Not a template to fill in — a top-down method where each stage inherits from the one above it. Each stage names the model behind it; hover to go deeper.
Why you govern, for whom, and under what rules.
Basis: laws, code, group policy · risk appetite Hover to expandEstablish the regulatory basis — companies law, the governance code, sector rules, and any group policies if you belong to a larger organisation. Name your stakeholders (you always govern for someone: shareholders, regulators, customers) and set the risk appetite the whole framework must respect. This is the most-skipped stage in practice, and the one everything else inherits from.
The board, its committees, and who watches whom.
Model: the Three Lines Model Hover to expandDesign the board and its committees — audit, risk, nomination & remuneration — and the reporting lines between them, with a genuine separation between executive management and oversight. The recognised way to make “who watches whom” explicit is the Three Lines Model: management owns and runs the risk, risk & compliance functions oversee it, and internal audit gives independent assurance.
Who decides, who approves, who executes.
Tools: RACI + Delegation of Authority (DoA) Hover to expandPlace authority inside the structure with two tools working together: a RACI matrix (Responsible, Accountable, Consulted, Informed) for each significant activity, and a formal Delegation of Authority mapping approval limits — amounts, contracts, investments — to roles, with clear thresholds for what must escalate to the board. This is where governance meets real control, and where duties must stay segregated so no one can both request and approve.
How each mandate is actually carried out.
Principle: risk-based controls Hover to expandTurn structure and authority into written policies and controls — placed fourth, not first, on purpose: a policy is the translation of the mandate, not the starting point. Every policy needs a named owner, a review frequency, and a defined scope; every control should trace to a real risk (risk-based controls) rather than sit on a generic checklist.
Monitor, audit, and keep it current.
Three lines of defense · KPIs / KRIs · loops back Hover to expandTest whether the framework actually works: first-line monitoring, second-line compliance & risk reviews, third-line internal audit — with external audit and regulators as a further layer. Track a few KPIs/KRIs on the framework's own health, such as policy breaches or time to close audit findings. The output loops back into stage one — governance is never a project that ends, only something kept current.
The stages are the spine, but a real framework depends on three things that don't sit in any single box — they run through the whole thing.
The interactive builder walks you through all five stages — applying these models as you go — and produces an exportable governance framework document. It's part of GRC Forge Pro; join now to be first in when it launches.
Get started