Business Core · Object

Governance

Who ultimately owns the business, who oversees it on their behalf, and how the risk carried by the whole organisation is held. The layer above management that management answers to.

The term

What it is

Governance is the arrangement by which the people who own a business hold the people who run it to account. The Cadbury Committee’s formulation from 1992 is still the one most codes build on: the system by which companies are directed and controlled. Direction and control are the two halves, and management does neither on its own behalf.

It applies at every size, though the form changes. A listed company has a board, committees and a published code to report against; a founder-owned firm of twenty people may have an advisory board that meets four times a year, or only an owner who has never written down what they expect. The questions are the same in both — who decides what, on whose behalf, and who checks — and the smaller firm answers them less formally, or leaves them open.

This object also holds the organisation’s view of risk as a whole. Individual risks are managed where they arise — in Compliance, in technology and security, in the supply chain — and only here are they set against one another and against how much risk the owners are willing to carry. The governance of a single partnership is a different matter and sits with Partners; decision rights below board level sit with Organisation.

Why it earns a place

What goes wrong without it

01

Ownership that is not written down gets settled in the worst week

Two founders with equal shares and no agreement on deadlock, departure or dilution have an arrangement that works until their first serious disagreement, and then has to be negotiated while they disagree.

02

A board that only receives reports is an audience

Oversight means the board can name the decisions it kept for itself, the risks it has accepted and the questions it asked that changed something. A board that cannot do this is being informed, not overseeing.

03

Risk looks manageable when it is seen in pieces

Each function can hold its own risks within tolerance while the organisation as a whole carries more than its owners would accept. The total only becomes visible when someone adds it up and sets it against an appetite.

One level in

The modules within governance

Four working areas: who owns the business, who oversees it for them, how much risk the whole organisation carries, and what happens when the people in those roles change.

  1. Ownership

    Who owns the business, in what proportions and with what rights, and what the owners expect in return. The owners’ expectations are the brief the board works to, which is why they belong in writing.

    Learn
  2. The board

    Who sits on it, what it has reserved to itself, how its year is structured, and whether it does its job well. For smaller firms the same questions apply to an advisory board, with the difference that its advice binds nobody.

    Learn
  3. Enterprise risk

    How much risk the owners are willing to carry, which risks the organisation actually holds across all its activities, and how the board keeps sight of both. Specific risks are managed where they arise; this is where they are added up.

    Learn
  4. Succession and exit

    Who takes over the leadership and the ownership when the current holders step back, and by which routes the owners could eventually leave. Both are slow to prepare and quick to be needed.

    Learn

Across the framework

What it touches

  • ComplianceRegulatory mapping, controls, monitoring and incident response sit in Compliance. Enterprise risk receives compliance risk as one input and weighs it against the rest; it neither designs nor tests the controls.
  • PartnersPartners has its own Governance module, for the joint decisions inside one partnership. This object governs the organisation itself: a partnership’s steering group answers to management, and management answers here.
  • OrganisationStructure and decision rights below the board belong to Organisation. The board delegates authority to the chief executive here; how that authority is then divided is settled there.
  • StakeholdersOwners are one stakeholder group among several. Identifying and engaging stakeholders, and reporting to them, belongs in Stakeholders; this object holds only the owners’ formal rights and their mandate to the board.
  • Contingency PlanningSlippage, buffers and fallback plans for the schedule are handled in Contingency Planning. A delay becomes an enterprise risk only where it threatens something the owners have set an appetite for.
  • Data GovernanceOwnership, quality and permitted use of data are governed in Data Governance. The board sees data risk as an entry in the enterprise risk register, not as a separate regime.
  • Goal CoreThe board approves the strategic goals, and the risk appetite sets how much may be staked on reaching them.

Beyond the framework

Models worth knowing here

The Omnigoal says where this belongs and what it touches. It does not tell you how to think about it — other people have done that, and done it well. These are theirs.

  1. The three lines model

    Institute of Internal Auditors · 2013

    Who owns a risk, who oversees it, and who independently checks both — kept as three distinct roles.

    The first line owns and manages risk in the work itself; the second sets policy and monitors; the third gives independent assurance to the governing body. The point is separation: assurance given by the people who would have to report their own failure is not assurance, whatever it is called.

    Reach for it when
    When setting up how risk and assurance are organised, and when it is unclear who is actually responsible for a control.
    Where it stops
    Read as an org chart it produces bureaucracy and a first line that believes risk is someone else’s department. The 2020 revision exists largely because of that.

    Institute of Internal Auditors, “The Three Lines of Defense in Effective Risk Management and Control”, position paper, 2013; The IIA’s Three Lines Model, 2020.

  2. ISO 31000 risk management

    International Organization for Standardization · 2009

    A common set of principles and a process for identifying, assessing, treating and monitoring risk.

    It gives a vocabulary and a cycle rather than a checklist, and deliberately is not certifiable. Its most useful contribution to ordinary practice is the insistence that risk is defined against objectives — which means you cannot assess risk at all until someone has said what the organisation is trying to do.

    Reach for it when
    When building a risk process from nothing, or when everyone in the room means something different by the word risk.
    Where it stops
    It is a framework for process, not a source of judgement. It will not tell you what your risks are or how much of them to accept.

    ISO 31000, Risk management — Guidelines, International Organization for Standardization, 2009; revised 2018.

  3. COSO Enterprise Risk Management

    Committee of Sponsoring Organizations of the Treadway Commission · 2004

    Also known as COSO ERM

    Risk treated as part of setting and carrying out strategy, overseen by the board, rather than as a list kept by a specialist.

    The first version extended internal control to risk across the whole enterprise; the 2017 revision went further and tied risk explicitly to strategy and performance, with governance and culture as its starting point. Its useful claim is that the largest risk is often the strategy itself — the chance that the chosen direction does not fit the organisation’s purpose or its appetite for risk.

    Reach for it when
    When the board receives a risk register every quarter and nothing in it has ever changed a decision.
    Where it stops
    It is broad and demanding, and easily reduced to a heat map that satisfies the auditors. It offers structure, not judgement about which risks are worth taking.

    Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management — Integrated Framework, 2004; Enterprise Risk Management — Integrating with Strategy and Performance, 2017. COSO is named here only to refer to its published work.

  4. Agency theory

    Michael C. Jensen & William H. Meckling · 1976

    Also known as The principal–agent problem

    Those who run a company and those who own it want different things, and governance exists largely to manage the gap.

    Owners delegate to managers who know more and have their own interests, so owners bear costs to monitor them, managers bear costs to reassure owners, and some value is lost anyway. Boards, audits, incentive pay and disclosure rules can all be read as attempts to shrink that loss — which is also a way of asking whether any of them actually does.

    Reach for it when
    When designing a board, an incentive scheme or a reporting line, and when management and owners seem to be pulling in different directions without anyone saying so.
    Where it stops
    It assumes people are narrowly self-interested, and designs built only on that assumption can crowd out the loyalty and professionalism they fail to count. It also says little about owners who want more than returns.

    Michael C. Jensen & William H. Meckling, “Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure”, Journal of Financial Economics, 1976.

These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.

Every model in the framework, and where each one belongs

Write down what the owners expect before asking the board to deliver it. A board with no stated mandate ends up inventing one, often from the chief executive’s plan.

The other objects in the Business Core

HR

The people the organisation has, the people it needs, and how the gap between them is closed through planning, hiring, development and retention. Capability is usually the slowest constraint on a plan to move.

Learn

Value Proposition

What the organisation offers, stated in terms of what it does for someone rather than what the product is. Who the customer is comes from the Market Core; what they are offered is settled here.

Learn

Monetisation

How what is offered turns into money: what is charged for, on what basis, how often and by whom. Whatever the pricing metric rewards is what the organisation will end up producing.

Learn

Core Competencies

The few things the organisation does better than most, that customers value and competitors struggle to copy. What counts as core decides what is kept in-house and what goes to partners.

Learn

Business Assets

What the organisation owns and can put to work, from premises and equipment to intellectual property and accumulated data. The intangible assets are usually the most valuable and the least often listed.

Learn

Operational Systems

The processes and standards that let the organisation do the same work twice without deciding how each time. A process that is routinely worked around is worse than none.

Learn

Partners

The organisations the business relies on for capability it has decided not to build. The decision is the substance, and the exit terms are best agreed while the relationship is still good.

Learn

Stakeholders

Everyone with a claim on the organisation or a stake in what it does, including groups it never chose. The market asks who will buy; this object asks who has standing.

Learn

Finance

Whether the business is profitable, whether it has cash, and whether it can fund what it intends to do next — three questions that are often confused. It also covers how capital is raised, how investments are appraised, and how tax bears on both.

Learn

Supply Chain

Everything between a supplier and a customer: sourcing, moving, holding and delivering. It is where the trade-off between efficiency and resilience is made, usually without anyone deciding it.

Learn

Manufacturing Operations

Where things are actually made: capacity, flow, quality and the maintenance that keeps all three possible. A production system runs at the speed of its slowest step.

Learn

Compliance

The obligations the organisation has no choice about — legal, regulatory, financial, health and safety, and data protection — and the controls that show they are being met. Commitments made above the legal minimum are held under Responsibility in the Vision Core.

Learn

Technology

The tools and systems estate as a whole — software, infrastructure, automation and AI — together with its security and the technical debt it carries. Individual processes are designed under Operational Systems; this object covers what they all run on.

Learn

Organisation

How the organisation is structured and led: who decides what, how work is divided and coordinated, and how people take up change. HR covers the people; this object covers the arrangement they work in.

Learn

Innovation

Where new offers and new ways of working come from, how they are tested, and how the decision to scale or stop them is taken. An idea nobody is able to stop is a commitment rather than an experiment.

Learn
Back to the Business Core