Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Book Review: Mission-Critical Governance—Focusing on What Matters Most

Book Review: Mission-Critical Governance—Focusing on What Matters Most

By
Key Takeaways
  • Purpose Before Process: Tim Leech argues that governance has become overly focused on structures, reports, controls, and compliance activity while losing sight of why the board exists and what it ultimately needs to accomplish.
  • Objectives Should Anchor Oversight: The book centers governance on Mission-Critical Objectives (MCOs), connecting performance, uncertainty, risk, and assurance directly to the outcomes that determine organizational success and survival.
  • Information Reliability Matters as Much as Risk Reporting: Boards need more than dashboards and management reports. They need confidence that information concerning mission-critical objectives is complete, relevant, and reliable.
  • Culture Determines Whether Governance Works: Leech’s “Don’t Tell / Don’t Ask Governance Syndrome” explains why sophisticated governance structures can still fail when management filters uncomfortable information and boards fail to demand it.
  • Governance Needs to Become More Continuous: The book looks toward a future where analytics and AI support continuous oversight while judgment, courage, and accountability remain firmly human responsibilities.
Deep Dive

I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. These are important components, but they are not the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives.

The measure of GRC, therefore, is not how many governance activities an organization performs. It is whether the organization can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.

Tim Leech’s Mission-Critical Governance: Focusing on What Matters Most approaches this issue primarily from the boardroom and arrives at a closely related conclusion: organizations have built extensive governance machinery, yet too often fail to connect that machinery to the objectives that actually determine whether the enterprise succeeds or fails.

The book asks an uncomfortable but important question. A board may receive hundreds of pages of reporting, review enterprise risk dashboards, hear internal audit findings, approve policies, monitor compliance statistics, and satisfy governance codes. But can that board clearly identify the relatively small number of objectives that are truly mission-critical? Does it understand the uncertainty surrounding achievement of those objectives, and does it have sufficient confidence that the information reaching it is reliable?

Leech’s answer is that too often it does not. His proposed alternative is Purpose-Driven Governance (PDG), supported operationally by Objective-Centric Risk & Uncertainty Management (OCRUM). Together, these shift governance away from activity and toward purpose, mission-critical objectives, uncertainty, reliable information, and assurance.

Governance Has a Purpose Problem

One of the book’s strongest ideas is what Leech calls the Purpose Void. Organizations routinely define corporate mission, strategy, values, and objectives, yet boards themselves often lack an equally explicit articulation of their own purpose. Leech sees this as more than a philosophical omission. Without a clear understanding of why the board exists, it becomes harder to determine what it should oversee, what information it needs, and how its effectiveness should be evaluated.

This absence contributes to what he characterizes as a form of governance theatre: committees meet, policies are approved, risk registers are reviewed, audits are completed, compliance reports are delivered, and a tremendous amount of governance activity takes place. Yet the board can remain surprisingly disconnected from the objectives upon which enterprise success, resilience, trust, and viability actually depend.

Leech’s answer is not simply another aspirational mission statement. He argues that a Board Purpose Statement should become an actual governance instrument, defining why the board exists, whom it serves, what outcomes it is responsible for overseeing, what information it requires, and how it holds itself accountable. He then carries purpose into board agendas, committee charters, decision protocols, reporting, and evaluations.

That distinction is important. Purpose can easily become corporate wallpaper. Leech wants it operationalized.

Don’t Tell / Don’t Ask

Perhaps the most memorable concept in the book is Don’t Tell / Don’t Ask Governance Syndrome. Governance failures are often reconstructed afterward as stories in which somebody failed to communicate something important. Management says the board never asked. Directors say management never told them. Risk had part of the story. Internal audit had findings. Compliance had concerns. Operations saw warning signs. Yet nobody assembled the information into a coherent view of what was happening to the objectives that mattered.

Leech argues that this is not simply a reporting problem. It is both behavioral and structural. Management learns what the board wants to hear. Information becomes progressively filtered as it moves upward. Dashboards become reassuring. Uncomfortable uncertainty is softened. Boards interpret the absence of visible alarms as evidence that things are under control.

His related Failure Information Loop captures how fragmented information becomes selectively aggregated and sanitized before reaching the board, after which the board provides direction based on an incomplete understanding of reality. Management interprets that direction as validation, and the loop continues.

This is an important contribution because GRC too often assumes more information means better governance. It does not. Organizations generally suffer from too much data, not too little. The challenge is whether information has context, relevance, and reliability, and whether it reaches the right decision-maker at the right time. A 400-page board pack can conceal reality just as effectively as no board pack at all.

