Understanding complexity, Governing IT

Complexity is not an anomaly to be reduced, but a structural condition of contemporary organizational systems. Interdependent technologies, dynamic regulations, global ecosystems and emerging risks make any approach that attempts to isolate causes or functions insufficient. Governing complexity requires first and foremost understanding it — a principle recognized by major international standards, cybersecurity frameworks and European ICT‑risk regulations. This article examines why the quality of decisions depends on the quality of the context, and how modern governance must transform complexity from noise into actionable information.

Why the quality of decisions depends on the quality of the context

In modern organizations, complexity is not an obstacle to be eliminated but an intrinsic condition of systems. Technological interdependencies, the pace of innovation, regulatory evolution and the globalization of supply chains make it increasingly difficult to trace a problem back to a single cause or a single function. In this scenario, governance cannot be reduced to managing isolated risks or fragmented indicators; it must instead understand the context, interpret connections and anticipate their consequences. The quality of decisions, in fact, depends on the quality of the context on which those decisions are made

Understanding complexity to improve the quality of decisions

1. Complexity as a structural condition

Complexity is often perceived as a problem to be reduced. However, in contemporary organizational systems it is a structural characteristic, generated by:

  • interdependent technologies and distributed infrastructures
  • regulations in continuous evolution
  • global and multilayered supply chains
  • new cyber threats and systemic risks
  • accelerated organizational transformations

These elements create ecosystems in which relationships matter more than individual components.

2. Why understanding the context is essential

Governing complexity requires first and foremost understanding it. This principle is recognized by major international standards:

  • ISO 31000 considers the definition of context a fundamental element of the risk‑management process and promotes the integration of risk into governance, strategy and decision‑making processes.
  • NIST Cybersecurity Framework 2.0 begins with an understanding of organizational context and risk: the Govern function establishes strategy, expectations and policies, while the Identify function enables the understanding of assets, suppliers and relevant cyber risks.
  • DORA (Regulation EU 2022/2554) requires that the ICT risk‑management framework be integrated into the entity’s overall risk‑management system and proportionate to the nature, scale and complexity of its activities.

In all these cases, complexity is not a factor to be simplified, but one to be interpreted.

3. Observing connections, not just indicators

Understanding context means going beyond individual indicators and observing connections. It means asking:

  • What is actually changing?
  • Which dependencies are emerging?
  • Which risks are shifting?
  • Which consequences are we not yet observing?

Complexity often manifests in the invisible relationships between processes, technologies, people and suppliers. Ignoring these relationships means making decisions based on an incomplete representation of the system.

4. Better decisions require better contexts

The quality of a decision depends on the quality of the context on which that decision is made. A poor, fragmented or outdated context leads to:

  • distorted assessments
  • incorrect priorities
  • underestimated risks
  • ineffective responses

Conversely, a rich, integrated and dynamic context enables organizations to:

  • make informed and resilient decisions
  • anticipate changes
  • understand dependencies
  • evaluate systemic impacts

5. The role of modern governance

Before governing complexity, we must learn to read it. Modern governance has a crucial task: transforming complexity from noise into actionable information.

This requires:

  • advanced analytical capabilities
  • integration of data and processes
  • systemic vision
  • cross‑functional collaboration
  • dynamic monitoring tools
  • solid and coherent reference frameworks

Complexity as a strategic competence of modern governance

Complexity is not an obstacle but a language. Organizations that learn to read it can turn into advantage what others perceive only as noise.

Understanding context is the first step in governing complexity — a principle recognized by international standards, cybersecurity frameworks and European ICT‑risk regulations.

The quality of decisions depends on the quality of the context. And the quality of the context depends on the ability of governance to interpret connections, dependencies and transformations.

In an interconnected world, understanding complexity is no longer optional: it is a strategic competence.

Sources and Regulatory References

European Regulations

  • Regulation (EU) 2022/2554 — DORA, Articles 4–6 Integration of ICT risk into the overall risk‑management system, proportionate to the entity’s complexity.
  • Directive (EU) 2022/2555 — NIS2 Strengthening cyber resilience and risk management for essential and important sectors.

International Frameworks

  • NIST AI Risk Management Framework 1.0
    • Functions Govern, Map, Measure, Manage for AI risk management.
  • ISO 31000:2018 — Risk Management System
    • Principi, framework e processo per la gestione del rischio, con enfasi sulla definizione del contesto.

Did you like this article? Share it with whoever you want!

Evolving Governance, Risk, and Compliance
from a control function
to a value driver.