Transcript
Welcome to Iconoclast Insights, where we don't just question conventional wisdom—we challenge it. I'm André Daus, and today we're confronting an uncomfortable truth: most organizational rules are destined to fail before they're even implemented. And the reason isn't rebellious employees or poor enforcement—it's fundamentally flawed rule-making.
Your carefully crafted policies are being systematically circumvented right now. Not occasionally. Not by a few bad actors. Systematically. By your best people. And they're right to do so.
The most disturbing part? You probably don't even know it's happening.
Let me tell you what's occurring in organizations across the world right now: Your most dedicated employees are living double lives. They're maintaining two parallel realities—one where they follow your impractical policies to the letter in all documentation, and another where they actually get the work done through unofficial channels and undocumented workarounds.
They're not being malicious. They're being pragmatic. And the fact that you don't know about it isn't a sign of their deviousness—it's evidence of how disconnected your leadership is from operational reality.
This isn't speculation—it's the inevitable result of how we create and implement rules. Today, I'm going to show you why your approach to governance is likely creating the very problems you're trying to solve, and why adding more rules is like trying to extinguish a fire with gasoline.
Let's be clear: this isn't about whether rules are necessary. They absolutely are. This is about the intellectual laziness with which most organizations approach rule-making—and the price they pay for it.
Consider these three examples that expose the fundamental dysfunction in how we govern:
In Cologne, Germany, authorities have essentially banned swimming in public waters except in a few designated spots. Why? Because a handful of intoxicated festival-goers drowned and some inexperienced swimmers challenged the Rhine's powerful current. Rather than targeting the specific risks—intoxication and inexperience—they implemented blanket prohibitions affecting everyone, including the vast majority of competent swimmers.
The result? Widespread non-compliance. The official response? Escalating fines and expanded prohibitions. This isn't governance—it's administrative theater that solves nothing while punishing the wrong people.
The EU's data privacy regulations present another case study in good intentions producing dysfunctional outcomes. A school I encountered requires students to complete both a paper form with signatures AND an identical online form for a simple two-week work placement. They call this "digital transformation"—a perfect example of how compliance mindsets create performative bureaucracy rather than actual protection.
The school collects excessive data while doubling administrative work—directly contradicting the regulation's data minimization principle. This isn't protecting privacy—it's fetishizing documentation at the expense of the regulation's actual purpose.
Our tax systems may be the most egregious example. We maintain the fiction of progressive taxation while engineering a system so complex that navigating it becomes a privilege of the resourced and connected. The complexity doesn't serve taxpayers—it serves tax professionals, software companies, and special interests who've carved out exceptions.
When someone finds a legal way to reduce their tax burden, we act shocked—as if the labyrinth of exemptions and credits was created by accident rather than design.
These aren't isolated failures. They reveal a profound truth that most organizations refuse to acknowledge: rules created without the direct involvement of those who must implement them are fundamentally compromised from inception.
Your organization likely suffers from this exact pathology. Your policies are probably written by people who will never have to execute them, approved by leaders who don't understand their operational implications, and enforced through metrics that measure compliance rather than effectiveness.
Here's what should terrify you: Your employees have likely created an elaborate façade of compliance while doing something entirely different behind the scenes.
Think about it. When was the last time you actually observed how your policies play out on the front lines? Not in a scheduled visit where everyone knows you're coming. Not through compliance reports that only show what people want you to see. But in the daily, unvarnished reality of getting work done?
Your best people aren't openly challenging your dysfunctional policies. That would be career suicide. Instead, they're doing something far more dangerous—they're creating shadow systems.
They're documenting processes exactly as your policies dictate while actually executing them differently. They're maintaining two sets of practices: the official version that satisfies auditors and the real version that actually accomplishes objectives. They're spending countless hours creating the appearance of compliance while simultaneously working around the very rules they're pretending to follow.
This isn't hypothetical. I've seen teams maintain elaborate documentation showing they follow every step of an impractical approval process, while in reality making decisions through informal channels and back-dating the required forms. I've witnessed departments create perfect audit trails for data handling procedures they don't actually use. I've observed employees spending more time documenting compliance than performing their core responsibilities.
