The SEC’s Enforcement Action Against ISS Is an Oracle Attack Warning, Not a Governance Footnote

CryptoEagle
Gaming
A regulator sent a subpoena. A counterparty said no. In ordinary markets, that sequence is a back-office curiosity, one line on a docket, a footnote in a compliance memo. This time, the counterparty was Institutional Shareholder Services, the quiet monolith that tells the world’s largest asset managers how to vote, and the regulator was the U.S. Securities and Exchange Commission. The SEC responded by opening an enforcement action. The crypto-native reflex is to scroll past. ISS does not issue tokens. ISS does not run a sequencer. ISS does not custody user funds. The reflex is wrong. What I see when I trace the anatomy of this case is not a proxy advisory dispute. I see the same failure mode I spent 72 hours mapping during the UST collapse — the failure of a system whose promises depend on the integrity of an input that nobody audits. ISS is not a blockchain company, but it is an oracle. Institutional shareholders plug into its recommendations the way DeFi protocols plug into price feeds. When that oracle withholds data, or when the data it produces becomes legally radioactive, every downstream decision — votes on auditor ratification, executive compensation, treasury allocation, even Bitcoin treasury proposals — inherits the contamination. The SEC’s enforcement action is not a footnote. It is a warning shot across the entire intermediary layer that connects capital to governance. Patterns emerge only when emotion is stripped away, and the pattern here is unmistakable: the market is watching the wrong crime scene. The parties, for the record, could not be more establishment. ISS is the dominant proxy advisory firm on the planet, publishing vote recommendations that guide trillions in institutional assets. The SEC is the agency tasked with policing exactly how those recommendations are produced and deployed. The charge — as reported — is not that ISS issued a fraudulent recommendation or concealed a conflict of interest. The charge is more procedural, which makes it more dangerous. ISS failed to comply with a subpoena. The SEC treats that as an enforcement event in itself, and in doing so, it signals that non-cooperation with an investigation is now a standalone business risk, not a negotiation posture. Tracing the silent bleed from 2017’s broken logic helps here. That year, I audited twelve obscure utility tokens before their launches and found critical reentrancy vulnerabilities in four of them. The projects were not fraudulent because they intended to steal; they were fraudulent because their code made theft a feature of normal operation. I learned that a failure to comply with a basic structural obligation — in that case, checks-effects-interactions — is the earliest sign of a system that will eventually fail. A reentrancy vulnerability begins with a function that does not protect its own state. A subpoena violation begins with an institution that does not protect its own legal position. Both are refusals to lock the door before the money moves. ISS, whatever its underlying merits, left the door open, and the SEC walked through it. The broader context matters because proxy advisory firms were never supposed to be this powerful. They existed for decades as a back-office convenience: research teams reading shareholder proposals so that fund managers did not have to. Power concentrated slowly and then suddenly, accelerated by three forces: the rise of index investing, which forced passive funds into voting positions they did not want; the expansion of ESG reporting frameworks, which required standardized interpretation of hundreds of ballot items; and the post-2020 retail trading boom, which pulled millions of Americans into funds that vote through intermediaries. Today, a handful of firms — ISS and Glass Lewis above all — operate as an effective gatekeeper between public companies and their own shareholders. They do not vote, but they say how voting should happen. In the language of the systems I dissect, they are validators with proposal power and no slashing condition. The SEC spent years issuing guidance, then vacating guidance, then reissuing narrower guidance, and throughout it all, the industry state remained the same: an unaccountable oracle at the center of the governance graph. Into that vacuum steps the enforcement action. And this is where the legal analysis becomes more interesting than the headline. The enforcement machinery here rests on the SEC’s investigative authority, not on a violation of a proxy advisory rule. Under the Securities Exchange Act of 1934, the Commission has broad power to issue subpoenas in the course of an investigation. Refusing to comply is not a defense; it is an independent violation. The legal framing matters for a reason the average reader will miss. The SEC did not need to prove that ISS harmed investors with a bad recommendation. It needed to prove only that ISS resisted an inquiry, and the inquiry itself becomes the punishment. In regulatory enforcement, the subpoena is the most powerful arrow in the quiver because it converts silence into a crime. ISS may have possessed perfectly valid reasons to resist — the request may have been overbroad, the burden may have been substantial, the documents may have implicated client confidentiality — but those arguments, in the standard course, form the substance of the response, not the reason for the resistance. Refusing to answer, rather than answering and lodging objections, transforms a negotiation into a war. The enforcement action, in other words, is a procedural squall that conceals a substantive earthquake. The SEC could have subpoenaed ISS over anything: a methodology dispute, a data-sourcing question, a conflict-of-interest theory. What the enforcement action tells us is not what the SEC is investigating. What it tells us is that the SEC is no longer willing to accept the industry’s implicit claim that its operations are too complex for regulatory inspection. Complexity is just laziness wearing a tech suit. I have watched crypto teams hide critical vulnerabilities inside sprawling governance contracts that no auditor fully read; I have watched proxy advisory firms hide their methodologies inside similarly sprawling policy documents. In neither case did the complexity make the system safer. In both cases, the complexity created a fog that the powerful used to avoid accountability. The SEC’s subpoena is a flashlight into that fog. What does the SEC actually want? That is the question every institutional investor should be asking, because the answer will define the next five years of corporate governance. Based on the available facts and the agency’s recent enforcement trajectory, I read the subpoena as an attempt to examine how ISS manages conflicts of interest. ISS sits in an uncomfortable structural position: it advises investors on how to vote, while its affiliates and parent companies service issuers and other market participants. The potential for capture is structural rather than conspiratorial — the same way a code audit is compromised not when the auditor lies, but when the auditor’s business model depends on keeping the auditee happy. In my 2025 compliance work, I analyzed more than two hundred crypto protocols against MiCA requirements and found that forty percent of lending platforms had failed to implement proper KYC checks. None of them woke up one morning and decided to break the law. Each of them built a system where compliance was an afterthought, an external bolt-on, a function that was structurally divorced from the engineering team. That is exactly the pattern I would expect to find inside a proxy advisory giant whose revenue streams straddle both sides of the table. The SEC is not investigating a crime. It is investigating an architecture. If the SEC’s real target is conflict-of-interest architecture, the enforcement action will have a ripple effect that extends far beyond ISS. The entire proxy advisory industry is built on a single fragile assumption: that the recommendation is independent of the recommendation’s financial consequences. But independence is not a status; it is a process. A recommendation is independent only if the data it uses is complete, the algorithm that processes it is transparent, and the incentives that surround it are disclosed. Proxy advisory firms have historically satisfied these tests in the way that many crypto protocols satisfy audit requirements — with paperwork. The audits are clean because the auditors are chosen by the audited. The methodologies are secret because secrecy is a competitive advantage. The conflicts are disclosed in footnotes that nobody reads, in the same way that token whitepapers disclose risks that nobody calculates. The code never lies, only the auditors do, and the auditor problem in traditional finance is the same auditor problem in decentralized finance: nobody audits the auditor until the auditor becomes the story. The SEC’s enforcement action against ISS also lands at an especially awkward moment for the crypto economy. Publicly traded crypto companies — exchanges, miners, treasury-heavy software firms — increasingly face shareholder proposals on issues that are incomprehensible to traditional analytical frameworks. Should the company add Bitcoin to its treasury? Should it deploy capital into staking? Should it disclose the energy mix of its mining operations? These proposals are complex, technically dense, and consequential. They are the kinds of proposals that fund managers are least equipped to evaluate on their own, and precisely the kinds of proposals where they will lean most heavily on proxy advisory recommendations. Now consider the irony: the firms that will shape institutional voting on crypto treasury strategies are themselves the subject of an enforcement action rooted in data opaque. The point is not that ISS has issued bad crypto recommendations — the point is that a system with a transparency deficit is being asked to govern an asset class whose core claim is transparency. This is not a governance footnote. It is a category error. Let me be precise about the systemic risk, because the words “systemic risk” are thrown around so loosely in crypto that they have lost their edge. The U.S. institutional market functions as a chain of delegation: retail investors delegate to funds, funds delegate to proxy advisory firms, and proxy advisory firms delegate to analysts. Each link in that chain introduces what mathematicians would call an error term. The error term is small when the incentives at each link are aligned and the data exposure is complete. It compounds when incentives misalign and data is withheld. The SEC’s case against ISS is best understood as an attempt to interrogate the error term in the governance chain. And because ISS sits at the center of that chain, its resistance to the subpoena does not just endanger ISS. It endangers the integrity of every vote that ISS influences while the investigation remains unresolved. Every recommendation issued while a compliance cloud hangs over the firm is a recommendation whose inputs can be questioned in retrospect. That is the true cost of non-compliance: not the fine, but the retroactive poisoning of a decision stream that millions of investors rely on. I want to stress-test the likely defense, because any honest forensic dissection has to steelman the subject. ISS will likely argue that the subpoena was overbroad — that the SEC demanded documents reaching far beyond the investigation’s scope, including methodologies, client communications, and pricing structures that constitute competitive intellectual property. This is not a frivolous argument. In my own audit work, I have routinely seen subpoena recipients drown under requests that are ninety percent fishing expedition and ten percent legitimate inquiry. The regulatory state does not always know what it is looking for; sometimes it uses the subpoena as a discovery device precisely because it lacks a specific theory. The procedural principle is simple: a subpoena must be relevant to an authorized investigation, and it must not impose an unreasonable burden. But the practical reality is more complicated. The SEC has enormous discretion in framing its requests, and courts have historically deferred to the agency’s investigative judgment. The Federal Rules give the SEC broad latitude at the investigation stage, before any formal litigation. At this stage, ISS cannot realistically demand that the SEC prove its theory. It can only attempt to narrow the scope or negotiate the timeline. If ISS refused the subpoena outright rather than negotiating, that decision was a miscalculation of the first order. The correct move in response to an overbroad subpoena is a detailed objection and a counterproposal, not a refusal. Refusal converts a legal disagreement into an existential event. There is also a deeper irony in ISS’s position that deserves mention. Proxy advisory firms spent years demanding that public companies open their books to external scrutiny. They built entire business models on the principle that shareholders deserve visibility into management decisions. They pushed for independent audits, enhanced disclosure, and robust conflict-of-interest policies at the companies they monitored. And yet, when the monitoring regime came for them, they declined to show their own books. The hypocrisy is so glaring that it becomes a data point: the enforcement action is not merely about a failure to comply with a specific legal obligation; it is about a failure to internalize the standards that the firm itself evangelizes. Forensics reveal the truth markets try to bury, and the truth here is that the guardians of governance have been operating inside the same covenant they impose on others. It was only a matter of time before the regulator holding the watch asked to see the watchmaker’s tools. The economic impact analysis is worth doing in detail because the market has not priced it. ISS faces at least three layers of financial consequence. The first layer is direct: legal defense costs, potential civil penalties, and the cost of any remedial compliance program imposed as a condition of settlement. I estimate the legal-defense and settlement range — based on comparable SEC enforcement actions against large financial infrastructure firms — at anywhere from fifty million to five hundred million dollars, depending on whether the investigation expands. The second layer is operational: compliance with the subpoena will force ISS to divert resources from its core research business to document collection and legal review. In my own experience conducting forensic analyses under regulatory pressure, document production is not a marginal cost; it is a vampire that consumes the entire engineering org. Every analyst who spends a week cataloguing emails is an analyst who is not producing vote recommendations. Every dollar spent on outside counsel is a dollar not spent on methodology development. The third layer is reputational and commercial. Institutional clients are notoriously skittish about vendors under investigation. A fund manager does not need to believe that ISS is guilty to reconsider its vendor relationship; it only needs to believe that the SEC’s investigation creates a future risk that its own proxy votes will be challenged. Voter challenges based on flawed recommendations are a nascent but real legal risk. If a fund relied on an ISS recommendation that is later shown to be tainted, shareholders could potentially contest the vote. That risk is enough to trigger a slow migration of assets toward competitors, or toward internal research teams. The market-structure consequences are even more significant. The proxy advisory industry has always been a duopoly — ISS and Glass Lewis — with a handful of smaller challengers orbiting. An enforcement action against ISS does not change that fundamental structure, but it changes the balance between the two giants. Glass Lewis will inevitably pitch its compliance posture as cleaner, its methodologies as more transparent, and its regulatory history as more unblemished. The pitch will work on marginal clients. Meanwhile, smaller proxy advisory firms will face a different pressure: the cost of compliance will rise across the entire industry. The SEC’s action sends a signal that proxy advisory firms must implement the same kind of compliance infrastructure that broker-dealers have long maintained. That infrastructure is expensive. Smaller firms may not be able to afford it, which will narrow the field further and consolidate power in the hands of firms that can. The outcome is unintuitive but important: an enforcement action designed to reduce the influence of proxy advisory firms may end up increasing the market power of the largest one, simply by making the cost of entry prohibitive. This is the pattern I identified in the 2024 EigenLayer restaking analysis, where I argued that theoretical slashing conditions would consolidate staking power into the handful of