Governance

Build a governance framework the way an auditor would.

Not a template to fill in — a top-down method where each stage inherits from the one above it. Each stage names the model behind it; hover to go deeper.

1

Mandate & context

Why you govern, for whom, and under what rules.

Basis: laws, code, group policy · risk appetite Hover to expand

Establish the regulatory basis — companies law, the governance code, sector rules, and any group policies if you belong to a larger organisation. Name your stakeholders (you always govern for someone: shareholders, regulators, customers) and set the risk appetite the whole framework must respect. This is the most-skipped stage in practice, and the one everything else inherits from.

2

Governance structure

The board, its committees, and who watches whom.

Model: the Three Lines Model Hover to expand

Design the board and its committees — audit, risk, nomination & remuneration — and the reporting lines between them, with a genuine separation between executive management and oversight. The recognised way to make “who watches whom” explicit is the Three Lines Model: management owns and runs the risk, risk & compliance functions oversee it, and internal audit gives independent assurance.

3

Roles & authorities

Who decides, who approves, who executes.

Tools: RACI + Delegation of Authority (DoA) Hover to expand

Place authority inside the structure with two tools working together: a RACI matrix (Responsible, Accountable, Consulted, Informed) for each significant activity, and a formal Delegation of Authority mapping approval limits — amounts, contracts, investments — to roles, with clear thresholds for what must escalate to the board. This is where governance meets real control, and where duties must stay segregated so no one can both request and approve.

4

Policies & controls

How each mandate is actually carried out.

Principle: risk-based controls Hover to expand

Turn structure and authority into written policies and controls — placed fourth, not first, on purpose: a policy is the translation of the mandate, not the starting point. Every policy needs a named owner, a review frequency, and a defined scope; every control should trace to a real risk (risk-based controls) rather than sit on a generic checklist.

5

Assurance & review

Monitor, audit, and keep it current.

Three lines of defense · KPIs / KRIs · loops back Hover to expand

Test whether the framework actually works: first-line monitoring, second-line compliance & risk reviews, third-line internal audit — with external audit and regulators as a further layer. Track a few KPIs/KRIs on the framework's own health, such as policy breaches or time to close audit findings. The output loops back into stage one — governance is never a project that ends, only something kept current.

Three threads run through all five stages

The stages are the spine, but a real framework depends on three things that don't sit in any single box — they run through the whole thing.

Culture & ethicsTone at the top and safe speak-up channels. Structure and rules only hold if the culture backs them — this is as real a control as any policy.
Stakeholder engagementGovernance serves people outside the org too — shareholders, customers, regulators. Design how you listen to and report to them, not just your internal hierarchy.
Risk & strategy (ERM)The framework should connect to enterprise risk management and strategic objectives, not run beside them. Governance that ignores strategy protects nothing that matters.
Pro feature

Build your framework, guided step by step.

The interactive builder walks you through all five stages — applying these models as you go — and produces an exportable governance framework document. It's part of GRC Forge Pro; join now to be first in when it launches.

Get started