From Risk Lists to Mission-Critical Objectives

This is where Mission-Critical Governance aligns most strongly with my own thinking. Leech argues that boards should organize oversight around Mission-Critical Objectives, not around abstract lists of risks. These are the relatively few objectives whose failure could materially threaten organizational viability, strategic success, integrity, trust, compliance, or license to operate. They can include both value-preservation objectives—such as safety, liquidity, cybersecurity, regulatory compliance, or reliable financial reporting—and value-creation objectives such as strategic transformations, product launches, or critical growth initiatives.

This sounds simple, but it changes the conversation dramatically. Instead of asking, “What are our top ten risks?” the board begins with, “What are we trying to achieve that is absolutely critical?”

It can then ask what uncertainty surrounds that objective, what could prevent or enable its achievement, what indicators reveal movement, what management is doing in response, what uncertainty management is accepting, and whether that acceptance aligns with the board’s expectations. Risk becomes contextual rather than abstract.

This is how risk management should work. Risk has no meaningful existence independent of objectives. Organizations do not pursue risk because they have an appetite for risk. They pursue objectives because there is value in achieving them and accept uncertainty along the way. Leech’s MCO concept gives boards a useful mechanism for structuring that conversation.

From Diagnosis to Architecture

A significant strength of the book is that Leech does not stop with criticism. The second half becomes increasingly practical. Purpose-Driven Governance turns into an operating architecture in which boards establish purpose, identify MCOs, assign ownership, determine the expected rigor of uncertainty assessment, establish reporting expectations, and create mechanisms for assurance.

Several tools support this model, including the Acceptable/Unacceptable Uncertainty (AU/UU) framework and the Board Assurance Index (BAI).

The AU/UU model challenges the language commonly used in traditional risk reporting. Rather than simply calling something “high,” “medium,” “low,” “emerging,” or whatever terminology appears on the organization’s current heatmap, the model asks whether uncertainty surrounding a Mission-Critical Objective is acceptable given current performance, risk treatments, assumptions, and management decisions.

The BAI addresses another issue that receives far too little attention: how confident should the board be in the information behind the assessment?

I particularly like this point because GRC professionals can spend extraordinary amounts of time debating a risk rating while giving remarkably little attention to the reliability of the assumptions, data, assessments, and reporting behind the rating. A green dashboard based on unreliable information is not reassuring. It is dangerous.

Assurance Should Produce Confidence

Leech applies the same objective-centric thinking to assurance. Internal audit audits. Compliance tests. Risk functions assess. External audit provides opinions. Cybersecurity conducts reviews. Safety and quality functions perform their own assurance activities.

Every one of these functions can operate competently within its mandate while the board still lacks an integrated understanding of whether a Mission-Critical Objective is appropriately managed and whether the information it receives can be trusted. Leech calls this the Assurance Paradox: an organization can have abundant assurance activity without producing corresponding confidence at the board level.

His response is Integrated Objective-Centric Assurance (IOCA), which organizes assurance around MCOs instead of functional silos. This challenges conventional thinking in a useful way. Assurance should ultimately answer a question that somebody needs answered. Boards do not need assurance activity simply because assurance functions exist. They need confidence in the information upon which consequential decisions are being made.

Leech proposes integrated assurance maps, coordinated methodologies, common definitions, and MCO-centered assurance opinions that look across performance, uncertainty, controls, culture, escalation, and information reliability. Whether an organization adopts his exact methodology is less important than the underlying principle: assurance should connect directly to objectives and the decisions surrounding them.

Culture, Candor, and Courage

The book becomes especially interesting when it moves beyond process and into human behavior. Leech recognizes that governance architecture can be technically sophisticated and still fail because people operate it.

He identifies four behaviors needed to sustain Purpose-Driven Governance: curiosity, candor, collaboration, and consequence. He connects these to confirmation bias, optimism bias, authority gradients, conformity, and fear of consequences—all forces that distort information as it travels toward senior management and the board. He then translates these concepts into practical mechanisms, including designated skeptics, red-team discussions, scenario analysis, uncertainty workshops, and deliberate practices for surfacing dissent and uncomfortable information.

This prevents PDG from becoming just another framework diagram. Organizations have spent decades talking about “tone at the top,” but tone is not evidence that information is flowing accurately.

A CEO can sincerely believe the organization has a speak-up culture while employees several levels below have learned that delivering bad news is professionally hazardous. A board can insist it welcomes challenge while its meeting dynamics teach executives exactly which challenges are unwelcome. Governance ultimately depends upon truth moving through the organization.