entities that could afford sophisticated risk management. Regulation works the same way as slashing: it imposes a cost function, and entities that can absorb the cost function consolidate power. Luna’s death was a math error, not a market crash, and consolidation is a mathematical outcome, not a political conspiracy. What would a compliance overhaul of the proxy advisory industry actually look like? This is the substantive question that the enforcement action should force into the open. A defensible framework would include four components. First, conflict-of-interest transparency: full disclosure of any revenue relationship between the proxy advisory firm and either the issuer or the institutional client whose vote is being guided. This should extend to affiliates and subsidiaries, and it should be published in machine-readable form. Second, methodology disclosure: publication of the decision rules that govern vote recommendations, including the weighting of quantitative versus qualitative factors and the treatment of management proposals versus shareholder proposals. The methodology does not need to be open-sourced, but it should be detailed enough that a reasonably informed client can understand why a recommendation was issued. Third, data provenance: documentation of the data sources used in each recommendation, including the timestamps of data collection and the identity of any third-party data vendors. In blockchain terms, this is an audit trail. It is incompatible with the model of a research analyst who pulls data from a proprietary terminal and produces a report with no recorded intermediate state. Fourth, independent audit: annual review of the proxy advisory firm’s recommendation process by an independent third party with the authority to examine client communications and conflicts-of-interest files. The audit would be the equivalent of a smart contract audit for institutional governance — imperfect, but a necessary baseline. Any of these requirements would create substantial friction for ISS. The firm’s core value proposition is speed and standardization: it processes thousands of ballot items each proxy season, and any requirement that each recommendation carry a complete audit trail would slow the pipeline. The friction is precisely the point. The SEC’s enforcement action is not merely about punishing past non-compliance; it is about making future non-compliance impossible by changing the cost structure of the business. Whether the agency succeeds depends on the terms of the eventual settlement and the scope of the injunctive relief. If ISS settles by committing to enhanced disclosure and independent audit, the industry will be forced to follow. If ISS fights and wins on narrow procedural grounds, the industry will draw the opposite lesson: that regulatory resistance pays. The outcome, in other words, is not just a legal event. It is a precedent that will determine whether the governance intermediary layer commits to transparency or continues to rely on opacity. The crypto parallels here are impossible to ignore, and they point to a puzzle that should concern anyone building in this space. Decentralized governance was supposed to eliminate the proxy advisory problem. In theory, token holders vote directly on proposals, and the chain records every ballot. There is no central recommendation engine, no intermediary, no opaque methodology. In practice, however, the same concentration pattern has emerged. Token holders do not research every proposal; they delegate to platforms like Snapshot, or they follow the recommendations of prominent community members, or they simply abstain. The result is a governance graph that is formally decentralized and practically centralized — comparable to the proxy advisory graph at the heart of the SEC’s enforcement action. I have seen this pattern across dozens of DAOs I have analyzed since 2021. The code never lies, only the auditors do, but in DAO governance, there are often no auditors at all. The truth is that proxy advisory firms and DAO delegates occupy the same functional niche, and both are subject to the same failure: they concentrate decision-making power in entities whose accountability depends entirely on disclosure norms rather than structural constraints. This suggests a deeper thesis: the SEC’s enforcement action is not an anomaly; it is a preview of the regulatory scrutiny that awaits the entire governance stack, both traditional and crypto-native. The question is not whether regulators will examine governance intermediaries more closely. The question is whether those intermediaries will build the transparency infrastructure before the subpoena arrives or after. My experience with Luna taught me that the market only discovers the real fragility of a system when the system is already in motion. In May 2022, I spent seventy-two hours tracing the exact sequence of oracle manipulations and liquidity drains that killed UST. At no point during that collapse did a regulator need to send a subpoena, because every transaction was visible on the ledger. The transparency was not because of regulatory pressure; it was because the system was built on-chain. ISS occupies the opposite position: it is a governance oracle that is entirely off-chain, with decision gates buried in email threads and spreadsheets that nobody outside the firm can inspect. The SEC cannot trace the development of an ISS recommendation the way I traced the collapse of UST. It has to subpoena the institution and ask for the emails. And when the institution says no, the regulator’s only recourse is an enforcement action. The on-chain/off-chain distinction is not a technical detail; it determines whether governance