Programme governance is often described through its visible components: steering committees, status reports, RAID logs, dashboards, stage gates and approval processes. All of these can contribute to governance, but none of them necessarily mean that a programme is well governed. An organisation can have a sophisticated reporting structure, several layers of meetings and an impressive set of controls while still struggling to make decisions, manage commercial exposure or establish whether the programme is delivering what the business originally intended.
The distinction matters because governance should provide control rather than simply create evidence that management activity is taking place. A programme may report a milestone as red for three consecutive months, identify a supplier dependency repeatedly or carry the same significant risk from one steering committee to the next. The reporting may be accurate, but if nobody has sufficient authority to change the position, or the right people are not brought together to resolve it, the organisation remains exposed. Governance is therefore better understood as the way an organisation directs a programme, assigns accountability, makes material decisions, controls investment and risk, and determines whether the work continues to support the outcome it was funded to achieve.
For senior leaders, good governance should reduce the amount of delivery detail they need to absorb rather than increase it. They should be able to understand what the programme is trying to achieve, what has materially changed, whether the commercial and benefits case still holds, where the most significant risks and dependencies sit, and which decisions require their involvement. Recent research by DeJong et al. (2026) highlights the problem with treating senior governance primarily as a reporting exercise. In a survey of chief transformation officers, nearly two-thirds said board involvement was mainly limited to status updates, while only 14% regarded their boards’ contributions as very useful. The issue is not that boards should become programme managers, but that senior governance creates more value when leadership contributes to significant decisions and strategic questions rather than acting primarily as a recipient of programme information.
The challenge is to achieve enough control to protect the organisation, its investment and the people affected by the change without creating bureaucracy that delays the work. This guide looks at how that balance can be achieved, covering decision rights, governance structures, meeting cadence, commercial and supplier controls, risk and assurance, legal and privacy considerations, organisational politics, leadership change and the controls that senior leaders should expect to see throughout the life of a programme.
1. What programme governance is actually for
A useful starting point is to separate governance from programme management. Programme management organises and delivers the work. Governance establishes the authority and boundaries within which that work takes place. The two are closely connected, but they are not interchangeable. The Government Project Delivery Functional Standard treats governance and roles as core elements alongside programme and project management, planning and control, and is designed to apply across different types of projects, programmes and portfolios (Government Project Delivery and Cabinet Office, 2025). In practice, effective governance needs to make authority limits, decision-making roles, accountability, assurance and reporting clear, while giving people sufficient autonomy to operate within those boundaries.
This means governance should not begin by copying the meeting structure from the previous programme. It should begin by establishing what the organisation actually needs to control. A large transformation may require decisions about investment, scope, technology, data, suppliers, organisational design, people, policy and operational readiness. Some of those decisions can be made within the programme, some belong to specialist functions and some may require executive or board authority. The governance model should make those boundaries clear enough that routine decisions are not continually escalated, while material decisions do not disappear into individual workstreams without appropriate challenge.
Reporting is part of this because leaders cannot make informed decisions without reliable information. However, the quality of governance depends on what the organisation can do with that information. If a supplier misses an important commitment, the programme should know whether this affects the critical path, what the contractual position is, what remediation is available and who can decide the response. If costs are forecast to exceed the agreed position, there should be clarity on the tolerances within which the programme can operate and the point at which further approval is required. If a risk cannot be managed within the programme team, there should be an escalation route to somebody with the authority to accept, mitigate or remove it.
This is where heavily administered programmes can give a false sense of security. A large RAID log may show that risks are being recorded, but it says very little about whether the important risks are being managed. A detailed dashboard may contain accurate information while obscuring the two decisions that actually matter. Several approval forums can create the appearance of control while making it difficult to identify who ultimately owns the outcome. Schroeck, Kwan and Stefanita (2020) make a similar distinction in their work on transformation governance, describing a transformation function that extends beyond traditional tracking and reporting into areas including prioritisation, budgeting, coordination and critical decision-making.
The practical test is whether the governance makes the programme easier to understand, easier to control and more capable of making timely, informed decisions. Where a control exists but does not materially improve any of those things, it is worth asking why it exists and whether there is a simpler way of achieving the same objective.
2. Start with the outcome and keep testing the case for investment
Governance should begin with the reason the programme exists. Before deciding which committees are needed or how frequently they should meet, leadership needs clarity on the outcome being pursued and the conditions against which success will be judged. A programme created to address regulatory exposure will have different priorities from one intended to increase revenue, replace an unsupported platform, improve customer experience or reduce operating cost. The level of investment, organisational impact, complexity and risk should influence the controls that follow.
The business case therefore has a role beyond obtaining initial funding. Circumstances change during major programmes. Costs can increase, assumptions can prove wrong, technology choices can become less attractive, customer priorities can change and organisational capacity may reduce. An acquisition or leadership change can alter strategy altogether. Governance needs to retain a connection between the original case for investment and what is now being delivered, otherwise the organisation risks continuing with a programme because it has already spent money on it rather than because it remains the right thing to do.
A programme that is technically on schedule may still require intervention if the expected benefits have materially reduced. Conversely, a programme that has slipped may still represent a sound investment if circumstances justify the additional time or cost. Governance should therefore keep testing whether the benefits remain achievable, whether the risks are manageable and whether the investment continues to make commercial and strategic sense. This is particularly important because sunk cost can exert its own pressure: the more an organisation has invested, the harder it may become to challenge whether the original plan is still appropriate.
Benefits also need owners. It is relatively easy for delivery teams to take responsibility for building a platform, completing a migration or launching a service. Many benefits, however, only materialise once the organisation changes the way it operates. A system intended to reduce cost may require process redesign, adoption, role changes and retirement of old technology before the financial benefit appears. The Project Management Institute’s Benefits Realization Management Framework separates the identification, delivery and long-term sustainment of benefits rather than treating them as an automatic consequence of completing a project or programme (PMI, 2016).
For leadership, this changes the question from “Are we on plan?” to whether the plan still represents the best route to the intended outcome. Schedule, cost and scope remain important, but they need to be interpreted in the context of the investment and the value the organisation expects to receive.
3. Decision rights: who decides, who contributes and who needs to know
Many governance problems are ultimately problems of decision-making. Sometimes nobody is certain who owns a decision. In other cases several people believe that they do, or an issue that should be resolved within a programme is repeatedly escalated because nobody is comfortable exercising the authority they already have. The opposite can happen as well, where a decision is taken locally without sufficient consideration of its impact on other teams, suppliers, customers or the wider organisation.
Responsibility matrices can help, but they are not a substitute for thinking carefully about the decisions themselves. Greer, Jordan and Sytch (2026) argue that organisations can assign decision roles without resolving the behaviours and ambiguity that prevent those roles working in practice. They describe one global technology company where twelve executives spent 90 minutes debating whether to create a new C-suite role without reaching a decision. The example is useful because the problem was not a lack of senior involvement; there was already plenty of it. The difficulty lay in how authority, competing interests and the decision-making process were operating in practice.
A useful distinction is between the person who has authority to decide, the people whose input is genuinely required and those who need to understand the outcome. These groups may overlap but they are not the same. An architect may need to provide specialist input into a platform decision without owning the commercial investment. A privacy specialist may need to assess data-processing implications without owning the overall programme. A sponsor may hold the final authority but should not be expected to decide responsibly without hearing from the people who understand the consequences.
Rogers and Blenko (2006) approached the problem by separating decision roles into Recommend, Agree, Perform, Input and Decide, forming the RAPID model. The value is not in adopting another acronym for its own sake. It is in recognising that a decision can become slow or politically contested when too many people believe they have approval rights or when nobody is clearly accountable for bringing it to a conclusion. Decisions can then be discussed repeatedly, delayed or even reopened after people thought they had been settled.
Decision rights also need tolerances. A programme leadership team may be able to approve changes within an agreed financial or scheduling threshold, while anything beyond that returns to the sponsor or steering committee. A technical team may be free to make design decisions within agreed architectural standards, but an exception that creates enterprise-wide implications may require another level of approval. The objective is not to escalate every decision upwards; it is to make clear where authority changes.
This becomes particularly important during recovery. When confidence in a programme falls, organisations often respond by moving more decisions upwards and involving more senior people. Some additional oversight may be necessary, but concentrating every decision at the top can make the situation worse by slowing down the people trying to correct it. A stronger response is to establish which decisions require executive intervention, which can remain with programme leadership and what evidence is needed for both.
4. Governance also has to deal with people, politics and competing interests
Governance models often assume that everyone involved is pursuing exactly the same objective. Organisations rarely work that neatly. Functions have their own targets, leaders have reputations and budgets to protect, suppliers have commercial interests, and a transformation can alter responsibilities, status and influence. None of this means that people are necessarily acting improperly. It does mean that decisions can be shaped by incentives that do not perfectly align with the wider programme.
McKinsey & Company (2026) describes this as a collective-action problem: an organisation can have a shared objective while individuals or groups act rationally according to their own interests but create a poorer outcome for the organisation as a whole. This does not necessarily imply bad intent. Local targets, budgets, resources, performance measures and priorities can encourage behaviour that makes sense within one part of the organisation while undermining the wider transformation. The governance implication is that important trade-offs should be visible rather than left entirely to informal negotiation between functions.
This matters because politics can appear in several forms. A business unit may resist a change because it loses local control. A function may push for its preferred platform even where the wider case is weak. A supplier may frame a problem in a way that protects its commercial position. A senior stakeholder may want a visible initiative prioritised over less glamorous work that is more important to the programme. Governance cannot remove personal motivation from organisations, but it can make it harder for individual interests to dominate without scrutiny by making ownership, evidence, financial implications and decisions more transparent.
The solution is not to invite everybody to everything. Excessive participation can create its own problems, particularly where people assume that attendance gives them decision authority. However, deliberately excluding somebody whose knowledge is material to the decision can be just as damaging. An operational leader who will inherit a new service, for example, may not own the programme but should have an appropriate voice before operational commitments are made. The same principle applies to architecture, security, data, finance, procurement, legal and other specialist functions where their expertise changes the risk or feasibility of a decision.
Recent BCG work on the human side of transformation similarly emphasises meaningful employee agency and the importance of obtaining honest signals from the organisation rather than assuming that apparent agreement represents genuine commitment (Boston Consulting Group, 2026). People do not need to participate personally in every decision, but they need confidence that relevant perspectives are represented and that meaningful input has somewhere to go. Governance should therefore be selective rather than closed: enough involvement to improve the quality of the decision, but sufficiently clear authority to prevent participation becoming permanent consensus-seeking.
Leadership change is another test of the governance model. A programme that depends heavily on the memory or influence of one sponsor becomes vulnerable when that person leaves. Previous decisions can be reopened, assumptions forgotten and people may interpret the arrival of new leadership as an opportunity to reposition priorities. A new leader should of course be able to change direction, but they should be able to understand why previous decisions were made before doing so. Maintaining a clear decision history, business case, financial baseline, major assumptions, commercial commitments and current risk position provides continuity without preventing legitimate change.
5. Governance should be proportionate to complexity and risk
There is no universally correct governance structure. A relatively contained programme in a smaller organisation might operate effectively with a sponsor, programme lead, integrated plan, financial view, clear risk and decision controls and one regular governance meeting. Adding an architecture board, programme board, commercial committee and executive forum to that environment may create more interfaces than the programme itself requires.
A global transformation involving multiple business units, regulated data, several strategic suppliers and significant organisational change is different. It may need workstream governance, integrated programme leadership, a steering committee, architecture and security assurance, commercial and procurement controls, privacy input, portfolio oversight and formal investment decisions. The additional governance is justified because the consequences and dependencies are different, not because the organisation is simply larger.
This principle of proportionality is consistent with the Government Project Delivery Functional Standard, which is intended to apply across different types of projects, programmes and portfolios rather than prescribe a single structure for every situation (Government Project Delivery and Cabinet Office, 2025). Schroeck, Kwan and Stefanita (2020) similarly argue that transformation arrangements need to reflect the characteristics of the transformation and the organisation’s capacity to deliver change rather than being imposed as a standard model.
Size is therefore only one factor. A comparatively small organisation handling sensitive personal information or undertaking a high-risk regulated change may need stronger assurance than a much larger organisation making a low-risk internal improvement. A programme with one established supplier may need less commercial governance than one coordinating several vendors whose deliverables depend on each other. A recovery programme may temporarily need a tighter cadence and more senior involvement than the same programme once stability has returned.
