Skip to content
SmartStudy

Emerging Technologies and ICT Governance

Systems

Emerging Technologies and ICT Governance

Syllabus tag: KASNEB CPA | Foundation Level | CA16 Information Communication Technology | Topic 10 Emerging Technologies and ICT Governance

Lesson objectives

By the end of this topic, you will be able to:

  • Explain what ICT governance addresses and why it exists
  • Describe the role of an IT steering committee
  • Explain IT strategy alignment with business strategy
  • Describe the main obligations under the Data Protection Act 2019
  • Explain outsourcing and service level agreements

Why this matters

Technology spending is large, long-lived and hard to reverse. Governance is the framework that stops it being decided by whoever is most enthusiastic.

What ICT governance addresses

It concerns who decides, on what basis, and who answers for the result:

  • Whether IT spending supports the business strategy
  • Whether the risks are understood and accepted at the right level
  • Whether resources are allocated to the right things
  • Whether the value promised is actually delivered

The board is accountable and cannot delegate that. It may delegate execution, but the responsibility for a failed system or a data breach remains with those charged with governance — the same principle the PFM and Companies Act topics apply elsewhere.

COBIT is the framework most often named for IT governance, and ITIL for service management.

The IT steering committee

A cross-functional body that approves and prioritises IT projects. Its membership is the point: it should include the business functions the systems serve, not only IT staff.

Its purposes:

  • Prioritising projects against limited budget
  • Approving major expenditure
  • Monitoring progress against plan
  • Ensuring the business, not the IT department, owns the requirements

Where a steering committee is composed only of technologists, projects get selected on technical interest rather than business need — which is the governance version of the operational feasibility failure.

Alignment of IT and business strategy

IT strategy should follow from business strategy, not precede it. The question is always what the organisation is trying to achieve and only then what systems support it.

Symptoms of poor alignment:

  • Systems that do not support the way the business actually works
  • Duplicated systems performing the same function in different departments
  • Substantial spending with no measurable benefit
  • Departments buying their own software because the central one does not serve them

That last symptom is the most diagnostic. Shadow IT is a message, not simply a breach of policy: it says the approved system is not meeting a real need.

Data protection

The Data Protection Act 2019 governs personal data in Kenya, supervised by the Office of the Data Protection Commissioner.

Principles: personal data must be processed lawfully and transparently, collected for a specified purpose, limited to what is necessary, accurate, kept no longer than needed, and held securely.

Rights of the data subject include being informed, accessing their data, correcting it, objecting to processing, and having it deleted in defined circumstances.

Obligations on the organisation: register as a data controller or processor where required, obtain valid consent, notify breaches, and appoint a data protection officer where the criteria apply.

Two points bear directly on accounting practice. Payroll and customer records are personal data, so the Act applies to systems accountants use daily. And data minimisation conflicts with the instinct to keep everything — retaining records beyond their statutory or commercial purpose creates a liability rather than an asset.

:::checkpoint A company retains full customer payment card details for eight years "in case of queries". Identify the data protection principles engaged and state what the company should do instead. :::

Outsourcing

Contracting an external provider to supply IT services — support, hosting, development or whole functions.

AdvantagesDisadvantages
Access to expertise not worth employingLoss of internal knowledge
Predictable costDependence on the provider
Scales with demandConfidentiality exposure
Management attention freedDifficult and costly to reverse

A service level agreement defines what is being bought: availability targets, response and resolution times, support hours, escalation, reporting, penalties, and the exit provisions.

The exit provisions are the ones companies neglect and later need. Who owns the data, in what format is it returned, and what assistance is given in transferring to another supplier. Negotiating those at the start is straightforward; negotiating them during a dispute is not.

Outsourcing transfers the activity, never the accountability. A company whose outsourced payroll provider fails to remit PAYE remains liable to KRA — which is the same principle as the cloud responsibility point, and the reason governance of a supplier matters as much as governance of a department.

:::checkpoint A finance director proposes outsourcing all IT support to reduce headcount, noting the provider quotes 30% less than current internal cost. Identify three matters that should be settled before signing. :::