Good Strategy, Bad Strategy: Why Most Regulated Organisations Have a Wish List, Not a Strategy
Most “strategies” inside regulated organisations aren’t strategies. They’re ambition dressed up as a plan. This draws on Richard Rumelt’s Good Strategy/Bad Strategy, the clearest account we know of the difference, and what a real one looks like once you apply it to delivery in a regulated environment.
Bad strategy is easy to spot once you know what to look for. It reads like a mission statement: ambitious, confident, and completely disconnected from what's actually stopping the organisation. Rumelt's argument, stripped down, is that this happens in three specific, recognisable ways, and that most organisations do at least one of them without noticing.
Fluff
A restatement of the obvious, dressed up in language that sounds like insight. “Leverage our core competencies to unlock stakeholder value” says nothing that could be argued with, because it says nothing at all. If a sentence would still be true with every noun swapped for a competitor's, it isn't strategy.
Failure to face the challenge
If nobody can name the actual obstacle, nobody can judge whether the plan addresses it, including the people who wrote it. Bad strategy skips straight from ambition to action and leaves out the one thing that would let anyone evaluate it: what, specifically, is standing in the way.
Mistaking goals for strategy
“Become the market leader” or “grow 20% this year” is a wish, not a strategy. A strategy is the specific approach for getting there given the obstacle in front of you. Ambition answers “what do we want”. Strategy answers “how, given what's actually stopping us”. Only one of those is useful on a Monday morning.
A specific failure mode of goal-setting
Two ways a goals list quietly becomes bad strategy.
Even organisations that know better than to write pure fluff often fall into one of these when they turn ambition into a list of objectives.
Blue-sky objectives
A list of good, desirable things (“improve customer satisfaction”, “be more innovative”) with no diagnosis behind any of them. They're not wrong. They're just not connected to a specific obstacle, so nobody can say whether pursuing them will fix anything.
Dog's dinner objectives
A long list of goals piled on top of each other with no ranking. It usually means nobody was willing to make the hard call about what actually matters most, so everything got kept in and nothing got prioritised.
The kernel
Every good strategy has the same three-part structure underneath it.
Rumelt calls this the kernel. Strip away the deck, the branding, and the mission-statement language, and a good strategy is always these three things, in this order.
Diagnosis
What's actually stopping you. Not the symptom (“delivery is slow”) but the mechanism (“every change touches a shared database three teams depend on, so nothing ships without a cross-team sign-off that takes weeks”). A real diagnosis is specific enough that someone could disagree with it.
Guiding policy
Given that diagnosis, your overall approach. Not a target, an approach. “We split the shared database along team boundaries before we build anything new on top of it” is a guiding policy. “We will be more agile” is not.
Coherent action
The specific, coordinated moves that carry out the guiding policy: resourced, sequenced, and consistent with each other. A roadmap with fourteen initiatives, half of which contradict the other half, is a backlog, not coherent action.
Worked example
A goal vs. a kernel, on the same real problem.
As a goal
“Modernise the architecture.”
As a kernel
A native API and Kafka topic per chain had accumulated over years. Nobody had audited which were still used, so every change was made defensively, assuming everything mattered.
Audit real usage first, then rebuild around two extensible APIs, one UTXO and one EVM, instead of one per chain.
A phased cutover with zero service interruption, not a big-bang rewrite.
Result: £1.2M in annual infrastructure cost optimisation, and more importantly, a codebase where the next change doesn't require defensive assumptions. Read the case study.
Where the power actually comes from
A kernel is the structure. These are what make it work.
Rumelt calls these sources of power: the specific mechanisms a coherent strategy exploits. Four of them come up constantly in regulated, legacy-heavy environments.
Chain-link logic
A system is only as strong as its weakest link, not its average. Improving the parts that already work well adds nothing if one specific link is what's actually holding the whole thing back. Good strategy finds that link before spending anywhere else.
Proximate objectives
A target close enough, under real uncertainty, to actually be achievable and to tell people what to do next. Distant, vague goals (“transform the business”) don't give anyone a next move. A proximate objective does.
Focus
Concentrating effort on the objective that matters most, instead of spreading it evenly across everything on the list. Most organisations already know this. Almost none of them do it, because saying no to the other eleven initiatives is the hard part.
Inertia and entropy
Organisations resist changing established ways of working (inertia), and left alone, coordination between teams quietly decays over time (entropy). A strategy that doesn't name which of these it's actually fighting usually isn't fighting either.
Bad strategy usually contains:
- A list of goals with no stated mechanism between them
- Language that could apply to any company in any industry
- No named obstacle, or one that's unfalsifiable (“the market”, “legacy”, “culture”)
- Everything prioritised, which means nothing is
Good strategy usually contains:
- A diagnosis specific enough to be wrong
- One guiding policy you could explain to a new hire in two sentences
- A short list of actions that reinforce each other, not a long list that don't
- A named weakest link, and resourcing that actually reflects it
Why this matters more, not less, in regulated organisations
Governance and compliance are real constraints, but they're also the easiest place to hide from a hard diagnosis. “We can't move faster because of regulation” is often true and also often the wrong diagnosis. The actual obstacle is usually that risk, engineering, and the business have never agreed what “acceptable” looks like for a given class of change, so every change gets treated as the hardest case. That's a fixable, specific problem. “Regulation” is not something you fix. It's something you stop hiding behind.
Have a goals list, not a strategy?
We don't arrive with a template strategy deck. We arrive and ask what's actually stopping you, then help you build the guiding policy and the coherent actions that follow from it.