Marentis Labs

The Theory of Governance Failure

Why do capable, fully-staffed boards still miss the risks that matter? This chapter sets out the theory of governance failure — bounded rationality, decision noise, consensus dependency and the absence of institutionalised challenge — that explains failure as a predictable structural output rather than bad luck.

Governance failure is not random. So why do organisations with governance frameworks, risk committees, internal audit functions, and external auditors still regularly experience catastrophic oversight failures?

This section proposes that governance failure is a predictable outcome of three structural defects that are embedded in how governance is designed and delivered in most medium-to-large organisations.

These defects are:

Each defect has independent theoretical support. Taken together, they explain why governance fails despite increasing investment and point toward the architectural changes required to produce different outcomes.

The intellectual frame for this diagnosis is older than any of the defects it identifies. Karl Popper, in The Open Society and Its Enemies, argued that institutional theory had been pursuing the wrong question. The governance question is not who should rule, which presumes decision-makers who will reliably get the answer right, but how can institutions be arranged so that bad or incompetent decisions can be detected and corrected before they do too much damage? [1] The distinction is subtle but significant. It shifts the object of governance design away from the selection of good decisions and toward the construction of systems that surface their own errors. The three structural defects that follow are each a specific way in which conventional governance architecture disables that second discipline. Episodic engagement prevents errors from being detected in time. Consensus dependency prevents them from being named once detected. The absence of institutionalised challenge ensures that no function is adequately mandated to look for them at all.

Bounded Rationality and the Satisficing Board

In 1947, Herbert Simon published Administrative Behavior [2], a study of decision-making processes in organisations that would fundamentally reshape economic and management theory. Simon’s central insight was that human decision-makers do not behave as classical economics assumes. They do not survey all available options, calculate the consequences of each, and select the optimal choice. They cannot, because they are constrained by limited information, limited cognitive processing capacity, and limited time.

Simon called this condition bounded rationality: rationality that is bounded by the cognitive limitations of the decision-maker and the complexity of the environment in which decisions are made. Under conditions of bounded rationality, decision-makers do not optimise. They satisfice, a term Simon coined as a portmanteau of “satisfy” and “suffice” to describe the practice of searching for alternatives only until finding one that meets a minimum threshold of acceptability.

“Whereas economic man maximizes-selects the best alternative from among all those available to him-his cousin, the administrator, satisfices-looks for a course of action that is satisfactory or ‘good enough.’” - Herbert Simon, Administrative Behavior1 [2].

Simon’s work earned him the Nobel Prize in Economics in 1978 and has been extensively validated across organisational, economic, and psychological research over the subsequent seven decades. Daniel Kahneman’s Thinking, Fast and Slow [3] extended Simon’s framework by demonstrating the specific cognitive mechanisms (anchoring, availability bias, overconfidence, and the substitution of System 1 intuition for System 2 deliberation) through which bounded rationality manifests in professional judgement. In The Psychology of Risk [4], Breakwell provides complementary evidence from risk psychology, documenting how optimism bias compounds these effects. Decision-makers systematically overestimate favourable outcomes through both motivated reasoning (defensive denial of threats to self-image) and cognitive egocentrism (weighting personal experience above base-rate evidence). In a governance context, optimism bias means that boards not only process incomplete information but do so through a cognitive lens biased toward favourable interpretation of the information they receive.

Application to board-level governance

Boardrooms are environments in which bounded rationality operates with particular force. Directors are typically part-time, serving on multiple boards, with limited time to process the volume of material presented to them. They are dependent on management for the information they receive, creating the information asymmetry that principal-agent2 theory [5] predicts: an asymmetry that the executive management controls and has an inherent interest in protecting. They operate under social pressure to maintain collegial relationships and to reach consensus within the limited time available at board meetings.

Under these conditions, satisficing is a predictable cognitive outcome, not a mark of individual failure. Boards accept management’s preferred narrative because challenging it requires time, information, and expertise they may not have. They approve strategies that have achieved internal consensus because the cognitive cost of reopening the analysis exceeds their available processing capacity. They focus on the agenda items management has prioritised rather than asking what has been omitted.

The consequence is a systematic bias toward acceptance and consensus. Boards that satisfice are not incompetent. They are operating exactly as bounded rationality predicts they will operate in the absence of structural mechanisms designed to counteract it.

The empirical signature

The cognitive argument is reinforced by a market pattern. Hunziker et al [6] analysed 471 severe share-price declines of 25% or more across Germany, Austria, and Switzerland between 2018 and 2024 (of which 395 were classified by underlying risk driver; see Section 2) and found that they cluster on the reporting calendar. The heaviest months were September (70 events), June (57), and October (56). The authors’ interpretation is that “event risk clusters around reporting cycles and is often triggered by corporate announcements”. The implication for governance is sharper than the statistic. Material risk does not crystallise on the reporting rhythm; its public recognition does. Boards whose engagement with risk is indexed to the same rhythm learn of material exposures at roughly the moment the market does, with no advantage of foreknowledge and no window in which to act. Episodic engagement is a documented empirical pattern in the timing of value destruction, confirmed by market data. And the pattern will not dissipate in a calmer environment: The WEF [7] reports that only 1% of over 1,300 surveyed risk experts anticipate a calm global outlook in either the two- or ten-year horizon. The cognitive defect identified here operates inside an environment that the practitioner consensus considers anything but benign.

The AI amplifier. Artificial intelligence provides a current, concrete test of bounded rationality under pressure. Deloitte [8], in a survey of 695 board members and C-suite executives across 56 countries in January and February 2025, found that 66% of respondents report their boards have “limited to no knowledge or experience” with AI. Nearly one-third (31%) say AI is not on the board agenda at all. Only 17% address it at every meeting. The bounded-rationality prediction is precise. Boards that lack the cognitive resources to evaluate a risk domain will engage with it episodically rather than continuously, and will default to accepting management’s framing rather than challenging it. The Deloitte findings confirm the prediction in the domain where governance stakes are rising fastest. Two-thirds of boards cannot evaluate what management tells them about AI. One-third do not discuss it. The satisficing pattern identified by Simon in 1947 is operating, measurably, in the risk category that the WEF [7] identifies as showing the sharpest increase in perceived severity between the short and long term.

Structural Defect 1: Episodic Engagement Boards engage with risk on a periodic cycle, marked by the quarterly report, the annual risk review, and the strategy day. Between these episodes, risk evolves continuously while oversight is dormant. Bounded rationality ensures that even when boards do engage, they process what is presented rather than seeking what is missing. The result is governance by snapshot in a world of continuous motion.

Noise and the Variability of Professional Judgement

In 2021, Daniel Kahneman, Olivier Sibony, and Cass Sunstein published Noise: A Flaw in Human Judgment [9], a work that identified a problem in professional decision-making that had been hiding in plain sight.

The authors distinguish between two types of error in judgement:

Bias is systematic directional error i.e., a consistent tendency to err in the same direction.

Noise is unwanted variability i.e., different professionals reaching materially different conclusions when presented with identical information.

Bias has been extensively studied. Noise, the authors argue, has been largely ignored despite contributing at least as much to total judgement error.

The evidence is striking. In one of the book’s most arresting findings, a study of insurance underwriters asked experienced professionals to set premiums for the same five fictitious customers. The median difference between any pair of underwriters’ quotes was 55%. When executives were asked to predict the variability, they estimated 10%.

Kahneman, Sibony, and Sunstein document comparable noise across medicine (psychiatric diagnoses agreed in only 50% of cases for the same patients), criminal sentencing, forensic science, patent evaluation, and personnel selection. The pattern is consistent. Wherever professionals exercise judgement, the variability in their conclusions is far greater than the professionals themselves believe.

Application to board-level governance

Board decisions are acts of professional judgement under uncertainty. Directors assess strategy proposals, evaluate risk exposures, approve capital allocations, and form views on management performance. These are precisely the kinds of complex, multi-dimensional judgements in which noise is most prevalent.

Consider two boards of equivalent competence, presented with the same strategic proposal, the same risk data, and the same management recommendation. If the noise findings apply (and there is no theoretical reason they would not) those two boards may reach materially different conclusions. The outcome depends not on the quality of the information but on who speaks first, how the question is framed, what recent events are salient in directors’ minds, and whether the prevailing mood in the room favours caution or ambition.

The practical implication is that board decisions are less reliable than boards believe them to be. A board that approves a strategy by consensus may be experiencing the comfort of agreement without the assurance of rigour. A different board, on a different day, with a different seating arrangement and a different opening speaker, might have reached a different conclusion, and either conclusion might be correct.

Kahneman, Sibony, and Sunstein propose a remedy they call “decision hygiene”, structured processes designed to reduce noise in the same way that medical hygiene reduces contamination. Their specific mechanism is the Mediating Assessments Protocol (MAP), which can be summarised to a three-step process: first, define the key dimensions of the decision independently before discussion begins; second, have each assessor rate each dimension independently, grounded in evidence, before seeing others’ assessments; third, integrate the independent assessments into a final decision only after all dimensions have been scored.

The MAP is designed to prevent the social dynamics that amplify noise, including anchoring to the first opinion expressed, conformity pressure, halo effects from strong personalities, and the substitution of overall impression for structured analysis. It is, in essence, an adversarial process, one that forces independent, evidence-based judgement before allowing group synthesis.

