Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.
Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.
That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.
A Book About the Decisions Before the Decision
Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.
The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.
Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.
Why Compliance Leaders Should Read It
The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.
Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.
Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.
This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.
Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.
The Most Useful Tool: HQDM
The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.
For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.
The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.
Where the Book Requires Compliance Translation
The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.
The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.
AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.
The Verdict
This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.
CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.
Questions for CCOs and Boards
Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?
Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?
Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?
Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?
Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?