When a board tells somebody to sort out organisational governance, what they usually mean is that the organisation feels out of control and the paperwork has started breeding faster than the judgement. The trouble is that most of what passes for governance advice is really advice about reporting and compliance. So much governance ends up as ceremony.
Organisational governance is the system that determines who makes each decision, what they must consider before committing, and how the organisation knows whether that decision worked.
I start there because it defines governance by what it must do. If a governance system does not help people make sound commitments, it may look impressive to auditors, but it is not doing the work.
What is organisational governance?
Organisational governance controls who can commit the organisation, on what basis, and with what follow-up. In practice it means deciding who may commit the organisation, what basis they need, and what monitoring follows.
Governance reaches further than the board pack. It covers who has authority to commit the organisation on any given matter, what challenge those decisions must receive, what records capture the reasoning, and what monitoring follows. When any of those elements is missing, the governance structure is partial. When all of them work, the organisation has genuine control over its commitments.
Most organisations dodge this. They talk about governance as if it were mainly oversight from above. It is not. It is about shaping the conditions under which decisions are made throughout the organisation. A board does not govern by being informed after the fact. It governs by ensuring the organisation has a reliable way of deciding.
I have had board chairs ask me to "fix governance" when what they really wanted was proof that the existing system could still be defended. Wrong starting point. The first question is whether the apparatus helps anyone decide well. If it does not, you have a control problem disguised as a documentation problem.
Why governance feels like paperwork
Governance feels like paperwork because most governance frameworks were built backwards. They start with what must be reported to the board or the regulator, then push that reporting requirement down through the organisation until everybody is feeding the machine. The machine gets mistaken for governance.
That is the heart of the governance vs compliance confusion. Compliance may be necessary. A compliance obligation tells you what must be demonstrated, not how a good decision is reached. The organisation ends up producing things that look respectable in a file while the actual decision on the desk remains muddy. A risk register does not help you decide because it was never designed to. The whole risk management millstone stays in place because too many interests are aligned behind it.
I have had people say, "Grant Purdy, you are too hard on risk management." Not hard enough. Risk management, as usually sold, is a belief system. It starts with the answer rather than careful definition of the problem. The language in COSO ERM during COVID-19 is a vivid example: an entire framework retrofitted to a crisis, and the Decider is still left with the hard part untouched. If "risk management" is the answer, what was your question? Most organisations never defined the question. They inherited the answer.
The answer stayed because insurers and directors had financial reasons to sponsor more visible controls, and consultants discovered a handsome living in promoting the paraphernalia. Once those interests merged, the edifice took on an air of nobility it had never earned. Organisations ended up with risk committees, appetite statements, and reporting frameworks with twelve tabs, behaving as if the artefact had magic properties.
A reporting requirement is never a good reason to call the exercise organisational governance. That is why apparently sensible questions such as should internal audit perform risk assessment are often asked backwards. Internal audit can test whether the organisation's arrangements are working. If nobody has first defined governance as the system for making sound commitments, audit is left inspecting scenery.
The paperwork feeling is the natural consequence of designing the system around evidence of diligence rather than help with deciding. Compliance wants proof. Governance should want competence.
Governance is not management
Governance is not management, though organisations constantly blur the line. Governance sets the conditions for good decisions. Management works within those conditions to run the business and execute.
If your governance layer is just more management, you have two copies of the same thing. One tries to run the business. The other pretends to supervise by doing the same job more slowly and with less context. If management is expected to invent its own decision rules every time, governance has abdicated.
I put the distinction bluntly. Governance controls how the organisation is steered. Management lives inside those controls. When the line dissolves, the damage shows up in committees. A board sub-committee asks operational questions it has no business running. Executives create another sub-committee to second-guess managers without clarifying authority. Collective activity increases, ownership decreases. Collective decision making fails when no one takes ownership, and that is exactly what happens when governance and management collapse into each other.
Organisational governance does not manage the plant or the sales team. It ensures the people running those things know what authority they have, what challenge is expected, and what must be monitored after they act. That is control.
The practical test I use for any governance system is whether someone can name the person who owns the decision in front of them. If nobody can, the distinction between governance and management has collapsed. I lay out that test and the four signals that it has broken down in governance vs management at the point of decision.
Who decides, who challenges, who monitors
Sound organisational governance must settle who decides, who contributes challenge before the decision, and who monitors after it.
The first question is authority. In Deciding, Roger Estall and I used the phrase "the authority of the Decider to make the decision" because most organisations skip this and pay for it later. If authority is vague, the decision will be made anyway, only by drift or exhaustion rather than by design. Start with a decision rights framework: write down who can make which calls. One person, the Decider, must own it.
The second question is challenge. Participants should be chosen because they know something relevant or can puncture bad thinking. Committee habit is not a reason. A great deal of supposed collaborative decision making is only a way of spreading risk to reputation. Real collaboration still needs one Decider; otherwise the discussion produces heat and deniability, not a decision.
