Failure mechanisms of internal governance controls
Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Internal governance controls become bureaucratic overhead when their intensity is no longer discriminatingly aligned to transaction hazard, because costly approvals, reviews, or documentation then remain attached to low-specificity or routine work after the coordination problem they once solved has changedWilliamson (1991)Mitchell (2026)Mitchell (2026)
- Proxy-target substitution is a distinct governance failure mechanism, because once a reported measure becomes the success target, managers can improve the metric while weakening the underlying control objective, as shown conceptually by Goodhart's proxy-target principle and concretely by Silicon Valley Bank's changed risk assumptionsGoodhart (1984)Guestrin (2019)Board (2023)
- Informal circumvention emerges from workflow hindrances, design flaws, and organisational pressures rather than from isolated bad actors, and the workaround literature shows that staff reroute around formal controls when the formal path blocks immediate task completion or patient or service goalsAlter (2014)Authority (2017)Clark et al. (2025)
- The enabling-versus-coercive distinction explains why some formalisation remains productive while other formalisation invites circumvention, because rules that help workers resolve exceptions and use reliable information support performance, whereas repetitive low-signal checkpoints mainly enforce ritual complianceBorys (1996)Clark et al. (2025)Mitchell (2026)
- Recent regulated-banking cases show that active control failure is visible through board information gaps, controls lagging growth, persistent data-quality weaknesses, and repeated remediation or compensating-control programs that remain open without closing the underlying design problemBoard (2023)Currency (2024)Board (2024)
- Shadow records and copied downstream artifacts form one documented circumvention surface in regulated workflows because they let local teams complete the work faster while severing authoritative-source control, complete audit evidence, governed change, and part of the organisation's operational resilienceMitchell (2026)Alter (2014)Authority (2017)
- In high-volume human-in-the-loop review, especially bank-compliance review, queue depth, review latency, very low disagreement, and very low effective override are measurable signs that the checkpoint still exists on paper but no longer contributes meaningful scrutinyMitchell (2026)Mitchell (2026)
- A practical early-warning bundle combines persistent remediation misses, management-information gaps, compensating-control dependence, duplicate reconciliations, shadow records, queue metrics, and unexplained proxy-metric improvement without matching reduction in the underlying hazardBoard (2023)Currency (2024)Board (2024)Mitchell (2026)Mitchell (2026)
Research Question
Through what mechanisms do internal governance controls in regulated enterprises transition from coordination cost minimisers to sources of bureaucratic inefficiency and informal circumvention, and what observable signals indicate each failure mode is active?
Findings
Executive Summary
Internal governance controls in regulated enterprises turn from coordination aids into bureaucracy when their administrative burden, proxy metrics, and approval rituals grow faster than their ability to improve the underlying risk decision, so staff and managers shift effort into workarounds, shadow processes, or nominal review.
The supported mechanisms include control misalignment to transaction hazard, path-dependent persistence of old controls, proxy-target substitution, coercive rather than enabling formalisation, and weak management information or compensating controls that hide the real state of the system.
A recurring circumvention pattern is practical rerouting, including shadow records, duplicate manual reconciliation, queue-clearing without meaningful challenge, and local workarounds that solve the task while quietly weakening the formal control surface.
A practical early-warning bundle therefore combines repeated remediation misses, persistent data-quality or compensating-control weakness, board or management information gaps, shadow records, duplicate reconciliations, queue depth, review latency, and implausibly low disagreement or override in high-volume review environments.
Key Findings
- Internal governance controls become bureaucratic overhead when their intensity is no longer discriminatingly aligned to transaction hazard, because costly approvals, reviews, or documentation then remain attached to low-specificity or routine work after the coordination problem they once solved has changed.
- Proxy-target substitution is a distinct governance failure mechanism, because once a reported measure becomes the success target, managers can improve the metric while weakening the underlying control objective, as shown conceptually by Goodhart's proxy-target principle and concretely by Silicon Valley Bank's changed risk assumptions.
- Informal circumvention emerges from workflow hindrances, design flaws, and organisational pressures rather than from isolated bad actors, and the workaround literature shows that staff reroute around formal controls when the formal path blocks immediate task completion or patient or service goals.
- The enabling-versus-coercive distinction explains why some formalisation remains productive while other formalisation invites circumvention, because rules that help workers resolve exceptions and use reliable information support performance, whereas repetitive low-signal checkpoints mainly enforce ritual compliance.
- Recent regulated-banking cases show that active control failure is visible through board information gaps, controls lagging growth, persistent data-quality weaknesses, and repeated remediation or compensating-control programs that remain open without closing the underlying design problem.
- Shadow records and copied downstream artifacts form one documented circumvention surface in regulated workflows because they let local teams complete the work faster while severing authoritative-source control, complete audit evidence, governed change, and part of the organisation's operational resilience.
- In high-volume human-in-the-loop review, especially bank-compliance review, queue depth, review latency, very low disagreement, and very low effective override are measurable signs that the checkpoint still exists on paper but no longer contributes meaningful scrutiny.
- A practical early-warning bundle combines persistent remediation misses, management-information gaps, compensating-control dependence, duplicate reconciliations, shadow records, queue metrics, and unexplained proxy-metric improvement without matching reduction in the underlying hazard.
