<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-28-2169</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v28i1.2169</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A conceptual governance framework for managing robotic process automation implementation challenges in insurance claims handling</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0009-0006-7852-7963</contrib-id>
<name>
<surname>Pietersen</surname>
<given-names>Lee-Ann</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0009-0004-5788-1387</contrib-id>
<name>
<surname>Lefela</surname>
<given-names>Teboho D.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-6290-8546</contrib-id>
<name>
<surname>Lamprecht</surname>
<given-names>Christiaan</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>School of Accountancy, Faculty of Economic and Management Sciences, Stellenbosch University, Stellenbosch, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Christiaan Lamprecht, <email xlink:href="clam@sun.ac.za">clam@sun.ac.za</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>06</day><month>08</month><year>2026</year></pub-date>
<pub-date pub-type="collection"><year>2026</year></pub-date>
<volume>28</volume>
<issue>1</issue>
<elocation-id>2169</elocation-id>
<history>
<date date-type="received"><day>18</day><month>02</month><year>2026</year></date>
<date date-type="accepted"><day>05</day><month>06</month><year>2026</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026. The Authors</copyright-statement>
<copyright-year>2026</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>Although insurers increasingly adopt Robotic Process Automation (RPA) to improve efficiency and accuracy in insurance claims handling, implementation projects may fail when information flows, data practices, technical capabilities and operational processes are poorly governed (hereinafter challenges). These challenges can create misalignment between business and information technology (IT) objectives and limit the sustained value of RPA initiatives.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>Building on prior research that identified key RPA implementation challenges, this study developed a theoretically informed governance framework to assist insurers in governing and managing RPA within the insurance claims-handling process.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>This study adopted a qualitative, non-empirical research design informed by a structured literature review. Governance guidelines were developed based on insights from the literature and mapped to the Control Objectives for Information and Related Technologies 2019 (COBIT 2019) governance and management objectives to ensure completeness and depth. The COBIT 2019 framework was used as a structuring mechanism to operationalise theoretical principles into actionable governance practices.</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>The resulting conceptual framework integrates theoretical lenses from IT governance, data governance and IT capability theory to address the challenges of RPA implementation. The framework provides a structured tool for identifying and managing RPA-related challenges in insurance claims handling.</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>The study demonstrates that effective RPA implementation requires governance mechanisms that extend beyond strategic considerations to address detailed technical and operational challenges.</p>
</sec>
<sec id="st6">
<title>Contribution</title>
<p>This study contributes to the literature by offering a theoretically grounded governance framework for managing RPA in insurance claims handling, supporting improved alignment, accountability and control over automation initiatives in information-intensive processes.</p>
</sec>
</abstract>
<kwd-group>
<kwd>claims-handling process</kwd>
<kwd>COBIT 2019</kwd>
<kwd>data governance</kwd>
<kwd>digital process automation</kwd>
<kwd>information management</kwd>
<kwd>insurance industry</kwd>
<kwd>IT governance</kwd>
<kwd>robotic process automation</kwd>
</kwd-group>
<funding-group>
<funding-statement><bold>Funding information</bold> The authors received no financial support for the research, authorship and/or publication of this article.</funding-statement>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>The global general insurance sector has experienced accelerated growth since 2020, with a market size of approximately $5.94 trillion as of 2022 (Tasdemir &#x0026; Alsu <xref ref-type="bibr" rid="CIT0041">2024</xref>). In today&#x2019;s insurance environment, effectively assessing and handling claims risk is crucial for maintaining financial stability and enhancing operational efficiency (Surya et al. <xref ref-type="bibr" rid="CIT0039">2024</xref>). In doing so, insurers rely heavily on the efficiency and effectiveness of the claims-handling process to manage customer satisfaction and increase their competitive advantage in the insurance industry (Yusuf, Ajemunigbohun &#x0026; Alli <xref ref-type="bibr" rid="CIT0052">2017</xref>).</p>
<p>The claims-handling process represents an information-intensive operational environment. Enhancing the speed, accuracy and quality of this process not only reduces administrative costs but also decreases the risks to which insurers are exposed, thereby improving service excellence and strengthening customer trust (Yusuf et al. <xref ref-type="bibr" rid="CIT0052">2017</xref>). To achieve these objectives, insurers increasingly employ digital technologies to streamline and automate repetitive administrative tasks and optimise the claims-handling process. Yusuf and Ajemunigbohun (<xref ref-type="bibr" rid="CIT0051">2015</xref>), however, warn that the modernisation of the claims-handling process is not as simple as it seems, owing to its high degree of integration within an insurance organisation, which increases risks and complexity. Improving the governance of robotic process automation (RPA) in claims handling is important because claims performance directly affects customer trust, financial stability and operational resilience within insurers.</p>
<p>One of the most promising technologies for optimising claims-handling administrative processes is RPA (Lamberton, Brigo &#x0026; Hoy <xref ref-type="bibr" rid="CIT0024">2017</xref>; Madakam, Holmukhe &#x0026; Jaiswal <xref ref-type="bibr" rid="CIT0025">2019</xref>). As an information-driven automation technology, RPA fundamentally reshapes how information is captured, processed, validated and acted upon across multiple systems within the claims-handling process. Robotic process automation utilises software robots to automate rule-based tasks that are typically performed by humans, interacting directly with existing systems and applications within an organisation without modifying their underlying code (Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Madakam et al. <xref ref-type="bibr" rid="CIT0025">2019</xref>). Within the insurance claims-handling process, RPA typically automates repetitive tasks such as data collection, claims validation and payment processing, thereby reducing the time required and improving accuracy (Smit <xref ref-type="bibr" rid="CIT0037">2009</xref>).</p>
<p>Despite their potential benefits, an estimated 30&#x0025; &#x2013; 50&#x0025; of these RPA projects fail to scale or are abandoned after pilot implementation (Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>, as cited in Sigur&#x00F0;ard&#x00F3;ttir <xref ref-type="bibr" rid="CIT0036">2018</xref>). This high failure rate highlights the importance of robust governance processes in one of the most critical functions of an insurer: aligning automation projects with organisational objectives and risk appetite. Lessons from past crises, such as the global financial crisis, underscore the need to redesign corporate governance to manage information technology (IT)-related risks in financial services, including insurance (Hilb <xref ref-type="bibr" rid="CIT0016">2011</xref>).</p>
<p>Prior research identifies the alignment of IT and business objectives as a key factor in achieving technology success (Goosen &#x0026; Rudman <xref ref-type="bibr" rid="CIT0013">2013</xref>). When this alignment is not achieved, challenges arise from miscommunication between business expectations and the delivery of technological services (Goosen &#x0026; Rudman <xref ref-type="bibr" rid="CIT0013">2013</xref>; Smit <xref ref-type="bibr" rid="CIT0037">2009</xref>). These challenges frequently arise in RPA projects, including inadequate ownership, weak data governance, insufficient change management and a lack of accountability (Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>).</p>
<p>Although RPA is no longer a new technology, unresolved implementation bottlenecks continue to limit the value realised from RPA projects, particularly where organisations lack process standardisation, clear ownership, sufficient change management and appropriate governance structures (Eulerich et al. <xref ref-type="bibr" rid="CIT0009">2024</xref>; Osmundsen, Iden &#x0026; Bygstad <xref ref-type="bibr" rid="CIT0029">2019</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>). For insurers, these bottlenecks may create significant opportunity costs, including unrealised efficiency gains, continued reliance on manual processing, fragmented automation efforts, weak exception handling, inadequate audit trails and increased compliance exposure (Hong, Ly &#x0026; Lin <xref ref-type="bibr" rid="CIT0018">2023</xref>; Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). The governance issue is therefore not whether RPA is technologically novel, but whether insurers have the governance mechanisms needed to integrate, monitor and sustain RPA within information-intensive claims-handling processes.</p>
<p>While RPA governance research has grown, existing work has largely emphasised business-level governance, including strategic alignment and operational change, with limited attention to technical, data and operational IT governance mechanisms in claims-handling contexts where many RPA project failures originate. Consequently, building on prior work that identified key technical, data and operational challenges (hereinafter challenges) using the Control Objectives for Information and Related Technologies 2019 (COBIT 2019) governance framework (Pietersen, Lefela &#x0026; Lamprecht <xref ref-type="bibr" rid="CIT0033">2025</xref>), this study considers the challenges arising during the implementation of RPA in the insurance claims-handling process and develops governance framework to address them systematically.</p>
<p>These challenges are particularly pronounced in emerging-market insurance contexts, where legacy systems, fragmented data architectures and regulatory complexity increase the information management burden associated with automation initiatives. The governance framework developed in this study aims to assist those charged with governance &#x2013; including IT managers, internal auditors and executives &#x2013; in identifying, prioritising and managing the governance challenges associated with RPA in the insurance claims-handling process, while guiding them in strengthening governance of RPA projects, improving alignment between business and IT objectives and ensuring that these projects achieve their intended benefits while managing associated challenges.</p>
<p>The development of the governance framework in this study is theoretically grounded in the IT governance theory, which emphasises the allocation of decision rights and accountability mechanisms to align IT activities with business objectives (De Haes &#x0026; Van Grembergen <xref ref-type="bibr" rid="CIT0004">2009</xref>; Weill &#x0026; Ross <xref ref-type="bibr" rid="CIT0047">2004</xref>), while also drawing on data governance theory, which highlights the importance of data ownership, quality, integrity and accountability (Khatri &#x0026; Brown <xref ref-type="bibr" rid="CIT0022">2010</xref>), as well as the IT capability theory, which positions governance mechanisms as dynamic organisational capabilities that enable firms to adapt to technological change (Pavlou &#x0026; El Sawy <xref ref-type="bibr" rid="CIT0032">2010</xref>).</p>
<p>Considered from an information management perspective, these theories collectively explain how decision rights, data accountability and organisational capabilities shape the effective management of information-intensive automated processes. Furthermore, these theoretical perspectives collectively inform the structure of the proposed governance framework, which integrates them using COBIT 2019 as the organising mechanism &#x2013; a structured approach that incorporates core IT governance principles for aligning, planning, implementing and monitoring governance activities across the IT lifecycle (De Haes et al. <xref ref-type="bibr" rid="CIT0005">2020</xref>). By applying COBIT 2019 to RPA implementation in the insurance claims-handling process, this study illustrates how governance mechanisms can be designed to manage challenges specific to automation in the insurance industry, resulting in a framework that not only serves as a conceptual governance tool for insurers but also a theoretically informed model that integrates the IT governance, data governance and IT capability theories within the RPA context.</p>
<p>The preceding discussion has highlighted both the strategic importance of RPA in insurance claims handling and the persistent governance gaps that limit its value. To develop a robust conceptual governance framework, it is first necessary to systematically examine the existing body of knowledge. The following literature review, therefore, synthesises current understanding of the insurance claims-handling process, the application and challenges of RPA in insurance, the relevant theoretical foundations (IT governance, data governance and IT capability theory) and the COBIT 2019 framework that will serve as the organising mechanism for the proposed governance model.</p>
</sec>
<sec id="s0002">
<title>Literature review</title>
<sec id="s20003">
<title>The insurance claims-handling process</title>
<p>The insurance claims-handling process is central to insurers&#x2019; operations and directly influences financial performance, customer satisfaction and market competitiveness (Yusuf et al. <xref ref-type="bibr" rid="CIT0052">2017</xref>). The insurance claims-handling process consists of four distinct phases, namely logging, validation, adjudication and payment (Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>), which requires coordination between multiple departments, systems and external stakeholders.</p>
<p>The process is initiated by the insured party lodging a claim with the insurer. Once the claim is lodged, the insurer validates it by conducting a thorough investigation to verify that the insured party has an up-to-date membership with the insurer and is eligible to claim for the specific occurrence, among other factors. After a claim is validated, the insurer&#x2019;s financial responsibility is adjudicated, and a decision is made on whether to pay the insured party. The insurance claims-handling process concludes with payment to the insured party (Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). These phases show that claims handling is not a single administrative task but rather an information-dependent process in which data must move accurately and timeously across several decision points.</p>
