The consensus among corporate governance watchers is straightforward enough: general counsels have become more risk-averse. Compliance budgets have swollen. Outside counsel gets hired for everything. Board committees multiply. The logic feels ironclad—more oversight, fewer scandals, better shareholder optics.

But this consensus is too comfortable. It mistakes activity for actual risk management.

The real question isn't whether corporations are complying more thoroughly. It's whether the infrastructure built to demonstrate compliance is becoming so elaborate that it obscures the actual legal and operational vulnerabilities companies should fear most.

Consider what's happened in practice. The in-house legal department that once advised executives on business strategy has increasingly become a documentation machine. Every decision gets circled back through compliance reviews. Every email risks becoming exhibit A. The incentive structure pushes GCs toward creating paper trails that protect themselves personally rather than genuinely protecting the organization.

This isn't cynicism. It's structural. When a general counsel's performance is measured partly by "audit readiness" and "regulatory touchpoints," the temptation is to build systems that look bulletproof on paper. Risk committees that meet quarterly. Detailed compliance manuals nobody reads. Third-party audits that generate three-hundred-page reports nobody implements.

Meanwhile, the actual legal risks—the ones that emerge from how a business actually operates—sometimes go unaddressed because they don't fit neatly into the compliance framework.

Consider how corporate mergers get handled. Recent consolidation activity in healthcare and other sectors raises a straightforward question: Are the legal teams integration-focused, or are they primarily concerned with regulatory approval and carve-out documentation? These aren't the same thing. A deal can clear all the compliance checkboxes while leaving enormous operational and contractual landmines for the combined entity to navigate two years post-close.

The pressure to show "good governance" also shifts how corporations handle their biggest legal exposures. In-house teams become increasingly risk-averse about bringing problems to the surface. If a compliance concern emerges, the instinct isn't always to solve it quickly and quietly. It's to escalate, document, and create a record showing that management took it seriously. Admirable in theory. But when every internal problem becomes a potential litigation document, it changes how problems actually get solved.

This has downstream consequences that governance frameworks don't fully capture.

External counsel relationships have evolved too. The traditional relationship where outside counsel served as candid advisors has been supplemented by a vendor model where law firms increasingly exist to execute compliance programs and manage risk exposure. That's not inherently bad. But when the relationship is primarily transactional and documentation-heavy, you lose something. You lose the lawyer who pushes back on the business decision not because it creates compliance exposure, but because it's genuinely risky.

The vulnerability the current system doesn't address well is this: What happens when the compliance infrastructure itself becomes the liability? What happens when a corporation can point to an elaborate risk management framework that still failed to prevent the actual harm?

We're seeing early cracks. Some sophisticated boards are quietly moving away from compliance theater toward genuine risk assessment. Some GCs are pushing back against the documentation impulse and asking what actually needs to happen operationally. Some outside counsel relationships are being restructured to restore the advisor role.

The better question than "Are corporations more compliant?" is "Are corporations actually better protected?" And increasingly, the answer from inside legal departments is: not necessarily.

The consensus says more oversight equals better outcomes. The harder conversation is whether our governance infrastructure is solving real problems or just creating the appearance of control while genuine risks migrate elsewhere.

That's what breaks next.