Conditions under which internal governance controls minimise coordination costs…

Conditions under which internal governance controls minimise coordination costs in regulated enterprises

2026-05-23 · governance-policy organisational-design regulatory-compliance cost-performance enterprise-adoption · medium · source → · wiki →
key claims
  1. Internal governance controls are most likely to minimise coordination cost when they are reserved for transactions with high relationship-specific investment, also called asset specificity, meaning investments that lose value outside the focal relationship, high uncertainty, or high consequence, because those are the cases where contracting failure, hold-up risk, or costly error correction make tighter hierarchy economically justifiedWilliamson (1991)Mitchell (2026)
  2. Banking supervisory guidance requires control intensity to be proportionate to the institution's size, complexity, risk profile, and business model in both governance design and periodic reviewSettlements (2015)Authority (2021)
  3. Banking supervisory guidance also requires responsibilities, authority, and reporting lines to be clearly allocated across business lines, management, and control functions throughout the governance frameworkSettlements (2015)Authority (2021)Mitchell (2026)
  4. Banking supervisory guidance requires periodic review of governance arrangements and reassessment after material change, making review cadence a direct design condition for internal controls in regulated firmsSettlements (2015)Authority (2021)
  5. Controls are enabling rather than coercive when they help staff solve exceptions with authoritative information and intelligible authority, whereas controls that mainly add surveillance, repetitive approval, or low-signal checkpoints tend to create resistance and bureaucratic dragBorys (1996)Settlements (2015)Europa (n.d.)
  6. High-volume line-by-line review is one of the clearest points where a control flips from coordination aid to overhead, because queue growth, latency, and very low effective disagreement or override indicate that nominal review is no longer producing meaningful challengeMitchell (2026)Mitchell (2026)
  7. Adjacent evidence from workforce-record control failures shows that when copied spreadsheets, presentations, or downstream artifacts become the working record, organisations lose authoritative-source control, complete audit evidence, governed change, and part of operational resilienceMitchell (2026)
  8. A practical governance-effectiveness diagnostic is whether a control has a named risk owner, a clear escalation path, authoritative inputs, proportionate trigger conditions, and a scheduled or event-driven review path, because missing any of these shifts the burden from risk reduction toward coordination overheadSettlements (2015)Europa (n.d.)Mitchell (2026)Mitchell (2026)

Research Question

Under what institutional and transaction-specific conditions do internal governance controls in regulated enterprises function as genuine minimisers of coordination costs rather than sources of bureaucratic overhead, and what distinguishes the design features that make them effective?

Findings

Executive Summary

Internal governance controls in regulated enterprises minimise coordination costs only when they are discriminatingly aligned to high-hazard transactions and designed as enabling coordination devices rather than blanket approval rituals.

The most consistently supported design features are proportionality to risk and complexity, clear ownership and authority, authoritative data inputs, and periodic review that removes or redesigns controls after material change.

Controls become bureaucratic overhead when they are applied uniformly to low-specificity or high-volume work, require duplicate data handling, or preserve nominal review after meaningful challenge capacity has collapsed.

The practical test is whether a control lowers rework, bargaining, and error-correction cost at the transaction level while still preserving accountable ownership and escalation for exceptions.

Key Findings

  1. Internal governance controls are most likely to minimise coordination cost when they are reserved for transactions with high relationship-specific investment, also called asset specificity, meaning investments that lose value outside the focal relationship, high uncertainty, or high consequence, because those are the cases where contracting failure, hold-up risk, or costly error correction make tighter hierarchy economically justified.
  2. Banking supervisory guidance requires control intensity to be proportionate to the institution's size, complexity, risk profile, and business model in both governance design and periodic review.
  3. Banking supervisory guidance also requires responsibilities, authority, and reporting lines to be clearly allocated across business lines, management, and control functions throughout the governance framework.
  4. Banking supervisory guidance requires periodic review of governance arrangements and reassessment after material change, making review cadence a direct design condition for internal controls in regulated firms.
  5. Controls are enabling rather than coercive when they help staff solve exceptions with authoritative information and intelligible authority, whereas controls that mainly add surveillance, repetitive approval, or low-signal checkpoints tend to create resistance and bureaucratic drag.
  6. High-volume line-by-line review is one of the clearest points where a control flips from coordination aid to overhead, because queue growth, latency, and very low effective disagreement or override indicate that nominal review is no longer producing meaningful challenge.
  7. Adjacent evidence from workforce-record control failures shows that when copied spreadsheets, presentations, or downstream artifacts become the working record, organisations lose authoritative-source control, complete audit evidence, governed change, and part of operational resilience.
  8. A practical governance-effectiveness diagnostic is whether a control has a named risk owner, a clear escalation path, authoritative inputs, proportionate trigger conditions, and a scheduled or event-driven review path, because missing any of these shifts the burden from risk reduction toward coordination overhead.

Assumptions

Analysis

Formalisation alone does not determine whether a control adds value; the decisive question is whether the control changes coordination work in a cost-saving direction for the transaction it governs.

They work when the control form matches the transaction hazard and the institution gives the control a clear owner, authoritative inputs, and a route for exception handling.

The evidence also shows why regulated enterprises so often misfire: once a control is embedded, ordinary organisational inertia and the practical politics of accountability make removal harder than addition, so low-signal approvals and duplicate data pathways accumulate unless review cadence is explicit and empowered.

The most useful operational distinction is therefore between controls that reduce downstream reconciliation and decision uncertainty, and controls that merely move work into review queues, shadow files, or committee routing.

Some overhead also comes from staffing constraints, weak tooling, or externally mandated review steps, but those alternatives reinforce the same diagnostic because a control cannot be treated as coordination-cost-minimising if the surrounding operating model lacks the capacity or automation needed to keep review meaningful.

Risks, Gaps, and Uncertainties

Open Questions


sources


cites
cites Transaction Cost Economics: foundations and speculative integration with SWE, AI, knowledge management, and context engineering
cites The Nature of the Firm: why organisations exist, their fitness functions, and invariants
cites How should human-in-the-loop (HITL) design be adapted when AI review volume makes human reviewers a bottleneck or causes rubber-stamping?
cites Control deficiencies from bypassing designated workforce record platforms
cites How should decision rights, accountability, and liability be structured for Artificial Intelligence (AI) systems and low-code applications in enterprise environments?
related (frontmatter)
related At what threshold does Human-in-the-Loop (HITL) oversight in bank compliance operations stop being a meaningful challenge function and become routine acceptance of automated outputs?
related When and how should human intervention be incorporated into Artificial Intelligence (AI)-driven and automated workflows?
related Knowledge curation governance as an enterprise AI capability in regulated financial institutions
version history
versiondatecommitsummary
1.02026-05-2399c9a4fInitial completion

Connected items

Loading…

View full knowledge graph →