The aim is not light governance or heavy governance. It is appropriate governance. The model should be strong enough to expose the decisions and risks that matter without creating unnecessary routes through which every piece of work must travel.
6. Meetings should exist to make decisions, not to consume reports
The quality of governance can often be seen in its meetings. A steering committee that spends most of its time listening to presentations, revisiting information already contained in the pre-read or discussing delivery detail that could have been resolved elsewhere is unlikely to be using senior time effectively. Where a governance forum has decision authority, the agenda should be designed around the decisions, risks and trade-offs that require that authority.
A programme leadership meeting serves a different purpose from a steering committee. The programme team may need to reconcile dependencies, challenge milestones, review actions, understand delivery constraints and resolve issues across workstreams. A steering committee should be more selective. It needs enough context to understand the position but should spend its time on material changes, decisions, financial and benefits implications, significant risks, supplier or commercial matters and anything that requires sponsor-level intervention.
This normally means using pre-reading properly. Routine status, completed milestones and detailed workstream information can be provided in advance. The meeting itself can then concentrate on what has changed, what is uncertain and what needs a decision. Keller and Schaninger (2020) similarly describe effective transformation governance as requiring senior leadership to make critical decisions, allocate resources, resolve issues and maintain accountability rather than simply receive programme information.
Cadence should follow the pace of decisions and risk rather than an inherited calendar. Weekly integrated programme governance may be appropriate during a complex build or recovery. A sponsor or steering committee may meet weekly, fortnightly or monthly depending on the rate of change and level of authority required. During a relatively stable period, a monthly meeting may be sufficient; immediately before a major migration or business-critical release, shorter and more frequent decision points can be appropriate. The range can be significant. Seppä et al. (2024) note that during Nokia’s transformation from mobile phones towards telecoms infrastructure, its board met 63 times in one year. That is an extreme example rather than a recommended timetable, but it illustrates why governance cadence sometimes needs to depart substantially from normal corporate rhythms.
There should also be a route for decisions that cannot wait for the next scheduled meeting. If the governance model forces a programme to sit on a material decision for three weeks simply because that is when the committee next meets, the structure is controlling the programme rather than supporting it. Clear delegated authority and an agreed escalation route are usually more effective than creating additional standing meetings.
7. The controls leadership should expect to see
The exact control set will vary, but leadership should be able to establish the position of the programme without having to reconstruct it from several disconnected reports. The following areas provide a practical baseline for most significant transformations.
| Governance area | What leadership should be able to understand |
|---|---|
| Strategy and outcomes | Why the programme exists, the outcomes being pursued, the business case and how success will be measured |
| Scope and priorities | What is in and out, what has changed, what is most important and who can approve material change |
| Integrated delivery | Milestones, critical path, cross-workstream dependencies, major assumptions and readiness against upcoming events |
| Risks and issues | Material exposure, ownership, mitigation, decisions required and whether the residual risk is acceptable |
| Decisions | What has been decided, by whom, why, what remains open and when unresolved decisions become critical |
| Financial position | Approved budget, actual spend, forecast, committed spend, variance and the consequences of any change |
| Benefits and value | Expected benefits, owners, measures, assumptions, forecast value and whether the original case remains credible |
| Commercial and suppliers | Contracted outcomes, deliverables, performance, changes, dependencies, service obligations and current commercial exposure |
| Technology and data | Architecture, integration, migration, data quality, security, technical risk and significant exceptions |
| People and organisational change | Capacity, capability, role changes, operational impact, adoption, training and readiness |
| Assurance and compliance | Legal, privacy, security, regulatory, policy, audit and other specialist requirements relevant to the work |
| Transition and operations | Go-live criteria, service acceptance, support model, ownership after delivery and whether the organisation is genuinely ready |
The purpose is not to produce a separate report for every row. In fact, that can make governance harder. The strongest programme views integrate these areas sufficiently for the relationships between them to be understood. A schedule change may create additional supplier cost. A technical constraint may alter scope. A delayed policy decision may affect operational readiness. A financial saving may reduce expected benefits elsewhere. Looking at each control in isolation can conceal those interactions.
The same applies to RAG status. Red, amber and green can be useful for directing attention, but the colour is not the decision. An amber programme with well-understood risks and credible recovery actions may be under better control than a green programme whose reporting does not reflect emerging problems. Leadership should be interested in the evidence behind the status, what has changed since the previous review and what action follows from it.
8. Commercial, supplier, legal, privacy, security and compliance governance
Complex programmes increasingly depend on third parties, which makes supplier governance part of programme governance rather than a procurement activity that ends once the contract is signed. The contract establishes the commercial framework; it does not manage the relationship. Governance still needs to connect supplier deliverables to the programme plan, monitor performance and dependencies, manage changes and acceptance, deal with disputes and understand when commercial decisions affect delivery or vice versa.
This is particularly important where suppliers depend on one another. A platform provider may be ready while an integration partner is not. A data migration may depend on decisions by the business. A vendor may meet the literal wording of a deliverable while leaving an operational gap that was never clearly assigned. Good supplier governance makes these interfaces explicit and keeps internal accountability clear. Outsourcing delivery does not outsource the organisation’s responsibility for the outcome.
Commercial governance should also distinguish between operational flexibility and contractual change. Teams need enough freedom to solve problems without requiring a contract amendment for every minor adjustment, but material changes to scope, cost, responsibilities, milestones or risk need to be understood before commitments are made. Legal specialists should advise where legal interpretation is required, particularly around matters such as liability, intellectual property, data processing or contractual remedies. The programme leader’s job is not to become legal counsel; it is to make sure the commercial and legal implications are brought into the decision before the organisation commits itself.
Privacy and data governance work in the same way. A migration should not automatically move everything from the existing system into the new one simply because the data is technically available. The organisation should understand what data is required, what should be retained, what should be cleansed or removed, who owns those decisions and what assurance is needed before migration. The Information Commissioner’s Office states that data protection should be considered from the design stage and integrated throughout the lifecycle of processing. Where the use of personal information is likely to result in a high risk to people’s rights and freedoms, a Data Protection Impact Assessment is required (Information Commissioner’s Office, 2026).
Storage limitation is equally relevant during modernisation. Personal data should not be retained for longer than is necessary for the purpose for which it is being processed, and organisations need to be able to justify their retention periods (Information Commissioner’s Office, n.d.). This turns a seemingly technical activity such as data cleansing into a governance question: what should move, what should remain, what should be deleted, what business or legal requirement determines that decision and who has authority to approve it?
Policies also become more meaningful when they are translated into operational controls. Publishing a policy is different from ensuring that the processes and systems affected by it actually enforce the required behaviour. Depending on the context, an access process might require acknowledgement of relevant policies, procurement may require defined approvals before a supplier can be engaged, or a release process may require security or privacy assurance before deployment. The control should reflect the underlying risk rather than exist simply to demonstrate that a policy has been written.
The same principle applies across security, regulation and compliance. Programme leadership should know which specialists need to be involved, what they are accountable for, when their input is required and what happens if they identify a material concern. Bringing them in only at the final approval stage can create expensive rework. Bringing every assurance function into every delivery conversation can create unnecessary friction. The governance model should define the appropriate points of involvement and preserve specialist independence where that matters.
9. Governance should change as the programme changes
A programme does not need exactly the same governance throughout its life. During discovery, leadership may be dealing primarily with strategic fit, feasibility, investment assumptions and whether the problem is worth solving. As the programme moves into mobilisation, ownership, scope, planning, decision rights, supplier arrangements and funding become more important. During build and integration, attention often shifts towards dependencies, delivery performance, quality, scope, commercial change and technical risk.
Migration and release introduce another set of decisions. Data quality, operational readiness, support, business continuity, training, cutover planning and acceptance criteria may become more important than the controls that dominated six months earlier. At that stage, governance needs to be capable of reaching an informed go/no-go decision rather than simply reporting the percentage of tasks completed.
Transition into normal operations changes the emphasis again. Ownership has to move from the temporary programme structure into the organisation that will run the service, product or process. Support arrangements, operational metrics, outstanding risks, supplier responsibilities and benefits ownership need somewhere to go. Closing a programme while leaving those areas unresolved is an administrative closure rather than a successful transition.
