When 100% Compliance Does Not Mean You Are Compliant

Imagine the dashboard showing 100% training completed, every policy reviewed, thousands of transactions screened and barely an overdue action in sight. Yet, at the same time, customers are being harmed and employees are quietly bypassing controls. That is the uncomfortable gap between compliance activity and compliance effectiveness. The Financial Conduct Authority’s (FCA’s) July 2026 outcomes-monitoring guidance reinforces the distinction, urging firms to understand customers’ actual experiences, identify emerging risks and act before harm occurs, rather than merely collecting data and producing reports. A green dashboard may look reassuring, but the harder question is whether the organisation is genuinely safer.

The Compliance Theatre Problem

Boards love green dashboards. Training completion hits 99%, policies are approved on time, alerts are investigated and audit actions are closed. Yet these numbers can create compliance theatre. This means visible activity that looks reassuring without proving that risk is actually controlled. The proxy problem is simple. Organisations measure what is easy to count, not necessarily what matters.

Imagine a firm where almost everyone has completed anti-bribery training. When a lucrative deal involves a questionable intermediary, however, employees fail to recognise the warning signs or escalate concerns. The training KPI is green but the organisation’s real capability is red.

EU expectations increasingly make such superficial assurance harder to defend. The European Banking Authority’s (EBA’s) revised internal-governance work, reflecting CRD VI (Capital Requirements Directive VI) and DORA ( Digital Operational Resilience Act), strengthens attention to documented responsibilities, robust governance and effective risk control. For compliance leaders, this should prompt a tougher question…. did the control merely happen, or did it work?

For these reasons, boards need indicators that test outcomes, recurrence, escalation and behaviour alongside completion statistics. A completed control is evidence of activity. An effective control is evidence that risk was genuinely changed.

What Does ‘Effective’ Compliance Actually Look Like?

Effective compliance asks a deceptively simple question: what changed because we intervened? Investigating 12,000 alerts sounds impressive, but did suspicious activity surface earlier? Achieving 98% training completion looks reassuring, but did employees subsequently make better decisions?

A more revealing model is activity → behaviour → outcome. Training is delivered, employees become quicker to escalate suspicious behaviour, and potential incidents are identified before losses occur. Likewise, reviewing 200 complaints matters less than whether recurring customer harm subsequently falls.

This requires sharper indicators, including repeat breaches, management overrides, escalation speed, remediation durability and control failures that stubbornly reappear. Organisations could also measure the risk-response gap, that is the time between the first warning signal and meaningful management action.

This approach echoes the FCA’s increasingly outcome-focused supervision. Its 2025–30 outcomes and metrics framework measures progress against regulatory outcomes, while Consumer Duty expects firms to monitor whether customers actually receive good outcomes.

The message for compliance teams is clear. Stop showcasing busyness and start demonstrating impact. The strongest metric is not what compliance completed, but what became safer, fairer or less likely to fail.

Would Your Controls Work on a Bad Day?

A control that works in calm conditions may buckle under pressure. Compliance teams should therefore stop merely asking whether controls exist and start trying to break them.

Consider a high-value client demanding approval at 4.45 pm on Friday, or a senior executive urging staff to bypass a procedure. Add in a sanctions alert or an AI tool confidently producing the wrong recommendation. Do employees challenge, escalate and document correctly when hierarchy, ambiguity and commercial pressure collide?

Compliance can borrow from cyber resilience through tabletop exercises, mystery testing, simulated breaches and red-team challenges. These expose vulnerabilities that immaculate policies may conceal. In financial services, DORA provides a powerful precedent. Applicable since January 2025, it requires digital operational resilience testing, including scenario-based and penetration testing, to uncover weaknesses and drive remediation.

The wider lesson extends beyond technology. Compliance functions could deliberately test sanctions, conduct, fraud and escalation controls under hostile conditions. Resilience should be demonstrated through evidence, not inferred from documentation. After all, if a control works only when everyone behaves perfectly, is it really a control?

Measuring the Compliance Culture People Actually Live

Culture is difficult to capture in a spreadsheet, but behaviour leaves footprints. Instead of relying on annual surveys and training completion, compliance teams can examine behavioural signals such as near misses, management overrides, repeated exceptions, escalation times, complaints and control-function turnover.

Crucially, silence can itself be data. If a high-risk division reports almost no concerns while comparable teams regularly speak up, management should question whether employees feel safe raising problems rather than celebrate an immaculate record.

This distinction separates stated culture from revealed culture. A company may proclaim “customers first”, but if bonuses overwhelmingly reward sales, employees receive a louder message from their payslips. The FCA’s Consumer Duty rules explicitly connect governance and culture with incentives and warn against remuneration structures that conflict with good customer outcomes.

In the EU, a response to the EBA’s revised internal-governance consultation proposed measurable risk-culture indicators including speak-up volumes, closure times, near misses, overrides and customer detriment. These measures expose what glossy culture statements cannot. Culture is ultimately what people do when the policy manual is closed.

Turning Failures, Data and AI into Continuous Improvement

The strongest compliance functions do not simply record failures. They learn from them. That means moving from annual reviews to continuous sensing, isolated incidents to pattern recognition, and static controls to controls that evolve as risks change.

AI and advanced analytics can connect signals. A rise in management overrides may appear harmless. So might unusual complaints or slower escalation times. Viewed together, however, they could reveal an emerging conduct problem before it becomes a regulatory crisis.

This creates a new measure, known as control half-life. How long does remediation remain effective before workarounds, new technology or changing behaviour erode it? Tracking recurrence can reveal whether a “closed” finding was actually fixed.

AI, however, can become box-ticking with better graphics. Blind reliance on automated risk scores may replace human judgement rather than strengthen it. The EU AI Act emphasises risk management, data quality, traceability and human oversight for high-risk systems. In the UK, the FCA stresses AI governance, testing, monitoring and explainability.

The goal is therefore continuous learning, not automated reassurance. The best compliance system does not merely detect failure. It learns from failure.

From Proof of Activity to Proof of Effectiveness

Compliance is moving from completion to capability, activity to outcomes and policies to behaviour. Regulators increasingly expect firms to demonstrate what controls achieve, not simply that they exist. The FCA’s Consumer Duty, for example, requires firms to assess whether customers are actually receiving good outcomes. Boards should therefore look beyond reassuring green dashboards towards continuous testing, behavioural evidence and lessons from failure. A green indicator is valuable only when it reflects reality. Tomorrow’s strongest compliance functions will measure whether interventions reduce harm, strengthen decisions and remain effective as risks evolve. The defining question is no longer, “Did we follow the process?” but “Did the process change the outcome?”

And what about you…?

  • Which of your current “green” compliance indicators could be hiding behavioural problems, ineffective controls or emerging risks?
  • What behavioural signals could you use to understand your organisation’s real compliance culture beyond training completion rates, policies and employee surveys?