Structural Defect 2: Consensus Dependency Board decision-making is structurally biased toward consensus. Directors operate under social pressure to agree, under time pressure to conclude, and under cognitive pressure to satisfice. Without a structured mechanism to force independent, evidence-based judgement (a decision hygiene function) boards are subject to the same noise that produces 55% variability in insurance underwriting. The result is decisions that feel rigorous but may be artefacts of group dynamics rather than structured analysis.

The Three Lines Model and the Missing Challenge Function

The Three Lines Model, updated by the Institute of Internal Auditors in July 2020, is the dominant governance architecture in medium-to-large organisations, particularly in financial services and professional firms. It provides a framework of layered assurance. The first line (management) owns and manages risk; the second line (risk management, compliance) provides oversight and monitoring; and the third line (internal audit) provides independent assurance.

The model has clear strengths. It defines ownership of risk across the organisation, establishes the principle of independent assurance, and provides a common language for governance architecture. It is, however, a model designed for assurance, providing confidence that controls are operating and risks are being managed. What it was not designed for and does not provide, is a resilient mechanism for continuous, adversarial challenge of strategic decisions and governance architecture at board level.

The Academic Critique

Michael Power, Professor of Accounting at the London School of Economics, has argued in Organized Uncertainty [10] that the intensification of risk management has produced a paradoxical outcome. Organisations invest heavily in demonstrating accountability for risks rather than in actually reducing risk exposure. Power’s thesis, building on his earlier The Audit Society [11], is that governance frameworks become rituals of verification, systems that produce the appearance of control without necessarily delivering its substance.

This critique applies with particular force to the Three Lines Model. The model creates an architecture of assurance in which each line produces reports, assessments, and opinions that flow upward to the board. But the model does not create a function whose purpose is to break the assurance, to challenge whether the reports reflect reality, whether the assessments withstand scrutiny, or whether the governance framework itself is fit for purpose.

Bantleon et al. [12] provided empirical evidence for these structural weaknesses in a peer-reviewed study published in the International Journal of Auditing. Their survey of Chief Audit Executives across Austria, Germany, and Switzerland found significant variance in coordination challenges between governance stakeholders, with the second line’s focus on stakeholder management creating a silo mentality that leads to duplication of risk areas, gaps in coverage, and conflicting assurance opinions reaching the board.

The Financial Stability Institute, a body of the Bank for International Settlements, acknowledged the structural limitations of the three-lines approach as early as 2015 [13], publishing a formal “Four Lines of Defence Model” in response to high-profile banking scandals that had exposed deficiencies in the framework. The FSI’s fourth line consists of external auditors and regulatory supervisors, an acknowledgement that the internal three lines are insufficient but a response that adds periodic external assurance rather than continuous adversarial challenge. The structural gap identified by the FSI remains open.

The Operational Reality

The academic critique is reinforced by the operational reality of how the second and third lines function in practice.

Internal audit (the third line) currently spends an average of 75% of its time on routine assurance work3, including compliance audits, SOX testing, and regulatory obligations. Budget trajectories are deteriorating. Only 23% of internal audit functions received budget increases in 2025, down from 34% the previous year [14]. The third line is structurally consumed by retrospective assurance. It does not have the bandwidth, the mandate, or in many cases the skills to perform forward-looking, adversarial challenge.

Risk management (the second line) faces an equivalent constraint. The PwC Global Risk Survey [15] found that 73% of risk functions report funding constraints for emerging-risk identification and 75% for advanced monitoring capabilities. The EY Institute of International Finance Global Bank Risk Management Survey 2025 [16] (covering 115 banks across 45 countries) found that CRO mandates have expanded significantly to cover AI governance, cyber resilience, ESG, and operational resilience, with no proportional increase in resources. The second line is consumed by monitoring, regulatory reporting, and issue remediation. Strategic, adversarial analysis goes unperformed, not because it is unwanted but because there is no capacity for it.

The Structural Gap

The Three Lines Model was designed for layered assurance. In practice, it produces three lines that are each occupied with their own mandates, with management focused on execution, risk and compliance on monitoring, and internal audit on retrospective review. Between these lines, in the space where continuous, adversarial, forward-looking challenge of governance and strategy should occur, there is a structural gap.

The gap is architectural. Expanding internal audit budgets or hiring additional risk analysts addresses resource constraints within the existing framework; it does not create the function the framework was never designed to include, one whose explicit, full-time purpose is to challenge assumptions, stress-test decisions, and surface failure modes at board level before they materialise.

Structural Defect 3: Absence of Institutionalised Challenge The dominant governance architecture, the Three Lines Model, provides assurance but not challenge. No permanent function exists in most organisations whose mandate is to act as a structured, adversarial, continuous counterweight to management narratives, board consensus, and governance complacency. Internal audit looks backward. Risk management monitors the present. Nobody is mandated to simulate the future.

The Three Defects as a Unified Diagnosis

The three structural defects are interconnected and mutually reinforcing.

