Guide

Business Governance Frameworks

Governance is about who decides what, and how those decisions are held to account. Four levels, and only some of them are yours to design.

Corporate governance follows published codes you should read rather than invent. Portfolio and operational governance are genuinely yours to design, and that is where practical frameworks apply.

Four nested rectangles with decision points marked on each boundary — layers of authority.

What governance actually means

Governance answers two questions: who has the right to decide what, and how are those decisions held to account. Everything else — committees, reporting lines, approval thresholds — is machinery in service of those two.

The term is used across four levels that differ so much in nature that treating them as one topic causes confusion. Two are governed by published standards you should follow rather than design; two are genuinely yours to build.

The four levels

  • Corporate governance — board composition, shareholder rights, executive accountability, disclosure. Largely determined by law and published codes in your jurisdiction.
  • Risk and compliance governance — how risk is identified, owned, escalated and reported. Partly regulated, partly designed.
  • Portfolio and project governance — how initiatives are approved, funded, monitored and stopped. Almost entirely yours to design.
  • Operational governance — how routine decisions get made, who approves what, how disputes resolve. Entirely yours, and usually undesigned.

Where to use published codes instead of frameworks

For corporate governance and much of risk governance, established bodies publish the canonical documents, and you should work from those rather than construct something in-house. The OECD Principles of Corporate Governance, national codes such as the UK Corporate Governance Code or King IV in South Africa, and the COSO frameworks for internal control and enterprise risk management are the reference standards, and in regulated contexts adherence is not optional.

This site does not attempt to reproduce them. They are long, jurisdiction-specific, periodically revised, and available from their publishers — and a summary of a compliance standard is a liability rather than a service. What general management frameworks contribute at this level is operational support: making the decision rights those codes require actually work day to day.

Frameworks for the levels you design

RACI is the foundational tool for decision rights, distinguishing who is Responsible, Accountable, Consulted and Informed. Its governance value comes from the discipline that exactly one party is Accountable for any decision — the most common governance failure is two functions both believing they hold approval, which surfaces only when they disagree. A Delegation Matrix extends this to authority thresholds: what can be decided at which level without escalation.

Stakeholder Analysis and Engagement determines who must be consulted and how, which is the mechanism that prevents legitimate objections arriving after commitments are made.

A Risk Management Framework provides identification, assessment, ownership and escalation for risk governance — and its practical test is whether risks have named owners and review triggers rather than living in a register nobody opens.

For portfolio governance, Hoshin Kanri supplies structured negotiation between levels through catchball, so commitments are agreed rather than issued. The Balanced Scorecard gives boards and executives a reporting structure that spans more than financial outcomes. A Resource Allocation Matrix makes funding and capacity decisions explicit rather than incremental.

The proportionality problem

Governance has a characteristic failure that differs from other framework domains: it tends to accumulate, and each individual addition is defensible.

An incident occurs; a control is added. A decision goes badly; an approval step appears. None is unreasonable in isolation, and none is ever removed. Eventually routine decisions require multiple sign-offs from people with no useful view, and the organisation's response is to route around the process — which produces the worst outcome, where formal governance exists on paper and real decisions happen elsewhere.

Proportionality means matching governance weight to decision consequence. A reversible decision costing a few thousand should not carry the same apparatus as an irreversible one costing millions. Two questions keep this honest: what would we lose if this approval step did not exist, and when did it last change an outcome? An approval that has never resulted in a rejection is a queue rather than a control.

Building a proportionate layer

  • Start from decisions, not committees. List the decisions that actually matter, then determine who should make each. Designing bodies first produces meetings in search of purpose.
  • Exactly one accountable party per decision. Ambiguity here is the single most common governance defect and is invisible until a dispute.
  • Set thresholds explicitly. Value, risk or reversibility bands that determine what escalates. Without them everything escalates or nothing does.
  • Define how disputes resolve. Most frameworks assume agreement. Naming the tie-breaker in advance is what prevents deadlock becoming delay.
  • Review controls for value, not just compliance. Ask annually which approval steps have ever changed an outcome.
  • Write down what people already do. Undesigned operational governance still exists as convention. Documenting it usually reveals the two or three genuine ambiguities worth fixing.

A caution on formality

Governance frameworks produce documents that look authoritative, and it is easy to mistake the document for the governance. A decision-rights matrix nobody consults during a real dispute has not established decision rights; it has recorded an intention.

The test is behavioural. When two functions disagreed last quarter, did anyone open the matrix? If not, the governance layer exists on paper — which is the same ritual-adoption failure that affects frameworks generally, with higher stakes attached.

Frequently Asked Questions

What is a business governance framework?

It is the structure that determines who has the right to make which decisions and how those decisions are held to account. In practice governance operates at four levels — corporate, risk and compliance, portfolio and project, and operational — and these differ enough that treating them as one topic causes most of the confusion around the term.

Should we design our own corporate governance framework?

No. Corporate governance is largely determined by law and by published codes such as the OECD Principles, national codes like the UK Corporate Governance Code or King IV, and the COSO frameworks for internal control and enterprise risk. These are jurisdiction-specific and periodically revised, so you should work from the current published version rather than construct something in-house.

Which frameworks help with project and operational governance?

RACI is the foundational tool for decision rights, with a Delegation Matrix extending it to authority thresholds. Stakeholder Analysis and Engagement determines who must be consulted. For portfolio governance, Hoshin Kanri supplies structured negotiation between levels, the Balanced Scorecard provides reporting breadth, and a Resource Allocation Matrix makes funding decisions explicit.

What is the most common governance failure?

Two parties both believing they hold approval authority for the same decision. It stays invisible while they agree and surfaces only during a dispute, usually at the worst moment. This is why the RACI discipline of exactly one Accountable party per decision matters more than the rest of the matrix.

How much governance is too much?

Governance accumulates because each addition is individually defensible — an incident produces a control, a bad decision produces an approval step, and nothing is ever removed. The practical test is to ask of each control what would be lost without it and when it last changed an outcome. An approval step that has never produced a rejection is a queue rather than a control.