<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>The Role of a Culture of Compliance in Information Technology Governance</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Syaiful Ali</string-name>
          <email>s.ali@feb.ugm.ac.id</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Peter Green</string-name>
          <email>p.green@business.uq.edu.au</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Michael Parent</string-name>
          <email>mparent@sfu.ca</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Faculty of Business Administration, Simon Fraser University</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Faculty of Economics &amp; Business</institution>
          ,
          <addr-line>Universitas Gadjah Mada</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>School of Business, University of Queensland</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2009</year>
      </pub-date>
      <abstract>
        <p>Ethics has been perceived as one of the most important factors in establishing good corporate governance. Information Technology (IT) plays an increasing role in helping modern organizations to achieve their goals, and it has become critical in creating and implementing effective IT governance mechanisms. This study examines the extent to which an ethic or culture of compliance in IT within an organization influences the overall effectiveness of IT governance, and the factors that contribute to this effect. Responses from 122 internal auditors, members of ISACA (Information Systems and Audit Control Association) Australia, show that two factors contributed to the ethics or culture of compliance in IT: corporate communication systems and the involvement of senior management in IT. This study advances our understanding of the roles of IT governance mechanisms and their impact on the overall effectiveness of IT governance. Furthermore, the findings of this study provide empirical results on the IT governance mechanisms that have been previously studied mainly by normative and case study approaches.</p>
      </abstract>
      <kwd-group>
        <kwd>compliance</kwd>
        <kwd>ethics</kwd>
        <kwd>information technology</kwd>
        <kwd>IT governance</kwd>
        <kwd>Australia</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>The collapses of Enron, WorldCom, HIH, One.Tel and many others early this century have brought about
renewed attention to corporate governance mechanisms and birth to a spate of legislation and regulations
worldwide. Some countries, like the United States and its Sarbanes-Oxley Act (SOX), have chosen
coercive mechanisms, focusing on enforcement and punishment for egregious behavior, while others, like
Australia and the United Kingdom, have chosen more cooperative approaches that place the burden for
disclosure and explanation on the companies themselves rather than auditors and regulatory enforcement
officers. Whichever approach is used, it remains that governments worldwide have ushered in a new era
for business, one in which the actions of directors and executives will be closely scrutinized in order to
prevent gross breaches of investor confidence, and their associated destruction of wealth, as has happened
in the past.</p>
      <p>
        Shailer (2004, p.55) defines governance as “…decision-making in the exercise of authority for direction
and control.” This theme is echoed in
        <xref ref-type="bibr" rid="ref30">Picou and Rubachs (2006)</xref>
        broader, agency-theoretic
conceptualization of governance as “…the construction of rules, practices and incentives to effectively
align the interests of agents…with those of principals.” These definitions imply four interrelated
principles: first, the company's directors and officers know the strategic direction the company is
pursuing. Second, they act, or make decisions. Third, they have authority over the affairs of the
organization. Finally, they have a fiduciary duty-of-care centered on oversight and control aimed at
optimizing the interests of the organizations shareholders. Underlying them is an active commitment to
engage in an ethic that transcends strict responses to precise regulations.
        <xref ref-type="bibr" rid="ref32">Roberts (2001)</xref>
        expresses this
enhanced form of governance as a shared responsibility felt towards others.
      </p>
      <p>
        This trend towards an ethic of responsibility or culture of compliance, in organizations is part of what
some have described as New Governance in which strict standards are replaced by boundaries that allow
local experimentation to occur.
        <xref ref-type="bibr" rid="ref22">Lobel (2004)</xref>
        describes this as a participatory, collaborative,
decentralized, diverse, flexible, fallible and adaptable system whereby governance is embedded. A New
1 Corresponding authors
Governance approach puts ethical behavior in the forefront, establishing it as one of its most important
factors
        <xref ref-type="bibr" rid="ref10 ref24 ref3 ref37 ref38">(Coffin, 2003; Farrar, 2002; Trevino et al., 1999; McCabe et al., 1996; and Verschoor, 2004)</xref>
        . In a
survey of Fortune 1000 firms,
        <xref ref-type="bibr" rid="ref41">Weaver et al. (1990)</xref>
        found that 98 percent of responding firms address
ethical or conduct issues in formal documents. Meanwhile, 78 percent have a separate code of ethics, and
most of them distribute these policies widely within the organization.
      </p>
      <p>
        Implicit in most governance legislation and regulation is the need for prudent governance of organizations
IT functions. As
        <xref ref-type="bibr" rid="ref23">McAfee (2006)</xref>
        recently showed, U.S. companies spend as much on information
technology each year as they do on offices, warehouses and factories combined. As a result of these large
investments, the consequences of any disasters are likely to be profound and lasting.
      </p>
      <p>
        The importance of IT to business functions is well documented
        <xref ref-type="bibr" rid="ref9">(cf. El Sawy and Pavlou, 2008)</xref>
        . IT, for so
long having been considered an enabler of an organizations strategy, is now viewed as an integral part of
an organizations strategy in facilitating the exploitation of information-based competitive advantage to
maximize benefits, capitalize on opportunities, and promote organizational growth. In this regard, IT has
progressed from being a separate function marginalized from the rest of the organization to increasingly
critical.
      </p>
      <p>In this study, we argue that an ethic or culture of compliance in IT is critical for organizations in
establishing and implementing effective IT governance. As IT becomes more important, a sound ethic
leads to more effective IT governance. Thus, our research questions are: To what extent does an ethic or
culture of compliance in IT influence the overall effectiveness of IT Governance mechanisms in
organizations? This question leads to additional sub-questions: What factors influence the development
of such an ethic of compliance? Which factors are most salient?
Existing research provides only anecdotal evidence. We explore in greater detail this role of ethical
compliance in governing information technology through a survey of 122 internal auditors and members
of the Information Systems Audit and Control Association (ISACA) in Australia. Furthermore, this study
represents to the best of our knowledge the first work to demonstrate empirically a positive significant
relationship between ethic or culture of compliance and effective IT governance.</p>
    </sec>
    <sec id="sec-2">
      <title>2 Theoretical Foundations</title>
      <p>In this section we develop the theoretical bases for our investigation. First, we examine the foundations
and importance of sound IT governance. Next, we review the few studies that have been done in linking
ethics to information systems decisions in organizations.</p>
      <sec id="sec-2-1">
        <title>2.1 IT Governance and Agency Loss</title>
        <p>
          Governance was first posited to be an agency problem, that is, one where power between the owners of a
corporation (shareholders) was less than that of its managers who, though not owners, had near-perfect
information about the company and its operations. Owners and managers also sometimes had conflicting
goals: owners for wealth-maximization, managers for ongoing employment with high remuneration.
“Agency loss”, then, occurred when managers pursued objectives that were more in their interest than in
the interests of the many, typically diffused shareholders
          <xref ref-type="bibr" rid="ref20">(Jensen and Meckling, 1976)</xref>
          . Principals were
aware of these possible agency losses, and took steps to minimize them by imposing contracts and
performance checks on management, mainly through elected representatives, some from outside the
organization, that formed a Board of Directors, and hence, corporate governance. Directors, in turn,
organized themselves to provide appropriate levels of scrutiny towards the organization, mainly through
Audit and Compensation committees composed solely of external (independent) directors.
The Boards compensation committee sets executive compensation levels. The audit committee oversees
and attests to the completeness and accuracy of corporate financial statements. In both cases, Directors
(and by extension, the managers who report to these directors through the CEO) rely on the organizations
information systems to provide the necessary data for decision-making. As such, senior management
involvement in financial reporting systems are crucial for the organization to succeed, and to
transparently demonstrate to shareholders and stakeholders that opportunistic behavior is nor occurring.
Information Technology (IT), then, has the potential to be one of the most significant drivers of economic
wealth for enterprises. In many organizations IT is a critical asset, not simply for organizational success,
but to provide opportunities to obtain competitive advantage
          <xref ref-type="bibr" rid="ref15 ref16 ref17">(IT Governance Institute, 2003)</xref>
          . Further, a
large portion of the market value of organizations has transitioned from the tangible, (e.g., facilities,
inventory, etc.) to the intangible (e.g., information, knowledge, expertise, reputation, etc.). However,
despite the large investments and potentially huge risks associated with IT, boards typically focus on
business strategy and strategic risks, perhaps at the cost of less effective IT Governance (ITG) in the hope
that nothing goes wrong (IT Governance Institute (ITGI), 2003a, 2003b). In this study, we propose a
more active form of involvement on the part of directors and managers that is subsumed in the ITGIs
(2003a) definition of IT Governance as “A structure of relationships and processes to control the
enterprise in order to achieve the enterprises goals by adding value while balancing risk versus return
over IT and its processes.”
Early research in IT Governance sought to identify and quantify the elements of good IT governance.
          <xref ref-type="bibr" rid="ref42 ref43">Weill and Ross (2004)</xref>
          , surveyed CIOs of 256 firms from 23 countries, and identified fifteen of the most
common IT governance mechanisms. They categorised these into three broad factors: decision-making
structures, alignment processes, and communication approaches.
        </p>
        <p>Sohal and Fitzpatrick (2002) observed the IT governance mechanisms used by Australian organizations,
including the existence of an IT steering committee, centralisation of IT decision-making activities and
the involvement of senior management in IT. However, the study did not provide empirical support of the
relationship of the three mechanisms to the level of effectiveness of IT governance.</p>
        <p>
          <xref ref-type="bibr" rid="ref6">De Haes and Van Grembergen (2005</xref>
          ) conducted a case study of a major Belgian financial firm,
examining how the mechanisms, processes and structures of IT governance contributed to the
implementation of IT governance. Their case study revealed that the firm used governance mechanisms
effectively; for example, an executive committee composed of business and IT people, service-level
agreements (SLAs), and charge-back systems were used to regulate IT resources.
        </p>
        <p>
          <xref ref-type="bibr" rid="ref39">Vaswani (2003)</xref>
          , ran a study of Auditors to determine the effectiveness of IT governance mechanisms,
revealing that the existence of three mechanisms — an IT steering committee, the involvement of senior
management in IT, and corporate performance measurement systems — were positively correlated with
the effectiveness of IT governance. Two additional mechanisms (centralisation of IT decision-making and
the position of the IT function within the organization) were not supported.
        </p>
        <p>
          More recent research
          <xref ref-type="bibr" rid="ref28">(Parent &amp; Reich, 2009)</xref>
          has noted that a plethora of possible ITG frameworks exist –
over 14 at last count, with more evolving. These frameworks differ somewhat in their approach, for
example, CoBIT, COSO, and ITIL provide comprehensive guidance from the micro level upwards. Given
their focus, they also tend to be fairly prescriptive. In contrast, AS8015, the Australian Standard for ICT
governance is targeted at the strategic level. Its focus is more macro level and discretionary, offering
principles rather than prescription. While these frameworks differ relative to their focus, they still have a
single common goal: the good governance of organizational IT through the establishment of structural
mechanisms (e.g., IT Steering and Strategy committees) that inevitably facilitate director focus and
attention to IT-related issues.
        </p>
        <p>
          <xref ref-type="bibr" rid="ref11">Filatotchev (2007)</xref>
          suggests that the dominant view of governance comes from agency theory, which
emphasizes monitoring and control functions. Within this perspective, director’s responsibilities take two
forms: ensuring accountability to minimize downside risk and enabling managerial entrepreneurship to
reap upside potential. These two perspectives are called the wealth protecting and wealth creating aspects
of corporate governance. They see to it that wealth is not squandered or put at risk and ensure that
measures are taken to increase this wealth over time.
        </p>
        <p>
          Given the number of alternative ITG frameworks, it is fair to conclude that no single dominant approach
to IT governance has emerged. Rather, recent research has conceived of IT Governance as having two
distinct modes consistent with Filatotchevs approaches: defensive and strategic
          <xref ref-type="bibr" rid="ref28">(Parent &amp; Reich, 2009)</xref>
          .
Defensive ITG seeks to fire-proof the organization by preventing or mitigating the consequences of
disasters. Strategic ITG, on the other hand, aims to create sustainable shareholder value by either
reducing costs (such as the cost of capital, or of IT projects) or creating a sustainable competitive
advantage. We contend that governance legislation and regulations help shape organizational responses
to ITG, as do the particular organizations approach to their IT functions. That is, organizations ITG
mechanisms evolve so they align with the legislation and regulation prevailing in their particular
jurisdiction, resulting in an organizational ethic that reflects this fiduciary environment.
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2 Ethic or Culture of Compliance and IT Governance</title>
        <p>
          Much has been written about the importance of ethics in establishing good corporate governance
          <xref ref-type="bibr" rid="ref10 ref24 ref3 ref37 ref38">(Coffin,
2003; Farrar, J. 2002; Trevino et al., 1999; McCabe et al., 1996; and Verschoor, C.C. 2004)</xref>
          . Effective
ethical compliance management has several advantages. First, as employees ethical and legal awareness
increase, the employees tend to ask questions correctly and, in the end, do “the right thing” when facing
dilemmas. Second, it influences employees to be willing to report violations to management, thus
contributing to process transparency in the organization. Finally, it increases employees’ commitment,
because a culture of ethical compliance creates value congruence that generates a sense of community and
organizational commitment among employees
          <xref ref-type="bibr" rid="ref24 ref37">(Trevino et al., 1999; McCabe et al., 1996)</xref>
          .
However, very little has been written with respect to ethics and IT Governance. One reason might be that
the link between a culture of ethical compliance and effective governance is seen as axiomatic, and has
been well handled in the literature. However, if this were the case, legislation like the Sarbanes-Oxley
Act of 2002, which mandates even closer scrutiny to IT practices and financial reporting mechanisms,
would not be necessary. Nor would increased attention to the ongoing failure of most IT projects be
studied so extensively.
        </p>
        <p>
          A recent study by
          <xref ref-type="bibr" rid="ref5">Córdoba (2007)</xref>
          suggested that stakeholder-centric perspectives still dominate research
into ethics and information systems, and that ethical behavior is largely a matter of reflective practice on
the part of individual decision-makers. This perspective is similar to that advocated by
          <xref ref-type="bibr" rid="ref11">Filatotchev
(2007)</xref>
          , which criticizes the disciplines focus on agency perspectives. We could find no study, however,
that directly addressed the notion of an ethic of compliance driving IT governance mechanisms, largely,
we feel, because the complexity information systems does not lend itself well to close scrutiny.
This study tries to uncover the invisible, and argue the need to promote a culture of ethical compliance in
order for firms to achieve effective IT governance. Such an environment is useful in preventing and
detecting conduct that may endanger the objectives of IT governance, and in particular, alignment of
business and IT goals and strategies.
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3 Research Model and Hypotheses Development</title>
      <p>H
1
2
H</p>
      <sec id="sec-3-1">
        <title>Involvement of Senior Management in IT</title>
        <p>
          Many researchers have examined the critical role of senior management practices in creating an ethic or
culture of compliance for IT processes within an organization
          <xref ref-type="bibr" rid="ref2 ref33 ref8">(Beyer and Nino, 1999; Dickson et al,
2001; Schein, 1992; Schneider, 1987; and Grojean et al., 2004)</xref>
          . In this study senior management means
the CEO and the level of management directly below that of the CEO whereas an ethic or culture of
compliance refers to “all the beliefs, values, attitudes, rituals and behavior pattern that people in an
organization share”
          <xref ref-type="bibr" rid="ref26 ref35 ref42 ref43">(Meyer, 2004, p.29)</xref>
          .
        </p>
        <p>
          It is important for top management to lead in promoting awareness of ethical compliance within their
organization, as it sends messages to employees that inevitably shape the culture of their organizations
          <xref ref-type="bibr" rid="ref2">(Beyer and Nino, 1999)</xref>
          . The involvement of senior management sends messages that “bond” or help to
align employees actions to the goals of the organization, and thus it contributes to Filatotchevs (2007)
wealth creating perspectives of governance. Dickson et al (2001) argue that the organizations leaders play
critical roles in communicating and demonstrating the importance of ethical values to the organization
stakeholders. Further, Grojean et al. (2004) proposed seven mechanisms by which senior management
promote the importance of ethical values to members such as using values-based leadership, setting the
example, establishing clear expectations of ethical conduct, and formal socialization activities. Using
fifty-seven in-depth, semi-structured interviews,
          <xref ref-type="bibr" rid="ref34">Schwartz (2004)</xref>
          found that provisions of examples and
senior management support are perceived as mechanisms in creating code effectiveness in influencing
behavior. In line with the above arguments, involvement of senior management in information technology
(IT) operations and decisions is also argued to be critical in creating an ethic/culture of compliance. Thus,
H1: Involvement of senior management in IT will positively influence the ethic or culture of compliance
in IT
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>Corporate Communication Systems</title>
        <p>
          Communication has been considered as one of the factors that critically supports an organizations internal
control. The Committee on Sponsoring Organizations (COSO) of the Treadway Commission (1992) listed
communication as one of the critical components of a sound internal control environment. Effective
communication enables an organizations stakeholder to capture and exchange the information needed to
manage and control its operations
          <xref ref-type="bibr" rid="ref4">(COSO, 1992)</xref>
          . In this way, an effective communication system
contributes to achieving the wealth creating perspectives of governance of IT. Some forms of
communication systems such as reporting violations (”whistleblowing”), provision of anonymous phone
lines to communicate violations, and formal socialization activities have been promoted as effective
mechanisms in implementing corporate codes of ethics successfully
          <xref ref-type="bibr" rid="ref34">(Schwartz, 2004; Grojean et al.,
2004)</xref>
          . However, these studies were based primarily on normative opinion and case studies that have a
limitation in terms of external validity. By contrast, this study differs from the previous studies in that it
provides empirical evidence of effective communication mechanisms based on an extensive questionnaire
survey. Accordingly,
H2: The implementation of an effective corporate communication system will positively influence the
ethic or culture of compliance in IT
        </p>
      </sec>
      <sec id="sec-3-3">
        <title>Ethic or Culture of Compliance in IT</title>
        <p>With respect to IT governance, this study argues the need to promote a culture of ethical compliance in
order for firms to achieve their IT governance effectively. Such an environment is useful in preventing
and detecting conduct that may endanger the objectives of IT governance, and in particular, alignment of
business and IT aims. Accordingly, this factor is significant in achieving the wealth creating perspectives
of effective IT governance for the organization.</p>
        <p>
          To achieve an effective ethic or culture of compliance, a firm needs to establish a code of conduct, adopt
and implement (at least in part) a comprehensive compliance framework such as COSO (Committee of
Sponsoring Organizations of the Treadway Commission), COBIT (Control Objectives for Information
and related Technology), ITIL (Information Technology Infrastructure Library), and/or ISO 17799,
provide sufficient ethical training for employees, and provide a reporting hotline. Thus,
H3: The existence of an ethic/culture of compliance in IT will positively influence the level of effective
IT governance.
IT is widely acknowledged as a critical enabler for an organization to achieve its objectives. Accordingly,
sound, independent, knowledgeable advice on the governance of IT within the organization to the Board
of Directors is expected to play a greater role for Boards. IT is a critical element of business strategies and
core operating processes. Accordingly, there is a need for direct involvement of the board of directors in
establishing effective governance of IT. A board can pursue these responsibilities by establishing a
committee (similar in function to the Audit Committee) called the IT strategy committee
          <xref ref-type="bibr" rid="ref15 ref16 ref17">(IT Governance
Institute, 2003)</xref>
          . In this study an IT strategy committee means a sub-committee of board members with
responsibility to provide insight and advice to the board on topics such as the alignment of IT with the
business direction and the achievement of strategic IT objectives, and also, to provide direction to
management relating to the IT strategy
          <xref ref-type="bibr" rid="ref15 ref16 ref17">(IT Governance Institute, 2003)</xref>
          . As with other board
subcommittees such as the audit committee, this committee has both wealth creating and wealth protecting
(or risk management) responsibilities.
        </p>
        <p>
          The involvement of boards more directly in IT governance implies that the organization is committed to
establishing effective IT governance. The commitment of the IT strategy committee to IT governance is
very important. Commitment is indicated by providing direction to management related to IT strategy and
its approval
          <xref ref-type="bibr" rid="ref15 ref16 ref17">(IT Governance Institute, 2003)</xref>
          . A recent study by
          <xref ref-type="bibr" rid="ref1">Ali &amp; Green (2007)</xref>
          in public-sector
organizations in Australia revealed that an IT strategy committee has a positive correlation with the level
of effectiveness of overall IT governance. Thus,
H4: The existence of an IT strategy committee will positively influence the level of effective IT
governance.
        </p>
      </sec>
      <sec id="sec-3-4">
        <title>IT Steering Committee</title>
        <p>
          The IT steering committee, as a mechanism for supporting information systems planning and
management, has been widely supported in the systems literature. In this study an IT steering committee
means a high-level executive management team of representatives from multiple divisions or functions
that are assigned the task of linking IT strategy with business strategy by setting strategic directions,
matching corporate concerns with technology potential, and building commitment
          <xref ref-type="bibr" rid="ref15 ref16 ref17">(IT Governance
Institute, 2003)</xref>
          . The committee serves as a high-level executive team, comprised of representatives from
various divisions or functions within the organization (such as business executives and the CIO), with the
main function of linking its IT strategy and business strategy
          <xref ref-type="bibr" rid="ref15 ref16 ref17 ref27">(Nolan, 1982; IT governance Institute,
2003)</xref>
          . Again, from an agency perspective, this committee of senior managers has responsibilities for both
wealth creating and wealth protecting activities in relation to the IT within the organization. This study
provides evidence as to how well, on average, these committees are perceived to contribute through the
performance of these activities to a higher level of effective IT governance for the organization.
Previous studies have empirically supported the benefits of the existence of an IT steering committee in
IS planning and management
          <xref ref-type="bibr" rid="ref31 ref36 ref7">(Doll, 1985; Steiner, 1979; Ragunathan &amp; Ragunathan, 1989)</xref>
          . Several
earlier IS studies provide empirical evidence of the importance of an IT steering committee. For example,
a study by
          <xref ref-type="bibr" rid="ref21">Karimi et al. (2000)</xref>
          found that an IT steering committee had a positive impact on the
sophistication of IT management, and it was shown to have made improvements to IS project portfolios
          <xref ref-type="bibr" rid="ref25">(McKeen &amp; Guimaraes, 1985)</xref>
          . A more recent study by
          <xref ref-type="bibr" rid="ref39">Vaswani (2003)</xref>
          revealed that an IT steering
committee has a positive correlation with the level of effectiveness of overall IT governance. Thus,
H5: The existence of an IT steering committee will positively influence the level of effective IT
governance
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4 Research Methodology</title>
      <p>All variables except for IT Strategy committee were adapted from previously validated scales. They were
all measured using seven-point Likert scales and are reproduced in Appendix A.</p>
      <sec id="sec-4-1">
        <title>4.1 Dependent Variables</title>
        <p>
          Perceived overall level of effective IT governance (EFFECT) was measured using two items that were
validated by
          <xref ref-type="bibr" rid="ref1">Ali and Green (2007)</xref>
          . The two items were originally developed and validated by
          <xref ref-type="bibr" rid="ref12">Goodhue &amp;
Thompson (1995)</xref>
          .
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2 Independent Variables</title>
        <p>
          To measure IT Strategy Committee (STRACOM), three questions adapted from the IT Governance
          <xref ref-type="bibr" rid="ref16 ref17">Institute (2003)</xref>
          were used.
        </p>
        <p>
          IT Steering Committee (STERCOM) was measured using three items that were validated by
          <xref ref-type="bibr" rid="ref1">Ali and
Green (2007)</xref>
          . All three items were originally developed and validated based on a study conducted by
          <xref ref-type="bibr" rid="ref21">Karimi et al. (2000)</xref>
          .
        </p>
        <p>
          To measure involvement of top management in IT (INVOLVE), this study used three items that were
validated by
          <xref ref-type="bibr" rid="ref39">Vaswani (2003)</xref>
          . The first two items were originally developed and validated based on a
study conducted by
          <xref ref-type="bibr" rid="ref19">Jarvenpaa and Ives (1991)</xref>
          , while the last item was developed and validated by
          <xref ref-type="bibr" rid="ref39">Vaswani (2003)</xref>
          .
        </p>
        <p>
          Corporate communication systems (COMSYS) was measured using three items adapted from
          <xref ref-type="bibr" rid="ref42 ref43">Weill &amp;
Ross (2004)</xref>
          .
Finally, an ethic or culture of compliance (ETHICULT) was measured using three items from Trevino
et.al. (1999) that we adapted to the context of IT governance.
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5 Results and Discussion</title>
      <sec id="sec-5-1">
        <title>5.1 Sample Characteristics</title>
        <p>
          Internal auditors were used as participants in this study. An objective of IT governance is to ensure that
risks related with IT have been analyzed and managed appropriately by management. The internal auditor
plays an important role as he/she has expertise in reviewing control structures and recommending controls
to overcome any uncontrolled risks
          <xref ref-type="bibr" rid="ref44">(Williams, 2002)</xref>
          . Furthermore, the internal auditor can provide a
relatively independent and objective assessment of IT governance in the organization as he/she does not
have a vested interest in the development/expansion of the IT functional area. Thus, the internal auditor is
one of the best sources in assessing IT governance practices within an organization.
        </p>
        <p>An online questionnaire survey was performed in 2005. Email invitations to participate in the survey were
sent out to 1116 members of ISACA throughout Australia. The total of completed and usable responses
was 176. From these responses, 122 were from internal auditors. The remaining 54 responses were from
external auditors.</p>
      </sec>
      <sec id="sec-5-2">
        <title>5.2 Structural Equation Modeling</title>
        <sec id="sec-5-2-1">
          <title>Overall Model Fit</title>
          <p>
            The structural equation modeling technique (SEM) was used to test hypotheses proposed in the model.
Prior to evaluating a structural model, the overall fit of the model has to be assessed to ensure that it is a
sufficient representation of the entire set of causal relationships
            <xref ref-type="bibr" rid="ref13">(Hair et al., 1998)</xref>
            . Hence this study
examined the absolute fit measures, the incremental fit measures, and the parsimonious fit measures
resulting from AMOS.
          </p>
        </sec>
        <sec id="sec-5-2-2">
          <title>Absolute Fit Measures</title>
          <p>
            The measures of absolute fit include the likelihood-ratio chi-square (χ2). The Chi-square (χ2) statistic is
the traditional measure for evaluating model fit (Schumacker, 1996). It examines the differences between
the covariance matrix implied by the model and the covariance matrix obtained from the data.
            <xref ref-type="bibr" rid="ref13">Hair et al.
(1998)</xref>
            suggest that the minimum p-value for the Chi-square to be considered insignificant is 0.05. The
chi-square value for this study model is 101.317 with 92 degrees of freedom, returning a probability value
of 0.238 (See Table 2, Panel A). Since the probability value of the chi-square test is far greater than the
.05 level, this study fails to reject the null hypothesis that the model fits the data, or in other words
suggests that the model fits nicely to the data.
          </p>
        </sec>
        <sec id="sec-5-2-3">
          <title>Incremental and Parsimonious Fit Measures</title>
          <p>
            The measure of incremental fit compares the proposed model to some baseline model, most often referred
to as the null model (Bentler &amp; Bonnet, 1980, Hair et al., 1999). Prior studies suggest some criteria such
as the Tucker-Lewis Index (TLI), Normed Fit Index (NFI), and the Comparative-Fit-Index (CFI)
            <xref ref-type="bibr" rid="ref13">(Hair et
al., 1998; Tabachnick and Fidell, 1996)</xref>
            as measurement indexes. All the three incremental fit measures
exceeded the recommended level of 0.90 (See Table 2, Panel B), that is considered to be indicative of
good model fit.
            <xref ref-type="bibr" rid="ref13">(Hair et al., 1998; Bentler &amp; Bonnet, 1980)</xref>
            Parsimonius fit measures are intended to determine the fit of the model in relation to the number of
estimated coefficients. As this paper only tested a single model, a normed chi-square measure was used
            <xref ref-type="bibr" rid="ref13">(Hair, et al., 1998)</xref>
            . The range of acceptable normed chi-square values is between 1 and 2. In our study,
the normed chi-square value is 1.090, which is clearly in the acceptable range (See Table 2, Panel C).
