Building compliance into the operating model, not bolting it on

There are two ways to run compliance, and they feel completely different to the people doing the work. Bolted-on compliance is a separate step: do the work, then take it to a second desk for a check that slows you down and, because it comes after the fact, usually catches only what is easy to see. Built-in compliance is invisible: the control lives inside the work itself, at the moment the decision is made, so the right thing is the default and the wrong thing is hard to do in the first place. One is a tax on getting things done. The other is a feature of how things get done.

021.242.563.88530Bolted on:after the85Built in:inside the
Where compliance sits, by how effective it is. Built-in catches problems before they happen. Indicative. Source: operating-model design practice

Why bolted-on compliance fails quietly

Bolted-on compliance fails in two directions at once. It is slow, because every piece of work has to queue for a separate blessing, which breeds resentment and pressure to skip it. And it is weak, because a check after the fact can only review what it is shown, and people under pressure show it what will pass. The sign-off becomes theatre: a delay that provides an audit trail without providing much safety. Everyone can feel it is pointless, which is corrosive, because a control people believe is pointless is a control people learn to route around.

What built-in looks like in practice

Built-in compliance means the control is part of the tool, the form, the workflow, the system, not a person you visit afterwards. The payment cannot be submitted without the second approver, because the system will not let it. The unusual transaction is flagged as it happens, not found in a review months later. The risky clause is caught by the template before the contract is drafted, not after it is signed. The point is to move the control from after the decision to inside it, so that doing it right is simply how the work works, and doing it wrong takes deliberate effort.

The solution, as an operating-model blueprint

Move a control from bolted-on to built-in

  • Find the decision. Identify the exact moment the risk is created, the point of the actual choice.
  • Move the control to that moment. Put the check where the decision is made, not downstream.
  • Make the safe path the easy path. If compliant is harder than non-compliant, people will route around it.
  • Make the wrong path hard. Where you can, make the non-compliant action require deliberate effort or sign-off.
  • Instrument it. Let the system show you the exceptions automatically, instead of relying on a manual review.
  • Keep the human for judgement, not for rubber-stamping. People should handle the genuine grey areas, not the routine.

The prize: speed and safety together

The reason built-in compliance is worth the design effort is that it dissolves the usual trade-off. Bolted-on compliance forces a choice between fast and safe, and under pressure people choose fast. Built-in compliance gives you both, because the safe way is the fast way, the control is not a queue, it is a guardrail you do not even notice until you steer toward the edge. That is why the best-run regulated businesses do not feel slow. They have engineered the compliance into the road, so nobody has to stop at a checkpoint to prove they were driving carefully.

Questions to move compliance into the work

  • Where exactly is the risky decision made, and is our control there or downstream?
  • Is the compliant way genuinely easier than the non-compliant way?
  • Which of our sign-offs are real safeguards, and which are theatre people route around?
  • Could the system flag the exception automatically, instead of a manual review?
  • Are we using people for judgement, or wasting them on rubber-stamping?

Compliance bolted on is a checkpoint, resented and easily fooled. Compliance built in is a guardrail, invisible until you need it. The work of moving from one to the other is to find where each risk is actually created and put the control at that moment, make the safe path the easy one, and let the system watch for exceptions so people are freed for the genuine judgement calls. Do it and you stop choosing between fast and safe. You get the thing every well-run business quietly has: compliance you cannot see, because it is built into how the work is done.

Notes and sources

  1. Compliance by design and embedding controls into processes rather than adding them afterwards. Overview. Link. ↩
Cover of Compliance industry

From the book

The Compliance Business Model Navigator

Fifty business-model patterns behind the compliance industry, each explained in plain language and carried by a real, named company.

View on Amazon →

← Back to Writing