Skip to main content
Red Rock Compliance

The Sedona Compliance Checklist: 8 Red Rock Filters for Modern Professionals

Compliance work is rarely about knowing the rules alone. It is about applying them consistently when deadlines loom, data is incomplete, and stakeholders disagree. The Red Rock Compliance approach offers a set of mental filters—eight of them—that help professionals check their decisions against common failure modes. This article turns those filters into a practical checklist you can use in reviews, audits, or daily workflow design. We wrote this guide for compliance officers, risk managers, project leads, and anyone who has ever stared at a checklist and wondered whether it was catching the right things. The eight filters are not a replacement for legal advice or regulatory expertise. They are a second set of eyes—a structured way to ask: Did we miss something obvious? 1. Where These Filters Show Up in Real Work The eight filters did not emerge from a boardroom.

Compliance work is rarely about knowing the rules alone. It is about applying them consistently when deadlines loom, data is incomplete, and stakeholders disagree. The Red Rock Compliance approach offers a set of mental filters—eight of them—that help professionals check their decisions against common failure modes. This article turns those filters into a practical checklist you can use in reviews, audits, or daily workflow design.

We wrote this guide for compliance officers, risk managers, project leads, and anyone who has ever stared at a checklist and wondered whether it was catching the right things. The eight filters are not a replacement for legal advice or regulatory expertise. They are a second set of eyes—a structured way to ask: Did we miss something obvious?

1. Where These Filters Show Up in Real Work

The eight filters did not emerge from a boardroom. They came from repeated patterns in compliance failures: overlooked data flows, misaligned incentives, and assumptions that went untested. In practice, you will encounter them in several common scenarios.

Consider a mid-sized company rolling out a new customer data platform. The legal team approves the privacy notice, but the product team ships a feature that shares data with a third-party analytics tool not listed in the notice. A filter that asks Does every data recipient match what we told users? would catch this before launch. That is the kind of gap these filters are designed to surface.

Another scenario: a financial services team updates its anti-money-laundering procedures. The changes look good on paper, but the training materials still reference the old thresholds. A filter that checks Are our operational documents aligned with policy updates? would flag the mismatch. Teams that run this filter quarterly often find two or three such disconnects per cycle.

The filters also appear in vendor reviews. When a procurement team evaluates a cloud provider, they might check certifications and data location. But a filter that asks What happens to our data if the vendor is acquired? adds a layer of resilience thinking that standard checklists miss. In one composite example, a team that added this question discovered that their vendor's contract allowed data transfer to a subsidiary in a jurisdiction with weaker protections. They renegotiated before the deal closed.

You will also see the filters in internal audits, incident response reviews, and even during onboarding of new team members. The key is that they are not a one-time exercise. They become a habit—a regular pause to ask whether the system still matches the intent.

We have seen teams integrate them into monthly review meetings, sprint retrospectives, and pre-launch checklists. The format adapts: some use a simple spreadsheet with yes/no columns; others embed the questions into their project management tool. The common thread is that the filters force a specific kind of attention—not to what the policy says, but to what the practice actually does.

Why Context Matters

The same filter can surface different issues in different industries. A healthcare team using the data flow alignment filter might catch a lab result going to an unsecured portal. A manufacturing team using the same filter might find that a supplier's system logs employee badge data without consent. The filter is generic; the insight is specific to your domain. That is by design.

2. Foundations That Readers Often Confuse

Before we walk through all eight filters, we need to clear up a few misunderstandings that trip up even experienced professionals. The first confusion is between compliance and risk management. Compliance is about meeting obligations. Risk management is about deciding which obligations matter most when resources are tight. The filters help with both, but they are not a substitute for a risk assessment. If you use them only to check boxes, you will miss the deeper patterns.

The second confusion is that a checklist guarantees completeness. It does not. A checklist is a memory aid, not a proof. The filters are designed to prompt questions, not to answer them. If you treat each filter as a pass/fail test, you will overlook the gray areas where most real problems live. For example, the filter Are our controls still proportionate? does not have a binary answer. It invites a discussion about whether the cost of a control exceeds the risk it mitigates. That discussion is where the value lies.

The third confusion is that the filters are static. They are not. As regulations change, as your organization grows, and as new technologies emerge, the filters need to be revisited. A filter that worked for a startup with ten employees may be too narrow for a company with five hundred. We have seen teams keep the same checklist for years and wonder why it stopped catching issues. The answer is usually that the context shifted while the questions stayed frozen.

Another common mistake is treating the filters as a solo exercise. They work best when multiple perspectives are involved. A compliance officer might see a legal risk; an engineer might see a technical constraint; a product manager might see a user impact. Bringing those views together around the same set of filters produces richer insights. If you run the filters alone in your office, you will likely miss half the picture.

Finally, some professionals confuse the filters with a framework like COSO or NIST. The filters are not a framework. They are a lightweight overlay that you can apply on top of whatever framework you already use. Think of them as a sanity check that fits into a 30-minute meeting, not a multi-month implementation project.

What the Filters Are Not

They are not a magic wand. They will not make your compliance problems disappear. They will not replace the need for expert judgment or legal review. What they will do is give you a structured way to spot gaps that your normal processes miss. That is a modest but valuable contribution.

3. Patterns That Usually Work

Over time, we have observed several patterns that make the filters effective. The first is regular cadence. Teams that run the filters monthly or quarterly catch issues earlier than those that run them annually. The reason is simple: drift happens gradually. A monthly check catches a small misalignment before it becomes a costly rework. In one example, a team that ran the filters every sprint found that a new API endpoint was logging credit card numbers in plaintext. They fixed it in two days. If they had waited until the quarterly audit, that data would have been exposed for weeks.

The second pattern is documenting the output. It is not enough to discuss the filters in a meeting. You need to write down what you found, what you decided, and what you will do differently. This creates a trail that you can review later. It also forces clarity. When you write We decided not to act on this because the risk is below our threshold, you are making a deliberate choice rather than a passive omission. That documentation becomes invaluable during audits or when a new team member joins.

The third pattern is pairing filters with specific triggers. Instead of reviewing all eight filters every time, some teams assign certain filters to certain events. For example, the data flow alignment filter runs whenever a new data integration is proposed. The vendor resilience filter runs when a contract is up for renewal. This makes the process lighter and more targeted. The full set of eight is still reviewed periodically, but the day-to-day use is event-driven.

The fourth pattern is involving a devil's advocate. One person in the meeting is assigned to challenge assumptions. This does not have to be a compliance expert. It can be a junior team member or someone from a different department. The goal is to surface blind spots. In one composite scenario, a devil's advocate asked, What if the regulator changes the definition of personal data next year? That question led the team to build more flexible consent mechanisms, saving months of rework when the regulation actually changed.

The fifth pattern is keeping the filters visible. Teams that display the filters on a shared dashboard or include them in meeting agendas tend to remember them better. Out of sight often means out of mind. A simple poster in the team area or a pinned message in the collaboration tool can make a surprising difference.

When the Patterns Fail

Even good patterns can break. If the team is under extreme time pressure, the filters become a box-ticking exercise. If the culture punishes raising concerns, people will stay silent. The filters are a tool, not a cure for organizational dysfunction. If you find that the filters are not surfacing anything useful, look at the environment first, not the tool.

4. Anti-Patterns and Why Teams Revert

Despite good intentions, many teams abandon the filters after a few months. The most common anti-pattern is overcomplication. Someone adds more questions, more criteria, more scoring. What started as eight simple filters becomes a 50-item questionnaire. The effort to complete it grows, and the value per question drops. Eventually, the team stops using it altogether. The fix is to resist the urge to expand. If a filter is not working, refine it—do not add another one.