          </p>
        </sec>
        <sec id="sec-5-2-4">
          <title>Measurement Model Fit</title>
        </sec>
      </sec>
      <sec id="sec-5-3">
        <title>Dependent variable</title>
      </sec>
      <sec id="sec-5-4">
        <title>ETHICULT EFFECT</title>
        <sec id="sec-5-4-1">
          <title>Structural Model Fit</title>
          <p>
            Following the assessments of the measurement model fit, the next step is to examine the estimated
coefficients between variables in the path analysis model. Table 4 presents the regression weights of
variables from AMOS that were used to evaluate the research hypotheses in the model.
The involvement of senior management in IT had a significant and positive effect on the ethic/culture of
compliance in IT. The result was consistent with studies conducted by
            <xref ref-type="bibr" rid="ref2">Beyer and Nino (1999)</xref>
            ,
            <xref ref-type="bibr" rid="ref8">Dickson et
al. (2001)</xref>
            and Grojean et al. (2004). Senior management leadership in promoting awareness of ethical
compliance within their organization was perceived critical, as it sends messages to employees that
inevitably shape the culture of their organizations
            <xref ref-type="bibr" rid="ref2">(Beyer and Nino, 1999)</xref>
            . The result provide empirical
support to Schwartzs (2004) study that found the provision of examples and senior management support
are perceived as mechanisms in creating code effectiveness in influencing behavior. It also points to the
growing importance of endogenous factors, not exogenous forces like legislation, in creating and
nurturing a culture of compliance in the organization.
          </p>
          <p>
            Similarly, corporate communication systems, another endogenous factor, were also found to be positive
and significant in influencing the ethic/culture of compliance in IT. This mechanism resulted as the
biggest factor contributing to the ethic/culture of compliance in IT (B=0.634). The result provides
empirical support for the
            <xref ref-type="bibr" rid="ref34">Schwartz (2004)</xref>
            and Grojean et al., (2004) studies that suggested
communication systems such as reporting violations, the provision of anonymous phone lines to aid
communication of violations, and formal socialization activities was one of the effective mechanisms in
facilitating a corporate code of ethics implementation successfully.
          </p>
          <p>
            Ethic/Culture of compliance in IT had a significant and positive influence on the overall effectiveness of
IT governance (ρ&lt;0.01). This result suggests support for Hypothesis 3 that the existence of an
ethic/culture of compliance in IT leads to a perception of an overall effective level of IT governance. The
unstandardised coefficient for the variable was 1.066, which was the largest score among other variables
— contributing the most toward the overall effectiveness of IT governance. This finding provides the first
empirical support of the benefits of an Ethic/Culture of compliance in the IT governance literature. This
finding is similar to other findings in the ethics literature, which reveals the increase of ethical and legal
awareness of employees leads them to do the right thing when facing dilemmas. It influences the
employees to be willing to report violations to management, thus contributing to better decisions in the
company. Finally, it increases employees’ commitment as an ethic/culture of compliance creates value
congruence that generates a sense of belongingness among employees
            <xref ref-type="bibr" rid="ref24 ref37">(Trevino et al., 1999; McCabe et
al., 1996)</xref>
            . These kinds of environments are useful in preventing and detecting conduct that may endanger
the objectives of IT governance.
          </p>
          <p>The direct influence of IT strategy committee on the overall effectiveness of IT governance (H4) was
positive and significant, with ρ value =0.013, that suggests some support for Hypothesis 4—the existence
of IT strategy committees positively influences the effectiveness of IT governance. This empirical finding
partially supports the normative literature proposed by the IT Governance Institute (2003a). As those at
board level get involved in the governance of IT through an IT strategy committee, they can provide
influential advice to the board and management on recent and future IT-related issues and their alignment
with business goals.
4 0.154
H</p>
          <p>
            The IT steering committee was negative and not significant (ρ=0.134). Thus, Hypothesis 5 that proposes
the existence of the IT steering committee is directly positively correlated with the overall effectiveness
of IT governance could not be supported. This finding is inconsistent with previous studies
            <xref ref-type="bibr" rid="ref21">(Vaswani et
al, 2008; Karimi, 2000)</xref>
            that found the IT steering committee positively influenced the level of IT
governance. A possible explanation is that, for these organizations, the IT strategy committee was
perceived as more effective in influencing the overall level of effective IT governance. It may also be
because senior management were considered to have good knowledge in IT and did not need any steering
committee in supporting their roles in governing the organizations IT. A third possible explanation is
that, on average, in the perception of the respondents, the IS steering committees were dysfunctional and
thus they did not contribute positively to an overall level of effective IT governance within the
organization.
          </p>
          <p>H3
1.066</p>
          <p>Effective</p>
          <p>IT Governance</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6 Summary, Contributions and Limitations</title>
      <p>
        This study examined empirically whether an ethic or culture of compliance in IT influences the overall
effectiveness of IT governance, and what factors affected this compliance. Other factors that influenced
the level of effective IT governance were also examined. Using sample responses from 122 internal
auditors, members of ISACA (Information Systems and Audit Control Association) Australia, this study
revealed that an ethic/culture of compliance in IT significantly influenced the level of IT governance.
Two factors were the main contributors: corporate communication systems and the involvement of senior
management in IT. Another factor that emerged as salient was the IT strategy committee.
This should really come as no surprise, for it is well in-line with many other studies that have shown the
importance of active senior management involvement in IT decision-making
        <xref ref-type="bibr" rid="ref29">(cf. Philip, 2007)</xref>
        .
        <xref ref-type="bibr" rid="ref29">Philip
(2007)</xref>
        notes that this involvement is manifested in two distinct fashions: by actively listening to IT
personnel when they discuss the role technology should play in the organization; and by acting decisively
to enact these roles. What our study found, in addition, is that doing so has the effect of creating and
permeating a strong ethic around the governance of IT in the organization as well.
      </p>
      <p>
        Interestingly, our study shows that the IT Steering Committee did not have a significant impact on
effective IT governance in the organization. Many point towards the utility of an ethics steering
committee in catalyzing and sustaining an embodied culture of ethics in the organization
        <xref ref-type="bibr" rid="ref40">(cf. Vitell and
Singhapakdi, 2008)</xref>
        . Our study does not support this contention, suggesting that this sort of committee
might in fact impede a culture of ethics in the organization by turning employees into “rule followers”
and the committee as enforcer. As a result, the emergence of cultural norms is impeded, not aided, by this
structure. Additional research is needed in order to determine which of these viewpoints dominates,
given the ubiquity of IT Steering Committees, and the axiomatic reliance on their good judgment as a
latent indicator of ethical compliance.
      </p>
      <p>This study advances our understanding of the roles of IT governance mechanisms and their impact on the
overall effectiveness of IT governance. In particular, this study found robust empirical evidence that (1)
the existence of ethics and a culture of compliance in IT is positively correlated with the overall
effectiveness of IT governance, and (2) the existence of IT strategy committee greatly enhances the
overall effectiveness of IT governance.</p>
      <p>
        The findings also suggest that the presence of communication systems is a positive influence on the ethics
and a culture of compliance in IT. As noted above, these communication systems are informal, as
epitomized by senior management leadership, as well as the more formal mechanisms used to inform
employees of technological innovations in organizations (newsletters, knowledge management system
repositories, training sessions, project rollout communications, etc…). Again, our study shows that the
mere fact of communicating has a positive effect on creating and sustaining a governance-centered
culture. It gives credence to the adage that “what is measured (or observed) matters”. The findings of this
study provide empirical results on the IT governance mechanisms that have been previously studied
mainly by normative and case study approaches
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref42 ref43">(IT Government Institute, 2003; Weill and Ross, 2004)</xref>
        .
