Issue 16: Compliance Theatre: When the Performance Matters More Than the Proof
David Ballew, Founder & CEO
When documentation becomes a performance, your audit trail is scenery, not evidence.
Originally published in The Compliance Edge at nimbleglobal.com, 8 July 2026 | This analysis is based on Nimble Global's proprietary research and 30+ years of practical experience across over 90 countries. | © 2019 - 2026 Nimble Global. All rights reserved.
There are certain observations that stay with you throughout your career. They don't arrive overnight and they rarely come from a single client or a single project. Instead, they quietly develop until, one day, you realise you've been seeing the same pattern all along.
For me, that pattern is something much broader and has nothing to do with one particular regulation, one country or one area of compliance.
I've spent enough time working with organisations and have seen both sides of the same conversation. I've listened to promises made to clients and prospective clients about governance, transparency and compliance. I've also spent many hours reviewing the operational evidence intended to support those same promises.
Sometimes they align remarkably well and often they do not. Increasingly, however, I find myself wondering whether the script and the operational reality are pulling even further apart. It isn't usually because anybody intended them to. More often, organisations evolve, jurisdictional laws change and compliance frameworks simply don't keep pace.
That thought has stayed with me for years because it seems to explain so many of the conversations I have with clients.
One of the most influential people I worked with in my career was Charlie, our Senior Vice President of Business Development. Charlie believed in what he called ‘hunting in packs’, bringing together the right people at the right time to give clients confidence that what we were proposing could actually be delivered. We worked particularly closely towards the end of the sales cycle when prospective clients wanted to move beyond the commercial discussion and understand how the proposed solution would actually work. Charlie's role was to win the business. Mine was to explain how we were actually going to deliver it.
Charlie often reminded me that there was always more happening behind the curtain than the client could see. At the time I understood exactly what he meant from a sales perspective. Looking back, I realise I took something quite different away from those conversations.
It gradually dawned on me that my own professional integrity, not just our organisation's, was on the line every time I sat across the table from a client. If I explained how a process worked, confirmed that a particular control existed or described how we managed compliance, I knew I would eventually be responsible for delivering exactly what I had just promised. Once the contract was signed, there was nowhere to hide. Operations now had to deliver what sales had sold.
That experience fundamentally changed the way I thought about compliance. Winning the business was only the beginning. The real measure of success was whether the operational reality consistently matched the promises we had made during the sales process. Looking back, I suspect that was where my fascination with compliance really began. Not with legislation or policies, but with the relationship between promises and delivery. Once I started seeing that relationship, I began noticing the same pattern everywhere I looked.
It also explains why I keep coming back to the same analogy, that compliance often feels like theatre. Perhaps I should explain what I mean.
Every organisation performs. Every sales presentation is, in many respects, a performance. We put our best people on stage, present our best thinking, demonstrate our strongest capabilities and explain the value we believe we can deliver. There is nothing wrong with that. Building confidence and winning business has always been part of every successful organisation.
The performance doesn't end when the contract is signed. It changes.
The focus shifts from persuading a client to trust you, to demonstrating that everything promised during the sales process can actually be delivered. That is where operations, governance and compliance become every bit as important as business development, because they are ultimately responsible for turning promises into reality.
Throughout my career I've seen organisations win business with the very best of intentions, only to discover later that operational reality struggles to keep pace with the promises that were made. Rarely is that because anybody intended to mislead a client. More often, commercial ambition simply moved faster than operational reality.
That, for me, is where the comparison with theatre really begins. Every theatre production begins with a script. Before the curtain rises, everyone knows the story they are trying to tell. The audience sees the finished performance and quite rightly assumes that everything behind the scenes is working exactly as intended. Why would anyone think otherwise?
Organisations are not very different.
Policies are written, procedures are documented, governance meetings take place and compliance reports are produced. Individually, each of those activities has value. Collectively, they create confidence that the organisation is operating as intended. Sometimes that confidence is entirely justified. Sometimes it creates a false sense of security because the existence of a process has quietly become more important than understanding whether the process is still working.
