Risk & Compliance Matters

Shadow Policies: Increasing Legal Exposure & Liability

Are you scared of shadows? You should be, as they can cause serious legal, operational, compliance, risk, brand/reputation, and integrity liability. 

For the past several years organizations have been battling shadow IT. This is the use of information technology applications, devices, software, technology, and services within departments and bypassing IT and without their approval. Shadow IT has grown significantly over the past several years with the adoption of cloud-based applications and services. It introduces serious risk exposure to your organization through data breaches and potential compliance violations.

The risk of shadow policies is growing with organizations coming out of lockdown.

Now there is a new shadow to be scared of: shadow policies. These are rogue policies that are being written at all levels of the organization without proper review and approval. This puts the organization at significant risk to legal liability and exposure. Policies set a legal duty of care for the organization. If a manager is communicating to employees and clients a policy, this establishes a potential exposure to the organization. If an employee, client, or other third-party is harmed and they can point back to a policy that a manager communicated, it opens the doors of liability. 

The issue is that organizations do not have a handle on their policies. Many lack a consistent portal, template, style guide, and a policy on writing policies. It is like the Wild West, with every department writing their own policies. Any manager can open a word processor and write a document, call it a policy and communicate it to others. One financial services firm found one division that did not like the official anti-money laundering policy and completely rewrote it the way they thought it should be written, a rogue shadow policy. An insurance firm, entering lockdowns a year back, found they had over 20 policy portals in the organization with no consistency in how policies were written, approved, or communicated.

The risk of shadow policies is growing with organizations coming out of lockdown. A business might have carefully crafted back-to-work policies combined with personal protective equipment policies, vaccination policies, and more. The issue is rogue managers think they are a little smarter than the organization and are writing shadow policies contrary to the official ones. Perhaps they think everything is a hoax and writing policies opposite of the organization, or perhaps they do not think the organization is strict enough in safety and are writing policies that require vaccinations, and in writing so may be crossing discrimination lines. I am seeing huge issues in retail and hospitality organizations with store managers going different directions on policies than what has been officially approved by the organization. I have seen this in bank branches as well. Shadow policies are putting significant legal liability and exposure on the organization.

So how do you combat shadow policies? Here is what you need to do:

Shadow policies, like shadow IT, are a growing concern for organizations and require a structured and continuous process – incorporating the elements defined above – to reduce liability. This is not a one-time issue to address but a continuous challenge to monitor.

Discover the 3 Keys to Successful Hybrid Risk & Compliance Programs

View on Full Site

The EU Whistleblower Protection Directive – How Are Member States Handling the Transposition?

‹ Previous Article

10 years of whistleblowing and WhistleB on World Whistleblower Day

Next Article ›