Rationalization: When Management Knows the Control Is Being Bypassed—and Explains Why It Is Okay
- John C. Blackshire, Jr.

- 5 hours ago
- 11 min read
“There Is a Good Reason We Do It This Way.”
Denial is difficult for an internal auditor to overcome.
Rationalization can be even more dangerous.
With denial, management disputes the facts:
“That didn't happen.”
With rationalization, management may accept the facts completely:
“Yes, we bypass the control. But there is a good reason.”
That distinction should immediately get an internal auditor's attention.
You may hear:
“We're understaffed.”
“Everyone does it.”
“The policy is unrealistic.”
“The system doesn't work.”
“We had to meet the deadline.”
“There wasn't enough time to get approval.”
“Management knows we do it this way.”
“We've always done it this way.”
“Nothing bad has ever happened.”
“It's only temporary.”
The facts are no longer necessarily in dispute.
Instead, the control violation has been explained, justified, and normalized.
For an internal auditor, that can be a much bigger problem.
What Is Rationalization?
Rationalization is the process of developing a seemingly reasonable explanation for behavior that conflicts with a rule, control, policy, expectation, or ethical standard.
It allows a person to reconcile two conflicting thoughts:
“I am a responsible employee.”
and
“I knowingly bypassed the control.”
Something has to bridge those two ideas.
Rationalization provides the bridge:
“I bypassed the control because the company didn't give me enough resources.”
Now the employee does not have to think:
“I violated the control.”
Instead:
“I did what was necessary to get the job done.”
That psychological distinction is enormously important to auditors.
Rationalization Does Not Automatically Mean Fraud
Auditors need to be careful here.
Rationalization is one component of the classic Fraud Triangle, along with:
Pressure
Opportunity
Rationalization
But hearing a rationalization does not establish that fraud has occurred.
An employee who says, “I skipped the approval because we were going to miss the deadline,” has not necessarily committed fraud.
What the statement tells the auditor is something different:
Under certain circumstances, the employee believes bypassing the control is acceptable.
That is important audit evidence.
The auditor should now understand those circumstances.
“We Had to Get It Done”
This may be one of the most common rationalizations in business.
Imagine an Accounts Payable department.
Company policy requires independent verification whenever a vendor requests a change to banking information.
The employee receives an urgent email:
“We changed banks. Please use the attached account information for today's payment.”
The employee tries to contact the vendor but cannot reach anyone.
The payment deadline is approaching.
The employee changes the banking information and releases the payment.
During the audit, the auditor asks why independent verification was not performed.
The employee responds:
“We couldn't reach the vendor, and the payment had to go out.”
Notice what happened.
The control did not fail accidentally.
The employee deliberately bypassed it.
But from the employee's perspective, the decision may have been completely reasonable.
Objective: Make the payment on time.
Obstacle: Verification could not be completed.
Solution: Bypass verification.
The employee solved one business problem while creating another.
That is precisely the type of situation Internal Audit needs to understand.
The Auditor Should Ask: What Behavior Is the Organization Actually Rewarding?
Suppose management tells employees:
“Never bypass the vendor-verification control.”
But those same employees are evaluated on:
Payment-processing time
Vendor complaints
Late-payment percentages
Transaction volume
What happens when the control conflicts with the performance metric?
The organization may officially say:
“Follow the control.”
while unofficially communicating:
“Whatever you do, don't miss the deadline.”
That creates an environment for rationalization.
The employee can say:
“Management expects us to get these payments processed.”
And the employee may be right.
Internal auditors should therefore look beyond written policies and ask:
What behavior does the organization's incentive system actually encourage?
That is a control-environment question.
“We're Understaffed”
This is another common explanation.
The auditor finds:
Reconciliations are not completed.
Supervisory reviews are late.
Access reviews are skipped.
Supporting documentation is missing.
Exception reports are not investigated.
Management responds:
“We're understaffed.”
That explanation may be entirely accurate.
But it does not make the risk disappear.
This is where auditors sometimes mishandle rationalization.
The auditor responds:
“The policy still requires the review.”
That may be technically correct but operationally useless.