failures are discoverable in real time or discoverable only through legal compulsion. I should address the contrarian argument, because any honest analysis of this case has to acknowledge the possibility that the bulls are partly right. There is a coherent story in which the SEC’s enforcement action against ISS is a net positive for the industry, and it runs something like this. ISS refused to comply with a subpoena either because the subpoena was genuinely overbroad or because ISS believed that the SEC was exceeding its statutory authority. If ISS wins on those grounds, the case will establish important limits on the SEC’s investigative power — limits that the crypto industry itself should welcome, given the SEC’s aggressive interpretations of its own jurisdiction in enforcement actions against exchanges and protocol teams. The regulatory state has a tendency to expand through procedural pressure rather than substantive rulemaking. A court decision that forces the SEC to articulate a specific theory before demanding documents would be a victory for due process across all regulated sectors, not just proxy advisory services. Moreover, even if ISS loses, the case provides clarity. The SEC’s investigation, whatever its scope, will eventually produce findings, and the findings will define the boundaries of acceptable behavior. Market participants prefer defined boundaries, even when they are more restrictive than the status quo, because defined boundaries reduce uncertainty and motivate investment. The alternative — years of vague guidance and uncoordinated enforcement — is harder for businesses to navigate. From this perspective, the enforcement action is not a threat to the proxy advisory industry. It is the beginning of a rulemaking process disguised as an enforcement action, and its outcome will produce the regulatory clarity that institutions have been demanding for years. That counter-argument has real force, and it should be stated with rigor, not dismissed because it runs against the cynical reading of the case. But I believe it is incomplete, and the incompleteness matters for anyone trying to forecast the next five years. The bulls assume that the SEC’s enforcement action is bounded — that it will conclude with a settlement or a judicial ruling and that the boundaries established will be clear and predictable. My experience with regulatory process tells me otherwise. In 2025, when I worked with a legal-tech firm to analyze two hundred DeFi protocols for MiCA compliance gaps, I discovered forty percent had failed to implement proper KYC/AML checks. The report I published — titled “The Compliance Illusion” — made the case that most projects were running backwards toward compliance, treating it as a checkbox exercise rather than a continuous process. The same backward motion is likely in the proxy advisory industry. A settlement with ISS will not produce a clear rule; it will produce a set of injunctive terms that apply only to ISS, leaving the rest of the industry to guess which of those terms reflect the SEC’s general expectations. The ambiguity will not resolve quickly. It will be resolved through a series of follow-on examinations, additional subpoenas, and eventually, new rulemaking. That process could take five years or more. During those five years, the industry will operate under a shadow: every recommendation issued without full disclosure is a potential liability, and every client relationship is a potential legal entanglement. The economic impact of that shadow will exceed the cost of any settlement — not because the SEC is wrong, but because the regulatory system is structurally incapable of producing rapid, clear rules through enforcement alone. The code never lies, only the auditors do, but the auditors have just been subpoenaed, and their responses will be charted in legal filings that most market participants will not read until the damage is already done. There is also a more subtle risk that the contrarian story misses. The enforcement action could trigger a structural shift in how institutional investors use proxy advisory services, and that shift could have unintended consequences for market efficiency. If ISS comes under sustained regulatory pressure, its clients will increasingly hedge their reliance on its recommendations. They may adopt a broader set of independent research sources, or they may internalize more of their proxy analysis, or they may simply reduce their voting activity, particularly on contested proposals where the risk of legal challenge is highest. Abstention is the hidden variable in all governance systems. In DAOs, abstention routinely results in a small minority of engaged holders controlling outcomes; in public company governance, abstention among index funds is functionally equivalent to handing decisions to management. If the enforcement action causes institutional investors to withdraw from contested corporate governance, the result will be less shareholder oversight, not more. The SEC will have won a procedural battle and lost the substantive war. The purpose of proxy voting regulation is to protect investors; if the effect of enforcement is to reduce voting, it has failed. This is the counter-intuitive conclusion that the market has not priced: the enforcement action may actually weaken corporate governance in the near term, whatever its long-term regulatory benefits. These are the trade-offs that disappear when the analysis is reduced to legal headlines, and they are the trade-offs that matter for real market outcomes. My assessment of the likely resolution path is as follows. ISS will enter settlement negotiations with the SEC, not because it believes the subpoena was justified, but