M · Guidelines

Guideline: Keeping Governance Proportionate

Maximum governance effectiveness with the minimum necessary friction — which means deciding what you are not going to do, and defending that decision.

The failure this prevents

A governance framework that is too heavy is not safer than one that is too light; it is less safe, because teams route around it and the systems you most need to see become the ones you cannot. The framework treats this as a design constraint rather than an afterthought: two bodies rather than eight, tier-scaled evidence, pre-approved patterns, and automated evidence collection wherever a control can be machine-checked.

The failure mode is gradual. Each addition is individually reasonable — a new field after an incident, a second reviewer after a near miss, a questionnaire after an audit — and the aggregate is a process nobody completes honestly.

Tier 1 — self-certify canvas, classification, pattern conformance, named owner. No meeting. Tier 2 — light assurance plus lineage, assurance summary, authorization record, one review point. Tier 3 — independent challenge plus countersignature, control matrix, board authorization, monitoring. Tier 4 — preventive control plus kill-switch approval, dual authorization, shortest drift windows.
Evidence depth is the dial, not the gate structure. Every system passes the same five gates; what changes is what each gate consumes. A process that asks Tier 4 questions of Tier 1 systems has disabled the only mechanism the framework has for staying affordable.

[Practice recommendation] Everything on this page is advice from this documentation rather than a requirement of IRGF. Disagreeing with it does not put you outside the framework; all practice recommendations are collected in Appendix B.

The friction budget

Decide, in advance, roughly how much time governance may consume per system per year at each tier, and treat that as a budget rather than an aspiration. Numbers below are a starting position to adjust against your own data, not a calibrated finding.

Tier Indicative annual governance effort What that buys
Tier 1Under half a dayCanvas, classification, pattern self-certification, owner named. No meetings.
Tier 2One to two daysThe above plus lineage, a light assurance summary, an authorization record, and one review point.
Tier 3Five to ten daysIndependent countersignature, full assurance, control matrix, board authorization, monitoring commitments, annual re-score.
Tier 4Fifteen days or moreThe above plus preventive controls, kill-switch approval, dual authorization, and the shortest drift windows.

If the real numbers are far above this, the process is buying something — find out what, and whether it is worth it. If they are far below at Tier 3–4, the tier is nominal.

What actually scales

  • Patterns. Pre-approved architectures that permit self-certification are the highest-leverage mechanism in the framework. Track coverage: the proportion of new systems conforming to a pattern is the best proxy for whether the library reduces load.
  • Automated evidence. Any control that can be machine-checked should emit its own evidence. Human-assembled evidence packs are where governance cost concentrates.
  • Tier-scaled fields. Templates that ask Tier 4 questions of Tier 1 systems teach people to fill forms rather than answer them.
  • One inventory. Every additional register doubles reconciliation work and halves trust in both.
  • Deciding not to govern something. Written down, with the reason. This is the cheapest and least used mechanism available.

What to cut first

When the process is too heavy, these are the reductions that lose the least:

  1. Fields that no decision depends on. Apply the framework's own rationalization test: what decision becomes impossible or materially weaker without this?
  2. Reviews of systems that conform to a pattern. That is what the pattern is for.
  3. Meetings that ratify decisions already made in the record.
  4. Hand-maintained summaries. Compile or delete.
  5. Questionnaires whose answers nobody has ever acted on. Check the last twelve months before defending one.

And the things not to cut, because they carry most of the framework's value: the independent countersignature at Tier 3–4, the named accountable owner, the authorized configuration record, boundary enforcement for agents, and the override-rate instrumentation on reviewed decision systems.

Telling over- from under-governance

Symptom Usually means Rather than
Teams ask forgiveness rather than permissionOver-governance: the path is slower than the risk warrantsA culture problem
Records are complete and uniformly blandOver-governance: fields are being completed, not answeredMature process
Gate decisions are never anything but approveEither: the gate is a formality, or the work upstream is genuinely goodCheck by reading three rejected-in-practice cases; if there are none, it is a formality
Systems reach production unclassifiedUnder-governance at intake, usually routing on contract valueNon-compliance
Drift alerts are ignoredUnder-governance in routing: alerts have no ownerAlert fatigue as an inevitability
Every incident adds a field and none removes oneThe process has no owner for removalContinuous improvement

Start smaller than feels responsible

The minimum viable framework exists precisely for this (Chapter 27). A mid-sized organization implementing classification, a named owner per system, one authorization record and one drift signal is in a materially better position than one that spent a year designing the full apparatus and has not yet classified anything.

Write down what you are not doing this year, and why. Revisit it annually. A governance function that cannot say what it has deliberately left undone is not making choices — it is accumulating them.

How to tell it is working

Every practice needs a failure signal, or it is a belief. These are the ones that show this guideline has stopped operating in your organization.

Signal What it means What to do
Cycle time from intake to G2 exceeds a few weeks at Tier 1–2The light path is not actually lightMove Tier 1–2 to pattern self-certification and measure again
Pattern coverage is fallingThe library is not keeping up with what teams buildAdd patterns from what is actually being built, not from what should be
Governance effort per system is rising year on yearAdditions are outpacing removalsGive someone ownership of removal and review template length annually
Shadow systems keep appearingTeams are routing around the processAsk them why, then fix that, before adding a detection control
Every field in the template is mandatoryTier scaling has been lostRestore the tier markers; a Tier 1 record should fit on one page