Episodic engagement means that boards engage with risk only at intervals, processing whatever information management presents during those intervals. Consensus dependency means that when they do engage, their decision-making is subject to noise, anchoring, and social pressure that bias outcomes toward agreement with the prevailing narrative. Absence of institutionalised challenge means that no function exists to counteract either defect, no mechanism to ensure that engagement is continuous rather than periodic, that decisions are stress-tested rather than consensual, and that governance architecture itself is subjected to adversarial scrutiny.

The result is a governance system that is extensive in its architecture, diligent in its process, and frequently ineffective in its outcomes. It is a system that produces comfort rather than challenge, assurance rather than resilience, and compliance rather than insight.

These defects compound in sequence. Each enables the next in a descending spiral. Episodic engagement creates dormancy between board cycles, rendering the structural gap invisible. Consensus then hardens unchecked into cognitive capture. Agreement feels like rigour; episodic engagement feels sufficient. The cycle restarts from a worse position. Figure  illustrates this dynamic.

The three structural defects of governance: theoretical basis, manifestation, and response required
Structural DefectTheoretical BasisManifestationWhat Is Required
Episodic EngagementSimon: Bounded Rationality (1947/1957); Kahneman: System 1/System 2 (2011)Boards engage with risk quarterly or annually; oversight is a snapshot, not a signalContinuous oversight: a function that monitors and challenges between board cycles
Consensus DependencyKahneman, Sibony & Sunstein: Noise (2021); the 55% variability findingBoard decisions biased toward agreement; noise hidden by the comfort of consensusDecision hygiene: structured, adversarial challenge that forces independent, evidence-based judgement
Absence of ChallengePower: Organized Uncertainty (2007); Bantleon et al. (2021); FSI Fourth Line paper (2015)No function mandated to break assumptions, simulate failure, or challenge governance architectureAn institutionalised challenge function: permanent, adversarial, principal-led, operating at board level

The rightmost column of Table describes three requirements: continuous oversight, adversarial decision hygiene, and an institutionalised challenge function. These are not separate prescriptions. They are different facets of a single architectural response.

The following sections trace these defects through documented case evidence, regulatory convergence, and the value gap in the Three Lines Model.


  1. quote from the 1997 fourth edition↩︎

  2. Principal agent theory was originally developed by Michael Jensen and William Meckling in their 1976 paper in the Journal of Financial Economics called "Theory of the firm: Managerial behavior, agency costs and ownership structure" (https://doi.org/10.1016/0304-405X(76)90026-X)↩︎

  3. based on a North America focused survey from IIA↩︎



References

  1. Karl R. Popper. (1945). The Open Society and Its Enemies. Routledge.
  2. Herbert A. Simon. (1947). Administrative Behavior: A Study of Decision-Making Processes in Administrative Organizations. Macmillan.
  3. Daniel Kahneman. (2011). Thinking, Fast and Slow. Farrar, Straus and Giroux.
  4. Glynis M. Breakwell. (2014). The Psychology of Risk. Cambridge University Press.
  5. David R. Koenig. (2018). Governance Reimagined: Organizational Design, Risk, and Value Creation. (b)right governance publications.
  6. Stefan Hunziker et al.. (2025). Corporate Crises in Germany, Austria, and Switzerland: Empirical Evidence on Risk Drivers. ERM Report 2025. Institute of Financial Services Zug IFZ, Lucerne School of Business.
  7. World Economic Forum. (2026). The Global Risks Report 2026. World Economic Forum.
  8. Anna Marks et al.. (2025). Governance of AI: A Critical Imperative for Today's Boards. Deloitte Global Boardroom Program.
  9. Daniel Kahneman et al.. (2021). Noise: A Flaw in Human Judgment. Little, Brown Spark.
  10. Michael Power. (2007). Organized Uncertainty: Designing a World of Risk Management. Oxford University Press.
  11. Michael Power. (1997). The Audit Society: Rituals of Verification. Oxford University Press.
  12. Ulrich Bantleon et al.. (2021). Coordination Challenges in Implementing the Three Lines of Defense Model. International Journal of Auditing. https://doi.org/10.1111/ijau.12201
  13. Isabella Arndorfer & Andrea Minto. (2015). The ``Four Lines of Defence Model'' for Financial Institutions: Taking the Three-Lines-of-Defence Model Further to Reflect Specific Governance Features of Regulated Financial Institutions. Financial Stability Institute, Bank for International Settlements. https://www.bis.org/fsi/fsipapers11.htm
  14. Institute of Internal Auditors. (2026). North American Pulse of Internal Audit 2026. Internal Audit Foundation. https://www.theiia.org/
  15. PricewaterhouseCoopers. (2024). Global Risk Survey. PricewaterhouseCoopers.
  16. EY & Institute of International Finance. (2025). Global Bank Risk Management Survey. EY and Institute of International Finance.