And leadership remains oblivious because the system is designed to shield them from this reality.
Let me be provocative: the professional rule-makers in your organization—your legal department, compliance officers, and policy specialists—are often the least qualified people to design functional rules. Not because they lack expertise in their domains, but because their expertise is dangerously incomplete without the practical knowledge of those who must translate policy into action.
When you allow rule-making to become the exclusive domain of specialists, you're not being thorough—you're being intellectually negligent.
Every workaround in your organization isn't evidence of employee defiance—it's evidence of policy failure. It's your people desperately trying to achieve your organization's actual goals despite rules that actively impede them.
These workarounds aren't just inefficient—they're dangerous. They create shadow systems, undocumented processes, and hidden risks far more threatening than whatever your policies were trying to prevent.
The hard truth is this: in the contest between rigid rules and human ingenuity, human ingenuity wins every time. Your choice isn't whether people will work around bad rules—it's whether those workarounds will be visible, managed, and aligned with your organization's interests, or hidden, chaotic, and potentially catastrophic.
So what's the alternative? Not anarchy—but a fundamentally different approach to creating rules that work with human nature rather than against it.
First, recognize that policy-making is not a technical exercise—it's a design challenge. Your rules are products that people must use. If they're rejecting your product, that's a design failure, not a user failure.
Second, demolish the wall between rule-makers and rule-followers. If those who create policies never experience their consequences, you've designed a system that's immune to its own failures.
Third, measure what matters. If you're tracking policy compliance rather than policy outcomes, you're incentivizing performance rather than results.
Here's how to start: Identify one policy in your organization that generates consistent workarounds. If you don’t know how to find that out, try a tool called „The lies we tell ourselves“. But be warned this is not for the unprepared leaders.
After you found them, instead of asking "how do we stop the workarounds?“, ask "what is this policy failing to account for?"
Bring together the people who created the rule and those who circumvent it. Not for punishment—for redesign. Have them map the gap between the policy's intent and its effects. Then rebuild together.
Ask these questions without flinching from the answers:
What legitimate work does this rule make impossible? What would happen if this rule didn't exist at all? What's the minimum viable policy needed here? Who benefits from the complexity of this rule? Most importantly, create psychological safety for honesty. If your employees believe they'll be punished for admitting they've been working around policies, you'll never discover what's actually happening in your organization.
Let's reimagine our earlier examples through this lens:
For public swimming, authorities could implement targeted restrictions on intoxicated swimming and put fines on people for accessing dangerous waters—addressing specific risks when they need to get rescued without punishing everyone.
For data privacy, that school could design a single digital process that collects only essential information while still meeting documentation requirements—actually fulfilling the regulation's intent rather than just its letter.
For tax policy, we could acknowledge that simplification and transparency would reduce the advantage that complexity creates for those with specialized knowledge—if that's actually what we want.
I'm challenging you to confront an uncomfortable question: Are your rules designed to actually work, or merely to demonstrate that you've tried to address a problem?
Because there's a profound difference between governance and the appearance of governance. One solves problems; the other creates the illusion of control while generating new problems that often exceed the original concerns.
The organizations that thrive in the coming decade won't be those with the most comprehensive rulebooks—they'll be those that design governance systems that harness human ingenuity rather than futilely trying to constrain it.
This isn't about having fewer rules or more rules. It's about having rules that actually work because they're designed with a sophisticated understanding of human behavior rather than against it.
Your choice is stark: Continue creating policies that your best people will be forced to circumvent, or fundamentally rethink how you approach governance.
The most dangerous situation isn't when employees openly resist bad policies—it's when they create the perfect illusion of compliance while doing something entirely different. That's not just inefficient—it's a organizational timebomb.
The rule paradox can't be solved with more rules. It can only be solved by creating rules worth following.
This has been Iconoclast Insights. I'm your host, challenging you to stop managing compliance and start designing systems that work.