Back to Insights
    The Anatomy of a Compliance Failure: The Behavioral Science of Human Risk
    research· 7 min read

    The Anatomy of a Compliance Failure: The Behavioral Science of Human Risk

    Compliance programs are designed to govern behavior — yet the science explaining why capable, well-intentioned people violate rules rarely reaches the boardroom. The work of three researchers, on self-awareness, ethical fading, and psychological safety, maps the human layer regulators now expect organizations to measure.

    Most compliance failures are investigated as control failures — a missing policy, a broken approval chain, an incentive left unchecked. But by the time misconduct surfaces in an audit, the decisive events have usually already happened inside the heads of ordinary employees who did not think of themselves as doing anything wrong. The uncomfortable truth is that the behavioral science explaining these moments has existed for decades. Regulators have begun to catch up to it; most governance programs have not. Three bodies of research, taken together, describe the anatomy of nearly every human-driven compliance failure — and explain why documentation-based training almost never prevents one.

    Why do capable, well-intentioned employees commit compliance violations?

    Because compliance failure is rarely a single act of bad character. It is usually the product of three overlapping human blind spots — one at the level of the individual, one at the level of the decision, and one at the level of the group. Each has been mapped in independent research. Each is invisible to a program that measures training completion. And each becomes visible only when an organization examines behavior directly.

    Start with the individual. Organizational psychologist Tasha Eurich, drawing on a research program that reviewed thousands of prior studies, found that roughly 95 percent of people believe they are self-aware, while only about 10 to 15 percent actually are. The gap matters for governance because self-perception is the instrument every employee uses to judge their own conduct — and it is miscalibrated far more often than not. More pointedly, Eurich's work suggests that senior leaders are frequently *less* self-aware than their teams, because seniority insulates them from the honest, unfiltered feedback that keeps self-perception accurate. In a governance context, that is a structural hazard: the people who set the ethical tone of an organization are often the least able to see how their own signals actually land. A leader who believes they invite challenge, but does not, will never learn otherwise from inside their own head.

    Now the decision itself. Even a reasonably self-aware person does not weigh every choice as a moral one — and that is the second blind spot. Business ethicists Max Bazerman of Harvard and Ann Tenbrunsel of Notre Dame describe a phenomenon they call *ethical fading*: under performance pressure, competitive framing, or short-term incentives, the ethical dimension of a decision quietly drops out of the frame, so the person making it never registers it as an ethical decision at all. It is experienced instead as a business problem, a target to hit, a number to reconcile. Their broader concept of *bounded ethicality* holds that we routinely act against our own values without noticing, because the situation has been framed in a way that hides the ethical stakes from us. This is not the psychology of villains. It is the ordinary machinery of a pressured workplace — and it is, almost exactly, the mechanism that turned aggressive sales targets into millions of fraudulent accounts in the Wells Fargo case. When incentives make the ethical choice invisible, a flawless policy manual is powerless, because no one consulted it — they never saw an ethical question to look up.

    What is the difference between a compliance program that exists and one that works?

    A program that exists documents that expectations were communicated. A program that works changes what people do when the expectation collides with pressure. The distinction is behavioral, which is why documentation cannot evidence it — and why regulators increasingly ask for proof of the latter.

    That brings the third blind spot, at the level of the group. Suppose someone *does* see the problem clearly. Whether they act depends on the environment. Amy Edmondson, now of Harvard Business School, named the deciding variable *team psychological safety* — a shared belief that the team is safe for interpersonal risk-taking, so that raising a concern, admitting an error, or asking for help does not invite embarrassment or punishment. The question came from an earlier observation in hospital teams: better-performing units recorded *more* errors, not fewer, because a climate of safety made mistakes speakable rather than hidden. To test the idea rigorously, Edmondson then studied fifty-one work teams in a manufacturing company, and found that psychological safety drives *learning behavior* — asking questions, seeking feedback, discussing errors — which in turn drives performance. Safety does not lift results directly; it works only by making problems surface-able. The governance implication is direct. In an organization low in psychological safety, risk does not disappear; it goes quiet. Employees who notice misconduct calculate, usually correctly, that speaking up carries personal cost — and the information that could have prevented a scandal never reaches anyone able to act on it. This is not a soft observation: Edmondson's own survey measured the belief with items such as whether a mistake made on the team is "held against you" — the precise texture of a failed speak-up culture. It is why regulators now treat a functioning speak-up culture as evidence of effectiveness, and why validated, anonymous culture surveys have become central to how the DOJ and OIG evaluate whether a program is real. The behavioral dynamic Edmondson mapped is exactly what those surveys are built to detect.

    Read in sequence, the three findings describe a single failure with a predictable structure. An individual cannot fully see themselves (Eurich). Pressure hides the ethical stakes of a specific choice (Bazerman and Tenbrunsel). And the surrounding culture discourages anyone from naming what they observe (Edmondson). A compliance program built only on policies and completion records intervenes at none of these points. It assumes employees see themselves accurately, recognize ethical questions when they arise, and speak freely when they do — three assumptions the research has spent decades dismantling. This is the same conclusion regulators reached from the enforcement side: the U.S. Department of Justice's Evaluation of Corporate Compliance Programs instructs prosecutors to assess whether a program works *in practice* — a standard that only behavioral evidence can satisfy. The science and the enforcement posture have converged on the same human layer, and it is precisely the layer that Emerald EI Academy's approach to behavioral risk in governance is built to make visible and measurable.

    Strategic Insight: Treating self-awareness, ethical framing, and psychological safety as measurable governance variables is not a soft addition to compliance — it is the leading-indicator layer that documentation cannot reach. Boards should stop asking only "did employees complete the training?" and start asking "can our people see themselves clearly, do our incentives keep ethical stakes visible, and do our employees feel safe naming what they see?" Those three questions map the terrain where misconduct actually begins. Organizations that learn to measure and strengthen that terrain — through practiced decision-making, real-time behavioral feedback, and evidence of cultural health — turn compliance from a paper defense into a genuine, demonstrable capability. That capability is what regulators now reward, and what the next failure will test.

    Related Research: The Corner-Office Blind Spot: Why Governance Fails at the Top of the Org Chart — how the self-awareness gap explored in this piece compounds at senior levels, and why "tone at the top" cannot be self-assessed.

    Sources

    • Eurich, T. Insight: The Surprising Truth About How Others See Us, How We See Ourselves, and Why the Answers Matter More Than We Think. Crown, 2017. See also "What Self-Awareness Really Is (and How to Cultivate It)," Harvard Business Review, 2018. https://hbr.org/2018/01/what-self-awareness-really-is-and-how-to-cultivate-it
    • Bazerman, M. H., & Tenbrunsel, A. E. Blind Spots: Why We Fail to Do What's Right and What to Do about It. Princeton University Press, 2011. https://press.princeton.edu/books/paperback/9780691156224/blind-spots
    • Bazerman, M. H., & Tenbrunsel, A. E. "Ethical Breakdowns." Harvard Business Review, 2011. https://hbr.org/2011/04/ethical-breakdowns
    • Edmondson, A. C. "Psychological Safety and Learning Behavior in Work Teams." Administrative Science Quarterly, 44(2), 1999, pp. 350–383. https://doi.org/10.2307/2666999
    • U.S. Department of Justice, Evaluation of Corporate Compliance Programs, 2023. https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl