article · Strategic decisions and risk management
Public-sector ICT environments are typically characterized by dense governance architectures intended to ensure accountability, compliance, and effective oversight. In South Africa, this architecture includes statutory financial management legislation, treasury regulations, audit regimes, and corporate governance codes that collectively prescribe how information systems should be governed. Despite this extensive framework, ICT governance failures continue to recur across public-sector organizations, appearing consistently in audit outcomes and practitioner accounts. Rather than being isolated breakdowns, such failures often persist across reporting cycles and leadership changes. This study examines how ICT governance failure becomes normalized and sustained over time in a highly regulated public-sector context. Drawing on qualitative interviews with 55 government information technology officers across national, provincial, and local government, the analysis shifts attention from why governance fails to how failure is accommodated within everyday organizational practice. The findings show that governance failure is routinely treated as an expected and manageable condition, absorbed through audit rituals, ceremonial governance structures, layered accountability arrangements, and the delegation of governance responsibility to technical units. These practices allow organizations to maintain procedural legitimacy while leaving underlying governance deficiencies largely unaddressed. By conceptualising governance failure as a socially produced and institutionally sustained outcome, the study extends institutional and governance-as-practice perspectives in ICT governance research. A system or process that is far from perfect is still able to function efficiently, provided that the necessary procedures are implemented correctly. This demonstrates that a system can accomplish routine tasks despite its flaws. Prior research highlights the difficulty of implementing and sustaining ICT governance in heavily regulated public sector environments. In these areas ICT reform projects have been repeatedly initiated yet have failed to deliver the expected outcomes. In practice, the results can be used to inform diagnostic and risk-focused evaluations of ICT governance by assisting public-sector organizations in recognizing when governance arrangements are perpetuating, rather than resolving, chronic dysfunction.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.17747/2618-947x-2025-4-316-325
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.