Most organisations have never spent more on compliance than they are today. Training programmes, policy updates, attestations and monitoring systems consume vast amounts of time and money. Yet regulators across the UK and Europe continue to uncover misconduct, governance failings and cultural weaknesses. The uncomfortable reality is that many firms can demonstrate extensive compliance activity but struggle to prove that their efforts are genuinely reducing risk.
Recent regulatory developments reflect a growing shift from process to outcomes. The UK’s Financial Conduct Authority (FCA) has repeatedly stressed the need for firms to deliver and evidence good customer outcomes rather than merely follow procedures. Meanwhile, European regulators are placing greater emphasis on governance, accountability and risk culture. At the same time, AI-powered monitoring tools and behavioural analytics are making it easier to identify gaps between documented controls and what employees actually do.
This raises a challenging question for modern organisations: is compliance truly protecting the business, or simply generating evidence that compliance took place?
When Did Compliance Become Theatre?
Somewhere along the way, compliance stopped being primarily about reducing risk and started becoming increasingly focused on proving that procedures had been followed. In many organisations, training completion rates became more important than whether employees actually changed their behaviour. Policy libraries expanded year after year, even when the underlying risks remained largely unchanged. Internal audits often rewarded the production of evidence, records and sign-offs rather than demonstrable improvements in risk management.
This phenomenon is often described as “compliance theatre”. The organisation appears well controlled because reports are filled with green indicators, completed checklists and reassuring statistics. Boards receive polished dashboards showing near-perfect completion rates, while deeper cultural or operational problems remain hidden.
The financial services sector provides several cautionary examples. Following major misconduct scandals, many firms invested heavily in documentation and mandatory training, yet regulators continued to identify weaknesses in culture and customer treatment. Similar patterns have emerged in healthcare, where extensive procedural compliance has not always prevented patient safety failures, and in technology companies that maintained detailed privacy policies while struggling to prevent data misuse. The result is defensible paperwork rather than genuine assurance.
Can You Measure What Really Matters?
Many compliance teams remain obsessed with activity metrics. They proudly report the number of policies reviewed, training completion and the volume of annual attestations collected. These figures are easy to gather and look impressive on board dashboards. Unfortunately, they often reveal little about whether risks are actually being reduced.
More progressive organisations are focusing on indicators that measure outcomes rather than effort. They track reductions in incidents, the speed with which concerns are escalated and resolved, levels of near-miss reporting and employees’ willingness to speak up when something feels wrong. These measures provide a far more realistic picture of organisational health.
In the UK financial sector, the FCA’s Consumer Duty has encouraged firms to focus on customer outcomes rather than procedural compliance. Across Europe, organisations are increasingly using behavioural analytics and risk-sensing technologies to identify emerging issues before they become serious problems. Some companies now monitor key risks continuously rather than relying on annual reviews that may already be out of date.
The challenge is simple but significant. Measuring effort is easy. Measuring impact, judgement and culture is considerably harder, but ultimately far more valuable.
The Cost of False Assurance
The greatest danger in compliance is not always non-compliance itself. It is the false belief that everything is under control. When leaders mistake activity for effectiveness, they create strategic blind spots that can leave serious risks undetected until it is too late.
Recent regulatory actions illustrate the problem. In both the UK and the EU, authorities are increasingly interested in whether controls actually worked rather than whether organisations can merely demonstrate that controls existed. A completed checklist offers little comfort if customers were harmed, data was compromised or misconduct went unchallenged.
The consequences can be severe. Regulatory penalties may follow, but reputational damage and customer mistrust often prove even more costly. The Post Office Horizon scandal showed how institutional confidence in established processes can obscure deeper problems for years. In financial services, repeated conduct failures have occurred despite extensive compliance frameworks and reporting structures.
Regulators are responding by placing greater emphasis on outcomes, accountability and operational resilience. The FCA’s Consumer Duty and the EU’s Digital Operational Resilience Act (DORA) both reflect this shift. Ultimately, recognising weaknesses and addressing them early is far safer than relying on reassuring reports that mask uncomfortable realities.
From Rule-Followers to Risk-Thinkers
Leading organisations are beginning to rethink a fundamental assumption about compliance. Rather than asking, “Did people follow the rule?”, they are increasingly asking, “Did people make the right decision?” This shift reflects the reality that modern risks often evolve faster than policies, procedures and training manuals can keep pace.
As a result, many firms are moving beyond traditional tick-box training towards scenario-based exercises that require employees to navigate realistic ethical dilemmas. Financial institutions, for example, increasingly use case studies and simulations to test judgement under pressure rather than simple knowledge recall. At the same time, organisations are introducing ethical decision frameworks that help staff balance commercial objectives with legal and reputational considerations.
Equally important is creating psychological safety. Employees who feel comfortable raising concerns are more likely to identify emerging risks before they become serious problems. Regulators in both the UK and EU have highlighted the importance of healthy organisational culture and accountability. Effective compliance ultimately depends on informed judgement, personal responsibility and the confidence to challenge questionable decisions, not merely on strict adherence to written rules.
Will AI Expose Compliance’s Greatest Weakness?
Artificial intelligence is rapidly transforming compliance from a retrospective exercise into a continuous process. Advanced analytics can now review vast volumes of emails, messages and transactions, identify unusual patterns and highlight emerging risks long before they appear in traditional reports. Financial institutions already use machine learning tools to detect potential market abuse and suspicious transactions, while healthcare and technology firms increasingly rely on AI-driven monitoring to identify operational and data protection risks.
This creates a provocative possibility. What happens when AI reveals that organisations with excellent training records, complete attestations and immaculate documentation are still experiencing poor decisions or recurring control failures?
The most forward-looking organisations are exploring AI-driven assurance, continuous controls monitoring and predictive compliance. Rather than waiting for annual audits, they can identify weaknesses in near real time and intervene before problems escalate. Yet there is also a danger. Some businesses may simply use AI to automate existing checklists and generate even more paperwork.
The real test is whether AI helps organisations understand risk more effectively. It could become the ultimate compliance enabler or the ultimate auditor of compliance theatre.
Outcomes, Behaviour and Judgement
The central question is no longer, “Are we compliant?” Increasingly, regulators, boards and stakeholders are asking whether compliance efforts are genuinely reducing risk and improving decision-making. Across the UK and EU, the direction of travel is clear. The focus is shifting from process to outcomes, from documentation to behaviour, from rule-following to judgement and from retrospective reviews to continuous monitoring. Organisations that continue to rely on compliance theatre may find themselves exposed. Over the next decade, the winners are unlikely to be those generating the most compliance activity, but those able to demonstrate that their compliance programmes genuinely work in practice.
And what about you…?
- Which of your current compliance metrics measure real behavioural change and better decision-making, rather than simply tracking training, policies and attestations?
- If AI were used to analyse your organisation’s communications, decisions and controls, would it confirm that your compliance framework is effective or expose a culture of sophisticated box-ticking?


