In some was, in a complicated world, sometimes it’s good to get back to basics.
Somewhere along the way, a lot of us in compliance and risk started using the word “manager” for everything. We manage risk. We manage compliance. We manage the file, the audit, the relationship. And because the word gets used so often, it’s easy to let it bleed into how we think about the people on our team.
But here’s the distinction I keep coming back to, especially after 25-plus years in this work: you manage a process. You lead people.
Compliance is a process. It has steps, controls, documentation, deadlines, and reviews. It can — and should — be managed. Tightened. Measured. Improved.
Your compliance staff is not a process. They are not a checklist item. And when we start treating them like one — tracking their output the same way we track a control, correcting them the same way we’d patch a gap in a procedure — we lose the thing that actually makes a compliance function work: people who care enough to do it well when no one is watching.
I think this is where a lot of well-intentioned compliance leaders quietly go wrong. They are excellent at managing the process. Deadlines get hit. Reports get filed. Audits get passed. And they assume that because the process is running well, the leadership is happening too.
It isn’t the same thing.
A managed process produces compliance on paper. A led team produces a culture where people flag the thing before it becomes a problem, ask the hard question in the meeting, and stay motivated to do careful, unglamorous work because they believe it matters — not because a KPI told them to.
Your compliance staff doesn’t need someone to manage their output. They need someone who develops them, trusts them, has hard conversations with them when it counts, and shows them why this work matters beyond the audit trail. That’s leadership. And it’s a different skill set than process management, even though we often ask one person to do both — usually without ever separating the two in our own heads.
So here’s the question I’d ask any CCO, risk manager, or executive reading this: when you think about your team, are you managing them or leading them? And if you’re honest, would your team say the same thing?
Why Post
I post because these challenges deserve more conversation, not less. What you read here comes from my own experience, the experiences of others, and what I continue to learn through research and literature.
My goal is to help close the gap between corporate governance and risk/compliance management — work I’ve focused on for years and don’t believe happens in isolation. If this resonates, or doesn’t match your own experience, I’d like to hear about it. Leave a comment, or send me a direct message if you’re working through a governance or compliance challenge of your own.
