You Do Not Have Governance, You Have Documentation

Ask most organizations with an IG program if they have governance over their information, and the answer is yes. There’s a policy. There’s a retention schedule. There’s a framework, usually well written, sometimes benchmarked against a recognized standard, occasionally reviewed by outside counsel. By any reasonable definition of “having governance in place,” the box gets checked.  None of that is governance. It’s documentation. Governance is what happens after the document is written, when a person somewhere in the organization makes a decision about a piece of information and that decision matches what the document says should happen. Too often, it doesn’t, and most organizations don’t find out until something forces the question.  The current state  Gartner estimates that 80 percent of organizations trying to scale digital business will fail because they lack a modern, execution-led approach to data and analytics governance, not because they lack policies. Separately, surveys of data management professionals consistently find that even among organizations with a formal governance program already in place, data quality and governance issues remain among their biggest ongoing challenges. The pattern is consistent across the industry: the documentation exists almost everywhere. The execution not so much.  That gap isn’t really about effort. Most governance teams work hard, and most policies are reasonably well constructed. The problem is that a policy describes an intention, and intentions don’t enforce themselves. A retention schedule says how long a category of content should be kept. It doesn’t move that content into the right folder, apply the right label, or delete it on schedule. A person, or a system acting on that person’s behalf, must do that, every time, across every system where the content lives.  The observation  This is the distinction that gets lost in most governance conversations: a document is a statement of what should happen. Governance is the process that executes what’s in the documents and preserves the evidence of what happened. Those are not the same thing and treating them as interchangeable is how organizations end up confident about their governance posture right up until an audit, a breach, or a discovery request asks them to prove it.  The confidence is usually genuine, which is what makes the gap dangerous. Leadership reviews the policy, sees that it’s thorough, and reasonably concludes the organization is in good shape. Nobody in that review is lying or cutting corners. They’re evaluating the wrong artifact. A well-written policy tells you what good behavior looks like. It tells you nothing about whether that behavior is occurring across the thousands of daily decisions people make about where information goes, who has access to it, how long it stays, and when it gets deleted.  Why this happens  Documentation is easier to produce than execution, and it’s easier to measure. A policy has a clear finish line: it gets drafted, reviewed, approved, and published. Execution doesn’t have a finish line. It’s an ongoing operational discipline that must hold up across every system, every team, and every new employee who never read the policy in the first place. Organizations naturally gravitate toward the work that can be finished and signed off on, and governance documentation fits that description far better than governance operations do.  There’s also an accountability problem underneath this. Writing the policy usually belongs to one team, records management, legal, or a governance committee. Following the policy belongs to everyone else, spread across every department, none of whom were involved in writing it and few of whom have any real incentive to prioritize it over their actual job. Nobody owns the gap between the document and the daily decision, so the gap persists.  Why this matters  The moment this gap becomes visible is rarely convenient. It shows up during litigation, when opposing counsel asks whether the retention schedule was actually followed and the honest answer is “inconsistently.” It shows up during a regulatory exam, when an examiner asks for evidence that a control was operating, not just that a policy described the control. It shows up during a breach investigation, when the organization discovers that sensitive data was sitting in a location the policy explicitly said it shouldn’t be.  In each of these cases, the organization isn’t caught because it lacked governance intentions. It’s caught because the intentions and the reality had quietly diverged, sometimes for years, without anyone measuring the distance between them. The document held up fine under review. The operation underneath it didn’t.  Common mistakes  A few habits show up repeatedly in organizations that mistake documentation for governance. The most common is treating policy approval as the finish line for a governance initiative, rather than the starting point for an operational one. A close second is measuring governance maturity by the quality of the written policy rather than by evidence of how consistently it’s been followed. A third is assuming that training people on a policy is the same as building a system that makes the right behavior the easy behavior. And a fourth is reviewing the policy on a regular cycle while never actually testing whether real-world practice still matches it.  The recommendation  Closing this gap requires treating execution as its own workstream, with its own accountability, rather than as something that automatically follows once the policy is published.  Assign explicit ownership for operational compliance, separate from ownership of the written policy. The person or team accountable for whether the retention schedule is being followed should not be the same as, or subordinate to, the team that simply drafted it.  Build measurement directly into the program. Sample actual practice against the documented policy on a regular basis, the same way an internal audit function would, rather than assuming compliance because the policy exists and training was delivered.  Where possible, move enforcement into the systems people already use, so following the policy is the default behavior rather than something an individual has to remember to do correctly every time. This is where classification, automated retention triggers, access reviews, and workflow-based controls do more good than another round of policy training.  Report on execution, not just documentation, to leadership. A governance update that only covers policy status gives leadership a false sense of where the organization stands. A governance update that includes evidence of operational compliance gives them something they can rely on.  What this looks like when it works  A mature governance program doesn’t necessarily look different on paper. It looks different in what leadership can point to when someone asks a hard question. Instead of