Civilisation will end not with a bang, but with Attachment B

Business performance monitoring concept, businessman using smartphone Online survey filling out, digital form checklist, blue background. Image iStock itThapana Onphalai

From hospitals and universities to IT systems, the machinery of compliance meant to reduce risk is increasingly swallowing the work it was designed to support.

Somewhere in the near future, our civilisation will collapse not from war, famine, or asteroid impact, but from a Change Management Framework Checklist. Future archaeologists will not find our ruins buried beneath ash. They will find them secreted away under Attachment B, Schedule 4, Version 12 (Track Changes Enabled), and conclude, correctly, that we all died waiting for sign-off.

We once built cathedrals in a single generation. Now it takes a generation just to approve the risk assessment. Somewhere between “let’s do something” and “the thing gets done”, an entire shadow society has emerged whose sole purpose is to ensure nobody ever quite does the thing. And to produce, in v.82, a record to demonstrate that due diligence was exercised in the not-doing.

The hospital cured of common sense

Take the modern hospital, an institution so committed to patient safety that it has become saturated with documentation about it. Somewhere in every hospital sits a swathe of clinical guidelines each running to roughly 200 pages, most of which exist to protect the hospital from the two-hundred-and-first page, which is the one where someone got sued. Alongside those is an eye-watering range of policies and procedures. To administer a paracetamol tablet now requires everyone to have done the training module, a competency framework, a checklist, a double-sign-off, a barcode scan, and should the patient so much as sneeze afterwards, an incident report describing the sneeze in a structured taxonomy of harm severity (Category 3: Moderate atmospheric disturbance, patient induced).

The great irony of clinical governance is that the guidelines and policies meant to reduce risk have become a risk in themselves. Nobody has read all 200 pages, let alone the more than 2,000 policies with accompanying standard operational procedures. But everybody has signed to say they have, and the actual clinical wisdom of the ward – which boils down to four steps: “watch the patient, use your judgement, do something if needed, call someone senior if it looks bad” – survives underground, whispered nurse to nurse like a folk remedy.

The university’s policy for policy policies

Universities, meanwhile, have achieved something remarkable: they have out-bureaucratised the hospitals. This is an institution, not so long ago, whose entire purpose was the free exchange of ideas. Somewhere on every campus sits a pro vice-chancellor (Compliance, Assurance, Policy Opportunity Enhancement and Strategic Risk), a title with more syllables than most PhD theses, whose office produces the “Policy on Policies”. That’s a document explaining how future policies must be formatted, consulted upon, reviewed, and endorsed by a committee of 30 faculty professors. And if one professor is away sick and another is overseas, it is, as they quaintly say, “inquorate”.

To hire a casual tutor now requires a position description, a merit-based selection panel, an equity checklist, a probity declaration, and sign-off from someone who has never met the tutor and never will. The tutor must then be onboarded and complete 17 learning modules covering everything from student risk and human ethics to software installation, classroom etiquette, plagiarism detection, and the unforgettable Five-step plan for contributing to a positive culture.

Meanwhile, academics, the theoretical custodians of critical thinking, spend so much of their week filling in forms attesting to their critical thinking that little time remains to do any.

The ethics committee needs a review

Nowhere has bureaucracy achieved a purer form than in the university research ethics committee, established to protect human subjects from harm but now largely devoted to protecting itself from audit. To ask 12 consenting adults whether they prefer tea or coffee before a focus group, a researcher must produce a protocol, risk assessment (categorising the tea-versus-coffee question by likelihood and consequence of harm), a participant information sheet longer than the survey itself, data management plan, and consent form warning that participation is not entirely risk-free. This being, admittedly, the most evidence-based claim in the document.

12 weeks, and five committee meetings later, approval arrives, subject to amendments governing the storage of anonymised tea preferences for seven years, in case anyone ever needs to know who requested Earl Grey.

The IT upgrade eclipsed by legalese

As if it couldn’t get any worse, there’s the IT upgrade, a project in which the terms-of-service riders, licensing schedules, data-sovereignty addenda, and change-advisory-board minutes will, by volume, exceed the code itself by several hundred times. Nobody has read the end-user licence agreement since Bill Clinton was president. We click “I Agree” the way medieval peasants made the sign of the cross: quickly, sincerely, and with no real understanding of what we have just agreed to. Somewhere, a vendor’s legal team has spent longer drafting the liability-limitation clause than the engineers spent writing the software it protects.

A modest proposal

It’s time for a solution. The obvious one is a taskforce to cut red tape. This would need to submit a charter, a terms of reference, a stakeholder consultation plan, and a risk register identifying “excessive process” as a risk to be managed through the establishment of a Red Tape Reduction Steering Committee (the RTRSC). It would meet quarterly, produce minutes, and eventually recommend the formation of a working group. But not before commissioning itself a logo. After all, every committee as important as the RTRSC needs more than just a plan, it needs a brand.

This is not a design flaw. It is the system working exactly as intended, if the intention was never efficiency but plausible deniability in a world so thoroughly papered over that no single human can ever quite be blamed for anything. Because everyone is, after all, just following the guideline, the policy, the protocol, and the terms and conditions, which somebody, somewhere, definitely read.

Future civilisations may marvel that we built the internet, sequenced the genome, and put a rover on Mars, only to bury ourselves a few decades later beneath a digital nightmare of our own design, sustained largely by our willingness to put up with it.

Our society will not end with a bang, but with a form (Attachment B, Schedule 4, Version 12 (Track Changes Enabled)), filled out correctly, filed in multiple MS Teams and Dropbox folders, then never read again.

Jeffrey Braithwaite

Jeffrey Braithwaite is Founding Director of the Australian Institute of Health Innovation, Macquarie University. He is an international member of the World Health Organisation Global Patient Safety Network. He publishes in the leading health and medical research journals and expresses his work at a unique intersection of organisational studies, health services research, and clinical care.