Almost every conversation about compliance runs in one direction. The worry is always that controls are too weak, that a threshold is too high, an approval too easy, an access too broad. The instinct, when something goes wrong, is to tighten: add an approval, lower a limit, restrict a permission, require another signature. More control feels like more safety, and the tightening feels like diligence.
There is a failure mode this instinct never sees, and it is at least as dangerous as the weak control everyone worries about. A control can be set so tight that people stop following it, and a control people route around is not a strong control. It is a fiction that produces a false record while the real work moves into the shadows, where nobody is watching at all. The organization believes it has locked a door. What it has actually done is send everyone out the window, and lost sight of them entirely.
The paradox: tightening can reduce safety
This is not a plea for lax controls. It is a specific, well-documented mechanism, and the evidence for it is blunt.
The governing principle, as security researchers put it, is that a cumbersome control that is bypassed 30% of the time is worse than a slightly weaker control that is followed 100% of the time. The stronger-on-paper control delivers less actual protection, because protection is a function of adherence, not of stringency. A control nobody follows protects nothing, no matter how strict its design.
The most striking illustration comes from healthcare. In a study of hospital staff, 73.6% of medical personnel admitted to using a coworker's password to access electronic records, and the researchers concluded that the strict policies themselves, requiring a unique login for every action, ironically drove the password sharing and decreased data safety. The control was tightened in the name of security, and the result was less security, because the tightness made compliance impractical and people found the fastest way through. That is the paradox in one finding: the stricter control produced the weaker outcome.
Gartner's research on why people bypass controls reaches the same place from the other direction, finding that circumvention is driven not by recklessness but by friction, conflicting incentives (hit the target versus follow the rule), and controls misaligned with how the work actually happens. Roughly 60% of employees, in one body of research, report working around controls, and the root cause is consistently organizational friction rather than defiance. People are not breaking the rules to cause harm. They are getting their jobs done, and the control made the compliant path slower than the work allowed.
What over-control looks like in a property business
The mechanism is abstract until you see where it lands in a real operation, and in property it lands in predictable places.
-
Approval thresholds set so low that everything escalates: When the limit that requires senior sign-off is set below the level of routine activity, the senior approver is buried in trivial approvals, and one of two things happens. Either they rubber-stamp everything, because genuine review of that volume is impossible, so the control exists but does not function, or the team learns to split transactions below the threshold to avoid the bottleneck, which is a workaround that also defeats the control while corrupting the record. Either way, a threshold set too tight produces less real oversight than a higher one that people respect.
-
Access so restricted that people share credentials: When getting the access you need to do your job takes days of approvals, or the role you were given does not cover a routine task, people borrow a colleague's login. The moment that happens, attribution is gone, the audit trail is fiction, and you have created exactly the accountability black hole the access control was meant to prevent. The tight control did not protect the system. It destroyed the one thing that made activity traceable.
-
Processes so rigid that work moves into spreadsheets: When the system's approved process is too cumbersome for how the work actually flows, people do the real work in a spreadsheet and enter it into the system afterward as a formality. The compliant-looking record exists, but the actual decision happened somewhere the controls do not reach, which is how critical logic ends up living outside the system of record entirely. The control did not govern the work. It just added a step people satisfy after the fact.
In each case the pattern is identical: the control is technically in force, the records look compliant, and the real activity has quietly relocated to where nothing is watching. That is strictly worse than a looser control, because a looser control that people actually operate within at least produces an honest record of what happened.
Why the failure is invisible
Over-control is more dangerous than it looks precisely because it does not announce itself the way under-control does.
When a control is too weak, the failure is visible, something got through that should not have, and there is an incident to point at. When a control is too tight, everything looks fine. The approvals are all present. The access logs are populated. The process was followed, on paper. The organization sees a pristine compliance record and concludes its controls are working, while the actual activity has moved to the shadows and the pristine record is precisely the evidence of the problem, not its absence. A perfect compliance record in a high-friction environment is a warning sign, not a reassurance, because real work is never that tidy unless the tidiness is being manufactured after the fact.
This is why tightening in response to a problem can quietly make things worse. The incident prompts a new, stricter control, the stricter control increases friction, the friction increases workarounds, and the workarounds are less visible than the original risk. The organization has traded a known, visible risk for an unknown, invisible one, and called it remediation.
The honest part
This argument has an obvious failure mode of its own, and it has to be named, because taken carelessly it becomes an excuse for weak controls.
Some controls genuinely should be tight, friction and all, and the friction is the point. Controls guarding against catastrophic or irreversible harm, the movement of large sums, access to the most sensitive data, the actions that could sink the company, should be stringent even if that is inconvenient, because the cost of the harm dwarfs the cost of the friction. The argument here is emphatically not that all controls should be loosened until they are frictionless. That would be its own disaster.
The distinction is between friction that buys proportionate protection and friction that does not. A tight control on a genuinely high-consequence action is friction well spent. A tight control on routine, low-risk activity is friction that buys almost nothing and costs adherence, and it is the second kind that generates the workarounds. The skill is matching the stringency of the control to the actual consequence of the risk, rather than tightening everything reflexively because tightening feels responsible.
And there is a real cultural trap on the other side. An organization that tolerates workarounds because "the control was too annoying" can slide into tolerating them everywhere, including on the controls that matter. The answer to an over-tight control is not to wink at bypassing it. It is to fix the control so the compliant path is also the practical one, which is a different and more demanding response than either blind tightening or quiet tolerance.
Design for the path people will actually take
The practical shift is to stop asking only "is this control strong enough" and start also asking "will people actually follow it, and what will they do if they won't." A control's real strength is its stringency multiplied by its adherence, and a design that maximizes the first while destroying the second is weaker than it looks.
For any control that matters, three questions surface whether it is set in the danger zone:
- Is the friction proportionate to the risk?
Does the consequence this control guards against actually justify the burden it imposes? High-consequence, tight is right. Low-consequence, tight is friction that will be routed around. - Is the compliant path the practical path?
Can someone do their job while following this control, or does compliance make the work meaningfully slower or harder? If the honest answer is that following the rule fights the work, the rule will lose. - What is the workaround, and is it worse?
If people bypass this control, where does the activity go, and is that place less visible and less safe than what the control was protecting against? Often it is, which means the workaround is the real risk you have created.
The most useful signal a leader can watch for is the workaround itself. Every credential shared, every transaction split, every process quietly moved to a spreadsheet is not just a compliance lapse to be scolded, it is a diagnostic pointing at a control that is misaligned with the work. Treating those signals as information rather than misbehavior is how you find your over-tight controls before they produce the invisible failure. The single question that reframes the whole pillar: is our cleanest compliance record coming from a genuinely well-run process, or from a process so tightly controlled that everyone has quietly agreed to satisfy it on paper and do the real work somewhere else. If it is the second, the control was never protecting you. It was just teaching everyone to hide.
FAQs
Q1. Isn't stronger control always safer?
No, because protection depends on adherence, not stringency. A control that is too cumbersome gets bypassed, and a control that is bypassed protects nothing regardless of how strict its design. Security researchers put it directly: a control bypassed 30% of the time is worse than a slightly weaker one followed every time. The stronger-on-paper control can deliver less actual safety than a looser one people genuinely operate within.
Q2. How can tightening a control reduce safety?
By driving people to workarounds that are less safe than the risk the control addressed. In one hospital study, 73.6% of staff shared coworkers' passwords precisely because strict unique-login rules were too cumbersome, and researchers concluded the strict policy decreased data safety. The tightness made compliance impractical, so people found the fastest path through, and that path destroyed the accountability the control was meant to create.
Q3. What does over-control look like in a property company?
Approval thresholds set so low that everything escalates, producing either rubber-stamping or transaction-splitting. Access so restricted that people share logins, which erases attribution. And processes so rigid that the real work happens in spreadsheets and gets entered afterward as a formality. In each case the records look compliant while the actual activity has moved somewhere the controls do not reach.
Q4. Why is over-control more dangerous than under-control?
Because it is invisible. A weak control fails visibly, something gets through and there is an incident. An over-tight control leaves a pristine record while the real activity moves to the shadows, so the organization sees clean logs and concludes its controls work. A perfect compliance record in a high-friction environment is a warning sign that the tidiness is being manufactured, not evidence that everything is fine.
Q5. Doesn't this just excuse weak controls?
No, and that is the important caveat. Controls guarding catastrophic or irreversible harm, large sums, the most sensitive data, actions that could sink the company, should be tight even when inconvenient, because the friction buys proportionate protection. The argument is against tightening routine, low-risk controls reflexively, where the friction buys little and costs adherence. The skill is matching stringency to actual consequence, not loosening everything.
Q6. Why do employees bypass controls?
Research consistently finds the cause is friction, conflicting incentives, and misalignment with real workflows, not recklessness. Gartner's work and broader studies show people work around controls to get their jobs done when the compliant path is slower than the work allows. Around 60% of employees report working around controls, and the driver is organizational friction rather than defiance, which means the control, not the person, is usually the problem to fix.
Q7. What should we do when we find a workaround?
Treat it as a diagnostic, not just misconduct. A shared credential, a split transaction, or work quietly moved to a spreadsheet is a signal pointing at a control misaligned with how the work actually happens. The right response is neither to punish the workaround nor to tolerate it, but to fix the control so the compliant path is also the practical one, which removes the reason the workaround existed.
Q8. How do we tell if a control is set too tight?
Ask three things. Is the friction proportionate to the risk the control guards against? Can someone do their job while following it, or does compliance fight the work? And if people bypass it, is the place the activity goes less visible and less safe than the original risk? A control that imposes heavy friction for low-consequence risk, fights the natural workflow, and pushes activity somewhere darker is set in the danger zone.