Calling on the ethics and organizational literature
        <xref ref-type="bibr" rid="ref24 ref37">(Trevino et al., 1999; McCabe et al., 1996)</xref>
        , this study is
the first empirical study to examine the influence of an ethic/culture of compliance in the context of IT
governance. This finding contributes to the IT governance literature on the importance of an ethic/culture
of compliance in establishing effective IT governance.
      </p>
      <p>For managers, this study also points to a number of initiatives they might undertake to create an ethic and
culture of compliance around their information technologies. First and foremost, we would echo our
predecessors that state IT is too important to be left to the back-room. That is, IT should form a regular
part of manager’s agendas and be a regular topic of discussion – not just one engaged in when projects go
wrong. Moreover, we would suggest that these discussions take place within the senior ranks of the
organization, during and between strategic planning sessions. Secondly, we would advocate establishing
formal communications mechanisms (employee newsletter, blog or other written communication) that
would reinforce the culture of governance around IT throughout the organization. By doing so formally
(as part of ongoing planning) and informally (communications to all employees), this ethic of compliance
that we have witnessed in other areas (e.g., financial reporting and accounting) would likely emerge with
respect to information technology. More research is needed on this point to establish which mechanisms,
specifically, would be most effective in doing so.</p>
      <p>There are some limitations that should be highlighted when interpreting the study’s results. First, more
reliable measures of the overall effectiveness of IT governance in an organization need to be developed,
since subjective and indirect measures (based on internal auditor’s perceptions) do not provide the same
strength as objective measures might. Second, there are some issues of structural equation modeling
design that may have limited the external validity of the results, such as the limited sample size, and the
usage of a confirmatory model strategy instead of other strategies (e.g., a competing models strategy).
Further analysis using a competing models strategy may provide a richer and better understanding of the
structural relationships of the existing variables in the model. Our results are also limited by the fact that
all respondents were internal auditors, the bulk of whom (70%) described themselves as IS auditors, from
Australian companies. While we are confident that they are representative of all Australian companies,
cultural differences may lead to different results in other cultures. The fact that all participants were also
auditors limits the applicability of results to that population only. Further studies are needed in other
countries as well as with other types of managers to see if our results hold. For example, it might be
interesting to conduct a similar study with CIOs.</p>
      <p>
        To our knowledge, this study is the first to explicitly consider the link between an ethical or culture of
compliance and information technology governance. Previous studies have considered IT Governance to
be exogenous, that is, imposed on the organization by law
        <xref ref-type="bibr" rid="ref44">(e.g., the Sarbanes-Oxley Act of 2002)</xref>
        , by
industry standard (e.g., CoBIT, COSO, ITIL) and/or by industry bodies (e.g., ISO). A number of
researchers looking at broader governance issues
        <xref ref-type="bibr" rid="ref35">(cf. Shailer, 2004)</xref>
        have contended that good governance
should be, and is often the result of endogenous factors, those that emerge from within, not without. The
most salient of these factors appears to be a strong ethic towards governance in the organization. In this
study, we extend this argument to consider the special challenge associated with IT governance, and find
that an ethic of compliance emerges naturally from senior management leadership aimed at this area, and
from corporate communication systems that promote and reify this ethic throughout. In doing so, we not
only extend the corporate governance literature, we also contribute to conversations about the governance
of information assets in organizations. For researchers, it opens up a number of interesting avenues
where the specific modalities of an IT governance ethic could be explored. For managers, this study
points to a number of easily-implemented initiatives that might lead to greater oversight of this critical
area in their organizations.
      </p>
      <sec id="sec-6-1">
        <title>References:</title>
        <sec id="sec-6-1-1">
          <title>Variable</title>
          <p>Perceived overall
effective IT
governance
Involvement of
top management
in IT
Ethic/culture of
compliance</p>
          <p>Appendix A. Variable, Questions and Source of Constructs in the Study</p>
          <p>To what extent do you agree with the following: The current
individual IT governance mechanisms within my organizations IT
environment has a large, positive impact on the overall level of
effective IT governance within the organization.</p>
          <p>To what extent do you agree with the following: The current
individual IT governance mechanisms within my organization are an
important and valuable aid to implementing overall effective IT
governance within the organization
To what extent does top management get involved in strategic
matters related to the use of IT within the organization, outside of the
IT steering committee?
To what extent is top management knowledgeable about IT
opportunities and possibilities for the organization?
To what extent is top management knowledgeable about IT
innovations that have been developed by major competitors?
My organization (client organization) communications systems
enable the organization to inform its employees effectively about the
existence of IT governance mechanisms.</p>
          <p>The communication systems enable the organization to inform its
employees about IT governance decisions and processes throughout
the organization.</p>
          <p>The communication systems provide support in educating
organizations members in IT governance processes in the
organization.</p>
          <p>To what extent does your organization's ethic/culture of compliance
enable you to achieve objectives in IT?
To what extent does your organization's ethic/culture of compliance
enable you to circumvent any violation that could hinder organization
to achieve its IT objectives?
To what extent does top management provides leadership in an
ethic/culture of compliance related with IT objectives?
To what extent does IT strategy committee provide strategic direction
and the alignment of IT and the business issue?
To what extent does IT strategy committee provide direction for
sourcing and use of IT resources, skills and infrastructure to meet the
strategic objectives?
To what extent does IT strategy committee provides direction to
management relative to IT strategy?
To what extent does IT steering committee provide strategic direction
to IT project that are in line with the strategic directions of the
organization?
To what extent does the IT steering committee provide a mechanism
for coordinating IT practices?
To what extent does the IT steering committee provide leadership in
deriving benefits from IT?
Source</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Green</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Effective IT Governance Mechanisms in Public Sectors: An Australian Context</article-title>
          .
          <source>International Journal of Global Information Management</source>
          . Vol.
          <volume>15</volume>
          ,
          <string-name>
            <surname>Issue</surname>
            <given-names>4</given-names>
          </string-name>
          ,
          <fpage>41</fpage>
          -
          <lpage>63</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Beyer</surname>
            ,
            <given-names>J. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nino</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          : Ethics and Cultures in International Business,
          <source>Journal of Management Inquiry</source>
          .
          <volume>8</volume>
          (
          <issue>3</issue>
          ),
          <fpage>287</fpage>
          -
          <lpage>297</lpage>
          (
          <year>1999</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Coffin</surname>
          </string-name>
          , Bill.: Ethics and Compliance at Honda of America.
          <source>Risk Management. (Dec)</source>
          ,
          <volume>50</volume>
          ,
          <fpage>12</fpage>
          . (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <article-title>Committee of Sponsoring Organizations of the Treadway Committee (COSO).: Jersey City</article-title>
          , NJ: AICPA. (
          <year>1992</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <surname>Córdoba</surname>
          </string-name>
          ,
          <string-name>
            <surname>J-R.</surname>
          </string-name>
          :
          <source>A Critical Systems View of Power-Ethics Interactions in Information Systems Evaluation, Information Resources Management Journal</source>
          .
