Explore the difference between surface, deep and adaptive compliance, and learn how to design systems that manage real workplace risk.

.jpg)
If your organisation is technically compliant but still seeing risk, incidents, or confusion in the field, you are not alone. In this post, you will learn why compliance on paper is not the same as risk being managed in practice, how to recognise surface, deep, and adaptive compliance, and what you can do to build a system that actually helps people do the work safely.
Why Compliance on Paper Is Not Enough
Compliance is essential. No one was arguing otherwise in the session. The real issue is the assumption many organisations make: if the forms are complete, the training is done, and the audit is green, then the work must be safe.
That assumption can be dangerously misleading. Kym Bancroft and Dr. Tristan Casey made a strong case for separating the mechanism of compliance from the outcome it is supposed to achieve.
A written procedure, checklist, permit, or risk assessment is only useful if it actually changes what happens in the work. Otherwise, you may have the appearance of control without the reality of control. That matters more than ever because regulators are no longer just asking whether you have a policy. They want evidence that the policy works in practice.
With penalties for reckless conduct now exceeding $17 million for a body corporate under harmonised WHS laws, the stakes are not just administrative, they are financial and legal too.
The deeper point is this: compliance is not binary. It is not simply compliant or non-compliant. There are levels to it, and those levels determine whether your system is genuinely reducing risk or just producing paperwork.
The Three Types of Compliance You Need to Understand
One of the most useful ideas from the session was the distinction between surface compliance, deep compliance, and adaptive compliance. If you only think in terms of yes/no compliance, you miss the real story.
Surface Compliance:
The Tick-and-Flick Trap - Surface compliance is when people follow the rule in form, but not in substance. The checklist gets completed, the box gets ticked, but the intended safety outcome is weak or absent. This shows up in a few familiar ways:
Surface compliance is not always malicious. In some low-risk, routine situations, it may be “good enough.” But in higher-risk work, it creates serious problems:
Kym’s example of the written risk assessment process in a utilities setting made this painfully clear. Workers were completing the task late, pre-filling it in the depot, or even asking family members to fill it out. On paper, the system looked fine. In reality, it was becoming safety clutter.
Deep Compliance:
When the Tool Matches the Purpose - Deep compliance is what most organisations actually want. It happens when people understand the purpose of the tool, think carefully about how to use it, and apply it in a way that changes the work for the better. This has three features:
Deep compliance improves both assurance and information. Leaders can trust the data more because the activity is more likely to reflect what is really happening. Workers are more engaged because the process helps them do the job, rather than slowing them down for no reason.
This is where many organisations get stuck. They implement the rule, but they never answer the “why” in a way frontline teams can actually use. If people do not understand the value, they will treat the process as administrative burden, not risk management.
Adaptive Compliance:
Flexibility Without Losing Control - Adaptive compliance is the most nuanced idea in the whole conversation. It means adjusting the method when conditions change, while still protecting the intended outcome. That may sound risky at first, but it is often exactly what safe work requires.
Work is dynamic. Plans change. Conditions change. People change. Sometimes the original procedure no longer fits the reality in front of you. In those moments, rigid compliance can actually make the situation worse. Adaptive compliance is about balancing control and flexibility:
Tristan used Jens Rasmussen’s thinking to explain that safe systems should not just constrain people. They should also expand the space in which people can work safely, make boundaries visible, and help people recover safely when something goes wrong.
That means adaptation is not a sign of failure. In the right context, it is a sign of competence. A good example from the session came from a nuclear organisation in the UK. The existing procedure did not adequately support a risky fuel rod lift, so the team used the procedure as a starting point, then worked with inspectors and regulators to design a compliant way to do the task safely. That is adaptive compliance in action. It is not about ignoring rules. It is about finding a better way to achieve the rule’s purpose when the original method no longer fits.
How to Design Compliance That Actually Works
So what do you do with all this? The answer is not to throw out procedures, forms, or documentation. The answer is to design them so they support real risk management instead of substituting for it.
1. Start With the Outcome, Not the Form. The first question should never be “What form do we need?” It should be “What risk are we trying to manage?” Kym’s case study is a good example. The original process had turned into a written exercise that workers no longer believed helped them think about the job. The organisation had accidentally confused the documentation with the obligation. Once they went back to the real intent, pausing to think through the task, the hazards, the controls, and the differences on site, they were able to redesign the process around that outcome.
That shift matters because it forces you to ask:
If the answer is no, the process may need redesign, not more enforcement.
2. Make It Easier to Deeply Comply. People are more likely to do the right thing when the process is usable, relevant, and timed properly. In the utilities case, the team replaced the long written risk assessment with a shorter, conversational tool called “The CHAT”. It kept the non-negotiables, but reduced clutter and added flexibility depending on the complexity of the task. That is the real lesson: deep compliance is designed, not demanded. If you want deeper compliance, reduce friction:
This is also where training matters. If you only teach people to memorise steps, they will struggle when conditions change. If you teach them to think through scenarios, they are more likely to make good decisions in the moment.
3. Build Safe Flexibility Into the System. Adaptive compliance does not happen by accident. It needs structure. Tristan shared several practical ways organisations can support it:
The aim is not to make everything flexible. The aim is to make the right parts flexible so people can stay safe without breaking the system. That is particularly important if you work in high-risk or fast-changing environments where the job you planned is not always the job you get.
What Leaders Should Measure Instead of Just Counting Forms
One of the strongest points in the Q&A was about measurement. Organisations love volume because it is easy to count. Pre-starts completed. Checklists filed. Inspections done. But volume alone tells you very little. A better approach is to pair quantity with quality. For example, instead of only asking how many take-fives were done, ask:
If leaders think quality is too subjective, Kym suggested a practical answer: run a micro-experiment. Test whether the quality measure changes anything in the operation. That gives you something more concrete than opinion alone. The broader lesson is that good compliance systems should not just produce outputs. They should produce evidence of thought. That is the difference between a checklist culture and a learning culture.
Frequently Asked Questions
What is surface compliance?
Surface compliance is when people complete the requirement but do not meaningfully engage with its purpose. It often looks good on paper but has little effect on actual risk control.
What is deep compliance?
Deep compliance is when people understand the purpose of the tool or rule, use it thoughtfully, and apply it in a way that improves safety and operational outcomes.
What is adaptive compliance?
Adaptive compliance is the ability to change the method while still achieving the intended compliant outcome when conditions, risks, or demands change.
Should organisations get rid of written risk assessments?
Not necessarily. The key is not to confuse the written form with the obligation itself. In many contexts, documentation is still valuable, but it should support risk management, not replace it.
How can leaders tell if compliance is meaningful?
Ask whether the activity changes how work is done, whether workers find it useful, and whether the data created by the process can be trusted to support better decisions.
The biggest takeaway is simple: compliance should help people manage risk, not just prove they filled out a form. When you focus on the quality of compliance, and design for deep and adaptive compliance where it makes sense, you build a system that is more useful, more trustworthy, and more resilient. If you want safer work, start by asking whether your compliance process is actually helping the work get done safely.