<p>Historically, these processes were manual, requiring extensive human involvement in data input, claim verification and communication (Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). Manual processing, however, is labour-intensive, time-consuming and can lead to human error (Hartmann <xref ref-type="bibr" rid="CIT0015">2018</xref>). Consequently, many insurers have started using computerised systems for the claims-handling process, which digitalises certain functions such as data storage, policy retrieval and mathematical calculations (Eling, Nuessle &#x0026; Staubli <xref ref-type="bibr" rid="CIT0008">2022</xref>; Hartmann <xref ref-type="bibr" rid="CIT0015">2018</xref>; Tkaczyk et al. <xref ref-type="bibr" rid="CIT0043">2018</xref>; Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). However, the literature also suggests that computerisation and automation should not be treated as equivalent. Computerised systems may improve discrete functions, whereas automation requires greater standardisation of inputs, rules, exceptions and system interactions across the end-to-end process (Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>; Tkaczyk et al. <xref ref-type="bibr" rid="CIT0043">2018</xref>).</p>
<p>Although these systems improve process efficiency, they still rely heavily on human involvement for claim validation and decision-making. This creates challenges in automating end-to-end processes (Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>), and highlights the need for effective governance.</p>
<p>From a governance perspective, precise control and accountability structures are required when transitioning from a manual to a computerised system, as errors or inefficiencies in the claims-handling process can lead to reputational damage, fines and penalties, and financial losses (Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). Consequently, the claims-handling literature provides the operational rationale for this study: automation may improve efficiency, but only if the underlying information flows, decision points and accountability structures are adequately governed. This position claims handling as a suitable context for examining RPA governance because the value of automation depends equally on technological capability and the governance of the information environment in which the technology operates.</p>
<p>While these studies collectively affirm the information-intensive nature of claims handling and the limitations of manual and partially computerised processes (Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>; Yusuf et al. <xref ref-type="bibr" rid="CIT0052">2017</xref>), they remain largely descriptive and pay limited attention to the governance structures required to support end-to-end automation. Most notably, the literature highlights process standardisation and data accuracy as prerequisites for successful digitalisation yet rarely examines how fragmented accountability across departments exacerbates these issues in practice. This gap underscores the need for a governance lens when moving from computerisation to full RPA-enabled automation.</p>
</sec>
<sec id="s20004">
<title>Robotic process automation in the insurance industry</title>
<p>Robotic process automation enables software robots to execute rule-based, repetitive tasks across existing systems and applications without requiring extensive system integration or changes to the existing code (Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Madakam et al. <xref ref-type="bibr" rid="CIT0025">2019</xref>). In insurance claims handling, this makes RPA suitable for activities such as capturing claims information, verifying policyholder details, cross-referencing documents and initiating payments (Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>). However, the maturity of RPA as a technology does not eliminate implementation risk. This creates a tension in the literature: RPA is often presented as a relatively accessible automation technology, yet its implementation depends on organisational conditions that are considerably more complex than the technology itself.</p>
<p>Although the literature consistently highlights RPA&#x2019;s potential to deliver efficiency, accuracy and cost reductions in claims handling (Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Guo et al. <xref ref-type="bibr" rid="CIT0014">2025</xref>; Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Madakam et al. <xref ref-type="bibr" rid="CIT0025">2019</xref>), a more critical reading reveals important tensions. Early studies tend to be optimistic and technology-centric, emphasising RPA&#x2019;s non-invasive nature and ease of implementation. In contrast, more recent empirical and case-based research (Eulerich et al. <xref ref-type="bibr" rid="CIT0009">2024</xref>; Flechsig, Anslinger &#x0026; Lasch <xref ref-type="bibr" rid="CIT0010">2022</xref>; Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>) paints a more cautious picture, demonstrating that the high failure and abandonment rates (30&#x0025; &#x2013; 50&#x0025;; Sigur&#x00F0;ard&#x00F3;ttir <xref ref-type="bibr" rid="CIT0036">2018</xref>) stem primarily from organisational and governance deficiencies rather than from technological shortcomings. These studies converge on several recurring challenges, namely process standardisation, data quality, system integration, change management and accountability, yet they differ meaningfully in emphasis and depth. For instance, Osmundsen et al. (<xref ref-type="bibr" rid="CIT0029">2019</xref>) stress the need to balance centralised control with local process ownership, while Syed et al. (<xref ref-type="bibr" rid="CIT0040">2020</xref>) offer a broader taxonomy of implementation barriers, including organisational readiness and skills gaps. Eulerich et al. (<xref ref-type="bibr" rid="CIT0009">2024</xref>) contribute a valuable risk-management perspective, highlighting operational and control risks that earlier work largely overlooked.</p>
<p>A common limitation across this body of research is its predominantly general or cross-industry focus; few studies provide deep insurance-specific or claims-handling insights (notable exceptions being Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref> and Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>). Moreover, most stop at identifying barriers without proposing integrated governance responses tailored to information-intensive processes. This gap is particularly relevant in insurance claims handling, where automated processes depend on policy data, claims documentation, validation rules, legacy systems and exception handling (Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Yusuf &#x0026; Ajemunigbohun <xref ref-type="bibr" rid="CIT0051">2015</xref>). These studies, considered together, indicate that the central issue is no longer the definition of RPA, but the governance of its integration into complex, information-intensive business processes. They therefore informed the conceptual framework developed in this study by highlighting the need for governance mechanisms addressing process architecture, data quality, access control, capability development, change management and monitoring.</p>
<p>Considered collectively, the literature reveals that RPA implementation failures in insurance claims handling stem less from the technology itself than from insufficient governance of the information-intensive environment in which it operates. Addressing these challenges requires a deeper understanding of the underlying theoretical foundations that can guide effective governance. The next section, therefore, examines three complementary theoretical perspectives, namely IT governance, data governance and IT capability theory, that together provide the conceptual lenses through which a structured governance response can be developed.</p>
</sec>
<sec id="s20005">
<title>Theoretical perspectives: Information technology governance, data governance and information technology capability</title>
<p>Good governance practices are essential to ensure that digital transformation initiatives align with both strategic and operational objectives and deliver sustainable value (Delagrammatikas, Stelios &#x0026; Tzavaras <xref ref-type="bibr" rid="CIT0006">2025</xref>; Weill &#x0026; Ross <xref ref-type="bibr" rid="CIT0047">2004</xref>). The governance mechanisms required to align RPA projects in the insurance industry are rooted in IT governance, data governance and IT capability theories.</p>
<p>Information technology governance theory provides the foundational structures and processes that help define decision rights and accountability between the business and IT (De Haes &#x0026; Van Grembergen <xref ref-type="bibr" rid="CIT0004">2009</xref>; Weill &#x0026; Ross <xref ref-type="bibr" rid="CIT0047">2004</xref>). Effective IT governance promotes strategic alignment, performance measurement and risk management, ensuring that investments in technological advancements contribute directly to organisational goals (Weill &#x0026; Ross <xref ref-type="bibr" rid="CIT0047">2004</xref>). In the context of RPA, IT governance theory is therefore useful because it explains how decision rights, accountability structures and alignment mechanisms shape whether automation initiatives remain connected to organisational objectives.</p>
<p>Data governance theory extends this focus by addressing the rules, responsibilities and processes that ensure data availability, quality and integrity (Khatri &#x0026; Brown <xref ref-type="bibr" rid="CIT0022">2010</xref>; Volz et al. <xref ref-type="bibr" rid="CIT0045">2025</xref>). In RPA implementation, data governance determines how data are captured, validated and secured &#x2013; a critical concern in automated environments where low-quality data can have a detrimental impact on the project&#x2019;s outcome (Dogan et al. <xref ref-type="bibr" rid="CIT0007">2024</xref>; Guo et al. <xref ref-type="bibr" rid="CIT0014">2025</xref>). Proper data governance mechanisms, therefore, ensure compliance, traceability and reliability, all of which are essential to the success of RPA projects. This perspective is particularly important in claims handling because RPA does not create value from automation alone but rather when the underlying data are sufficiently accurate, accessible, controlled and traceable to support automated processing.</p>
<p>Finally, IT capability theory extends these perspectives by seeing governance mechanisms as dynamic organisational capabilities that enable organisations to identify opportunities for technological innovation, learn from experience, and reconfigure IT and process resources to respond to changes within the organisation or its environment (Pavlou &#x0026; El Sawy <xref ref-type="bibr" rid="CIT0032">2010</xref>; Weritz et al. <xref ref-type="bibr" rid="CIT0048">2025</xref>). From this perspective, effective RPA governance reflects the insurer&#x2019;s ability to implement mechanisms that coordinate people, processes and technologies to create value from automation.</p>
<p>The three theories are complementary to one another. Information technology governance theory explains who should make and monitor automation-related decisions; data governance theory explains how the information used by the automated processes should be controlled; and IT capability theory explains how insurers develop the organisational capacity to implement, maintain and adapt RPA over time (Khatri &#x0026; Brown <xref ref-type="bibr" rid="CIT0022">2010</xref>; Pavlou &#x0026; El Sawy <xref ref-type="bibr" rid="CIT0032">2010</xref>; Weill &#x0026; Ross <xref ref-type="bibr" rid="CIT0047">2004</xref>). This distinction is important because RPA implementation failures can occur even when a single dimension is addressed. For example, a project may be strategically aligned but still fail because data quality is poor, or it may have adequate data controls but lack the skills and routines needed to maintain bots after implementation (Dogan et al. <xref ref-type="bibr" rid="CIT0007">2024</xref>; Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>).</p>
<p>Combining these three theories provides a multidimensional foundation for understanding and developing a governance framework for implementing RPA in the insurance industry, ensuring sustainable value creation through effective risk management. Notably, few prior studies have synthesised these three perspectives in the context of RPA, particularly within highly regulated, information-intensive sectors such as insurance. The theoretical contribution of this study, therefore, lies in integrating these perspectives into a single governance logic: alignment and accountability from IT governance, information integrity and control from data governance and adaptive implementation capability from IT capability theory. <xref ref-type="fig" rid="F0001">Figure 1</xref> illustrates the conceptual model.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Conceptual model.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2169-g001.tif"/>
</fig>
<p><xref ref-type="fig" rid="F0001">Figure 1</xref> illustrates this integrated conceptual model. While the three theories offer a strong conceptual foundation for understanding why governance is needed, they do not prescribe how these principles should be operationalised in practice. The following section, therefore, bridges theory and practice by introducing COBIT 2019 as the structuring mechanism that translates the theoretical constructs of alignment, accountability, data integrity and organisational capability into concrete governance and management objectives suitable for RPA implementation in insurance claims handling.</p>
</sec>
<sec id="s20006">
<title>From theory to practice: The Control Objectives for Information and Related Technologies 2019 governance framework</title>
<p>While the governance theories discussed above offer conceptual insights into how organisations should align technology with strategic objectives, COBIT 2019 provides a practical structure for operationalising these principles. Control Objectives for Information and Related Technologies 2019, the latest governance framework published by Information Systems Audit and Control Association (ISACA), provides a holistic approach to IT governance (Thabit, Ishhadat &#x0026; Abdulrahman <xref ref-type="bibr" rid="CIT0042">2020</xref>).</p>
<p>The framework is organised into domains and governance objectives that support alignment between business and IT, value delivery, and effective risk management (ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>). The framework is known to be flexible, allowing organisations to tailor governance practices to emerging technologies, making it suitable for addressing the risks and governance challenges that arise from RPA implementation. In this study, COBIT 2019 is used as a guiding framework to synthesise the governance challenges identified in the literature and to develop appropriate governance mechanisms to address them.</p>
<p>The COBIT 2019 framework, therefore, serves as a bridge between theory and practice by addressing the principles of IT governance (alignment and accountability), incorporating elements of data governance (information integrity and control) and advancing IT capability theory (the development of adaptable governance routines). Applying COBIT 2019 to the insurance claims-handling process enables the integration of these theoretical perspectives into a single, structured model to address the challenges posed by RPA implementation. In this way, COBIT 2019 provides the organising logic for the framework, while the literature and theoretical perspectives determine why particular governance mechanisms are relevant to RPA implementation in insurance claims handling.</p>
<p>In summary, the literature review has established the operational context of claims handling, documented both the promises and ongoing challenges of RPA, clarified the relevant theoretical foundations and identified COBIT 2019 as a suitable organising framework. With this conceptual and theoretical foundation in place, the next section will outline the research design and methodology used to synthesise the literature and develop the governance framework presented in this study.</p>
</sec>
</sec>
<sec id="s0007">
<title>Research design and methodology</title>
