Sprggun

Mobile Navigation Menu

Governance done badly: what most businesses build, and what it takes to be effective.

12 August 2026

Emma Di iorio | CEO & Co-founder, Spriggun

Governance is business. It is either embedded in how a business manages its data, AI and cyber security, or it is corporate decoration. The flagship piece in this series set out five elements that tell you which one you have, each more demanding than it reads.

  1. Ownership. A named executive owns the work.
  2. A funded roadmap. Board-approved, covering data, technology, AI and cyber security.
  3. Governance as business. Built into the strategic decisions the business is making.
  4. Policies and thresholds that fit. Tailored to the realities of the company.
  5. Fluency with limits. Capability across the workforce, inside limits leadership has set.

These have always applied to data privacy, data governance and cyber security. AI has not changed the principles; it has changed the urgency and the scale, running on the data the business already holds, through the systems it already has, at a speed that makes weaknesses visible which were previously tolerable. Data, technology, cyber and AI are deeply interconnected; a failure in one is routinely a failure in all, carrying consequences across the business, its technology estate and its regulatory position.

Few businesses have all five, and in rapidly developing areas gaps are expected. What boards, general counsel and technology leaders must not assume is that the elements they do have were properly scoped and implemented at the time, let alone that they remain fit for purpose now. A badly scoped element is worse than an acknowledged gap. A policy that does not reflect how the business operates is disclosable to a regulator, a buyer or the opposing side in a dispute; a record of what the business knew it should do and failed to execute. An executive appointed without the expertise, time or standing to do the job carries personal exposure across multiple regulatory regimes, with no ability to discharge what the appointment requires.

1. Ownership: a named executive owns the work

This has to be a senior executive who actively drives data, AI and cyber governance as a core mandate. Their role is to set the strategic direction, approve use cases, and carry ultimate accountability; committing the business to a position it can confidently defend under intense scrutiny. That takes a dedicated budget line, sufficient standing that decisions hold once taken through the right channels, and a hybrid skill set: a pure technologist will build capability the business cannot govern; and a pure lawyer will govern capability the business cannot build. The role also requires someone who can work across the business, building the cross-functional relationships that ensure results are delivered, because this work depends on functions the executive does not directly control.

Allocating responsibility without budget or authority delegates blame, not control. Capable leaders are right to refuse such roles.

2. A funded, board-approved roadmap

A roadmap starts from a Know Your Data and Know Your AI baseline (Spriggun's KYD and KYAI): what the business holds, where it came from, who has access, what can lawfully be done with it, and what the AI already touches. That baseline is the foundation; without it, the roadmap is a set of intentions with no evidence underneath.

From there, the roadmap turns the baseline into a plan that covers the full scope: not just AI, but the privacy remediation, data quality, technology and cyber posture that have to be in place across use cases. Which priorities to pursue and in what order, given what the data can actually support; which the data is not yet ready for, and what has to happen before it is; what the dependencies are across functions; what is funded and by whom. It is the instrument the business runs against, revisited as conditions change, not a document written once and filed. To achieve this, active engagement is needed from functions, as well as the responsible executive and board, at their respective levels.

3. Governance as business

Data, AI and cyber governance belongs in the boardroom, with the same weight as the decisions the business makes on markets, pricing and hiring. Settled once at the top, it sets the direction everything downstream runs against: the use case that fits is approved without ceremony; the one that does not does not proceed. Enabling trust is now largely accepted as a competitive differentiator, but to be effective, this must be embedded, not trust-washing.

Where governance is added after a decision has already been taken, the people responsible are left defending a position the business never formally set, on data nobody has fully assessed, for a commitment somebody has already made to the market. That is not governance failing; it is governance being handed a job that belongs with the executive and the board.

4. Policies and thresholds that reflect the company

A policy records what has been governed. It sets out what the business will and will not do across its data, technology and cyber security, and what staff should do as a result. Thresholds sit inside it, or in the procedures beneath it, and they are the lines that turn a policy into something someone can act on.

