Circular Image

N. Bharosa

info

Please Note

41 records found

Trust Anchors in the Trust Framework Lifecycle

Trust is a crucial factor in multi-actor data-sharing initiatives, particularly in sensitive domains like healthcare, where patient privacy, regulatory requirements, and organizational collaboration intersect. However, achieving trust-by-design, creating trust through intentional design choices, is challenging. To address this challenge, this paper investigates how trust frameworks in healthcare data-sharing are designed and how they evolve over time. Central to this inquiry is the conceptualization of “trust anchors”– designable components that provide a foundation for creating trust. Drawing on Technological Innovative Systems theory, this research qualitatively examines two healthcare trust frameworks, each at different lifecycle stages. The case studies reveal how trust anchors contribute to both the development and active management of trust frameworks. The contribution includes a lifecycle approach for trust frameworks and a matrix for categorizing trust anchors, providing guidance for organizations aiming to implement and maintain multi-actor data-sharing frameworks. We find that enforceable trust anchors are more important in the mature phase of a trust frameworks, while in the growing phase, less designable and enforceable trust factors assume a greater role. ...
Conference paper (2026) - Maria Haasnoot, Marijn Janssen, Nitesh Bharosa
Governments struggle to exercise control over their digitalization efforts, often with many risks and uncertainties. Literature on IT control provides a fragmented understanding of government-specific digitalization areas. This paper systematically identifies and analyzes different areas of IT control through a systematic literature review, resulting in a novel classification. The literature review reveals that the current classifications of IT controls are fragmented, lack coherence, are incomplete, and depend on the research field and the language in which the data was collected. The novel classification presented in the paper focuses not only on technology, but also on the whole domain of digitalization, including the arrangements of organizations and projects, data management, agreements with other organizations, and the achievement of political ambitions and goals. This paper gives insights into the areas of control and argues that more research is needed to understand differences among government IT control approaches. ...

Co-Creating Multi-Actor Agreements for Data Sharing

Companies and public agencies who are looking to improve their services can benefit from more data sharing. However, due to regulations and security concerns, data sharing between individuals, businesses and public agencies is complicated. There are many variables to consider in a multi-actor environment where actors with various roles and incentives look for legal and technical certainty. Public and private organizations increasingly acknowledge the need for multi-organizational agreements on data sharing standards. This results in the rise of trust frameworks to guide efforts towards trustworthy data sharing in an interorganizational setting. However, academic literature on trust frameworks is scarce, and we lack a systematic understanding of the factors that constitute trust in a multi-actor data sharing environment. The objective of this paper is to provide a systematic understanding of the antecedents of trust playing a role in trust frameworks. A two-stage approach is followed, starting with a systematic review of antecedents, followed by an empirical inquiry as verification. Our findings indicate a wide range of antecedents - including technological and organizational antecedents - can be considered. ...
Conference paper (2025) - Nard Janssens, Marijn Janssen, Nitesh Bharosa
Central government policy departments need to collaborate with executive agencies to provide IT-based services to society. These collaborations are complicated by the fact that the executive agencies are controlled by different ministerial hierarchies, resulting in conflicting interests. Yet, a detailed analysis of these challenges is lacking in the literature. In this paper, we analyze the challenges at several ministries through interviews focused on specific cases as well as interviews focused on expert knowledge. We identified the challenge themes and compared them with the literature, finding several new challenges in practice, including restricted procurement, a Goldilocks zone for escalation, the inability to hold an agent ultimately accountable, and the low priority the central government policy departments give to the implementation. Paradoxically, central government policy departments, as principals, are less powerful and highly dependent on executive agencies instead of the other way around, as suggested by principal-agent theory. These findings imply that there is a need for new governance mechanisms able to deal with all the challenges encountered. The overview of the challenges can serve as a sound foundation for conducting further research into cross-ministerial governance. ...