The second anti-pattern is perfectionism. Some teams delay running the filters because they want the perfect format or the perfect data. They wait for a full data map, a complete risk register, or a finalized policy. That wait can last months. In the meantime, issues go unnoticed. The better approach is to run the filters with whatever information you have today. Imperfect data is better than no data. You can improve the inputs over time.

The third anti-pattern is ownership ambiguity. When everyone is responsible, no one is. If the filters are not assigned to a specific person or role, they tend to fall through the cracks. We have seen teams where the compliance officer assumes the project manager is running them, and the project manager assumes the compliance officer is running them. The result is that they never happen. The solution is to assign a clear owner for each review cycle, even if that owner rotates.

The fourth anti-pattern is treating the filters as a one-way gate. Some teams run the filters before a launch and then never again. But compliance is not a one-time event. Systems change, people change, regulations change. A filter that passed six months ago may fail today. The filters should be part of an ongoing monitoring process, not a pre-launch checklist that gets archived.

The fifth anti-pattern is ignoring the emotional dimension. Compliance reviews can feel like criticism. If the filters are used to blame people for past mistakes, the team will resist them. The tone matters. Frame the filters as a way to catch problems before they become incidents, not as a post-mortem inquisition. When people feel safe to raise concerns, the filters work much better.

Why Teams Revert

Under pressure, teams revert to what is familiar. If the filters feel like extra work with no immediate payoff, they will be dropped. The key is to demonstrate value quickly. The first few runs should aim for a quick win—a small issue that the filters catch and the team fixes easily. That builds confidence and momentum. Without that early success, the filters will feel like overhead.

5. Maintenance, Drift, and Long-Term Costs

Maintaining the filters is not free. It requires time, attention, and sometimes uncomfortable conversations. The most visible cost is the meeting time. A thorough review of all eight filters can take 30 to 60 minutes, depending on the complexity of the area being reviewed. For a team of five, that is two to five hours per cycle. Over a year of monthly reviews, that adds up to 24 to 60 hours. That is a real investment.

But the cost of not maintaining them can be higher. Drift is the slow misalignment between what you think you are doing and what you are actually doing. It happens when a policy is updated but the training is not, or when a new tool is adopted without updating the data flow diagram. Drift is dangerous because it is invisible. By the time you notice, you may already be out of compliance. The filters are designed to catch drift early, when the cost of correction is low.

Another cost is the emotional labor of raising issues. If a filter surfaces a problem that requires significant rework, the person who raised it may face resistance. Teams need to create a culture where raising issues is rewarded, not punished. That is not a cost that shows up on a spreadsheet, but it is real. If the culture is not supportive, the filters will produce silence.

There is also the risk of filter fatigue. If the same filters are applied to every situation without adaptation, they become routine and lose their edge. The questions start to feel stale, and the team stops thinking deeply. To counter this, we recommend rotating the filters periodically or adding a wildcard question that changes each cycle. For example, one month you might ask, What would a regulator who is skeptical of our industry focus on? That keeps the exercise fresh.

Long-term, the filters may need to be retired or replaced. As your organization matures, some filters may become redundant because the underlying issues are now handled by other processes. That is a sign of progress. Do not cling to a filter that no longer adds value. Replace it with something that addresses a current gap.

Tracking Maintenance

A simple log of filter reviews—date, findings, actions taken, and next review date—helps you see whether the filters are still earning their keep. If a filter consistently finds nothing for six consecutive cycles, consider whether it is still needed or whether you are looking in the wrong place.

6. When Not to Use This Approach

The eight filters are not universal. There are situations where they add little value or even create false confidence. The first is when you are facing a novel or unprecedented risk. The filters are based on common patterns. If you are dealing with a completely new technology or regulatory scenario, the patterns may not apply. In that case, you need a deeper analysis, possibly with external experts. The filters can still be a starting point, but do not rely on them alone.

The second situation is when the regulatory environment is highly prescriptive. If the rules tell you exactly what to do and how to do it, the filters may feel redundant. For example, if a regulation mandates specific encryption standards and audit logs, the filter Are our controls proportionate? might not be helpful because the control is already specified. In that case, the filters should focus on implementation gaps rather than design choices.