The third question is monitoring. Many governance models quietly become absurd at this point. They ask for a report, file the report, and assume control has occurred. Monitoring has no value unless the results reach somebody competent and authorised to act. If the report goes to somebody who cannot interpret it or cannot change anything, the monitoring is ornamental. The most common failure is the gap between monitoring and action. Data gets collected because a policy demands it. The report gets filed. Nobody with authority reads it.
Accountability matters inside governance because a system that names authority but not follow-through is unfinished. A system that monitors but does not authorise action is theatre. Good accountability in leadership begins before the decision is made and continues through monitoring of the assumptions on which it rested.
Structure is the arrangement that makes one person own the live call and keeps challenge attached while the call is still open. When that arrangement is missing, every layer of assurance just protects the people who built the maze. A closer look at governance structure shows what the chart must actually contain.
What governance failure actually looks like
Governance failures are rarely failures of structure. The structure was there. The policies were there. None of it helped anyone decide when it mattered.
The Australian Royal Commission into Misconduct in the Banking, Superannuation and Financial Services Industry (2017-2019) exposed this at national scale. Commonwealth Bank, AMP, and NAB had boards, risk committees, and constant reporting. Commissioner Hayne found that the institutions had prioritised revenue over the interests of their customers. Staff at Commonwealth Bank sold products customers did not need. At AMP, fees were charged to a dead adviser's account for a decade. In each case the governance apparatus monitored reports, not the quality of the decisions those reports were supposed to reflect. Nobody with authority said clearly and in time: this must stop.
At the human level, these are not exotic failures. They are cognitive biases in business dressed in formal titles. Sound judgment in leadership erodes when the system rewards compliance over candour. The decision fatigue examples are visible in every governance failure: weary shortcuts that compound the damage.
Then the institution stalls. Analysis paralysis in business takes hold as committees debate without deciding, and people defend what they built long past the point of usefulness. The sunk cost fallacy examples in governance are everywhere because nobody likes admitting the expensive apparatus never did what it claimed.
A client case from food manufacturing shows the same pattern at operational scale. The plant had precautionary biological-count testing. Routine, well-documented, externally audited. Over eighteen months the instruments drifted out of calibration. Nobody noticed because the monitoring system measured whether tests were performed, not whether the instruments doing the testing were still accurate. Contaminated water reached the product before anyone asked the underlying question. Revenue and reputation followed it out the door.
Every governance failure I have cared about has this structure. The organisation did not fail because it lacked a form. It failed because the form did not force a live human being to respond when the basis of the decision shifted.
That pattern repeats across sectors and continents. I have written about governance failures that survived inside fully functioning oversight structures because the apparatus measured activity, not the decision it was supposed to protect.
What a governance framework should actually do
A governance framework should make the next decision better. If it does not, it is decoration or a compliance shield.
The clearest scaffold I know is the Universal Decision-Making Method. It asks five questions: what is the decision, what are the options, what assumptions are we making, are we certain enough to commit, and who will monitor? If an organisational governance framework cannot support those questions, it is not controlling the organisation in any useful sense.
I am wary of any governance model that favours visibility over clarity. If the model does not keep accountability on the person who decides, it is a courier service.
Plenty of tools exist for parts of the problem. A RAPID decision-making framework sorts roles, a decision record preserves reasoning, and the IIA Three Lines Model separates advisory from assurance. Collaborative decision-making models describe how groups contribute. None of those answers the hardest governance question: has the person with authority considered enough to commit?
The range of decision-making frameworks keeps growing. Organisations do not need another management faith. They need a method that helps human beings decide under uncertainty. A governance framework worth having says who decides, makes assumptions visible before approval, and specifies who monitors and what they are authorised to do when reality shifts. If your existing framework cannot do that, do not be sentimental about it.
If you are comparing specific layouts, the test is the same. Three Lines, RACI, Delphi all promise oversight, but a governance model that works keeps accountability with the person who decides, not the committee that reviewed.
How to know if your governance is working
Put one live decision on the table and test the system against it.
- Who is the Decider for this decision, and what must that person consider before committing the organisation?
- Which assumptions are visible now, and what would make us revise or stop if those assumptions fail?
- Who will monitor the result, and is that person competent and authorised to act on what they see?
Those questions are a practical translation of these five steps. If your organisational governance cannot answer them on a real decision, your problem is not missing policy language. Your problem is that the organisation is not actually controlled where it matters.
That is the challenge I would put to any board or chief executive who says they want governance sorted out. Put one significant decision on the table. If the system cannot say who decides or trigger action when reality shifts, stop repairing the paraphernalia. Rebuild how the organisation decides.
You could circulate the paper, then watch the real decision happen elsewhere.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.