In the world of risk management and compliance, decision-making errors can carry significant consequences, doing versus not doing. To get fancy, the two concepts often discussed in this context are errors of commission and errors of omission. While they may sound like technical nuances, understanding the difference between the two—and how they manifest in everyday practice—can be a powerful tool for preventing critical risks.
Defining Errors of Commission and Omission
An error of commission occurs when a person does something incorrectly. This could mean taking an action they shouldn’t have taken, misapplying a rule, or actively introducing mistakes into a process. The hallmark of commission errors is the presence of wrongful action.
An error of omission, by contrast, happens when a person fails to act when they should. This typically involves overlooking steps, neglecting responsibilities, or failing to follow through. Omission errors are marked by inaction—or insufficient action—when an action was necessary.
Both carry implications, but the nature of their risks differs.
What do I mean:
- Commission Error Example:
A compliance officer mistakenly approves a client relationship that violates Know Your Customer (KYC) standards because they misinterpret due diligence documents. This incorrect action creates direct exposure to regulatory penalties. Most likely because the advisor may put pressure on the compliance officer because of the dollar value in commissions the client can bring to the firm. - Omission Error Example:
A compliance team fails to update policies and procedures in a timely manner of a new regulatory requirement. No direct misstep occurs in the moment, but the absence of proactive action leaves the firm non-compliant when an audit comes. In my mind, they know there is an update required but defer for what ever reason.
From these two examples, it’s clear that commission creates visible, active mistakes, while omission often lurks quietly in the background until uncovered.
The Risk Management Angle
Risk management requires organizations not only to avoid the wrong moves (commission) but also to recognize when they have not acted where necessary (omission). The dangers differ:
- Commission Risks often manifest in the short term. Mistakes, unauthorized approvals, or incorrect trades quickly come to light. They are traceable to an identifiable action and can usually be corrected once discovered.
- Omission Risks tend to build silently. Missing a step in monitoring, failing to document, or not reassessing controls accumulates invisible exposure, which may only show up during crises, investigations, or regulatory reviews.
This distinction matters because companies often design control frameworks to catch commission errors, such as implementing approvals, reconciliations, and review layers. Omission errors, however, are systematically harder to spot, as they rely on recognizing what is missing, not just what is done incorrectly.
What Risk Managers and Compliance Officers Should Watch For
As gatekeepers of risk and regulatory alignment, compliance professionals must be vigilant about both error types. Key considerations include:
- For errors of commission:
- Build training programs that emphasize proper interpretation of laws and policies,
- Develop systems of “second eyes” checks for critical actions (e.g., client onboarding, transaction approvals),
- Leverage automation to reduce manual inputs that often lead to accidental errors,
- Bright lights usually shine on non-compliant actions.
- For errors of omission:
- Map out all recurring compliance obligations and deadlines to prevent missed reporting or filings.
- Establish proactive monitoring processes to identify gaps before regulators do.
- Use regular gap analyses or mock audits to intentionally search for what isn’t being done.
The subtlety here is that omission errors often stem from assumptions: “If no issues have come up, everything must be fine.” Challenging this assumption is critical.
A Balanced Approach
Risk management maturity depends on acknowledging both risks of taking the wrong action and failing to act at all. Organizations with robust compliance cultures encourage employees not only to avoid missteps but also to ask: What have we overlooked? What silence in our system might be misleading us?
For compliance officers, risk managers, and business leaders alike, the challenge is to foster a mindset that catches both the visible and invisible forms of error. As you reflect on your organization, ask yourself:
- Have we built controls that detect both commissions and omissions?
- Do our monitoring practices reveal blind spots, not just obvious mistakes?
- Are we encouraging teams to question areas of silence as vigorously as we scrutinize questionable activity?
The next compliance challenge your organization faces may not come from what someone did wrong, but from what no one remembered to do at all. Building vigilance around both error types is not just a best practice—it is essential risk management
The idea behind postings on this platform is to hopefully provide ideas, concepts or thoughts that highlight the challenges facing risk and compliance managers in the corporate governance structure. These postings are based on my personal experience, the experiences of others, and developing my understanding of the many leadership challenges, through publications and literature.
It’s my desire to help close the perceived negative gaps between corporate governance and risk/compliance management. There are ways and means to enhance the relationship, which I’ve focused on for several years. Direct message me for additional information on how to create a collaborative governance environment.