<p>This study follows a qualitative, non-empirical research design informed by a structured literature review. A structured literature review was chosen because it allows for the systematic identification, evaluation and synthesis of existing knowledge (Ivan&#x010D;i&#x0107;, Su&#x0161;a Vugec &#x0026; Bosilj Vuk&#x0161;i&#x0107; <xref ref-type="bibr" rid="CIT0021">2019</xref>), while minimising selection bias and ensuring replicability &#x2013; critical for developing a governance framework in emerging fields like RPA (Okoli &#x0026; Schabram <xref ref-type="bibr" rid="CIT0028">2010</xref>). Rigorous and transparent synthesis of existing literature plays a critical role in information and knowledge management research, particularly in emerging and interdisciplinary domains characterised by rapid growth and fragmentation. Such approaches support the identification of prevailing themes and research gaps while reducing selection bias and enhancing methodological integrity (Rensleigh <xref ref-type="bibr" rid="CIT0034">2025</xref>).</p>
<p>Building on the structured literature review approach in prior work that identified RPA challenges in insurance claims-handling (Pietersen et al. <xref ref-type="bibr" rid="CIT0033">2025</xref>), this study&#x2019;s literature review provides an understanding of the existing research on the insurance claims-handling process, RPA technology and IT governance, extending the scope to include governance mechanisms and theoretical integration to help with the development of the governance framework.</p>
<p>The three steps as recommended by Ivan&#x010D;i&#x0107; et al. (<xref ref-type="bibr" rid="CIT0021">2019</xref>) were followed to conduct a rigorous and structured literature review, starting with: (1) a definition of the review protocol, searching and collection of relevant publications, followed by (2) a quality evaluation of the publications to narrow them down to relevant publications to be used, and (3) qualitative analysis and synthesis of the publications that made it through the selection process. To improve transparency and replicability, the search and selection process was documented using a Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA)-informed flow process (Page et al. <xref ref-type="bibr" rid="CIT0030">2021</xref>), although the review was not designed as a full systematic review or meta-analysis. The literature search and selection process is summarised in <xref ref-type="table" rid="T0001">Table 1</xref>.</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Preferred Reporting Items for Systematic Reviews and Meta-Analyses-informed summary of the literature search and selection process.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Stage</th>
<th valign="top" align="left">Description</th>
<th valign="top" align="center">Number of publications</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Identification</td>
<td align="left">Records identified through Scopus, ScienceDirect, Emerald Insight and Google Scholar</td>
<td align="center">149</td>
</tr>
<tr>
<td align="left">Initial screening</td>
<td align="left">Records remaining after deduplication and initial screening</td>
<td align="center">76</td>
</tr>
<tr>
<td align="left">Exclusion after full-text assessment</td>
<td align="left">Publications excluded after full-text review for relevance, quality and alignment with the research question</td>
<td align="center">34</td>
</tr>
<tr>
<td align="left">Inclusion</td>
<td align="left">Sources included in the final qualitative synthesis</td>
<td align="center">42</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>As per Ivan&#x010D;i&#x0107; et al. (<xref ref-type="bibr" rid="CIT0021">2019</xref>), step 1 involved identifying relevant literature using academic databases, including Scopus, ScienceDirect, Emerald Insight and Google Scholar. The primary search string was &#x2018;robotic process automation&#x2019;, supported by targeted combinations of the primary search string with the terms &#x2018;governance&#x2019;, &#x2018;insurance&#x2019;, &#x2018;claims&#x2019;, &#x2018;implementation challenges&#x2019;, and &#x2018;COBIT&#x2019;. The initial search yielded 149 results. Furthermore, to ensure rigour, a review protocol was established, defining inclusion criteria (e.g. have &#x2018;robotic process automation&#x2019; explicitly in the title, be published between 2009 and 2025, be scholarly journals, articles or conference papers, and be written in English with full access available) and exclusion criteria (e.g. duplicates, articles published before 2009, non-English publications, book chapters and professional papers, and articles where &#x2018;robotic process automation&#x2019; was cited in a different context were removed).</p>
<p>A review log was maintained during the identification and screening process. The log recorded the title, author(s), year, abstract, publication type, database or source, screening decision, and, where applicable, the reason for exclusion. This log was used to remove duplicates, assess relevance and support traceability between the reviewed literature and the challenges and governance mechanisms identified in the study. Following the deduplication process, 76 publications passed the initial screening process.</p>
<p>During step 2, the evaluation phase, the 76 publications were screened and selected for relevance to RPA implementation and governance, with an emphasis on peer-reviewed journal articles, conference papers and professional reports published between 2009 and 2025. Screening involved an initial title and abstract review for topical fit, followed by a full-text assessment of quality (e.g. methodological soundness, empirical evidence and alignment with RPA), culminating in synthesis (Okoli &#x0026; Schabram <xref ref-type="bibr" rid="CIT0028">2010</xref>), as described in step 3 below. After the evaluation phase, 42 sources remained, forming the final list that informed the research question.</p>
<p>Finally, in step 3, the remaining 42 sources were synthesised to identify challenges, recurring themes and governance considerations related to the technical, data and operational dimensions of RPA governance in the insurance industry. The synthesis employed thematic analysis, grouping concepts into categories (e.g. process integration, data management) and cross-referencing with COBIT 2019 objectives to highlight gaps and inform framework development (Webster &#x0026; Watson <xref ref-type="bibr" rid="CIT0046">2002</xref>).</p>
<p>To ensure structure and rigour in the development of the RPA governance framework, this study integrates the conceptual model in <xref ref-type="fig" rid="F0001">Figure 1</xref>, where RPA governance is positioned at the centre, supported by these three theoretical pillars, and leveraging the COBIT 2019 framework &#x2013; with its emphasis on governance and management objectives &#x2013; as a guiding mechanism to systematically identify, categorise and interpret the associated challenges, thereby informing targeted guidelines. A completeness check was performed by mapping synthesised findings back to COBIT 2019 domains to supplement any gaps with targeted searches.</p>
<p>The structured literature review and thematic synthesis described above, guided by COBIT 2019 domains, yielded a comprehensive set of RPA implementation challenges specific to the insurance claims-handling context. These challenges are presented and categorised in the following section. Articulating them explicitly is a necessary precursor to the subsequent development of targeted governance mechanisms, ensuring that the framework directly addresses the most salient risks identified in the literature.</p>
</sec>
<sec id="s0008">
<title>Results</title>
<sec id="s20009">
<title>Governance challenges in robotic process automation implementation</title>
<p>While RPA projects offer significant potential for improving efficiency and accuracy in the insurance claims-handling process, several challenges have been identified in the literature that hinder their successful implementation. To ensure the appropriate alignment between business and IT objectives and the success of the RPA project, these challenges must be well understood by those responsible for governance. The identified challenges are numbered C01 through C16 and categorised into four recurring, interrelated themes: process and system integration, data management, operational capability, and operational IT governance and control. <xref ref-type="table" rid="T0002">Table 2</xref> summarises these challenges.</p>
<table-wrap id="T0002">
<label>TABLE 2</label>
<caption><p>Technical, data and operational governance challenges of robotic process automation implementation in the insurance claims-handling process.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Theme</th>
<th valign="top" align="center">No.</th>
<th valign="top" align="left">Challenges identified</th>
<th valign="top" align="left">Sources</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="4" valign="top">Process and system integration challenges</td>
<td align="center">C01</td>
<td align="left">Lack of process standardisation and documentation before automation, making automation design and execution inconsistent.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Dogan et al. <xref ref-type="bibr" rid="CIT0007">2024</xref>; Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>)</td>
</tr>
<tr>
<td align="center">C02</td>
<td align="left">Complex legacy systems that are not designed for automation require workarounds that introduce instability and maintenance issues.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Eulerich et al. <xref ref-type="bibr" rid="CIT0009">2024</xref>; Yadav &#x0026; Mishra <xref ref-type="bibr" rid="CIT0049">2024</xref>; Yatskiv, Yatskiv &#x0026; Vasylyk <xref ref-type="bibr" rid="CIT0050">2020</xref>)</td>
</tr>
<tr>
<td align="center">C03</td>
<td align="left">Limited integration between systems and RPA tools, resulting in frequent process interruptions or the need for manual intervention.</td>
<td align="left">(Auth, Czarnecki &#x0026; Bensberg <xref ref-type="bibr" rid="CIT0002">2019</xref>; Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Flechsig et al. <xref ref-type="bibr" rid="CIT0010">2022</xref>; Kirchmer <xref ref-type="bibr" rid="CIT0023">2017</xref>; Yusuf et al. <xref ref-type="bibr" rid="CIT0052">2017</xref>; Zhang &#x0026; Guo <xref ref-type="bibr" rid="CIT0053">2024</xref>)</td>
</tr>
<tr>
<td align="center">C04</td>
<td align="left">Inadequate testing environments and weak change management procedures increase the risk of implementation errors.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Dogan et al. <xref ref-type="bibr" rid="CIT0007">2024</xref>; Eulerich et al. <xref ref-type="bibr" rid="CIT0009">2024</xref>; Kirchmer <xref ref-type="bibr" rid="CIT0023">2017</xref>)</td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Data management challenges</td>
<td align="center">C05</td>
<td align="left">Poor data quality, duplication and inconsistency across systems disrupt automated workflows.</td>
<td align="left">(Axmann &#x0026; Harmoko <xref ref-type="bibr" rid="CIT0003">2020</xref>; Dogan et al. <xref ref-type="bibr" rid="CIT0007">2024</xref>; Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Hartmann <xref ref-type="bibr" rid="CIT0015">2018</xref>; Tkaczyk et al. <xref ref-type="bibr" rid="CIT0043">2018</xref>)</td>
</tr>
<tr>
<td align="center">C06</td>
<td align="left">Fragmented data ownership and limited visibility into where data is stored within the organisation.</td>
<td align="left">(Axmann &#x0026; Harmoko <xref ref-type="bibr" rid="CIT0003">2020</xref>; Hartmann <xref ref-type="bibr" rid="CIT0015">2018</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>)</td>
</tr>
<tr>
<td align="center">C07</td>
<td align="left">Weak access controls and insufficient validation checks increase compliance and security risks.</td>
<td align="left">(Flechsig et al. <xref ref-type="bibr" rid="CIT0010">2022</xref>; Fox et al. <xref ref-type="bibr" rid="CIT0011">2021</xref>; Horvat, Ivani&#x0161;evi&#x0107; &#x0026; Glu&#x0161;&#x010D;evi&#x0107; <xref ref-type="bibr" rid="CIT0019">2024</xref>; Patri <xref ref-type="bibr" rid="CIT0031">2020</xref>)</td>
</tr>
<tr>
<td align="center">C08</td>
<td align="left">Lack of clear accountability for data governance across business and IT functions.</td>
<td align="left">(Eling et al. <xref ref-type="bibr" rid="CIT0008">2022</xref>; Hartmann <xref ref-type="bibr" rid="CIT0015">2018</xref>; Hong et al. <xref ref-type="bibr" rid="CIT0018">2023</xref>; Kirchmer <xref ref-type="bibr" rid="CIT0023">2017</xref>)</td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Operational capability challenges</td>
<td align="center">C09</td>
<td align="left">Lack of skills and expertise within the organisation to design, monitor and maintain bots effectively.</td>
<td align="left">(Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>; Patri <xref ref-type="bibr" rid="CIT0031">2020</xref>)</td>
</tr>
<tr>
<td align="center">C10</td>
<td align="left">Over-reliance on external vendors or consultants for technical maintenance.</td>
<td align="left">(Auth et al. <xref ref-type="bibr" rid="CIT0002">2019</xref>; Flechsig et al. <xref ref-type="bibr" rid="CIT0010">2022</xref>; Kirchmer <xref ref-type="bibr" rid="CIT0023">2017</xref>)</td>
</tr>
<tr>
<td align="center">C11</td>
<td align="left">Insufficient employee training and resistance to change due to job security concerns.</td>
<td align="left">(Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>; Patri <xref ref-type="bibr" rid="CIT0031">2020</xref>)</td>
</tr>
<tr>
<td align="center">C12</td>
<td align="left">Limited mechanisms for knowledge transfer or collaboration.</td>
<td align="left">(Agostinelli, Marrella &#x0026; Mecella <xref ref-type="bibr" rid="CIT0001">2019</xref>)</td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Operational IT governance and control challenges</td>
<td align="center">C13</td>
<td align="left">Absence of clearly defined roles, ownership and accountability for RPA within the organisation.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>)</td>
</tr>
<tr>
<td align="center">C14</td>
<td align="left">Insufficient oversight and monitoring of automation performance and associated risks.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Horvat et al. <xref ref-type="bibr" rid="CIT0019">2024</xref>; Osmundsen et al. <xref ref-type="bibr" rid="CIT0029">2019</xref>)</td>
</tr>
<tr>
<td align="center">C15</td>
<td align="left">Limited auditability and lack of escalation procedures for errors or exceptions.</td>
<td align="left">(Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>)</td>
</tr>
<tr>
<td align="center">C16</td>
<td align="left">Disconnect between IT-led automation initiatives and broader business strategy.</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Goosen &#x0026; Rudman <xref ref-type="bibr" rid="CIT0013">2013</xref>)</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Please see the full reference list of this article, Pietersen, L.-A., Lefela, T.D. &#x0026; Lamprecht, C., 2026, &#x2018;A conceptual governance framework for managing robotic process automation implementation challenges in insurance claims handling&#x2019;, <italic>South African Journal of Information Management</italic> 28(1), a2169. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v28i1.2169">https://doi.org/10.4102/sajim.v28i1.2169</ext-link> for more information.</p></fn>
<fn><p>IT, information technology; RPA, robotic process automation.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The challenges summarised in <xref ref-type="table" rid="T0002">Table 2</xref> indicate that RPA project failures in the insurance claims-handling process are not limited to technical challenges but also encompass weaknesses in governance, alignment and operational mechanisms. Process and data challenges emphasise the need for stronger standardisation, quality controls and mechanisms to improve integration. These principles are central to the IT and data governance theories. Furthermore, operational and governance-related challenges indicate that many insurers lack the capacity and accountability structures to implement RPA successfully. Together, these identified challenges reinforce the need for a holistic governance framework to address the challenges of RPA.</p>
