Reading the Room in Compliance, Knowing When and How to Push an Issue
Compliance professionals are trained to notice what others may overlook, an approval that never happened, a control that is not operating as intended, an exception becoming routine, a regulatory change that has not yet made its way into a policy, or a business decision carrying more risk than people realize.
Spotting the issue, however, is only part of the job. The harder question is often: What do you do with it now? Do you raise it immediately? Speak to the business owner first? Take it to senior leadership? Ask more questions before forming a view? Put the concern in writing? Push firmly, or give the team space to find a workable solution?
This is where one of the less discussed skills in compliance becomes important: reading the room.
Reading the room does not mean becoming political, softening an uncomfortable message, or staying quiet because raising an issue might be inconvenient. It means understanding the people, context, timing, incentives, and consequences surrounding a compliance issue so that the message has the best chance of leading to action.
The goal is not simply to be right. The goal is to make sure the right thing happens. Compliance rarely operates through authority alone.
Highlights
Most compliance officers do not directly manage every person responsible for completing a control, updating a policy, conducting due diligence, retaining evidence, investigating an issue, or addressing a regulatory obligation.
They depend on people across Legal, HR, Finance, IT, Security, Operations, Sales, Procurement, and senior leadership.
That makes compliance an unusual function. It can carry significant responsibility without having direct authority over many of the actions required to manage that responsibility.
A compliance officer may identify a gap, but someone in Operations has to fix it. Compliance may establish a requirement, but managers have to reinforce it. Compliance can design a training program, but employees still need to take it seriously. Compliance can escalate an overdue obligation, but leadership may ultimately determine how quickly resources are allocated.
The U.S. Department of Justice’s Evaluation of Corporate Compliance Programs reflects this broader reality. Its September 2024 guidance asks not only whether a compliance program exists, but whether it is adequately resourced and empowered, whether employees are willing to report concerns, whether compliance personnel have appropriate access to data, and whether the program actually works in practice.
That distinction matters. A policy can exist on paper while the organization behaves differently. A control can have an owner while nobody feels genuinely responsible for it. Leadership can say compliance matters while operational pressures quietly send another message. The compliance officer has to understand both worlds.
Compliance happens on paper and between people. Strong programs pay attention to both.
Read the room first
Reading the room starts before the meeting. Imagine discovering that a business unit has repeatedly missed a regulatory control deadline. The facts may be straightforward, but the reason behind the delay rarely is.
One manager may not understand the requirement. Another may understand it but lack the resources to act. A third may disagree with compliance’s interpretation of the obligation. Senior leadership may believe the problem was resolved months ago, while the control owner is already dealing with another major operational issue.
Sending the same escalation email to everyone treats very different situations as though they are identical. Before pushing an issue further, compliance needs to understand what is actually preventing action.
Is it a knowledge gap, unclear ownership, limited resources, disagreement over risk, a broken process, or simply a lack of urgency? Each problem requires a different response.
If ownership is unclear, another reminder will accomplish little. If leadership has knowingly accepted the risk, repeatedly explaining the regulation may not change the discussion. If the team lacks resources, the real conversation may be about priorities rather than awareness.
Reading the room means diagnosing the barrier before choosing the response.
Before asking, “How do I escalate this?” ask, “Why has this not moved already?”
Choose the right audience
Not every compliance issue needs the biggest audience available. Escalating too broadly, too early can sometimes make resolution harder.
Suppose a compliance officer identifies incomplete evidence for an important control. Copying the department head, general counsel, CIO, and several senior executives on the first email may get attention, but it can also put the control owner immediately on the defensive. A short conversation might reveal that the evidence exists and was simply stored in the wrong system.
The opposite can happen too. Compliance may continue working quietly with a control owner even after it becomes clear that the person cannot resolve the issue independently. At that point, failing to involve leadership can allow the risk to grow.
The skill is knowing when the audience needs to change. A useful principle is to involve the people who can understand the issue, make the necessary decision, and provide the resources or authority required to resolve it.
Sometimes that is one manager. Sometimes it is the board.
The OECD’s Good Practice Guidance similarly emphasizes visible senior-management commitment to compliance while recognizing that compliance programs should reflect an organization’s individual circumstances and risks. Good escalation is therefore not about how many senior people receive the message. It is about whether the right people receive it at the right stage.
Consider the timing
A compliance issue does not become less important because the business is busy. But timing can determine whether people actually absorb what compliance is saying.
