The Good Place Has a Point System. We Don’t.
If you’ve ever watched The Good Place, you know the setup: every action you take in life, good or bad, gets a number attached to it, and at the end you get sorted accordingly. Steal a car, lose points. Help an old lady cross the street (for the right reasons, not for the Instagram post), gain points. It’s a tidy, seemingly satisfying system. Chidi, the resident moral philosophy professor, spends four seasons trying to figure out whether Aristotle or Kant had it right, all while the rest of us watch and think, “must be nice to have a scoreboard.”
Here in the real world of governance, risk, and compliance, we don’t get a scoreboard. Nobody pings you mid-assessment to say “hey, that little shortcut you just took on the evidence review just cost you four points” (I’m referring to cosmic, existential points; I haven’t forgotten about SPRS, you CMMC nerds.) The temptation is there, the opportunity is often there too, and the only thing standing between a shortcut and a real ethical failure is you and your team.
I’ve been thinking about this a lot lately, partly because our industry talks constantly about frameworks, controls, and assessment methodologies, but rarely stops to ask the more foundational question: why does any of this matter ethically in the first place? So, in this blog, I want to walk through the common temptations we face in GRC work, the basic ethical commitments that should be the foundation for everything we do, where those commitments actually come from (spoiler: further back than most of us realize), and how professional codes of conduct like the CyberAB’s Code of Professional Conduct fit into that bigger picture.
Cutting the Corner You Think Nobody Will Notice
Let’s start with the temptations, because pretending we don’t face them doesn’t help anybody. If you’ve spent any real time in the trenches of compliance and security work, you’ve either faced these yourself or watched a colleague wrestle with them.
There’s the temptation to soften a finding because the client is frustrated and you’d rather keep the relationship smooth than deliver an uncomfortable truth. There’s the temptation to mark evidence as sufficient when it’s really just adequate, because you’re behind schedule and the deadline doesn’t care about your integrity. There’s the temptation, especially for consultants who also do assessment adjacent work, to blur the lines of independence because the extra engagement is good for revenue. There’s the quieter temptation of just not knowing something and bluffing your way through an answer rather than saying “I’m not sure, let me find out,” because admitting a gap feels like it costs you credibility in the room.
None of these seem to be dramatic villain moves. Nobody wakes up plotting fraud. They’re small, reasonable sounding compromises that stack up, one on top of another, until the person doing them notices they’ve seriously drifted. That’s what makes them dangerous. Ethical failure in white collar work rarely looks like a heist movie. It looks like a hundred tiny “close enough” decisions.
The Basics We Shouldn’t Need to Say Out Loud
Before we get philosophical, let’s ground this in the obvious stuff, because the obvious stuff still needs saying. Compliance and security professionals are, at minimum, obligated to be honest in what they report, competent in what they claim to know, careful with the confidential information they’re trusted with, and consistent in applying standards regardless of who’s sitting across the table. That’s the floor, the basics, and the non-negotiables.
The question I want to sit with is “why?”. Why is honesty actually binding on us, and not just a nice preference some committee wrote into a handbook? That question matters more than it sounds, because if ethics is just a preference, it bends the moment it’s inconvenient.
This is where I want to bring in Thomas Aquinas. Aquinas argued that there’s a natural law written into the structure of human reason itself, something every person has access to simply by being rational, regardless of their religious background or worldview. His famous first precept of natural law is deceptively simple: good is to be done and pursued, and evil is to be avoided. From that starting point, Aquinas argued that certain moral truths become self-evident to anyone who reasons honestly about human flourishing: don’t lie, don’t steal, keep your word, treat people justly. He called our built-in grasp of these basics synderesis, essentially a moral compass baked into human nature rather than bolted on afterward by culture or law.
Here’s why that matters for us. You don’t have to share Aquinas’s theology to notice that his conclusion tracks with what nearly every worldview, religious or secular, independently lands on. Confucian ethics, Stoic philosophy, secular humanism, and most major religious traditions all converge on some version of “don’t deceive people” and “keep your commitments.” That convergence is the point. It suggests these aren’t arbitrary cultural preferences we happened to inherit and it’s up to you to determine the epistemological backing for the different world-views on your own time. These principles are closer to discoveries, truths about how humans are built to live well together, that show up again and again because they’re actually true.
That has a direct payoff for GRC work. When you’re tempted to fudge a finding, you’re not just risking a violation of some framework’s Trust Services Criteria or an assessment objective in NIST SP 800-171. You’re pushing against something more basic than any framework, something that predates ISO 27001 by a very long time.
Practice Makes… Virtuous?
Now let’s bring in Aristotle, because Aquinas tells us what the basic moral truths are and how to surmise them, but Aristotle tells us how a person actually becomes the kind of person who lives them out consistently.
Aristotle’s whole ethical project in the Nicomachean Ethics is built around the idea that virtue isn’t something you’re born with, it’s something you build through repetition. He used the word hexis, meaning a settled habit or disposition, to describe how virtue works. You don’t become honest by reading a definition of honesty. You become honest by choosing the honest answer over and over, in small moments, until it stops requiring a fight and starts being who you are. The same goes for courage, temperance, and justice. Virtue is a muscle, not a light switch.
Aristotle also gave us the doctrine of the mean, the idea that virtue sits between two extremes. Courage sits between cowardice and recklessness. Diligence in reviewing evidence sits between negligent shortcuts and paralyzing perfectionism that never actually finishes an assessment. And he insisted that all of this requires phronesis, practical wisdom, the skill of figuring out what the right action actually looks like in this specific, messy, real situation rather than in the abstract.
Here’s why this matters for those of us in white collar, often unseen work. Nobody’s watching most of what a GRC professional does. Nobody sees the extra hour spent verifying an artifact instead of taking the client’s word for it. Nobody applauds when you tell a difficult truth in a report instead of softening it into meaninglessness. Aristotle would say that’s exactly the point. Integrity, from the Latin root meaning wholeness, is what you are when nobody’s grading you. Hard work and honest work in the dark are precisely how virtue gets built, one unseen, unglamorous choice at a time. You’re not just doing your job. You’re becoming someone.
The Codes We Didn’t Invent, We Just Wrote Down
This brings us to the professional codes of conduct our industry actually operates under, and here’s the thing I want you to notice: none of them invented ethics, obviously. They codified what natural law, virtue ethics, and other ethical systems already pointed to, and gave it enforcement teeth.
The CyberAB’s Code of Professional Conduct lays out eight guiding principles for CMMC ecosystem members: professionalism, impartiality, confidentiality, information integrity, lawful and ethical behavior, equal opportunity, proper use of CMMC methods, and proper use of technology and AI. Read through those and you’ll recognize Aquinas’s honesty and justice, and Aristotle’s practical wisdom about staying within appropriate limits, showing up in modern, assessment specific language.
ISC2’s Code of Ethics, binding on every CISSP and other certified professional, boils down to four canons: protect society and the infrastructure, act with integrity, provide competent service to those you serve, and advance the profession. ISACA’s Code of Professional Ethics runs longer, covering governance support, professional conduct, confidentiality, competence, and transparent reporting. Different organizations, different wording, remarkably similar substance.
That’s not a coincidence, and it’s not because these bodies necessarily copied each other. It’s because they’re all reaching for the same underlying reality many were describing centuries earlier. The codes are useful. They give us shared language, accountability structures, and a way to hold each other to account. But they’re downstream of something deeper, not the source of it. A code of conduct can tell you what to do. It can’t make you the kind of person who wants to.
The Intelli Way: Aiming for Excellence, Not Just “Met”
Here’s where I’ll get specific instead of staying up in the philosophical clouds, because none of this means much if it doesn’t show up in how a firm actually operates. At IntelliGRC, we’ve got a principle we live by internally, we call it the Intelli Way. It sounds like something you’d see on a poster in a break room, but the substance behind it is pretty simple: we don’t take shortcuts, we’re strive to be honest even when it costs us, and we do things Intelligently. Think of it as a smarter, not harder approach with a huge emphasis on empathy and integrity.
