First: by "leader" I don't mean only the CEO. I include the broader management layer — executives and managers with final approval authority. I'll call all of them leaders below.
I'm not a leader myself, so I hesitated to write on this theme — but whenever I look for blog topics, this one keeps coming up, so I'm writing it down.
In business, internal operations and workflows should be as efficient, rational, and simple as possible. Ideally, only the minimum consensus needed for the company's goals (revenue and profit) should exist.
That said, for internal control you also end up with mechanisms that may not be essential in substance.
There are standard internal flows like approval requests and proposal documents, and you sometimes need system constraints for risk management.
For a small change, someone may have to apply, get an approver's sign-off, and only then make the change.
Still, if you get trapped by formality, you get bizarre internal workflows.
Automatic ZIP encryption when sending files is one example of a rule that exists because people got stuck on form.
Why do such annoying rules exist? Because leaders carry risk.
When something serious goes wrong, the leader is accountable.
Of course this isn't about personal blame-dodging — as an organization you need internal controls to run properly.
But to put it extremely: if you aim for perfect internal control, you can keep adding forever.
You could blanket even how people lift their chopsticks with strict rules.
Focus on that, though, and nobody can move for the revenue and profit that keep the company alive.
No amount of internal work raises sales.
Extremely speaking, if you want zero risk, you'd be better off not running a business at all.
So leaders need to firmly say NO to internal controls that feel excessive, and no matter how much outside criticism comes in, they have to push the debate to protect operations all the way. Sometimes they'll have to fight outsiders too.
Are leaders really thinking carefully about operations and internal control? Are they trying to protect operations?
If the other side of the risk scale becomes only themselves (≈ self-preservation), and they adopt excess rules for that reason, the business ends up with shackles on its feet.
© 2020 ZUUHE