Imagine walking into the final meeting before a major product launch and introducing a significant compliance concern that could delay release. If the risk is material, silence is not an option. But how the issue is framed still matters.
“Compliance hasn’t approved this. The launch needs to stop.”
That lands very differently from:
“Before we launch, there is one unresolved issue that could create regulatory exposure. Here is the specific gap, what we need to resolve it, and the fastest compliant path forward.”
The underlying concern has not changed. The second approach gives the room something it can work with.
This becomes even more important when the organization is under pressure. During a regulatory examination, security incident, customer escalation, acquisition, product launch, or major operational deadline, attention narrows. Long explanations of compliance theory rarely help. The compliance professional has to identify what matters most and communicate it clearly. Urgency should make compliance communication clearer, not louder.
Explain what the issue means for them
Compliance professionals naturally think in terms of obligations, controls, regulations, evidence, policies, and risk. Other functions may see the same issue through a very different lens.
A CFO may focus on financial exposure. A COO may think about operational disruption. A salesperson may be concerned about closing a customer. An IT leader may be thinking about system dependencies. A CEO may be balancing reputation, growth, customers, investors, employees, and several other priorities at once.
Compliance does not need to abandon its own language. But translating the issue into the context of the person responsible for acting can make the message far more useful.
Compare: “We need this completed because control 4.3 requires quarterly review.”
With: “We haven’t completed the access review for this quarter. That means we cannot currently demonstrate that privileged access is still appropriate. We need the system owner to complete the review before Friday so we have evidence before the audit.”
One explains the rule. The other explains the consequence, owner, action, and deadline.
That is not watering down compliance. It is making compliance actionable.
COSO’s guidance on applying enterprise risk management to compliance risk emphasizes integrating compliance risk into the organization’s broader management of risk rather than treating it as an isolated activity. Compliance becomes easier to act on when people can see how an issue connects to broader organizational objectives.
Ask before assuming
Compliance professionals are often expected to provide answers. But some of the most useful compliance conversations begin with questions.
What is stopping this from being completed? Who actually owns this process today? What would happen operationally if we introduced this control? Is there another way to achieve the same compliance outcome? When did the process change? Who else needs to be part of the decision?
Questions reveal information that an escalation spreadsheet cannot.
Consider an employee who repeatedly misses required compliance activities. It would be easy to conclude that the employee is ignoring compliance. A conversation might reveal that responsibilities changed months ago, but the compliance system still assigns tasks based on the old organizational structure.
The apparent behavior problem was actually a process problem.
Strong compliance professionals develop enough curiosity to investigate the situation before deciding what it means. They look for the cause behind the missed obligation rather than treating every delay as resistance.
Not every missed obligation is resistance. Sometimes it is a signal that the process itself is not working.
Watch the reaction
Reading the room also means paying attention to what happens when Compliance enters the conversation.
Do people become defensive? Do they stop sharing information? Does the tone suddenly become formal? Do employees involve Compliance early, or only after something has already gone wrong?
These reactions can reveal a great deal about compliance culture.
The DOJ’s current compliance guidance looks at whether employees understand how to report concerns, whether they feel comfortable doing so, whether reporting channels are trusted, and whether people are protected from retaliation.
A compliance function can be technically correct and still be difficult to approach. When that happens, important information may reach Compliance too late.
That does not mean Compliance needs to become everyone’s friend. Independence still matters, and difficult decisions will still need to be made.
The goal is trust. People should believe that involving Compliance early will lead to a thoughtful assessment, not an automatic obstacle.
That reputation is built one conversation at a time.
Know when the room stops mattering
There is an important boundary.
Reading the room should improve how an issue is handled. It should not determine whether a serious issue is addressed.
Potential fraud, retaliation, deliberate concealment, serious safety concerns, major regulatory breaches, obstruction of an investigation, or conduct that could cause substantial harm may require immediate escalation.
In those situations, organizational awareness cannot become organizational avoidance.
If the issue requires action, act.
Even then, the escalation should be clear. Senior leaders need to understand what happened, what is known, what remains uncertain, the potential impact, the immediate action required, and who needs to be involved next.
Reading the room changes the delivery. It should never change the integrity of the message.
Escalate facts, not frustration
Compliance work can be frustrating.
A task may be overdue for 60 days. Evidence may have been requested several times. A business unit may have made a decision without involving Compliance. A policy update may still be waiting for approval after repeated discussions.
Frustration is understandable, but it rarely improves an escalation.
Statements such as, “We’ve asked repeatedly and nobody is taking this seriously,” may reflect how the situation feels. They do not necessarily help leadership decide what to do next.
A stronger escalation stays factual.
“The control was due July 1. The owner was contacted on July 3, July 15, and August 2. Evidence remains outstanding. Without the review, we cannot confirm that the control operated during the quarter. We recommend completing the review by Friday or formally documenting the exception and remediation plan.”
The structure is simple: dates, facts, risk, action, decision.
That makes it easier for leadership to understand the issue and respond quickly. It also protects the credibility of Compliance by keeping the focus on the risk rather than the emotion surrounding it.
Start your 21-day free trial and experience how VComply helps you with your policy management and compliance maturity.
Build influence early
The worst time to start building a relationship with a business leader is when you need to tell them something they do not want to hear. Compliance influence develops long before escalation.
It comes from understanding how teams operate, joining the right discussions, responding quickly when someone asks for guidance, explaining why requirements exist, recognizing legitimate operational constraints, and following through when Compliance makes a commitment.
Over time, people begin to understand what kind of compliance function they are dealing with. When Compliance consistently brings context rather than simply citing rules, difficult conversations become easier.
When Compliance distinguishes genuinely serious issues from minor administrative ones, escalation also carries more weight. And when the team has demonstrated that it understands how the business actually operates, its advice becomes harder to dismiss as theoretical.
This is one reason effective compliance programs cannot sit entirely outside business operations. COSO’s compliance risk guidance connects compliance with broader enterprise risk management and organizational objectives, with responsibilities extending beyond the compliance function itself.
Compliance still needs independence, but independence does not require isolation.
Know when to push
Reading the room is ultimately a judgment skill. It means recognizing when a conversation needs patience and when it needs urgency, when a private discussion may resolve the issue and when leadership needs visibility.
It also means knowing when someone needs more explanation and when they already understand the risk. Resistance may come from disagreement, limited resources, unclear ownership, or competing priorities. Each situation calls for a different response.
Sometimes the right move is to ask another question. Sometimes it is to offer another route. And sometimes it is to say clearly that the situation cannot continue.
The strongest compliance professionals are not necessarily the people who speak the loudest or escalate the fastest. They are the people whose judgment others trust.
They understand the requirement and the risk, but they also understand the organization in which that requirement has to become real.
Successful compliance is not measured only by how many concerns the compliance team identifies. What matters is what the organization does about them.
Read the requirement. Read the risk. But also read the room.
Frequently Asked Questions (FAQs)
What does “reading the room” mean for a compliance officer?
It means understanding the people, timing, business circumstances, decision-makers, and organizational dynamics surrounding a compliance issue before deciding how best to address it. It is not about changing the compliance requirement. It is about choosing an approach that makes action more likely.
Does reading the room mean compromising on compliance?
No. A compliance requirement does not disappear because it is inconvenient. Reading the room affects how you communicate, sequence, investigate, collaborate, or escalate an issue. Serious risks still need to be addressed even when the conversation is uncomfortable.
How can compliance officers become more influential without formal authority?
Start by building credibility outside moments of conflict. Understand how the business operates, explain risk in practical terms, make recommendations rather than simply identifying problems, follow through on commitments, and distinguish between issues that genuinely require escalation and those that can be solved directly with the owner.
When should a compliance issue be escalated?
There is no universal threshold. Factors can include the seriousness of the potential harm, regulatory impact, repeated control failures, inability or unwillingness of the owner to remediate the issue, approaching deadlines, senior-management involvement, potential misconduct, and whether immediate action is needed to prevent further harm. Organizations should establish clear escalation criteria so these decisions do not depend entirely on individual judgment.
How do you raise a compliance concern without making people defensive?
Lead with facts rather than accusations. Explain what happened, why it matters, what remains unknown, and what needs to happen next. Where appropriate, begin by asking questions. People are more likely to engage when the conversation is focused on resolving the issue rather than assigning blame before the facts are established.
What makes someone effective at reading the room?
Experience helps, but the core habits can be learned: listen carefully, understand stakeholders, pay attention to incentives and pressures, ask questions before reaching conclusions, communicate according to the audience, separate emotion from escalation, and know which issues leave little room for compromise.
Ultimately, reading the room is not about becoming less assertive.
It is about becoming more effective.
A compliance professional still needs the confidence to challenge decisions, raise uncomfortable issues, and protect the integrity of the program. But knowing when to speak, how to frame the issue, who needs to hear it, and what action to ask for can determine whether a compliance concern simply gets communicated or actually gets resolved.