This analysis serves two purposes. First, it establishes exactly which framework controls would have prevented specific failures. Second, it identifies failures lying entirely beyond the reach of existing frameworks—a gap with significant implications for the governance of high-stakes digital systems.
8.1. Mapping Failures to Framework Controls
Table 6 and
Figure 2 presents a systematic mapping of the five failure categories identified in this paper against specific controls within seven frameworks: ISO/IEC 27001 [
52], NIST SP 800-53 Rev. 5 [
53], NIST SP 800-218 (SSDF) [
54], COBIT 2019 [
55], ISO/IEC 27035 [
11], NIST SP 800-61 [
56], and ISO/IEC 27036 [
57,
58]. ISO/IEC 27037 [
12]—the standard governing digital evidence handling—is additionally applied given its direct relevance to the investigative failures documented in
Section 6. NIST SP 800-92 [
59] is applied to log management failures. Remote access controls and supplier management obligations are treated within the log management and other failures categories, respectively, consistent with their classification in
Table 4.
Method and criteria. The mapping in
Table 6 was produced through directed content analysis [
60]: the full control set of each of the nine framework documents applied in this study was read in its entirety and recorded systematically in a spreadsheet against the documented Horizon failure descriptions catalogued earlier in this paper. A control was judged to match a failure where its stated requirement directly addressed the specific technical or procedural deficiency documented for that failure—for example, a control mandating pre-deployment testing was matched to a failure involving an undetected pre-deployment defect. The matched requirement is quoted alongside each failure category in
Table 6, allowing the basis for every mapping to be inspected directly rather than taken on trust.
Limitations. The mapping reflects expert judgement rather than a formally validated coding protocol. Every control within each framework’s published control set was reviewed systematically, rather than only those controls already anticipated to be relevant, but no second, independent review of the resulting mappings was conducted, and no inter-rater reliability statistic is therefore reported. The mapping should accordingly be read as a transparent, criterion-based single-pass analysis rather than as a consensus-validated systematic review.
The mapping reveals consistent and substantial coverage of every failure category across multiple frameworks. The absence of these controls from Horizon’s governance was not a consequence of inadequate frameworks but of their wholesale non-application.
8.2. Counterfactual Analysis: The Conditional Preventive Value of Framework Compliance
The framework mapping presented in
Table 6 demonstrates that every major failure category identified in the Horizon scandal was addressed by controls that existed within recognised cyber security, software assurance, incident response, and supplier governance frameworks during the relevant period. No category of failure identified in this study lacked an applicable governance mechanism.
This finding is significant because it challenges interpretations of the scandal that attribute the failures primarily to the absence of suitable standards or governance frameworks. Controls addressing software quality, change management, audit logging, incident investigation, evidential integrity, and supplier oversight were already established and widely recognised throughout much of Horizon’s operational lifetime. The issue was therefore not the absence of good practice, but the failure to implement, enforce, and act upon it.
The mapping further demonstrates that these controls were not isolated requirements contained within a single framework. Rather, the principal failure categories identified in this study were addressed repeatedly across multiple frameworks. Software defects were subject to testing, defect-management, and change-control requirements; audit logging failures were addressed through controls governing privileged access, audit record generation, and log review; investigative failures were covered by incident response and evidential integrity standards; and supplier governance weaknesses were addressed through vendor oversight and independent assurance requirements. This degree of overlap strengthens confidence that the failures identified were not governance blind spots but recognised risks for which established controls already existed.
The counterfactual conclusion must nevertheless be carefully bounded, and its method, assumptions, scope, and limitations are made explicit here.
Method and assumptions. The reasoning applied is a necessary-condition test [
61]: each control is treated as a barrier that, where genuinely implemented and permitted to operate as designed [
62], would have constituted a necessary obstacle to the documented failure pathway. This is a substantially weaker claim than sufficiency, and rests on the assumption that the relevant control was implemented in good faith and acted upon—an assumption
Section 8.3 shows did not hold in several instances. The analysis is also conducted at the level of the documented incident rather than a full system simulation, and frameworks published after the Horizon-era events in question (notably NIST SP 800-218, 2022, and ISO/IEC 27036-3, 2021) are treated as articulating retrospectively-recognised good practice rather than instruments available for contemporaneous adoption.
