{"id":2828,"date":"2026-07-06T13:27:19","date_gmt":"2026-07-06T12:27:19","guid":{"rendered":"https:\/\/icomply.pm\/resources\/article-unified-programme\/"},"modified":"2026-09-08T12:07:46","modified_gmt":"2026-09-08T11:07:46","slug":"unified-programme","status":"publish","type":"post","link":"https:\/\/icomply.pt\/en\/resources\/unified-programme\/","title":{"rendered":"Building a unified governance programme from scratch"},"content":{"rendered":"<h2 data-dc-tpl=\"25\">Unified Governance Programme<\/h2>\n<p data-dc-tpl=\"25\">Whether you\u2019re setting up governance for the first time \u2014 or tidying up a jumble of spreadsheets \u2014 it\u2019s tempting to start with a framework. Don\u2019t do that. Start with an architecture into which all the frameworks fit. Here\u2019s a sequence that scales.   <\/p>\n<h2 data-dc-tpl=\"26\">1. Scope prior to the standards<\/h2>\n<p data-dc-tpl=\"27\">Define what you are managing \u2014 entities, systems, data, suppliers \u2014 before choosing frameworks. The scope determines everything else and helps you avoid the classic mistake of certifying one aspect whilst leaving the real risk out of the picture. <\/p>\n<h2 data-dc-tpl=\"28\">2. Build a library of controls, not a checklist<\/h2>\n<p data-dc-tpl=\"29\">Create a single library of operational controls. Frameworks map <em data-dc-tpl=\"30\">down <\/em>to these controls; the controls map <em data-dc-tpl=\"31\">up<\/em> to various frameworks. It is this decision that determines whether any duplication of work ever occurs.  <\/p>\n<h2 data-dc-tpl=\"32\">3. Assign responsibility<\/h2>\n<p data-dc-tpl=\"33\">Every control needs a person in charge and a schedule. Governance fails when controls are the responsibility of \u2018everyone\u2019. Link the people in charge to notifications so that any outstanding work is automatically highlighted.  <\/p>\n<h2 data-dc-tpl=\"34\">4. Collect evidence once<\/h2>\n<p data-dc-tpl=\"35\">Attach supporting evidence to the controls and reuse it across all frameworks that reference them. The version history is non-negotiable \u2014 auditors place greater trust in a clear audit trail than in a voluminous dossier. <\/p>\n<h2 data-dc-tpl=\"36\">5. Take risks alongside controls<\/h2>\n<p data-dc-tpl=\"37\">Link risks to the controls that mitigate them. A risk register that exists in isolation from the controls becomes a document that nobody reads; one that guides the prioritisation of controls becomes the driving force behind the programme. <\/p>\n<h2 data-dc-tpl=\"38\">6. Ensure the guarantee remains in force<\/h2>\n<ul data-dc-tpl=\"39\">\n<li data-dc-tpl=\"40\">Out-of-date evidence speaks for itself.<\/li>\n<li data-dc-tpl=\"41\">The backlog of tasks is growing.<\/li>\n<li data-dc-tpl=\"42\">The growing risk prompts a review.<\/li>\n<li data-dc-tpl=\"43\">Audits draw on the same ongoing controls.<\/li>\n<\/ul>\n<h2 data-dc-tpl=\"44\">7. Expand by mapping, not by reconstruction<\/h2>\n<p data-dc-tpl=\"45\">Once the architecture is in place, adding NIS2, the AI Act or ESG reporting is simply a matter of mapping. The second framework is dramatically cheaper than the first \u2014 exactly the opposite of what happens with single-standard tools. <\/p>\n<p data-dc-tpl=\"46\">Build the architecture first, and every framework you add will make the programme more robust rather than more cumbersome.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A step-by-step approach to scope, controls, evidence and ongoing assurance \u2014 designed to be scalable across domains.<\/p>\n","protected":false},"author":1,"featured_media":2847,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_ice_seo_score":0,"_ice_review":"","footnotes":""},"categories":[40],"tags":[],"class_list":["post-2828","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-best-practice"],"_links":{"self":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/comments?post=2828"}],"version-history":[{"count":7,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2828\/revisions"}],"predecessor-version":[{"id":4060,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2828\/revisions\/4060"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media\/2847"}],"wp:attachment":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media?parent=2828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/categories?post=2828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/tags?post=2828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}