<p>A piecemeal approach to address the challenges, as summarised in <xref ref-type="table" rid="T0002">Table 2</xref>, is insufficient because RPA project failures arise from weaknesses across process integration, data management, operational capability and IT governance. The following section draws on the theoretical foundations and COBIT 2019 governance and management objectives to translate these challenges into a coherent set of actionable governance guidelines, thereby closing the gap between identified problems and practical governance responses.</p>
</sec>
<sec id="s20010">
<title>Developing a governance framework to manage challenges</title>
<p>The identified challenges can be managed through governance mechanisms that strengthen IT and data governance, as well as operational control environments, for RPA projects in the insurance claims-handling process. To develop the framework, this study identified governance guidelines from the literature and mapped them to the relevant COBIT 2019 governance and management objectives.</p>
<p>This mapping ensured that the guidelines were structured and consistent with recognised governance practices. Control Objectives for Information and Related Technologies 2019 was not merely used as a general reference framework, but as an organising mechanism to translate the identified RPA implementation challenges into governance responses. Each guideline was therefore linked to one or more COBIT 2019 governance or management objectives to make the governance logic explicit. For example, enterprise architecture guidance was linked to the COBIT objective managed enterprise architecture, while process standardisation and automation suitability guidance was linked to managed requirements definition and managed solution identification and build. Guidelines on data architecture, privacy, logging and access control were linked to COBIT objectives related to managed data, managed security services, managed controls and managed security. Guidelines relating to change, configuration, capacity and availability were linked to COBIT objectives concerned with managed changes, managed configuration, managed availability and capacity, and managed operations.</p>
<p>In addition to the COBIT 2019 mapping, each guideline was linked to the theoretical perspective that informed its inclusion in the framework. Information technology governance theory informed guidelines concerned with decision rights, accountability, business-IT alignment, oversight and control. Data governance theory informed guidelines concerned with data ownership, data quality, privacy, access, integrity, traceability and monitoring. Information technology capability theory informed guidelines concerned with skills, organisational learning, technology enablement, knowledge transfer, adaptability and the development of repeatable automation capabilities. This dual mapping ensured that the framework was not only practice-oriented but also theoretically anchored in the governance and capability mechanisms required to manage RPA implementation challenges.</p>
<p>Following the initial mapping, a completeness check was performed, in which the COBIT 2019 objectives most relevant to RPA in the insurance industry were reviewed to identify any control areas not covered by the guidelines identified in the literature. Where gaps were identified, additional guidelines were formulated to align with the COBIT 2019 framework. The governance framework in <xref ref-type="table" rid="T0003">Table 3</xref> was therefore developed through an iterative process that combined literature-derived challenges, theoretical grounding and COBIT 2019 mechanisms to provide structured, literature-based guidelines for a governance response.</p>
<table-wrap id="T0003">
<label>TABLE 3</label>
<caption><p>Governance framework to address robotic process automation implementation challenges.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Ref. no.</th>
<th valign="top" align="left">Area of improvement</th>
<th valign="top" align="left">Guidelines</th>
<th valign="top" align="left">COBIT 2019 objective(s)</th>
<th valign="top" align="left">Theory</th>
<th valign="top" align="center">Origin</th>
<th valign="top" align="left">Sources</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" colspan="7"><bold>1. Process and technology architecture</bold></td>
</tr>
<tr>
<td align="left">G01</td>
<td align="left">Enterprise architecture</td>
<td align="left">An enterprise architecture for the organisation needs to be documented to show the interrelationships among the business processes, the information required to support decision-making in these processes, the applications that process this information and the technology that hosts and runs these applications. The business architecture layer maps the enterprise processes end-to-end, depicting the value chain embedded in each arrangement. With the business process architecture defined, the portfolio of automation projects can be managed better in line with the value chain. Selection of RPA automation that can yield the anticipated benefits can be done easily, as the processes are mapped and arranged according to the value they are expected to generate.</td>
<td align="left">APO03 Managed Enterprise Architecture;<break/>BAI11 Managed Projects</td>
<td align="left">ITGov;<break/>ITCap</td>
<td align="center">L</td>
<td align="left">(Auth et al. <xref ref-type="bibr" rid="CIT0002">2019</xref>; Horvat et al. <xref ref-type="bibr" rid="CIT0019">2024</xref>; Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>)</td>
</tr>
<tr>
<td align="left">G02</td>
<td align="left">Requirements for automation</td>
<td align="left">Processes that are recommended for automation through RPA should have the following features:
<list list-type="bullet">
<list-item><p>highly manual</p></list-item>
<list-item><p>highly rule-based</p></list-item>
<list-item><p>deal with high volumes</p></list-item>
<list-item><p>mature, stable and standardised</p></list-item>
<list-item><p>capable of processing structured and digitised data</p></list-item>
<list-item><p>dealing with transactional tasks</p></list-item>
<list-item><p>have low levels of exception cases</p></list-item>
<list-item><p>highly repetitive</p></list-item>
<list-item><p>dealing with less complex tasks</p></list-item>
<list-item><p>well documented.</p></list-item>
</list></td>
<td align="left">BAI02 Managed Requirements Definition; BAI03 Managed Solutions Identification and Build</td>
<td align="left">ITGov;<break/>ITCap</td>
<td align="center">L</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>)</td>
</tr>
<tr>
<td align="left">G03</td>
<td align="left">Initial assessment of automation suitability</td>
<td align="left">During the assessment of the project to determine the suitability of automation through RPA, software architects, business analysts and process analysts should be consulted. The inclusion of architects can be separated if there is no Centre of Excellence (CoE) or if architects do not form part of the CoE. Otherwise, they could participate through their involvement in the CoE. Software architects have experience building automation solutions and could assist the RPA team by applying their expertise to determine the optimal approach to automating the process. Business and process analysts could assist with process and business requirements to facilitate process analysis and determine the suitability of RPA automation.</td>
<td align="left">BAI01 Managed Programmes; BAI02 Managed Requirements Definition; APO03 Managed Enterprise Architecture</td>
<td align="left">ITGov;<break/>ITCap</td>
<td align="center">L</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; Horvat et al. <xref ref-type="bibr" rid="CIT0019">2024</xref>; Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>; Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>)</td>
</tr>
<tr>
<td align="left">G04</td>
<td align="left">Investigate legacy systems</td>
<td align="left">Legacy systems may be included in the scope of the RPA project, but there may be no supporting documentation to assist with the system&#x2019;s design and architecture. The recommendation is to conduct research to locate and retrieve relevant documentation, either from the web or from other companies that may be operating similar systems. A thorough search of the organisation&#x2019;s archives and document storage areas should also be conducted to locate these documents. An impact assessment should be undertaken to determine the impact of not having the required information if the required documentation cannot be located. Decisions should be made regarding whether the legacy system in question should be excluded from the project scope and whether the project can continue without it. Legacy systems without source code may also be within the scope of the RPA project. Legacy systems without the source code should also be excluded from the scope of the RPA project or other automation options should be considered.</td>
<td align="left">APO03 Managed Enterprise Architecture; BAI03 Managed Solutions Identification and Build; BAI09 Managed Assets</td>
<td align="left">ITGov;<break/>ITCap</td>
<td align="center">L</td>
<td align="left">(Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>)</td>
</tr>
<tr>
<td align="left" colspan="7"><bold>2. Data and information governance</bold></td>
</tr>
<tr>
<td align="left">G05</td>
<td align="left">Data architecture</td>
<td align="left">The data architecture should be defined as part of the enterprise architecture. The data architecture acts as a blueprint that defines the data business and quality requirements. It defines the data and associated schemas, as well as the requirements for data collection, storage and delivery. Data governance should be supported by an associated data management framework that provides policies and governance controls to enforce the organisation&#x2019;s conduct in line with the defined architecture. Definition of the data, schemas and associated quality requirements should be communicated to relevant stakeholders to ensure standardisation of the data inputs to the process.</td>
<td align="left">APO03 Managed Enterprise Architecture; APO14 Managed Data</td>
<td align="left">DGov</td>
<td align="center">L</td>
<td align="left">(Khatri &#x0026; Brown <xref ref-type="bibr" rid="CIT0022">2010</xref>; Thabit et al. <xref ref-type="bibr" rid="CIT0042">2020</xref>; Volz et al. <xref ref-type="bibr" rid="CIT0045">2025</xref>)</td>
</tr>
<tr>
<td align="left">G06</td>
<td align="left">Privacy management</td>
<td align="left">The principles of privacy by design and privacy by default should be implemented to ensure that privacy compliance is embedded throughout the RPA robot life cycle. As a result, the RPA robot should incorporate the privacy design elements, and the operational environment should have built-in controls to manage privacy. The privacy-by-default principle, by contrast, stipulates that software robots, as data-processing technologies, should limit the processing of personal data to the minimum necessary to achieve the original purpose. The relevant framework, policies, standards, processes, guides and codes of conduct should be adopted to underpin these principles. A personal data inventory mapping system should be maintained that lists the personal data collected, processed, stored and shared, and the justification for each of these operations. This system should be monitored continuously to track changes and address identified gaps.</td>
<td align="left">APO14 Managed Data; DSS05 Managed Security Services; MEA03 Managed Compliance with External Requirements</td>
<td align="left">DGov; ITGov</td>
<td align="center">L</td>
<td align="left">(Holder et al. <xref ref-type="bibr" rid="CIT0017">2016</xref>; Zhang &#x0026; Guo <xref ref-type="bibr" rid="CIT0053">2024</xref>)</td>
</tr>
<tr>
<td align="left">G07</td>
<td align="left">Logging and monitoring</td>
<td align="left">Familiarisation with and understanding of best practices for logging and monitoring should be established to inform the logging requirements. A formal guideline or framework, such as the Open Web Application Security Project, should be followed when crafting the requirements. These logging requirements for the RPA solution should be included in the technical requirements specification. Logging should be configured in accordance with these requirements, and periodic tests across different scenarios should be conducted to identify gaps in logging quality. Test reports should be reviewed, and identified gaps should be addressed promptly.</td>
<td align="left">DSS01 Managed Operations; DSS06 Managed Business Process Controls; MEA01 Managed Performance and Conformance Monitoring</td>
<td align="left">DGov; ITGov</td>
<td align="center">C</td>
<td align="left">(Hong et al. <xref ref-type="bibr" rid="CIT0018">2023</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Treacy et al. <xref ref-type="bibr" rid="CIT0044">2023</xref>)</td>
</tr>
<tr>
<td align="left" colspan="7"><bold>3. Technology enablement and integration</bold></td>
</tr>
<tr>
<td align="left">G08</td>
<td align="left">Technology library</td>
<td align="left">A library of RPA automation software robots should be maintained, which would aid the reuse of the smaller and simpler software robots referred to as modules to build more complex robots. Stored robot modules could be reused in subsequent projects, minimising effort, cost and duration associated with RPA projects while improving the quality of the software robots. These modules could improve development efficiency and maintenance, as updates to reused components can be easily applied across all relevant processes.</td>
<td align="left">BAI03 Managed Solutions Identification and Build; BAI08 Managed Knowledge; BAI09 Managed Assets</td>
<td align="left">ITCap</td>
<td align="center">L</td>
<td align="left">(Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>; Zhang &#x0026; Guo <xref ref-type="bibr" rid="CIT0053">2024</xref>)</td>
</tr>
<tr>
<td align="left">G09</td>
<td align="left">Integration with complementary technologies</td>
<td align="left">Adoption of artificial intelligence (AI) technologies is recommended for tasks that involve cognitive processes and unstructured data, where RPA can be integrated with these technologies. This would enable end-to-end process automation. Advances in technologies such as optical character recognition (OCR), chatbots and AI would enable RPA to handle complex parts of the claims management process. The integration of RPA and AI could be used during the validation phase of the claims-handling process, where AI would automate claim approvals, which require cognitive decision-making beyond RPA&#x2019;s capability.</td>
<td align="left">APO04 Managed Innovation; BAI03 Managed Solutions Identification and Build</td>
<td align="left">ITCap</td>
<td align="center">L</td>
<td align="left">(Fox et al. <xref ref-type="bibr" rid="CIT0011">2021</xref>; Lamberton et al. <xref ref-type="bibr" rid="CIT0024">2017</xref>; Mannix &#x0026; Sethuraman <xref ref-type="bibr" rid="CIT0026">2020</xref>; Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>)</td>
</tr>
<tr>
<td align="left">G10</td>
<td align="left">Adoption of OCR technology</td>
<td align="left">Insurers should adopt OCR to augment RPA use cases in processing physical data. The OCR capability and competence should be developed to enable automation of tasks associated with physical data. Optical character recognition solutions should be developed to expand the value proposition and use cases for RPA. Optical character recognition software digitises physical data and enables software robots to interpret data entered on forms, as well as certain manual handwritten claims process artefacts, such as police reports, bringing the claims-handling process closer to full automation through RPA projects.</td>
<td align="left">APO04 Managed Innovation; BAI03 Managed Solutions Identification and Build</td>
<td align="left">ITCap</td>
<td align="center">L</td>
<td align="left">(Sobczak &#x0026; Ziora <xref ref-type="bibr" rid="CIT0038">2021</xref>; Tkaczyk et al. <xref ref-type="bibr" rid="CIT0043">2018</xref>)</td>
</tr>
<tr>
<td align="left" colspan="7"><bold>4. People and capability management</bold></td>
</tr>
<tr>
<td align="left">G11</td>
<td align="left">Talent management strategy</td>
<td align="left">Implement a talent management strategy to ensure the acquisition of the right talent, retention and continuous development and capacity building, so that the relevant individuals can carry out their tasks effectively. Depending on the organisation&#x2019;s size, all required talent should be in-house, outsourced or a combination of both. The talent management strategy should be reviewed, where applicable, to ensure it covers RPA resources. A pool of talent from business and IT should be trained and coached in the relevant areas of RPA automation to ensure succession planning requirements are addressed.</td>
<td align="left">APO07 Managed Human Resources; BAI08 Managed Knowledge</td>
<td align="left">ITCap</td>
<td align="center">L</td>
<td align="left">(Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>)</td>
</tr>
<tr>
<td align="left">G12</td>
<td align="left">Stakeholder management</td>
<td align="left">Insurers should discuss and promote RPA knowledge and benefits with their various stakeholders. The claims-handling process handles data from multiple stakeholders, and it is critical that these stakeholders understand the need to standardise information deliverables and to implement controlled, planned change. This would minimise the risk of unplanned changes being implemented, which could result in exceptions and crashes, disrupting RPA robot operations. This would also help to minimise the maintenance efforts.</td>
<td align="left">APO08 Managed Relationships; APO02 Managed Strategy</td>
<td align="left">ITGov; ITCap</td>
<td align="center">L</td>
<td align="left">(Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>; Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>)</td>
</tr>
<tr>
<td align="left">G13</td>
<td align="left">Empowering personnel</td>
<td align="left">The CoE should build capacity and empower business units to develop and implement the software robots. The CoE should conduct a technical review of the completed robots before transitioning them to the operational environment. The technical review should be conducted to ensure conformance with the defined RPA development life-cycle standards. Empowerment of the business personnel would ensure smooth maintenance of the robots after implementation, as they would be maintained by the same people who own and manage the relevant automated process.</td>
<td align="left">APO07 Managed Human Resources; BAI08 Managed Knowledge</td>
<td align="left">ITCap</td>
<td align="center">L</td>
<td align="left">(Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>; Schlegel et al. <xref ref-type="bibr" rid="CIT0035">2024</xref>)</td>
</tr>
<tr>
<td align="left" colspan="7"><bold>5. Operational IT governance</bold></td>
</tr>
<tr>
<td align="left">G14</td>
<td align="left">Change management</td>
<td align="left">Insurers should adopt and enforce a change management process. The change management process would ensure that changes are logged, assessed, approved, scheduled, implemented, communicated and closed, with a post-implementation review to evaluate their impact and challenges and to review lessons learned. A formalised change management process would minimise the occurrence of unauthorised changes, which could disrupt RPA robot operations.</td>
<td align="left">BAI06 Managed IT Changes; BAI07 Managed IT Change Acceptance and Transitioning</td>
<td align="left">ITGov</td>
<td align="center">C</td>
<td align="left">(Delagrammatikas et al. <xref ref-type="bibr" rid="CIT0006">2025</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Zhang &#x0026; Guo <xref ref-type="bibr" rid="CIT0053">2024</xref>)</td>
</tr>
<tr>
<td align="left">G15</td>
<td align="left">Configuration management</td>
<td align="left">Insurers should adopt and maintain the configuration management process. The configuration management process would account for all implemented configurations and ensure that all configuration changes are approved, implemented, recorded and verified. This would ensure that unauthorised and unplanned configuration changes that could disrupt or break the software robots would not be implemented in the operational environment.</td>
<td align="left">BAI10 Managed Configuration</td>
<td align="left">ITGov</td>
<td align="center">C</td>
<td align="left">(Gartner <xref ref-type="bibr" rid="CIT0012">2025</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Noppen et al. <xref ref-type="bibr" rid="CIT0027">2020</xref>)</td>
</tr>
<tr>
<td align="left">G16</td>
<td align="left">Identity and access management</td>
<td align="left">A formalised identity and access management process should be adopted. Users should be added and revoked in accordance with the defined process, following authorisation of such requests. The catalogue of these users&#x2019; roles and access profiles should be maintained and reviewed periodically to ensure that only authorised users are granted access to the services and that the assigned roles and privileges are appropriate based on the principle of least privilege. An identity and access management system is recommended to manage identities and access rights throughout the lifecycle of users or services.</td>
<td align="left">DSS05 Managed Security Services</td>
<td align="left">DGov; ITGov</td>
<td align="center">C</td>
<td align="left">(Hong et al. <xref ref-type="bibr" rid="CIT0018">2023</xref>; Horvat et al. <xref ref-type="bibr" rid="CIT0019">2024</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Zhang &#x0026; Guo <xref ref-type="bibr" rid="CIT0053">2024</xref>)</td>
</tr>
<tr>
<td align="left">G17</td>
<td align="left">Capacity management</td>
<td align="left">Insurers should implement a capacity management process to manage current and future capacity in line with demand. Business requirements would be translated into capacity plans to ensure fulfilment of the organisation&#x2019;s obligations. The capacity and performance of production services and their associated components (IT resources) that address business requirements would be predicted, controlled and managed to ensure alignment with capacity plans. Capacity reports should be documented and reviewed for gaps, which should be addressed accordingly.</td>
<td align="left">BAI04 Managed Availability and capacity</td>
<td align="left">ITGov; ITCap</td>
<td align="center">C</td>
<td align="left">(Gartner <xref ref-type="bibr" rid="CIT0012">2025</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Syed et al. <xref ref-type="bibr" rid="CIT0040">2020</xref>)</td>
</tr>
<tr>
<td align="left">G18</td>
<td align="left">Availability management</td>
<td align="left">A formal availability management process should be adopted to ensure deliberate effort is made to maintain service availability in the operational environment. Proper procedures and measures to improve availability to agreed levels should be built into the services and their components. Periodic testing of the availability and effectiveness of the recovery measures should be undertaken and reported. Reports should be reviewed for gaps, and service improvement plans should be developed and implemented to address them.</td>
<td align="left">BAI04 Managed Availability and Capacity; DSS01 Managed Operations</td>
<td align="left">ITGov; ITCap</td>
<td align="center">C</td>
<td align="left">(Gartner <xref ref-type="bibr" rid="CIT0012">2025</xref>; ISACA <xref ref-type="bibr" rid="CIT0020">2018</xref>; Hong et al. <xref ref-type="bibr" rid="CIT0018">2023</xref>)</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Please see the full reference list of this article, Pietersen, L.-A., Lefela, T.D. &#x0026; Lamprecht, C., 2026, &#x2018;A conceptual governance framework for managing robotic process automation implementation challenges in insurance claims handling&#x2019;, <italic>South African Journal of Information Management</italic> 28(1), a2169. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v28i1.2169">https://doi.org/10.4102/sajim.v28i1.2169</ext-link> for more information.</p></fn>
<fn><p>ITGov, IT governance theory; DGov, data governance theory; ITCap, IT capability theory; L, Literature; C, Communication; COBIT 2019, Control Objectives for Information and Related Technologies 2019; RPA, robotic process automation; IT, information technology; CoE, Centre of Excellence; Ref. no., reference number.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>For clarity and traceability, <xref ref-type="table" rid="T0003">Table 3</xref> numbers the governance guidelines from G01 to G18 and identifies the origin of each guideline, indicating whether it was derived from the literature or through the COBIT 2019 completeness check. <xref ref-type="table" rid="T0003">Table 3</xref> also identifies the relevant COBIT 2019 governance and management objective(s) and the theoretical grounding for each guideline, thereby making the framework development logic more transparent.</p>
<p>To improve ease of use, the guidelines are grouped into five recurring governance themes that reflect how insurers would typically organise operational IT governance: (1) process and technology architecture, (2) data and information governance, (3) technology enablement and integration, (4) people and capability management, and (5) operational IT governance.</p>
<p>To illustrate the alignment between the identified challenges and the governance framework developed in <xref ref-type="table" rid="T0003">Table 3</xref>, the guidelines were mapped to the specific challenges they address in <xref ref-type="table" rid="T0004">Table 4</xref>. This mapping demonstrates comprehensive literature-based coverage of the governance framework, confirming that each identified challenge is mitigated by one or more COBIT 2019-aligned governance mechanisms. <xref ref-type="table" rid="T0004">Table 4</xref> also highlights how the controls are interconnected, as several controls mitigate multiple risks.</p>
<table-wrap id="T0004">
<label>TABLE 4</label>
<caption><p>Mapping of governance guidelines to challenges in robotic process automation implementation.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left" rowspan="3">Challenge themes (from <xref ref-type="table" rid="T0002">Table 2</xref>)</th>
<th valign="top" align="left" rowspan="3"></th>
<th valign="top" align="left" rowspan="3">Challenge reference and summary</th>
<th valign="top" align="center" colspan="18">Governance themes and guidelines (from <xref ref-type="table" rid="T0003">Table 3</xref>)<hr/></th>
</tr>
<tr>
<th valign="top" align="center" colspan="4">Process and technology architecture<hr/></th>
<th valign="top" align="center" colspan="3">Data and information governance<hr/></th>
<th valign="top" align="center" colspan="3">Technology enablement and integration<hr/></th>
<th valign="top" align="center" colspan="3">People and capability management<hr/></th>
<th valign="top" align="center" colspan="5">Operational IT governance<hr/></th>
</tr>
<tr>
<th valign="top" align="center">G01</th>
<th valign="top" align="center">G02</th>
<th valign="top" align="center">G03</th>
<th valign="top" align="center">G04</th>
<th valign="top" align="center">G05</th>
<th valign="top" align="center">G06</th>
<th valign="top" align="center">G07</th>
<th valign="top" align="center">G08</th>
<th valign="top" align="center">G09</th>
<th valign="top" align="center">G10</th>
<th valign="top" align="center">G11</th>
<th valign="top" align="center">G12</th>
<th valign="top" align="center">G13</th>
<th valign="top" align="center">G14</th>
<th valign="top" align="center">G15</th>
<th valign="top" align="center">G16</th>
<th valign="top" align="center">G17</th>
<th valign="top" align="center">G18</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="4" valign="top">Process and system integration</td>
<td align="center">C01</td>
<td align="left">Lack of process standardisation and documentation</td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C02</td>
<td align="left">Complex legacy systems not designed for automation</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C03</td>
<td align="left">Limited integration between systems and RPA tools</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C04</td>
<td align="left">Weak testing and change-management processes</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Data management</td>
<td align="center">C05</td>
<td align="left">Poor data quality, duplication and inconsistency</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
</tr>
<tr>
<td align="center">C06</td>
<td align="left">Fragmented data ownership and lack of visibility</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C07</td>
<td align="left">Weak access controls and security validation</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C08</td>
<td align="left">Lack of accountability for data governance</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Operational capability</td>
<td align="center">C09</td>
<td align="left">Insufficient RPA skills and expertise</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C10</td>
<td align="left">Over-reliance on external vendors</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C11</td>
<td align="left">Employee resistance to change</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C12</td>
<td align="left">Limited knowledge transfer or collaboration mechanisms</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="left" rowspan="4" valign="top">Operational IT governance and control</td>
<td align="center">C13</td>
<td align="left">Undefined roles and ownership for RPA governance</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C14</td>
<td align="left">Insufficient oversight and monitoring of automation performance</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C15</td>
<td align="left">Lack of auditability and exception escalation</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
</tr>
<tr>
<td align="center">C16</td>
<td align="left">Disconnect between IT-led automation and business strategy</td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="left"></td>
<td align="center">&#x00D7;</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>IT, information technology; RPA, robotic process automation.</p></fn>
</table-wrap-foot>
</table-wrap>
<p><xref ref-type="table" rid="T0004">Table 4</xref> illustrates the thorough scope of the conceptual governance framework, demonstrating that each identified challenge is effectively addressed by one or more governance mechanisms aligned with COBIT 2019. Furthermore, the table emphasises the interconnectivity of the controls, showing that several mechanisms contribute to managing multiple challenges, thereby reinforcing the framework&#x2019;s robustness and efficiency. In line with the methodology, the synthesis of reviewed publications into key challenges and their subsequent mapping to recommended governance guidelines are illustrated in <xref ref-type="fig" rid="F0002">Figure 2</xref>.</p>
<fig id="F0002">
<label>FIGURE 2</label>
<caption><p>Synthesised themes and related guidelines.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2169-g002.tif"/>
</fig>
<p>As depicted in <xref ref-type="fig" rid="F0002">Figure 2</xref>, the structured synthesis process transforms insights from the existing literature into a comprehensive set of challenges and tailored conceptual guidelines, providing a rigorous foundation for RPA governance in insurance claims handling. This approach highlights the interconnections between identified issues and proposed solutions, facilitating better alignment.</p>