Leech’s concept of Purpose Courage takes this further. Directors need to ask questions whose answers may be inconvenient. Executives need to expose uncertainty instead of managing its optics. Risk and audit functions need to challenge assumptions rather than simply administer frameworks. That is harder to accomplish than writing another governance policy but far more important.

Looking Toward Continuous Governance

The book closes by looking forward. Leech sees governance moving away from periodic information delivered through static board packets toward continuous oversight, supported by analytics and AI. AI can help detect emerging uncertainty, monitor MCOs, identify cultural drift, test information reliability, integrate assurance evidence, and surface inconsistencies before they become crises.

He is also clear that AI cannot replace judgment, courage, or accountability. I agree with the direction, although I would be somewhat cautious with his use of the phrase “co-governor” for AI. AI will become extraordinarily important within governance architecture. It can sense, analyze, challenge, recommend, orchestrate, and increasingly execute authorized activities. But accountability ultimately remains with people and governing bodies.

The larger point is compelling: governance cannot remain a sequence of episodic meetings reviewing what happened weeks or months ago. Organizations need the capacity to sense changes in their internal and external environment continuously, understand their relationship to objectives, determine whether intervention is required, and orchestrate action while preserving accountability.

Governance needs to learn faster because the environment it governs is changing faster.

Where I Would Add Some Nuance

Leech writes with conviction, and that makes the book engaging. Occasionally, that conviction leads him to characterize traditional ERM, internal audit, risk registers, and established governance approaches more categorically than I would.

I share much of the criticism. Risk-list ERM disconnected from objectives is problematic. Internal audit that focuses on isolated control deficiencies without connecting them to enterprise objectives can miss the bigger picture. Fragmented assurance can create activity without confidence. However, I would distinguish between the disciplines themselves and the way they are frequently implemented.

ERM is not inherently disconnected from objectives; poorly designed ERM is. Internal audit does not inherently have to be backward-looking or controls-centric. An objective-centric audit function can provide tremendous decision-relevant assurance.

The book also uses the deliberately provocative “Quadrillion-Dollar Problem” to describe the cumulative economic consequences of governance failure. This certainly grabs attention, but the manuscript acknowledges that the figure includes AI-supported estimation of cumulative value destruction and missed opportunity rather than a conventional empirical calculation. I would therefore treat the number as an illustration of scale rather than a statistic upon which the thesis depends. The argument does not need it.

There are already more than enough corporate collapses, misconduct events, strategic failures, regulatory penalties, safety disasters, and destroyed enterprise value to establish that ineffective governance is extraordinarily expensive.

Finally, there is a substantial amount of terminology to absorb: PDG, OCRUM, MCOs, AU/UU, BAI, IOCA, and several related constructs. Readers deeply immersed in governance, risk, and internal audit will follow this readily, but some directors and executives may initially experience acronym overload. Once understood, however, the concepts connect into a coherent architecture.

Final Assessment

Tim Leech has written an ambitious and worthwhile book. Mission-Critical Governance is not simply another guide to board effectiveness, enterprise risk management, or internal audit. It challenges readers to reconsider the architecture connecting all of them. Its central message is straightforward: boards need to know what matters most, understand the uncertainty surrounding it, and have confidence in the information they use to govern it.

The sophistication lies in what follows. Leech connects board purpose to Mission-Critical Objectives, objectives to uncertainty, uncertainty to risk acceptance and decisions, decisions to assurance, and assurance to confidence and accountability. He then recognizes that none of these mechanisms works without a culture willing to surface inconvenient truths.

That makes the book relevant well beyond the boardroom. I recommend it to board directors and committee chairs, CEOs, CROs, CAEs, compliance and governance leaders, risk professionals, regulators, investors, and anyone responsible for designing systems through which organizations understand uncertainty and make consequential decisions.

Readers may disagree with some of Leech’s criticisms of established governance practices, prefer different terminology, or challenge particular assumptions. That debate is healthy, but the larger challenge is much harder to dismiss.

An organization can have committees, policies, dashboards, risk registers, internal audits, external audits, compliance reports, and carefully documented minutes, and still fail to understand whether its most important objectives are on track. Governance activity is not the same thing as governance effectiveness.

Mission-Critical Governance asks boards to stop measuring how much governance they perform and start examining whether their governance enables them to see what matters, understand uncertainty, challenge assumptions, and act before reality makes the decision for them.

That is a conversation governance professionals need to have. The destination is not another governance framework. The destination is an organization that knows what matters, understands the uncertainty around it, and can trust the information on which it acts.

Purchase Mission-Critical Governance: Focusing on What Matters Most on Amazon.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong