Why compliance workarounds happen, and how to tell which ones are a risk

Published

Workarounds blog

Every compliance team knows the moment a workaround comes to light. It might be a spreadsheet nobody mentioned, an onboarding step that's been quietly skipped for months, or a fee earner who never opens the AML policy and rings compliance instead. The instinct is to fix it straight away, but the most useful first step is to ask why it's there.

That was the thread running through our recent webinar, 'Confessions of a compliance team: the workarounds we don't talk about'. A panel of compliance leaders from Girlings Solicitors, Boodle Hatfield, Berwins and consultancy, All Things Risk, shared the workarounds they see most and how they deal with them.

Why the "why" matters more than the fix

When a workaround appears, it's easy to treat it as a behaviour problem and send a reminder email or book a refresher session. More often, though, it's a sign that the process isn't working for the people using it. Tackle only the behaviour and the same problem tends to pop up somewhere else.

A common example could be your firm-wide AML policy. If this runs to 50 pages or more, you tend to get people asking compliance repetitive questions instead of checking it; the instinct is to wonder why they won't read it. Often the answer is that the information is hard to find. It's buried in an old intranet page, written for a regulator rather than a fee earner and full of legislation quoted word for word. In that case, the workaround is perfectly rational, and the fix is a shorter, clearer policy that's easy to find.

It's one of the most recognisable workarounds there is. In a live poll during the webinar, over a third of attendees (33%) said colleagues asking compliance instead of reading the policies was the workaround they see most in their working week.

Workarounds poll

Is it an innocent shortcut or a chosen risk?

Not every workaround deserves the same response. Someone trying to get the job done who doesn't realise they've created a problem is very different from someone who knows the risk and does it anyway. The first calls for support and education. The second is a different conversation.

It also helps to accept that shortcuts are human nature, not a sign of bad intent. Even conscientious people bend a rule when it's harder to follow than the alternative, which is why so much of compliance is about understanding behaviour as well as setting rules.

"We're kind of working against nature, aren't we? Because shortcuts are what humans do. We are absolutely wired to take a shortcut."

Emma Barnard, Risk and Compliance Director at Boodle Hatfield

Five questions to ask when you find a workaround

Before deciding what to do, work through these five questions to separate the harmless from the risky.

  1. Who's doing it? One person, one team or the whole firm? A habit shared across a team usually points to a process or a manager, while one person going their own way is more often about knowledge or confidence.

  2. Why does it exist? Most workarounds fill a gap. The process might be slow or duplicated, the guidance hard to find or nobody has shown them the right way. Sometimes it's simply how things have always been done, and someone senior is fine with it.

  3. Do they know it's a risk? If they don't, it's a chance to explain and support. If they do, it needs a firmer approach, which we cover in a separate piece.

  4. What's the worst that could happen? A missed AML check or client funds at risk needs dealing with now. A minor inconvenience can wait, or be accepted with your reasoning recorded.

  5. What's the fix? Match it to the cause. That might mean changing the process, sharing the load across the team, making the guidance easier to find or taking it to the partners or the board.

Working through these before you act means your energy goes into fixing the cause rather than chasing the symptom.

Free template: we've turned these five questions into a one-page checklist you can fill in whenever a workaround comes to light, with a red, amber or green risk rating, a fix and an owner. Download the compliance workaround checklist

What about the workarounds you can't see?

The workarounds you know about are only part of the picture. For many compliance leaders, the bigger worry is the ones happening quietly in teams and offices they don't see day to day.

"The ones that I worry most about are the ones I don't know about. Someone's doing something somewhere to circumvent something. That's the stuff that keeps me up at night."

Nikki Coyne, Head of Risk and Compliance at Girlings Solicitors

You can't audit your way to every hidden workaround. The most reliable way to surface them is to make people feel safe enough to tell you, whether it's their own shortcut or something a colleague does. That trust is built in small moments, like compliance being first to ask the "silly" question in a meeting so others feel they can too.

It also depends on how you react when someone owns up. Stay calm and supportive in the moment and save any frustration for later, so they come back next time instead of keeping the next one to themselves.

Start with curiosity, not correction

A workaround is rarely just someone being difficult. More often it's a sign that a policy is too long, a system isn't doing its job or someone needs more support. Asking 'why' is what turns a frustrating discovery into something you can fix for good.

"Try and find out why first, even if your first reaction is to hit the roof."

Catherine Prosser-Carr, Associate Director of Risk and Compliance and MLRO at Berwins

Sound familiar?

If a few of these feel close to home, you're far from alone. Our two short films, 'The Onboarding' and 'Everything Comes To Me', take a lighter look at the workarounds compliance teams know all too well. Watch the No More Workarounds films.

Compliance Workarounds FAQs


A compliance workaround is any unofficial shortcut staff use to get around a process, policy or system. Examples include a spreadsheet nobody mentioned, a skipped onboarding step or ringing compliance instead of checking the AML policy.


Most workarounds fill a gap. The process might be slow or duplicated, the guidance hard to find or nobody has shown staff the right way. In our webinar poll, 33% of attendees said colleagues asking compliance instead of reading the policies was the workaround they see most.


Find out why it exists before you act. Then work through five questions: who's doing it, why does it exist, do they know it's a risk, what's the worst that could happen and what's the fix?


Ask whether the person knows they're creating a risk. Someone who doesn't realise needs support and education, while someone who understands the risk and does it anyway needs a firmer conversation.


Make people feel safe enough to tell you about them. Be the first to ask the "silly" question in meetings, stay calm when someone owns up and save any frustration for later, so they come back with the next one.


Match the fix to the cause behind it. Depending on the cause, that might mean changing the process, sharing the load across the team, making the guidance easier to find or taking workload and culture issues to the partners or the board.

Subscribe to our newsletter

Subscribe to our monthly newsletter for recaps and recordings of our webinars, invitations for upcoming events and curated industry news. We’ll also send our guide to Digital ID Verification as a welcome gift.

Our Privacy Policy sets out how the personal data collected from you will be processed by us.

Related articles