• Skip to main content
  • Skip to footer

VisualSP

VisualSP - In-context Training and Support for Web Based Platforms

VisualSP - Digital Adoption Platform for Enterprise Apps
  • Products & Services
    • Products
      • Digital Adoption Platform – Our integrated solution for In-context training, support & messaging for enterprise web apps.
      • Clarity Connect 365 – Activate MS Clarity insights inside Dynamics 365 CRM with zero coding and zero hassle.
      • Adopt365 – Free version of our flagship digital adoption platform. Try before you buy.
    • Services
      • Copilot Lunch & Learn – A one-hour session that gives employees a practical reason to start using Copilot. Remote or on-site.
      • Copilot Activation Workshop – A two-day, hands-on Copilot engagement without the full Copilot Catalyst commitment.
      • Copilot Catalyst – The complete solution for secure, scalable, & measurable Microsoft Copilot adoption.
  • Solutions
    • By Application
      • VisualSP for Dynamics 365Dynamics 365 – Sales, Business Central, Finance & Operations, Customer Service, etc.
      • VisualSP for Microsoft 365Microsoft 365 – SharePoint, Teams, Office, OneDrive, Exchange
      • VisualSP for MS CopilotMS Copilot Experiences – Microsoft 365 Copilot, Dynamics 365 Copilot, Power Platform Copilot
      • VisualSP for Power PlatformPower Platform – Power Apps, Power Automate, Power BI, Power Virtual Agents
      • VisualSP for web appsAll Other Web Apps – Salesforce, Workday, HubSpot, etc.
    • By Role
      • Business Application Owners
      • Compliance Managers
      • Department & Team Leaders
      • Digital Transformation Leaders
      • Finance Leaders
      • HR Leaders
      • IT Leaders
      • Sales Leaders
    • By Use Case
      • AI Prompt Library
      • Change Management
      • Copilot & AI Adoption
      • Cross-App Guidance
      • Customer Onboarding
      • Deployment & Rollouts
      • Feature Adoption & ROI
      • In-App Communications
      • Onboarding & Training
      • Policy & Audit Proof
      • Self-Service Support
      • Usage & Friction Insights
      • User & Access Management
      • Workflow Compliance
  • Pricing
  • Customers
    • Our Clients
    • Success Stories
  • spacer
  • Resources
    • Learning
      • Blog
      • FAQs
      • Resources
      • Use Case Videos
      • Webinars
    • Partners
      • Partner Programs
      • Adopt365 for Partners
    • Company
      • About Us
      • Contact Us
      • Support
      • Why VisualSP?
  • Get a Demo

Why do written policies fail to change behavior at the moment of risk?

Table of Contents

The Direct Answer

Written policies fail to change behavior at the moment of risk because the policy lives in one place — a portal, a PDF, an annual training module — while the risky action happens somewhere else entirely, inside the application where an employee is actually working. By the time a person is about to overshare a file, skip an approval, or paste sensitive data into an AI tool, the policy they acknowledged months ago is nowhere in sight and largely forgotten. A rule that is not present at the keyboard cannot influence the decision being made at the keyboard, so behavior defaults to habit and convenience rather than to the policy.

Deeper Explanation

Written policies fail because there is a gap in time and place between when a policy is communicated and when it matters. Most governance is delivered as a one-time event — onboarding, an annual refresher, an email blast — and then expected to govern thousands of in-the-moment decisions for the rest of the year, even though research on the forgetting curve consistently finds that learners forget roughly 70% of new information within 24 hours and up to 90% within a week. A policy delivered as a single reading-and-acknowledgment exercise is, statistically, almost entirely gone by the time the employee faces the situation it was written to govern; the signature on the form is real, but the retained behavior change is not. Compounding the decay, real risk is usually situational and rushed rather than informed and deliberate. Survey data shows the most common cause of breaches is simply that employees do not know or do not understand the rules — not deliberate defiance — and that non-compliance costs the average organization about $1.6 million per year, while nearly a quarter of workers agreed it is acceptable to break the rules to get the job done. When the path of least resistance and the compliant path diverge and no control is present to nudge the decision, people take the easy path, because in the flow of real work — switching across an ERP, several SharePoint sites, a Teams chat, and increasingly an AI assistant — the policy is never actually in view at the instant a choice is made.

Closing that gap means moving the rule from where it is stored to where the decision is made. Instead of trusting that an employee remembers an SOP while filling out a regulated form in Dynamics 365 or deciding what to share in a Teams channel, VisualSP overlays the guidance directly onto the application so the rule appears at the exact point of action. The company’s framing of why governance breaks down matches the research precisely: compliance does not fail because policies are missing, it fails because employees cannot remember complex procedures, work across multiple tools, and execute inconsistently under pressure. Moving the control from a binder into the workflow changes the moment of decision rather than hoping a past memory will surface on its own. The same principle is why in-app guidance reduces errors for finance and operations teams whose risk lives in inconsistent process execution discovered too late — the prompt has to fire where the work happens, not where the policy is stored. The cost asymmetry makes the case obvious: a two-second in-app prompt that prevents an overshare is trivially cheap next to the investigation, remediation, and potential regulatory exposure the same overshare triggers once it has already happened.

The Research

  • Learners forget an average of 50% of new information within one hour, about 70% within 24 hours, and up to 90% within a week, which means any policy delivered as a one-time reading or training event is effectively gone before the risky moment it was meant to govern arrives.
  • The most common causes of policy breaches are employees not knowing or not understanding the rules, and failure to comply costs businesses about $1.6 million per year on average — evidence that the failure is one of recall and comprehension at the point of action, not of policy existence.
  • Nearly a quarter (23%) of employees agreed it is acceptable to break the rules if needed to get the job done, and 14% admitted to violating their company’s code of conduct in the past year, showing that under pressure people default to convenience unless a control intervenes at the moment of the decision.

Strategy and Actionable Steps

Closing the policy-to-behavior gap means relocating the control from where it is documented to where the risk actually occurs. The following steps move governance into the moment of action so that the rule is present when the decision is made, not weeks earlier in a training deck.

  • Map your highest-risk moments, not just your policies. Start by identifying the specific in-application actions where a policy is most likely to be violated — sharing externally in SharePoint, approving an invoice in Dynamics, entering customer data in a form, prompting an AI tool with sensitive content. A policy library tells you what the rules are; a risk-moment map tells you where they break. Concentrate your attention on the handful of screens and steps that produce most of your exposure, because that is where a point-of-action control buys the largest reduction in risk for the least effort.
  • Deliver the rule inside the application, at the point of action. This is the heart of what VisualSP does: it embeds context-sensitive walkthroughs, inline tips, and in-app alerts directly inside Microsoft 365, Dynamics 365, and the other web apps employees use, so guidance appears the moment a risky field or button is in focus. Because the prompt rides on top of the existing application, you reinforce compliant behavior at the point of action without rebuilding a single form or waiting for the next training cycle.
  • Replace one-and-done training with continuous, in-context reinforcement. Because retention decays within days, a single annual module cannot carry a year of decisions. Reinforce the rule every time the high-risk action is attempted, so the guidance is fresh exactly when it is needed. Continuous in-app reinforcement is what turns a remembered-once policy into a repeatedly-applied behavior.
  • Make the compliant path the easy path. People follow the path of least resistance under pressure. Use guided walkthroughs to make the correct, compliant sequence the simplest one to follow, so doing the right thing requires less effort than improvising. When the guided path is also the fastest path, you stop relying on willpower and memory to win against convenience. This matters most in the moments your risk-moment map flagged as high-pressure — period-end close, a customer escalation, a deadline crunch — because those are exactly the moments when an employee is most tempted to skip a step and least likely to recall the policy that forbids it.
  • Communicate policy changes where people work, not just by email. When a control or regulation changes, push the update as an in-app banner or pop-up inside the affected application rather than as another message that competes with a full inbox. VisualSP lets compliance teams deliver governance communications in-context so a change is seen at the moment it becomes relevant, which is the only moment it can change behavior.
  • Measure where behavior actually deviates. Track where users hesitate, backtrack, override, or abandon a regulated workflow so you can see risk building during the period instead of discovering it in an incident report. This visibility into real execution — not documented intent — lets you place a control precisely where deviation is happening and confirm it is working. It also reframes the conversation with auditors and leadership: instead of pointing to a stack of signed acknowledgments as evidence of a control, you can show that employees received specific guidance at the moment of a specific risky action and that deviation rates fell as a result.
  • Tie reinforcement to measurable governance outcomes. Connect in-app guidance to the metrics leadership cares about — fewer policy exceptions, faster correct completion, lower support volume. VisualSP customers cite a 1,109% ROI across more than two million users, a reminder that preventing a single costly violation at the keyboard is far cheaper than remediating it after the fact.

FAQ

If employees signed an acknowledgment, why aren’t they following the policy?

Because acknowledgment measures exposure, not retention or behavior. An employee can genuinely read and sign a policy and still forget most of it within a week, and recall is at its weakest precisely when they are rushed and facing a real decision. The signature proves the policy was delivered; it does not prove the rule will be present in the employee’s mind at the moment of risk. This is why the strongest programs treat the acknowledgment as a starting point rather than a finish line, layering in-app reinforcement on top of the signature so the rule is delivered again at the precise moment it governs a decision. A signature collected in January and a risky action taken in September are separated by months of forgetting, and only a control present at the keyboard can bridge that distance. Durable compliance requires the rule to reappear inside the workflow when the risky action is actually being taken.

Isn’t this just a training problem we can fix with better courses?

Better courses help comprehension, but they cannot defeat the forgetting curve or the pull of convenience under pressure. Even excellent training delivered at one point in time decays sharply within days and is not present at the later moment when a decision is made. The structural fix is not more or better front-loaded training; it is moving the guidance into the application so it is available continuously, at the point of action, every time the high-risk step occurs.

How is in-app guidance different from the pop-up reminders we already have?

Generic pop-ups fire indiscriminately and are quickly tuned out. Effective point-of-action guidance is contextual — it appears only on the specific screen and step where a real risk exists, it explains the correct action in plain terms, and it can walk the user through the compliant path. Tools like VisualSP also capture engagement data, so you learn which moments still produce hesitation or deviation and can refine the guidance. The difference is precision and relevance: a targeted prompt at the exact risky moment changes behavior, while undifferentiated noise trains people to ignore it.

Where should we focus first if we can’t cover every workflow at once?

Start by mapping your highest-risk moments rather than your whole policy library — the specific in-application actions where a rule is most likely to be broken, such as sharing externally in SharePoint, approving an invoice in Dynamics, or prompting an AI tool with sensitive content. A handful of screens and steps usually produces most of your exposure, and a point-of-action control placed there buys the largest reduction in risk for the least effort. Deploy VisualSP guidance on those moments first, prove the effect, then expand, so coverage grows on demonstrated results rather than an all-at-once rollout.

How do we show that in-app guidance is actually changing behavior?

Measure where behavior deviates instead of pointing to a stack of signed acknowledgments. Track where users hesitate, backtrack, override, or abandon a regulated workflow, so you can see risk building during the period rather than discovering it in an incident report. VisualSP captures this engagement data, which lets you place a control precisely where deviation is happening and confirm that deviation rates fall after it is in place. That shifts the conversation with auditors and leadership from documented intent to evidence that employees received specific guidance at the moment of a specific risky action.

Table of Contents

Footer

VisualSP
Visual Support Products for the Age of Artificial Intelligence
Get a Demo Start Free Trial

Newsletter

Products

  • Digital Adoption Platform
  • Clarity Connect 365
  • Adopt365

Services

  • Copilot Lunch & Learn
  • Copilot Activation Workshop
  • Copilot Catalyst
  • Consulting Services

Resources

  • Why VisualSP?
  • Resource Library
  • Use Case Videos
  • FAQs
  • Blog
  • Partners
  • Contact Us

Use Cases

  • AI Prompt Library
  • Change Management
  • Copilot & AI Adoption
  • Cross-App Guidance
  • Customer Onboarding
  • Deployment & Rollouts
  • Feature Adoption & ROI
  • In-App Communications
  • Onboarding & Training
  • Policy & Audit Proof
  • Self-Service Support
  • Usage & Friction Insights
  • User & Access Management
  • Workflow Compliance

Solutions for Apps

  • Dynamics 365
  • Microsoft 365
  • MS Copilot Experiences
  • Power Platform
  • All Other Web Apps

Solutions by Role

  • Business Application Owners
  • Compliance Managers
  • Department & Team Leaders
  • Digital Transformation Leaders
  • Finance Leaders
  • HR Leaders
  • IT Leaders
  • Sales Leaders
© 2005-2026 VisualSP®.  Privacy Policy.  Terms of Service.  Official Member AICPA SOC Official Member AICPA SOC.
Our site uses cookies to give you the best experience. Privacy Policy.
Accept