what a signature measures
july 21, 2026
A voluntary compliance regime is measured through the population that signs it. Whoever’s already close to the standard signs. Whoever isn’t, doesn’t. So the numbers coming out of the regime describe the signatory set’s alignment with a formalization of the signatories’ existing practice, and describe nothing about the field.
This is a selection effect the size of the whole regime.
The mechanism is straightforward. Signing a voluntary framework carries a cost: internal audit alignment, reporting infrastructure, staffing, occasional scrutiny. A firm signs when that cost is small relative to the firm’s existing internal practice, because the firm was already doing most of the work the framework asks for. A firm doesn’t sign when the cost is large, because the firm was doing little of the work. So the signatory set is a self-selected subset already near the standard, and the non-signatory set is a self- selected subset that isn’t. The regime’s yes/no is a labeled sample of the field’s prior alignment. It is not a treatment.
The pattern is old.
The Basel Committee’s Regulatory Consistency Assessment Programme runs peer reviews of Basel III implementation across member jurisdictions. Participation is at the jurisdiction level and voluntary. Signatory countries submit for peer review; the reviews have published findings, including rare “materially non-compliant” verdicts. The countries that submit substantive reports are the countries with functional prudential regulators. The countries whose reports would be letterhead-and-boilerplate, if they submitted, are the countries whose regulators are the problem the accord was written to catch. RCAP reaches the first set. The second set is the reason the accord was written.
The TCFD’s climate risk disclosure framework was voluntary from its 2017 recommendations through the beginning of jurisdictional mandates in 2022. During those years, its signatories were the firms with dedicated climate risk teams. The reports were sophisticated; year-over-year metrics improved; coverage stayed at a fraction of the market. Once the UK and EU introduced mandatory disclosure aligned to TCFD in 2022 and 2023, coverage jumped and average report quality dropped, because the newly-covered firms didn’t have the teams. If you read the voluntary-era numbers as evidence the framework was raising practice, you were reading the sophistication of the volunteers, and the volunteers were mostly reporting what they would have reported anyway.
The FDA’s MedWatch adverse-event reporting is voluntary for individual clinicians. The clinicians who file are the clinicians who track. The rest don’t; the underreporting rate on serious device events is estimated between roughly 90 and 99 percent depending on device class. The system is technically operating at 100% of its designed capacity across a submitted-report population whose adverse-event awareness was already high before MedWatch existed. The other clinicians, whose reports would be the point, were never inside the system.
The OECD Guidelines for Multinational Enterprises are voluntary at the state level, implemented through National Contact Points. The countries whose NCPs handle real cases are the countries whose ministries would have taken the complaints regardless. The countries whose NCPs are dormant have functionally opted out of the guidelines while remaining formally in.
The distinction I want is between two senses of “the regime is working.”
One sense: the signatory population is meeting the framework’s stated criteria. In this sense, most voluntary regimes work well. TCFD in its voluntary years worked well. RCAP works well. MedWatch works well among the clinicians who file. Wolfsberg has worked well among the large private banks that drafted it. The metrics inside the signatory set are real and usually improving.
The other sense: the field the regime was designed to affect is meeting the framework’s stated criteria. In this sense almost no voluntary regime works, because the field always includes the population the regime cannot reach - which is not a bug of the regime but a property of the instrument. TCFD in its voluntary years covered a fraction of the market. MedWatch misses ninety percent of what it exists to see. The countries whose regulators matter most for global financial stability are not always inside the RCAP peer review room.
If you don’t distinguish these two senses you get a confusing outcome: the regime’s internal metrics keep improving, the field keeps looking about the same, and the connection between the two stays unsaid. The regime is measuring a population that is not the field, and its metrics have nothing to say about the field. This is not the regime’s fault. It is what the regime was, structurally: a mechanism for encoding the practices of firms who wanted to codify their own practices, sold to the public as a mechanism for lifting the field.
A firm’s willingness to sign is itself data. It tells you the firm’s internal review is close enough to the framework that signing is cheap. Unwillingness to sign is symmetric data: the firm’s internal review is not close enough, or the political return on signing is negative, or the firm has reason to prefer opacity in the specific dimension the framework audits. The yes/no roster is a labeled map of the industry’s prior alignment with the standard, and it is generated before the framework has done anything. Read the roster; don’t read the reports.
If you are the party that wrote the framework, and you look at your signatory list and it consists of firms whose internal practices you were designing around, this is not evidence you failed. It is evidence you succeeded at codification. It is not evidence you succeeded at anything else. Whether the gap between the signatory set and the field can be closed by iterating on the framework is a different question than the one the metrics can answer. Usually it can’t. Usually the closing happens through the transition from voluntary to mandatory, which is a different instrument, and which measures different things and is priced differently by the firms it reaches.
Voluntary regimes also create a public record of which firms took which positions when the regime was optional - a record the field can be read against once the mandatory instrument arrives. That’s the undersold value. A voluntary regime’s roster is a snapshot of internal confidence at a specific moment, and the moment is the one before the field knew what would eventually be required.
The pattern is showing up right now in the frontier-AI regulatory conversation. Some labs will sign the current voluntary framework; others won’t. The roster, once it lands, will be a labeled map of which firms judge their existing internal safety review to be close enough to the framework that signing is cheap, and which don’t. That is the useful reading. The metrics coming out of the signatory set, later, will describe the signatory set. The metrics will not describe the frontier.
None of this is an argument against voluntary regimes. Voluntary regimes are how mandatory regimes get their language, their audit protocols, their political feasibility, and their implementation-cost estimates. What they don’t do is lift the field. That is a different instrument’s job.
Just don’t confuse the roster with the effect.
twin on the paper side: what was holding.