In December 2023, the consulting firm Gartner asked 1,012 employees at companies in the United States whether, in the previous twelve months, they had ever faced a situation where they didn't know how to comply with a rule at their own company. 87% said yes.

The same study went further and compared two possible responses to that problem. Strengthening organizational culture is one. Improving the quality of standards — the policy itself, the training, the communication, and the tools used day to day — is the other. According to Gartner, the second approach had twice the impact of the first in reducing the uncertainty that leads to noncompliance.

For whoever leads compliance, legal, HR, or finance at a company in Brazil or Latin America, the number matters for a direct reason: the problem is rarely the absence of a rule. The company has almost always already written the policy. What's missing is the path between the document approved two years ago and the concrete doubt someone has at 3pm on a Tuesday.

Where the rule gets stuck

The scene repeats in any mid-size or larger company. There's an expense policy, a purchasing manual, an information-security standard — usually thirty pages long, reviewed by legal, approved two years ago. Nobody denies the document exists. The problem is what happens the moment someone actually needs it: approving an expense outside the norm, deciding whether a contract can go to a new vendor, knowing whether a discount needs two signatures.

At that moment, almost nobody opens the thirty-page file. The person decides from memory, risks an "I think so," or asks a more senior colleague. If they're right, nobody notices. If they're wrong, the mistake only surfaces months later, in an audit or a complaint.

The 2023 Global Business Ethics Survey, from the Ethics & Compliance Initiative, measured that gap at scale: with more than 70,000 respondents across 42 countries, only 13% said they work in a culture considered strongly ethical — the other 87% described something weaker. In the same survey, 65% reported having witnessed some form of misconduct in the prior twelve months, and only 30% believe their own company takes adequate measures to reduce that risk.

The pattern in both studies is the same: the written rule isn't what guides the day-to-day decision. It's a document that exists in parallel to the operation, rarely consulted and remembered even less.

The informal shortcut and its price

The informal shortcut and its price

The most common reaction to this problem is to write more: a more detailed policy, an internal memo, a mandatory once-a-year training session. None of these measures work, because none of them change the distance between where the rule lives and where the decision happens.

LRN's 2025 Ethics & Compliance Program Effectiveness Report surveyed more than 1,500 compliance professionals and 1,500 employees worldwide — and found exactly that perception gap between the two groups. Whoever designs the program believes it works. Whoever lives the operation faces a different reality, because the rule reaches the right person on a cadence that isn't theirs: once a year, when the doubt shows up every Tuesday.

And the most common shortcut — asking a colleague — carries a cost that's rarely counted. The answer might be outdated, might come from someone who's also guessing, and leaves no record of what that decision was based on. When the same doubt reaches someone else, on the other side of the company, they start from zero — and might get a different answer to the same question.

Uncertainty, not bad intent, is the most common reason someone doesn't follow their own company's rule.

Gartner, survey of employees in the United States, 2024

What has to be in place

Closing that gap doesn't depend on rewriting the policy again. It depends on a set of mechanisms any governed work environment can have.

Sign-in uses the company's identity, not a separate account. The person logs in with the same corporate badge already used across other systems, and what they receive is filtered by who they actually are inside the organization — not by a login created on the side, easy to forget to revoke.

Access follows each person's role. Whoever works in finance sees what applies to finance. Whoever works in sales sees what applies to sales. Nobody gets a generic document that, by trying to serve everyone, ends up serving no one in particular.

The knowledge used in the answer has an owner and a current version. Every rule, table, or procedure has someone responsible for it, and the answer points to the exact passage of the version in force — not a forgotten copy from two years ago sitting in a shared folder.

Critical documents go through review before becoming the basis for an answer. Before a policy becomes an official source, whoever owns the document approves that content, with a separation between who writes and who approves — configurable, and reserved for the documents that genuinely warrant that care.

Every query is logged. Who asked what, when, and which passage of the rule backed the answer — a trail that serves both an audit and a review of the policy itself once it becomes outdated.

This is how Skyller was designed: identity coming from the company directory, knowledge approved by whoever owns the document, and an answer that points to the source used — not just a loose conclusion.

An answer that serves everyone

An answer that serves everyone

When a doubt is resolved once, in working language and with approval from whoever owns the document, the gain doesn't stay only with the person who asked. The same answer now holds for anyone with the same role, within the same permission scope — the newest person on the team gets the same guidance as the most experienced one, without depending on who happens to be nearby that day.

That also changes the work of whoever maintains the rule. A compliance or HR team that today answers the same question by email dozens of times a month starts approving the answer once — and reusing it every time the doubt repeats, freeing up time for what genuinely needs human attention. And the company doesn't have to build this foundation from scratch: Skyller, for instance, ships with more than 170 ready-made policy and process templates that serve as a starting point for the documents each company approves and maintains.

Questions to test your next policy

Before approving one more version of an internal rule, it's worth answering these questions with whoever leads compliance, legal, HR, and the operating areas:

  1. Can anyone point, right now, to the exact passage that answers the most common doubt in your area? If the answer depends on opening a thirty-page document or asking whoever's been at the company longest, the problem isn't a missing rule — it's distance.
  2. When the rule changes, who makes sure the old version stops circulating? An outdated copy sitting in an email is just as risky as no rule at all.
  3. Does the newest person on the team reach the same answer as the most experienced one? If the right answer depends on who happens to be nearby, the company is exposed to a variation nobody decided on.
  4. Who approved this document becoming the official basis for an answer? Without that step, any forgotten file can end up guiding a real decision.
  5. If an audit asked for the source of an answer given three months ago, would there be a record? Without one, a doubt that seemed resolved turns into a question with no proof.

Discover Skyller