The Governance Maturity Trap: Why More Process Buys Less Decision
A process can be audited; a judgement can only be trusted — and the maturity ladder is built almost entirely from the things that can be audited.
Executive Summary
For fifteen years the maturity model has been the organising idea of transformation governance. Borrowed from software engineering and generalised outward into project, programme and portfolio management, it offers a ladder any organisation can climb: from the initial and ad hoc, through the repeatable and the defined, to the managed and at last the optimising. The promise is intuitive, and at the lower rungs it is largely true — a great deal of avoidable failure comes from having no method at all, and the model cures that. This essay argues that the same idea conceals a trap. A maturity assessment measures the presence, consistency and documentation of process, and then quietly equates that with the quality of governance. But governance is not process. It is the capacity to make good decisions under uncertainty and to own them afterwards. The two diverge; and past a certain height on the ladder they pull apart, so that each further increment of “maturity” tends to buy more procedure and less decision. The defender’s case is strong and I want to take it seriously before answering it. What is harder to explain is why the trap persists among people who can plainly see it — and that is the real subject here: the assessment incentives, the auditability of the present control climate, the self-justifying logic of the delivery office, and the plain asymmetry that a process can be shown to a reviewer while a judgement cannot. I close by asking what maturity would look like if we scored it in decisions rather than documents.
The Board That Reviewed Everything and Decided Nothing
Picture a programme board on the third Thursday of the month. The pack runs to forty-odd pages and it arrived, as required, five working days in advance. Every template is complete: the highlight report, the risk and issue logs with their movement arrows, the benefits tracker, the dependency map, the change register, the resource heat-map. The overall status is green. The programme was assessed last quarter at level three and is working towards level four. By every visible measure this is a well-governed programme.
And yet the one thing that needed to be decided that morning — whether to keep funding a workstream that had missed three consecutive milestones and whose sponsor had gone quiet — was not decided. It was noted. It was assigned an owner and a date. It was, in the language of the minutes, “to be reviewed at the next stage gate.” The gate duly arrived six weeks later, and the workstream passed it, because the gate’s criteria asked whether the documentation was complete and the process had been followed, and it had. The workstream was eventually closed nine months and a substantial sum later, when it could no longer be carried. Nobody on that board was negligent. Every one of them was doing exactly what the process asked of them.
I have sat through a version of that morning more times than I can count, and the striking thing is never incompetence. It is how much governance is visibly happening, and how little deciding. In one composite I keep returning to, a monthly board reviewed forty-two discrete artefacts and made, by any honest accounting, a single binding decision — and that decision was to approve the minutes of the previous meeting. The other forty-one items were received, noted, tracked and rolled forward. The board was mature. It was also, in the sense that matters, inert.
The Promise of the Ladder
It is worth remembering why the maturity model was so welcome, because the trap is baked into a genuine success. The idea came out of software engineering, where a five-level scale was used to describe how predictably an organisation could produce working systems, and it spread because it named something real: the difference between a group that reinvents its approach on every project and one that has a method it can rely on. Through the late nineties and into this decade the model was generalised — into project management, then programme management, then the portfolio — and the great national method guides grew up alongside it. The appeal was obvious to anyone who had lived through the alternative. After a decade of expensive public and private failures, “we follow a defined, repeatable process” was a reassuring thing to be able to say — to a board, to a regulator, to oneself.
The present environment has sharpened the appeal into something closer to necessity. The control climate since the accounting scandals at the start of the decade rewards demonstrable process above almost everything; an organisation implementing the new banking capital rules, or attesting to the state of its financial controls, is asked continually to evidence that things are done consistently and that someone is accountable. A maturity model answers that demand beautifully. It converts the messy question “are we any good at this?” into the tractable question “do we have these processes, and do we follow them?” — and the second question can be audited, scored, benchmarked and improved. That translation is the source of both the model’s power and its central deception.
The maturity model quietly rewrites the question “are we good at governing?” into “do we have, and follow, the processes we are supposed to have?” — and then treats a rising answer to the second as if it were a rising answer to the first.
How Process Comes to Stand In for Decision
Watch the substitution happen and it is almost mechanical. Each rung of the ladder is defined by processes that must be present and consistent. So climbing means adding process: another board, another template, another checkpoint, another approval, another report. None of these is foolish on its own; each was added to fix a real lapse. But their aggregate effect is to interpose more and more procedure between a situation and a response to it — and procedure, unlike judgement, has a cost that compounds.
Consider what a “decision” becomes at the upper rungs. By the time an item reaches the board it has been through a working group, a design authority, a change process and a pre-meeting. Its recommendation is pre-formed; the papers exist to support it; dissent has been routed into a risk log. The board’s act is no longer to decide but to ratify — to confirm that the process arrived somewhere and to lend its authority to the arrival. Ratification looks exactly like decision from the outside. It produces the same minute. But it carries none of the same weight, because no one in the room is exposing their judgement to being wrong. The judgement was diffused across a procedure precisely so that no single person would have to own it.
This is the mechanism beneath the green status report. A programme can be fully compliant, fully assessed, fully documented, and be quietly failing, because the instruments measure whether the process is being followed and are largely blind to whether the decisions taken through it are any good. A gate that has never once been failed is not evidence of a healthy portfolio; it is evidence that the gate is not a decision point at all. I have watched a stage gate operate for two years without a single project ever being stopped at it, and heard that offered — sincerely, by people I respected — as proof of delivery discipline.
The Strongest Version of the Other Case
None of this would be worth writing if the maturity model were simply wrong, and it is not. The honest essay has to make the defender’s case at full strength before answering it, because a great many serious people hold it, and hold it for good reasons.
The case runs like this. Before the discipline of a defined method, transformation was a lottery. Knowledge lived in individuals and left when they did. Every programme negotiated its own approach from scratch, which meant every programme repeated the same avoidable errors. The maturity model, and the process it brings, raises a floor. It guarantees that risks are at least logged, that dependencies are at least mapped, that a sponsor at least exists and is named, that there is a common language a new joiner can learn in a week rather than a year. It makes work legible across a portfolio, so that a centre can see thirty programmes in a comparable form rather than thirty idiosyncratic stories. And in a climate that demands accountability, it provides exactly the auditable trail that boards and regulators now require. To dismiss all of that as “process for its own sake” is the complaint of someone who has forgotten, or never saw, the chaos the process replaced.
Every clause of that is true. The floor is real, the discipline is real, and I would not return any organisation to the state that came before it. The question is not whether the process brought gains. It is what happens after the floor is built.
Why the Gains Do Not Keep Coming
The gains from process are real, but they are front-loaded, and this is the crux of the matter. The move from no method to a basic, repeatable one buys an enormous amount: it eliminates the worst and most avoidable failures. The move from a defined method to a more elaborate one buys much less, because the failures that remain are not failures of process at all. They are failures of judgement — the wrong bet, the deferred decision, the sponsor who would not confront a peer, the strategy that no template can supply. Adding process cannot touch those, because they were never process problems in the first place. Yet the ladder can only offer more process, so more process is what gets added, and the organisation keeps climbing while the thing that actually limits it goes unaddressed.
Past the middle rungs, then, the curve inverts. Each further increment of documented, consistent process now consumes more attention, more senior time, more of the calendar — while adding progressively less to the quality of outcomes and, beyond a point, actively subtracting from it. It subtracts because attention is finite. The hours a leadership team spends servicing the governance apparatus — assembling packs, attending boards, maintaining the artefacts an assessment will inspect — are hours not spent on the two or three decisions that will actually determine whether the transformation succeeds. The apparatus does not merely fail to help; it crowds out the very judgement it was built to support.
| Governance as process maturity | Governance as decision maturity |
|---|---|
| Measures the presence and consistency of process | Measures the quality and ownership of decisions |
| Success looks like a complete, compliant pack | Success looks like fewer, better, owned decisions |
| A gate that is always passed reads as “discipline” | A gate that is never failed is a gate that does not work |
| Diffuses accountability across a procedure | Concentrates accountability in a named person |
| Optimises for what an auditor can see | Optimises for what a customer eventually feels |
| Improves by adding process | Improves by removing what does not aid a decision |
The distinction the table draws is the whole argument in miniature. We have two different things and a single word for both. When we say an organisation’s governance has “matured”, we almost always mean the left-hand column has advanced. We rarely check the right-hand one, because it is so much harder to see.
Why the Trap Persists
If the trap were merely an intellectual error it would have been corrected long ago; plenty of experienced people can describe it exactly as I just have. It persists because a set of structural forces holds it in place, and each of those forces is, taken on its own, entirely rational.
- The assessment measures process, so process is what improves. An organisation optimises what it is scored on. A maturity assessment inspects whether processes exist and are followed; it cannot inspect whether the decisions taken were wise, because wisdom leaves no artefact. So the improvement effort flows, sensibly, towards the things the assessment can see — and the score rises while the substance may not move at all. What gets measured gets managed, and here what gets measured is the paperwork of governance rather than its purpose.
- The present control climate rewards auditability above judgement. In an era of financial-control attestation and new regulatory capital regimes, the ability to evidence that a decision followed due process has become more valuable, institutionally, than the decision being right. A defensible process that leads to a poor outcome is survivable; a sound instinct that skipped a step is not. Rational people respond accordingly, and build ever more process to stand behind.
- The delivery office justifies itself by producing process. Once a central programme or portfolio office exists, it must demonstrate its worth, and the worth it can most easily demonstrate is more method: new templates, new standards, a higher assessed level next year. An office is rarely thanked for removing a control. Its incentives point in one direction only — upward on the ladder — whether or not the organisation needs the next rung.
- Process is a shelter from personal exposure. This is the quietest force and the strongest. Making a real decision under uncertainty means owning it when it turns out wrong. A thick procedure lets responsibility be shared until it belongs to no one — the working group recommended, the design authority endorsed, the board ratified, the gate passed. Everyone acted correctly and no one decided. In an unforgiving environment, that diffusion is not a flaw people tolerate; it is a feature they seek out.
- Good judgement is invisible and easy to undervalue. A decision that quietly prevents a disaster leaves no trace — the disaster simply never happens — while a completed governance pack is tangible, countable and impressive. We systematically over-reward the visible artefact and under-reward the invisible judgement, and so we keep investing in the former.
Notice that not one of these forces is stupidity or laziness. Each is a sensible response to a real pressure. That is precisely why the trap is so durable: it is assembled from individually reasonable choices whose sum is an organisation that governs more and more and decides less and less.
What Maturity Would Mean If We Measured Decisions
I am not arguing for a bonfire of controls; that would only rebuild the chaos the model was right to end. The floor should stay. The argument is narrower, and I think harder: that we have been measuring the wrong thing at the top of the ladder, and that a mature organisation should be recognised not by the weight of its process but by the quality of its deciding.
What would that look like in practice? It would ask different questions at the review. Not “is the pack complete?” but “what did this board actually decide this month, and who owns each decision?” Not “have we passed every gate?” but “when did a gate last change a course of action — and if it never has, why do we still hold it?” It would treat a governance body’s health as measurable by the ratio of decisions made to items merely noted, and would grow suspicious of any board whose ratio approached zero however green its reports. It would regard the removal of a control that no longer aids a decision as a sign of maturity rather than a lapse in discipline — the way an experienced hand knows which steps can be skipped precisely because they have mastered all of them. And it would prize the named owner over the diffuse procedure, because a decision that belongs to someone is a decision that can be got right and, when it must be, answered for.
There is a test I have come to trust, and it is embarrassingly simple. Sit at the back of a governance meeting and count two things: how many decisions are genuinely taken in the room, and how many items are received, noted and rolled forward. A healthy body decides more than it defers. A mature-on-paper, inert-in-practice body defers almost everything and calls the deferral governance. That ratio will tell you, faster than any formal assessment, whether you are looking at a decision-making engine or a very well-documented way of avoiding decisions.
“A gate that is never failed is not a sign of discipline; it is a decision point that has been quietly demoted to a formality, and it should be either mended or abolished.”
The deepest reason the maturity model misleads is an asymmetry it can do nothing about. A process can be audited; a judgement can only be trusted — and the maturity ladder is built almost entirely from the things that can be audited. That is why it drifts, over time and under pressure, towards the auditable and away from the essential. It is not that the people climbing it are fooled. It is that the instrument points at what it can measure, and what it can measure is not the thing that matters most. The organisations that will govern transformation well in the years ahead are not the ones that reach the top of the ladder. They are the ones that remember, at every rung, that the whole point of the process was only ever to help someone make a better decision — and that are willing to strip away anything, however mature it looks, that has quietly stopped doing so.