A bad technology decision costs money. An unmade technology decision costs more, consistently, and almost never shows up as a line item anywhere — because nothing was spent, nothing was approved, and the cost hides entirely in what didn’t happen instead of what did.
I’ve written about the governance gap between decision rights and feedback loops. This is the cost that accumulates on the other side of that gap — not a decision made badly, but a decision genuinely never made at all, deferred indefinitely because deferral, unlike a wrong call, never shows up as a visible mistake.
Why indecision is the invisible failure mode
A platform migration approved and later found wrong produces a visible, attributable cost — a project, a budget line, a post-mortem. A platform migration that’s been “under consideration” for eighteen months produces no visible cost at all, on any spreadsheet, even though the organisation has spent those eighteen months paying the old platform’s licensing, absorbing its limitations, and losing whatever the new platform would have delivered — a real cost, compounding monthly, that never appears anywhere because no decision was ever made to compare it against.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
This asymmetry is precisely why indecision persists longer than a bad decision would: a bad decision eventually gets noticed, escalated, and corrected, because it produces a visible, attributable failure. An absent decision produces no failure to notice — only a slowly accumulating opportunity cost that nobody is specifically tasked with measuring, because measuring the cost of something that didn’t happen requires deliberately constructing a counterfactual, which almost nobody does under normal operating pressure.
Where this actually costs the most
Technical debt left unaddressed because the decision to fund remediation never gets made, compounding at the rate I’ve written about separately — every month of deferral is a month the debt’s interest accrues invisibly. A vendor relationship left unrenegotiated because nobody owns the decision to push back on unfavourable terms, silently costing the difference between the current price and what a genuine negotiation or a credible alternative would have achieved. An architecture decision left ambiguous because two stakeholders disagree and nobody has the standing to force a resolution, leaving teams building on an uncertain foundation that eventually requires rework proportional to how long the ambiguity persisted.
Each of these shares the same signature: real, ongoing cost, attributable to nobody, because the decision that would have crystallised it into something visible was never actually made.
Why organisations default to indecision
Deferring a decision feels, in the moment, like avoiding risk — no commitment made, no chance of being wrong. It’s actually a decision with its own risk profile, just one that’s invisible because it was never named as a choice: choosing the status quo, actively, has the same consequence as choosing it passively, but only the active choice gets scrutinised, discussed, and held accountable. The passive version simply persists, unexamined, because nobody ever framed “keep doing nothing” as the decision it actually is.
The fix is procedural, not motivational: treat “no decision made” as a tracked state with its own cost estimate and its own forced review date, the same discipline I’ve written about for technology risk registers generally — a decision genuinely deferred, with an owner and a revisit date, is a legitimate choice. A decision that’s simply never been forced into the open is an invisible, compounding cost with nobody’s name on it.
What naming the cost actually changed
A logistics firm had been “evaluating” a replacement for its ageing dispatch system for over two years, with the evaluation itself never formally closed and never formally abandoned — simply persisting, unowned, on a list nobody was accountable for moving forward. Naming the actual cost of that persistence — calculated honestly, against the licensing, workaround labour, and lost efficiency the old system was quietly costing every month — turned an abstract, indefinitely-deferred question into a number large enough that funding a genuine decision process, one way or the other, became the obvious choice within a single budget cycle. The number had been there the entire two years. Nobody had ever calculated it. That calculation took an afternoon once someone was actually tasked with doing it — considerably less time than the two years it went unasked.
Surfacing which consequential technology decisions in an organisation have quietly never been made — and what that indecision has actually cost so far — is exactly the kind of diagnostic a technology control assessment is built to run.
Indecision compounds the same way audit gaps do — see audit readiness as a continuous state for the compliance-specific version of this pattern.
Most organisations, asked directly, can name at least one decision that’s been quietly pending for longer than anyone would admit out loud. Naming it, and pricing what the delay has actually cost, is usually enough to move it.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming