The most common finding in a governance review is not a missing policy. It is that nobody can say who decides.
Ask five executives who approves a change to programme scope. You will often get four different answers and one “it goes to the steering committee”, which is not a person and cannot be held to a date.
What that breaks, in ascending order of cost.
Decisions queue. Work continues while approval is pending, because stopping is unpopular. By the time the decision lands the team has already built past it.
Risk ownership goes nominal. A risk assigned to a function is assigned to nobody. It gets reviewed monthly and closed by attrition.
Evidence disappears. When an auditor asks how a control was approved, the answer needs a name and a date. A minute recording that something was “noted” is not an approval, and discovering that during an audit is an expensive way to find out.
None of this is exotic. It is the boring half of governance, and it decides whether the framework on paper describes anything real.
The fix starts with a table. One row per decision type, one named person per row, one escalation path. An afternoon to draft. A quarter to make stick.