Assumptions
- The prior completed items used here restate the Coase-Williamson boundary logic accurately enough to scaffold this item where direct access to Williamson's 1985 book was incomplete.
- The workaround mechanisms documented in regulated healthcare transfer cautiously to other regulated enterprises because the common mechanism is rule-constrained work under delivery pressure rather than sector-specific clinical content.
Analysis
The evidence supports a mechanism chain rather than a single cause. Controls first misalign to the transaction or survive past their useful context, then proxy metrics and formal checkpoints keep signalling compliance even as the work becomes slower or less informative.
Staff and managers respond to that misfit pragmatically. They create workarounds, shadow records, or queue-clearing routines that preserve local throughput while weakening authoritative data, challenge quality, or auditability.
Recent banking cases matter because they show the same pattern under direct supervisory scrutiny: weak board information, controls lagging growth, repeated remediation, and insufficient compensating controls. These signals show that the governance surface is no longer reliably transmitting the real state of risk to decision makers.
Alternative explanations such as temporary under-staffing or weak model quality remain relevant, but the evidence here supports a broader governance diagnosis because the recurring failures include ownership, information quality, remediation discipline, and control design, not only capacity or tool performance.
Risks, Gaps, and Uncertainties
- The regulated-enterprise case layer in this item is strongest for banking, so sector transfer to insurance, energy, or pharmaceuticals is reasonable but not equally evidenced here.
- The circumvention mechanism is well evidenced, but the exact rate at which local workarounds spread into organisation-wide shadow systems remains under-measured in public literature.
- The proxy-target mechanism is clear, but this item does not establish one numeric threshold at which metric optimisation becomes visibly harmful in every control setting.
- Direct extraction from three seeded sources, Williamson (1985), Power (1997), and the Parliamentary Commission report, was incomplete in this session.
Open Questions
- Which public supervisory datasets could support a more quantitative early-warning model for remediation persistence, management-information weakness, and compensating-control dependence across banks?
- Under what conditions do local workarounds remain a bounded adaptation rather than spreading into a shadow operating model that management can no longer fully see?
- Which proxy measures in internal governance are most vulnerable to Goodhart-style distortion, and what paired counter-metrics best reveal the distortion early?
sources
- [ ] Williamson (1985) The Economic Institutions of Capitalism - seed primary source, official library record identified after the seeded Internet Archive URL returned no usable copy in this session
- [x] North (1990) Institutions, Institutional Change and Economic Performance - consulted Cambridge book page and summary
- [x] Goodhart (1984) Problems of Monetary Management: The UK Experience - consulted DOI landing page and chapter metadata
- [ ] Power (1997) The Audit Society: Rituals of Verification - official Oxford University Press page identified, but no clean extractable text was obtained in this session
- [ ] Crozier (1964) The Bureaucratic Phenomenon - official University of Chicago Press page identified; not directly consulted for claims in this item
- [ ] UK Parliamentary Commission on Banking Standards (2013) Changing Banking for Good - official report identified, but direct extraction was not successful in this session
- [x] Williamson (1991) Comparative Economic Organization: The Analysis of Discrete Structural Alternatives, working paper version - consulted accessible working paper copy
- [x] Alter (2014) Theory of Workarounds - consulted abstract on the Association for Information Systems library page
- [x] Adler and Borys (1996) Two Types of Bureaucracy: Enabling and Coercive - consulted authoritative abstract text via search result and official article record
- [x] Fire and Guestrin (2019) Over-optimization of academic publishing metrics: observing Goodhart's Law in action - consulted open-access article for the proxy-target mechanism
- [x] Pennsylvania Patient Safety Authority (2017) Workarounds: Trash or Treasure? - consulted official advisory
- [x] Clark et al. (2025) Do healthcare professionals work around safety standards, and should we be worried? - consulted open-access scoping review
- [x] Federal Reserve Board (2023) Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank - consulted via local Portable Document Format extraction
- [x] Office of the Comptroller of the Currency (2024) OCC Amends Enforcement Action Against Citibank, Assesses $75 Million Civil Money Penalty - consulted official news release
- [x] Federal Reserve Board (2024) Federal Reserve Board fines Citigroup $60.6 million for violating the Board's 2020 enforcement action - consulted official enforcement release
- [x] Mitchell (2026) Transaction Cost Economics: foundations and speculative integration with Software Engineering, Artificial Intelligence, knowledge management, and context engineering - consulted prior completed item
- [x] Mitchell (2026) The Nature of the Firm: why organisations exist, their fitness functions, and invariants - consulted prior completed item
- [x] Mitchell (2026) Conditions under which internal governance controls minimise coordination costs in regulated enterprises - consulted adjacent completed item
- [x] Mitchell (2026) How should human-in-the-loop design be adapted when AI review volume makes human reviewers a bottleneck or causes rubber-stamping? - consulted prior completed item
- [x] Mitchell (2026) At what threshold does Human-in-the-Loop oversight in bank compliance operations stop being a meaningful challenge function and become routine acceptance of automated outputs? - consulted adjacent completed item
- [x] Mitchell (2026) Control deficiencies from bypassing designated workforce record platforms - consulted prior completed item
- [x] Mitchell (2026) How should decision rights, accountability, and liability be structured for Artificial Intelligence systems and low-code applications in enterprise environments? - consulted prior completed item
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-23 | 5fdc53d | Initial completion |