Guideline: Keeping Governance Proportionate
Maximum governance effectiveness with the minimum necessary friction — which means deciding what you are not going to do, and defending that decision.
The failure this prevents
A governance framework that is too heavy is not safer than one that is too light; it is less safe, because teams route around it and the systems you most need to see become the ones you cannot. The framework treats this as a design constraint rather than an afterthought: two bodies rather than eight, tier-scaled evidence, pre-approved patterns, and automated evidence collection wherever a control can be machine-checked.
The failure mode is gradual. Each addition is individually reasonable — a new field after an incident, a second reviewer after a near miss, a questionnaire after an audit — and the aggregate is a process nobody completes honestly.
[Practice recommendation] Everything on this page is advice from this documentation rather than a requirement of IRGF. Disagreeing with it does not put you outside the framework; all practice recommendations are collected in Appendix B.
The friction budget
Decide, in advance, roughly how much time governance may consume per system per year at each tier, and treat that as a budget rather than an aspiration. Numbers below are a starting position to adjust against your own data, not a calibrated finding.
| Tier | Indicative annual governance effort | What that buys |
|---|---|---|
| Tier 1 | Under half a day | Canvas, classification, pattern self-certification, owner named. No meetings. |
| Tier 2 | One to two days | The above plus lineage, a light assurance summary, an authorization record, and one review point. |
| Tier 3 | Five to ten days | Independent countersignature, full assurance, control matrix, board authorization, monitoring commitments, annual re-score. |
| Tier 4 | Fifteen days or more | The above plus preventive controls, kill-switch approval, dual authorization, and the shortest drift windows. |
If the real numbers are far above this, the process is buying something — find out what, and whether it is worth it. If they are far below at Tier 3–4, the tier is nominal.
What actually scales
- Patterns. Pre-approved architectures that permit self-certification are the highest-leverage mechanism in the framework. Track coverage: the proportion of new systems conforming to a pattern is the best proxy for whether the library reduces load.
- Automated evidence. Any control that can be machine-checked should emit its own evidence. Human-assembled evidence packs are where governance cost concentrates.
- Tier-scaled fields. Templates that ask Tier 4 questions of Tier 1 systems teach people to fill forms rather than answer them.
- One inventory. Every additional register doubles reconciliation work and halves trust in both.
- Deciding not to govern something. Written down, with the reason. This is the cheapest and least used mechanism available.
What to cut first
When the process is too heavy, these are the reductions that lose the least:
- Fields that no decision depends on. Apply the framework's own rationalization test: what decision becomes impossible or materially weaker without this?
- Reviews of systems that conform to a pattern. That is what the pattern is for.
- Meetings that ratify decisions already made in the record.
- Hand-maintained summaries. Compile or delete.
- Questionnaires whose answers nobody has ever acted on. Check the last twelve months before defending one.
And the things not to cut, because they carry most of the framework's value: the independent countersignature at Tier 3–4, the named accountable owner, the authorized configuration record, boundary enforcement for agents, and the override-rate instrumentation on reviewed decision systems.
Telling over- from under-governance
| Symptom | Usually means | Rather than |
|---|---|---|
| Teams ask forgiveness rather than permission | Over-governance: the path is slower than the risk warrants | A culture problem |
| Records are complete and uniformly bland | Over-governance: fields are being completed, not answered | Mature process |
| Gate decisions are never anything but approve | Either: the gate is a formality, or the work upstream is genuinely good | Check by reading three rejected-in-practice cases; if there are none, it is a formality |
| Systems reach production unclassified | Under-governance at intake, usually routing on contract value | Non-compliance |
| Drift alerts are ignored | Under-governance in routing: alerts have no owner | Alert fatigue as an inevitability |
| Every incident adds a field and none removes one | The process has no owner for removal | Continuous improvement |
Start smaller than feels responsible
The minimum viable framework exists precisely for this (Chapter 27). A mid-sized organization implementing classification, a named owner per system, one authorization record and one drift signal is in a materially better position than one that spent a year designing the full apparatus and has not yet classified anything.
Write down what you are not doing this year, and why. Revisit it annually. A governance function that cannot say what it has deliberately left undone is not making choices — it is accumulating them.
How to tell it is working
Every practice needs a failure signal, or it is a belief. These are the ones that show this guideline has stopped operating in your organization.
| Signal | What it means | What to do |
|---|---|---|
| Cycle time from intake to G2 exceeds a few weeks at Tier 1–2 | The light path is not actually light | Move Tier 1–2 to pattern self-certification and measure again |
| Pattern coverage is falling | The library is not keeping up with what teams build | Add patterns from what is actually being built, not from what should be |
| Governance effort per system is rising year on year | Additions are outpacing removals | Give someone ownership of removal and review template length annually |
| Shadow systems keep appearing | Teams are routing around the process | Ask them why, then fix that, before adding a detection control |
| Every field in the template is mandatory | Tier scaling has been lost | Restore the tier markers; a Tier 1 record should fit on one page |