After a governance audit, most teams move straight to a remediation plan addressing the gaps the audit identified. The step they skip is testing whether the audit's conclusions rest on verified operating reality or on documentation that exists independently of how decisions actually get made.

A governance audit is a systematic review of an organisation's governance arrangements against established standards, codes, or internal policies.

The standard next step after a governance audit

The standard move is to produce a remediation plan. The audit report lists findings: non-conformities, observations, recommendations ranked by severity. Each finding references a clause or principle from the applicable code or standard. Where the audit follows ISO 19011 guidelines for auditing management systems, each finding is graded against defined audit criteria, and the remediation response is expected to match the severity of the gap. The governance team works through the list. Policies are updated. Committee terms of reference are rewritten. Board calendars are adjusted to address meeting-frequency gaps. Reporting templates are revised to match the standard's requirements.

The remediation plan follows the structure of the audit itself. If the audit flagged that the board's skills matrix had not been reviewed for two years, the plan schedules a review. If it found that the risk committee's charter did not specify escalation thresholds, the charter gets amended. The logic is gap-closure: the audit identified where governance arrangements fell short of the standard, and the plan closes each gap.

What to do after a governance audit: test the assumptions beneath the documented arrangements
The governance audit checks the documented arrangements. The decision to act on its findings rests on what those arrangements are taken to prove.Click to expand

Completion is tracked against the audit's own categories. Green when the policy is updated. Amber when work is in progress. Red when nothing has moved. The audit committee reviews progress quarterly. The next audit cycle checks whether the gaps were closed. An organisational governance framework in good standing means the policies exist, the committees meet, the reporting lines are drawn, and the documentation can be produced when the next audit is scheduled. Whether those arrangements produce the decisions they were designed to produce is a different question, and one the standard remediation process does not ask.

What that step adds

The remediation plan adds genuine structural improvement. Without it, audit findings accumulate without consequence. Policies that existed only on paper get rewritten to reflect current operations. Committee structures that had drifted from their original mandate get realigned. Governance structures that created ambiguity in reporting lines get clarified.

There is also a defensibility benefit. A governance audit with a tracked remediation plan creates a visible record of the board's response to identified gaps. Regulators, shareholders, and external auditors can see that findings were addressed. In jurisdictions subject to governance codes such as the UK Corporate Governance Code, this procedural record is often the minimum threshold for demonstrating duty of care. The difference between governance and compliance is supposed to be that governance concerns itself with the quality of decisions, not just adherence to rules. In practice, the remediation plan tracks adherence.

Structured audit findings also expose gaps that accumulate slowly. A committee that has met consistently but never updated its terms of reference since its formation five years ago may not recognise the drift until the auditor flags it. The audit catches what incremental habit misses. The limitation is not in what the remediation does. It is in what it takes for granted. A board that meets twelve times a year instead of eight has closed the frequency gap. Whether the additional meetings produce better oversight is an assumption the remediation plan never examines.

Write down the governance audit finding your remediation plan depends on most and ask whether it tested oversight effectiveness or only structural compliance. Start the Walk →

Where the standard playbook breaks down

The playbook breaks down at the boundary between governance structure and governance behaviour. Every remediation action carries an implicit assumption: that fixing the documented arrangement will fix the decision-making it was supposed to enable. The OECD Principles of Corporate Governance emphasise that governance frameworks should promote transparent and fair markets and effective accountability. But the audit process that measures against those principles checks structure, not the quality of judgment the structure is meant to produce.

What the audit shows
Board committees constituted, terms of reference current, meetings held at required frequency
▼ ▼ ▼
What it assumed
Constituted committees with current terms of reference are exercising effective oversight of management
▼ ▼ ▼
What could break
Committee accepts management assurances without testing underlying assumptions; oversight exists on paper but not in practice

Carillion demonstrated what happens when that assumption goes untested. The UK construction and services company received unqualified audit opinions from KPMG for nineteen consecutive years, the last issued in March 2017. The board had an audit committee. It had a risk committee. Board meetings were held at the required frequency. The documented arrangements satisfied every structural requirement a governance audit would check.

The company collapsed in January 2018 with liabilities of approximately £7 billion and £29 million in cash. The parliamentary joint inquiry found that the audit committee had accepted management's estimates of contract profitability without sufficient challenge. Revenue recognition on long-term contracts depended on assumptions about future margins that were never independently tested. Goodwill of £1.6 billion sat on the balance sheet without write-down. The board continued to approve dividend payments and share buybacks while the underlying business was deteriorating. Governance structures existed. They were not producing governance.

The pattern is not unique to Carillion. It is the predictable result of measuring governance by its documentation rather than by its operating culture. An audit that confirms the committee met quarterly and reviewed management reports has verified a procedural fact. Whether the committee tested the assumptions inside those reports, or treated management's narrative as sufficient, is not something the standard audit methodology examines. Governance failures consistently follow this pattern: the structures were in place, the behaviours were not, and the audit checked the structures.

The step to take first

The governance audit is not the problem. Building on its findings without testing the assumptions they carry is. Before the remediation plan enters the board agenda, each material finding needs a second question: what is this finding being taken to prove about how decisions are actually made here? A finding that the risk committee met eight times in twelve months is a verified fact. The inference that the risk committee is providing effective oversight is a claim the finding does not support on its own. The same question applies after an internal audit, where severity ratings embed the same kind of untested judgment. It applies after a SOX compliance review as well, where an effective controls opinion is routinely read as proof that the reported numbers are sound.

1
Complete the governance auditOutputs: findings, non-conformities, remediation recommendations
2
Standard next step: build a remediation plan against each finding
Most teams skip straight to step 4
3
Test the assumptions behind each findingWhich remediation actions depend on conditions the audit did not verify?
4
Act with sufficient certaintyImplement, monitor, adjust

The five-step structure in the Sufficient Certainty method places assumption recognition before any commitment. Frame the decision: what governance outcome is the remediation plan supposed to produce, and how will the board know whether it succeeded. Identify the tentative elements: the conditions, relationships, and behaviours the plan depends on. Surface the assumptions embedded in the audit findings: which conclusions rest on verified evidence and which rest on the existence of documentation that the audit checked against a standard. Determine whether the evidence behind each critical assumption is proportionate to the weight the remediation plan places on it. Then implement with monitoring in place.

A governance arrangement that exists on paper and a governance arrangement that changes decisions are not the same thing. The audit checks the first. The remediation plan fixes the first. The step between them, the one that tests whether structural compliance translates into effective oversight, is the step that determines whether the next audit cycle produces a clean report or a better-governed organisation.

An organisational governance framework is only as sound as the assumptions it rests on. The audit measures the framework against a standard. The question worth asking before acting on those measurements is whether the standard measured the right thing.

You could present a clean governance audit to the board and still leave what it is taken to prove untested.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.