When Everyone Knows Something, But Nobody Knows Everything
Nobody in the organisation was completely unaware.
Finance had noticed the payments. Procurement had concerns about the supplier. Compliance had received a disclosure. Internal audit had flagged an unusual pattern.
Yet nobody had the full picture.
By the time someone finally connected the dots, the organisation was no longer dealing with a collection of minor concerns. It was dealing with a problem that had been sitting in plain sight.
This is not a story about incompetence. Each person did roughly what their job description asked of them. Finance processed and queried. Procurement questioned and documented. Compliance logged a disclosure and moved to the next item. Internal audit noted an exception and scheduled a follow-up review. Individually, every action was defensible.
The failure was not in any one department. It was in the space between them.
Where information goes to die
Ask a finance manager, a procurement officer and a compliance lead in the same company what they know about a specific supplier, and you will often get three different, incomplete answers. Finance knows the payment history. Procurement knows the contracting relationship. Compliance knows whether anyone has ever raised a concern. Nobody has all three.
This is not usually because people are hiding information from each other. Most employees genuinely believe that what they have seen belongs to another department, and that flagging it upward within their own reporting line is enough. A procurement officer who spots an unusual supplier relationship reasonably assumes finance would catch anything wrong with the payments. Finance, seeing an odd transaction, assumes procurement already vetted the supplier. Each function trusts that someone else is watching the part of the picture they cannot see.
That trust is often misplaced, not because colleagues are careless, but because nobody has been given responsibility for the whole picture. Departmental structure was built to divide work efficiently. It was not built to detect patterns that only become visible when information from several departments sits next to each other.
What happens on the way up
Reporting lines are supposed to move information to someone with the authority to act on it. In practice, information often gets thinner as it climbs.
A junior employee raises a concern with a direct manager. That manager, who may have limited authority to investigate and a strong interest in keeping their own department looking well run, decides how much of the concern to pass upward, in what language, and with what urgency. By the time a board or executive committee hears about it, if they hear about it at all, the concern may have been summarised into something that sounds far less serious than it did at the point it was first raised.
This is rarely deliberate concealment. It is closer to a filtering effect that happens naturally as information moves through layers of management, each one applying its own judgment about what deserves attention above it. An anomaly becomes an administrative issue. A concern becomes a misunderstanding. A repeated exception becomes a business requirement that everyone has simply learned to work around. None of these reframings are dishonest on their own. Collected together, they can quietly erase the significance of what was originally reported.
The question worth asking is not whether your reporting lines move information upward. Most do. The question is whether they move it to someone positioned to see it alongside everything else, or simply to the next manager in the chain.
Systems that never talk to each other
The same fragmentation exists in data as it does in people. Supplier records sit in the procurement system. Payments sit in the finance system. Employee relationships and conflicts of interest, where they are recorded at all, sit with HR. Complaints and disclosures sit with compliance. Delivery and performance information sits with operations.
Each system, examined on its own, tends to look unremarkable. A supplier with a slightly unusual ownership structure is not automatically suspicious. A cluster of exceptions in one region is not automatically fraud. A single disclosure without financial detail attached to it is not automatically evidence of anything. The risk only becomes visible when these separate, individually explainable data points are placed next to each other and a pattern emerges that no single system was built to show.
Very few organisations routinely compare these systems against each other outside of a formal investigation. That means the connection usually gets made only after something has already gone wrong badly enough to justify bringing in forensic investigators, whose entire method is built around doing exactly this: taking information that looked unrelated in five separate places and asking what it means when it is read together.
Whose problem is it
Narrow definitions of responsibility compound the fragmentation. A procurement officer who identifies an unusual supplier is not typically expected to trace the payments attached to that supplier. Finance staff who notice an unusual transaction pattern are not typically positioned to know whether the recipient has any relationship with an employee. Compliance may receive a disclosure with no visibility into the financial pattern sitting behind it in another department entirely.
Each person can honestly say the matter was outside their remit. That may be true of their formal job description. It is rarely true of the organisation as a whole, because somebody, somewhere, needs to own problems that cross functional boundaries. If nobody has that mandate explicitly, the honest answer to “whose problem is this” is often nobody’s, right up until it becomes everybody’s.
Escalation without a trigger
A concern does not need to be proven to deserve attention. There is an important difference between an allegation, a red flag and established misconduct, and organisations that treat all three the same way tend to either escalate everything, which exhausts the people meant to respond, or escalate almost nothing, because employees are unsure whether what they have noticed clears the bar.
Clear escalation thresholds matter more than most governance frameworks give them credit for. Employees need to know what kind of observation must be escalated, to whom, and what happens once it lands on that person’s desk. Without that clarity, judgment calls about seriousness get made informally, inconsistently, and usually by the person with the least authority to make them.
More reports is not the answer
It would be easy to conclude that the solution is more reporting, more committees and more paperwork. It is worth resisting that conclusion. A board can receive twenty separate reports in a single sitting, from finance, risk, compliance, internal audit, HR and operations, and still miss the one pattern connecting three of them, because each report was built to stand alone.
Effective governance is not about the volume of information reaching the top of the organisation. It is about whether that information is structured, and whether someone has the mandate to look across it rather than within a single function. Very few organisations have that role clearly assigned. Fewer still have tested whether it actually works before a crisis forces the question.
The national conversation
South Africa has spent much of the past year watching a version of this problem play out at national scale. The Madlanga Commission, established in July 2025 to investigate the infiltration of criminal networks into policing, intelligence, prosecutorial and other justice system structures, delivered an interim report in December 2025 that referred a number of officials for further investigation.
The details of that inquiry are a matter of public record and not the subject of this article. What it offers every board and executive team is a large-scale illustration of what can happen when information that could have been connected earlier is instead left sitting in separate parts of a system. Fragmented information is not unique to state institutions. It is a feature of how most organisations are built.
The question worth sitting with
The organisation should not have to wait for a forensic investigation to discover that five different people had already seen five different pieces of the same problem.
If five people in your organisation each knew something important about the same problem, would anyone know enough to put it together?
Effective oversight was never simply about ensuring information gets reported. It is about ensuring the right information reaches the right people, gets connected across the boundaries departments naturally create, and triggers action before the pieces become a crisis. The five people in your organisation who already know something are not the risk. The space between them is.
