Governance vs compliance is a distinction most organisations get backwards. Compliance proves rules were followed. Governance controls the decision itself. A bank can meet every regulatory capital requirement and still fail because nobody governed the judgement calls that built the exposure.

By the end of 2022 Credit Suisse met regulatory capital and minimum liquidity requirements. FINMA had run 108 on-site reviews, supervisors were carrying 382 points requiring action, 113 of them high or critical. UBS still took it over on 19 March 2023. Compliance had done its job. Governance had not.

Most people search the distinction after an audit finding or an awkward board paper, when somebody realises the organisation bought a compliance apparatus and called it governance because that keeps auditors booked, trainers selling courses, and template vendors paid. The obligations may be mapped and the training may be complete, yet the board still cannot see who is committing the organisation, what the call rests on, or what would force it back into the room.

GovernanceCompliance
ControlsLive decisions and commitmentsSpecific rules and obligations
AsksWho can commit? What does the call rest on? What brings it back?Were procedures followed? Is the record complete?
OwnsBoard and senior executives (authority holders)Compliance team (obligation holders)
Fails whenA bad decision travels uncheckedA rule is missed or unrecorded
ProvesThe decision was sound and monitoredThe requirement was met and documented

Governance vs compliance is the difference between controlling live decisions and proving that specific rules were followed.

Governance vs compliance shows up when the decision is live

I do not find the distinction difficult once a live decision is on the table. Compliance asks whether the organisation has appropriate procedures for a defined obligation, such as bribery or market abuse. Governance asks who owns the call under uncertainty, what has to be true for it to work, and what monitoring will drag it back if reality starts to bite.

The United Kingdom's Serious Fraud Office guidance on evaluating a corporate compliance programme is useful because it stays in its lane. It helps you judge whether anti-bribery procedures are genuine and effective, which matters, but it still cannot tell a chief executive weighing an acquisition or a plant closure which assumption carries the bet or what evidence should reopen it.

Listen to the room. Nobody asks compliance whether a market exit still fits Purpose. They ask whether approvals, disclosures, or training records are in order. Governance arrives earlier and stays later because it deals with the commitment itself, not just whether the required proof was assembled.

I have watched organisations blur these jobs until the board asks for governance and gets another compliance artefact. They bought the apparatus before they named the problem. If you want the wider frame, organisational governance.

Governance vs compliance: compliance proves rules were followed, governance controls the live decision
A missed rule needs compliance. An unchecked decision path needs governance.
Click to expand

Governance vs compliance is not settled by a passing audit

Credit Suisse is useful because compliance did not vanish. According to FINMA's 2023 annual report, the bank kept passing the formal tests right up to the end. Governance stayed blind where it mattered most: the organisation had formal warnings and remediation activity, yet the people with authority did not regain control of confidence in time.

The same split appears in enforcement. In a 31 March 2021 speech, FCA enforcement chief Mark Steward said many misconduct events are not failures of compliance at all, but failures of choices and personal responsibility. He cited cases such as former UBS compliance officer Fabiana Abdel-Malek and Bill Hwang's Tiger Asia conduct to show that formal controls do not stop bad calls once people decide to step around them. He is right, and the compliance trade hates admitting it. Once the distinction is reduced to a glossary exercise, the expensive part disappears: harm grows in the gap between the signed control and the live decision.

That is why I am sceptical when someone says, "compliance signed off". Signed off what, exactly, and at what point in the decision? A sign-off can be useful evidence, but it is a miserable substitute for ownership. The same trap swallows business ethics and decision making, where legal permission answers whether an act was allowed and never whether it was the right commitment. The secretariat keeps the date, the paper keeps moving, and the executive who made the bet still carries the failure when it unravels.

Trace one live decision through your controls and see whether governance owns it or compliance merely documents it. Start the Walk →

What governance adds that compliance cannot

What governance adds is plain enough. It says who can commit the organisation, what the call rests on, and what brings it back. That is why the Financial Reporting Council keeps dragging companies away from boilerplate. Its Corporate Governance Code guidance, updated on 3 June 2026, says good governance is not a tick-box exercise and ties it to how boards actually work inside the business they govern.

The FRC made the same complaint more directly in its 13 March 2026 review of comply or explain reporting. Too many companies wrote about policies and procedures and too little about what boards actually decided and what followed. I see that drift constantly. Once reporting becomes the product, the decision disappears, which suits more people than they like to admit. Compliance teams get their evidence, secretariats get their papers, and the board still does not know which assumption is carrying the bet.

Roger Estall and I argued in Deciding that boards do not regain control by adding more reporting when the decision itself is still untested. We regain control when the room can name the call, the assumption doing the real work, and the trigger that drags the decision back before the damage compounds. That is why I use the Universal Decision-Making Method, and why I judge any governance framework by whether it makes that conversation unavoidable.

Checklists are good at proving someone touched the process, but they are terrible at showing whether the organisation is still making sense. People keep using them as cover because the checklist can be filed, the board minute can be written, and nobody has to say plainly which assumption is carrying the decision.

The Monday morning test for governance vs compliance

When someone asks me about governance vs compliance, I do not reach for a comparison table. I take the next live decision and ask what changes if we treat it as a governance problem instead of a compliance problem. If the answer is better rule documentation, we are still in compliance. If the answer is clearer authority, a named assumption, and an agreed trigger for review, we are in governance.

These arguments usually calm down once you ask who can reverse the call. Compliance can own specific obligations and the evidence around them. Governance cannot be handed off so neatly because it sits with authority, which is why governance structure matters more than another round of definitions. Somebody must be able to commit the organisation, and somebody must know what would make that commitment reversible.

I used that test with a board that had spent two years building out its compliance framework after a regulatory warning. When I asked what had changed about the way decisions were actually made, the room went quiet. The reporting was better and the training register was up to date, but nobody could tell me who had decided to enter the market segment that triggered the warning, or what assumption that entry had rested on. The compliance framework had answered its own question beautifully. The governance question had never been asked.

My test is blunt. When a board says it has a governance issue, I ask whether a missed rule is the real problem, or whether a bad decision can still travel a long way before anyone stops it. A missed rule needs compliance, while an unchecked decision path needs governance. If your board cannot name the call, the assumption, and the trigger, stop buying another layer of proof and start fixing the decision.

You could pass the next audit and still leave the real decision uncontrolled.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.