Why Governance Fails When It Treats Complexity Like a Checkbox

Kerry Friend

Hatched by Kerry Friend

May 23, 2026

9 min read

87%

0

The hidden flaw in most oversight

What if the real problem with governance is not weak rules, but the belief that rules alone can produce trust?

That is the uncomfortable tension at the heart of modern institutions. Boards, regulators, and data custodians are often asked to do two things at once: prevent harm and enable action. In practice, they usually choose the easier illusion, which is to create the appearance of control through forms, policies, approvals, and periodic reviews. The result is a system that looks accountable on paper while remaining brittle in reality.

This is why the most interesting shift in governance today is not about adding more oversight. It is about rebuilding governance as a living system, one that can think with complexity instead of pretending complexity can be compressed into a checklist.

The same problem shows up in two places that seem unrelated at first glance: boardrooms and health data platforms. In both settings, the danger is not merely misuse or incompetence. It is the deeper failure to design institutions that can be trusted because they are visible, adaptive, and structurally constrained, not because someone promised they would behave well.


The false comfort of control

Most governance models were built for a world that imagined risk as something linear. If something goes wrong, the assumption goes, find the breach, fix the rule, tighten the process, and the problem is solved. But many of today’s hardest problems are not linear. They are complex adaptive systems, where small decisions ripple unpredictably, incentives shift, and the act of monitoring changes behavior.

A board is not a machine with a few levers. It is more like a weather system. Individual directors may have expertise, but the whole is shaped by feedback loops, blind spots, institutional memory, and the unspoken norms that determine what can be said. When governance is treated as a static compliance exercise, it becomes especially vulnerable to what looks like competence but is actually ritual.

The same pattern appears in data governance. A common response to privacy risk is pseudonymisation, which sounds reassuring because it removes obvious identifiers. But that is only the first layer of defense. In a rich dataset, people can still be re identified through context, pattern matching, and external information. The lesson is stark: privacy is not a label, it is an architecture.

A system is not trustworthy because it says it is careful. It is trustworthy because it is designed so that care is hard to fake.

This is the shared insight behind governance reform and secure research platforms. The real question is not whether institutions can write better rules. It is whether they can create structures where the right behavior becomes the path of least resistance.


From supervision to system design

Traditional governance asks leaders to supervise outcomes from above. But in complex environments, supervision alone is too slow, too distant, and too dependent on individual judgment. The more novel approach is to move from governance as inspection to governance as system design.

That shift sounds abstract until you see what it means in practice. Instead of asking, “Did we follow the policy?” a better question is, “Does the system make misuse visible, make good behavior easy, and make bad behavior expensive?” That question changes everything. It moves governance from morality to mechanics.

Consider a research environment handling sensitive health records. One model says: restrict access, trust a small number of cleared users, and audit occasionally. Another model says: encode the rules into the platform itself, log every action publicly within the secure environment, share code for review, and minimize unnecessary data movement. The second model does not rely on heroic trust. It creates computational accountability.

That phrase matters because it captures a deeper shift in institutional logic. When governance is embedded in software, workflow, and architecture, it no longer depends entirely on human vigilance. Human judgment still matters, but it is supported by constraints, traceability, and transparency by default.

Board governance can learn from this. In many organizations, the board is expected to provide oversight without enough instrumentation. It receives polished reports, curated metrics, and retrospective explanations, then is asked to evaluate whether the organization is well led. That is a weak information environment. It is like trying to diagnose a storm by reading the shipping forecast after the ships have already sunk.

A more enlightened governance model would ask what signals are missing, what kinds of failure are becoming invisible, and what mechanisms could reveal issues earlier. That is the essence of critical systems thinking. Not every problem can be solved by intelligence alone. Some problems require redesigning the sensing and feedback loops that make intelligence useful.


Trust is earned through constraints, not declarations

One of the most counterintuitive lessons from secure analytics is that trust becomes stronger when dependence on trust becomes weaker.

That sounds paradoxical, but it is profoundly practical. Open, reviewable code, public logs, minimal data sharing, and privacy enhancing layers do not eliminate trust. They relocate it. Instead of asking people to trust opaque processes, the system asks them to trust the combination of constraints, visibility, and reviewability.

The same principle applies to governance. A board that depends on charisma, deference, or vague assurances is fragile. A board that depends on disciplined information flows, explicit escalation paths, and independent challenge is stronger. In other words, trustworthy institutions are not those that ask for more trust, but those that need less of it.

This is especially important because institutions tend to overestimate the value of good intentions. Good intentions are real, but they are not enough. In health data, a well meaning analyst can still make an error that reveals something sensitive. In corporate governance, a well meaning executive can still present a distorted picture because incentives reward optimism. In both cases, the system must be designed for fallibility.

