R365 SeriesWho decides what is true? Part 6 / 26

Who Watches the Watchers?

Regulatory capture, the revolving door, conflicts of interest, and the problem of independent oversight

Every complex society needs watchdogs. Someone has to check:

  • whether an aircraft is safe;
  • whether a bank manages risk properly;
  • whether an auditor truly reviews a company independently;
  • whether a regulator enforces the law;
  • whether a state body abuses its powers;
  • whether a company tells the public the same thing its internal experts know.

But another question immediately appears:

Who watches the watcher?

A regulator needs expertise in the industry it oversees. An auditor has to know the company it audits. An inspector needs access to the institution under investigation. The state wants to attract people with private-sector experience into oversight bodies.

All of that is reasonable. But that same proximity can create another risk:

the watcher gradually begins to see the world through the eyes of the entity it is supposed to oversee.

That is the core problem of regulatory capture.

Capture does not necessarily mean corruption

The word capture quickly evokes an image:

a company bribes the regulator.

That is one possible case, but it is too narrow. The OECD uses the term policy capture for situations in which public decisions are repeatedly or systematically redirected away from the public interest toward a particular special interest.[1]

In academic literature, the concept can be narrower or broader depending on the author. Richard Posner describes regulatory capture as the subordination of a regulatory agency to the interests of regulated firms.[2] But Luigi Zingales makes a particularly important point:

regulatory capture does not necessarily require dishonest regulators.

It can arise from ordinary incentives and informational dependencies built into the system itself.[3] That distinction is essential. If we understand capture only as bribery, we may miss much more common mechanisms.

The regulator needs information from the regulated entity

Imagine a regulator overseeing a highly technical industry. It regulates:

  • aircraft electronics;
  • complex financial instruments;
  • pharmaceutical manufacturing;
  • nuclear technology;
  • telecommunications networks.

The industry has:

  • thousands of engineers;
  • enormous databases;
  • its own laboratories;
  • detailed operational knowledge.

The regulator has fewer people and a limited budget. What does it do? It has to ask the industry. That is normal. But it creates information asymmetry:

the regulated party often knows more about its own system than the regulator does.

Zingales points precisely to this dependency on information from the regulated industry as one mechanism that can pull regulators closer to regulated interests.[3]

Expertise creates a paradox

Good oversight requires people who understand the industry. But who understands it best? Often people who have:

  • worked in it;
  • advised it;
  • done business with it.

We therefore get a paradox:

more expertise can mean greater proximity to the regulated industry.

If we remove everyone with industry experience from an oversight body, we may weaken its ability to supervise. If we include them without safeguards, we increase conflict-of-interest risks. The answer is therefore not:

“No one from industry should ever become a regulator.”

It is:

clear disclosure rules, recusal, cooling-off periods, independent oversight, and transparency.

The revolving door

The OECD describes the revolving door as movement between public and private sectors that can create conflicts of interest.[4] The risk takes several forms.

Before leaving public service

An official may think:

“Will I need a job next year from the company I am regulating today?”

After leaving

A former official may:

  • lobby former colleagues;
  • use personal relationships;
  • exploit non-public information;
  • advise a company on how the regulator operates.

When entering from industry

A new regulator may bring into public service:

  • valuable expertise;
  • but also cultural assumptions from the previous environment.

The OECD therefore treats the revolving door as an area requiring specific conflict-of-interest management.[4][5]

Ferdinand Pecora, left, at the U.S. Senate in 1937 with Senator Royal S. Copeland.
Ferdinand Pecora, 1937. A few years earlier, as chief counsel to the Senate investigation of banking and securities practices, Pecora questioned powerful financiers; the inquiry became widely known as the Pecora investigation. This photograph shows him in a different Senate context in 1937, so it is used as a historical portrait of an investigator, not as an image of the 1932–1934 inquiry itself. Image: Harris & Ewing / Library of Congress / Wikimedia Commons Public domain — no known restrictions (Library of Congress)

A revolving door is not proof of wrongdoing

This is an important methodological boundary. If a regulator later takes a job in industry, that alone does not prove that they previously made improper decisions in its favor. We need additional evidence:

  • which matters they handled;
  • when employment discussions began;
  • whether they recused themselves;
  • whether they used confidential information;
  • whether there was an unusual change in decisions;
  • whether any rules were violated.

The revolving door is:

a conflict risk and a reason for further scrutiny.

It is not automatic proof of capture.

Why do states allow movement at all?

Because a total ban has costs. For decades, the GAO has emphasized the need to balance:

  • protecting the public from conflicts of interest;
  • the government's ability to recruit and retain highly qualified people.[6]

A person who enters public service cannot necessarily be permanently excluded from their professional field. The problem is therefore the design of the rules. Not mobility itself.

Who has time to participate in regulation?

Capture does not happen only through employment. When drafting rules, regulators often collect:

  • comments;
  • expert opinions;
  • data;
  • proposals.

Who has the most time and money to participate? Often:

  • large companies;
  • professional associations;
  • organized interest groups.

An ordinary citizen has much less incentive to read a 300-page technical regulation and submit comments. This creates an asymmetry of participation. The OECD therefore emphasizes diverse participation, transparency, access to information, accountability, and organizational integrity as protections against policy capture.[1]

Capture can be cultural, not only financial

Regulators and regulated entities may spend years:

  • attending the same conferences;
  • using the same technical language;
  • coming from the same universities;
  • changing jobs between institutions;
  • solving the same problems.

Over time, a shared professional culture can emerge. A regulator may begin to unconsciously transform the question:

“How do we protect the public from the industry?”

into:

“How do we help the industry make the system work?”

These two questions are not necessarily in conflict. But if the second completely replaces the first, the oversight function can weaken.

A regulator is not the industry's enemy

The opposite image is dangerous too. A regulator that treats a company as an enemy regardless of the evidence is also not regulating well. A good regulator must be:

  • close enough to understand;
  • distant enough to judge.

That is a difficult balance. Independence does not mean hostility. It means the ability to decide without improper influence.

Boeing 737 MAX: an important case, but not proof of capture by itself

After the Lion Air 610 and Ethiopian Airlines 302 crashes, the U.S. Department of Transportation Office of Inspector General reviewed the certification of the Boeing 737 MAX 8. Its 2021 report found that the FAA and Boeing followed the certification process then in place, but weaknesses in FAA guidance, processes, and communication led to significant misunderstandings regarding the MCAS system.[7]

The OIG also found weaknesses in FAA oversight of Boeing's Organization Designation Authorization (ODA) program.[7] This is a very useful example of oversight structure. But it would not be fair to infer automatically from the report:

“The OIG proved that Boeing captured the FAA.”

The report does not say that.

Delegated oversight

In some technical systems, a regulator delegates part of the review work to qualified people inside the company or organization. Why? Because otherwise there would be:

  • too much data;
  • too few regulators;
  • slower certification.

Delegation can be efficient. But it creates a specific question:

How does the regulator ensure that the delegated function remains a regulatory function rather than becoming an extension of the business objective?

That requires:

  • clearly separated responsibilities;
  • a path for independent escalation;
  • protection of technical experts;
  • sufficient competence on the regulator's side.

JATR: systemic lessons from MAX certification

The Joint Authorities Technical Review, involving the FAA, NASA, and experts from several international aviation regulators, issued recommendations in 2019 concerning certification of the 737 MAX flight-control system.[8] Among other things, the JATR pointed to:

  • assumptions about pilot behavior;
  • the impact of design changes on operations and training;
  • the need for a better holistic understanding of system effects.

The methodology matters here too:

a report can identify weak oversight and process risks without proving deliberate corruption.

That distinction is fundamental to this entire series.

Self-regulation: when can an industry oversee itself?

Industry self-regulation has advantages. The industry has:

  • expertise;
  • the ability to develop standards quickly;
  • direct contact with the technology.

But the question is:

What happens when a safety standard conflicts with cost or speed?

Self-regulation works best when there are:

  • clear external legal frameworks;
  • independent audit;
  • real accountability;
  • competing standards;
  • enough information for the public.

Without external verification, there is a risk that a standard becomes mainly:

proof of compliance with itself.

Auditing: the watchdog paid by the entity it watches

Auditing contains an interesting structural conflict. An independent auditor must assess a company's financial statements. But the company usually pays for the audit. Modern auditing standards therefore place special emphasis on independence in fact and appearance.

The PCAOB states that auditors have a fundamental responsibility to protect investors by issuing accurate, informative, and independent audit reports and must be independent of the company both in fact and appearance.[9] The system therefore already recognizes in its design:

expertise alone is not enough; independence is also required.

A conflict of interest does not automatically mean a wrong decision

Someone can have a conflict of interest and still reach the correct decision. The problem is different. A conflict of interest:

  • increases the risk of bias;
  • makes public verification of impartiality more difficult;
  • reduces trust in the outcome.

Conflicts are therefore often managed through:

  • disclosure;
  • recusal;
  • independent review;
  • restrictions on certain relationships.

Actual corruption does not have to be proven before a conflict is worth managing.

Independence in appearance

This is an important concept. An auditor may be subjectively completely honest. But if their financial or personal relationship with the client is so strong that a reasonable outside observer would question impartiality, a problem exists even without provable bias.[9]

Why? Because oversight requires not only the right decision. It also requires:

a credible process.

Inspector General: oversight from inside the system

The U.S. model of Offices of Inspector General tries to create internal bodies with a degree of institutional independence. The Council of the Inspectors General on Integrity and Efficiency is established by law as an independent entity within the executive branch and is intended to improve professionalism and coordination in oversight of fraud, waste, and abuse.[10]

The model is interesting:

the watchdog sits inside the broader state system,

yet must remain separate enough to criticize that system. That is a difficult institutional design problem.

A completely independent watchdog hardly exists

Every watchdog depends on something. On:

  • a budget;
  • appointment;
  • a statutory mandate;
  • access to documents;
  • data from the entity being overseen;
  • courts;
  • political support.

So the question:

“Is the regulator completely independent?”

is not very useful. A better one is:

What does it depend on, and what safeguards prevent that dependency from altering its judgment?

Who audits the auditor?

If an auditor reviews a company:

  • a regulator can review the auditor;
  • an audit committee can oversee the relationship with the auditor;
  • standards can limit conflicts;
  • markets and courts can create additional accountability.

This creates layered oversight. But every added layer raises the same question:

who checks the next layer?

Modern institutional design does not answer with one “supreme watchdog.” It answers with:

a network of mutual checks.

Redundancy is a good property in oversight

In engineering, redundancy means deliberately duplicating a system. If the first sensor fails, there is a second. Institutions can work similarly. For example:

  • internal compliance;
  • an external regulator;
  • an independent auditor;
  • a court;
  • a parliamentary body;
  • the media;
  • a whistleblower;
  • civil society.

No layer is perfect. But simultaneous failure across all layers is harder.

The “single point of failure” problem

If one institution:

  • sets the rules;
  • collects the data;
  • interprets the rules;
  • judges violations;
  • decides appeals,

we have a single point of institutional failure. That does not prove abuse. But it means the consequences of error or capture are greater. Good design therefore separates functions where possible.

Oversight theatre

An institution can have extensive oversight on paper:

  • committees;
  • forms;
  • certificates;
  • audits;
  • codes of ethics.

That does not mean the oversight works. There can be:

oversight theatre—the appearance of oversight without a real ability to affect decisions.

Ask:

  • Can the watchdog demand documents?
  • Can it stop a process?
  • Can it impose sanctions?
  • Can it publish an unfavorable finding without permission from the entity it oversees?
  • Does it have enough technical expertise?

If not, its independence is largely formal.

Transparency is not the same as accountability

Publishing data is useful. But transparency by itself does not correct a system. If an institution publishes 10,000 pages of documents but:

  • nobody has authority to act;
  • the data are unintelligible;
  • there are no consequences,

we have transparency without accountability. The OECD therefore links prevention of capture to a combination of:

  • plural participation;
  • transparency;
  • access to information;
  • accountability;
  • integrity rules.[1]

More regulation does not automatically mean less capture

If a regulator is captured or ineffective, adding more rules by itself does not solve the problem. It may even increase:

  • complexity;
  • dependence on experts;
  • barriers to entry for new competitors.

Regulation may be necessary. But regulation itself must be designed to be:

  • understandable;
  • verifiable;
  • transparent;
  • open to competition among interests.

And less regulation does not automatically mean more freedom

The opposite simplification is:

“If the regulator can be captured, remove the regulator.”

But if the regulator disappears, another concentration of power may remain:

an industry without external oversight.

The Cambridge volume Preventing Regulatory Capture explicitly warns that diagnosing capture does not mean regulation is hopeless or should be abandoned.[11] The question is:

how do we design oversight that is more resistant to capture?

Capture must be demonstrated, not merely declared

The phrase regulatory capture has become a powerful political label. When we dislike a regulator's decision, there is a temptation to say:

“The regulator is captured.”

But Carpenter and Moss emphasize the problem of detecting and measuring capture: it is necessary to show that decisions are actually being systematically shifted in favor of a special interest, not merely that we disagree with a particular decision.[12] For THY-REALITY, the rule is therefore:

capture is a hypothesis that needs both a mechanism and evidence.

What would count as evidence of capture?

Possible indicators include:

  • systematically privileged access for one side;
  • decisions contrary to the regulator's own technical findings without a reasonable explanation;
  • unmanaged conflicts of interest;
  • repeated employment transitions between specific decision-makers and regulated entities;
  • internal documents showing improper influence;
  • regulatory rules systematically designed in favor of the regulated at the expense of the statutory objective.

