4 minute read

Doctrine of Proactive Governance

Everyone who works in a financial institution has an opinion about governance, and most of them are cynical ones. If you come from a security background, governance is the wall that keeps bad things from happening. If you come from development, governance is the wall that keeps you from shipping. I have done a lot of governance work over the years, and I want to argue for a third view, one that is less cynical and, I think, more useful: proactive governance.

The problem governance is actually solving

Start with the scale of the thing. Since the early 2010s, financial institutions have had one big objective: to align and resolve enterprise level risk. The word enterprise matters. This is risk at a scale that crosses many departments, and you cannot manage that kind of risk from a single team’s desk.

Here is the tension that started it all. The sales team has KPIs and the compliance team has KPIs, and these two sets of targets pull in opposite directions. Sales wants to move faster and take more on. Compliance wants to slow down and verify everything. Both teams are right, and both cannot win at the same time. The institution needs a structured channel to resolve that kind of difference, so it built one: new mechanisms, new checks and balances, and the whole thing grew into the modern risk management framework that now touches every activity in the company.

Read it that way and the picture changes. The framework is a calculus of incentives and ownership of risk. The objective was never to stop people from doing things. It was to resolve KPI conflicts between departments in a structured manner, so the company can keep moving instead of freezing at every disagreement.

The two cynical readings

With that bigger picture, it is easy to get cynical, and I have caught myself doing it too. The first cynical reading: anyone who pushes back on governance is trying to get away with something, probably something slightly dishonest. The second: anyone who runs governance is there to stop me from doing productive work. I have believed both on different days, and both are wrong.

The useful reading sits in between. Governance is a dance between parties who do not naturally agree, conducted in the risk language, with the differences resolved through a clear mechanism of reporting and resolution. That mechanism exists and it is concrete: the risk committee, chaired at C level and very often by the CEO. When you know the mechanism is there, the maze turns into a process. You can see where disagreements go, who decides them, and what language they get argued in.

Why be proactive

There are two levels to being proactive, and the second one is the deeper.

The first level is defensive: if you do not engage with risk and governance, they will get to you anyway. Risk does not wait for you to be ready. It arrives on someone else’s terms, usually at the worst moment, and you get to react instead of shape. Engaging early costs less than being dragged in late.

The second level is the one I really want to make the case for: proactive governance is a lever for influence without authority. If you understand the risk framework, you understand how the company actually decides. A developer who can frame a proposal in the risk language, who can say what risk this retires, who owns it, and how we would know if it went wrong, can move decisions that years of seniority cannot move. Done well, this brings real value to the company, and it is available to anyone willing to learn the language. Every person in the company should understand this concept, because it is one of the few genuine levers you get without a title.

Trust is the fuel

All of this is trust based, and trust breeds from one unglamorous activity: speaking to people and actually understanding their perspective. Not scanning their slides, not reading their policy. Talking, and listening until you can restate their problem back to them.

The payoff is faster than people expect. With proper trust you navigate ideas quicker, you resolve priorities quicker, and a surprising amount of unnecessary work simply never gets created. Most governance pain I have seen was not caused by the framework. It was caused by people who did not trust each other trying to negotiate through paperwork.

The bloat trap

The failure mode of big governance structures is diffusion of responsibility. As parties get bigger and bigger, no single person feels truly accountable. The company draws RACI matrices, but not everyone understands them, so accountability slips out of the process and everything bloats. The governance process becomes something people perform at, and the original purpose, resolving the KPI conflicts, gets buried under the machinery.

Which is exactly why the trust point matters. The antidote to bloat is not a better framework, it is a few key allies. Practically speaking, a lot of the acceleration born in governance comes from trust between a handful of people. If you have two or three allies who genuinely understand the risk framework, one in risk, one in compliance, one in the business line, you can move at a speed the org chart would never suggest.

The point of it all

Governance in a financial institution is the machinery the company uses to decide things when the people involved do not agree. It is worth understanding, worth engaging with, and worth doing well. The cynical path is the expensive path: it turns every decision into a fight. The proactive path turns the same decisions into leverage. The dance is happening either way. You might as well learn the steps.

Updated: