Why compliance programmes fail, and what the failure looks like from the inside
They rarely fail by missing a notification. They fail in the gap between knowing a rule exists and knowing which of your seven sites it lands on — and that gap has a recognisable shape.
Ask a compliance function what worries them and they will say missing something. Ask what actually went wrong the last time, and it is almost never that they did not know about the rule.
They knew. It was in a law firm update. Someone forwarded it. What went wrong was everything between knowing and doing.
The four failure modes
1. Known but not scoped
A notification arrives amending hazardous waste rules. Corporate compliance reads it and concludes it applies. It does — to four of seven plants, based on category and quantity thresholds. The assessment is done at group level, circulated to all seven, and three plants spend effort on something that does not apply while one plant with a threshold nobody checked is missed.
The failure is not detection. It is that scoping was done informally by someone with an incomplete picture of seven sites.
2. Assessed, but nothing durable produced
A workshop generates opinions in a spreadsheet. The spreadsheet reaches a conclusion. The project starts, the spreadsheet is superseded by a plan, and the reasoning evaporates.
Two years later the rule is amended. Nobody can tell what was assessed the first time, so the assessment runs again from scratch and reaches a different answer, which nobody notices because the first answer is not recoverable.
3. Assessed at the wrong altitude
The assessment concludes "this affects the EHS team". It does. It also affects procurement, because a supplier now needs an authorisation; finance, because the compensation is a provision; and legal, because a contract clause is now wrong.
Second-order impact is missed reliably, because manual assessment traverses about two hops before the assessor runs out of knowledge, and the chain crosses functions that do not talk.
4. Evidence assembled at the end
An inspector asks how you knew about a rule, when you decided what to do, who approved it and what confirmed it works. The answer is assembled from email, a shared drive and memory.
You can usually produce something. You can rarely produce something that looks like a controlled process, because it was not one — and under statutes with a due diligence defence, that is precisely the question.
What these have in common
Every one is a failure of connective tissue, not of information or effort.
The notification exists in one place. Which sites it affects lives in people's heads. The assessment lives in a spreadsheet. The action lives in a project plan. The evidence lives in email. Nothing links them, so every transition is a manual, lossy handoff performed under time pressure.
The team is not short of people to read more circulars. It is short of capacity because its people spend most of their time re-establishing connections that should have been persistent.
What a functioning version looks like
Obligations, not Acts, are the unit of work. You cannot assign or test "the Factories Act". You can assign and test "maintain the register of adult workers in Form 12 and produce it on inspection". Decomposition is unglamorous and it is the precondition for everything.
Sites are modelled, not remembered. Each site, its state, its category, its headcount, its licences, its processes — written down and traversable. Then scoping is a query rather than a judgement call.
Evidence is a by-product. If detection, scoping, assessment, approval and closure happen in one system, the audit trail exists because the work happened.
The uncomfortable implication
Most of the work is not technology. It is decomposition and modelling — writing down the obligations and writing down the sites. That is the part organisations most want to skip, and skipping it is why tools bought to solve this become an expensive alerting system with a dashboard.
The honest question to ask any vendor in this space, including us: what does it require you to write down, and is the organisation prepared to write it down? If the answer is nothing, you are buying an inbox.
Written by Ananya Bhat, Head of Regulatory Research
Part of the team that builds and maintains the Regulens obligation library and platform. If you disagree with something here, we would genuinely like to hear it — get in touch.