
We have all seen this happen; something goes wrong so the organization adds a control. The next problem happens so they add another. The reasoning is usually sound and every addition makes sense at the time. There was some type of failure; add a control. A risk is uncovered; require an approval.
As the controls accumulate the process that once took a few minutes now takes days. More people are involved. More evidence is required. More meetings are on the calendar. I have seen more time and effort spent navigating a process than doing the work the process was created to support.
Of course, this doesn’t mean that the controls are wrong. It may mean that we have stopped looking at the process as a whole. This can be hard to recognize because the original intent can remain perfectly clear. We all understand why the process exists. However, as the mechanism grows the process can become something people optimize around rather than work through.
I saw this with a process for introducing new technologies. The original intent was straightforward: control costs and prevent duplication. The earliest version of the process was almost as simple as adding it to the list.
Then as we started to control technology sprawl a mandatory architecture review was added. To control duplication an evaluation matrix got added to compare against existing tools. A review meeting was added to allow subject matter experts to weigh in. Every addition addressed a legitimate concern, but they also added time and friction.
Eventually teams started finding shortcuts and workarounds. One such workaround was to ‘discover’ a technology after it was already in use. That path was much easier. We started seeing more “discoveries”.
And despite all the governance and controls intended to prevent duplication, we still had seventeen reporting tools.
What I noticed here was not that people were unwilling to follow the process. They were responding to the incentives the process created. And when following the process threatens the project timeline, finding a way around it becomes the mitigation.
Resistance to a process is not automatically evidence that the process and controls are wrong. Sometimes the risk justifies the friction. Removing every control that frustrates people would be just as careless as adding controls without considering their cumulative effect. However, a growing pattern of resistance and workarounds is different from an isolated complaint. When workarounds become common, or when behavior starts changing to avoid the process, I think that is a signal worth examining. Is the control still justified by the risk? If so, is the friction it has accumulated necessary? If both are yes, then we probably need to communicate the rationale more clearly.
Organizations are good at adding controls because they provide a visible response to problems. We are less consistent about noticing when they start changing how people work. By then, the process may be working as designed while producing behavior that was never intended.
When people keep finding ways around a process, are they avoiding a necessary control or are they telling us something about the process itself?