because the cost of continued resistance is prohibitive. Legal fees, client attrition, and the compounding uncertainty of an unresolved enforcement action will combine to make settlement the rational move at every stage. ISS will agree to produce the disputed documents, pay a penalty, and commit to a compliance enhancement plan. The SEC will announce the settlement as a victory for investor protection and a warning to other intermediaries. Glass Lewis will hire additional compliance officers and review its own document-retention policies. The smaller players will scramble to hire the few available compliance experts. And then, the real work will begin: implementing the transparency measures that should have existed long before the subpoena arrived. None of those measures will be cheap, and none of them will be perfect, because the transparency problem at the heart of the proxy advisory industry is not a legal problem. It is a data problem, and data problems are only solved by building the infrastructure that captures the data in real time. The infrastructure is not impossible to build. It has already been built, in prototype form, by the most sophisticated on-chain governance systems. The chasm between traditional aters and crypto-native governance has never been about the technology; it is about the willingness of incumbent intermediaries to give up opacity as a competitive advantage. That willingness will not emerge from an enforcement action. It will only emerge from a structural change in the economics of the industry — a change that makes transparency more valuable than secrecy. What would that structural change look like? The first mover to publish a fully auditable trail of its voting recommendation data — each source timestamped, each methodology step recorded, each conflict of interest disclosed — would have a transformative advantage. Such a firm would be immune to enforcement actions targeting opacity. It would court regulatory attention rather than fear it. It would offer clients not just a recommendation, but an unbroken chain of custody from raw data to final vot. That is the product that institutional investors should be demanding, and the fact that they are not demanding it is the real indictment of the industry. During the 2022 UST collapse, I published a technical post-mortem that debunked the claim that UST’s design could maintain a stable peg under stress. The post-mortem was effective not because I was a better analyst than the market — I was not — but because I built a traceable chain from on-chain transactions to economic conclusions. Nobody had to trust my opinion; they could verify my transactions. The proxy advisory industry has never embraced that model. It asks the market to trust its recommendations without providing the underlying evidence that would allow the trust to be verified. The SEC’s enforcement action is the market’s first real demand for that evidence, and the industry’s resistance is its first real answer. The takeaway from this case is not that proxy advisory firms are corrupt or that the SEC is a weaponized agency. The takeaway is that intermediaries who concentrate decision-making power must be structurally transparent, or they will become structurally unstable. ISS is not the villain in this story; it is the set-piece for a recurring drama that will play out across every layer of the financial system that sits between ordinary investors and the companies they own. The drama will replay the moment a governance oracle is asked to reveal its inputs and refuses. It will replay the moment an institution realizes that its power to shape decisions exceeds its accountability for those decisions. And it will replay the moment when the regulator steps in, not because it has a precise theory of what went wrong, but because the refusal itself is proof enough that the system needs a visit. For crypto builders, the lesson is closer than it appears. Every governance platform, every voting aggregator, every delegation layer will eventually face a similar subpoena — from regulators, from users, or from the adversarial researchers who expose the fragile premises at their heart. The identity of the challenger matters less than the question posed: where is the data? What are the rules? Who benefits from the opacity? The code is not an exemption from those questions. The code never lies, but the code also does not protect its operators from the responsibility to answer. Patterns emerge only when emotion is stripped away, and the emotional response here — a mix of industry panic and I-told-you-so glee — obscures the one pattern that matters. Governance transparency is not optional. It is not a regulatory constraint. It is the price of the power that every governance intermediary wants to hold. The SEC’s enforcement action is simply a reminder that the bill has come due, and the only question that remains is whether the industry will pay the bill quietly and reform, or pay it loudly and fight a war it cannot win. The evidence so far suggests the industry has chosen the fight. The evidence also suggests that the fight, like most fights against inevitability, will result in more cost, more delay, and the same outcome. Luna’s death was a math error, not a market crash, and the stabilization of a governance oracle is a process of arithmetic, not a matter of wills. Any system that does not reconcile its claims with its structure will eventually be reconciled by an external force. For ISS, the external force is the SEC. For the next intermediary in line, the external force may be a forensic analyst with a subpoena-shaped question. The market would be wise to build its transparency before that question arrives.