top of page

The Difference Between Necessary Constraints and Unintentional Friction

By: Amaya Watters

June 2026

Many conversations about operational resilience imply that organizations should minimize all dependency on individuals and remove every constraint from a workflow. Those principles are useful in some situations, but they do not apply universally.

As discussed in The Quiet Cost of Key Person Dependency, operational resilience does not mean eliminating every dependency. It means understanding which dependencies create value and which create unnecessary risk.

Some constraints exist for good reasons, such as protecting the organization, the people it serves, and its employees. Others exist simply because a workflow was never intentionally designed. The distinction between the two is fundamental to designing good workflow architecture, particularly in regulated operating environments.

Necessary constraints may include:

  • Specialized expertise required to perform certain work

  • Adhering to regulatory and legal requirements

  • Financial approvals designed to prevent fraud

  • Authentication required to prove identity

  • Compliance reviews

  • Security controls

Unintentional friction may include:

  • Processes that depend on informal workarounds

  • Approvals that exist without clear purpose

  • Information trapped in one person

  • Extra handoffs that add no value

  • Unclear ownership of decisions

Both can slow work down, but they require opposite responses. Removing a necessary constraint creates risk, but removing unnecessary friction creates capacity.

A compliance officer reviewing a high-risk transaction is a necessary control. A compliance officer answering routine questions because policies and workflows are unclear may indicate operational friction.

Expertise Is Not the Problem

Every organization relies on people with specialized education, training, judgment, and experience.

  • A fraud investigator recognizes patterns that indicate potential risk based on years of experience

  • A compliance officer applies regulatory judgment when reviewing complex situations

  • A member or client services professional understands nuanced situations that require experience and discretion

  • A cybersecurity specialist evaluates threats that require specialized technical knowledge

Attempting to eliminate that expertise would reduce the organization's ability to perform specialized work effectively and could introduce safety, quality, legal, compliance, or privacy risks.

When to Be Concerned

Dependency becomes a problem when a person becomes an unnecessary single point of failure. If nobody else within the organization could perform that work if they were unavailable, the dependency creates operational risk.

For example:

  • Only one operations manager can approve routine account exceptions

  • Only one employee understands how a fraud monitoring workflow operates because the process was never documented

  • Employees rely on one KYC specialist to answer recurring policy questions because procedures are unclear

  • Only one employee knows how to resolve unusual client or transaction scenarios because decision criteria were never documented

Experts Should Focus on Expert Work

As organizations grow, experts often become responsible for far more than work that uses their expertise. They may also answer routine questions, explain undocumented processes, approve decisions that don't require their direct judgment, or carry historical context that exists nowhere else.

 

Over time, their capacity is used to compensate for weaknesses in the operating system rather than applying their expertise where it creates the most value. This prevents the organization from using its most valuable resources effectively.

bottom of page