Beyond Amazing
The Strategy Toolkit

Playbook

Putting Governance in Place

Governance is my day job, so this is the order I build it in for real clients: settle who owns risk and who checks it, pin decision rights to named people, take the same discipline down to task level, then give the whole structure a live risk register to manage.

Governance is the part of my work people expect to be boring, and I have made my peace with that. I build governance architecture at Beyond Amazing, and before that I spent twenty years growing a tax consultancy from a few thousand in turnover to a seven-figure turnover, which means I have lived the exact moment this playbook is written for: the business outgrows the founder's ability to see everything, and 'we all trust each other' quietly stops being a control environment. Most organisations respond by writing policies, and policies on their own are wallpaper. Structure is what holds when someone is having a bad quarter. This sequence builds the structure in the order I build it for clients. Three Lines of Defence settles who owns each risk, who oversees it and who checks independently, before anyone starts arguing about headcount. RAPID pins decision rights, because governance usually fails at the moment nobody can say who decides. RACI takes the same discipline down to task level, one accountable name per row. Then the risk matrix gives the whole apparatus something real to manage, because structure without content is an org chart with ambitions. Roles first, decisions second, tasks third, risks last. Get the order right and when a risk finally lands, there is already a named person whose job it was to catch it.

The Working runs this playbook on your own situation

A governance model that separates risk work into three distinct roles: management that owns and controls risk, risk and compliance functions that oversee it, and internal audit that gives the board independent assurance that the first two are working.

Start with roles, because in a growing organisation risk work is happening everywhere and nobody can say who owns which control and who checks it. The three lines are roles rather than departments. In a small business one person can hold a first-line and a second-line role at once, provided the hats are named and never worn simultaneously for the same control. When I map this with clients, the first draft nearly always shows the board taking comfort from assurance that is really management marking its own homework. Finding that out on paper is cheap.

Watch forTreating the model as an organisation chart to be staffed, then hiring three departments a business of your size does not need.

Read Three Lines of Defence in full

A role-charting tool from Bain & Company that assigns five roles for any major decision, Recommend, Agree, Perform, Input and Decide, so that one named person owns the call and everyone else knows exactly how they are expected to contribute.

Risk ownership can be beautifully mapped while decisions still stall, get made twice at different levels, or unravel in delivery. RAPID exists for that gap. For each decision that matters, one named person holds the D, one recommends, a short list gives input, and only genuine legal or financial sign-offs earn an Agree. Count the roles when you are done. More than one D, or a long Agree list, means you have documented the ambiguity instead of removing it. Put the D where the information lives, which is often below the most senior person in the room.

Watch forGiving the D to a committee, or to two people jointly, restores exactly the ambiguity the tool exists to remove.

Read RAPID Decision Roles in full

III

Org, people & execution

RACI Matrix

A grid that assigns one of four roles to everyone involved in a task or decision: Responsible for doing the work, Accountable for the outcome, Consulted before it is done, Informed after. Its whole discipline lives in one rule, exactly one Accountable name per row.

Now take the same discipline down to the level where work actually gets dropped. Tasks fall into the gaps at handovers, and each side sincerely believes the dropped task belonged to the other. A RACI grid forces those arguments in week zero, on paper, rather than in month three, in an incident review. Hold the one rule that gives the tool its teeth: exactly one Accountable name per row. Every argument the chart provokes is the chart working, because the disagreement already existed and you have simply made it discussable.

Watch forConsultation inflation, C's handed out to avoid offence, until every task waits on five opinions and none of them can say what their input changes.

Read RACI Matrix in full

Places each risk on a grid of likelihood against impact so that limited attention and budget flow to the risks that are both probable and damaging, with a distinct response posture, from acceptance through to avoidance, attached to each quadrant.

The structure now needs something to manage. Put every identified risk on the likelihood and impact grid, give each one a response posture and an owner, and let the top-right corner set the agenda. The matrix is triage rather than measurement, and its real job here is to connect the machinery you have just built: each significant risk gets an owner in the first line, oversight in the second, and a place on the board's assurance map. A risk register with no names attached is just a list of worries.

Watch forA register reviewed annually and returning the same picture every time is recording effort rather than managing anything.

Read Risk Matrix in full

✦

In the end

You should finish with four documents that reference each other: an allocation of risk roles across the three lines, a decision chart with named D's, a task grid with one accountable per row, and a live, owned risk register. Here is the caveat I give every client: the structure distributes the work on risk, and it guarantees nothing about how well that work is done. Governance on paper gets tested in calm weather. The real test arrives when the numbers are bad and the deadline is close. Book the first review before you sign off the design, because that is the moment most governance quietly dies.

Ask the Analysis Engine about your situation