Governing for the Regulator and the Business
The dual-track model is not a compromise — it is a deliberate design that gives each mandate what it needs without forcing either to operate in a framework designed for the other.
The Problem of Two Masters
Organisations in regulated sectors face a governance challenge that is rarely acknowledged and almost never designed for: they must satisfy two fundamentally different governance regimes simultaneously. Regulatory governance demands control, traceability, and compliance — the ability to demonstrate, at any point, that the organisation is operating within its regulatory boundaries. Delivery governance demands pace, adaptability, and decision-making speed — the ability to move a programme of change from inception to realisation without the delays and bureaucracy that kill momentum.
These two mandates are not merely different in emphasis. They operate on different logics, measure different things, and create different incentive structures. And in most organisations, they are served by the same governance framework — a framework that was designed for one mandate and has had the other bolted on as an afterthought.
The result is predictable: either regulatory compliance dominates and delivery grinds to a halt under the weight of assurance and documentation, or delivery pace dominates and regulatory obligations are met superficially or late, creating exposure that materialises when the regulator next examines the organisation’s controls. Neither outcome is acceptable. The question is whether a governance framework can be designed that genuinely serves both.
This paper argues that it can — but only if the two mandates are explicitly distinguished, their tensions are acknowledged rather than papered over, and the governance design makes deliberate choices about where each mandate takes precedence.
Two Logics, One Organisation
The distinction between regulatory governance and delivery governance runs deeper than most organisations recognise. It is not simply a matter of different reporting requirements or different stakeholders. The two regimes rest on different foundational logics.
| Dimension | Regulatory Governance | Delivery Governance |
|---|---|---|
| Primary objective | Demonstrate compliance; protect against regulatory sanction | Deliver outcomes; realise benefits within constraints |
| Time horizon | Ongoing and perpetual; obligations do not expire | Bounded; programmes have defined start and end points |
| Risk posture | Risk avoidance and mitigation; non-compliance is not an acceptable risk | Managed risk-taking; some risk is necessary to deliver change |
| Evidence standard | Auditable documentation; ability to demonstrate compliance retrospectively | Decision-quality information; sufficient to make timely decisions |
| Decision cadence | Deliberate and documented; decisions require formal approval trails | Rapid and iterative; decisions are made as close to the work as possible |
| Success measure | No adverse regulatory findings; clean audit opinions | Outcomes delivered on time, within budget, with benefits realised |
| Accountability | Distributed across control functions; shared responsibility with the board | Concentrated in the Senior Responsible Owner and programme director |
| Change response | Formal change control; amendments require impact assessment and re-approval | Adaptive; the ability to respond to emerging information is a design feature |
These differences are not reconcilable by compromise. A governance framework that attempts to split the difference between the two — moderately fast, moderately documented, moderately compliant — satisfies neither mandate. The regulatory regime requires specific, auditable evidence of compliance; “moderate” documentation is either sufficient or it is not. The delivery regime requires decisions at a pace that keeps the programme moving; “moderate” speed is either fast enough or the programme stalls.
Where the Mandates Conflict
The conflicts between the two mandates are concrete, recurring, and consequential. Three areas generate the most friction.
Documentation and evidence
Regulatory governance requires comprehensive documentation: policies, procedures, control descriptions, evidence of control operating effectiveness, decision records with formal approval chains, and audit trails that can withstand regulatory examination. This documentation serves a legitimate purpose — it demonstrates that the organisation is managing its regulatory obligations — but it imposes a significant overhead on delivery teams.
Delivery governance requires enough documentation to support good decisions, but not more. In my experience, the most effective delivery teams document decisions, risks, and dependencies — and not much else. The documentation is decision-oriented rather than compliance-oriented, and its volume is a fraction of what the regulatory regime demands.
The conflict materialises when a programme is required to produce both: regulatory-grade documentation for the controls it is implementing and delivery-grade documentation for the decisions it is making. Without deliberate design, the regulatory documentation requirement expands to cover everything — because it is easier for a programme team to apply one documentation standard uniformly than to distinguish between what requires regulatory-grade evidence and what does not.
Decision speed
Regulatory governance requires decisions to follow formal approval pathways: impact assessments, committee reviews, documented approvals with named signatories. These pathways exist to create the audit trail that the regulator will examine. They are designed for rigour, not speed.
Delivery governance requires decisions to be made at the pace the programme demands. A programme that must wait three weeks for a committee cycle to approve a design decision that affects the next sprint’s work will either slow down — losing momentum and extending timelines — or make the decision informally and document it retrospectively, which defeats the regulatory purpose.
Change control
Regulatory governance treats change as a risk. Each change to a controlled process, system, or data flow requires assessment, approval, and documentation. The change control process is designed to prevent unapproved changes that could create regulatory exposure.
Delivery governance treats change as a feature. Programmes operate in conditions of uncertainty, and the ability to adapt the approach as new information emerges is essential to successful delivery. A change control process that requires formal approval for every adjustment to the programme’s approach creates a friction that is incompatible with effective delivery.