No single indicator is always enough. We need:

pattern + mechanism + documented connection.

An unpopular decision is not proof of capture

A regulator sometimes has to make a decision that benefits industry. That can be correct. For example:

  • an old rule is ineffective;
  • technology has changed;
  • the cost of the rule exceeds its benefit.

If we label every such decision capture, the concept loses analytical value. The real question is:

Is the decision explainable by the public mandate and the evidence, or is it better explained by a private interest that improperly prevailed?

Opposition to industry is not proof of independence either

A regulator can adopt a very strict rule and still be a poor regulator. Strictness is not the same as independence. A good watchdog must be able to:

  • demand more when necessary;
  • remove a rule when it no longer makes sense.

Independence is shown by:

consistency of method, not by how often the regulator says “no.”

The revolving door is a two-way problem

Much discussion focuses on:

regulator → industry.

But there is also:

industry → regulator.

In both directions there can be:

  • useful expertise;
  • conflicts;
  • cultural influence.

The OECD specifically notes that movement can bring valuable skills and knowledge into government while simultaneously creating risks involving information, relationships, and future employers.[4] This illustrates a broader rule:

the same mechanism can create both benefit and risk at the same time.

Cooling-off periods

One common safeguard is a period during which a former official may not:

  • represent certain interests before a former agency;
  • participate in specific matters;
  • use certain relationships.

The GAO documents U.S. post-employment restrictions and revolving-door rules for former federal officials.[6][13] But such a rule is only as useful as it is:

  • clear;
  • monitored;
  • enforced.

A rule without data is difficult to oversee

The OECD's Anti-Corruption and Integrity Outlook 2024 warns that many countries have conflict-of-interest rules but often lack enough data to know whether revolving-door risks are actually being controlled.[14] This is a broader problem. An institution can say:

“We have a policy.”

But evaluation requires:

evidence of implementation.

Who funds the watchdog?

Independence is also connected to the source of money. A budget-funded watchdog depends on political decisions. A watchdog funded through industry fees is financially connected to the industry it regulates. An independent private auditor is paid by the client.

Every model contains a conflict structure. So the question is not only:

“Who pays?”

but:

Does the funding arrangement allow the payer to influence a specific finding?

Who appoints the watchdog?

The same problem applies to appointment. If the watchdog is appointed by:

  • the government;
  • parliament;
  • industry;
  • a professional association,

each model has advantages and disadvantages. Good institutional design uses:

  • limited terms;
  • transparent criteria;
  • removal procedures;
  • multiple actors in the appointment process;
  • public reporting.

The goal is not to eliminate all dependency. That is impossible. The goal is:

to prevent one dependency from becoming absolute.

Auditor independence as a model for broader epistemology

Why do we require independence from an auditor? Because we understand that:

expertise without independence is not enough for trust.

The same applies to:

  • scientific peer review;
  • safety review;
  • fact-checking;
  • regulatory assessment;
  • internal investigation.

We could call the broader principle:

EPISTEMIC INDEPENDENCE

Does the person reviewing something have a real possibility of reaching a conclusion that is uncomfortable for the client?

A test of epistemic independence

For every watchdog, ask:

Who chooses it?

Who pays it?

Who can dismiss it?

From whom does it get information?

Can it compel data?

Can it publish an unfavorable conclusion?

Does it have sanctioning power?

Is there an appeal from its decision?

Is the watchdog itself subject to independent review?

Where do its people go after their term ends?

This is more useful than the abstract question:

“Is it independent?”

WATCHDOG CHAIN

For future THY-REALITY articles, I would add another standard model:

REGULATED ENTITY → PRIMARY REGULATOR → INTERNAL OVERSIGHT → EXTERNAL AUDIT/IG → LEGISLATIVE/JUDICIAL REVIEW → PUBLIC/MEDIA SCRUTINY

At every link we ask:

  • who has the information;
  • who has the power;
  • who depends on whom;
  • what happens if the previous layer fails.

This shows whether the system has:

redundancy

or:

a single point of failure.

The watchdog itself can become a source of complacency

The existence of an oversight institution can create the reaction:

“If the regulator approved it, it must be safe.”

But regulatory approval means:

the system passed a particular process under particular assumptions.

It does not mean:

risk is zero.

This matters for:

  • medicines;
  • aircraft;
  • financial products;
  • construction.

Oversight reduces risk. It does not abolish reality.

