The Compliance Function Knows. It Just Can’t Say. The people inside organisations whose job is to see risk first are often structurally silenced from saying so clearly. That silence is rational, not negligent — and it is exactly why it is dangerous. Almost every serious regulatory or financial failure I have examined, after the fact, contains the same quiet detail: someone inside the organisation knew. Not vaguely, not in hindsight-flattering retrospect, but specifically, often in writing, often well before the failure became visible externally. The compliance or risk function had identified the issue, frequently in language precise enough to be unmistakable in a later investigation. And yet the warning did not change the outcome. Understanding why is, I think, one of the more important and least comfortable questions in organisational risk. The easy explanation — that the warning was ignored, or buried, through some act of leadership negligence or bad faith — is occasionally true, but it is the less common and, in a sense, the less dangerous version of the story. The more common version is structural: the warning was heard, was technically accurate, and was nonetheless rendered ineffective by the conditions under which it had to be delivered. The compliance function, in most organisations, occupies a genuinely difficult position. It is tasked with identifying risk clearly, but it operates inside a reporting structure, a career incentive system, and a set of relationships that make clear identification of serious risk an act with real personal cost to the person making it. The warning was heard, was technically accurate, and was nonetheless rendered ineffective by the conditions under which it had to be delivered. This produces a specific and recognisable linguistic pattern, one that becomes visible only in retrospect, once an investigation goes looking for it. The genuinely serious concern is rarely stated as a flat warning. It is hedged, qualified, framed as one of several considerations, embedded in a longer document where its significance can be read past rather than confronted directly. This is not because the person raising it failed to understand the severity of what they were seeing. It is because clear, unhedged language carries a cost — to relationships, to standing, to the perceived reasonableness of the person delivering it — that hedged language does not, and most people, reasonably, manage that cost by softening the delivery even when the substance is unambiguous. I have read enough of these documents, after the event, to recognise the texture of a warning that the writer believed was serious but did not feel safe stating as plainly as the underlying fact warranted. The phrase “this may warrant further consideration” sitting where the writer’s actual view was closer to “this is a serious problem.” The recommendation buried as the fourth point in a list rather than stated as the headline finding. The risk identified accurately but framed in a way that allows a reader who does not want to engage with it to read past it without quite registering what they have read. None of this is dishonesty. It is the natural adaptation of someone operating inside a structure that punishes clarity more reliably than it rewards it. The natural adaptation of someone operating inside a structure that punishes clarity more reliably than it rewards it. The deeper problem is that this adaptation is, in most organisations, invisible until it is tested. A compliance function that has learned to hedge its findings looks, on the surface, identical to one that genuinely has no serious findings to report — both produce calm, measured documentation, free of alarm. The difference only becomes apparent when someone goes back, after a failure, and reads the old documents with the benefit of knowing what eventually happened. What looked like routine monitoring, read in hindsight, reads as a warning that was simply never permitted to be stated at the volume the situation actually required. What this suggests, for anyone responsible for genuinely understanding the risk inside an organisation rather than simply receiving its formal reports, is that the documents themselves are an unreliable guide to severity, precisely because severity is what gets filtered out in the translation from what is known to what is safely sayable. The more useful exercise — and a genuinely uncomfortable one for most leadership teams to undertake honestly — is to ask the people closest to the risk a different kind of question: not “what have you found,” which invites the practiced, hedged answer, but “what would you say if there were no cost to saying it plainly.” The gap between those two answers, where it exists, is usually where the real exposure is concentrated. This is not a problem that better policy alone resolves, because the issue is rarely the absence of a reporting structure — most organisations of any size have an elaborate one. The issue is that the structure exists inside a set of human incentives that make honest severity expensive to convey, regardless of how clearly the policy states that it should be welcomed. Closing that gap requires something closer to a standing practice than a one-time fix: leadership that has demonstrated, repeatedly and specifically, that unhedged bad news is received without cost to the person delivering it — not as a stated value, but as a lived and observed pattern, tested under real conditions, often more than once, before the people closest to the risk will fully believe it applies to them. Until that trust exists, the compliance function will keep doing exactly what it has always done in organisations where it does not: knowing the truth, writing it down carefully, and hoping that someone reading closely enough will understand what was actually being said. Yanka Golemin provides private counsel to founders and principals navigating high-consequence decisions. Inquiries: counsel-inquiry@yankagolemin.com