The Governance Maturity Trap — More Process, Less Decision

Essay·Giovanni Leonardi·July 2006·9 min read

The organisations with the most governance are frequently the ones least able to make a decision when it matters.

The Allure of the Maturity Model

There is a seductive logic to governance maturity models. They promise a clear progression — from ad hoc and reactive to structured and optimised — and they offer organisations a mirror in which to assess their own sophistication. The appeal is obvious: if governance can be measured on a scale, then improvement becomes a matter of climbing it. More structure. More rigour. More process. The assumption, rarely examined, is that more of these things produces better outcomes.

In my experience, the opposite is at least as common. The organisations with the most governance are frequently the ones least able to make a decision when it matters. They have escalation paths, terms of reference, approval matrices, and reporting cycles — but the decisions that would actually move a programme forward sit in a queue, waiting for a committee that meets monthly, chaired by someone who has not read the papers, attended by people whose authority to decide is ambiguous at best. The maturity model says these organisations are advanced. The evidence from the ground says they are stuck.

This is not a complaint about bureaucracy in the ordinary sense. It is an observation about a specific structural trap: the tendency for governance to evolve in ways that add process without adding — and frequently while actively removing — decision-making capacity.

How Governance Grows

Governance frameworks rarely arrive fully formed. They accumulate. A programme encounters a failure — a missed dependency, an uncontrolled scope change, a cost overrun that surprises the board — and the response is a new control. A new report. A new gate. A new committee. Each addition is rational in isolation. Each responds to a real problem. But governance growth is almost never accompanied by governance pruning. Controls are added; they are virtually never removed. The framework thickens.

The pattern I have observed across sectors and programme types is remarkably consistent:

  • The initial governance is lightweight and decision-focused. A small group of senior people meet regularly, they have the information they need, and they make calls.
  • A failure occurs — or an audit finds a gap — and new controls are layered on top. Reporting requirements increase. Additional approval stages are introduced.
  • The governance forum becomes larger, more formal, and less able to have the candid conversations that good decision-making requires.
  • Decision-making slows. Accountability fragments. The response, almost invariably, is to add further governance — another layer of oversight, another review point, another committee.
  • The organisation now has a mature governance framework that is structurally incapable of making timely decisions.

This is the maturity trap. The framework has matured, but matured into something that serves the process rather than the purpose.

The Reporting Reflex

At the heart of this trap lies a confusion between reporting and governing. Governance maturity models tend to reward completeness of reporting: dashboards, RAG statuses, exception reports, benefits tracking logs, risk registers. The assumption is that if senior leaders have comprehensive information, they will make good decisions. But comprehensive information is not the same as decision-ready information, and the act of producing it consumes enormous energy.

I have sat in governance meetings where the first forty-five minutes of an hour-long session were consumed by status reporting — a walk through every workstream, every RAG status, every risk movement — leaving fifteen minutes for the two or three genuinely difficult decisions that the programme needed resolved. The reporting was thorough. It was also, for the purposes of governance, largely useless. The people in the room did not need a comprehensive update; they needed a focused brief on the three things that required their judgement, the options available, and the consequences of each.

Governance maturity models measure the sophistication of the reporting apparatus. They almost never measure whether decisions are actually being made, or made well, or made in time.

The distinction matters because reporting and deciding require fundamentally different things. Reporting requires completeness, accuracy, and structure. Deciding requires clarity about what is at stake, confidence in the authority to act, and willingness to accept the consequences of being wrong. An organisation can have superb reporting and paralysed decision-making. Many do.

The Committee Problem

Governance maturity models also tend to reward the existence of formal structures — committees, boards, forums — without examining whether those structures are constituted to decide. The pattern that recurs is one of governance bodies that are too large, too infrequent, and too uncertain of their own authority.

Size matters because candour matters. A governance meeting of six people can have a genuine discussion about whether a programme is in trouble and what to do about it. A governance meeting of twenty cannot. The larger the group, the more performative the conversation becomes — sponsors present good news, programme managers defend their positions, and the difficult truths that governance exists to surface remain unsurfaced.

Frequency matters because programmes do not pause between meetings. A monthly governance board that encounters a critical issue in week one must either convene an extraordinary session — which the maturity model does not anticipate and the diary does not accommodate — or wait three weeks while the issue compounds. The mature framework has a schedule; the programme has a problem.

Authority matters most of all, and this is where the trap is deepest. In many organisations, the governance framework defines who attends decisions but not who makes them. A steering committee may have terms of reference that specify its purpose as “providing strategic direction and oversight” — language so broad as to be meaningless. When a concrete decision arrives — should we descope this workstream, should we delay this release, should we replace this supplier — the committee discovers that it is unclear whether it has the authority to decide, whether the decision needs to be escalated, or whether someone else has already been empowered to act. The decision is deferred. The maturity model records a functioning governance structure. The programme records another month of drift.

Why the Trap Persists

If the pattern is so visible, why does it persist? Several forces sustain it.

The first is that governance maturity is measured by process, not by outcomes. The assessment asks whether the framework exists, whether it is documented, whether it is followed. It does not ask whether it produces decisions, or whether those decisions are timely, or whether they are any good. An organisation can score highly on governance maturity while its programmes consistently miss their objectives. The measurement and the reality have parted company, but the measurement is the one that gets reported to the board.

The second is risk aversion. Every additional control exists because someone, at some point, was worried about a specific risk. Removing a control means accepting that risk, and in most organisational cultures, the person who removes a control and is subsequently proved wrong faces far greater consequences than the person who adds one and is never tested. The incentive structure overwhelmingly favours accumulation.

“The cost of adding a control is borne by the programme. The cost of not adding one is borne by the individual who chose restraint. No rational actor in that system will choose restraint.”

The third is the consulting and audit ecosystem. Governance maturity assessments are frequently conducted by external parties whose frameworks reward comprehensiveness. A recommendation to simplify governance — to remove a committee, eliminate a report, reduce an approval chain — is rare because it looks like a recommendation to reduce rigour. The professional incentive is to recommend more, not less.

The fourth, and perhaps most fundamental, is that governance complexity serves as a substitute for trust. In organisations where senior leaders do not trust programme teams to make sound decisions, the response is to require those decisions to be escalated, reviewed, and approved. Each escalation point is a trust deficit made structural. The maturity model formalises the deficit and calls it rigour.

What Effective Governance Actually Looks Like

The programmes I have seen governed well share characteristics that maturity models tend not to measure. They are distinguished not by the sophistication of their frameworks but by the clarity of their decision-making.

  • Authority is explicit and specific. Every governance body knows precisely which decisions it owns, which it advises on, and which belong elsewhere. The terms of reference name the decision types, not just the purpose.
  • Meetings are structured around decisions, not reports. The standing agenda begins with the decisions required this period, not the status of every workstream. Reporting exists to inform those decisions, not as an end in itself.
  • The group is small enough for candour. Six to eight people who can speak plainly about what is going wrong, rather than twenty who perform confidence.
  • Frequency matches pace. Governance meets as often as the programme requires decisions, not on a fixed calendar that bears no relation to the rhythm of delivery.
  • Controls are reviewed and pruned. At least annually, someone asks: is this gate still necessary? Is this report still read? Is this approval stage adding value, or is it adding delay?

None of these characteristics require a maturity model. They require, instead, a clear-eyed understanding of what governance is for — which is to ensure that the right decisions are made, by the right people, at the right time, with adequate information. Everything else is overhead.

The Maturity Model We Need

This is not an argument against governance, nor against the idea that governance can improve over time. It is an argument against the specific way that improvement is currently conceived — as a progression from less process to more process, from informal to formal, from lightweight to comprehensive.

A more honest maturity model would measure different things entirely. It would ask:

  1. How many decisions did the governance framework make this quarter, and what was the average time from issue identification to resolution?
  2. How many decisions were deferred, and why?
  3. What proportion of governance meeting time was spent on decisions versus reporting?
  4. How many controls were removed or simplified in the last year?
  5. Can every governance body articulate, specifically, which decisions it owns?

These are harder questions than “does a steering committee exist” or “is there a risk register.” They are also more useful questions. An organisation that can answer them well is governing effectively, regardless of how its framework scores on a conventional maturity assessment.

The trap is real, and it is widespread. The organisations that escape it are not the ones that build more elaborate governance. They are the ones that remember, persistently and sometimes stubbornly, that the purpose of governance is to decide — and that anything which interferes with that purpose, however sophisticated it appears, is not maturity but its opposite.


More from Transformation