Think of an airplane cockpit. Safety does not come from assuming the pilots are saints. It comes from designing layered controls, clear instrumentation, standardized procedures, and redundancy. Nobody mistakes that for bureaucracy when the plane lands safely. Yet many organizations still resist this logic, preferring the myth of agile judgment over the reality of robust design.

The deeper point is that openness and security are not opposites. In well designed systems, they reinforce each other. Transparency can improve security by exposing weak points before they become disasters. Constraint can improve freedom by making participation safer. Governance fails when it treats these tensions as tradeoffs instead of as design problems.


A better model: governance as a three layer stack

If we want institutions that can operate in complexity, we need a more useful mental model than compliance. One promising framework is to think of governance as a three layer stack.

1. The visible layer

This is what people see: policies, reports, board packs, audit trails, public summaries, and formal approvals. It matters, but it is only the surface.

2. The behavioral layer

This is how people actually work: who can access what, how decisions get escalated, what gets measured, what gets ignored, and what incentives quietly shape conduct.

3. The structural layer

This is the deepest layer: software architecture, data permissions, role definitions, reporting pathways, network design, and the rules that determine what is possible in the first place.

Most institutions spend too much time on the visible layer and too little on the structural layer. That is why governance reforms often disappoint. They produce better language without producing better behavior.

A board can ask for more reports, but if the reports are delayed, sanitized, or impossible to verify, the board is still flying blind. A data system can promise privacy, but if identifiers are merely stripped and the dataset remains easily re identifiable, the promise is thin. In both cases, the structure matters more than the statement.

This stack also explains why governance education needs to evolve. Leaders need to understand not only finance, law, and strategy, but also complexity, system dynamics, and information design. The challenge is not simply choosing the right policy. It is understanding how policies interact with systems that adapt to them.

Good governance is less about knowing the answer and more about designing a system that can survive being wrong.

That is a hard standard, but it is the right one for institutions that operate under uncertainty.


What enlightened governance would actually do

If governance is really about making good behavior easier than bad behavior, what does that change in practice?

First, it would prioritize real time visibility over episodic reporting. A board should not only receive summaries of performance. It should have access to the signals that reveal emerging risk, including anomalies, near misses, and areas where information has been filtered too aggressively.

Second, it would treat traceability as a design principle. In data systems, every action should leave a meaningful trail. In organizations, important decisions should be documented in ways that make reasoning auditable, not just outcomes explainable after the fact.

Third, it would build safe disagreement into the process. Complex systems fail when people are afraid to surface bad news. Good governance invites challenge early, before dissent becomes scandal.

Fourth, it would minimize unnecessary concentration of power. When too much depends on a few individuals or a single opaque process, fragility increases. Distributed checks, federated structures, and layered controls create resilience.

Finally, it would recognize that governance is not a department. It is an ecology. Every interface, workflow, approval step, and data boundary communicates what an organization truly values.

A practical example helps. Imagine two organizations handling sensitive data. The first stores records in a central database, grants broad access to a trusted research team, and relies on a periodic audit. The second keeps the data where it already resides, uses secure analytics that minimize movement, logs activity continuously, and allows code to be reviewed and reused. The second approach is not just more technical. It is more governable, because it shrinks the gap between intention and enforcement.

The same logic can transform boards. Instead of treating the board pack as a quarterly ritual, boards could demand live risk dashboards, structured challenge sessions, scenario tests, and explicit system maps showing where blind spots are most likely to emerge. The point is not to overwhelm directors with data. The point is to make the organization legible at the level where complexity actually lives.


Key Takeaways

  1. Stop treating governance as a compliance checklist. In complex systems, the real question is whether the structure makes good behavior easier and bad behavior harder.

  2. Design for fallibility, not perfection. People make mistakes, incentives distort judgment, and pseudonymisation alone does not guarantee privacy. Strong systems assume this from the start.

  3. Shift from supervision to system design. Ask what signals are missing, where feedback loops are broken, and how accountability can be built into the architecture.

  4. Make trust less necessary by making actions more visible. Open code, logging, traceability, and constrained access can strengthen both security and legitimacy.

  5. Upgrade governance literacy. Boards and leaders need to understand complexity, information design, and system dynamics, not just rules and reporting.


The real test of governance

The deepest challenge is not how to create more oversight. It is how to build institutions that are worthy of oversight because they are already structured to reveal truth, limit harm, and adapt under pressure.

That is why board reform and secure health data infrastructure belong in the same conversation. Both are attempts to answer the same question: How do we create trust in environments too complex for trust to be enough?

The answer is not more performance, more ceremony, or more declarations of responsibility. It is a new discipline of institutional design, one that understands governance as an active, engineered relationship between visibility, constraint, and adaptation.

In the end, the best institutions will not be the ones that promise they can be trusted. They will be the ones that make trust almost unnecessary.

Sources

← Back to Library

Hatch New Ideas with Glasp AI 🐣

Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)

Start Hatching 🐣
Why Governance Fails When It Treats Complexity Like a Checkbox | Glasp