          <volume>20</volume>
          (
          <issue>2</issue>
          ),
          <fpage>74</fpage>
          -
          <lpage>89</lpage>
          . (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>De Haes</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grembergen</surname>
            ,
            <given-names>W. V.</given-names>
          </string-name>
          : IT Governance Structures, Processes and Relational Mechanisms: Achieving IT/Business Alignment in a Major Belgian Financial Group.
          <source>Proceedings of the 38th Hawaii International Conference on System Sciences. (</source>
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>Doll</surname>
            ,
            <given-names>W. J.</given-names>
          </string-name>
          :
          <article-title>Avenues for Top Management Involvement in Successful MIS Department</article-title>
          .
          <source>MIS Quarterly</source>
          .
          <volume>9</volume>
          (
          <issue>1</issue>
          ),
          <fpage>17</fpage>
          -
          <lpage>35</lpage>
          (
          <year>1985</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Dickson</surname>
            ,
            <given-names>M. W.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>D. B.</given-names>
            <surname>Smith</surname>
          </string-name>
          .,
          <string-name>
            <given-names>M.W.</given-names>
            <surname>Grojean</surname>
          </string-name>
          .,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ehrhart</surname>
          </string-name>
          .: Ethical Climate:
          <article-title>The Result of Interactions Between Leadership, Leadership Values, and Follower Values</article-title>
          .
          <source>Leadership Quarterly</source>
          .
          <volume>12</volume>
          ,
          <fpage>1</fpage>
          -
          <lpage>21</lpage>
          (
          <year>2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <given-names>El</given-names>
            <surname>Sawy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Omar A.</given-names>
            ,
            <surname>Pavlou</surname>
          </string-name>
          , Paul A.:
          <article-title>IT-Enabled Business Capabilities for Turbulent Environments</article-title>
          .
          <source>MIS Quarterly Executive</source>
          . Vol.
          <volume>7</volume>
          <issue>Issue 3</issue>
          ,
          <fpage>p139</fpage>
          -
          <lpage>150</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <surname>Farrar</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          :
          <source>Corporate Governance in Australia and New Zealand</source>
          . Oxford University Press (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>Filatotchev</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          :
          <article-title>Corporate Governance and the Firms Dynamics: Contingencies and Complementarities</article-title>
          .
          <source>Journal of Management Studies</source>
          .
          <volume>44</volume>
          (
          <issue>6</issue>
          ),
          <fpage>1041</fpage>
          -
          <lpage>1056</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <string-name>
            <surname>Goodhue</surname>
            ,
            <given-names>D.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thompson</surname>
            ,
            <given-names>R.L.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Task-Technology Fit</surname>
            and
            <given-names>Individual</given-names>
          </string-name>
          <string-name>
            <surname>Performance</surname>
          </string-name>
          .
          <source>MIS Quarterly (19:2)</source>
          , pp.
          <fpage>213</fpage>
          -
          <lpage>236</lpage>
          (
          <year>1995</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          <string-name>
            <surname>Hair</surname>
            ,
            <given-names>J.F.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>R.E.</given-names>
            <surname>Anderson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.L.</given-names>
            ,
            <surname>Tatham</surname>
          </string-name>
          .,
          <string-name>
            <given-names>W.C.</given-names>
            <surname>Black</surname>
          </string-name>
          .:
          <source>Multivariate Data Analysis 5th Ed. Upper Saddle River</source>
          , NJ: Prentice Hall (
          <year>1998</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          <string-name>
            <surname>Haes</surname>
            ,
            <given-names>S. D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grembergen</surname>
            ,
            <given-names>W. V.</given-names>
          </string-name>
          : IT Governance and
          <string-name>
            <given-names>Its</given-names>
            <surname>Mechanisms</surname>
          </string-name>
          .
          <source>Information Systems Control Journal</source>
          ,
          <volume>1</volume>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <string-name>
            <surname>Hardy</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>Coordinating IT Governance--A New Role for IT Strategy Committees</article-title>
          .
          <source>Information Systems Control Journal. 4</source>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          <string-name>
            <surname>Institute</surname>
          </string-name>
          , IT Governance (ITGI).
          <article-title>: Board Briefing on IT Governance</article-title>
          . IT Governance Institute (
          <year>2003a</year>
          ),
          <source>Visited 31 January</source>
          <year>2005</year>
          . http://www.isaca.org/Content/ContentGroups/ITGI3/Resources1/Board_Briefing_on_IT_Govern ance/26904_Board_Briefing_final.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <string-name>
            <surname>Institute</surname>
          </string-name>
          , IT Governance (ITGI).
          <source>: IT Governance Global Status Report</source>
          <year>2003</year>
          (2003b,)
          <article-title>Visited 1 February 2005</article-title>
          . Http://www.itgi.org/Template_ITGI.cfm?Section=ITGIandCONTENTID=14539andTEMPLAT E=/ContentManagement/ContentDisplay.cfm.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          ISACA.:
          <article-title>The 2004 Annual Report (</article-title>
          <year>2004</year>
          ),
          <article-title>Visited 1 April 2005</article-title>
          . Http://www.isaca.org/Content/ContentGroups/Annual_Report/2004- Annual-Report.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          <string-name>
            <surname>Jarvenpaa</surname>
            ,
            <given-names>S.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ives</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Executive Involvement and Participation in the Management of Information Technology</article-title>
          .
          <source>MIS Quarterly</source>
          .
          <volume>15</volume>
          (
          <issue>2</issue>
          ),
          <fpage>205</fpage>
          -
          <lpage>227</lpage>
          (
          <year>1991</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          <string-name>
            <surname>Jensen</surname>
            ,
            <given-names>M.C.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>W.H.</given-names>
            <surname>Meckling</surname>
          </string-name>
          .:
          <article-title>Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure</article-title>
          .
          <source>Journal of Financial Economics</source>
          . Vol.
          <volume>3</volume>
          , No.
          <volume>4</volume>
          ,
          <fpage>305</fpage>
          -
          <lpage>360</lpage>
          (
          <year>1976</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          <string-name>
            <surname>Karimi</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bhattacherjee</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gupta</surname>
            ,
            <given-names>Y. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Somers</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>M.:</surname>
          </string-name>
          <article-title>The Effect of MIS Steering Committees on Information Technology Management Sophistication</article-title>
          ,
          <source>Journal of Management Information Systems</source>
          .
          <volume>17</volume>
          (
          <issue>fall</issue>
          , 2),
          <fpage>207</fpage>
          -
          <lpage>230</lpage>
          (
          <year>2000</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          <string-name>
            <surname>Lobel</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <article-title>The Renew Deal: The Fall of Regulation and the Rise of Governance in Contemporary Legal Thought</article-title>
          .
          <source>Minnesota Law Review</source>
          .
          <volume>89</volume>
          (
          <issue>2</issue>
          ),
          <fpage>342</fpage>
          -
          <lpage>471</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <string-name>
            <surname>McAfee</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Mastering the Three Worlds of Information Technology</article-title>
          .
          <source>Harvard Business Review. November</source>
          ,
          <volume>84</volume>
          (
          <issue>11</issue>
          ),
          <fpage>141</fpage>
          -
          <lpage>149</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          <string-name>
            <surname>McCabe</surname>
            ,
            <given-names>D.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Trevino</surname>
            ,
            <given-names>L.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Butterfield</surname>
          </string-name>
          , K.D.:
          <article-title>The Influence of Collegiate and Corporate Codes of Conduct on Ethics-related behavior in the Workplace</article-title>
          .
          <source>Business Ethics Quarterly</source>
          .
          <volume>6</volume>
          ,
          <fpage>461</fpage>
          -
          <lpage>476</lpage>
          (
          <year>1996</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          <string-name>
            <surname>McKeen</surname>
            ,
            <given-names>J. D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guimaraes</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Selecting MIS Projects by Steering Committee</article-title>
          .
          <source>Communications of the ACM</source>
          ,
          <volume>28</volume>
          (
          <issue>12</issue>
          ),
          <fpage>1344</fpage>
          -
          <lpage>1352</lpage>
          (
          <year>1985</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          <string-name>
            <surname>Meyer</surname>
          </string-name>
          , N. D.:
          <source>Systemic IS Governance: An Introduction. Information Systems Management</source>
          ,
          <volume>21</volume>
          (
          <issue>4</issue>
          ),
          <fpage>23</fpage>
          -
          <lpage>34</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          <string-name>
            <surname>Nolan</surname>
            ,
            <given-names>R. L.</given-names>
          </string-name>
          :
          <article-title>Managing Information Systems by Committee</article-title>
          .
          <source>Harvard Business Review</source>
          .
          <fpage>72</fpage>
          -
          <lpage>79</lpage>
          (
          <year>1982</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          <string-name>
            <surname>Parent</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>B.H.</given-names>
            <surname>Reich</surname>
          </string-name>
          .: Governing IT Risk. California Management Review. Forthcoming, spring,
          <source>MarApr</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          <string-name>
            <surname>Philip</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>IS Strategic Planning for Operational Efficiency</article-title>
          .
          <source>Information Systems Management</source>
          .
          <volume>24</volume>
          ,
          <issue>3</issue>
          (
          <issue>summer</issue>
          ),
          <fpage>247</fpage>
          -
          <lpage>264</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          <string-name>
            <surname>Picou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>M.J.</given-names>
            <surname>Rubach</surname>
          </string-name>
          .:
          <article-title>Does Good Governance Matter to Institutional Investors? Evidence from the Enactment of Corporate Governance Guidelines</article-title>
          .
          <source>Journal of Business Ethics</source>
          .
          <volume>65</volume>
          ,
          <fpage>55</fpage>
          -
          <lpage>67</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          <string-name>
            <surname>Ragunathan</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ragunathan</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <source>MIS Steering Committees: Their Effect on Information Systems Planning. Journal of Information Systems</source>
          .
          <volume>104</volume>
          -
          <fpage>116</fpage>
          (
          <year>1989</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          <string-name>
            <surname>Roberts</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          :
          <source>Corporate Governance and the Ethics of Narcissus. Business Ethics Quarterly</source>
          .
          <volume>11</volume>
          (
          <issue>1</issue>
          ),
          <fpage>109</fpage>
          -
          <lpage>127</lpage>
          (
          <year>2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          <string-name>
            <surname>Schein</surname>
            ,
            <given-names>E. H.</given-names>
          </string-name>
          :
          <article-title>Organizational Culture and Leadership</article-title>
          . 2nd
          <string-name>
            <given-names>Edition</given-names>
            <surname>Jossey-Bass</surname>
          </string-name>
          , San Fransisco (
          <year>1992</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          <string-name>
            <surname>Schwartz</surname>
          </string-name>
          , Mark S.:
          <article-title>Effective Corporate Codes of Ethics: Perceptions of Code User</article-title>
          .
          <source>Journal of Business Ethics</source>
          .
          <volume>55</volume>
          ,
          <fpage>323</fpage>
          -
          <lpage>343</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          <string-name>
            <surname>Shailer</surname>
            ,
            <given-names>G.E.P.:</given-names>
          </string-name>
          <article-title>An Introduction to Corporate Governance in Australia. Frenchs Forest NSW: Pearson Education Australia (</article-title>
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          <string-name>
            <surname>Steiner</surname>
            ,
            <given-names>G. A.</given-names>
          </string-name>
          :
          <article-title>Strategic Planning: What Every Manager Must Know</article-title>
          . New York: Free Press (
          <year>1979</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          <string-name>
            <surname>Trevino</surname>
            ,
            <given-names>L. K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weaver</surname>
            ,
            <given-names>G. R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gibson</surname>
            ,
            <given-names>D. G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Toffler</surname>
            ,
            <given-names>B. L.</given-names>
          </string-name>
          :
          <article-title>Managing Ethics and Legal Compliance: What Works and What Hurts</article-title>
          .
          <source>California Management Review. Winter</source>
          <volume>41</volume>
          (
          <issue>2</issue>
          ),
          <fpage>131</fpage>
          -
          <lpage>151</lpage>
          , (
          <year>1999</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          <string-name>
            <surname>Verschoor</surname>
            ,
            <given-names>C.C.</given-names>
          </string-name>
          :
          <article-title>Does Superior Governance Still Lead to Better Financial Performance? Strategic Finance</article-title>
          , Oct-
          <volume>4</volume>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          <string-name>
            <surname>Vaswani</surname>
          </string-name>
          , Ravi.:
          <article-title>Determinants of Effective Information Technology (IT) Governance</article-title>
          .
          <source>Unpublished Thesis</source>
          . School of Business, University of Queensland, Australia (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          <string-name>
            <surname>Vitell</surname>
            ,
            <given-names>S.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Singhapakdi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>The Role of Ethics Institutionalization in Influencing Organizational Commitment, Job Satisfaction</article-title>
          , and Esprit de Corps.
          <source>Journal of Business Ethics</source>
          .
          <volume>81</volume>
          (
          <issue>2</issue>
          ),
          <fpage>343</fpage>
          -
          <lpage>353</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          <string-name>
            <surname>Weaver</surname>
            ,
            <given-names>G.R;</given-names>
          </string-name>
          <string-name>
            <surname>Trevino</surname>
            ,
            <given-names>L.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cochran</surname>
            ,
            <given-names>P.L.</given-names>
          </string-name>
          :
          <article-title>Corporate Ethics Practices in the mid-1990s: An empirical Study of the Fortune 1000</article-title>
          , Journal of Business Ethics. (
          <year>1990</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          <string-name>
            <surname>Weill</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Don't Just</surname>
            <given-names>Lead</given-names>
          </string-name>
          ,
          <article-title>Govern: How Top-Performing Firms Govern IT</article-title>
          . CISR Working Paper: CISR MIT. (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          <string-name>
            <surname>Weill</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ross</surname>
            ,
            <given-names>J. W.</given-names>
          </string-name>
          : IT Governance.:
          <article-title>How Top Performers Manage IT Decision Rights for Superior Results</article-title>
          , Boston, Massachusetts: Harvard Business School Press. (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          <string-name>
            <surname>Williams</surname>
          </string-name>
          , Paul.: IT Management:
          <article-title>The Future of the IT Organization: How IT governance can help stop scandal (2002), visited 1 October 2007 at www</article-title>
          .
          <source>computerWeekly.com.</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>