The better response is:
“If staffing levels make the control impossible to perform consistently, do we have a control-design or resource-allocation problem?”
Now the audit has moved beyond blaming employees.
The root cause may be that management has designed a control environment that cannot operate with available resources.
That is a much more valuable audit conclusion.
Rationalization Can Reveal the Root Cause
This is one reason auditors should not immediately shut down rationalizations.
Listen to them.
A rationalization may contain extremely valuable information.
Consider these statements:
“The system takes too long.”
Possible root cause: Technology/design problem
“Nobody reviews those reports.”
Possible root cause: Monitoring failure
“We don't have enough people.”
Possible root cause: Resource constraint
“My supervisor told me to do it.”
Possible root cause: Management override
“The policy doesn't reflect how the process actually works.”
Possible root cause: Outdated policy
“Everybody shares that password.”
Possible root cause: Access-control design and cultural problem
“We have to close the books by Day Three.”
Possible root cause: Conflicting performance objectives
The rationalization may be pointing directly at the cause of the finding.
The skilled auditor listens before judging.
“Everyone Does It”
This statement should get an auditor's attention.
It suggests that the issue may not be an isolated exception.
Suppose one employee bypasses an approval requirement.
That might be an individual operating failure.
But the employee tells the auditor:
“Everybody does it.”
Now the auditor has a different question:
Is this actually the organization's informal process?
That may justify expanding testing.
Interview other employees.
Examine additional transactions.
Observe the process.
Determine whether supervisors know about the practice.
The difference is significant:
One employee bypassing a control
is different from:
An entire department routinely bypassing the control with management's knowledge.
The second situation may indicate a control-environment problem.
“We've Always Done It This Way”
This phrase often represents organizational inertia combined with rationalization.
The practice may have made sense ten years ago.
But perhaps:
Transaction volume increased.
Technology changed.
Fraud risks changed.
Regulations changed.
The organization grew.
Employees changed.
Systems became more complex.
The control environment did not evolve.
People continue performing the process because:
“That's how we do it.”
The auditor should ask:
Why?
Not sarcastically.
Literally.
Why does this step exist?
What risk does it address?
What would happen if it disappeared?
Who relies upon it?
The auditor may discover either that:
An obsolete practice should be eliminated, or
Employees no longer understand why an important control exists.
Both are useful findings.
“Nothing Bad Has Happened”
This rationalization confuses absence of detected loss with effective risk management.
Consider a company where administrators share privileged system credentials.
Management says:
“We've done this for years and never had a problem.”
That does not establish the control is appropriate.
Perhaps:
No misuse has occurred.
Misuse occurred but was not detected.
Other controls prevented loss.
The organization has simply been fortunate.
The relevant audit question is:
What prevents or detects unauthorized activity?
Internal controls should not depend upon continued good luck.
“Management Knows About It”
This statement changes the audit.
Suppose an employee knowingly bypasses a control and says:
“My manager knows we do it.”
The auditor now needs to determine:
Does the manager actually know?
Did the manager authorize it?
Is the exception formally approved?
Is the control no longer considered necessary?
Is there a compensating control?
Is this management override?
How far up the organization does the practice extend?
Do not assume the employee's statement is correct.
Verify it.
But if management knowingly tolerates repeated control circumvention, the auditor may be looking at more than an operating-effectiveness exception.
The issue may involve the control environment.
When an Exception Becomes Normalized
This is where rationalization becomes particularly dangerous.
Consider the progression:
Step 1: An unusual situation occurs.
“We'll bypass the control this one time.”
Step 2: It happens again.
“We did it last month.”
Step 3: Employees become comfortable with the workaround.
“This is easier.”
Step 4: New employees learn the workaround.
“This is how we actually do it.”
Step 5: Management becomes accustomed to the practice.
“Everybody knows about it.”
Step 6: The written policy still describes the original control.
Now the organization has two processes:
The formal process
and
the real process.
Internal auditors need to find the real one.
That is why walkthroughs are so important.
Walkthroughs Should Look for Rationalization
A weak walkthrough asks:
“Does the supervisor approve purchase orders?”
The employee responds:
“Yes.”
The auditor checks the box.
A stronger walkthrough asks:
“Show me the last purchase order you processed.”
