
A pharmaceutical company trained its sales teams for years on how to talk about competitor products. The rule was simple and everyone in the room could recite it: describe your own medicine, stay factual, avoid running down the alternative. Then a representative sat at a keyboard, under a quarterly number, and wrote to doctors that a rival generic “is not the same.” Regulators read that phrase as unlawful disparagement and issued a fine of around EUR 25 million. Nobody in that story failed the training. They passed it, and then they wrote the line anyway.
If you run compliance, legal, or risk, this is the pattern you already suspect. The annual module lands, the completion rate hits 98 percent, the auditor is satisfied, and three weeks later someone types the exact sentence the module warned against. This is general information rather than legal advice, but the mechanism behind it is worth naming precisely, because it tells you where the real catch has to happen.
There are two different rooms in every compliance program. The first is the training room, real or virtual, where the auditor effectively lives. Attention is high, stakes feel abstract, and the person is thinking about policy. The second room is the inbox at 4:58pm on a Thursday, where the deadline lives. Attention is thin, the stakes feel like this one client reply, and the person is thinking about the deal, the fire, the reply-all thread with twelve people on it.
Knowledge sits in the first room. Behaviour happens in the second. The distance between them is where your residual risk actually accumulates, and it is a distance no amount of extra training content closes, because the problem was never a knowledge gap. Adding a fifth module to a program that already has four does very little for the person who was tired and rushing, because tired and rushing was the whole cause.
Consider the everyday phrases people are trained to avoid and write regularly anyway:
Every trained employee knows these are risky in the abstract. The training did its job. What it cannot do is be present in the two seconds between finishing the sentence and pressing send, which is the only moment that decides the outcome.
Training is a stock that leaks. Hermann Ebbinghaus measured the leak more than a century ago: without reinforcement, recall of new material drops sharply within days and keeps falling. A compliance module is subject to the same curve, then made worse by four forces specific to the workplace. Here is the model, and what a nudge at the moment of writing does about each force.
| Force that erodes trained behaviour | Why training alone cannot hold it | What a point-of-writing nudge adds |
|---|---|---|
| Time decay | Recall fades within days of the session; the annual refresh is 11 months too late for most emails. | Reinforcement arrives on the day it matters, on the sentence that matters, not on a calendar. |
| Context gap | Policy is learned as a general rule; the risky sentence appears as a specific, deadline-driven exception the brain does not tag. | The flag fires against the actual words in the actual draft, so the rule is applied in context. |
| Cognitive load | Under deadline pressure, System 1 writes fast and skips the compliance check the training installed. | An external prompt does the noticing the tired writer cannot, without asking them to slow down. |
| No feedback loop | The employee never learns which specific lines were risky, so the same habit repeats. | Each flag is a micro-lesson tied to a real phrase, which is how habits actually change. |
Read the right-hand column as one idea: a nudge at the point of writing turns a once-a-year event into a quiet, continuous correction on the exact words that carry the risk. That is the layer training has always been missing.
VerbaPulse is a pre-send check that runs inside Gmail and Outlook. As someone writes, it flags a risky phrase in the seconds before they hit send, and offers a short, phrase-level rewrite. The point is to catch the careless line a well-intentioned employee simply did not notice, so real output stays tight. For example:
These are small edits, and that is the design. The writer keeps their meaning, loses the exposure, and gets a two-second reminder of a rule they were trained on but had stopped applying under pressure. Do that a few hundred times across a team and the training finally has a place to land every day.
Be clear about the boundary. A pre-send check is a front-end shield against accidental human risk, the well-meaning line written in a hurry. It is not an adversarial security control. It will not stop a determined bad actor who intends to write something improper, and it does not replace your training, your policies, or your supervision.
It also complements the tools you already run rather than competing with them. Archiving and supervision platforms such as Smarsh and Proofpoint capture and review what was sent, which is essential for recordkeeping and lookback. A pre-send nudge sits one step earlier, at the keyboard, so fewer risky messages reach those queues in the first place. The supervision team spends less time reviewing avoidable incidents, and the ones that do surface are more likely to be the genuinely hard cases worth their attention.
Keep the training. It sets the standard and it satisfies the auditor. Then add the layer that training structurally cannot provide: a reminder at the moment of writing, on the specific sentence, in the tools people already use. Measure it the way you would measure any control, by whether the risky phrases actually decline over the following quarter.
If you want to test that claim against your own team’s real email, the 30-day Proof-of-Value Pilot covers up to 10 seats for EUR 120, credited to your plan if you continue. You can see how it works and start on the page for compliance teams.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →