The Real Governance Problem Is Information Asymmetry

Ebuka Emmanuel Ajaegbu
Internal Audit Leader and Researcher focused on corporate governance, internal control, risk management and the role of internal audit in reducing principal–agent conflicts.
One of the most dangerous risks in corporate governance is not always fraud.
Sometimes, the greater risk is information imbalance.
In most organisations, management naturally knows more about the true condition of the business than the board, shareholders, regulators and other stakeholders.
Management is directly involved in the organisation’s daily activities. It understands the operational realities, financial pressures, control weaknesses and emerging risks that may not be immediately visible to those outside the day-to-day management process.
Managers often know:
- where controls are weak;
- which processes are not functioning as intended;
- which risks are increasing;
- which corrective actions are being delayed;
- which reports do not fully reflect operational reality; and
- where management targets are placing pressure on employees and business processes.
This information advantage is not inherently wrong.
Management is expected to know more about the organisation because it has been appointed to run the business.
The governance problem begins when the information available to management is not accurately, completely and promptly communicated to those charged with oversight.
That is where information asymmetry becomes dangerous.
What is information asymmetry?
Information asymmetry exists when one party in a relationship possesses more or better information than another party.
Within a company, management usually has more detailed information than shareholders and the board.
In agency theory, shareholders are commonly described as the principals, while managers are the agents appointed to manage the organisation on their behalf.
The principals provide capital and expect management to protect their interests, grow the organisation and use its resources responsibly.
However, shareholders cannot directly observe every management decision, transaction or operational activity. They therefore rely on financial statements, management reports, board meetings, regulatory returns and assurance functions to understand what is happening within the organisation.
This dependence creates a potential information gap.
Management may understand the full reality of the organisation, while the board and shareholders see only the information presented to them.
When that information is incomplete, inaccurate, delayed or presented without sufficient context, those charged with governance may make decisions based on an incomplete picture.
The gap between what is reported and what is happening
Information asymmetry creates a gap between what is reported and what is actually happening.
For example, a board may receive a report showing that a significant control weakness has been resolved.
However, the corrective action may only have addressed the visible symptom rather than the underlying cause.
Management may report that bank reconciliations are being performed, while several reconciling items remain unresolved for months.
A regulatory return may be submitted before the deadline, but the underlying data used to prepare the return may be incomplete or poorly validated.
A risk may be classified as moderate, even though operational employees know that the problem is becoming more serious.
An audit recommendation may be described as closed, while the evidence shows that the control has not yet operated effectively over a reasonable period.
In each of these situations, the report may create an appearance of stability or compliance that does not fully reflect operational reality.
This does not always mean that management is deliberately misleading the board.
Information gaps can also arise from:
- weak reporting systems;
- poor escalation procedures;
- unclear accountability;
- fragmented communication;
- inadequate documentation;
- excessive focus on positive performance;
- fear of reporting bad news;
- pressure to meet targets; or
- a culture that discourages challenge.
Regardless of the cause, the consequence is the same: those responsible for governance may not have the information they need to make sound decisions.
How information asymmetry creates agency conflict
Agency conflict occurs when the interests or actions of management are not fully aligned with the interests of shareholders or the organisation.
Managers may make decisions that protect their positions, compensation, reputation or short-term performance, even when those decisions are not in the organisation’s long-term interest.
Information asymmetry makes this conflict more difficult to detect.
Because management controls much of the information flowing to the board, it may be able to present decisions in a favourable manner, delay the disclosure of problems or provide explanations that cannot easily be independently verified.
A board may believe that the organisation is stable while serious control weaknesses are growing beneath the surface.
Shareholders may rely on financial and performance reports that do not fully reflect operational challenges.
Regulators may receive returns that appear compliant even though the processes supporting those returns remain weak.
The board may therefore be formally exercising oversight without having sufficient visibility into the true condition of the organisation.
This is why effective governance requires more than receiving reports from management.
It requires independent mechanisms for validating those reports.
Internal audit helps reduce the information gap
Internal audit plays an important role in reducing information asymmetry.
It independently reviews organisational processes, evaluates risk management, tests internal controls, validates reports and communicates significant issues to senior management, the board and the audit committee.
Internal audit provides an objective perspective on whether the information presented by management is supported by evidence.
For example, when management reports that an audit issue has been resolved, internal audit may:
- inspect the corrective action taken;
- review supporting documents;
- test whether the revised control is working;
- confirm whether the underlying risk has been addressed; and
- determine whether the issue can reasonably be considered closed.
This process helps distinguish between a reported action and an effective outcome.
Internal audit also examines areas that may not be adequately reflected in routine management reporting.
These may include:
- recurring control failures;
- unresolved reconciliation items;
- delayed regulatory filings;
- unauthorised transactions;
- incomplete customer documentation;
- weak segregation of duties;
- management override of controls;
- inadequate follow-up on corrective actions; and
- differences between policies and actual operating practices.
By bringing these matters to the attention of the board and audit committee, internal audit gives those charged with governance a clearer understanding of the organisation’s true risk and control environment.
Internal audit is not a substitute for management
The role of internal audit is not to manage the organisation or take ownership of management responsibilities.
Management remains responsible for designing controls, managing risks, producing accurate reports and correcting identified weaknesses.
Internal audit provides independent assurance on whether these responsibilities are being properly discharged.
This distinction is important.
An internal audit function that becomes too involved in operating controls may lose the independence required to assess those controls objectively.
At the same time, an internal audit function that is disconnected from the business may fail to understand the operational context behind the issues it reviews.
The goal is therefore not isolation, but independent and informed engagement.
Internal auditors must understand the organisation, maintain constructive relationships with management and communicate recommendations practically, while preserving their ability to report issues objectively.
The importance of unrestricted access
Internal audit can only reduce information asymmetry when it has sufficient access, authority and independence.
The function must be able to obtain relevant documents, engage with employees, review sensitive processes and communicate directly with the board or audit committee when necessary.
When internal audit is denied information, excluded from important discussions or pressured to soften significant findings, the information gap becomes wider.
The board may then receive reports from management without the benefit of effective independent challenge.
A strong internal audit function should therefore have:
- an approved mandate;
- unrestricted access to records and personnel;
- functional reporting to the board or audit committee;
- adequate resources and competence;
- protection from inappropriate management interference; and
- the authority to escalate significant unresolved issues.
Without these conditions, internal audit may exist in name but remain unable to perform its governance role effectively.
Reporting must go beyond listing exceptions
Internal audit does not reduce information asymmetry simply by producing long reports.
The value of internal audit depends on the quality of the insight communicated.
A useful internal audit report should explain:
- what happened;
- what should have happened;
- why the difference occurred;
- what risk the issue creates;
- how the organisation may be affected;
- who is responsible for addressing it;
- what action management has agreed to take; and
- whether the issue requires board-level attention.
Internal auditors should also identify patterns.
One isolated exception may appear minor. However, repeated exceptions across several processes may indicate a deeper governance problem.
Repeated delayed reconciliations may reveal inadequate staffing, poor supervision or weak financial discipline.
Recurring documentation gaps may indicate a culture in which evidence is not treated as important.
Repeated extensions of audit action deadlines may suggest that management is not prioritising corrective actions.
By connecting individual findings to broader governance concerns, internal audit helps the board understand not only what went wrong but why it matters.
Trust must be supported by assurance
Good governance requires trust.
Boards must trust management to run the organisation responsibly. Shareholders must trust directors and executives to protect their interests. Regulators must trust that organisations are operating within applicable laws and standards.
However, trust alone is not sufficient.
Trust without verification can allow serious weaknesses to remain hidden.
Independent assurance strengthens trust by providing evidence that reports, controls and management representations can be relied upon.
This does not mean that internal audit should assume that management is dishonest.
It means that good governance should not depend solely on the accuracy of information supplied by the people whose performance and decisions are being assessed.
Independent assurance protects both the organisation and responsible management.
It confirms where processes are working and identifies where improvement is required.
Internal audit helps balance organisational power
Information creates power.
The party with greater access to information is usually in a stronger position to influence decisions, shape perceptions and determine which issues receive attention.
Management’s information advantage gives it significant influence over the way the organisation is understood by the board and other stakeholders.
Internal audit helps balance that power.
By independently reviewing operations, validating management reports and escalating significant concerns, internal audit improves the quality of information available to those charged with governance.
This strengthens:
- transparency;
- managerial accountability;
- board oversight;
- risk awareness;
- control effectiveness; and
- stakeholder confidence.
Internal audit therefore serves as more than a control-testing function.
It is an important part of the organisation’s governance architecture.
A governance mechanism, not merely a compliance function
In my research article, “Resolving Principal–Agent Conflicts: Revisiting Agency Theory Through the Lens of Internal Audit,” I argued that internal audit plays a unique role in reducing information asymmetry, strengthening accountability and improving transparency between principals and agents.
The article is available here:
This perspective positions internal audit as a governance mechanism rather than merely a compliance or inspection function.
Its contribution is not limited to detecting errors after they occur.
Internal audit helps ensure that those responsible for oversight receive a more accurate and balanced view of the organisation.
It challenges unsupported representations, verifies corrective actions and brings attention to risks that may otherwise remain below the surface.
When properly positioned, internal audit reduces the distance between what management knows and what the board understands.
Final thoughts
One of the greatest threats to effective governance is not always the absence of information.
It is the unequal distribution of information.
When management possesses important information that is not fully, accurately or promptly communicated to those charged with governance, accountability becomes weaker and agency conflict becomes more likely.
Internal audit helps close this gap by providing independent assurance over the information, controls and processes on which the board relies.
In governance, the person with better information often has more power.
Internal audit helps balance that power.
Good governance is not built on trust alone.
It is built on trust supported by independent assurance.