The questions that have interested me most are rarely complicated. They usually begin by asking how a decision was reached, when it was last reviewed and whether the documented process still reflects the reality of how the business operates today. Those conversations are not about questioning the integrity of an organisation or its people. They are about understanding whether what is happening behind the curtain still reflects the story being presented on the stage. More importantly, does that story still match the one being told to customers?
That distinction has become increasingly important to me because documentation and evidence are not the same thing. Documentation tells us what an organisation intended to do. Evidence helps us understand what actually happened. The two often align, but they should never simply be assumed to.
Worker classification is probably the obvious place to begin, not because I believe it is the most important compliance issue facing organisations today, but because it has become the issue that attracts the greatest attention. Entire businesses have been built around worker classification, technology platforms have been developed to automate assessments and countless articles have been written about employment status, independent contractors and legislation such as IR35 in the United Kingdom.
All of that is valuable.
What concerns me is that worker classification has gradually become the public face of workforce compliance, creating the impression that if organisations solve classification, they have somehow solved compliance itself. They haven't.
Worker classification is one important control within a much broader governance and compliance framework. Alongside it sit insurance, privacy, right to work, payroll governance, tax, contractual obligations, licensing, background screening, information security and dozens of other operational controls, each carrying its own level of risk and, increasingly, being reduced to a system check box. Some are administrative, others are legal or regulatory, but all require the same discipline. They require organisations to move beyond documentation and demonstrate that the underlying control is actually working.
Every additional layer of technology, outsourcing and automation creates another opportunity to assume that somebody else has already verified the control.
Perhaps the greatest risk isn't that organisations ignore worker classification. It is that they become so focused on one highly visible compliance issue that they overlook the many others operating quietly in the background.
Insurance has prompted many of the same reflections. Receiving a certificate of insurance often creates a reassuring sense that another compliance requirement has been completed. Only when somebody who understands insurance compares the certificate against the contractual obligations does the real review begin. Does the policy actually satisfy the requirement? Are the endorsements present? Are the limits correct? Has anyone compared one document with the other, or has everyone assumed somebody else already has? Over the years I've realised that collecting documentation and evaluating documentation are two entirely different disciplines, and confusing one with the other is surprisingly easy.
That observation has become even more relevant as the workforce ecosystem has evolved. Today's workforce programmes rarely rely on a single technology platform or service provider. Instead, they operate across a network of integrated technologies, outsourced services and operational workflows, all exchanging information with one another, often across organisational boundaries and international borders. The efficiencies are undeniable, but every new integration, every additional platform and every outsourced process also introduces another layer of governance that must be understood, managed and, ultimately, verified.
What is moving through those ecosystems is not simply information. It is often personal information, employment information and commercially sensitive data crossing organisational boundaries and, increasingly, international borders. Every transfer creates another governance obligation. Every integration creates another point where somebody must understand not only how the technology works, but also the legal and regulatory responsibilities that travel with the data.
There is no question that these advances have improved efficiency. Information moves more quickly, workflows are more streamlined and organisations have access to far more data than ever before. Technology makes all of this appear effortless. Governance, however, is rarely that simple.
Technology has become exceptionally good at moving information from one platform to another. It has not become equally good at determining whether that information is accurate, complete or sufficient to demonstrate compliance with the underlying obligation. Information moving successfully through a workflow is not the same as demonstrating that the compliance control behind it is operating effectively.
A platform can confirm that a document has been uploaded. It can record who uploaded it, when it was uploaded and where it now sits within the workflow. It can move that information seamlessly between service providers, clients and technology partners. What it cannot always determine is whether the document satisfies the contractual obligation it was intended to support. That still depends upon somebody understanding what they are looking at.
As if that wasn't complicated enough, the next stage of this evolution is already underway. Artificial intelligence is beginning to review documents, identify missing information, compare contractual requirements and even recommend compliance decisions. There is enormous potential in these developments, and I have little doubt they will continue transforming the industry. They will also introduce a new governance challenge. Organisations will need to understand not only whether the underlying document demonstrates compliance, but also whether the AI reaching that conclusion has itself been appropriately governed, tested and validated. Technology continues to evolve. Professional judgement does not become less important. It simply moves to a different level.