<p>The governance framework presented above provides a structured, theoretically grounded response to the RPA implementation challenges identified in the literature. Before concluding, it is important to delineate the boundaries of the study and acknowledge its limitations. The following section, therefore, clarifies the scope of the framework and identifies avenues for future empirical validation.</p>
</sec>
</sec>
<sec id="s0011">
<title>Discussion</title>
<p>The study employs a structured literature review and uses the COBIT 2019 governance and management objectives to guide the integration of IT governance, data governance and IT capability theories. This study does not consider supporting technologies such as artificial intelligence (AI) and machine learning. Instead, the research focuses on RPA as a process automation tool and investigates how governance processes can be applied to manage the challenges introduced by implementing RPA in insurance claims handling.</p>
<p>The scope of this research is limited to the risks, controls and governance considerations associated with implementing RPA in the insurance industry, specifically focusing on the insurance claims-handling process. Consequently, it is not intended as a governance framework for managing risks associated with other digital technologies or the implementation of RPA in other industries.</p>
<p>As the framework was developed through a structured review and COBIT-informed synthesis rather than empirical testing, it should be interpreted as a conceptual and literature-based framework. Its practical effectiveness, completeness and applicability across different insurance organisations, RPA maturity levels and claims-handling environments require empirical validation in future research.</p>
</sec>
<sec id="s0012">
<title>Conclusion</title>
<p>For insurance organisations, initiation of the claims-handling process has been identified as the critical moment in the relationship between an insurer and the insured party, when the insured party demands that the insurer fulfil the obligations set out in the contract. A well-crafted insurance claims-handling process provides insurers with a competitive advantage, as customers highly value it. It is therefore essential to ensure that the process is efficient, reliable and transparent. However, the process remains predominantly manual because it involves handling data from various systems in different formats. Some of this data has been identified as manual and unstructured, with inconsistencies that lead to longer processing cycles, higher operational costs and a greater likelihood of fraud. As a result, insurers have adopted technologies such as RPA to improve efficiency, accuracy and consistency in their claims-handling processes.</p>
<p>While RPA offers clear benefits to insurers, this study shows that many projects fail to scale due to ungoverned challenges stemming from misalignment among IT, data and business operations. To address these challenges, this research developed a conceptual governance framework grounded in IT governance, data governance and IT capability theories. The governance framework guidelines were structured around the governance and management objectives of COBIT 2019 as the organising mechanism. Using a structured, trusted governance framework ensured that the challenges and guidelines were detailed and well organised. Through a structured literature review and a subsequent completeness check using COBIT 2019, governance guidelines were developed, mapped to the identified risks and organised into five domains that reflect how insurers typically manage IT governance. However, because the framework has not yet been empirically tested, the findings should be understood as a conceptual contribution rather than as evidence of practical effectiveness across all insurance contexts.</p>
<p>This framework shows how different categories of RPA implementation challenges may be addressed through targeted governance mechanisms. Technical and process-related challenges are addressed through guidelines on process standardisation, enterprise architecture, suitability assessment of automation, legacy system evaluation and technology integration. Data-related challenges are addressed through data architecture, privacy management, logging, monitoring and access-control mechanisms. Operational challenges are addressed through people and capability management, stakeholder engagement, change management, configuration management, capacity management and availability management. In this way, the framework provides a structured basis for considering how insurers may strengthen governance over RPA implementation in the claims-handling process.</p>
<p>From a practical perspective, the governance framework may assist those responsible for governance and IT management in an insurance organisation to support the identification, appropriate planning and management of implementation challenges that arise when using RPA to automate the insurance claims-handling process. Furthermore, internal and external assurance providers can utilise this framework to assess the risks and controls that should be in place for this technology. However, its practical use should be interpreted as guidance rather than as a validated implementation model. Further empirical research is required to test the framework across multiple RPA projects, insurance organisations and automated claims-handling processes, and to refine the framework based on evidence from practice.</p>
<p>From a theoretical perspective, this study contributes to the literature by demonstrating how COBIT 2019 can be utilised to conceptualise governance responses to automation challenges at the technical, data and operational governance levels. Furthermore, data governance theory is extended to the RPA environment to demonstrate how data integrity, privacy and accountability requirements are applied in this context. Finally, the IT capability theory is reinforced, as the developed governance framework demonstrates that appropriate governance mechanisms can help an RPA project succeed by adapting to the broader environment rather than just addressing risks within the project.</p>
<p>The recommendation for further research is to test the governance framework across multiple RPA projects and automated processes, and to refine it based on the additional knowledge that emerges. Similar studies are recommended, including RPA-complementary technologies such as AI and optical character recognition (OCR), to assess the framework&#x2019;s validity.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<p>This article is based on research originally conducted as part of Teboho Lefela&#x2019;s master&#x2019;s thesis titled &#x2018;What are the IT gap challenges that influence the failure of RPA automation projects for the motor vehicle accident claims handling processes?&#x2019;, submitted to the Faculty of Economic and Management Sciences, Stellenbosch University in 2021. The thesis was supervised by Christiaan Lamprecht. The thesis was reworked, revised and adapted into a journal article for publication. The authors confirm that the content has not been previously published or disseminated and complies with ethical standards for original publication.</p>
<p>This article is based on data from a larger study. A related article focusing on Technical and operational governance challenges of robotic process automation in the insurance claims handling process has been published in Southern African Journal of Accountability and Auditing Research Vol. 27, No. 1. The present article addresses a distinct research question, focusing on managing RPA implementation challenges in insurance claims-handling.</p>
<p>During the preparation of this work, the authors used Grammarly, V1.2.232.1818, for language editing. The content was reviewed and edited by the authors, who take full responsibility for its accuracy.</p>
<sec id="s20013" sec-type="COI-statement">
<title>Competing interest</title>
<p>The authors, Lee-Ann Pietersen, Teboho D. Lefela and Christiaan Lamprecht, declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20014">
<title>CRediT authorship contribution</title>
<p>Lee-Ann Pietersen: Investigation, Project administration, Validation, Writing &#x2013; original draft, Writing &#x2013; review &#x0026; editing. Teboho D. Lefela: Conceptualisation, Data curation, Formal analysis, Investigation, Methodology, Project administration, Validation, Writing &#x2013; original draft. Christiaan Lamprecht: Conceptualisation, Methodology, Supervision, Validation, Writing &#x2013; review &#x0026; editing. All authors reviewed the article, contributed to the discussion of results, approved the final version for submission and publication, and take responsibility for the integrity of its findings.</p>
</sec>
<sec id="s20015">
<title>Ethical considerations</title>
<p>This article followed all ethical standards for research without direct contact with human or animal subjects.</p>
</sec>
<sec id="s20016" sec-type="data-availability">
<title>Data availability</title>
<p>The data supporting the findings of this study consist of publicly available documents identified through a structured literature review. All sources are cited in the reference list and can be accessed via standard academic databases, institutional repositories, or publicly available online resources. No primary data were collected, and no restrictions apply to the availability of the referenced materials.</p>
</sec>
<sec id="s20017">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and are the product of professional research. They do not necessarily reflect the official policy or position of any affiliated institution, funder, agency or that of the publisher. The authors are responsible for this article&#x2019;s results, findings and content.</p>
</sec>
</ack>
<ref-list id="references">
<title>References</title>
<ref id="CIT0001"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Agostinelli</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Marrella</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Mecella</surname>, <given-names>M</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<chapter-title>Research challenges for intelligent robotic process automation</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>C.</given-names> <surname>Di Francescomarino</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Dijkman</surname></string-name> &#x0026; <string-name><given-names>U.</given-names> <surname>Zdun</surname></string-name> (eds.)</person-group>, <source><italic>Business process management</italic> workshops</source>, pp. <fpage>12</fpage>&#x2013;<lpage>18</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Cham</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Auth</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Czarnecki</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Bensberg</surname>, <given-names>F</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Impact of robotic process automation on enterprise architectures</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>C.</given-names> <surname>Draude</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Lange</surname></string-name> &#x0026; <string-name><given-names>B.</given-names> <surname>Sick</surname></string-name> (eds.)</person-group>, <conf-name>INFORMATIK 2019 workshops, Gesellschaft f&#x00FC;r Informatik, Bonn</conf-name>, Conference held <conf-date>September 23&#x2013;26, 2019</conf-date>, pp. <fpage>59</fpage>&#x2013;<lpage>65</lpage>.</mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Axmann</surname>, <given-names>B</given-names></string-name>. &#x0026; <string-name><surname>Harmoko</surname>, <given-names>H</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Robotic process automation: An overview and comparison to other technology in industry 4.0</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>M.</given-names> <surname>Dyvak</surname></string-name> (ed.)</person-group>, <conf-name>Proceedings of the 2020 10th International Conference on Advanced Computer Information Technologies (ACIT)</conf-name>, <conf-loc>IEEE, Deggendorf</conf-loc>, <conf-date>September 16&#x2013;18</conf-date>, pp. <fpage>559</fpage>&#x2013;<lpage>562</lpage>.</mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>De Haes</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Van Grembergen</surname>, <given-names>W</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>An exploratory study into IT governance implementations and its impact on business/IT alignment</article-title>&#x2019;, <source><italic>Information Systems Management</italic></source> <volume>26</volume>(<issue>2</issue>), <fpage>123</fpage>&#x2013;<lpage>137</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/10580530902794786">https://doi.org/10.1080/10580530902794786</ext-link></comment></mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>De Haes</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Van Grembergen</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Joshi</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Huygh</surname>, <given-names>T</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<chapter-title>COBIT as a framework for enterprise governance of IT</chapter-title>&#x2019;, in <source><italic>Enterprise governance of information technology: Achieving alignment and value in digital organizations</italic></source>, <edition>3rd edn.</edition>, pp. <fpage>125</fpage>&#x2013;<lpage>162</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Cham</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Delagrammatikas</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Stelios</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Tzavaras</surname>, <given-names>P</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>The role of RPA and data analysis in the transformation of the insurance and banking industries</article-title>&#x2019;, <source><italic>Encyclopedia</italic></source> <volume>5</volume>(<issue>4</issue>), <fpage>155</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/encyclopedia5040155">https://doi.org/10.3390/encyclopedia5040155</ext-link></comment></mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dogan</surname>, <given-names>O</given-names></string-name>., <string-name><surname>Arslan</surname>, <given-names>O</given-names></string-name>., <string-name><surname>Tirpan</surname>, <given-names>E.C</given-names></string-name>. &#x0026; <string-name><surname>Cebi</surname>, <given-names>S</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Risk assessment of employing digital robots in process automation</article-title>&#x2019;, <source><italic>Systems</italic></source> <volume>12</volume>(<issue>10</issue>), <fpage>428</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/systems12100428">https://doi.org/10.3390/systems12100428</ext-link></comment></mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Eling</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Nuessle</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Staubli</surname>, <given-names>J</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>The impact of artificial intelligence along the insurance value chain and on the insurability of risks</article-title>&#x2019;, <source><italic>The Geneva Papers on Risk and Insurance &#x2013; Issues and Practice</italic></source> <volume>47</volume>(<issue>2</issue>), <fpage>205</fpage>&#x2013;<lpage>241</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1057/s41288-020-00201-7">https://doi.org/10.1057/s41288-020-00201-7</ext-link></comment></mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Eulerich</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Waddoups</surname>, <given-names>N</given-names></string-name>., <string-name><surname>Wagener</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Wood</surname>, <given-names>D.A</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>The dark side of robotic process automation (RPA): Understanding risks and challenges with RPA</article-title>&#x2019;, <source><italic>Accounting