Back to Insights
    The End of "Bad Apples": Why a Systems View of Ethics Fails
    article· 7 min read

    The End of "Bad Apples": Why a Systems View of Ethics Fails

    For decades, organizations have blamed ethical failures on 'bad apples.' But regulatory guidance and behavioral science tell a different story: misconduct is a predictable outcome of flawed systems. This article explains why the 'bad apple' theory is a governance dead end and how to adopt a Human Risk Governance model that actually works.

    Most compliance programs are designed with a fatal flaw: they are built to catch 'bad apples.' This decades-old approach assumes that misconduct is the product of a few rogue employees with flawed character. When something goes wrong—from fraud to harassment—the organization launches an investigation, identifies the culprits, terminates their employment, and declares the problem solved. This narrative is simple, satisfying, and deeply reassuring to leadership. It is also fundamentally wrong, leaving organizations dangerously exposed.

    This 'bad apple' theory conveniently ignores a mountain of evidence from behavioral science and a clear shift in regulatory expectations. The U.S. Department of Justice, for example, explicitly states in its Evaluation of Corporate Compliance Programs that prosecutors must assess whether a company’s compliance program is 'adequately designed to prevent and detect wrongdoing' and is 'working in practice.' The focus is on the system, not just the individual. When misconduct occurs, regulators no longer see a single failure of character; they see a potential failure of the entire governance ecosystem.

    Blaming individuals allows organizations to avoid the difficult work of examining the systemic pressures, misaligned incentives, and cultural blind spots that truly drive misconduct. As Emerald EI Academy helps leaders understand, risk is an output of the organizational environment—the context in which decisions are made. Until the system is addressed, the cycle of failure is guaranteed to repeat. This isn't just a philosophical difference; it's a strategic error that invites regulatory scrutiny and undermines the very foundation of effective governance.

    Behavioral science research consistently shows that context, not just character, drives ethical decision-making. Good people can make profoundly bad choices under the right (or wrong) conditions. Understanding these conditions is the first step toward building a compliance program that works in the real world.

    One key finding is the power of situational pressure. Research by scholars like Dan Ariely has demonstrated that when people are placed under stress or believe they can rationalize their dishonest acts, their ethical guardrails weaken. In a business context, this can manifest as intense sales targets or 'what-it-takes' cultures that implicitly reward corner-cutting. When leaders fail to see how they are creating these pressures, they are engineering the very misconduct they claim to condemn. This is a core concept explored in The Pressure Principle: Why Good People Make Bad Decisions, which highlights the gap between intent and action.

    Another critical insight is the concept of 'ethical fading,' a term coined by researchers Ann Tenbrunsel and David Messick. It describes a process where the ethical dimensions of a decision disappear from view, obscured by a focus on other priorities like meeting goals or pleasing a supervisor. People become so focused on the business problem they need to solve that they fail to see the ethical problem they are creating. This is not a failure of character, but a cognitive failure driven by the environment. It is a critical human factor that most governance systems fail to measure or mitigate.

    A third factor is the normalization of deviance. What starts as a small transgression—a minor fudging of numbers, a slightly exaggerated claim—can become standard practice over time. This phenomenon was famously identified in the analysis of the Space Shuttle Challenger disaster and is visible in countless corporate scandals. Each small step away from the ethical baseline recalibrates the norm, making the next, larger deviation more likely. This is not about a single 'bad apple,' but a system that allows its ethical standards to erode incrementally, often without anyone consciously deciding to do wrong.

    Why does a company's reliance on the 'bad apple' theory matter? Because regulators have moved on. The DOJ, SEC, and other global enforcement bodies are now laser-focused on systemic issues. When they investigate misconduct, they don't just ask 'who did it?' but 'why did it happen?' and 'what did the company’s program do to prevent it?'. A governance approach that stops at firing the individual is a red flag for investigators, signaling that the company does not grasp the root cause of the failure and is therefore likely to be a repeat offender.

    This matters because regulators now evaluate the effectiveness of a compliance program based on its ability to influence behavior and culture, not just its ability to punish rule-breakers. An effective program is one that actively works to reduce pressure, counter ethical fading, and prevent the normalization of deviance. Proving this requires data—not just on policy distribution and training completion, but on the behavioral realities within the organization. As detailed in our guide on How Regulators Evaluate Compliance Program Effectiveness, the burden of proof is on the company to demonstrate its program 'works in practice.'

    Traditional compliance and risk management tools are ill-equipped for this challenge. They are built to manage rules, not human behavior. An over-reliance on annual training modules, policy attestations, and top-down communication fails because these methods do not address the powerful psychological and situational drivers of misconduct. They operate on the flawed assumption that if people know the rules, they will follow them.

    These approaches fail to provide the one thing regulators and boards now demand: evidence of effectiveness. A 98% training completion rate is not evidence that behavior has changed. A signed policy document is not proof that an employee can resist pressure from a manager. This is the central blind spot of traditional governance: it measures administrative activity, not behavioral outcomes. This leaves a critical gap that Emerald EI Academy's Human Risk Governance perspective is designed to fill.

    The Human Risk Governance perspective reframes the problem entirely. It moves beyond the 'bad apple' fallacy to see misconduct as a measurable output of the organization's systems, culture, and leadership. From this viewpoint, behavior is not an unknowable 'soft' issue but a critical form of data. Decisions, especially those made under pressure, are the primary source of risk, and they can be analyzed and understood.

    This approach provides a defensible, evidence-based framework for governance. Instead of relying on intentions and attestations, it focuses on measuring the human factors that predict risk. It examines the emotional competencies—like the ability to recognize pressure or the self-awareness to see an ethical conflict—that determine whether an employee will speak up or stay silent. By integrating insights from behavioral science, it makes the 'human element' visible, measurable, and manageable, offering a smarter way to lead.

    To truly mitigate human risk, organizations must stop hunting for bad apples and start examining the barrel. The data is unambiguous: organizational context, not individual character, is the primary driver of misconduct. Your compliance program must be redesigned to address the systemic pressures, cognitive blind spots, and cultural norms that lead good people to make bad decisions.

    Stop chasing completion rates. Start measuring decision-making under pressure. Your goal is not to prove people *read* the policy, but to prove they can *apply* it in a high-stakes moment.

    Re-evaluate your incentive structures. Are you inadvertently rewarding the very behaviors you publicly condemn? As the Wells Fargo scandal demonstrated, misaligned incentives are a root cause of systemic failure.

    Invest in measuring the 'human layer' of your governance. This means assessing the emotional competencies—like self-regulation and empathy—that enable employees to navigate ethical gray areas. These are not soft skills; they are critical risk-control functions.

    Shift your focus from punishing failure to understanding it. Every instance of misconduct is a data point that reveals a weakness in your system. Use it as an opportunity to learn and improve, not just to blame and forget.

    Ultimately, building a defensible, effective compliance program requires a new lens. It demands that leaders move beyond the reassuring simplicity of the 'bad apple' story and embrace the complex, measurable reality of human behavior. By understanding how risk is created at the human layer, organizations can finally move from a reactive posture to a proactive one, building the kind of resilient, ethical culture that regulators demand and stakeholders deserve.

    Sources

    • U.S. Department of Justice, Evaluation of Corporate Compliance Programs, 2020.
    • Ann E. Tenbrunsel and David M. Messick, Ethical Fading: The Role of Self-Deception in Unethical Behavior, Social Justice Research, 2004.
    • Dan Ariely, The (Honest) Truth About Dishonesty: How We Lie to Everyone—Especially Ourselves, 2012.
    • Diane Vaughan, The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA, 1996.