Scope and limitations. The claims are confined to the technical and procedural categories in
Table 6 and do not extend to the institutional and incentive-based failures examined in
Section 8.3. They are also necessarily retrospective, cannot be verified through a controlled counterfactual test, and are susceptible to hindsight bias [
63]. The claim advanced here is therefore narrower: the frameworks available during Horizon’s operational lifetime contained controls capable of preventing, exposing, or substantially mitigating many of the failures identified in this study, provided those controls were implemented in good faith and permitted to perform their intended corrective function. This qualification exposes a deeper question. If recognised frameworks already contained controls capable of addressing the principal technical and procedural failures, why did those controls fail to constrain organisational behaviour? The answer lies not in the frameworks themselves, but in the institutional environment within which they operated. Horizon therefore points towards a failure that extends beyond the scope of conventional cyber security and IT governance frameworks, leading directly to the governance gap examined in the following section.
8.3. The Governance Gap: Institutional Failures Beyond Framework Reach
The preceding analysis reveals a more significant finding. Existing cyber security, software assurance, and IT governance frameworks provide substantial coverage of technical failure modes, including software quality, change management, audit logging, supplier oversight, incident response, and evidential integrity. However, they are considerably less effective in addressing institutional failures arising from conflicts of interest, organisational incentives, and deliberate suppression of adverse information.
The Horizon scandal illustrates a failure mode in which the Post Office simultaneously occupied the roles of system operator, investigator, prosecutor, and alleged victim. In such circumstances, organisational incentives may actively favour the minimisation of defects, resistance to scrutiny, and suppression of contradictory evidence. Existing frameworks provide only limited protection against this scenario because they govern the mechanics of assurance and compliance rather than the incentive structures within which those mechanisms operate.
This limitation is evident in several of the most consequential aspects of the scandal. The suppression of expert concerns raised by Second Sight, Jason Coyne, and Fujitsu personnel; the withholding of PEAKs and KELs from defence teams; the continued reliance upon system-generated evidence despite known reliability concerns; and the use of private prosecutions without independent oversight are not failures readily addressed through conventional security controls. Rather, they reflect organisational decisions taken despite the existence of information indicating that serious problems existed.
This distinction is important. The Horizon scandal was not caused primarily by the absence of suitable governance frameworks. Nor does the evidence suggest that the frameworks themselves were technically inadequate. Instead, the scandal demonstrates that governance frameworks generally assume organisations possess a genuine interest in identifying, disclosing, and correcting failures. Where institutional incentives favour denial, reputational protection, financial preservation, or prosecutorial success, those assumptions may no longer hold.
This gap is not a complete absence of legal constraint.
Section 3 of the Criminal Procedure and Investigations Act 1996 imposes a clear statutory duty on prosecutors, including private prosecutors acting under section 6(1) of the Prosecution of Offences Act 1985, to disclose any material that might reasonably be considered capable of undermining the prosecution case or assisting the defence. The Post Office was advised of this obligation in explicit terms by external counsel during the relevant prosecution period, yet the Court of Appeal in
Hamilton and others v Post Office Limited [
64] later found that the Post Office had failed to discharge this duty so comprehensively that the prosecution of the Horizon cases amounted to an abuse of process, quashing thirty-nine convictions on that basis. The relevant legal mechanism therefore existed, and its existence was known to the Post Office at the time; what failed was its enforcement in real time. Compliance depended on the same organisation that held the institutional incentive to suppress the material choosing to identify and disclose it voluntarily, and correction was available only retrospectively, through appeal, years after the prosecutions had concluded and the harm had occurred. This finding motivates the Institutional Independence pillar of the LADS proposal set out in
Section 8.4: rather than relying on a self-policed disclosure duty enforced only after the fact, a structural separation between the entity controlling system-generated evidence and the entity prosecuting on the basis of it would remove the dependency on voluntary compliance that failed here.