A certificate of insurance illustrates the point perfectly. Uploading the document into a platform is an administrative task. Determining whether that certificate actually complies with the contractual requirements is a compliance task. Those are two very different disciplines.
As the workforce ecosystem becomes increasingly sophisticated, it also becomes easier to assume that somebody else has already asked the difficult questions. The supplier assumes the service provider will review the document. The service provider assumes the contractual requirements have been correctly defined. The client assumes the process has been completed. The technology faithfully records each step along the way, yet none of those assumptions necessarily confirms that anybody has actually determined whether the document demonstrates compliance.
Perhaps that is one of the greatest challenges facing our industry. Technology has dramatically improved our ability to collect, move and store information. It has not removed the need for knowledge, experience and professional judgement. If anything, it has made those qualities even more valuable because the volume of information continues to increase while the time available to review it continues to decrease.
Privacy has taken me down a different path again, and in some ways a more uncomfortable one.
With worker classification, the risk is that organisations focus on the wrong thing. With insurance, the risk is that nobody ever properly checked. Privacy reveals a third possibility, and I suspect it is the most common of all. The control was checked. It was checked thoroughly, by capable people, and it was right. It simply stopped being right, and nobody was watching when it happened.
Organisations quite rightly describe themselves as global because their clients, workers and operations span multiple jurisdictions. Yet every so often I read a privacy notice that tells a rather different story. The document was clearly written with care. Somebody invested time, took proper advice and got it right for the business as it existed at the time. The difficulty is that the business no longer exists in that form. It has entered new markets, adopted new platforms and begun transferring candidate data to processors in jurisdictions the original drafters never contemplated. The notice, meanwhile, still reflects the assumptions of the country where it was first written.
This is drift, and drift is harder to detect than absence. A missing control announces itself eventually. A decayed control does the opposite. It sits in the compliance framework looking exactly like a functioning control, generating exactly the same confidence and passing exactly the same document requests. Everything about it says ‘verified’, because once upon a time it genuinely was.
Privacy is where drift does the most damage, for a simple reason. Data protection obligations attach to what the organisation actually does with personal information today, not to what it did when the notice was written. Every new market, every new integration and every new category of data quietly rewrites those obligations, whether or not anyone rewrites the supporting documentation. The gap opens silently, one acquisition, one platform migration and one new country at a time.
None of this necessarily means the organisation has failed in its legal obligations. It does, however, suggest that the question organisations most need to ask about privacy is different from the one they usually ask. Rather than asking, ‘Do we have a compliant privacy framework?’, perhaps the better question is, ‘When did we last confirm that our framework accurately describes the business we are running today, rather than the business we were running when it was first written?’ In my experience, the honest answer to that second question is often measured in years.
The longer I work in this industry, the less interested I become in what organisations tell me they do. I'm far more interested in how they prove it.
Perhaps that is what I mean by Compliance Theatre.
It is not a criticism of organisations and it is certainly not an accusation that people are pretending to be compliant. It is simply an observation that, over time, every organisation risks confusing the existence of controls with the effectiveness of those controls. The script remains reassuring, the performance continues and the audience leaves believing everything happened exactly as planned.
The goal should never be to win an Academy Award® for the most convincing compliance performance. It should always be to build a compliance programme that doesn't need an audience in the first place. Eventually every performance ends. The evidence remains.
Stay Nimble. Stay Compliant.
About the Author: With extensive experience in workforce compliance and global workforce solutions, David Ballew has consistently driven innovation and operational excellence. As the Founder and CEO of Nimble Global, David combines deep industry expertise with a unique perspective shaped by his neurodiverse AuDHD profile, enabling creative problem-solving and multidimensional insight. A pioneer in MSP models and workforce technologies, he is dedicated to bridging global compliance gaps and helping organisations build resilient, future-ready workforces.
Real People. Real Action. Real Innovation.
Disclaimer: This content is intended for informational purposes only and does not constitute legal, tax, or employment advice. Readers should consult qualified professionals in relevant jurisdictions before acting on the guidance provided. Nimble Global disclaims any liability for actions taken based on this publication.
%20(1).png)