Governance & Compliance
Turning policy, audit, and process discipline into the invisible backbone that makes IT trustworthy.
Governance is checking whether what an organization says it does and what it actually does are the same thing. Usually they aren't, and the gap is where the incidents live.
Mine started small in 2013: password policies, backup procedures, an asset registry nobody read. By 2023 it was the Enterprise Architecture Review Process, which now gates every significant change to the IT landscape here — a document I wrote, and one that has made me unpopular at least twice.
Day to day that means ITIL change management and the Change Advisory Board; audit readiness in the boring sense, where the evidence trail exists before anyone asks for it; ISO/IEC 27000 and SOX-aligned controls; and the unglamorous authorship work — review triggers, escalation paths, documentation standards, approval gates.
The 2016 audits were genuinely uncomfortable. They were also the fastest education I've had, because an audit doesn't tell you that you're sloppy, it tells you exactly where. Everything I've written since has been an attempt to make that finding-out happen earlier, and internally, rather than in a room with someone holding a checklist.