The third situation is when the team is already overwhelmed. Adding a new process to a team that is struggling to keep up with existing obligations will only increase burnout. If the team cannot spare 30 minutes per month, the filters will become a burden rather than a help. In that case, address the workload issue first, or simplify the filters to just two or three that target the highest-risk areas.

The fourth situation is when the culture is punitive. If mistakes are met with blame rather than learning, the filters will be used as weapons. People will hide issues rather than surface them. The filters will produce a false sense of security because the real problems stay hidden. In such an environment, invest in culture change before introducing new compliance tools.

The fifth situation is when you need a formal audit trail for a regulator. The filters are not a substitute for a documented compliance program. They are a supplement. If a regulator asks for your risk assessment methodology, the filters alone will not satisfy that request. You need a more formal framework. Use the filters as a tool within that framework, not as the framework itself.

Signs You Should Skip or Pause

If you find that the filters are consistently producing the same results with no action taken, or if the team dreads the review meetings, it is time to pause and reassess. The filters should feel like a useful check, not a chore. If they feel like a chore, something is off.

7. Open Questions and FAQ

We often get questions from teams trying to adopt the filters. Here are the most common ones, along with our best answers based on what we have seen work.

How do I get buy-in from my team?

Start small. Pick one filter and apply it to a current project. Show the team what it catches. If the filter finds something useful, they will see the value. If it does not, try a different filter. Once you have a success story, share it. People are more likely to adopt a tool that has already proven itself.

Can I use the filters alone?

You can, but the results will be limited. The filters work best when multiple perspectives are involved. If you are a solo practitioner, consider asking a colleague from another department to join you for 15 minutes. A fresh pair of eyes can spot things you miss.

How often should I run them?

For most teams, monthly is a good cadence. If you are in a fast-moving industry or undergoing significant changes, consider bi-weekly. If things are stable, quarterly may be enough. The key is consistency. Running them every month is better than running them intensively once a year.

What if a filter raises an issue we cannot fix?

Document it. Note why it cannot be fixed now and what conditions would need to change for it to become fixable. Then set a reminder to revisit it. Some issues are not worth fixing immediately because the cost outweighs the risk. That is a legitimate decision, but it should be explicit.

Should I customize the filters?

Yes. The eight filters are a starting point. Adapt the wording to your industry, your organization, and your current risks. Just be careful not to add too many. Keep the list short enough that you can review it in one sitting.

How do I know if the filters are working?

Track two things: the number of issues surfaced and the number of issues that lead to action. If the filters are surfacing issues but no action is taken, the process is broken. If they are not surfacing anything, either the filters are too generic or the team is not applying them honestly. Use the log to spot trends.

8. Summary and Next Experiments

The eight Red Rock filters are a practical tool for catching compliance gaps before they become incidents. They are not a silver bullet, but they are a structured way to ask better questions. To make them work for you, start with one filter, run it on a real project, and see what you find. Then add a second. Build the habit gradually.

Here are five concrete next steps you can take this week: (1) Pick one filter from this article that resonates with a current challenge. (2) Schedule a 30-minute meeting with two or three colleagues to apply that filter to a live project. (3) Document what you find and decide on one action item. (4) Set a reminder to repeat the exercise next month. (5) After three cycles, review whether the filters are adding value and adjust as needed.

We also encourage you to experiment with the format. Try running the filters as a silent writing exercise before the meeting, then compare notes. Or assign each filter to a different team member to present. The goal is to keep the process alive and responsive to your context.

Finally, remember that compliance is not a destination. It is a continuous practice of alignment. The filters are one way to maintain that alignment. Use them, adapt them, and when they stop serving you, replace them with something better. The ultimate filter is your own judgment—these eight are just a scaffold to support it.

Share this article:

Comments (0)

No comments yet. Be the first to comment!