Then:
“Who approved this?”
Then:
“What happens when that person isn't available?”
Then:
“Can the purchase proceed without approval?”
Then:
“Has that happened?”
Then:
“What circumstances would cause you to bypass the normal process?”
That final question is particularly valuable.
It searches for the conditions under which the control stops operating.
Use S.P.I.N. Questioning to Explore Rationalization
The S.P.I.N. methodology can be extremely useful during these conversations.
Situation
Understand the actual process.
“Walk me through what happens when a payment requires approval.”
Problem
Identify where the process becomes difficult.
“What happens when the approver is unavailable?”
Implication
Explore the consequence of the workaround.
“If another employee uses that person's credentials to approve the transaction, how would anyone later determine who actually authorized it?”
Need-Payoff
Explore a better control.
“Would a delegated-approval workflow allow the department to meet deadlines without sharing credentials?”
Notice the difference.
The auditor has not simply said:
“You violated policy.”
The auditor has helped expose:
Problem → Workaround → Risk → Better solution
That is much more likely to produce sustainable corrective action.
Rationalization and the Fraud Triangle
Rationalization becomes particularly important when fraud risk is present.
The Fraud Triangle is commonly expressed as:
Pressure
The individual has some motivation or perceived need.
Opportunity
The person has the ability to commit and potentially conceal the act.
Rationalization
The individual develops an explanation allowing the behavior to appear acceptable to themselves.
Common fraud rationalizations can include:
“The company owes me.”
“I'm only borrowing it.”
“I'll pay it back.”
“Management cheats employees all the time.”
“Everyone manipulates their expense reports.”
“I deserve the money.”
“Nobody will be hurt.”
This is why organizational culture matters.
When employees routinely hear control violations being justified, the ethical boundary can gradually move.
Rationalization Can Become Contagious
Culture teaches employees what is really acceptable.
Imagine a new employee sees an experienced employee bypass an approval.
The new employee asks:
“Aren't we supposed to get approval first?”
The experienced employee responds:
“Technically, yes. But nobody actually does that.”
That single sentence teaches the new employee more about the organization's real control environment than the policy manual does.
The lesson is:
The written rule is not the real rule.
Over time, rationalization can become institutionalized.
That is why Internal Audit should pay attention not only to individual exceptions but also to the language people use to explain them.
Listen for Rationalization Language
During interviews and walkthroughs, auditors should listen carefully for phrases such as:
“Technically...”
“Normally...”
“Most of the time...”
“Unless we're busy...”
“We usually...”
“Everybody knows...”
“Management understands...”
“We don't really follow that anymore.”
“That's what the policy says, but...”
“We have to be practical.”
“There's no other way to get the work done.”
These statements are not proof of wrongdoing.
They are investigative leads.
The next question should usually be:
“Tell me more about that.”
Do Not Confuse Explanation With Justification
This distinction is essential.
Management may provide a completely legitimate explanation for why a control failed.
The auditor should understand that explanation.
But:
Explaining why a control failed does not automatically make the control failure acceptable.
Suppose management says:
“We couldn't perform the monthly reconciliation because two employees resigned.”
That may explain the failure.
Now the auditor must determine:
How long did the situation continue?
Was the risk recognized?
Was management informed?
Was a temporary compensating control implemented?
Were unreconciled balances subsequently reviewed?
What is management doing to prevent recurrence?
The objective is not to punish management for having a staffing problem.
The objective is to determine whether the resulting risk was appropriately managed.
The Auditor Must Also Avoid Rationalization
Auditors are not immune.
Internal Audit can rationalize poor practices too:
“We didn't have time to finish the testing.”
“We used last year's workpapers.”
“Management told us the control works.”
“The sample was probably enough.”
“We've always audited it this way.”
“We needed to issue the report.”
Those statements should sound familiar.
The same behavioral mechanism applies.
An audit deadline does not magically convert insufficient evidence into sufficient evidence.
Internal Audit should apply the same skepticism to its own explanations that it applies to management.
AI Can Help Challenge Rationalizations
AI can be useful as a structured challenge tool.
