the lenses where deviations align (a product, a team, a customer segment, a rule that gets waived a lot), and compares the accumulated effect against a system-level envelope — a risk appetite, a fairness metric, a policy tolerance. Where a normal audit asks "was this decision correct?", this asks "did all the correct-looking decisions still add up to something the system can carry?" Its output is a change to guidance and ownership, not a reversal of past calls.

Tuning parameters

  • Cadence — how often the pool is reviewed. Frequent review catches drift early but can turn latitude into a chilling audit; infrequent review lets accumulation run.
  • Aggregation lens — which grouping the decisions are pooled by (product, officer, region, rule). The lens you don't slice by is the alignment you won't catch.
  • Inclusion threshold — what counts as "discretion" worth pooling. Set it low and the review drowns in trivia; set it high and the small, frequent waivers that actually add up slip under it.
  • Aggregate limit — the system-level ceiling the pool is checked against; too loose and it never bites, too tight and normal discretion trips it.
  • Attribution stance — whether reviewers see who made each call. Blind aggregation protects individual judgment; attributed review risks becoming a performance tribunal and suppressing legitimate discretion.

When it helps, and when it misleads

Its strength is that it catches the failure that no individual review can: a chain of locally-defensible exceptions that composes into a global breach — the fallacy of composition made operational.[1] It also converts an ownerless drift into an owned budget, which is what lets an organization keep useful discretion instead of banning it outright.

It misleads when it slides from judging the aggregate to judging individuals — the moment underwriters feel each override will be second-guessed, they stop exercising the very judgment the discretion exists for, and the mechanism defeats its own purpose. It is also easily run backwards: convened after a bad outcome to manufacture a paper trail blaming line staff for a policy the institution designed. The discipline that keeps it honest is to fix the guidance and the budget, protect individual latitude, and treat a high override rate as a signal about the policy, not a verdict on the people using it.

How it implements the components

  • exception_and_waiver_control — its core function: it treats each discretionary approval as consuming shared latitude rather than vanishing as an isolated sign-off, and controls the aggregate rather than the instance.
  • stack_owner_or_integration_owner — it names an accountable owner for the pooled effect, so the drift that "nobody caused" has somebody responsible for keeping it in bounds.

It does not measure or model how the deviations combine — the journey-level accumulation is the province of Service Deviation Journey Audit, and the shared budget itself is set and tracked by Error Budget Register and Variation Budget Allocation Sheet.

Notes

This is not a performance review, and reading it as one is the fastest way to break it. Its subject is the policy envelope and its ownership, not the competence of the people exercising discretion. Kept in that lane, it is the only sibling that governs a stack whose contributors are human judgments rather than measured parts.

References

[1] The fallacy of composition — inferring that what is true of each part is true of the whole. Every override being individually within policy does not make the portfolio within policy; the review exists precisely because that inference fails.