Horizons</italic></source> <volume>38</volume>(<issue>2</issue>), <fpage>143</fpage>&#x2013;<lpage>152</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2308/HORIZONS-2022-019">https://doi.org/10.2308/HORIZONS-2022-019</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Flechsig</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Anslinger</surname>, <given-names>F</given-names></string-name>. &#x0026; <string-name><surname>Lasch</surname>, <given-names>R</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>Robotic process automation in purchasing and supply management: A multiple case study on potentials, barriers, and implementation</article-title>&#x2019;, <source><italic>Journal of Purchasing and Supply Management</italic></source> <volume>28</volume>(<issue>1</issue>), <fpage>100718</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.pursup.2021.100718">https://doi.org/10.1016/j.pursup.2021.100718</ext-link></comment></mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Fox</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Frimpong-Manso</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Sanchez</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Wheeler</surname>, <given-names>D</given-names></string-name></person-group>., <year>2021</year>, <source><italic>Robotic process automation analysis in the financial and insurance industries</italic></source>, <publisher-name>Worcester Polytechnic Institute (WPI)</publisher-name>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://digital.wpi.edu/downloads/h989r611r">https://digital.wpi.edu/downloads/h989r611r</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>Gartner</collab></person-group>, <year>2025</year>, <source><italic>Information technology glossary</italic></source>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.gartner.com/en/information-technology/glossary">https://www.gartner.com/en/information-technology/glossary</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Goosen</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Rudman</surname>, <given-names>R</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>An integrated framework to implement IT governance principles at a strategic and operational level for medium-to large-sized South African businesses</article-title>&#x2019;, <source><italic>International Business &#x0026; Economics Research Journal (IBER)</italic></source> <volume>12</volume>(<issue>7</issue>), <fpage>835</fpage>&#x2013;<lpage>854</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.19030/iber.v12i7.7972">https://doi.org/10.19030/iber.v12i7.7972</ext-link></comment></mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Yang</surname>, <given-names>L</given-names></string-name>., <string-name><surname>Zhou</surname>, <given-names>X</given-names></string-name>. &#x0026; <string-name><surname>Jiang</surname>, <given-names>G</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>The impact of big data technology application on the technical efficiency of insurance firms: Empirical evidence from Chinese insurers</article-title>&#x2019;, <source><italic>Finance Research Letters</italic></source> <volume>86</volume>, <fpage>108828</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.frl.2025.108828">https://doi.org/10.1016/j.frl.2025.108828</ext-link></comment></mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="thesis"><person-group person-group-type="author"><string-name><surname>Hartmann</surname>, <given-names>F</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Evolving digitisation: Chances and risks of robotic process automation and artificial intelligence for process optimisation within the supply chain</article-title>&#x2019;, <comment>Bachelor&#x2019;s dissertation</comment>, <publisher-name>Berlin School of Economics and Law</publisher-name>, <publisher-loc>Berlin</publisher-loc>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.theseus.fi/handle/10024/153503">https://www.theseus.fi/handle/10024/153503</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hilb</surname>, <given-names>M</given-names></string-name></person-group>., <year>2011</year>, &#x2018;<article-title>Redesigning corporate governance: Lessons learnt from the global financial crisis</article-title>&#x2019;, <source><italic>Journal of Management &#x0026; Governance</italic></source> <volume>15</volume>(<issue>4</issue>), <fpage>533</fpage>&#x2013;<lpage>538</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10997-010-9131-8">https://doi.org/10.1007/s10997-010-9131-8</ext-link></comment></mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Holder</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Khurana</surname>, <given-names>V</given-names></string-name>., <string-name><surname>Harrison</surname>, <given-names>F</given-names></string-name>. &#x0026; <string-name><surname>Jacobs</surname>, <given-names>L</given-names></string-name></person-group>., <year>2016</year>, &#x2018;<article-title>Robotics and law: Key legal and regulatory implications of the robotics age (Part I of II)</article-title>&#x2019;, <source><italic>Computer Law &#x0026; Security Review</italic></source> <volume>32</volume>(<issue>3</issue>), <fpage>383</fpage>&#x2013;<lpage>402</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.clsr.2016.03.001">https://doi.org/10.1016/j.clsr.2016.03.001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hong</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Ly</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Lin</surname>, <given-names>H</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Robotic process automation risk management: Points to consider</article-title>&#x2019;, <source><italic>Journal of Emerging Technologies in Accounting</italic></source> <volume>20</volume>(<issue>1</issue>), <fpage>125</fpage>&#x2013;<lpage>145</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2308/JETA-2022-004">https://doi.org/10.2308/JETA-2022-004</ext-link></comment></mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Horvat</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Ivani&#x0161;evi&#x0107;</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Glu&#x0161;&#x010D;evi&#x0107;</surname>, <given-names>L</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Risks associated with robotic process automation</article-title>&#x2019;, <source><italic>Journal of Process Management and New Technologies</italic></source> <volume>12</volume>(<issue>1&#x2013;2</issue>), <fpage>72</fpage>&#x2013;<lpage>82</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5937/jpmnt12-50617">https://doi.org/10.5937/jpmnt12-50617</ext-link></comment></mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>Information Systems Audit and Control Association (ISACA)</collab></person-group>, <year>2018</year>, <source><italic>COBIT<sup>&#x00AE;</sup> 2019 framework: Governance and management objectives</italic></source>, <publisher-name>ISACA</publisher-name>, <publisher-loc>Schaumburg, IL</publisher-loc>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://fliphtml5.com/qzvfo/unwt/basic">https://fliphtml5.com/qzvfo/unwt/basic</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ivan&#x010D;i&#x0107;</surname>, <given-names>L</given-names></string-name>., <string-name><surname>Su&#x0161;a Vugec</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Bosilj Vuk&#x0161;i&#x0107;</surname>, <given-names>V</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<chapter-title>Robotic process automation: Systematic literature review</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>C.</given-names> <surname>Di Ciccio</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Gabryelczyk</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Garc&#x00ED;a-Ba&#x00F1;uelos</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Hernaus</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Hull</surname></string-name>, <string-name><given-names>M.I.</given-names> <surname>&#x0160;temberger</surname></string-name>, <etal>et al</etal>. (eds.)</person-group>, <source><italic>Business process management: Blockchain and central and eastern europe forum (BPM 2019)</italic></source>, pp. <fpage>280</fpage>&#x2013;<lpage>295</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Cham</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khatri</surname>, <given-names>V</given-names></string-name>. &#x0026; <string-name><surname>Brown</surname>, <given-names>C.V</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Designing data governance</article-title>&#x2019;, <source><italic>Communications of the ACM</italic></source> <volume>53</volume>(<issue>1</issue>), <fpage>148</fpage>&#x2013;<lpage>152</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/1629175.1629210">https://doi.org/10.1145/1629175.1629210</ext-link></comment></mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Kirchmer</surname>, <given-names>M</given-names></string-name></person-group>., <year>2017</year>, <source><italic>Robotic process automation &#x2013; Pragmatic solution or dangerous illusion?</italic></source> <publisher-name>BPM-D</publisher-name>, <publisher-loc>West Chester, PA</publisher-loc>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/profile/Mathias-Kirchmer/publication/317730848_Robotic_Process_Automation_-_Pragmatic_Solution_or_Dangerous_Illusion/links/594f913da6fdccebfa69e543/Robotic-Process-Automation-Pragmatic-Solution-or-Dangerous-Illusion.pdf">https://www.researchgate.net/profile/Mathias-Kirchmer/publication/317730848_Robotic_Process_Automation_-_Pragmatic_Solution_or_Dangerous_Illusion/links/594f913da6fdccebfa69e543/Robotic-Process-Automation-Pragmatic-Solution-or-Dangerous-Illusion.pdf</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lamberton</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Brigo</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Hoy</surname>, <given-names>D</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Impact of robotics, RPA and AI on the insurance industry: Challenges and opportunities</article-title>&#x2019;, <source><italic>Journal of Financial Perspectives</italic></source> <volume>4</volume>(<issue>1</issue>), <fpage>8</fpage>&#x2013;<lpage>20</lpage>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3079495">https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3079495</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Madakam</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Holmukhe</surname>, <given-names>R.M</given-names></string-name>. &#x0026; <string-name><surname>Jaiswal</surname>, <given-names>D.K</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The future digital work force: Robotic process automation (RPA)</article-title>&#x2019;, <source><italic>Journal of Information Systems and Technology Management</italic></source> <volume>16</volume>(<issue>1</issue>), <fpage>e201916001</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4301/S1807-1775201916001">https://doi.org/10.4301/S1807-1775201916001</ext-link></comment></mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Mannix</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Sethuraman</surname>, <given-names>S</given-names></string-name></person-group>., <year>2020</year>, <source><italic>Automating for end-to-end claims processing: How design thinking combined with automation technology pushes insurers to evolve</italic></source>, <publisher-name>UiPath</publisher-name>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.uipath.com/hubfs/Whitepapers/Automating_for_End-to-End_Claims_Processing_Whitepaper.pdf?_hsenc=p2ANqtz-_6hfNZU63XlphD9lOY1QpDFNa7Ig-k0eZY8xXU8_aYNifW6StsUYWl9OzgsthQxpf-Kw8VJcyccWlgWK3nM9NQv_HaTg&#x0026;_hsmi=77661930">https://www.uipath.com/hubfs/Whitepapers/Automating_for_End-to-End_Claims_Processing_Whitepaper.pdf?_hsenc=p2ANqtz-_6hfNZU63XlphD9lOY1QpDFNa7Ig-k0eZY8xXU8_aYNifW6StsUYWl9OzgsthQxpf-Kw8VJcyccWlgWK3nM9NQv_HaTg&#x0026;_hsmi=77661930</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Noppen</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Beerepoot</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Van de Weerd</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Jonker</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>Reijers</surname>, <given-names>H.A</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<chapter-title>How to keep RPA maintainable?</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>D.</given-names> <surname>Fahland</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Ghidini</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Becker</surname></string-name> &#x0026; <string-name><given-names>M.</given-names> <surname>Dumas</surname></string-name> (eds.)</person-group>, <source><italic>Business process management (BPM 2020)</italic></source>, pp. <fpage>453</fpage>&#x2013;<lpage>470</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Cham</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Okoli</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Schabram</surname>, <given-names>K</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>A guide to conducting a systematic literature review of information systems research</article-title>&#x2019;, <source><italic>Sprouts: Working Papers on Information Systems</italic></source> <volume>10</volume>(<issue>26</issue>), <fpage>1954824</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2139/ssrn.1954824">https://doi.org/10.2139/ssrn.1954824</ext-link></comment></mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Osmundsen</surname>, <given-names>K</given-names></string-name>., <string-name><surname>Iden</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Bygstad</surname>, <given-names>B</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Organizing robotic process automation: Balancing loose and tight coupling</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>T.X.</given-names> <surname>Bui</surname></string-name> (ed.)</person-group>, <conf-name>Proceedings of the 52nd Hawaii International Conference on System Sciences (HICSS)</conf-name>, <conf-loc>University of Hawaii, Maui, HI</conf-loc>, <conf-date>January 08&#x2013;11</conf-date>, pp. <fpage>6918</fpage>&#x2013;<lpage>6926</lpage>.</mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Page</surname>, <given-names>M.J</given-names></string-name>., <string-name><surname>McKenzie</surname>, <given-names>J.E</given-names></string-name>., <string-name><surname>Bossuyt</surname>, <given-names>P.M</given-names></string-name>., <string-name><surname>Boutron</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Hoffmann</surname>, <given-names>T.C</given-names></string-name>., <string-name><surname>Mulrow</surname>, <given-names>C.D</given-names></string-name>. <etal>et al</etal></person-group>., <year>2021</year>, &#x2018;<article-title>The PRISMA 2020 statement: An updated guideline for reporting systematic reviews</article-title>&#x2019;, <source><italic>British Medical Journal</italic></source> <volume>372</volume>, <issue>n71</issue>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1136/bmj.n71">https://doi.org/10.1136/bmj.n71</ext-link></comment></mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Patri</surname>, <given-names>P</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Robotic process automation: Challenges and solutions for the banking sector</article-title>&#x2019;, <source><italic>International Journal of Management (IJM)</italic></source> <volume>11</volume>(<issue>12</issue>), <fpage>322</fpage>&#x2013;<lpage>333</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.34218/ijm.11.12.2020.031">https://doi.org/10.34218/ijm.11.12.2020.031</ext-link></comment></mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pavlou</surname>, <given-names>P.A</given-names></string-name>. &#x0026; <string-name><surname>El Sawy</surname>, <given-names>O.A</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>The &#x201C;third hand&#x201D;: IT-enabled competitive advantage in turbulence through improvisational capabilities</article-title>&#x2019;, <source><italic>Information Systems Research</italic></source> <volume>21</volume>(<issue>3</issue>), <fpage>443</fpage>&#x2013;<lpage>471</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1287/isre.1100.0280">https://doi.org/10.1287/isre.1100.0280</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pietersen</surname>, <given-names>L.-A</given-names></string-name>., <string-name><surname>Lefela</surname>, <given-names>T</given-names></string-name>. &#x0026; <string-name><surname>Lamprecht</surname>, <given-names>C</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>Technical and operational governance challenges of robotic process automation in the insurance claims handling process</article-title>&#x2019;, <source><italic>Southern African Journal of Accountability and Auditing Research</italic></source> <volume>27</volume>(<issue>1</issue>), <fpage>45</fpage>&#x2013;<lpage>58</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.54483/sajaar.2025.27.1.3">https://doi.org/10.54483/sajaar.2025.27.1.3</ext-link></comment></mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rensleigh</surname>, <given-names>C</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>The integral role of systematic reviews in the information and knowledge management field</article-title>&#x2019;, <source><italic>South African Journal of Information Management</italic></source> <volume>27</volume>(<issue>1</issue>), <fpage>a2093</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v27i1.2093">https://doi.org/10.4102/sajim.v27i1.2093</ext-link></comment></mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Schlegel</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Rosenberg</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Fundanovic</surname>, <given-names>O</given-names></string-name>. &#x0026; <string-name><surname>Kraus</surname>, <given-names>P</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>How to conduct successful business process automation projects? An analysis of key factors in the context of robotic process automation</article-title>&#x2019;, <source><italic>Business Process Management Journal</italic></source> <volume>30</volume>(<issue>8</issue>), <fpage>99</fpage>&#x2013;<lpage>119</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/BPMJ-06-2023-0465">https://doi.org/10.1108/BPMJ-06-2023-0465</ext-link></comment></mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="thesis"><person-group person-group-type="author"><string-name><surname>Sigur&#x00F0;ard&#x00F3;ttir</surname>, <given-names>G.L</given-names></string-name></person-group>., <year>2018</year>, &#x2018;<article-title>Robotic process automation: Dynamic roadmap for successful implementation</article-title>&#x2019;, <comment>Master&#x2019;s dissertation</comment>, <publisher-name>Reykjavik University</publisher-name>, <publisher-loc>Reykjavik</publisher-loc>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://hdl.handle.net/1946/31385">https://hdl.handle.net/1946/31385</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="thesis"><person-group person-group-type="author"><string-name><surname>Smit</surname>, <given-names>S</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<article-title>Defining and reducing the IT gap by means of comprehensive alignment</article-title>&#x2019;, <comment>Master&#x2019;s dissertation</comment>, <publisher-name>Stellenbosch University</publisher-name>, <publisher-loc>Stellenbosch</publisher-loc>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="http://hdl.handle.net/10019.1/15038">http://hdl.handle.net/10019.1/15038</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sobczak</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Ziora</surname>, <given-names>L</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>The use of robotic process automation (RPA) as an element of smart city implementation: A case study of electricity billing document management at Bydgoszcz City Hall</article-title>&#x2019;, <source><italic>Energies</italic></source> <volume>14</volume>(<issue>16</issue>), <fpage>5191</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/en14165191">https://doi.org/10.3390/en14165191</ext-link></comment></mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Surya</surname>, <given-names>H.A</given-names></string-name>., <string-name><surname>Sukono</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Napitupulu</surname>, <given-names>H</given-names></string-name>. &#x0026; <string-name><surname>Ismail</surname>, <given-names>N</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>A systematic literature review of insurance claims risk measurement using the hidden markov model</article-title>&#x2019;, <source><italic>Risks</italic></source> <volume>12</volume>(<issue>11</issue>), <fpage>169</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/risks12110169">https://doi.org/10.3390/risks12110169</ext-link></comment></mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Syed</surname>, <given-names>R</given-names></string-name>., <string-name><surname>Suriadi</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Adams</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Bandara</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Leemans</surname>, <given-names>S.J.J</given-names></string-name>., <string-name><surname>Ouyang</surname>, <given-names>C</given-names></string-name>. <etal>et al</etal></person-group>., <year>2020</year>, &#x2018;<article-title>Robotic process automation: Contemporary themes and challenges</article-title>&#x2019;, <source><italic>Computers in Industry</italic></source> <volume>115</volume>, <fpage>103162</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.compind.2019.103162">https://doi.org/10.1016/j.compind.2019.103162</ext-link></comment></mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tasdemir</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Alsu</surname>, <given-names>E</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>The relationship between activities of the insurance industry and economic growth: The case of G-20 economies</article-title>&#x2019;, <source><italic>Sustainability</italic></source> <volume>16</volume>(<issue>17</issue>), <fpage>7634</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/su16177634">https://doi.org/10.3390/su16177634</ext-link></comment></mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Thabit</surname>, <given-names>T.H</given-names></string-name>., <string-name><surname>Ishhadat</surname>, <given-names>H.S</given-names></string-name>. &#x0026; <string-name><surname>Abdulrahman</surname>, <given-names>O.T</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Applying data governance based on COBIT2019 framework to achieve sustainable development goals</article-title>&#x2019;, <source><italic>Journal of Techniques</italic></source> <volume>2</volume>(<issue>3</issue>), <fpage>9</fpage>&#x2013;<lpage>18</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.51173/jt.v2i3.212">https://doi.org/10.51173/jt.v2i3.212</ext-link></comment></mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Tkaczyk</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Skibinski</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Jaskulska</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Abramczuk</surname>, <given-names>K</given-names></string-name>., <string-name><surname>Biele</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Marasek</surname>, <given-names>K</given-names></string-name>. <etal>et al</etal></person-group>., <year>2018</year>, &#x2018;<article-title>Hybrid approach to automation, RPA and machine learning: A method for the human-centered design of software robots</article-title>&#x2019;, in <conf-name>CSCW&#x2019; 18 Workshop on Industrial Internet of Things, Association for Computing Machinery</conf-name>, <conf-loc>New York, USA</conf-loc>, <conf-date>November 3&#x2013;7, 2018</conf-date>.</mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Treacy</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Adyanthaya</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Kearny</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Anand</surname>, <given-names>J</given-names></string-name>., <string-name><surname>O&#x2019;Sullivan</surname>, <given-names>K</given-names></string-name>. &#x0026; <string-name><surname>Xu</surname>, <given-names>Y</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>From hype to reality: Navigating the challenges of RPA implementation</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>F.</given-names> <surname>Moreira</surname></string-name> &#x0026; <string-name><given-names>S.</given-names> <surname>Jayantilal</surname></string-name> (eds.)</person-group>, <conf-name>Proceedings of the 18th European Conference on Innovation and Entrepreneurship</conf-name>, Part 2, vol. <volume>18</volume>, no. <issue>2</issue>, <conf-loc>Academic Conferences International Limited, Reading, UK</conf-loc>, <conf-date>September 21&#x2013;22, 2023</conf-date>, pp. <fpage>875</fpage>&#x2013;<lpage>882</lpage>.</mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Volz</surname>, <given-names>F</given-names></string-name>., <string-name><surname>M&#x00FC;nch</surname>, <given-names>C</given-names></string-name>., <string-name><surname>Lohm&#x00FC;ller</surname>, <given-names>M</given-names></string-name>. &#x0026; <string-name><surname>K&#x00FC;ffner</surname>, <given-names>C</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>From data jungle to data governance in digital ecosystems: Empirical evidence from a multiple holistic case study</article-title>&#x2019;, <source><italic>Journal of Business Research</italic></source> <volume>201</volume>, <fpage>115747</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.jbusres.2025.115747">https://doi.org/10.1016/j.jbusres.2025.115747</ext-link></comment></mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Webster</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Watson</surname>, <given-names>R.T</given-names></string-name></person-group>., <year>2002</year>, &#x2018;<article-title>Analyzing the past to prepare for the future: Writing a literature review</article-title>&#x2019;, <source><italic>MIS Quarterly</italic></source> <volume>26</volume>(<issue>2</issue>), <fpage>xiii</fpage>&#x2013;<lpage>xxiii</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2307/4132319">https://doi.org/10.2307/4132319</ext-link></comment></mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Weill</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Ross</surname>, <given-names>J.W</given-names></string-name></person-group>., <year>2004</year>, <source><italic>IT governance: How top performers manage IT decision rights for superior results</italic></source>, <publisher-name>Harvard Business School Press</publisher-name>, <publisher-loc>Boston</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Weritz</surname>, <given-names>P</given-names></string-name>., <string-name><surname>Braojos</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Matute</surname>, <given-names>J</given-names></string-name>. &#x0026; <string-name><surname>Benitez</surname>, <given-names>J</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>Impact of strategic capabilities on digital transformation success and firm performance: Theory and empirical evidence</article-title>&#x2019;, <source><italic>European Journal of Information Systems</italic></source> <volume>34</volume>(<issue>3</issue>), <fpage>415</fpage>&#x2013;<lpage>435</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/0960085X.2024.2311137">https://doi.org/10.1080/0960085X.2024.2311137</ext-link></comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Yadav</surname>, <given-names>S.S.K</given-names></string-name>. &#x0026; <string-name><surname>Mishra</surname>, <given-names>G</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Robotic process automation applications across industries: An exploration</article-title>&#x2019;, in <conf-name>Proceedings of the 2024 7th International Conference on Contemporary Computing and Informatics (IC3I)</conf-name>, <conf-loc>IEEE, Greater Noida</conf-loc>, <conf-date>September 18&#x2013;20</conf-date>, pp. <fpage>26</fpage>&#x2013;<lpage>32</lpage>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://ieeexplore.ieee.org/document/10828986/authors#authors">https://ieeexplore.ieee.org/document/10828986/authors#authors</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="conference"><person-group person-group-type="author"><string-name><surname>Yatskiv</surname>, <given-names>N</given-names></string-name>., <string-name><surname>Yatskiv</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Vasylyk</surname>, <given-names>A</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Method of robotic process automation in software testing using artificial intelligence</article-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>M.</given-names> <surname>Dyvak</surname></string-name> (ed.)</person-group>, <conf-name>Proceedings of the 2020 10th International Conference on Advanced Computer Information Technologies (ACIT)</conf-name>, <conf-loc>IEEE, Deggendorf</conf-loc>, <conf-date>September 16&#x2013;18</conf-date>, pp. <fpage>501</fpage>&#x2013;<lpage>504</lpage>.</mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yusuf</surname>, <given-names>T.O</given-names></string-name>. &#x0026; <string-name><surname>Ajemunigbohun</surname>, <given-names>S.S</given-names></string-name></person-group>., <year>2015</year>, &#x2018;<article-title>Effectiveness, efficiency, and promptness of claims handling process in the Nigerian insurance industry</article-title>&#x2019;, <source><italic>European Journal of Business and Economics</italic></source> <volume>10</volume>(<issue>2</issue>), <fpage>6</fpage>&#x2013;<lpage>10</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.12955/ejbe.v10i2.686">https://doi.org/10.12955/ejbe.v10i2.686</ext-link></comment></mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yusuf</surname>, <given-names>T.O</given-names></string-name>., <string-name><surname>Ajemunigbohun</surname>, <given-names>S.S</given-names></string-name>. &#x0026; <string-name><surname>Alli</surname>, <given-names>G.N</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>A critical review of insurance claims management: A study of selected insurance companies in Nigeria</article-title>&#x2019;, <source><italic>Journal of Economics and Business</italic></source> <volume>67</volume>(<issue>2</issue>), <fpage>69</fpage>&#x2013;<lpage>84</lpage>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://hdl.handle.net/10419/195195">https://hdl.handle.net/10419/195195</ext-link>.</comment></mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname>, <given-names>Y</given-names></string-name>. &#x0026; <string-name><surname>Guo</surname>, <given-names>L</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Assessing the efficiency gains and operational risks of implementing robotic process automation in healthcare insurance claims processing</article-title>&#x2019;, <source><italic>Studies in Knowledge Discovery, Intelligent Systems, and Distributed Analytics</italic></source> <volume>14</volume>(<issue>12</issue>), <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <comment>viewed 06 November 2025, from <ext-link ext-link-type="uri" xlink:href="https://edgescholar.com/index.php/SKDISDA/article/view/e-2024-12-04">https://edgescholar.com/index.php/SKDISDA/article/view/e-2024-12-04</ext-link>.</comment></mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Pietersen, L.-A., Lefela, T.D. &#x0026; Lamprecht, C., 2026, &#x2018;A conceptual governance framework for managing robotic process automation implementation challenges in insurance claims handling&#x2019;, <italic>South African Journal of Information Management</italic> 28(1), a2169. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v28i1.2169">https://doi.org/10.4102/sajim.v28i1.2169</ext-link></p></fn>
</fn-group>
</back>
</article>