Failure mechanisms of internal governance controls

Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises

2026-05-23 · governance-policy organisational-design regulatory-compliance cost-performance enterprise-adoption · medium · source → · wiki →
key claims
  1. Internal governance controls become bureaucratic overhead when their intensity is no longer discriminatingly aligned to transaction hazard, because costly approvals, reviews, or documentation then remain attached to low-specificity or routine work after the coordination problem they once solved has changedWilliamson (1991)Mitchell (2026)Mitchell (2026)
  2. Proxy-target substitution is a distinct governance failure mechanism, because once a reported measure becomes the success target, managers can improve the metric while weakening the underlying control objective, as shown conceptually by Goodhart's proxy-target principle and concretely by Silicon Valley Bank's changed risk assumptionsGoodhart (1984)Guestrin (2019)Board (2023)
  3. Informal circumvention emerges from workflow hindrances, design flaws, and organisational pressures rather than from isolated bad actors, and the workaround literature shows that staff reroute around formal controls when the formal path blocks immediate task completion or patient or service goalsAlter (2014)Authority (2017)Clark et al. (2025)
  4. The enabling-versus-coercive distinction explains why some formalisation remains productive while other formalisation invites circumvention, because rules that help workers resolve exceptions and use reliable information support performance, whereas repetitive low-signal checkpoints mainly enforce ritual complianceBorys (1996)Clark et al. (2025)Mitchell (2026)
  5. Recent regulated-banking cases show that active control failure is visible through board information gaps, controls lagging growth, persistent data-quality weaknesses, and repeated remediation or compensating-control programs that remain open without closing the underlying design problemBoard (2023)Currency (2024)Board (2024)
  6. Shadow records and copied downstream artifacts form one documented circumvention surface in regulated workflows because they let local teams complete the work faster while severing authoritative-source control, complete audit evidence, governed change, and part of the organisation's operational resilienceMitchell (2026)Alter (2014)Authority (2017)
  7. In high-volume human-in-the-loop review, especially bank-compliance review, queue depth, review latency, very low disagreement, and very low effective override are measurable signs that the checkpoint still exists on paper but no longer contributes meaningful scrutinyMitchell (2026)Mitchell (2026)
  8. A practical early-warning bundle combines persistent remediation misses, management-information gaps, compensating-control dependence, duplicate reconciliations, shadow records, queue metrics, and unexplained proxy-metric improvement without matching reduction in the underlying hazardBoard (2023)Currency (2024)Board (2024)Mitchell (2026)Mitchell (2026)

Research Question

Through what mechanisms do internal governance controls in regulated enterprises transition from coordination cost minimisers to sources of bureaucratic inefficiency and informal circumvention, and what observable signals indicate each failure mode is active?

Findings

Executive Summary

Internal governance controls in regulated enterprises turn from coordination aids into bureaucracy when their administrative burden, proxy metrics, and approval rituals grow faster than their ability to improve the underlying risk decision, so staff and managers shift effort into workarounds, shadow processes, or nominal review.

The supported mechanisms include control misalignment to transaction hazard, path-dependent persistence of old controls, proxy-target substitution, coercive rather than enabling formalisation, and weak management information or compensating controls that hide the real state of the system.

A recurring circumvention pattern is practical rerouting, including shadow records, duplicate manual reconciliation, queue-clearing without meaningful challenge, and local workarounds that solve the task while quietly weakening the formal control surface.

A practical early-warning bundle therefore combines repeated remediation misses, persistent data-quality or compensating-control weakness, board or management information gaps, shadow records, duplicate reconciliations, queue depth, review latency, and implausibly low disagreement or override in high-volume review environments.

Key Findings

  1. Internal governance controls become bureaucratic overhead when their intensity is no longer discriminatingly aligned to transaction hazard, because costly approvals, reviews, or documentation then remain attached to low-specificity or routine work after the coordination problem they once solved has changed.
  2. Proxy-target substitution is a distinct governance failure mechanism, because once a reported measure becomes the success target, managers can improve the metric while weakening the underlying control objective, as shown conceptually by Goodhart's proxy-target principle and concretely by Silicon Valley Bank's changed risk assumptions.
  3. Informal circumvention emerges from workflow hindrances, design flaws, and organisational pressures rather than from isolated bad actors, and the workaround literature shows that staff reroute around formal controls when the formal path blocks immediate task completion or patient or service goals.
  4. The enabling-versus-coercive distinction explains why some formalisation remains productive while other formalisation invites circumvention, because rules that help workers resolve exceptions and use reliable information support performance, whereas repetitive low-signal checkpoints mainly enforce ritual compliance.
  5. Recent regulated-banking cases show that active control failure is visible through board information gaps, controls lagging growth, persistent data-quality weaknesses, and repeated remediation or compensating-control programs that remain open without closing the underlying design problem.
  6. Shadow records and copied downstream artifacts form one documented circumvention surface in regulated workflows because they let local teams complete the work faster while severing authoritative-source control, complete audit evidence, governed change, and part of the organisation's operational resilience.
  7. In high-volume human-in-the-loop review, especially bank-compliance review, queue depth, review latency, very low disagreement, and very low effective override are measurable signs that the checkpoint still exists on paper but no longer contributes meaningful scrutiny.
  8. A practical early-warning bundle combines persistent remediation misses, management-information gaps, compensating-control dependence, duplicate reconciliations, shadow records, queue metrics, and unexplained proxy-metric improvement without matching reduction in the underlying hazard.

Assumptions

Analysis

The evidence supports a mechanism chain rather than a single cause. Controls first misalign to the transaction or survive past their useful context, then proxy metrics and formal checkpoints keep signalling compliance even as the work becomes slower or less informative.

Staff and managers respond to that misfit pragmatically. They create workarounds, shadow records, or queue-clearing routines that preserve local throughput while weakening authoritative data, challenge quality, or auditability.

Recent banking cases matter because they show the same pattern under direct supervisory scrutiny: weak board information, controls lagging growth, repeated remediation, and insufficient compensating controls. These signals show that the governance surface is no longer reliably transmitting the real state of risk to decision makers.

Alternative explanations such as temporary under-staffing or weak model quality remain relevant, but the evidence here supports a broader governance diagnosis because the recurring failures include ownership, information quality, remediation discipline, and control design, not only capacity or tool performance.

Risks, Gaps, and Uncertainties

Open Questions


sources

cites
cites Transaction Cost Economics: foundations and speculative integration with SWE, AI, knowledge management, and context engineering
cites The Nature of the Firm: why organisations exist, their fitness functions, and invariants
cites Conditions under which internal governance controls minimise coordination costs in regulated enterprises
cites How should human-in-the-loop (HITL) design be adapted when AI review volume makes human reviewers a bottleneck or causes rubber-stamping?
cites At what threshold does Human-in-the-Loop (HITL) oversight in bank compliance operations stop being a meaningful challenge function and become routine acceptance of automated outputs?
cites Control deficiencies from bypassing designated workforce record platforms
cites How should decision rights, accountability, and liability be structured for Artificial Intelligence (AI) systems and low-code applications in enterprise environments?
related (frontmatter)
related What tiered human oversight models maintain meaningful human-in-the-loop (HITL) control at scale under high-volume multi-step Artificial Intelligence (AI) adoption, and how should organisations measure oversight quality when productivity mandates exist without explicit quality Key Performance Indicators (KPIs)?
related Overlapping and Absent Accountability at Strategic and IT Layers: Empirically Observed Organisational Failure Modes
related How Do Formal Governance Structures Distort Cross-Department Knowledge Flows?
version history
versiondatecommitsummary
1.02026-05-235fdc53dInitial completion

Connected items

Loading…

View full knowledge graph →