Compliance theatre: when ticking the box becomes the risk itself

Wells Fargo did all the compliance. It had a code of ethics, mandatory training, an ethics hotline and a compliance function. And under all of it, driven by brutal sales targets, employees opened around 3.5 million deposit and credit-card accounts that customers never asked for. The bank later paid three billion dollars to settle criminal and civil investigations.1 Every box was ticked while the harm was happening. That is not an argument for more boxes. It is the clearest possible warning about what boxes are for.

This is compliance theatre: the performance of being compliant, complete with binders, certificates and passed audits, running in parallel with a business that behaves however it likes. It is worse than doing nothing, because it manufactures false comfort. A board looks at the green dashboard and relaxes. The regulator, later, looks at the same dashboard and sees a company that documented its own failure in advance.

023.847.571.29595%Policieswritten92%Trainingcompleted30%Behaviouractually
The compliance gap: high on paperwork, low on the thing that matters. Indicative. Source: pattern seen across enforcement cases

Why box-ticking is actively dangerous

The danger is not that the paperwork is useless. It is that it substitutes for the real thing. Once the policy is written and the training is logged, everyone can say they did their part, and nobody owns the outcome. The control exists on paper, so no one checks whether it works in practice. Boeing had processes and sign-offs too, and 346 people died in two 737 MAX crashes tied to decisions that the paperwork was supposed to catch and did not.2 The documents were not the safeguard. They were the alibi.

The test: does the control change behaviour, or just record it?

The single question that separates real compliance from theatre is this: does this control change what people actually do, or does it only produce evidence that we told them to? A policy nobody reads, training nobody remembers, an attestation everyone clicks through, these record intent and change nothing. A real control makes the wrong action harder and the right action the default. Wells Fargo's problem was never a missing policy. It was a sales incentive that made cheating rational, sitting next to a code of conduct that made cheating forbidden. Behaviour follows incentives, not binders.

The solution, as a control diagnostic

Run each of your controls through this test

Ask of the controlTheatreReal
What does it change?Produces a recordChanges a behaviour
What happens if it is ignored?Nothing, until an auditThe work cannot proceed
Who owns the outcome?"Compliance"A named manager
Does it fight the incentives?Sits beside them, losingAligns with how people are paid and judged
Would it catch a real breach?Only after the factAt the point it happens

Any control that scores "theatre" on the incentives row is the one that will fail you, whatever its documentation looks like.

Fixing it starts with the incentives, not the policies

If you suspect you have compliance theatre, do not start by rewriting policies. Start by looking at what your people are actually rewarded and punished for, because that is your real control system whether you designed it or not. Where the incentive and the policy point in opposite directions, the incentive wins every time, and the policy just becomes the document that proves you knew. Align the two, put a named manager on the outcome rather than on the paperwork, and measure whether behaviour changed, not whether the training was completed.

Questions to tell theatre from the real thing

  • If a control were quietly ignored, would anything actually stop, or just an audit trail?
  • Where do our incentives and our policies point in opposite directions?
  • Who owns the outcome of each key control, by name, not by function?
  • Are we measuring behaviour change, or just completion and attestation?
  • Would our own dashboard have looked green the week before a scandal?

Ticking the box is not being compliant. It is being able to prove you were told, which is a very different and much weaker thing. The organisations that get caught are rarely the ones with missing paperwork. They are the ones whose paperwork was perfect and whose behaviour was not, because they built a compliance function to generate evidence instead of to change what people do. Compliance beyond ticking the box starts by admitting that the box was never the point. The behaviour was.

Notes and sources

  1. Wells Fargo agreed to pay 3 billion dollars over the opening of millions of unauthorised accounts. US Department of Justice. Link. ↩
  2. Boeing charged over 737 MAX fraud conspiracy tied to two crashes that killed 346 people, agreeing to pay over 2.5 billion dollars. US Department of Justice. Link. ↩
Cover of Compliance

From the book

Compliance Beyond Ticking the Box

Turn compliance from a cost you endure into a system that protects the business and drives its growth.

View on Amazon →

← Back to Writing