Why "we've always done it this way" quietly costs firms the most
Published

Every firm has a phrase that shuts a conversation down before it starts. If compliance raises a better way to run client due diligence, more headcount, new tooling, a different process, the answer often arrives before the question is finished: "it's just how we've always done it."
Sometimes that's exactly what it means. More often, though, it's standing in for something harder to say. On our Compliance Unfiltered webinar this year, compliance leaders told us one of their toughest challenges is making the business case for change at all, especially when what they're asking for is more headcount or new technology. Call it inertia with a business case attached: the current process, whatever it costs, still passes a regulator check, nobody's been asked to properly own fixing it, and the time or money to change it properly never quite turns up this quarter.
And because nobody's ever had to put a number on what it's actually costing, the phrase gets to keep winning. That's the number this piece is trying to find.
What ‘the old way’ is actually built from
Most firm leaders have never had to put a figure on what the workarounds actually cost, and may not even know there's a figure to find. It's a silent killer of time: it doesn't show up as a line item or trigger an alert; it just quietly drains hours nobody budgeted for.
It's worth trying to find that figure anyway. A workaround doesn't appear on an invoice or sit in a cost centre. It shows up in three quieter places instead.
The hours: Our own research into 150 senior compliance leaders found teams already absorbing regular overtime just to keep pace. That tracks with the wider market: one 2026 analysis of UK compliance spending found that 68% of compliance professionals spend up to half their working time on tasks they believe could be automated, out of an estimated £33.9 billion UK businesses spend on compliance activity each year. That's not a busy month. That's the system working exactly as it was never designed to.
The ceiling: Most compliance teams aren't resourced to grow at the same rate as the firm around them, which means every workaround added is one more thing a small team has to absorb on top of everything else. Somewhere, something gives.
The seniority, misspent: The most experienced person on the team ends up handling admin that could sit anywhere, while the judgement only they can give waits its turn. That's an expensive way to spend anyone's time, let alone your most senior person's.
The risk sitting behind the convenience
None of this stays a private inconvenience for long, and it isn't only a time cost either. Here's what's worth knowing: these aren't hypothetical numbers, they're what a workaround-shaped gap has actually cost firms in the last year.
One 2026 review of Solicitors Regulation Authority (SRA) enforcement activity found the regulator had issued more than 35 anti-money laundering (AML) fines totalling over £565,000, with individual penalties ranging from under a thousand pounds to £300,000 for historic control weaknesses, £172,934 for failing to identify a politically exposed person, and £120,000 for 15 years of non-compliance.
Across the same period, the SRA carried out 935 proactive AML engagements, nearly double the previous period. The most common gaps: missing or inadequate risk assessments, incomplete source of funds documentation and defective AML policies and controls, which is exactly where manual, stitched-together processes tend to leave holes, and exactly where a workaround-built process struggles to show its working.
Ask yourself the question a regulator, an insurer or a client might ask tomorrow: if you needed to show the evidence, across every file, right now, could you? For a firm running on workarounds, the honest answer is usually "some of it, somewhere."
The backdrop makes that answer riskier by the year. UK Finance's 2026 Annual Fraud Report put losses to fraud at close to £1.28 billion, with criminals increasingly using AI to generate convincing fake documents and identities.
That matters here specifically because it's the manual, eyeball-led checks- the ones workarounds tend to lean on hardest- that are easiest to fool. Scrutiny on client due diligence isn't going to ease off. A clear, current picture of your own compliance is worth having before anyone asks to see it, not after.
What changes when it's a decision, not an inheritance
"We've always done it this way" was never really a choice. It was the absence of one, made by default, one workaround at a time. Building client due diligence as a single, intelligent process is a decision a firm can make instead, and it's one leadership doesn't have to leave to chance, or to whoever happens to be under enough pressure to fix it themselves.
That's what Thirdfort's Client Due Diligence Platform is built to do: bring know your client (KYC) checks, ID document verification and source of funds into one place, with the oversight to see everything and the control to decide how it runs. Intelligent client due diligence, with you in control.
In practice, that means specific things change first. Every case that needs a human decision lands in a single Tasks view instead of being scattered across systems and inboxes. The Firm-wide insights dashboard gives leadership a live, firm-wide picture of risk across every check, instead of a report someone has to assemble by hand. And an Activity Log keeps a clear, time-stamped audit trail running in the background, so nobody has to reconstruct one when a regulator or insurer comes asking.
No more workarounds
Every firm's process had to start somewhere. For most, the first version was the workarounds. It's worth deciding, on purpose, what the next version looks like before a regulator, an insurer or a client asks you to explain the current one.
Intelligent client due diligence
See what your process could look like without the workarounds. We're ready when you are.
Subscribe to our newsletter
Subscribe to our monthly newsletter for recaps and recordings of our webinars, invitations for upcoming events and curated industry news. We’ll also send our guide to Digital ID Verification as a welcome gift.
Our Privacy Policy sets out how the personal data collected from you will be processed by us.

