Every Organisation Has Two Governance Systems

Most organisations are very good at writing policies.

Within a few minutes of asking, an executive can usually produce a risk management framework, a code of ethics, procurement policies, delegations of authority, compliance procedures and enough governance documentation to fill a filing cabinet. Today, it’s more likely to be a SharePoint site than a filing cabinet, but the principle is the same. On paper, everything appears to be under control.

The more interesting question is what happens when something goes wrong. When a mistake is made, is it raised immediately or quietly ignored? When the CEO asks for bad news, does somebody speak or does the room suddenly become uncomfortable? When a meeting ends with a list of actions, do they happen because people are committed to them or because someone will eventually ask for an update?

None of these behaviours are written into a policy. Yet they reveal far more about an organisation than the policies themselves ever could. Perhaps that’s because every organisation has two governance systems. The first is the one that is documented. The second is the one that actually operates. One tells people what they should do. The other determines what they actually do. The two are often assumed to be the same. In reality, they rarely are.

Take something as ordinary as a leadership meeting. Every executive team will say it values challenge. Every board wants robust debate. Every organisation encourages people to speak up. Then somebody asks the difficult question. The room goes quiet. Nobody says the question shouldn’t have been asked. Nobody openly disagrees. The conversation simply moves on. The next time, fewer people are willing to ask. Nothing in the governance framework changed. But the culture quietly rewrote the rules.

The same thing happens with corrective actions. Almost every organisation has a process. Assign an owner. Set a due date. Monitor progress. Yet six months later, many of the same actions are still open. Deadlines are extended. Priorities shift. Eventually someone closes the action because it has been on the report for too long. The governance process didn’t fail. The behaviour did.

It’s why culture is so often misunderstood. It’s frequently treated as an HR initiative or a leadership programme. Something separate from governance. But it isn’t. Culture is the operating system that determines whether governance ever gets executed.

History offers plenty of examples. Many organisations that experienced spectacular governance failures had well-written policies, active audit committees, compliance functions and sophisticated risk frameworks. The documents weren’t missing. The behaviours were.

It raises an important question. If culture has such a profound influence on governance, how should leaders measure it? Most organisations ask people. They run engagement surveys, culture assessments and questionnaires. Those tools have their place. But culture also leaves evidence. It appears in recurring audit findings. In overdue corrective actions. In risks that never seem to reduce. Culture is In incidents that repeat themselves. In the issues that everyone knew about long before they appeared in a board report. Individually, each of these looks like an operational issue. Together, they tell a much bigger story.

They reveal how an organisation behaves when nobody is watching.

This is where governance becomes something far more valuable than compliance. Governance shouldn’t simply confirm that policies exist. It should help leaders understand whether those policies are being lived.

One of the most common phrases heard after almost every organisational failure is remarkably simple. “I didn’t know.” Sometimes that’s  true. Sometimes it isn’t. More often than not, what people really mean is that they never saw the whole picture. One person knew about the audit finding. Someone else knew the corrective action was overdue. Another team knew the same incident had happened three times before. Operations knew. The board eventually found out. Everyone knew something but nobody knew everything. And that’s where organisations become vulnerable. The information existed but it lived in too many places, owned by too many people, until nobody could see what was really happening.

BarnOwl was built to change that. It brings risks, audits, findings, near-misses, incidents, compliance, controls, action plans and assurance activities together in a single, connected governance ecosystem, providing one source of truth, so that leadership sees the whole picture, not just the individual pieces.  Something interesting happens when everyone is looking at the same picture. The conversation changes. “It’s not my issue.” “I assumed it had been done.” “I didn’t know.” Those excuses begin to disappear. When everyone can see, accountability stops feeling like something that is imposed from above. It becomes part of how the organisation works.

Perhaps that’s what good governance has always been about. Making it impossible for important things to quietly disappear. Because every organisation has two governance systems. The one it writes down. And the one people live every day.  When those stories become one, good governance is no longer an aspiration. It’s the outcome. 

arrow up