Regulatory Governance Versus Delivery Governance — The Dual Mandate
The programme that tries to satisfy its regulator and its sponsor through the same governance forum will, in the end, satisfy neither.
Two Masters, One Agenda
Every programme delivered within a regulated sector — financial services, utilities, healthcare, telecoms — operates under a dual mandate that is rarely acknowledged in its governance design. On one side sits the sponsor’s agenda: deliver the business change, realise the benefits, stay within budget and timeline. On the other sits the regulator’s agenda: demonstrate compliance, maintain controls, evidence due process. Both are legitimate. Both demand governance attention. And yet, in my experience, most programmes attempt to serve both through a single set of forums, a single reporting structure, and a single set of governance behaviours.
The result is predictable. The governance forum oscillates between two modes. In one meeting it is a delivery board, interrogating progress, challenging timelines, pressing for acceleration. In the next — or sometimes in the same meeting — it becomes a compliance committee, demanding evidence packs, questioning audit trails, insisting on documentation that the delivery team regards as bureaucratic overhead. Neither mode gets sustained attention. The delivery conversation is interrupted by compliance concerns; the compliance conversation is curtailed because the programme is behind schedule.
The Structural Impossibility
The core problem is not that organisations are unaware of the dual mandate. Most are acutely aware. The problem is structural: the two mandates pull governance in opposite directions, and no single forum design can optimally serve both.
Delivery governance needs to be forward-looking, decision-oriented, and focused on removing obstacles. It asks: what needs to happen next, what is in the way, and who needs to decide? Its natural cadence is frequent, its papers are brief and action-oriented, and its measure of success is the speed and quality of decisions made.
Regulatory governance needs to be evidence-based, backward-looking (in the sense of demonstrating what was done and why), and focused on defensibility. It asks: can we demonstrate that due process was followed, that risks were identified and managed, that controls are operating effectively? Its natural cadence is periodic and aligned to regulatory reporting cycles, its papers are detailed and documentary, and its measure of success is the completeness and traceability of the record.
Delivery governance asks what needs to happen next. Regulatory governance asks what can be proven to have happened already. A forum that tries to do both at once does neither well.
These are not contradictory objectives, but they are genuinely different activities requiring different information, different behaviours, and often different people around the table. The delivery board needs the programme director, the workstream leads, the business change manager. The regulatory governance forum needs the compliance function, the risk function, and the programme’s assurance lead. There is overlap — the programme director should attend both — but the core membership, the core questions, and the core outputs are distinct.
The Symptoms of Conflation
When organisations conflate the two mandates into a single governance structure, the symptoms are recognisable:
- Agenda bloat. Meetings run to three hours because they are trying to cover delivery progress, risk reviews, compliance updates, and regulatory readiness in a single sitting. Nothing gets adequate time.
- Information overload. Papers are designed to serve two audiences simultaneously and end up serving neither. The delivery-oriented members skip the compliance sections; the compliance-oriented members have no context for the delivery decisions being discussed.
- Decision paralysis at the intersection. The hardest decisions in regulated programmes sit at the intersection of the two mandates: where delivery speed conflicts with compliance rigour, where a pragmatic shortcut is commercially sensible but regulatorily indefensible. These decisions require a deliberate, explicit conversation about trade-offs. In a conflated forum, they are either avoided or resolved by whichever voice in the room is loudest on the day.
- Accountability confusion. When something goes wrong, it is unclear whether the governance failure was one of delivery oversight or regulatory assurance. The answer is usually both, precisely because the structure did not separate them.
What Separation Looks Like
The programmes I have seen navigate this most effectively have done so by making the dual mandate explicit in their governance design. This does not mean doubling the governance overhead. It means designing two distinct governance tracks with clear interfaces between them.
The delivery track operates at the cadence the programme requires — fortnightly or monthly — with decision-oriented agendas and a membership drawn from those with authority over the programme’s resources and direction. Its outputs are decisions and actions.
The regulatory assurance track operates at a cadence aligned to the regulatory reporting cycle and the organisation’s own assurance framework. Its membership includes the compliance and risk functions. Its outputs are evidence packs, assurance opinions, and regulatory submissions.
The interface between the two is explicit: the assurance track receives delivery information from the programme (progress, risks, changes) and provides assurance opinions back. Where the assurance opinion raises concerns that affect delivery decisions, those concerns are escalated to the delivery board as a specific agenda item, not as a general compliance update.
“The programme that tries to satisfy its regulator and its sponsor through the same governance forum will, in the end, satisfy neither.”
The Cultural Challenge
Designing the structure is the easier part. The harder challenge is cultural. In many regulated organisations, there is a deep-seated reluctance to separate assurance from delivery because it is perceived as reducing oversight. The compliance function, in particular, may resist a structure that does not give it a permanent seat at the delivery table, fearing that it will be sidelined or that delivery pressures will override compliance requirements.
This fear is understandable but misplaced. A well-designed separation actually strengthens the compliance function’s position, because it gives them a dedicated forum with dedicated time, rather than a few agenda items squeezed between delivery updates in a meeting that is already running over time. The compliance conversation is better when it is not competing for airtime with the delivery conversation.
The programme director’s role becomes critical here. They are the bridge between the two tracks, present in both, responsible for ensuring that the interface works. This requires a programme director who understands both the delivery and the regulatory dimensions — not merely as parallel obligations, but as a genuinely integrated dual mandate that must be managed with deliberate structural separation at the governance level precisely because it is integrated at the operational level.
A Practitioner’s Conclusion
The dual mandate is not going away. As regulatory environments become more demanding and transformation programmes more complex, the tension between delivery governance and regulatory governance will intensify, not diminish. The organisations that will navigate this successfully are not the ones that try harder to make a single governance structure serve both purposes. They are the ones that acknowledge the structural impossibility, design for it deliberately, and invest in the interfaces that keep the two tracks aligned without conflating them.
This is not about creating more governance. It is about creating governance that is honest about what it is trying to do.