Developing a taxonomy for classifying digital wallets

Conference paper (2025) - Bert Lukkien, Mark de Reuver, Nitesh Bharosa
Digital wallets are emerging as new tools that provide citizens with control over their personal data while allowing innovation in service delivery. Wallets promise various functionalities, from authentication, authorisation, and signing, to storage and generating qualified electronic attestations. Given the potential, policymakers and service providers face significant challenges in selecting, developing, implementing, and regulating digital wallets due to the lack of clarity about their characteristics. This paper focuses on this lack of clarity. Through a socio-technical systems theory lens, we developed a comprehensive taxonomy for classifying digital wallets. Our empirical analysis reveals a taxonomy of 47 characteristics in 14 dimensions. The contribution of this taxonomy is two-fold. Firstly, it can help develop a more precise theory on specific types of wallets. Secondly, actors in the field can use the taxonomy for more granular communication on wallet development and adoption challenges, standardisation efforts, and policy development. ...
Conference paper (2024) - Antonia Sattlegger, Nitesh Bharosa
Artificial intelligence (AI) adoption by public sector organizations (PSOs) introduces various ethical risks stemming from a lack of integrating human values into AI design. Addressing these ethical risks is a complex collective responsibility among designers, developers, risk experts, and public sector managers. Embedding these risks in existing risk management practices is crucial for responsible AI adoption, as emphasized by the legal requirements of the EU AI Act. However, the responsibility for managing these ethical risks is often unclear. Public sector organizations face unique challenges due to the complex, uncertain, and rapidly evolving nature of AI technologies, further complicating the management of ethical risks. This paper explores using the Three Lines of Defense (TLoD) risk management model to understand and address these ethical risks in public sector AI adoption. The TLoD model structures risk management across three lines: operational management, risk oversight and compliance, and internal audit. This framework helps to distribute and integrate the collective responsibility for ethical AI risk management within public sector organizations, emphasizing alignment and collaboration among different actors. Through an exploratory study involving a survey and semi-structured interviews with professionals responsible for AI-related risk management in Dutch public sector organizations, we assess the TLoD model’s usefulness in addressing ethical AI risks. The study examines the challenges and opportunities in applying the TLoD model to manage ethical risks and identifies the potential gaps in responsibility and oversight. The findings suggest that while the TLoD model offers a valuable lens for distributing risk management responsibilities, there are limitations in addressing the emergent and complex nature of ethical risks in AI adoption. ...

Implementation and adoption challenges and policy recommendations for quantum-safe transitions

Journal article (2024) - Ini Kong, Marijn Janssen, Nitesh Bharosa
By utilizing the properties of quantum mechanics, quantum computers have the potential to factor a key pair of a large prime number and break some of the core cryptographic primitives that most information infrastructures depend on. This means that today's widely used cryptographic algorithms can soon become unsafe and need to be modified with quantum-safe (QS) cryptography. While much work is still needed in developing QS cryptographic algorithms, the institutional, organizational, and policy aspects of transitioning the current infrastructures have received less attention. This paper provides an empirical analysis of QS transition challenges and policy recommendations for moving to a QS situation. We analyzed the data collected through interviews with experts and practitioners from the Dutch government. The results reveal that institutional, organizational and policy aspects of QS transitions are interconnected, and solutions for QS transitions are scattered. Consequently, organizations may face a Catch-22 loop without further actionable approaches and planning for QS transitions. ...

Goals and Components Identified Through a Case Study

Conference paper (2024) - L. Van der Peet, Nitesh Bharosa, Sander Dijkhuis, M.F.W.H.A. Janssen
Amidst increasing online data sharing among organisations, there is a growing need for interoperability and trust in the digital space. When there is no infrastructure provider for sharing information (e.g. by Big Tech players and/or government-owned infrastructures), public and private actors must figure out how to reach agreements about the technical specifications and data infrastructure components to facilitate inter-organizational collaboration. This paper zooms in on the empirical phenomenon of trust frameworks emerging in practice. The main research question is twofold: (1) what are the goals actors strive for with trust frameworks and (2) which components are developed for achieving these goals? Drawing on previous literature and a case study approach, interoperability, certainty, efficiency, and security emerge as goals of trust frameworks. As for the second question, we draft an exhaustive diagram of components from both the literature and our case study. This explorative research lays the foundation for future research into trust frameworks as a major change in traditional approaches to cross-sector data exchange. ...
Conference paper (2024) - Wout Hofman, B.D. Rukanova, Y. Tan, Nitesh Bharosa, J. Ubacht, Elmer Rietveld
The transition towards a circular economy (CE) will require data sharing across different platforms and data spaces of parties operating in a variety of supply chains. From a circular economy compliance monitoring perspective, beyond the access to mandatory data that governments will receive, authorities may benefit from accessing additional business data from the source on a voluntary basis, which is challenging. While platforms and data spaces solve a great deal of complexity and interoperability within their realm, platform, and data space interoperability is still challenging. In the logistics domain, efforts have been made to overcome these issues of data sharing across logistics platforms with a Semantic data sharing architecture developed by the CEF FEDeRATED Action, at the heart of which is a semantic model aligning other semantic models for logistics. In this paper, we take the Semantic data sharing architecture as a point of departure and examine the opportunities and limitations that it has for CE monitoring, and how it relates to other developments in the EU and beyond. Many of these developments acknowledge the need for data access across heterogeneous systems and – processes of actors; others add security and trust to data sharing that goes all the way to the level to cover legal obligations. The goal of this paper is to gain further insights into how data sharing across multiple platforms and data spaces enables circular economy monitoring, where government organizations would need to address the issue of how they would interface with, and access data that resides in multiple platforms and data spaces. We found that the various models can be aligned on some architecture principles that promote interoperability across dimensions (e.g. federation, keeping data at the source), yet they still differ on other dimensions (e.g. data model and semantics, as well as how they address issues of identification, authentication and authorization). We suggest further efforts towards developing meta-level agreements and standardization for data space interoperability and we propose further research directions on that topic. ...
Journal article (2024) - Henk Marsman, Michael Klenk, Mark de Reuver, Nitesh Bharosa
The European Union (EU) Digital Identity Wallet (DIW) intends to give citizens control over personal data sharing. The DIW users will have full and sole control over their data. The EU intends to address the risk to citizens' privacy in cases where data from and about users is gathered and exchanged by online service providers. However, it is unclear how users of the EU DIW can decide what data to share and how to prevent sharing too much data with online service providers. In order to reduce this risk, we need to understand it first. Drawing on expert interviews, this paper presents a novel analysis of the risk of over sharing through the EU DIW. It defines the risk and what aspects influence the risk from literature, documentation and expert interviews. Over-sharing data occurs when users share more data than strictly required for the service or product acquired online and multiple aspects influence this risk, specifically the user capabilities and orientation, the loss of context awareness, the quality of the data and the ease of sharing. ...
Conference paper (2024) - Kong Ini, Janssen Marijn, Bharosa Nitesh
Ensuring the secure provision of data and services using critical information infrastructures amidst the evolving technology landscape is a crucial yet recurrent task. However, these infrastructures can become vulnerable due to developments in quantum computing and modifying the infrastructures with quantum-safe (QS) technology is unlike regular control and maintenance. Organizations need to modify their cryptographic layers, which act as the fundamental building blocks of infrastructures. For organizations, many uncertainties pose challenges across technological, organizational and ecosystem areas. While QS technology is new and not yet available for implementation and adoption, changes in critical information infrastructures require collaboration among multiple public and private organizations spanning industries and borders. By understanding the roles, organizations may better understand what should be done for QS transitions. Until now, there has been no academic research examining the roles that government could or should play in QS transitions. This paper reveals 12 different roles, showing the diversity and breadth of actions needed. While there are many possible roles that still need to be allocated for coordinated efforts, there is a high reliance on the government, and organizations are waiting for and expecting governments to take more active roles in QS transitions. The results also signals that QS transition research is at its early stage with a clear governance void and lack of collective urgency in the ecosystem. ...
Conference paper (2024) - I. Kong, M.F.W.H.A. Janssen, Nitesh Bharosa
When implementing and adopting new technologies, knowing the level of organizational readiness is crucial. By assessing the readiness levels, organizations can focus on areas with low readiness levels and prepare for the change processes. Due to the increasing vulnerabilities presented by the advancement of quantum computing technology, today’s widely used cryptographic algorithms and encryption methods need to be modified with quantum-safe (QS) ones. However, organizations currently lack tools to understand the complexity of implementing and adopting QS technology, and there is no readiness assessment model available in the context of QS transition. By including different dimensions that organizations should consider when implementing and adopting QS technology, we develop an organizational readiness assessment model for QS transition. The dimensions used in the model include collaboration, governance, policy & regulation, awareness, QS solution standards, hybrid QS solutions, cryptographic agility strategies and knowledge on QS transition. While the organizational readiness assessment model with different dimensions shows the complexity involved in implementing and adopting QS technology, it acts as a guidance tool for organizations to navigate and prepare for uncertainties surrounding QS transition. ...
Conference paper (2024) - Nitesh Bharosa, Tomasz Janowski
Governments struggle to harness emerging technologies to improve public services, address social needs, and produce public value. In response, we see a rise in GovTech startups and other non-government actors trying to bring innovative solutions to governments. While some public agencies welcome such help, many are reluctant to rely on external organizations to provide digital identities, data wallets and AI-based services to citizens, businesses, and the government itself. Many also fear engaging a dynamic ecosystem of small non-government actors working together and gaining more experience in the process. Consequently, the GovTech supply and demand are misaligned with each other and the public value imperative. Public tendering may help but does not protect against vendor lock-in and innovation-blocking. Co-creation of public and private solutions may be technically possible but may face institutional void, calling for trust frameworks, steward-ownership, ecosystem building or other alternative instruments. This paper presents a research challenge to examine GovTech evidence, learn about applicable theories, methods and knowledge gaps, and formulate theoretically and empirically well-grounded recommendations on GovTech and public value creation. It also outlines the response to the challenge: organizing a dg.o 2024 workshop and developing a special issue of Government Information Quarterly (GIQ). ...

A case study of GovTech ecosystems in the Netherlands and Lithuania

Conference paper (2023) - Marissa Hoekstra, Anne Fleur Van Veenstra, Nitesh Bharosa
GovTech, an acronym of Government Technologies, is a novel concept that is gaining attention in the public and private sector. It entails improving the design and delivery of human centric public services and data-driven processes with the use of emerging (digital) technologies. Furthermore, GovTech is concerned with the development of digital technologies that are used in these processes or services, but that are often developed by organizations outside the public sector. As a result, GovTech ecosystems emerge, in which public and private organizations as well as civic partners, including citizens, collaborate. GovTech ecosystems can be defined as networks of citizens, public and private actors, academia, and (venture) capital involved in the development of technological solutions to address public challenges. At this moment, literature on GovTech is still scarce and empirical studies into the emergence and impact of GovTech ecosystems are even scarcer. Therefore, this study explores the emergence and development of GovTech ecosystems. More specifically, the goal of this study is to contribute to the understanding of the barriers and success factors for the emergence of GovTech ecosystems. To do so, this paper conducts an explorative case study of success factors and barriers of GovTech ecosystems in two frontrunner countries: the Netherlands and Lithuania. Regarding the emergence of GovTech ecosystems, we find that the way in which the two GovTech ecosystems emerged and are built up, differs. Whereas the ecosystem in Lithuania is more centralized, the ecosystem in the Netherlands is more scattered. In addition, we find that factors that contribute to successful GovTech ecosystems include public-private collaborations, having a clear vision and strategy, sufficient space for experimentation, having infrastructure, networks and initiatives in place that stimulate sharing of knowledge and resources, and the presence of a culture of co-creation and innovation. ...
Conference paper (2023) - Bert Lukkien, Mark De Reuver, Nitesh Bharosa
Across the European continent, governments and GovTech companies are rushing to launch digital identity wallets for citizens. These wallets should allow citizens to obtain a higher level of control over their personal data. While there are some regulations and policy directions, actors are struggling with the design, launch, and governance of these digital wallets. Those looking for help will find little guidance in academic literature. The objective of this paper is to provide insights in barriers for launching digital identity wallets by a public-private ecosystem. Drawing on the case study approach, we study the available regulations and policy directions, and collect insights from workshops with policy makers and aspiring wallet providers. The main findings indicate that barriers such as the lack of boundary resources (e.g. shared data specifications and exchange standards) and the absence of a collaborative, public-private governance impede the launch of digital identity wallets. Policy makers looking to speed up the launch of digital wallets must focus on removing these barriers, starting with the development and governance of boundary resources by the public-private ecosystem. ...

Recommended policy guidelines to aid and facilitate collective action in migration towards quantum-safe public key infrastructure systems

As the development of quantum computers advances, actors relying on public key infrastructures (PKI) for secure information exchange are becoming aware of the disruptive implications. Currently, governments and businesses employ PKI for many core processes that may become insecure or unavailable when quantum computers break the cryptographic algorithms foundational to PKI. While standardization institutes are currently testing quantum safe cryptographic algorithms, there are no globally agreed-upon cryptographic solutions available. Actors looking to prepare for the implementation of quantum safe cryptographic algorithms lack methods that allow for collective planning and action across organizations, sectors, and nations. The goal of this policy paper is to elicit requirements for a serious game on QS PKI, and derive policy guidelines that actors can use to prepare and formulate governance arrangements. We followed a two-step approach, drawing on technology threat avoidance theory and collective action theory, followed by empirical grounding through a focus group. The results from the literature confirm that a serious game could be a suitable governance mechanism for QS PKI. The focus group results discussed 12 requirements and the requirement's relation to the theoretical background. From this, the findings section arrived at four policy guidelines derived from the requirements that can function as focus areas for further requirement development and as input for policy makers. The policy guidelines concluded are (1) prioritize increasing collective awareness through emphasizing social networks, (2) acknowledge the interdependencies in migrating towards QS PKI, (3) create an understanding of the technical standards in the field and their issuers, and (4) being highly realistic with both negative and positive scenarios to center the players' understanding of real-world impact. ...
Journal article (2023) - Ini Kong, Marijn Janssen, Nitesh Bharosa
The quantum computing-based threats call for a critical information infrastructure to modify widely used cryptographic algorithms to ones that are quantum-safe (QS). Yet, little scholarly research has been undertaken to study QS transition, and the guidance to prepare for socio-technical predicaments of the transition falls short. To address the gaps, the paper aims to determine the contextual interaction between QS transition challenges and classify these challenges into driving power and dependency power. In doing so, we use an integrated Interpretive Structural Modelling (ISM)-Matrice d'Impacts Croisés Multiplication Appliqués à un Classement (MICMAC) approach. The results of ISM-MICMAC analysis indicate that the dominant challenges that organizations need to prioritize are establishing a clear QS transition governance and collaborations in the ecosystem. The findings show that it is crucial for organizations to understand the ecosystem making up the critical information infrastructure they are operating in and collaboratively navigate the action approaches for the QS transition. This also implies that preparation for the QS transition not only includes developing QS solution standards but also requires well-defined roles and responsibilities for various actors in the ecosystem. ...
Journal article (2023) - Silvia Lips, Valentyna Tsap, Nitesh Bharosa, Robert Krimmer, Tanel Tammet, Dirk Draheim
In the management of national electronic identity (eID) infrastructure, cooperation between public and private parties becomes more and more important, as the mutual dependencies between the provision of e-services and the provision of the national public key infrastructure (PKI) continuously increases. Yet, it is not clear which key factors affect the public-private collaboration in the eID field, as existing studies do not provide insight into this particular matter. Therefore, we aim to identify the factors that affect public-private partnership (PPP) in the field of eID. We also describe feasible formats that help to improve the cooperation between the two sectors, based on insights from the case of Estonia. In service of that study, we conducted twelve qualitative interviews with high-level experts representing several parties from the public and the private sector. By conducting a thematic analysis of the interviews, we identified five key factors for successful PPP in the eID field, i.e., engagement, joint understanding, two-way communication, clear role division, and process orientation. Furthermore, we generalize our results by discussing, in how far the found cooperation formats can be used by stakeholders to manage state-critical information technology (IT) infrastructure components similar to eID such as mobile phone services, data transmission services and digital signature services. ...

Searching for Meaningful Human Control in Algorithmic Government

Journal article (2023) - Anastasija Nikiforova, Nitesh Bharosa, Dirk Draheim, Kuldar Taveter
The future is likely to see an increase in the use of automated decision-making systems in the public sector, which employ Artificial Intelligence and, in particular, machine learning techniques, to enable more proactive and personalised delivery of public services. Proactive delivery can reduce the administrative burdens on citizens and government staff. While there is a small but growing body of literature that highlights the benefits of proactive public services, the implementation of such services is data intensive and can harm citizens beyond privacy concerns. Proactive service delivery requires high degrees of automated data processing using various data sources and algorithms that reduce the level of human control that both citizens and public officials have in verifying or correcting system errors. The purpose of this workshop is to initiate a discussion about proactive and personalised public services, discussing them and learning from the EGOV community about the practice of applying proactive and personalised services in different countries. This includes presenting an initial version of the developed framework for proactive and personalised public services, which is expected to provide further research directions. ...
Governments are increasingly using sophisticated self-learning algorithms to automate and standardize decision-making on a large scale. However, despite aspirations for predictive data and more efficient decision-making, the introduction of artificial intelligence (AI) also gives rise to risks and creates a potential for harm. The attribution of responsibility to individuals for the harm caused by these novel socio-Technical decision-making systems is epistemically and normatively challenging. The conditions necessary for individuals to be adequately held responsible-moral agency, freedom, control, and knowledge, can be undermined by the introduction of algorithmic decision-making. Thereby responsibility gaps are created where seemingly no one is sufficiently responsible for the system's outcome. We turn this challenge to adequately attribute responsibility into a design challenge to design for these responsibility conditions. Drawing on philosophical responsibility literature, we develop a conceptual framework to scrutinize the task responsibilities of actors involved in the (re-)design and application of algorithmic decision-making systems. This framework is applied to an empirical case study involving AI in automated governmental decision-making. We find that the framework enables the critical assessment of a socio-Technical system's design for responsibility and provides valuable insights to prevent future harm. The article addresses the current academic and empirical lack of philosophical insights to understand and design for responsibilities in novel algorithmic ICT systems. ...