The mystery of repeated mistakes

Why do companies continue to fail in precisely the same ways despite decades of regulation, thousands of enforcement actions and billions spent on compliance? Across the UK and Europe, regulators repeatedly uncover the same weaknesses. Warnings are ignored, challenge is muted, risks are poorly escalated and departments operate in isolation. Yet organisations have never possessed more policies, dashboards or compliance manuals.

The Financial Conduct Authority (FCA) increasingly places culture and governance at the centre of supervision, while European regulators continue to stress risk culture and internal governance. Despite this, enforcement cases regularly reveal that senior leaders received incomplete information or failed to act upon it. Recent investigations have shown that poor oversight, weak accountability and inadequate challenge remain stubbornly common.

The paradox is striking. Businesses are drowning in data but starving for insight. Compliance functions have expanded, ESG reporting has multiplied and risk registers have grown longer. Nevertheless, the same failings continue to appear, suggesting that modern enforcement is exposing organisational weaknesses rather than isolated mistakes.

The new pattern: silo failures are becoming system failures

For many years, corporate responsibilities were neatly divided. Compliance teams interpreted regulations, risk specialists managed threats, sustainability departments handled ESG matters and fraud investigators examined misconduct after the event. Regulators now see these boundaries breaking down. A misleading environmental claim may become a fraud allegation. A cyber attack can expose failures in governance. Supply-chain weaknesses increasingly raise human rights concerns, while poorly supervised artificial intelligence tools create conduct and accountability risks. The result is that apparently separate problems often originate from the same organisational weakness.

Recent greenwashing investigations in Europe have demonstrated how inaccurate sustainability statements can trigger regulatory action and reputational damage. Sanctions breaches have also revealed inadequate oversight of third parties and supply chains. At the same time, new European due diligence requirements are forcing boards to examine labour practices and supplier risks more closely.

Regulators are therefore becoming less interested in isolated incidents. They increasingly investigate how information flows through organisations, whether warnings reach senior leaders and how decisions are challenged. The modern enforcement case is no longer about a single failure. It is about whether the entire system was capable of preventing it.

Five recurring failures regulators repeatedly identify

Risk information doesn’t travel

Regulators across Britain and Europe continue to encounter the same organisational weaknesses. The first is that risk information never reaches the board in its original form. Directors receive lengthy dashboards and reassuring summaries while uncomfortable messages are filtered out or delayed. Important warnings often disappear between management layers.

Incentives win

Second, incentives frequently overwhelm controls. Sales targets, ambitious ESG commitments and pressure to deploy artificial intelligence tools quickly can encourage employees to bypass procedures. Compliance departments rarely succeed when commercial rewards point in the opposite direction.

Risky relationships

Third, third-party risk remains the weakest link. Organisations increasingly depend upon suppliers, contractors, agents and cloud providers. Sanctions breaches, bribery cases and supply-chain failures regularly arise outside the company itself. Regulators now expect firms to understand the risks created by their external relationships.

Overpromising

Fourth, public ESG commitments often exceed internal capabilities. Companies announce climate targets, diversity ambitions and ethical supply-chain promises that cannot be supported by reliable data or effective governance. This gap has contributed to growing scrutiny of greenwashing and misleading disclosures.

Hiding in plain sight

Finally, known problems frequently remain unresolved. Internal audits, whistleblowers and compliance reviews often identify concerns years before regulators intervene. Yet organisations delay action because of competing priorities or optimism that issues will disappear.

Perhaps the greatest lesson is that regulators rarely uncover entirely new problems. They usually discover old warnings, ignored reports and unanswered questions. Enforcement cases therefore reveal not simply individual mistakes but an organisational failure to listen, challenge and act before small weaknesses become major scandals.

The AI problem: a new source of recurring failure

Artificial intelligence is rapidly becoming the newest source of recurring enforcement failures. Firms now use AI-generated reports, automated compliance monitoring, AI-assisted risk assessments and ESG reporting tools to process vast quantities of information. The difficulty is that these systems often create an illusion of certainty.

Several organisations have already discovered that inaccurate outputs and model bias can produce misleading results. In 2023, lawyers using ChatGPT submitted fictitious legal authorities to a US court, demonstrating how unchecked AI can generate convincing but false information. Financial regulators have also warned that automated decision-making may embed hidden biases and weaken accountability.

The EU AI Act and recent guidance from the UK’s  FCA  increasingly emphasise governance rather than technology. Regulators want firms to identify who owns AI decisions, how models are tested and how AI-generated conclusions are challenged.

Many organisations are responding by introducing human review panels, independent model validation and mandatory checks for high-risk decisions. The lesson is straightforward. Artificial intelligence may improve efficiency, but enforcement cases increasingly show that responsibility cannot be delegated to an algorithm.

The UK and EU enforcement shift

The UK and the European Union are taking different regulatory routes, yet both are moving towards the same destination. In Europe, sustainability reporting obligations, supply-chain due diligence requirements and anti-greenwashing initiatives are pushing companies to prove that their public commitments match their internal controls. New digital and artificial intelligence rules are also increasing expectations around accountability and governance.

The UK has concentrated on economic crime reforms, operational resilience and stronger corporate fraud prevention measures. Regulators are paying closer attention to organisational culture, board oversight and the way important decisions are challenged.

Despite these differences, both jurisdictions increasingly examine how companies make decisions rather than simply whether a rule has been broken. Investigators want to understand who knew about emerging risks, how concerns were escalated and whether management acted quickly enough.

The message is becoming unmistakable. Good governance, clear accountability and a healthy organisational culture now matter as much as technical compliance. Future enforcement cases are therefore likely to focus less on isolated incidents and more on the quality of corporate decision-making.

Conclusion: fewer controls, better conversations

The instinctive response to every enforcement failure is to introduce another policy, another training programme or another control. Yet recent cases across compliance, risk, ESG and fraud suggest that organisations rarely suffer from a shortage of rules. They suffer from a shortage of honest conversations.

The next generation of enforcement cases is unlikely to arise because regulations are unclear. Problems emerge when information remains trapped within departments, assumptions go unchallenged and warning signs are ignored. Boards may receive more data than ever before, but they still struggle to hear uncomfortable truths.

Effective organisations therefore need fewer reports and better questions. They need managers who escalate concerns, directors who challenge assumptions and cultures that reward openness rather than silence.

Regulators seldom discover problems that companies did not already know about. Their real discovery is often that nobody listened. In the end, enforcement is less about technical failure and more about whether organisations possess the courage to confront inconvenient truths.

And what about you…?

  • Have you observed situations where ESG commitments or policies were not fully reflected in actual business practices, and what risks did this create?
  • If a regulator were to review your organisation today, which area of compliance, risk management, ESG, or fraud prevention would cause you the greatest concern?