Using an organization's approved AI environment and properly protected information, an auditor could ask:
“Management states that the control cannot be performed because the department is understaffed. Identify alternative controls that could mitigate the risk without adding staff.”
Or:
“Identify the assumptions contained in management's explanation.”
Or:
“What additional evidence would help determine whether this is an isolated exception or a systemic control problem?”
Or:
“Develop five follow-up questions using the S.P.I.N. methodology to explore management's explanation.”
This is a better use of AI than simply asking it to write the finding.
Use AI to help challenge the thinking behind the finding.
Turn Rationalization Into Root-Cause Analysis
When management says:
“There is a good reason we do it this way,”
the auditor should not immediately respond:
“That's unacceptable.”
Instead ask:
“Why is this workaround necessary?”
Then continue.
Why?
Why again?
What creates that condition?
What would have to change?
Eventually the auditor may move from:
Condition: Required approvals are bypassed.
to:
Rationalization: Employees must bypass them to meet deadlines.
to:
Root Cause: The approval process is dependent upon one manager who is frequently unavailable.
to:
Corrective Action: Establish formally delegated approval authority through the workflow system.
Now Internal Audit has created value.
A Practical Method for Auditors
When you encounter rationalization, use this sequence:
2. Separate fact from explanation.Establish what actually happened.
3. Identify the rationale.Why does management believe the behavior was reasonable?
4. Determine whether the rationale is valid.There may actually be a legitimate control-design problem.
5. Look for normalization.Is this isolated or routine?
6. Identify incentives and pressures.What encourages employees to bypass the control?
7. Determine management awareness.Who knows about the workaround?
9. Identify the root cause.Why does the organization need the workaround?
10. Develop corrective action addressing the cause—not merely the symptom.
That final point is critical.
Do Not Recommend “Follow the Policy” When the Policy Is the Problem
Sometimes Internal Audit's recommendation is:
“Employees should comply with company policy.”
That is appropriate when employees simply fail to follow a reasonable control.
But suppose everyone bypasses the policy because the required procedure is operationally impossible.
The auditor should consider whether the real recommendation is:
Redesign the control.
A control that cannot function in the real operating environment may be a poorly designed control.
That is fundamentally different from a well-designed control that employees occasionally fail to perform.
Advanced auditors understand the difference between:
Design effectiveness
and
Operating effectiveness.
Rationalization can help reveal which problem exists.
The Bigger Governance Question
When rationalization becomes widespread, Internal Audit should consider whether the organization has a broader cultural issue.
Ask:
Does this organization tolerate control circumvention when achieving operational objectives becomes difficult?
If the answer is yes, the issue may extend beyond one process.
The Audit Committee and executive management should care because normalization of control overrides can affect:
Financial reporting
Fraud risk
Regulatory compliance
Cybersecurity
Procurement
Payroll
Expense reimbursement
Data privacy
A culture that says:
“Get the result first and worry about the control later”
can eventually produce serious consequences.
The Bottom Line
Denial tells the auditor:
“There isn't a problem.”
Rationalization tells the auditor:
“There is a problem, but there is a good reason for it.”
That makes rationalization particularly important.
The auditor should not automatically dismiss management's explanation.
Listen to it.
It may reveal:
Pressure.
Incentives.
Control-design problems.
Resource constraints.
Management override.
Cultural weaknesses.
The root cause of the finding.
But the auditor should also remember:
A good explanation for a control failure does not make the resulting risk disappear.
The internal auditor's job is to move the conversation beyond:
“Why we had to do it.”
and toward:
“How can we accomplish the business objective without accepting an unnecessary level of risk?”
That is where Internal Audit stops merely identifying exceptions and begins helping the organization improve.
The Five Human Behavior Problems Internal Auditors Must Overcome
This is Part Two of our series:
1. Denial — “We don't have a problem.”
2. Rationalization — “There is a good reason we do it this way.”
3. Defensiveness and Ego — “You're criticizing me.”
4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”
5. Resistance to Change — “We've always done it this way.”
Understanding these behaviors should be part of every internal auditor's professional toolkit because the strongest audit methodology in the world will accomplish very little if the auditor cannot effectively work with the human beings operating the controls.
Comments