Agile Product Hub

Agile Product Hub

ProductStrategy

DigitalProduct

Organisational Friction

Organisation

Governance That Moves Risk Instead of Reducing It

How can an organisation add more governance and still feel less confident about its decisions?

It sounds contradictory. More oversight should create more control. More reviews should create more confidence. More approvals should reduce risk. Yet in many organisations, the opposite happens.

Governance becomes heavier. Decision-making slows. Uncertainty is discovered later.

Teams spend more time preparing for reviews.

And nobody feels particularly confident that the underlying risk has actually been reduced.

I explored this tension in the latest episode of the Organisational Friction Series.

🎧 Hopefully you have already listened to the podcast. If not, you can find it here: https://agileproducthub.com/podcasts

The episode “Governance That Moves Risk Instead of Reducing It” looks at why governance can sometimes create reassurance without creating real decision confidence, and what healthier governance might look like instead.


Governance is not the problem

It is easy to criticise governance.


  • Approval boards.

  • Risk reviews.

  • Steering committees.

  • Security checks.

  • Financial controls.

  • Portfolio forums.


But those mechanisms usually exist for good reasons.

Organisations need to understand risk. They need to protect customers. They need to meet legal and regulatory responsibilities. They need confidence that investment is being used responsibly. They need ways to make difficult decisions when consequences extend beyond one team.

The problem is therefore not governance itself. The problem appears when governance becomes primarily about demonstrating control rather than improving the decision.

That is where reassurance and confidence start to diverge.

Reassurance is not the same as confidence

Reassurance often comes from visible signs of control.


  • A detailed governance pack.

  • A green status.

  • A comprehensive risk register.

  • A formal review.

  • Several signatures beneath the decision.


All of those things can create the feeling that the organisation is managing the situation carefully.

But confidence comes from something deeper. Confidence comes from understanding:


  • What do we actually know?

  • What remains uncertain?

  • What evidence do we have?

  • What risks are changing?

  • What trade-offs are we making?

  • What would make this decision safer?

  • What would cause us to stop, adapt or change direction?


That distinction matters.

A governance process can be extremely thorough on paper and still fail to improve the quality of the underlying decision.

The purpose of governance should be better decisions, not simply more defensible ones.

A decision is not safer because more people approved it

One of the easiest ways to make a decision feel safer is to involve more approvers.

Architecture signs off. Security signs off. Finance signs off. A steering committee signs off. Leadership signs off.

That may be entirely appropriate for some decisions. But adding more approvals does not automatically reduce the underlying uncertainty. Sometimes it simply spreads the accountability.

When five forums have approved something, it becomes easier for everyone to say: “We followed the process.” But following the process is not the same as understanding the risk. In the worst cases, approval starts replacing ownership. Teams begin preparing evidence to satisfy the forum rather than to improve the decision. Specialist expertise becomes something to pass through rather than something to learn from. Governance shifts from helping people think to helping people defend themselves later. That is when risk starts moving rather than reducing.

Guardrails and stage gates are different

This is one of the most useful distinctions in the whole conversation.

A stage gate asks for permission.

A guardrail creates the conditions to act.

A stage gate is a formal point where work cannot continue without approval. That can be completely appropriate. Some decisions genuinely require formal assurance. A change may involve significant legal implications. It may affect sensitive customer data. It may introduce a material security concern. It may create a major financial commitment. It may be safety-critical. It may be extremely difficult to reverse. In those situations, stopping at a gate can be the responsible thing to do.

But not every decision carries that level of risk.

A guardrail works differently.

It defines the boundaries within which teams can make decisions without repeatedly asking for permission.

For example:


  • A spending threshold.

  • A defined security standard.

  • A data-handling rule.

  • An architectural constraint.

  • A risk threshold.

  • A clear escalation trigger.


The team understands the safe operating space. Inside that space, it can act. When it crosses the boundary, it knows additional advice, alignment or approval is required. This leads to a simple principle:

Good governance knows when a gate is necessary and when a guardrail is enough. The problem begins when every decision is treated like a border crossing.


When expertise arrives too late

Imagine a product team working on a significant customer-facing change.


  • They explore the opportunity.

  • They shape the solution.

  • They begin development.

  • Commitments are made.

  • Delivery progresses.


Then, close to launch, a formal governance review brings in a specialist function that has not previously been closely involved.

Perhaps


  • Privacy.

  • Security.

  • Legal.

  • Compliance.

  • Risk.


The specialist identifies a legitimate concern. The concern is real. It needs to be addressed. But by this point, the organisation has fewer options available.

Design decisions have hardened. Code may already exist. Dependencies have formed. Stakeholder expectations have been set. The late review now creates rework and delay. The immediate temptation is to blame someone.

Why did the product team not identify the issue?

Why is the specialist function blocking delivery?

Why did governance wait until now?

But none of those questions gets to the real problem.

The product team was trying to deliver.

The specialist function was doing its job.

The governance mechanism behaved exactly as it had been designed to behave.

The problem was that the right expertise entered the decision after the options had already narrowed.


Early advice is often more valuable than late approval

If the same specialist had contributed while the options were still being shaped, the conversation might have been very different.


  • The team could have adapted the design.

  • Changed the architecture.

  • Modified how information was handled.

  • Chosen a different approach.

  • Avoided building risk into the solution in the first place.


This is why governance should not sit outside Product Flow waiting for work to arrive at a gate.

Good governance brings relevant expertise into the conversation early enough to influence the decision.

That does not mean every specialist needs to attend every meeting.

It means the organisation needs clear ways for teams to access expertise at the right time.

And it requires another important distinction.


Advice, alignment and approval are not the same thing

Many governance problems begin because nobody is clear what kind of interaction is taking place.

A team approaches a specialist.


  • Is it asking for advice?

  • Is it asking for alignment?

  • Or is it asking for formal approval?


Those are very different things.

Advice means the specialist helps the team understand the risks and possible responses. The team may still own the final decision within its agreed boundaries.

Alignment means different parts of the organisation need to coordinate or agree a shared direction. No single party necessarily grants permission to the other.

Approval means the decision genuinely cannot proceed without explicit acceptance from the relevant authority. That should be clear.

The friction comes when these blur together.


  • A team asks for advice and accidentally enters an approval process.

  • A specialist believes it owns a decision when it is actually there to advise.

  • A leader expects alignment but the team interprets the conversation as permission-seeking.


Soon, every interaction starts feeling like a gate.

Healthy governance makes the distinction explicit.


Escalation can be healthy

Escalation is not automatically a sign of failure.


  • A team may reach a genuine boundary.

  • A decision may exceed an agreed level of risk.

  • It may require access to a new category of sensitive information.

  • It may create a portfolio-wide consequence.

  • It may need investment beyond the team’s authority.#


In those situations, escalation is the system working as intended.

The team knows where its authority ends. The boundary is clear. The next decision-maker is known. But there is another kind of escalation.

A team escalates because nobody is sure who owns the decision. Or because the boundary keeps moving. Or because making the decision locally feels personally unsafe. Or because approval is easier than carrying responsibility.

That is different.

When ordinary decisions repeatedly travel upwards, escalation becomes a signal.

It may indicate that governance is compensating for unclear decision rights, weak trust or unstable boundaries.


Leadership behaviour determines whether guardrails are trusted

A governance model can look excellent on paper.

But pressure reveals whether it is real.

When something goes wrong, leaders have a choice.

They can respond by


  • Adding reporting.

  • Adding approval.

  • Centralising decisions.

  • Taking control back


Or they can ask:


  • What is the system telling us?

  • Was the boundary clear?

  • Did the team have the right context?

  • Was the risk visible early enough?

  • Did expertise enter at the right time?

  • Has the constraint changed?

  • Does the guardrail need adjusting?


This is where governance becomes more than process design.

It becomes leadership behaviour.

A guardrail is only useful if people believe it will remain a guardrail when pressure increases.


Healthy governance creates confidence to decide

Healthy governance does not mean less responsibility.

It means responsibility is designed more deliberately.

It tends to include:


  • Clear decision rights.

  • Explicit guardrails.

  • Governance proportionate to the risk.

  • Early specialist involvement.

  • Evidence appropriate to the decision.

  • Visible uncertainty.

  • Clear escalation paths.


Formal approval where the consequences genuinely justify it.

And enough trust for decisions to remain close to the people with the strongest context.

The aim is not to eliminate oversight.

It is to make oversight useful.

Healthy governance creates confidence to decide, not dependency on approval.


This is where Harmony matters

Governance does not operate in isolation.

If strategic intent is vague, governance forums often become places where strategy is repeatedly reinterpreted.

If trust is weak, governance becomes heavier.

If decision rights are unclear, escalation increases.

If expertise sits outside Product Flow, risk appears late.

If leaders reclaim control whenever pressure rises, teams learn that autonomy is temporary.

That is why governance is part of the wider organisational system.

Harmony is about making those elements reinforce one another.


  • Strategic intent.

  • Decision rights.

  • Risk.

  • Expertise.

  • Learning.

  • Governance.

  • Leadership behaviour.


A harmonised organisation still has controls. It still has boundaries. It still escalates genuinely difficult decisions.

But those mechanisms exist to help the organisation make better decisions, not simply to make those decisions easier to defend later.

A question worth asking

Think about the governance in your organisation.


  • The forums.

  • The approvals.

  • The reviews.

  • The reporting.


Then ask:

Where does governance genuinely reduce risk, and where does it mostly move responsibility somewhere else?

And then:

What would need to change for that governance to help the people closest to the work make a better decision earlier?

Because sometimes the answer is not another approval.

Sometimes the safer choice is a clearer boundary, earlier expertise and the confidence to act.