The Design Principle: Separation with Integration
The argument of this paper is that the dual mandate can only be served by a governance framework that explicitly separates the two regimes while providing defined integration points where they must interact.
Separation means that regulatory governance and delivery governance operate as distinct processes, with distinct accountabilities, distinct cadences, and distinct evidence standards. The regulatory governance process manages the organisation’s regulatory obligations, produces the evidence and documentation the regulator requires, and is accountable to the compliance and risk functions. The delivery governance process manages the programme’s delivery, produces the information needed to make delivery decisions, and is accountable to the Senior Responsible Owner and the sponsoring board.
Integration means that at defined points — and only at those points — the two processes must interact. These integration points are where the programme’s delivery decisions affect the organisation’s regulatory position, or where regulatory requirements constrain the programme’s delivery options. At these points, both governance regimes must be engaged, and the decision must satisfy both mandates.
The integration points are typically:
- Programme initiation: the regulatory impact assessment that determines which regulatory obligations the programme affects and what regulatory governance requirements apply.
- Design decisions: decisions about process, system, or data design that affect regulated activities. These require regulatory-grade impact assessment and approval alongside the delivery decision.
- Stage gates: the points at which the programme’s delivery governance and the regulatory governance must independently confirm that the programme is fit to proceed — the delivery governance confirming that the approach is sound, the regulatory governance confirming that regulatory obligations will be met.
- Go-live / cutover: the point at which new processes, systems, or controls become operational and the organisation’s regulatory posture changes. This requires formal sign-off from both governance regimes.
- Post-implementation: the handover of programme-level controls to business-as-usual operations, with the regulatory governance regime confirming that the ongoing control framework is adequate.
Between these integration points, the two governance processes operate independently. Delivery governance manages delivery; regulatory governance manages compliance. Neither is subordinate to the other.
The Recommendation: Design for Both, Optimise for Neither
The recommendation of this paper is specific: organisations in regulated sectors should design their programme governance frameworks with an explicit dual-track structure.
Track one: delivery governance. This track is owned by the programme director and the Senior Responsible Owner. It operates on a delivery cadence — weekly or fortnightly decision cycles. It produces delivery-grade documentation: risk registers, decision logs, dependency maps, delivery confidence assessments. Its purpose is to ensure the programme delivers its outcomes.
Track two: regulatory governance. This track is owned by the compliance or regulatory change function. It operates on a regulatory cadence — aligned to the regulatory reporting cycle and the organisation’s assurance calendar. It produces regulatory-grade documentation: control descriptions, operating effectiveness evidence, regulatory impact assessments, audit-ready decision records. Its purpose is to ensure the programme satisfies the organisation’s regulatory obligations.
Integration governance. At each integration point, the two tracks converge. A joint review is conducted, involving both the delivery and regulatory governance leads. The review confirms that the delivery approach satisfies regulatory requirements and that the regulatory requirements are not unnecessarily constraining delivery. Disagreements are escalated to the sponsoring board for resolution.
The dual-track model is not a compromise — it is a deliberate design that gives each mandate what it needs without forcing either to operate in a framework designed for the other. The integration points are where the two mandates negotiate; everywhere else, they proceed on their own terms.
This model requires three things that most organisations do not currently provide:
- Explicit role separation. The delivery governance lead and the regulatory governance lead must be different people, with different reporting lines and different accountabilities. Asking one person to serve both mandates guarantees that one will dominate the other.
- Defined integration points. The points at which the two tracks must converge must be specified in advance, agreed by both parties, and embedded in the programme plan. Ad-hoc interaction — where the regulatory function intervenes in delivery decisions, or the delivery team bypasses regulatory requirements — defeats the model.
- Board-level sponsorship of the dual track. The sponsoring board must understand and endorse the dual-track model. In particular, it must be willing to act as the arbiter when the two tracks disagree at an integration point. A board that defaults to the regulatory position on every disagreement will strangle delivery; a board that defaults to the delivery position will create regulatory exposure.
The Cost of Not Designing
The alternative to deliberate design is the status quo: a single governance framework that attempts to serve both mandates and serves neither well. The cost of this approach is visible in every regulated organisation that runs major change:
- Programmes that take twice as long as they should because every decision requires regulatory-grade documentation, whether or not the decision affects regulated activities.
- Regulatory findings that arise not from genuine non-compliance but from the inability to produce the specific evidence the regulator requires, because the programme’s documentation was designed for delivery decisions rather than regulatory examination.
- Governance fatigue — the point at which delivery teams, overwhelmed by the volume of governance requirements, begin to treat governance as a box-ticking exercise rather than a decision-making discipline. This is the most dangerous outcome of all, because it means that neither mandate is being served.
The dual mandate is real, it is permanent, and it is not going away. The organisations that manage it effectively will be those that design for it explicitly rather than hoping that a single governance framework can serve two fundamentally different purposes.