Organisations often invest significant time and effort developing policies and procedures, yet the existence of a policy alone does not guarantee that employees understand how to apply it in real workplace situations.
This project was initiated following a series of minor security-related incidents that highlighted a recurring challenge. Whilst employees had access to comprehensive policy documentation and procedures, many struggled to translate the written guidance into practical day-to-day decision-making. The organisation recognised an opportunity to move beyond traditional policy communication and create a learning experience that would help employees understand not only what the policies said, but why they mattered and how they should be applied in practice.
The objective was to improve policy adherence, strengthen security awareness and reduce future incidents by making learning more engaging, relevant and behaviour-focused.
Challenge
The root cause analysis quickly revealed that the issue was not a lack of information. Employees had access to detailed policy documents, but the format created an unintended barrier to understanding.
Many policies described what employees should and should not do, but provided limited context around how those decisions would present themselves in the workplace. As a result, employees often found it difficult to visualise the situations they might encounter or understand the consequences of poor decision-making. This disconnect between policy and practice increased the likelihood of inconsistent application and avoidable security incidents.
The solution also needed to work for a highly diverse audience. All new employees were expected to complete the training during their first week, regardless of age, role, experience level or seniority. The challenge therefore extended beyond compliance. The learning needed to feel relevant and engaging for everyone, from frontline employees through to senior management.
Success would ultimately depend on changing behaviour rather than simply increasing awareness.
Approach
I began by reframing the learning challenge. Rather than asking how we could make policy documents more engaging, I focused on how we could help employees practise applying security policies in realistic workplace situations.
Following discussions with stakeholders and a review of previous incidents, it became clear that scenario-based learning offered the strongest opportunity to influence behaviour. Employees needed to experience situations that mirrored the decisions they might encounter in their daily roles and understand the consequences of their actions within a safe learning environment.
To support this objective, I designed a video-led branching scenario experience using realistic workplace situations as the core learning mechanism. Instead of presenting policies as a series of rules, the course placed learners in authentic scenarios where they were required to assess information, make decisions and observe the outcomes of those choices.
The use of video provided a higher degree of realism and emotional connection than traditional text-based training. Learners could see the situations unfold, recognise familiar workplace behaviours and better understand how seemingly small decisions could create larger operational or security risks.
Throughout the design process, significant attention was given to creating realistic situations that reflected genuine workplace challenges rather than simplistic right-or-wrong quiz questions. Branching pathways allowed learners to explore the consequences of poor decisions without real-world repercussions, creating valuable opportunities for reflection and discussion.
The overall experience was supported by multimedia elements, interactive activities and knowledge reinforcement techniques designed to maintain engagement whilst ensuring the key policy messages remained clear and actionable.
Outcome
The final solution transformed mandatory policy training into a practical and immersive learning experience centred around decision-making and behavioural application.
Employees were no longer expected to simply memorise procedures. Instead, they were given opportunities to apply policies within realistic contexts, helping them build confidence and develop a clearer understanding of how security procedures should influence their actions in everyday situations.
By shifting the focus from information delivery to behavioural practice, the programme helped bridge the gap between policy awareness and workplace performance. Complex policies became more relatable, easier to understand and more relevant to employees regardless of role or experience.
The project also demonstrated how compliance learning can move beyond a traditional "tick-box" exercise and become a meaningful intervention that actively supports operational risk reduction and organisational security objectives.
This project reinforced a principle that continues to influence my approach to compliance learning today: people rarely fail because they don't know a policy exists. More often, they struggle to recognise when and how to apply it.
The original request focused on improving policy training, but the deeper challenge was improving judgement and decision-making. By placing learners into realistic situations and allowing them to explore the consequences of their choices, the project shifted compliance learning from knowledge transfer to behavioural development.
It also highlighted the importance of designing learning around real workplace performance rather than organisational content. Policies are important, but what ultimately matters is the behaviour they are intended to influence. The most effective compliance programmes are those that help employees confidently bridge the gap between knowing and doing.