Enterprise Architecture
2026-07-05
01Architecture that shapes decisions
Enterprise architecture has an image problem it partly earned. The version that earns its place sits close to where capital is allocated. Architecture that only records decisions is overhead. Architecture that shapes them is one of the cheapest forms of risk management an organization has.
Governance at the point of decision
Most AI governance failures are not failures of policy. The failure is that the policy has no contact with the moment a decision actually gets made: the model that ships, the dataset quietly reused, or the exception waved through because a deadline is closer than the risk.
Transformation Governance
2026-07-07
03Motion is not transformation
There is a version of transformation that is mostly motion: new committees, refreshed roadmaps, rebranded program offices, and very little change. The tell is simple: ask who now makes a decision differently than they did last year.
Data Governance
2026-07-08
04Classification is not the value
Most data governance programs start by counting. The map matters, but it is not the point. Data governance earns its cost the moment it changes what someone is allowed to do with data.
Decision Rights
2026-07-09
05The org chart is not the decision system
Every reorganization redraws boxes and lines. Almost none of them redraw the decisions. If you want to know how an organization really works, do not ask for the chart. Ask who has to say yes.
Compliance as repeatable capability
Compliance is usually run as a series of deadlines. The organizations that cope treat the recurring parts as capability: knowing what data they hold, who is accountable for it, and how a control maps to evidence.
Technology Governance
2026-07-11
07The real cost of software
The price that gets scrutinized is the license. The price that actually hurts shows up in the second year: integration, people, workflows bent to fit it, and the quiet tax of not being able to leave.
Approval steps can become distrust
Under pressure, most managers add a step. Each step is reasonable on its own. Together they pull every decision back up until the manager becomes the bottleneck they were trying to avoid.
Ownership needs a name
Ask who owns a critical dataset and the confident answer is often 'the business.' Which is another way of saying no one. Accountability without a name is not accountability.
You cannot govern what you push out of sight
The first instinct with AI tools is often to ban them. What it actually does is move usage out of sight. Prohibition without an alternative does not remove the risk. It removes visibility of it.
Enterprise Architecture
2026-07-15
11The value of what never broke
Most of what enterprise architecture is credited with is visible. Most of what it is actually worth is invisible: the duplicate platform not bought, the lock-in avoided, the local fix stopped before it became legacy.
Risk Management
2026-07-16
12A calm risk review can be the risk
A risk register that looks the same this quarter as last is usually presented as stability. More often it is neglect. If the risk review is calm every time, the risk is not the thing on the register. It is the review.
Transformation Governance
2026-07-17
13A pilot should be allowed to say no
Organizations are good at starting pilots and bad at ending them. A pilot is only useful if it can produce a no. Without that, a pilot is not a test. It is a demonstration with a budget.
Decision Governance
2026-07-18
14Tell the doors apart
Some decisions can be unwound in a week. Some cannot be unwound at all. Most governance treats every decision as equally dangerous. The skill is telling the doors apart and spending caution where it cannot be refunded.
Compliance maturity is operating proof
Compliance often looks mature because the documents exist. The harder question is whether the organization can prove the control is operating when nobody is preparing for an audit.
Risk reports should ask for decisions
Most risk reports are written as if the decision has already happened elsewhere. A useful risk report makes the ask visible: accept, fund, escalate, pause, redesign, or remove the exposure.
Compliance Evidence
2026-07-23
17Weak evidence turns review into archaeology
Evidence fails in quiet ways. The file exists, but nobody owns it. The screenshot is current, but the control changed. Executives need evidence that is traceable, owned, fresh, and connected to a real obligation.
Regulatory Readiness
2026-07-24
18Stop rebuilding compliance from scratch
The most expensive compliance programs are rebuilt from scratch every time a new requirement arrives. The recurring parts should become capability: obligations, controls, owners, evidence, issues, and reporting.
Control Ownership
2026-07-25
19A control without an owner
A control without an owner is a hope with formatting. Good GRC is often less about adding controls and more about making ownership impossible to avoid.
Board Reporting
2026-07-26
20Boards do not need raw control inventories
Boards need to know which obligations are material, which controls are failing or unproven, which risks exceed tolerance, which owners are accountable, and what decision is being requested.
GRC Operating Model
2026-07-27
21The platform cannot invent the discipline
GRC platforms do not fix unclear governance. They expose it faster. Before buying the system, design the discipline: what must be proven, who owns it, how evidence is judged, and when exceptions escalate.