Data Governance: When the System Works Too Well

This is from the “Accounting Makes Cents” podcast episode #120 released on Monday, 24 August 2026.


Today we begin the final episode of our three-part series unpacking the strategic lessons from our spotlight case study on the Pizza Hut lawsuit.

In our first two episodes, we explored how KPI targets can lead to goal incongruence, and how a complex three-player sourcing arrangement can evolve into a reputation issue. Today, we’re going to focus our discussion on a particular kind of digital transformation risk through the lens of CIMA’s E3 framework: “what happens when the technology works exactly as designed, but that it becomes part of the problem or future problem of the company?”

Jump to show notes.

Case Recap: Pizza Hut Lawsuit

If you missed our previous two episodes, we used the Pizza Hut lawsuit to spotlight a couple of management theories and business issues. In that case, Pizza Hut franchisees initially managed their own delivery process operations, including individual arrangements with DoorDash. This created local flexibility but also resulted in inconsistent delivery performance across the network.

Head office later introduced a national agreement with DoorDash, and at the same time rolled out a centralised, AI-enabled platform to support the process, looking at kitchen workflow, order allocation, and delivery routing across the system.

By most accounts, the platform itself worked. It was processing orders, sequencing the kitchen, and coordinating with delivery drivers broadly as intended. But part of how it worked involved giving DoorDash drivers real-time visibility into information like kitchen workflow, order timing, and individual order details, including tip amounts. Questions were raised around how drivers used that visibility—for example, in deciding which orders to accept and when to pick them up—and how it affected delivery consistency and customer experience of those Pizza Hut stores.

To be clear, we’re not lawyers, and we’re not here to comment on the legal merits of the case or to suggest anyone did anything wrong. What interests us, from a CIMA perspective, is simply using the situation as a helpful illustration of a risk category that’s becoming increasingly relevant to our studies. Under E3, we explore how organisations identify and respond to strategic risks in a digital transformation.

The CIMA Perspective: When the System Works Too Well

A lot of conversations about digital transformation risk focus on whether a new system will work: will it be reliable, will it integrate with existing processes, will it scale. Those are all reasonable questions. But there’s a quieter question that’s just as important to be addressed: who can see what, inside this new system, and what might they do with that information?

So here’s the core idea for this episode. Imagine, in principle, a parent company rolling out a centralised, AI-enabled platform across its subsidiaries to coordinate a previously fragmented activity. In this case, delivery allocation. The platform is designed to be efficient, data-driven, and responsive in real time. To do that well, it needs to share a certain amount of information with the people operating within it (users): in this scenario, that might include delivery drivers, who need to know things like pickup locations, estimated distances, and delivery windows in order to do their jobs.

The risk worth thinking about isn’t that this information-sharing is unnecessary. Some of it clearly supports the platform’s core purposes. The risk is that once information is shared, the people receiving it will act in their own interest, not necessarily in the interest of the parent company’s original goals. If drivers can see enough detail about an order—say, the tip amount, or how soon another order will be ready in the same kitchen—some may reasonably choose to wait a few extra minutes to pick up a more attractive order, or to bundle two orders together, rather than collecting the first order the moment it’s ready. From the driver’s perspective, that’s a rational response to the information they’ve been given. From the parent company’s perspective, if enough drivers behave this way, it can produce exactly the kind of inconsistent delivery experience the centralised platform was meant to solve in the first place.

In other words: the system can be working exactly as designed at a technical level, while still producing an outcome the organisation didn’t intend, simply because of what information was visible to whoever.

Data Governance and Information Asymmetry

This is where data governance comes in. In an E3 context, data governance isn’t just about data quality or security in the narrow sense. It’s about deciding, deliberately, what information is shared with which stakeholders, and thinking through the incentives that visibility creates.

Now think about information asymmetry. It’s this idea that whoever holds more relevant information in a relationship can use it to their own advantage. Sometimes in ways the other party didn’t anticipate.

For a parent company rolling out a similar platform across its subsidiaries, the data governance questions worth asking might include: what does each type of user—drivers, local managers, customers—actually need to see to do their job well? Is there information that, while technically useful, could be used in ways that work against the platform’s goals if visible to everyone? And has anyone really looked at how people might behave once they have access to this information? Not assuming bad faith, just assuming people will act in their own best interest.

Responding to the Risk: Using TARA

Once a risk like this is identified, TARA framework gives us a useful structure for thinking about the response. TARA stands for Transfer, Avoid, Reduce, and Accept.

Transferring this kind of risk might mean restructuring contractual terms with the delivery provider so that responsibility for consistency sits more clearly with them. Avoiding it might mean not sharing certain categories of information through the platform at all, even if it would technically be possible to do so. Reducing it could include redesigning what information is visible to whom, perhaps showing drivers less granular detail about individual orders, or introducing allocation logic that doesn’t rely on driver self-selection in the same way. And accepting it might mean acknowledging that some variability is an inherent trade-off of a platform-based model, while monitoring its impact closely.

None of these is automatically “correct”. The right response depends on the company’s priorities, its contractual relationships, and how significant the impact turns out to be. But having a structured way to think through the options is useful.

Lessons for Our Own Rollout

So what does all this mean if you’re a finance, accounting or strategy person, looking at your own company’s next big digital transformation?

One big takeaway that comes out of this discussion: When designing or reviewing a new digital platform, ask not just “does it work” but “what does it show, to whom, and why.” We need to treat data governance and information design as part of strategic risk management, not just a technical or IT consideration. We need to deal with these risks before any platform goes live.


Show notes simplified

In this final episode of the series, MJ the tutor explores a different kind of corporate risk: what happens when a digital transformation works exactly as designed, but the information it shares creates incentives nobody planned for. Using our case study, we look at how an AI-enabled platform’s transparency may have shaped employee behaviour in ways that undermined the very goal it was meant to achieve.

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.