Skip to content

Post-Exit Dependency Audit

Forensic audit — instantiates Dependency-Capture Exit Design

A follow-up audit, run after exit, that checks whether the old dependency has quietly re-formed and protects those who report it.

Version
v1 · 2026-08-24 · History
Mechanism #
6426
Type
Forensic Audit
Form family
Assessment, Review & Assurance
Solution family
Boundary & Scope Control
Problem family
Incentive Conflict, Gaming & Collective-Action Failure
Problem subfamily
Delegated Interest Conflict & Capture
Origin domain
Organizational & Management Science
Also from
Law & Governance
Instantiates
Dependency-Capture Exit Design

An exit that looks clean on the day of handover can silently unravel in the months after, as the old dependency creeps back under new names — a "temporary" re-engagement, an "advisory" call that becomes weekly, a successor who quietly forwards every hard case back to the departed incumbent. Post-Exit Dependency Audit is the forensic check run after the exit is supposedly complete, to detect exactly this recapture. Its defining property is that it is a retrospective, point-in-time investigation of an exit already made — it does not decide whether to exit, and it does not track a live reduction trend; it goes looking, at 6 or 12 months out, for evidence that independence held or quietly failed. Because recapture is often hidden by the very people who benefit from it, the audit pairs its forensic look with a protected channel through which insiders can report what the paperwork conceals.

Example

A large firm spent two years and considerable expense "insourcing" a strategy function it had long outsourced to a consultancy, declaring at handover that it no longer depended on external advisers. A year later, the board commissions a Post-Exit Dependency Audit. The auditor — reporting to the audit committee, not to the executives who ran the insourcing — pulls the evidence: invoices, calendar patterns, and the provenance of major decisions.

It finds the exit reversed in all but name. The same consultancy's partners now appear as "independent advisers" on retainer; several ex-consultants were hired and still route the real analysis back to their old firm — a textbook revolving door[n1]. Junior staff had noticed but feared their managers, who were championing the "successful" insourcing. The audit's protected reporting channel is how that got surfaced: two analysts described the pattern under a non-retaliation guarantee. The audit re-verifies, independently, that the underlying need is not in fact being met in-house — and hands the board the evidence to act.

How it works

  • Look after the fact, at the recapture. The audit is scheduled at intervals after handover and specifically hunts for signs the old dependency re-formed — renewed engagements, back-channeling, decisions still originating with the departed party.
  • Re-verify the need independently. It re-tests, from a disinterested stance, whether the underlying need is genuinely being met without the old role — closing the gap between "we exited" and "the need is actually covered here now."
  • Protect the reporters. It runs a channel — anonymized or non-retaliation-guaranteed — through which insiders can report recapture or quiet sabotage they would never raise openly, because those who benefit from recapture usually outrank those who notice it.
  • Distinguish drift from sabotage. It reads the pattern for intent: honest relapse for lack of capacity looks different from deliberate re-entrenchment by someone reclaiming an indispensable role, and the remedies differ.

Tuning parameters

  • Timing and repetition — a single check at 12 months vs. several over years. Repeated audits catch slow recapture but cost attention and can feel like distrust; a single check is cheap but easy to survive by lying low.
  • Reporting-line independence — who the auditor answers to. Reporting to a body independent of the exit's champions is essential; reporting to those champions guarantees a clean bill.
  • Channel protection strength — from a named "open door" to true anonymity with anti-retaliation enforcement. Stronger protection surfaces more but is costlier to run credibly; weaker protection yields silence.
  • Evidence reach — how far the audit can pull records (invoices, calendars, decision provenance). Broad reach detects disguised recapture; narrow reach sees only what the recapturers chose to document.

When it helps, and when it misleads

Its strength is catching the failure the celebration hides: recapture is often invisible precisely because the people positioned to relapse are the ones writing the status reports. An independent audit with a protected channel gets past that, and its mere existence deters the "quiet re-hire" because someone can safely tell. It also cleanly separates honest relapse (fix the capacity gap) from deliberate sabotage (a governance problem).

Its failure mode is the toothless audit: independent on the org chart but starved of records, or offering a "confidential" channel everyone knows is not, so it certifies a clean exit that has in fact reversed — worse than no audit, because it launders the recapture. A classic misuse is scheduling it once, briefly, right after handover, before recapture has had time to form. The guard is genuine reporting-line independence, enforceable non-retaliation, and timing the look for when relapse would actually have surfaced.

How it implements the components

  • recurrence_and_sabotage_monitor — it is the after-the-fact detector for the old dependency re-forming, reading the evidence for both honest relapse and deliberate re-entrenchment.
  • challenge_and_whistleblower_protection — it provides the protected channel through which insiders can report recapture without retaliation, surfacing what records hide.
  • independent_need_verification — it re-tests, from a disinterested stance, whether the need is truly being met without the old role, rather than trusting the "we exited" narrative.

It does not track the reduction as a continuous in-flight trend, nor read the live pathway map during the program (durable_resolution_metric, dependency_pathway_map) — that's Dependency-Reduction Scorecard; this audit is a retrospective forensic look at an exit already made, not the running gauge.

Editorial Notes

Form Classification

Form family: Assessment, Review & Assurance

Rationale: Post-Exit Dependency Audit operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it a follow-up audit, run after exit, that checks whether the old dependency has quietly re-formed and protects those who report it.

Independent corroboration: The frozen evidence defines Post-Exit Dependency Audit as 'A follow-up audit, run after exit, that checks whether the old dependency has quietly re-formed and protects those who report it', so its operative form is Assessment, Review & Assurance.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Organizational & Management Science

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Checking whether an exited organizational dependency has quietly re-formed is a governance and vendor-management practice.

Related originating lineages:

  • Law & Governance — Law contributes non-retaliation, exit rights, and protection for reporters.

Review resolution: Both blind reviewers agree that organizational management is the primary origin. Reconciliation resolves reported ambiguity. Formative alternate lineages are retained as law_governance; later breadth of use is recorded separately as domain_reach=multi_domain, while origin_mode=cross_disciplinary_synthesis describes the relationship among origin lineages.

Attribution caveat: The mechanism generalizes multiple exit-audit settings under one new label.

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Reconciled after independent review; medium confidence.

Notes

[n1] The revolving door — the movement of individuals between an organization and the outside party it deals with (regulator↔industry, buyer↔vendor), such that a formal separation is undone by personal relationships and continued influence. It is a principal vector by which a supposedly-ended dependency quietly re-forms.