“We need more governance” and “governance is slowing us down” are usually complaints about the same broken system, coming from different vantage points. Leadership sees inconsistent decisions and unmanaged risk; teams on the ground see approval queues and forms that exist to protect someone from blame rather than to improve the outcome. Both are right. The failure isn’t too much governance or too little — it’s governance designed without regard for where decisions actually get made and how fast they need to move.
Good governance is closer to guardrails on a highway than a checkpoint at every exit. It should be nearly invisible when things are going normally and only become visible when something’s genuinely at risk. Most governance frameworks fail because they apply the same scrutiny to every decision regardless of stakes, which is what makes them feel like friction rather than protection.
Key Takeaways
- Governance should scale with risk and reversibility — low-stakes, easily reversible decisions need far less oversight than high-stakes, hard-to-reverse ones.
- The most common governance failure is uniform process applied to non-uniform decisions.
- Effective frameworks separate “decisions that need a committee” from “decisions that need a single accountable owner” and route accordingly.
- Governance built by the people who have to live under it is more durable than governance imposed from above.
- Every governance control should have a clearly stated purpose — if you can’t say what risk it mitigates, it’s a candidate for removal.
Why Governance Frameworks Drift Into Friction
Governance frameworks rarely start bloated. They accumulate weight one incident at a time. A vendor contract goes wrong, so a new approval step gets added. A project overruns budget, so a new reporting requirement gets layered on. Each addition is a reasonable response to a real problem, but nobody goes back and asks whether the older controls are still earning their cost. Three years in, the framework is a stack of individually justifiable rules that collectively make routine decisions take twice as long as they should.
The other common drift is treating governance as a single tier. Every initiative, regardless of size or risk, goes through the same steering committee, the same sign-off chain, the same documentation requirements. This isn’t rigor — it’s an inability to distinguish between decisions that genuinely need multiple eyes and decisions a single accountable person could make in an afternoon. Uniform process is what makes governance feel bureaucratic, because it treats a $5,000 vendor renewal the same as a $2 million system migration.
Tiering Governance to Match Risk and Reversibility
The single highest-leverage change most organizations can make is building explicit tiers, so the weight of oversight matches the weight of the decision. A practical starting structure:
- Tier 1 — Low risk, easily reversible. Single accountable owner decides, informs stakeholders after the fact. No committee, no sign-off chain. Example: reallocating budget within an already-approved line item.
- Tier 2 — Moderate risk or moderate cost to reverse. Owner decides after consulting a short, named list of stakeholders. Decision and rationale documented briefly. Example: changing a vendor for a non-critical service.
- Tier 3 — High risk or hard to reverse. Requires a defined approval body, a documented business case, and a pre-agreed decision timeline so the review itself doesn’t become the bottleneck. Example: a system migration, a material policy change, anything with significant financial or regulatory exposure.
The tiering criteria should be written down and genuinely usable by the people making the call, not left to interpretation. A one-page decision guide — “if the decision costs more than X, or can’t be easily undone, or affects more than one department, it’s Tier 3” — does more to keep governance fast than any committee restructuring.
Designing Controls With an Expiration Date
Every control added in response to an incident should come with a built-in review point, not a permanent place in the framework. When you add a new sign-off step, note explicitly what risk it addresses and schedule a review in six or twelve months to check whether it’s still needed in that form. Controls that never get revisited are how frameworks accumulate weight nobody intended.
A useful discipline here is a standing annual governance audit — not a compliance audit, but a simple exercise where the team lists every control currently in place and, for each one, answers two questions: what risk does this address, and has that risk changed? Controls that address a risk that no longer exists, or that never materialized, are candidates for removal. This single practice, done consistently, is what prevents governance frameworks from calcifying.
Building Governance With the People Who’ll Live Under It
Frameworks designed entirely by leadership or a compliance function, then handed down, tend to optimize for the risks that function is most worried about — often to the exclusion of practical delivery speed. Frameworks built with input from the people who’ll actually operate under them tend to be both more realistic about where risk actually lives and more likely to be followed rather than worked around.
In practice, this means testing any proposed governance change against a handful of real recent decisions before rolling it out. Take three or four decisions the team made in the last quarter and run them through the proposed framework: would this tier assignment have felt right? Would the approval chain have added meaningful protection, or just delay? This kind of pressure-testing catches over-engineering before it’s locked into policy.
Frequently Asked Questions
How do we know if our governance framework has become too heavy?
A reliable signal is staff routing around official processes to get things done — informal approvals, side conversations that substitute for documented sign-off, or shadow trackers that exist because the official system is too slow to use in real time. If people are working around the framework rather than through it, the framework has stopped matching how the organization actually needs to move.
Who should own maintaining a governance framework once it’s built?
Ideally a single accountable owner — often someone in a PMO, operations, or governance function — who’s responsible for running the periodic control review, not just for enforcing existing rules. Without a named owner, the framework tends to only grow, since adding a control is easy and removing one requires someone to actively decide it’s no longer needed.
Does a small or fast-growing company need formal governance at all?
Some governance is worth having earlier than most founders expect — not heavy process, but clarity on who can approve what, and at what size a decision needs a second set of eyes. The mistake is waiting until after a costly decision goes wrong to build any structure at all, and overcorrecting into heavy process once that happens.
How many governance tiers should a framework have?
Three tiers is usually enough for most mid-sized organizations and is easy for people to remember and apply without a reference document. More than four or five tiers tends to reintroduce the complexity the framework was meant to reduce, since people have to think harder about which tier applies than about the decision itself.