The consequences of this limitation are particularly acute when digital systems generate evidence used within legal proceedings. In such contexts, the failure to disclose defects, logs, warnings, or investigative findings can produce wrongful convictions rather than merely operational disruption. Horizon therefore exposes a governance gap that extends beyond software assurance and cyber security: even where, as here, a relevant legal disclosure duty exists, its dependence on voluntary compliance and retrospective correction proved insufficient to prevent wrongful conviction on this scale.
Accordingly, the principal lesson arising from this analysis is not that additional technical controls are required, but that future governance models for evidential systems must incorporate stronger forms of independent oversight, transparency, and challenge. Without such safeguards, even organisations operating within formally compliant governance environments may be capable of neutralising the corrective functions those frameworks were designed to provide.
8.4. Legally-Accountable Digital Systems: A Proposed Governance Extension
We propose that systems whose outputs are used directly as evidence in criminal or civil legal proceedings constitute a distinct governance category warranting supplementary requirements beyond those of existing cyber security frameworks. We term these Legally-Accountable Digital Systems (LADS). While Horizon is the foundational example, this category applies to any platform where automated outputs serve as legal evidence of individual culpability. Examples include automated fraud detection, financial monitoring, benefits management, and AI-assisted public administration systems.
LADS is intended as a supplementary governance category, not a replacement for the technical and legal mechanisms already discussed in this paper, and its relationship to each is worth making explicit. The cyber security and software assurance frameworks mapped in
Section 8.1 (ISO/IEC 27001, NIST SP 800-53, the SSDF, COBIT 2019, and related standards) govern the technical and procedural quality of a system; they do not address the institutional incentive structures examined in
Section 8.3, and LADS does not seek to duplicate them. ISO/IEC 27037 [
12], applied as a minimum condition under the Technical Independence pillar below, specifies how digital evidence should be handled once it has been identified as relevant, including chain-of-custody documentation; it does not require that the verifying party be independent of the system operator, which is the gap the Technical Independence pillar is intended to close. The disclosure duty under section 3 of the Criminal Procedure and Investigations Act 1996, discussed in
Section 8.3, already requires prosecutors to disclose material capable of undermining their case; the Institutional Independence pillar differs from this existing duty by removing the dependency on voluntary self-assessment, requiring structural separation between the entity controlling the evidence and the entity prosecuting on the basis of it, rather than relying on that entity to identify and disclose adverse material itself. The common law presumption that computer evidence is reliable absent a positive challenge, which Lloyd [
2] argues is poorly suited to complex networked software, is addressed directly by the Forensic Admissibility Governance pillar, which proposes replacing this presumption with a requirement for positive, independently issued certification. LADS is therefore best understood as drawing together gaps left at the boundaries of three existing regimes—technical assurance frameworks, criminal disclosure law, and the evidential presumption of reliability—rather than as a wholly new field of regulation.
We propose three supplementary governance pillars for LADS, each targeting a dimension of failure that existing frameworks do not address.
Technical Independence. All audit trails, logging mechanisms, and patch deployment records in a LADS must be verified by an independent technical body with no contractual relationship to either the system operator or any prosecuting authority. Compliance with ISO/IEC 27037 [
12] should be a minimum condition for the admissibility of system-generated evidence, but independent verification—analogous to statutory financial audit requirements—should be mandated in law rather than left to organisational discretion. This addresses the Horizon failure in which the same organisation that operated the system also controlled access to its audit records.
Institutional Independence. The organisation operating a LADS must be structurally separated from the investigatory and prosecutorial functions in any proceeding where system-generated data is used as evidence. This separation should be a legal prerequisite for private prosecution, and should include mandatory disclosure to defence teams of all known system faults, error logs, and expert assessments—regardless of whether the operating organisation considers them material to the proceedings. The Horizon case demonstrates conclusively that self-assessment of materiality by an interested party cannot be relied upon as a safeguard against wrongful conviction.
Forensic Admissibility Governance. System-generated data should not be admissible as evidence of individual culpability without prior software reliability certification, issued independently of the system operator and renewed after each significant software update. Such certification should require documented evidence of full regression testing, patch governance compliance, and audit trail integrity verification. The existing legal presumption of computer reliability—which Lloyd [
2] identifies as more applicable to hardware than to complex networked software systems—should be replaced with a rebuttable standard requiring positive certification of reliability, rather than the current absence of challenge.
Implementation, funding, and enforcement. The three pillars set out above establish the governance principle that should apply to a LADS; they do not, by themselves, specify a fully designed regulatory architecture, since the appropriate institutional model is a policy question requiring dedicated research beyond the scope of this paper. At least three institutional models are plausible. The first is a newly created statutory regulator with defined powers, a defined scope, and the capacity to impose penalties, analogous to the Public Company Accounting Oversight Board established under the Sarbanes-Oxley Act discussed below. The second is an extension of an existing body’s remit; the Forensic Science Regulator, which already accredits forensic science methods and providers in England and Wales, is one plausible candidate, since system-generated digital evidence verification is conceptually close to its existing function. The third is a funding model analogous to statutory financial audit, in which the audited organisation pays for independent verification but has no control over the verifier’s appointment, findings, or professional obligations. Each model would also need to confront a genuine structural difficulty that existing oversight regimes for less complex systems do not face to the same degree: for a proprietary, decades-old system such as Horizon, the pool of people with sufficient technical understanding to verify it may overlap substantially with those who built or maintained it. Mitigating this would likely require, at minimum, mandatory technical documentation and handover requirements imposed on system operators at the point of deployment, so that independent verification does not depend on the original development team, together with an accreditation scheme for technical experts that excludes current commercial relationships with the system operator. Which of these institutional models is most appropriate, how compliance would be funded in practice, and what specific powers and penalties an enforcement body should hold are questions this paper leaves open for future policy research; the contribution made here is the governance principle that independent verification should be structurally mandated, not the detailed architecture of the body that would carry it out.
The closest historical parallel for the kind of statutory intervention these pillars require is the Sarbanes-Oxley Act of 2002 [
65], enacted in the United States in direct response to the Enron and WorldCom accounting scandals. Sarbanes-Oxley mandated independent financial auditing, created the Public Company Accounting Oversight Board as a dedicated statutory regulator with a defined scope and enforcement powers, and introduced enhanced criminal penalties for obstruction of justice—all legislative responses to failures of institutional incentive rather than failures of technical process. The parallel with Horizon is instructive rather than exact. Both cases share the same underlying mechanism, in which institutional incentives to suppress adverse information amplified the harm caused by an initial technical or accounting failure, and in both cases the resulting harm fell on parties who lacked the power to independently verify the system or process used against them. Sarbanes-Oxley, however, resolved the question of institutional design at the point of legislation, establishing a single purpose-built regulator with a defined scope and statutory penalties from the outset; LADS, as proposed here, does not yet have an equivalent settled architecture, and the discussion above leaves open whether a comparable new regulator should be created or whether an existing body’s remit should be extended. The analogy is therefore offered to demonstrate that legislative intervention of this scale, in response to institutional incentive failure rather than mere technical inadequacy, has a precedent and a track record, not to claim that LADS should replicate Sarbanes-Oxley’s institutional design without further work.
The Post Office Horizon Public Inquiry dataset provides an empirical foundation for equivalent legislative progress in the governance of legally-accountable digital systems. The breadth and granularity of the inquiry materials—witness testimony, technical documents, internal communications, and audit records spanning more than two decades—offer researchers and policymakers a resource comparable in significance to the Enron materials that informed a generation of corporate governance reform. The inquiry’s final report represents a legislative opportunity that, if taken, could do for digital evidence governance what Sarbanes-Oxley did for financial reporting: establish independent oversight, mandatory disclosure, and enforceable accountability as structural requirements rather than organisational aspirations. The LADS governance pillars proposed above provide a starting framework for what that statutory intervention should require, grounded in systematic analysis of a case that is, in its combination of technical, institutional, and legal failures, without precedent in the history of British computing.