That shows up most clearly in how we advise clients on implementation, not just assessment. One of the mottos we repeat constantly on our team is this: let’s do things in such a way that causes the assessor to ask fewer questions instead of more. That’s not about gaming an assessment or hiding weaknesses behind polished documentation. It’s the opposite. It means implementing a requirement so thoroughly and so thoughtfully that when an assessor looks at it, there’s nothing left to dig into, not because you buried the evidence, but because you did the work well enough that the obvious follow-up questions already have obvious answers sitting right there in front of them. We really try to advise these customers to align their culture with this approach, hence why our advisory work is very pedagogical, meaning, that we really try to teach as we go.
If that sounds a lot like Aristotle’s arete, that’s because it is. Arete doesn’t just mean “good enough,” it means excellence, the full realization of what something is meant to be. A requirement marked “Met” because you technically checked a box is a very different thing from a requirement implemented so well that it actually accomplishes what it was designed to do. Aquinas’s first precept says good is to be pursued, not just that evil is to be avoided. The Intelli Way tries to live in that pursuit rather than settle for the avoidance.
We’ll say this plainly: we’re not perfect, and no firm or professional in this industry is. But we strive for perfect anyway, because the alternative, aiming for “just enough to pass,” isn’t a posture that produces trustworthy security programs or trustworthy people. It’s a posture that produces exactly the kind of drift we talked about earlier in this article.
So What Do You Actually Do With All This?
When you’re staring down a tempting shortcut in an assessment, a report, or a client conversation, remember three things. First, the basic moral truth you’re weighing (don’t deceive, keep your word) isn’t just a corporate policy, it’s closer to bedrock, recognized across just about every worldview humans have ever held. Second, every time you choose the honest, diligent path instead of the easy one, you’re not just avoiding a violation, you’re building the kind of character that makes the next hard choice easier and makes you the professional someone can trust. And third, the professional codes you’re certified under aren’t arbitrary hoops. They’re the industry’s attempt to write down what good practical wisdom already displayed.
None of this makes the work easier in the moment, but having an ethics-based view of things and being able to answer the “why?” behind the ethical decisions we each make will make for a better industry with better security and integrity.
If you’re building out a GRC program and want a team that treats these questions as more than theoretical, we’d love to talk. IntelliGRC exists because we believe compliance done well is compliance done honestly, one unglamorous, unseen decision at a time. We call it “The Intelli Way.”
As always, Happy Implementing!
Steven Molter
Connect with me on LinkedIn if you want to keep the conversation going!
Frequently Asked Questions
Why does ethics matter in GRC and compliance work specifically?
Compliance and security professionals are regularly trusted with confidential information, asked to attest to what they’ve verified, and put in situations where a shortcut is easy and unlikely to be caught. Ethics in GRC isn’t an abstract add-on, it’s the thing that determines whether a finding, an attestation, or an SSP entry is actually trustworthy.
What is natural law ethics and why is it relevant here?
Natural law, as Thomas Aquinas described it, is the idea that certain moral truths (like the obligation to be honest and keep your word) are accessible to human reason itself, regardless of religion or worldview. It matters for GRC because it explains why honesty in an assessment isn’t just a policy preference, it’s something closer to bedrock.
How does Aristotle’s virtue ethics apply to compliance professionals?
Aristotle argued that virtue is built through habituation (hexis), not declared all at once. Applied to GRC work, that means integrity is built through the small, unseen choices made in day-to-day circumstances and not just through a single big decision.
Do certification bodies like the CyberAB, ISC2, and ISACA all have their own codes of ethics?
Yes. The CyberAB’s Code of Professional Conduct lays out eight principles for CMMC ecosystem members, ISC2’s Code of Ethics is built on four canons for certified professionals like CISSPs, and ISACA’s Code of Professional Ethics covers seven obligations for its members. The wording differs, but the substance overlaps significantly.
What is the “Intelli Way”?
The Intelli Way is IntelliGRC’s internal standard for doing GRC work ethically and above the bare minimum. It means not taking shortcuts, being honest even when it costs us, and implementing requirements thoroughly enough that an assessor is left with fewer questions instead of more, all in pursuit of excellence rather than the bare minimum needed to pass.
Does a professional code of conduct replace the need for personal ethical formation?
No. Codes of conduct give the industry shared language and enforcement mechanisms, but they codify ethical principles rather than create them. They can tell a professional what to do, but they can’t make someone the kind of person who wants to do it.
