Governance Is Not Who Decides. It’s How You Find Out.

Ask any organisation who’s responsible for a given technology decision and you’ll get an answer immediately. Ask them how they’d know if that person made the wrong call, and how long it would take to find out, and the confidence usually evaporates. Governance isn’t about who decides. It’s about how the organisation finds out, and most governance conversations skip straight past the harder half of that question, because naming who decides is comfortable and checking whether they decided well is not.

Decision rights get documented reasonably often — an org chart, a RACI matrix, a policy naming who approves what. What almost never gets documented is the feedback mechanism: once a decision is made, what tells the organisation whether it was right, and on what timeline. A decision right without a feedback loop is authority without accountability, however clearly the authority itself is drawn on paper.

Why the feedback question is the one that actually matters

Consider two organisations with identical decision-rights documentation: the CTO approves platform selections above a defined budget threshold. In the first, that approval is followed by nothing structural — no review of whether the platform delivered what was promised, no comparison against the alternatives that were rejected, no mechanism that would surface a pattern of consistently poor calls before the fourth or fifth expensive mistake. In the second, every approval above the threshold gets a scheduled review at a defined interval, comparing actual outcome against the case made at approval time, visible to whoever the CTO reports to. The decision right is identically drawn in both organisations. The governance is not, because governance lives in the second organisation’s feedback loop, not in either organisation’s approval chart.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

Where this gap actually costs money

The organisations that discover expensive technology mistakes late are, almost without exception, the ones with clear decision rights and no feedback mechanism — a platform decision that quietly underperformed for eighteen months before anyone formally revisited it, not because nobody suspected a problem, but because no scheduled mechanism existed to force the question onto anyone’s agenda. The person who made the call had no structural reason to revisit it, and nobody else had the standing to ask without it looking like a challenge to their authority rather than a routine governance process.

This is also where board-level technology oversight most often fails quietly: a board that has approved a clear decision-rights framework can still have no idea whether decisions made under that framework are actually working out, because approving the framework was treated as the governance task, and checking whether it’s producing good outcomes was never built in as a separate, ongoing one.

What a genuine feedback mechanism actually requires

Three things, attached to every decision right that actually matters: a defined review point, set at the time of the decision, not left to whenever someone happens to think of it. A comparison standard — what was promised or expected, recorded at decision time, so the review has something concrete to measure against rather than a vague retrospective impression. And visibility one level up — the review’s outcome genuinely reaching whoever holds the decision-maker accountable, not just being noted quietly by the decision-maker themselves, which produces a self-graded exam rather than real oversight.

None of this requires reviewing every decision — that produces the same fatigue and abandonment any over-engineered process eventually suffers. It requires being deliberate about which decisions are consequential enough to warrant this discipline, and building the feedback loop into those specific decisions from the moment they’re made, not retrofitted after something has already gone wrong.

What a missing feedback loop actually cost

A logistics firm’s technology lead had clear, documented authority to select platforms above a defined threshold, and used it to select a warehouse-management system eighteen months before a review of any kind. No review point had been set at the time of approval, so none happened organically. When the system’s limitations finally surfaced — during an expansion into a new facility that the platform genuinely couldn’t support — the retrospective conversation revealed the original business case had promised capabilities the platform had never actually delivered, silently, for the entire eighteen months. Nobody had lied. Nobody had checked. The decision right had worked exactly as documented; the absence of any mechanism to find out whether the decision was working was the actual gap, and it cost eighteen months nobody would have chosen to spend that way if a scheduled review had existed to force the question sooner.

Mapping which technology decisions in an organisation carry real decision rights but no genuine feedback mechanism is exactly the kind of governance gap a technology control assessment is built to surface.

The absence of a feedback loop is one specific case of a broader pattern — see the cost of a decision that never gets made at all.

Most boards would recognise this gap immediately if it were put to them plainly. Almost none have actually gone looking for it, because the decision-rights chart looks complete on its own, and nobody thinks to ask what happens after the box is ticked. That question is worth adding to the next governance review, whatever else is on the agenda.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming