Compliance Training Has a Behaviour Problem

A 99 per cent completion rate may look impressive, but it says little about what an employee will do when a lucrative client, impatient manager or suspicious transaction creates real pressure. Across the EU and UK, financial crime, sanctions, data protection, AI and conduct obligations increasingly require judgement, not memorised rules. The Financial Conduct Authority (FCA) itself identifies interactive, realistic, role-relevant scenarios as a positive training indicator. Annual e-learning followed by predictable multiple-choice questions is therefore no longer enough. Tomorrow’s compliance training must be risk-based, personalised, experiential, continuous and measurable. If behaviour does not change, can the training really be described as effective?

Knowing the Rules Rarely Changes Behaviour

Annual compliance training often creates an illusion of competence. Employees may pass a test in January yet struggle to recognise a sanctions risk or data-protection problem just months later. The forgetting curve captures a simple reality that without reinforcement, memories weaken over time. Rather than repeatedly presenting information, organisations can use spaced learning and retrieval practice, asking employees to recall and apply key principles at intervals.

This means replacing the annual compliance “event” with short interventions throughout the year. A procurement manager recording hospitality might receive a 60-second conflicts reminder, while a payments employee encountering an unusual transaction could receive a sanctions prompt at the point of risk. Near misses, regulatory changes and internal mistakes can also trigger rapid micro-learning.

The approach fits an environment where EU and UK requirements on sanctions, financial crime, AI and data protection keep evolving. The Information Commissioner’s Office (ICO) already stresses appropriate refresher training and warns that staff knowledge diminishes without it. Compliance should therefore become a continuous reinforcement cycle, connecting learning to the moments when judgement actually matters.

Put People Under Pressure

Knowing a rule in a quiet training room is very different from applying it when revenue, reputation or an impatient director is at stake. Compliance training should therefore rehearse difficult decisions, not merely explain regulations. Branching simulations can place an employee before unusual customer activity, then introduce pressure from a valuable client and senior manager. Each choice changes what happens next.

Sanctions exercises should likewise move beyond obvious name matches. UK guidance stresses that firms may need to investigate ownership and control, including entities that never appear on the sanctions list. Similar simulations can cover bribery approaches, data breaches, misleading customer communications and inappropriate AI use.

Employees should justify decisions rather than simply select A, B or C. Teams can also face timed “compliance stress tests”, with new information arriving throughout the exercise. AI can carefully vary characters and circumstances, preventing memorised responses. Crucially, debriefing should expose how hierarchy, ambiguity and commercial pressure affected judgement. Compliance training should become less like an online textbook and more like a flight simulator.

One Size Trains Nobody

Giving everyone the same compliance course is administratively convenient, but operationally questionable. A board director needs to understand oversight and accountability, while a relationship manager confronts customer risk, procurement faces third-party bribery concerns, developers handle data and AI risks, and payments teams encounter suspicious transactions.

Instead, organisations can create risk personas using role, authority, system access, geography and external exposure. Training priorities should then incorporate complaints, incidents, audit findings and control failures. This reflects the FCA’s expectation that Conduct Rules training should be relevant to individual roles and use scenarios showing their particular nuances.

Adaptive learning can go further. If someone struggles with sanctions ownership questions, subsequent exercises can concentrate there. AI could recommend similarly targeted refreshers, while just-in-time prompts appear before higher-risk activities.

However, personalisation must not become surveillance. The ICO warns that worker monitoring must be lawful, fair, transparent and proportionate. Organisations should therefore personalise learning around genuine risk exposure, not intrusive behavioural profiling.

The practical answer is a risk-to-learning map, connecting each material risk with those able to create, detect, prevent or escalate it.

When Culture Defeats Compliance

Sometimes employees know the rule perfectly well. The problem is that everything around them rewards breaking it. A salesperson trained to treat customers fairly may still cut corners when bonuses, aggressive targets and an impatient manager reward volume above judgement. The FCA recognises this connection, identifying leadership, governance and approaches to rewarding people as important drivers of culture.

This is the organisation’s say–do gap. Training says, “challenge inappropriate behaviour”, while hierarchy whispers “do not challenge the boss”. Psychological safety therefore matters. The FCA argues that environments where employees feel safe to speak up can reduce inappropriate risk-taking and misconduct.

Training must consequently connect with incentives, performance management, speak-up arrangements and leadership accountability. EU whistleblower rules similarly require effective confidential reporting channels and appropriate follow-up.

Organisations should also try friction mapping, identifying recurring points where commercial objectives collide with compliance requirements. If employees repeatedly report that a procedure is unworkable, investigate the process instead of ordering another course. Managers can then discuss these real dilemmas in team meetings. Repeated failure may signal a badly designed system, not an untrained employee.

Proving That Compliance Training Actually Works

A near-perfect dashboard showing training completion measures activity, not effectiveness. The better question is what employees do differently afterwards. Are suspicious transactions escalated faster? Are recurring errors declining? Are employees making better decisions when scenarios become ambiguous?

Start by establishing a behavioural baseline. Test employees with realistic simulations before training, then repeat comparable exercises afterwards. Combine the results with near misses, reporting quality, repeat breaches, control failures and escalation times. The FCA explicitly identifies assessment of training effectiveness as a positive indicator, rather than treating delivery alone as sufficient.

Organisations can go further by linking learning analytics with risk analytics. If weak sanctions judgement coincides with increasing exposure to higher-risk customers, that overlap deserves attention. Different interventions can also be tested with comparable groups to discover what genuinely improves decisions.

Metrics still require interpretation. Rising whistleblowing reports might indicate worsening conduct, but they could equally signal greater confidence in speaking up. Boards therefore need trends, context and outcomes, not seductive percentages.

A Compliance Behaviour Dashboard should measure capability, decision quality and changing risk, turning training from an attendance exercise into evidence of behavioural improvement.

From Course Completion to Compliance Capability

The future of compliance training is not another annual course with a smarter quiz. It is a shift from annual training to continuous reinforcement, rule memorisation to decision practice, generic content to risk-based personalisation, individual responsibility to supportive organisational environments, and completion rates to behavioural evidence. UK regulators already emphasise realistic scenarios, role-relevant training, regular reinforcement and effectiveness assessment.

In increasingly complex EU and UK regulatory environments, employees must recognise emerging risks, exercise judgement and act correctly when commercial pressure makes the compliant choice difficult. A completed module proves attendance. A well-handled sanctions alert, customer dilemma or data incident demonstrates capability. Compliance leaders should therefore stop asking, “Has everyone completed the training?” and start asking, “What can our people now do differently because of it?”

And what about you…?

  • Which compliance situations create the greatest pressure on employees in your organisation, and does your current training realistically prepare them for those moments?
  • If you stopped measuring course completion, what behavioural indicators could you use to demonstrate that your compliance training is genuinely working?