Overview
Security teams were spending too much time on compliance
An annual survey of 77 IBM Cloud Security Focals revealed a significant efficiency problem. 79% spent at least a quarter of their time supporting compliance activities, while only 5% were dedicated solely to Security Focal responsibilities.

Results from 2023 Annual Cloud Security Focal Survey
The problem
Discovery
Starting with the people closest to the problem
I partnered with the Security Program Director, Security Focal lead, and UX Researcher to plan and facilitate a four-day, in-person design thinking workshop with 14 Security Focals from across IBM Cloud to dig into where that time was going.
We started by mapping their existing workflows to identify repetitive, time-consuming tasks and create an as-is journey.

In-person workshop with Security Focals at the IBM Austin Design Studio
— IBM Cloud Platform Security Program Director
Audit support emerged as a problem worth solving
The workshop surfaced audit support as one of the biggest opportunities to reduce repetitive compliance work.
Preparing for an audit required Security Focals, Compliance Analysts, and external auditors to coordinate evidence and reviews across multiple disconnected systems.

Current internal audit processes require back and forth between 3 tools
Designing an internal solution would have been relatively straightforward: understand IBM's existing workflow and consolidate it into a better interface, but we wanted the product to eventually serve customers outside IBM.
That meant distinguishing between fundamental audit-management needs and processes that existed simply because that's how IBM had historically operated.
How might we…
Simplify IBM's audit workflow while creating an experience grounded in industry practices that could scale beyond IBM?
Research
Designing for IBM today and external customers tomorrow
The product needed to improve audit management for IBM's internal teams in the short term, but the long-term vision was to offer it to external customers. Simply digitizing IBM's existing process could make the product difficult to scale, while designing only around industry standards could fail to meet the needs of our first users.
Our research focused on answering two questions:
Question 1
What does a mature audit management product need to support?
Question 2
How do IBM's internal processes compare to the broader market?

Findings:
Most competitors offered mature audit capabilities as part of much larger platforms, the most notable being:
Centralized Dashboard
Understand progress and outstanding work.
Pre-defined frameworks
Support established frameworks such as SOC 2.
Evidence collection
Collect and review manual and automated evidence.
Reporting
Prepare audit information for external auditors.
We recruited a diverse sample set of participants in order to get their unique perspectives. We conducted interviews with:
6 Internal compliance analysts
To understand IBM's existing workflows, terminology, and pain points
9 External compliance analysts
To understand industry workflows and expectations
4 Security executives
To understand the broader requirements in organizations
Findings:
IBM teams had developed their own audit terminology, so industry-standard terms didn’t always match their expectations. We needed to balance familiarity for internal users with language that could scale externally.

I collected UMUX-Lite scores to measure both ease of use and whether the concept met participants’ needs. Participants generally found the experience easy to use, but internal users rated its feature coverage lower than external users.
This reinforced a key tension in our strategy: a scalable product could follow industry conventions, but still needed to account for IBM-specific workflows in the short term.

Participants valued the efficiency of an in-platform auditor experience, but wanted to review and approve evidence before it was shared externally. This reinforced that automation needed to preserve human oversight for sensitive audit workflows.

““I am a huge fan of automation but some things need manual intervention.”
— Research participant
Strategy
From research to product direction
The research challenged key assumptions about how the product should work. I translated the findings into a North Star experience and presented the vision to leadership to align on product direction.
From there, I worked with product, engineering, and security to prioritize an MVP focused on audit progress, control management, and evidence collection, while laying the foundation for future capabilities.
Conclusion
Design isn't always about the final UI
This project reinforced that some of design's most valuable work happens before a polished interface exists.
Through research and design thinking, we challenged assumptions, shaped the product strategy, and gave leadership a clearer direction for what to build.
What I learned
Although the product was discontinued before launch, the work taught me that design is as much about creating clarity, influencing decisions, and solving the right problem as it is about the final interface.