Setting those lines requires the board to have formed a high-level view of the business it is protecting: the sector, the customers and regulators, the data held, the risk it will carry. The detailed work sits with the executive and the teams beneath them, but the direction has to come from the top. Without that clarity, individuals across the business take different approaches: some over-governing, blocking use cases the business needs; others under-governing, exposing it to risks nobody has weighed. The business ends up in the wrong position either way. Where leadership has done this work, it is in a position to unlock use cases and enable trust; where it has not, every function is guessing independently, and the guesses will not be consistent. Agentic tools will always outrun a drafting cycle, which is no excuse for poorly thought-out policies. These should, as far as practical, set out effective safeguards, guardrails and clarity, with regular review built in from the start.

5. Fluency, inside a defined playground

Fluency is judgement at the point of use, specific to each role, and built now alongside real and ongoing change management; not bolted on at deployment when it is too late to change anything. It requires genuine upskilling across the whole organisation, not merely annual training: every function developing the capability to exercise judgement, recognise when something is beyond their remit, and know when a call has to be passed up. An organisation is only as strong as its least equipped team, and the weakest link is usually the one furthest from the technology and business conversations, working in a silo, unable to see the full picture.

A playground with visible edges lets people experiment safely inside them, without asking permission every time. However, building this playground is an all-company matter. People need to be told, as honestly as possible, what this technology means for the future of their roles. Fear around AI displacement is widespread and entirely reasonable. Left in the dark, people freeze, and the expensive seats the business pays for sit unused. Alternatively, under pressure to perform, they improvise, using unapproved tools and untraced data; the shadow AI that governance exists to prevent.

Why getting the foundations right once changes everything

The five elements rely entirely on one another, and the ones that look easiest to build are the most likely to fail. The executive and the roadmap are stuck in a classic deadlock: the executive cannot act without a roadmap to run against, and the roadmap cannot exist until the executive secures the budget and authority to build it. Neither comes first cleanly, so somebody has to make the first move with less than they need.

Without the executive and the roadmap firmly in place, the rest of the strategy collapses. Governance cannot sit inside strategic decisions if leadership has not set a direction. Policies cannot reflect realities the business has not assessed. Staff cannot use these tools confidently if nobody has set the boundaries.

Most businesses have seen no return on their data and AI investment because they have skipped this foundational work. Doing the foundations once, properly, is slower at the start. It is also the only way to make everything that follows sustainable: the next use case, the next audit, the next deal handled from a position of strength rather than a blank page.

Where to start

The governance tooling on the market assumes the strategic decisions have already been taken, and sells the administration of them. The order matters: find out what the business actually holds; work out what has to happen in what order; set the limits that follow; build fluency as the work progresses. Most businesses start with whatever is easiest to produce, which is exactly why what they end up with does not stand up to scrutiny from clients, consumers, investors or regulators.

A single month of focused effort, backed by real leadership commitment, will establish the true size of the problem. The remediation that follows is longer, and worth planning honestly rather than promising away. What that month produces is the one thing no vendor can supply: a clear, settled view of what the business holds, what it will do with it, and who is accountable.

How you take that first step depends on your current setup.

  • If you have the leverage, equip the executive. Put the owner at executive level, not adjacent to it, with the budget and time to do the job properly. Without this the appointment will fail, and the failure will be misread as evidence the work was not worth doing.
  • If there is no executive who is accountable and actively owning the area, get on the board's agenda. Whoever is currently fielding the hard questions, whether the general counsel, the CTO or the chief data officer, needs to present the high-level reality: what the business holds, where the exposure sits, and what falling behind costs commercially, with a funding request attached to scoping the problem properly.

Both paths lead to the same destination: sizing the problem and solutions across every function, to enable functional heads, delivery teams and leadership to operate from a single, shared reality. The output must actively shape your roadmap, rather than sitting forgotten in a report. This does not just isolate risk; it uncovers hidden operational efficiencies, establishes good governance as a tool for speed, and builds the regulatory readiness needed to act with confidence.

The best move is simply to take the first step.


Emma Di Iorio is Co-Founder and CEO of Spriggun, a UK-based RegTech and AI governance advisory firm. A qualified solicitor with senior in-house and advisory experience, she writes and speaks internationally on AI, data, privacy, and web compliance.