Regulation and Compliance

An Unhealthy Culture Can Undermine the Best Compliance Program

Companies can end up in scandal when they reward the wrong behavior. In this excerpt from the book Paper to Practice, Eugene Soltes argues that preventing misconduct requires leaders to understand the psychology behind people’s decisions.

Book cover on purple background. The book cover is red and is titled “Paper to Practice” by Eugene Soltes, featuring a crumpled white paper ball and the subtitle “Why Compliance Programs Fail and How to Build Programs That Work.”

This is an excerpt from the book Paper to Practice: Why Compliance Programs Fail and How to Build Programs That Work by Eugene Soltes. John Wiley & Sons, Inc., August 2026.

The difference between a company achieving its business goals and becoming tomorrow’s headlines typically doesn’t come down to policies and controls. Companies that end up in scandal often have well-written policies and reasonably designed controls.

What drives an organization toward integrity or malfeasance is how those policies and the surrounding culture are enacted in the thousands of decisions employees make every day. Companies can pour billions into technical systems, compliance software, and detailed controls, yet their fate ultimately rests on human choices. This is why effective compliance and integrity program design is, at its core, a psychological exercise.

Companies can pour billions into technical systems, compliance software, and detailed controls, yet their fate ultimately rests on human choices.

To genuinely mitigate legal and reputational damage, we need to start with what actually fosters misconduct—the psychological, behavioral, and organizational forces that can drive behavior. These forces include the pressure to hit quarterly targets, the rationalization that “everyone else is doing it,” and the gradual normalization of bent rules.

It’s absolutely true that there are some components of compliance that are purely technical in nature. Banks need effective anti-money-laundering controls to flag suspicious transactions, manufacturers must implement product quality specifications that meet regulatory standards, and technology companies need systems that enforce sanctions restrictions.

Implementing these controls requires competent execution and investment in technology, appropriate vendor selection, and thoughtful system design. Yet spectacular failures rarely result from software glitches or technical malfunctions alone. Wells Fargo didn’t create millions of unauthorized accounts because of a database error, and Volkswagen didn’t install software to cheat emissions tests due to a technical coding mistake. These failures occurred because of decisions made by people whose motivations undermined the company’s integrity.

The fundamental challenge is that people are not switches you can simply flip to “compliant” mode. You can mandate a policy, require attestations, and even secure written commitments. However, when those same individuals face the pressure of a quarterly sales target or see an opportunity to circumvent a policy undetected, they may do the opposite of what they intended when they signed a policy acknowledgment only a few weeks earlier.

Unfortunately, we’re also not always able to recognize when we’re about to err, either. Unlike in a training exercise or the comfort of a classroom, no one flags the consequential decision from the hundreds of others made within a day. We make decisions quickly, without much time for reflection, and within teams that tend to think alike. All of these factors make our actual decisions in the workplace and boardroom different from the virtuous choices we express and expect.

For my first book, Why They Do It: Inside the Mind of the White-Collar Criminal, I spent nearly seven years interviewing former executives who ultimately made choices that led to criminal consequences. Often it was clear that if these executives had possessed the capacity to pause, to bounce their decision-making by a dispassionate outsider and encounter what I call “uncomfortable dissonance,” they would have avoided making their worst decisions.

Steven Garfinkel, a CFO later convicted of fraudulent accounting, told me, “What we all think is, when the big moral challenge comes, I will rise to the occasion. [But] there’s not actually that many of us that will actually rise to the occasion. I didn’t realize I would be a felon.”

We’re rarely able to see how much our intended behavior and our actual behavior diverge. We see this frequently in survey results at Integrity Lab. When we ask employees whether they would report misconduct if they observed it, over 90% of respondents consistently say they would. However, when we slightly reframe the question to ask whether they did report a violation they observed in the past six months, the share who reported it typically falls below 50%. This simple example shows a dramatic difference of 40 percentage points between actual and intended behavior. I don’t see this as hypocrisy—it’s simply that our intended and actual behavior routinely diverges in the context of integrity, yet many compliance programs are designed as if this gap doesn’t exist.

To compound matters, many actions that trigger considerable regulatory and public scrutiny today do not reflect hardwired moral imperatives but instead arise from social constructs that have evolved over time.

Consider insider trading. In the early 20th century, one of the benefits of joining a corporate board was the opportunity to trade on inside information that one learned. This practice was not illicit and instead an openly acknowledged perk. Consider what one director told the New York Times: “If we were all Christian gentlemen with a very fine sense of honor, I suppose no Director would buy or sell stocks in his own company on information which comes to him as a Director. As a practical matter, nearly all directors do. If I see that earnings are improving, I feel that I have a right to buy or to sell if they are failing.” Railroad magnates and industrial barons routinely profited from advance knowledge of mergers, bankruptcies, and major contracts.

It wasn’t until the mid-1960s that the United States began enforcing a prohibition against insider trading, and many other countries didn’t follow suit for decades. Singapore didn’t prohibit it until 1973, Japan until 1988, and Germany until 1994.

The story of bribery follows a similar arc. Until the Foreign Corrupt Practices Act of 1977, American companies could—and did—bribe foreign officials. Even after the US prohibition, bribery payments remained tax-deductible across much of Europe until 1999. Today, many companies speak of anti-corruption as if it’s a universal value, but for most of commercial history, it was how business was done.

Now, with evolving enforcement priorities in the United States and discussions about FCPA shifts that could create enforcement exceptions for payments that advance American strategic interests, we may be witnessing a reversal that transforms what was prohibited conduct into a more ambiguous competitive tool.

Even today, what constitutes malfeasance varies dramatically across jurisdictions. Sanctions against operating in Russia and Iran can lead to significant penalties for American companies and employees. Yet when I speak to executives at companies in the Middle East and Asia, many view these same restrictions as arbitrary Western impositions, and they have expanded into markets their American competitors must avoid. The same transaction that can land an American executive in prison might earn an executive operating in another country a promotion.

In fact, several countries, including the EU’s Blocking Regulation, prohibit European companies from complying with certain US extraterritorial sanctions, including those against Iran and Cuba. Multinational European companies with business in the United States that historically did work in sanctioned jurisdictions face a Catch-22 decision of whether to violate American or European law.

Culture will dominate any compliance program built around processes, no matter how extensive or rigorous those processes are.

This is why treating compliance as simply a set of processes ignores the complexity of the environment in which businesses operate and the drivers of human behavior. Culture isn’t what’s written in the employee handbook or in a CEO’s company-wide email—it’s the thousands of micro-decisions about what gets rewarded, what gets punished, and what gets ignored. It’s reinforced through the actions and words of leaders and managers and both the explicit and implicit systems and incentives that shape daily behavior.

When a salesperson watches a colleague circumvent a process to hit their target and get promoted while the employee who followed the rules and missed their number gets coached out, or when they see competitors who violate rules celebrated as innovators, that’s where the culture of compliance is formed. Culture will dominate any compliance program built around processes, no matter how extensive or rigorous those processes are.

Therein lies the challenge of achieving effective compliance within large, decentralized organizations. Because compliance has increasingly become a process-driven exercise, it’s been progressively marginalized. Compliance gets buried within legal or audit departments, funded at only the most essential level, and staffed by people who may have significant talent, but lack the authority to challenge business decisions that undermine integrity.

At the same time, many of the most crucial questions that drive integrity demand the attention and effort of a company’s most senior leadership, including its board of directors and C-suite executives. Only these leaders can answer key questions like these: What risks are we truly willing to accept? How do we balance competitive pressure against regulatory requirements? What message does our compensation structure send about our priorities? When compliance violations occur, do we treat them as seriously as missing financial targets?

I don’t take a naive view of integrity, where every decision is black and white. Having spent years advising companies and their most senior leadership, I understand that there are many genuinely difficult decisions where legal requirements conflict with business necessities, where different jurisdictions demand approaches that are not compatible with one another, and where competitive dynamics mean taking aggressive positions that regulators may later challenge. Depending on an organization’s goals, risk appetite and tolerance, and values, companies can reasonably reach different conclusions about what are appropriate decisions.

But that’s precisely why compliance can’t be relegated to a back-office function. While compliance obviously does have components of form-filing and policy-updating, the big questions that matter are ones demanding leadership attention. They’re strategic decisions about the kind of organization you want to be, the risks you’re willing to accept, and the culture you’re creating.

Excerpted with permission from the publisher, Wiley, from Paper to Practice: Why Compliance Programs Fail and How to Build Programs That Work by Eugene Soltes. Copyright © 2026 by John Wiley & Sons, Inc. All rights reserved. This book is available wherever books and eBooks are sold.

Have feedback for us?

Latest from HBS faculty experts

Expertly curated insights, precisely tailored to address the challenges you are tackling today.

Strategy and Innovation

Social Responsibility

Data and Technology