Who Is Auditing Governance?

Who Is Auditing Governance?

By
Key Takeaways
  • Governance Itself Is Rarely Assessed: Organizations routinely audit risks, controls, compliance, and financial reporting, but few formally evaluate whether the governance framework is effective.
  • Board Purpose Should Be the Starting Point: Governance effectiveness cannot be measured credibly without first defining and agreeing on the PURPOSE of the board.
  • Process Is Not Proof of Effectiveness: Governance codes, board evaluations, and compliance with prescribed activities demonstrate process, not necessarily successful governance.
  • Governance Should Focus on Mission-Critical Objectives: An effective governance framework ensures boards receive reliable information on organizational PURPOSE, performance, and the risks to achieving mission-critical objectives.
  • The Assurance Profession Has an Opportunity: Regulators, boards, shareholders, internal auditors, and risk leaders should place greater emphasis on independently assessing governance effectiveness rather than only reviewing governance activities.
Deep Dive

I recently posed what I believe is one of the most important unanswered questions in governance on LinkedIn: Who is auditing the governance framework? The responses confirmed two things. First, many practitioners instinctively recognize the gap. Second, there is still remarkably little agreement on who should be responsible for assessing governance effectiveness or even what "effective governance" actually means. That conversation reinforced why I have been asking this question for decades.

I have been asking that question for decades because governance is not just another management process. It is the system responsible for directing and overseeing the organization. If that system is ineffective, can we really take comfort from knowing that individual controls, compliance programs, or assurance activities have been reviewed? Surely the effectiveness of the governance framework should be one of the most important things an organization measures. Instead, it is often one of the least examined.

The assurance work carried out in most organizations today focuses on governance activities rather than governance effectiveness. Boards complete self-assessments. Organizations benchmark themselves against governance codes. Internal audit reviews governance processes. Regulators examine whether prescribed oversight mechanisms exist. None of these activities is without value, but they do not answer the fundamental question. Is the governance framework helping the organization achieve its purpose?

That distinction matters because effectiveness cannot be measured until there is agreement on what governance exists to achieve. More specifically, there must first be agreement on the PURPOSE of the board. Surprisingly few governance assessments begin there. Most begin with checklists of expected board activities or established governance practices. They measure whether directors have fulfilled prescribed responsibilities, whether committees have met, or whether governance documentation is complete. What they rarely do is establish an agreed BOARD PURPOSE and then measure success against it.

Without that foundation, claims that governance is "effective" become difficult to defend. Effectiveness is not demonstrated because meetings were held or reports were received. It is demonstrated by showing that governance is achieving the purpose for which it exists. Governance assessments that do not begin by establishing and disclosing BOARD PURPOSE risk becoming exercises in GOVERNANCE THEATRE. They may demonstrate that expected activities occurred, but they tell us remarkably little about whether governance itself is working.

This is not a new concern. More than twenty-five years ago, the Institute of Internal Auditors recognized governance assessment as something internal audit should do. That expectation was eventually removed when it became clear that, in practice, very few organizations had developed a credible way to assess governance effectiveness. Risk management standards have remained largely silent on whether chief risk officers should assess and report on governance frameworks. Boards continue to complete self-assessments, and some engage external reviewers, but those reviews frequently rely on accepted practices rather than beginning with a simple question: what is this board here to accomplish?

In my view, an effective governance framework linked to a clearly defined BOARD PURPOSE should ensure that the organization's PURPOSE and mission-critical objectives are explicitly identified and agreed. It should ensure that reliable information on the performance and risks associated with achieving those objectives reaches both the CEO and the board in time to improve decision-making. Accountability for the quality of that information should be clear, and assurance providers should assess whether the reports on which directors rely are sufficiently reliable to help them discharge their fiduciary responsibilities.

That shifts the conversation away from governance process and toward governance outcomes. The objective of governance is not simply to hold meetings, approve policies, review risk registers, or satisfy governance codes. Its purpose is to improve the quality of decisions that determine whether the organization succeeds. If governance is not helping leadership focus on what matters most, then it is difficult to argue that it is effective, regardless of how mature individual assurance functions may appear.

This is why organizations can have sophisticated enterprise risk management programs, comprehensive compliance functions, extensive internal audit coverage, and impressive control environments, yet still experience catastrophic failure. They may be exceptionally good at monitoring individual risks while failing to ensure that governance remains relentlessly focused on entity PURPOSE and MISSION CRITICAL objectives. Assurance over components is not the same as assurance over the system that connects them.

The governance profession has spent decades refining frameworks, standards, and assurance practices. Perhaps the next step is also the simplest. Before we ask whether governance activities have been completed, we should ask whether governance itself is effective. That starts with agreement on BOARD PURPOSE and ends with measuring governance against that purpose. Until that becomes standard practice, one of the organization's most important controls will continue to be one of its least examined.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong