Unified Governance Programme
Whether you’re setting up governance for the first time — or tidying up a jumble of spreadsheets — it’s tempting to start with a framework. Don’t do that. Start with an architecture into which all the frameworks fit. Here’s a sequence that scales.
1. Scope prior to the standards
Define what you are managing — entities, systems, data, suppliers — before choosing frameworks. The scope determines everything else and helps you avoid the classic mistake of certifying one aspect whilst leaving the real risk out of the picture.
2. Build a library of controls, not a checklist
Create a single library of operational controls. Frameworks map down to these controls; the controls map up to various frameworks. It is this decision that determines whether any duplication of work ever occurs.
3. Assign responsibility
Every control needs a person in charge and a schedule. Governance fails when controls are the responsibility of ‘everyone’. Link the people in charge to notifications so that any outstanding work is automatically highlighted.
4. Collect evidence once
Attach supporting evidence to the controls and reuse it across all frameworks that reference them. The version history is non-negotiable — auditors place greater trust in a clear audit trail than in a voluminous dossier.
5. Take risks alongside controls
Link risks to the controls that mitigate them. A risk register that exists in isolation from the controls becomes a document that nobody reads; one that guides the prioritisation of controls becomes the driving force behind the programme.
6. Ensure the guarantee remains in force
- Out-of-date evidence speaks for itself.
- The backlog of tasks is growing.
- The growing risk prompts a review.
- Audits draw on the same ongoing controls.
7. Expand by mapping, not by reconstruction
Once the architecture is in place, adding NIS2, the AI Act or ESG reporting is simply a matter of mapping. The second framework is dramatically cheaper than the first — exactly the opposite of what happens with single-standard tools.
Build the architecture first, and every framework you add will make the programme more robust rather than more cumbersome.