Formal project-delivery standards also treat governance, control and solution transition as activities that continue across the programme lifecycle rather than ending once an initial investment decision has been made (Government Project Delivery and Cabinet Office, 2025). Transformation governance may therefore need to change in emphasis as interdependencies, implementation risk and operational impact increase (Schroeck, Kwan and Stefanita, 2020).
Governance should be reviewed periodically rather than treated as fixed. Meetings that were essential during mobilisation may later become redundant. A monthly steering committee may need to become weekly for a period of recovery. New assurance may be required as a programme begins processing different data or enters a regulated stage. Simplifying governance when complexity falls is just as important as strengthening it when risk increases.
10. What bad governance looks like in practice
Poor governance is not always obvious. Some badly governed programmes are visibly chaotic, but others produce regular reports, hold all the expected meetings and appear controlled until a problem becomes too large to conceal. The warning signs usually appear earlier if leadership knows where to look.
Repeated unresolved risks are one example. A risk that appears unchanged in several steering committee packs may indicate that mitigation is ineffective, ownership is unclear or the programme lacks the authority required to address it. Repeatedly changing the wording or RAG status does not alter the underlying exposure. The same is true of decisions. If an important decision continually moves to the next meeting, there may be a missing decision-maker, insufficient evidence or a political issue that the formal governance structure is failing to address.
Another warning sign is excessive participation. A meeting with twenty people can sometimes be necessary, but it can also indicate that the organisation has not distinguished between consultation and authority. The reverse is equally important: if the same small group makes every major decision while operational, technical or specialist knowledge is routinely excluded, the programme may be efficient only until an overlooked consequence appears.
Supplier relationships can hide governance weakness as well. Where internal leaders rely heavily on a supplier’s version of programme status, the organisation can lose the ability to challenge assumptions or understand its own commercial position. Strong governance does not assume suppliers are acting against the organisation; it simply recognises that suppliers have their own responsibilities and incentives, and that the client must retain sufficient knowledge and authority to govern the outcome.
Leadership behaviour is another indicator. A programme where bad news is routinely softened before reaching senior stakeholders may stay green longer than it should. This can happen because people are concerned about reputation, political consequences or the reaction they expect to receive. Governance cannot compensate for a culture that punishes transparency. Leaders need to make it possible for material problems to surface early while still holding people accountable for how those problems are managed.
Programme recovery often involves stripping this complexity back. The initial objective is to establish a reliable view of scope, milestones, finances, risks, dependencies, suppliers and open decisions, then identify which issues genuinely affect the outcome. Governance can be rebuilt around those facts with clearer ownership, decision rights and escalation. Adding more reports to a programme whose information is already fragmented rarely fixes the underlying problem.
11. A programme governance health check
A leadership team reviewing an existing programme should be able to answer the following questions without requiring weeks of investigation:
- Can we explain clearly why the programme exists and the outcomes it is expected to deliver?
- Does the original investment case still make sense based on what we know now?
- Is somebody clearly accountable for each material outcome and benefit, not simply each deliverable?
- Do we know who can make the important decisions and where their authority ends?
- Are the right people consulted without turning every decision into a consensus exercise?
- Can we identify the programme’s material risks, dependencies and unresolved decisions without reading several different reports?
- Are risks changing as a result of action, or simply being carried from one reporting period to the next?
- Do we understand approved budget, actual spend, committed spend and forecast cost, including the financial effect of known changes?
- Are suppliers being governed against agreed deliverables, outcomes, dependencies and commercial obligations?
- Are legal, privacy, security, regulatory and policy considerations being brought into the programme early enough to influence decisions?
- Can leadership trace significant scope, commercial and investment decisions and understand why they were made?
- Does each governance meeting have a clear purpose and authority, or are several forums discussing the same information?
- Could the programme continue to operate effectively if a sponsor or key leader changed tomorrow?
- Is operational ownership clear for what happens after delivery, including outstanding risk and benefits?
- If the evidence showed that the programme was no longer the right investment, does the governance model provide a credible route to change direction, reduce scope or stop?
A programme does not need a perfect answer to every question at every point in its lifecycle. The purpose of the health check is to expose where the governance model may be relying on assumptions, personalities or administrative process rather than explicit control.
Conclusion
Programme governance is not primarily about producing more information. It is about establishing enough structure for an organisation to make informed decisions, control investment and risk, understand accountability and respond when circumstances change. Reports, steering committees, RAID logs, stage gates and assurance processes are useful only to the extent that they support those objectives.
The strongest governance models also recognise that programmes operate inside real organisations. Functions have different priorities, suppliers have commercial interests, specialists need an appropriate voice and leadership can change. Clear decision rights and transparent evidence do not remove these pressures, but they make it less likely that important decisions will be driven solely by organisational politics, incomplete information or whoever carries the greatest influence at a particular moment.
Governance should therefore be designed around the programme rather than imposed on it. A smaller, lower-risk initiative may need a relatively simple structure, while a large transformation involving significant investment, complex technology, sensitive data, regulatory exposure and multiple suppliers will require considerably more control. In both cases the same test applies: the governance should be proportionate to the risk, clear about authority and useful to the people making decisions.
When governance works well, senior leaders do not need to manage the programme themselves. They have sufficient confidence in the information, accountabilities and controls to know when the programme can operate within its authority and when leadership intervention is genuinely required. That is the point of governance: not bureaucracy for its own sake, but a reliable way of directing change while the organisation still has time to influence the outcome.
References
Boston Consulting Group (2026) CEOs Are Betting Big on AI Transformations. Science Is How They Win, 14 May. Available at: https://www.bcg.com/publications/2026/ceos-are-betting-big-on-ai-transformations (Accessed: 14 August 2026).
DeJong, E., Ellmer, K., Berthion, M., Biggar, L., Black, B. and Chen, L. (2026) ‘The Secret to a Successful Transformation? An Engaged Board’, Boston Consulting Group, 1 June. Available at: https://www.bcg.com/publications/2026/how-active-boards-improve-transformation-success (Accessed: 14 August 2026).
Government Project Delivery and Cabinet Office (2025) Government Functional Standard GovS 002: Project Delivery, Version 2.1. Available at: https://www.gov.uk/government/publications/project-delivery-functional-standard (Accessed: 15 August 2026).
Greer, L., Jordan, J. and Sytch, M. (2026) ‘What Companies Get Wrong About Decision Rights’, Harvard Business Review, July–August. Available at: https://hbr.org/2026/07/what-companies-get-wrong-about-decision-rights (Accessed: 17 August 2026).
Information Commissioner’s Office (2026) Data protection by design and by default, updated 5 February. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/data-protection-by-design-and-by-default/ (Accessed: 16 August 2026).
Information Commissioner’s Office (n.d.) Storage limitation. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/ (Accessed: 14 August 2026).
Keller, S. and Schaninger, B. (2020) ‘How do we manage the change journey?’, McKinsey & Company, May. Available at: https://www.mckinsey.com/capabilities/people-and-organizational-performance/our-insights/how-do-we-manage-the-change-journey (Accessed: 18 August 2026).
McKinsey & Company (2026) ‘Collective action, collective success: A CEO’s role in transformations’, 15 June. Available at: https://www.mckinsey.com/capabilities/transformation/our-insights/collective-action-collective-success-a-ceos-role-in-transformations (Accessed: 18 August 2026).
Project Management Institute (2016) Benefits Realization Management Framework, November. Available at: https://www.pmi.org/learning/thought-leadership/series/benefits-realization/benefits-realization-management-framework (Accessed: 19 August 2026).
Rogers, P. and Blenko, M.W. (2006) ‘Who Has the D?: How Clear Decision Roles Enhance Organizational Performance’, Harvard Business Review, 84(1), pp. 52–61.
Schroeck, M., Kwan, A. and Stefanita, C. (2020) ‘What it takes to execute large-scale and lasting transformations’, Deloitte Insights, 23 November. Available at: https://www.deloitte.com/us/en/insights/industry/manufacturing-industrial-products/industry-4-0/digital-transformation-nerve-center.html (Accessed: 20 August 2026).
Seppä, T., Klemmer, D.C., Ramachandran, R. and Abreu, J. (2024) ‘Boards Can Make or Break a Transformation’, Boston Consulting Group, 20 February. Available at: https://www.bcg.com/publications/2024/boards-can-make-or-break-transformation (Accessed: 21 August 2026).