“The regulator approved it” is not final proof

In research, we still need to ask:

  • what the regulator actually checked;
  • what it delegated;
  • what data it had;
  • what assumptions were used;
  • whether the data later changed.

This prevents regulatory authority from becoming another form of:

argumentum ad auctoritatem.

The best oversight allows the regulated party to win

That sounds paradoxical. If a regulator investigates a company and the evidence shows:

the company did not violate the rule,

the regulator must be prepared to say so. If a watchdog always finds a violation because its existence depends on finding violations, it too has an incentive problem. The system must therefore be designed so that a legitimate outcome can also be:

no evidence of a violation.

The same applies to THY-REALITY

If we begin an article with:

“We will prove capture,”

we have already made a mistake. The correct form is:

“We will test whether the evidence supports the capture hypothesis.”

The result may be:

  • capture is well documented;
  • there is a conflict of interest without proof of capture;
  • there is weak oversight without proof of improper influence;
  • there is an ordinary regulatory disagreement.

That is harder. And therefore more useful.

Conclusion: we do not solve the watchdog problem by adding one bigger watchdog

The question “who watches the watchers?” has no final person at the top of the pyramid. If we create:

a super-regulator,

we can ask:

who watches it?

Modern institutional design uses a different answer:

  • separated powers;
  • transparency;
  • professional standards;
  • independent audit;
  • judicial review;
  • legislative oversight;
  • whistleblowers;
  • media;
  • the public.

No element is infallible. Their strength is that they are not all dependent on the same center. The healthiest institution is therefore not the one with:

a perfect watchdog.

It is the one with:

multiple paths by which an error can become visible, even if one path fails.

This is the same principle that recurs throughout the entire series:

truth needs the possibility of correction.

And oversight is only as good as the degree to which the watchdog itself remains corrigible.

Methodological note

This article does not use the term regulatory capture as a political label. It specifically distinguishes between:

  • conflicts of interest;
  • revolving-door risk;
  • informational dependency;
  • weak oversight;
  • delegated oversight;
  • demonstrated regulatory capture.

The Boeing 737 MAX case is used as a documented example of weaknesses in certification and delegated oversight; the DOT OIG report itself is not presented as proof of regulatory capture. Likewise, an individual's movement between public and private sectors is not by itself presented as proof of corruption or an improper decision.

Sources and further reading

  1. OECD, Preventing Policy Capture: Integrity in Public Decision Making, 2017. Used for the concept of policy capture and protective strategies: plural participation, transparency, accountability, and organizational integrity. Source
  2. Richard A. Posner, “The Concept of Regulatory Capture,” in Daniel Carpenter & David A. Moss (eds.), Preventing Regulatory Capture, Cambridge University Press, 2013/2014. Source
  3. Luigi Zingales, “Preventing Economists' Capture,” in Preventing Regulatory Capture. Used for the idea that capture does not necessarily require corruption and that regulators' informational dependence on regulated entities creates structural incentives. Source
  4. OECD, Public Integrity Handbook, section on the revolving door. Source
  5. OECD, Post-Public Employment: Good Practices for Preventing Conflict of Interest, 2010. Source
  6. U.S. Government Accountability Office, reports on post-federal employment and the revolving door. Used for the balance between preventing conflicts and the government's ability to recruit qualified experts. Source 1 Source 2
  7. U.S. Department of Transportation Office of Inspector General, Weaknesses in FAA’s Certification and Delegation Processes Hindered Its Oversight of the 737 MAX 8, February 23, 2021. Source
  8. FAA, Boeing 737 MAX Flight Control System – Joint Authorities Technical Review, October 2019. Source 1 Source 2
  9. Public Company Accounting Oversight Board, AS 1000: General Responsibilities of the Auditor and Ethics & Independence Rules. Used for auditor independence in fact and appearance. Source 1 Source 2
  10. Council of the Inspectors General on Integrity and Efficiency, CIGIE Governing Documents. Source
  11. Daniel Carpenter & David A. Moss (eds.), Preventing Regulatory Capture: Special Interest Influence and How to Limit It, Cambridge University Press. Used for the broader academic framework and the point that capture is not necessarily inevitable. Source
  12. Daniel Carpenter & David A. Moss, “Detecting and Measuring Capture,” in Preventing Regulatory Capture. Source
  13. U.S. GAO, Former Federal Trade Officials: Laws on Post-Employment Activities, Foreign Representation, and Lobbying, 2010. Source
  14. OECD, Anti-Corruption and Integrity Outlook 2024 – Conflict of Interest. Used for the current finding that many countries do not adequately measure the effectiveness of restrictions on revolving-door risks. Source