Governance, written for the people who have to fund it.
Short pieces on what actually moves maturity, organized by domain.
Is Your AI Governance Tool Actually Governance?
Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.
Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability
Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.
Who Actually Owns the Data?
Poor data quality costs the average organization $12.9 million a year, according to Gartner. See why the owner-versus-custodian confusion is usually to blame.
Who Owns This Requirement?
Nearly 4 in 10 organizations have lost revenue or a bid over missing compliance evidence. See why tracking a requirement isn't the same as owning it.
What Happens When Risk Ownership Isn't Assigned
Firms without board-level risk visibility are 20% more likely to face major risk events. See what happens when a risk register lists departments instead of names.
Security Ownership: Why “IT Handles That” Is Usually Wrong
IT and security get treated as one job. They aren't. See where that confusion actually breaks, and what the 2026 DBIR shows about the cost of unassigned risk decisions.
What Happens When No One Owns the AI Policy
A policy without a named owner is a document, not a control. See what shadow AI adoption looks like without real governance behind it.
Five Data Findings That Repeat in Every Audit
Poor data quality costs the average company $12.9M a year. See the five data findings that repeat in audit after audit and what actually fixes them.
Five Signs an AI Deployment Has No Governance Behind It
No model inventory, no owner when things go wrong, no real review before approval. See the five signs an AI deployment has no governance behind it.
Five Signs Your Risk Register Is a Filing Cabinet, Not a Tool
Firms without board-level risk visibility are 20% more likely to face major risk events. See the five signs a risk register has stopped being a tool.
Five Privacy Findings That Show Up Long After the Policy Was Signed
A privacy policy is a snapshot, not a subscription. See the five privacy findings that surface long after the policy was signed and board-approved.
Five Controls That Always Pass Review and Always Fail in Practice
A control can pass a SOC 2 exam for years and still fail the moment it matters. See the five controls that consistently pass review and fail in practice.
Five Security Findings That Show Up in Every Audit
The same five cybersecurity gaps show up in audit after audit. See why they keep recurring and how continuous governance closes them.
Subscribe to The Governance Brief.
One email when something new is published. No sequences, no drip campaign.