In June 2020, German payments company Wirecard collapsed after disclosing that €1.9 billion in reported cash balances could not be verified in escrow accounts purportedly held in the Philippines. The missing funds triggered insolvency within days, despite concerns regarding the firm's accounting practices having been raised repeatedly over more than a decade.
Contemporary governance frameworks exhibit a verification deficit – a structural condition in which the outputs of monitoring institutions cannot be independently validated.
These concerns included persistent questions regarding the credibility of third-party acquiring revenues and the authenticity of supporting financial documentation. Yet, the company continued to receive unqualified audit opinions, remained listed on Germany's DAX 30 index, and was supported by its financial regulator until the fraud became impossible to conceal.
The Wirecard episode underscores the need for a structural challenge at the core of modern corporate governance. Governance systems rely on monitoring institutions—including auditors, boards, and regulators—to verify corporate disclosures and protect stakeholders. However, these institutions operate within incentive structures that may weaken their oversight function.
The deeper issue, however, is not that monitoring institutions may be conflicted; it is that governance systems lack reliable mechanisms for independently verifying whether monitoring itself is being performed effectively.
While governance systems mostly rely on monitoring to reduce information asymmetry, they do not adequately address the problem of verifying the verifier.
Corporate governance is typically grounded in the principal-agent problem, wherein ownership is separated from control, creating incentives for managerial opportunism. Governance frameworks rely on mechanisms such as boards, audit committees, and disclosure requirements to provide oversight and ensure credibility in corporate reporting. It is also worth noting that audit quality is largely unobservable and becomes apparent primarily after failures occur.
We conceptualise these gaps as a verification deficit, the absence of systematic mechanisms for independently assessing whether monitoring institutions are performing their function with integrity and effectiveness.
Modern governance frameworks are designed to ensure oversight through independent monitoring institutions. However, these frameworks largely assume that these institutions, once established as independent, continue to perform their role effectively.
The presence of monitoring institutions does not automatically guarantee effective governance and control
This assumption creates a structural limitation. Monitoring systems intervene primarily at the level of the principal-agent relationship but do not adequately address the reliability of the monitoring layer itself.
Three structural characteristics contribute to this limitation:
As a result, governance systems may appear effective without ensuring adequate oversight in the truest sense. The verification deficit therefore arises not from the absence of monitoring, but from the absence of mechanisms that ensure the monitoring outputs are independently verifiable.
Addressing this deficit requires a shift in governance design from monitoring alone to the verifiability of monitoring.
Based on the structural issues identified, four interrelated principles emerge:
These principles shift governance systems toward a verifiability-centric design, in which monitoring outputs are actively tested rather than assumed.
Let us examine how a breakdown in verification and oversight within a modern governance system brought Germany’s fintech success story to a bitter end.
Collectively, all these observations point to the fact that the failure was not one of oversight, but of verification. The monitors existed; what was missing was a way to independently validate their conclusions.
The future of governance will not be defined by more oversight, but by better verification. What matters is not merely that risks are monitored, but that the outputs of monitoring can be traced, tested, and independently validated. This has implications for both institutions and regulators, which merit due consideration when organisations build or renew their governance architectures (see Table 1).
For Institutions |
For Regulators |
– Governance frameworks must move beyond compliance toward verifiability and traceability – Risk assessments and control evaluations must be supported by transparent methodologies and documented logic – Monitoring outputs must be linked to underlying data and processes to ensure auditability |
– Supervisory evaluation should extend beyond framework presence to include execution quality and traceability – Greater emphasis should be placed on assessing whether monitoring outputs can be independently validated – Regulatory systems should incorporate mechanisms enabling independent challenge and cross-verification |
Every board believes it has adequate governance. Every organisation with a significant governance failure believed the same. The Wirecard board did not know it was sitting over a decade-long fraud — not because they failed to ask questions, but because the governance architecture they relied upon could not be verified.
A system that cannot verify its monitors is as exposed as a system with no monitors at all — perhaps more so, because it carries the false comfort of apparent oversight.
Organisations must ask three diagnostic questions — not once, but on a recurring basis:
Q1. If our primary audit or assurance function were compromised tomorrow, what independent mechanism would surface that failure, and how quickly?
Q2. Can we trace the methodology behind every material assurance we have received in the past, say 12 months, or do we rely on the credential of the provider?
Q3. Are there signals from markets, external analysts, internal dissent, or regulatory feedback that our formal governance processes have treated as noise rather than inputs?
Governance maturity is no longer a function of the presence of oversight structures alone. Boards that cannot answer these questions with confidence are carrying a blind spot that no compliance framework will close.
Corporate governance systems frequently assume that independence ensures credibility. However, the central weakness in modern governance lies not in insufficient monitoring, but in the absence of mechanisms to verify the outputs of monitoring institutions.
A system that cannot independently validate the information produced by its monitors remains structurally vulnerable, regardless of the number of layers it contains.
We believe the governance challenge to be one of verifiability rather than monitoring alone. Strengthening governance systems therefore requires embedding mechanisms that ensure monitoring outputs are transparent, traceable, and independently verifiable.