Governance architecture and Independent Assurance
I stand at the boundary between your specialists and your leadership, translating technical and operational risk into something you can make a decision on, and then tell you what I think.
Your specialists know what they are doing. So do you. What nobody at your level has is the days it would take to personally interrogate what you are being asked to approve. That gap is where the accountability now sits.

"Technical implementation can be delegated.
Executive responsibility cannot."
JONATHAN MAIN
GOVERNANCE ARCHITECT
25+ years across 19 industries and
35 countries.
ISO 9001, 14001, 27001, 42001, 45001
& 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE
NIS2 Directive Trained Professional
Senior quality, audit and governance roles at

Audit programmes delivered through these roles have covered utilities, automotive, aerospace, rail, mining, chemicals, electronics, insurance, telecoms and government across thirty-five countries.


.png)


WHAT CHANGED
Liability used to attach to companies.
Now It Attaches To People
This is why a governance conversation that could be deferred for a decade can no longer be deferred at all.
⏹ ⏹ Domain by domain, the same shift, and the same gap.
Health & safety
Long established
Personal duties on directors and officers
Supply chain
In force
Due diligence obligations reaching the company's leadership
Sustainability
Reporting and diligence duties, phasing in by size
Phasing in
Information security
The NIS2 Cybersecurity Directive places approval, oversight and training on the management body itself
In force · enforcement beginning
Product security
Next
Obligations reaching manufacturers of connected products
Artificial intelligence
Timeline in flux
Governance duties for high-risk systems
THE PATTERN
Most of the work can be handed to someone.
One Layer Cannot
Every management-system domain has the same structure. A specialist function speaking a technical language, and a leadership body carrying accountability it has no way to personally evaluate.
Not a question of capability. A question of time. Interrogating the request properly would take days, and nobody at that level has days. So it is either declined, and the exposure stays exactly where it was, or it is approved on trust.
Approving on trust is the sensible thing to do. You hired those people for a reason. But in the record, an approval given on trust and an approval given on evidence look identical. The difference only appears when someone asks you to show which one it was.
.png)
Leadership layer
APPROVE · OVERSEE
TRAIN · EVIDENCE
.png)
Specialist layer
SYSTEMS · CONTROLS
DETECTION · RESPONSE
CAN BE DELEGATED
TRANSLATION
JUDGEMENT
EVIDENCE
USUALLY UNDER-RESOURCED
How this practice works
I build governance,
Or I Independently Verify It
Never both for the same system.
Build
Structure built around how the business actually runs
Oversight structures, decision rights, delegated authority and assurance mechanisms, shaped to fit the organisation as it operates today, then embedded into daily decision-making.
VERIFY
An independent opinion you can put in front of anyone
Testing whether governance is demonstrable rather than assumed, against the statute or the standard, never against a framework of mine. Findings written as decisions not yet put to leadership, not as failures.
Two things one practitioner should never do for the same system. So I don't.
Where I have seen it
The same gap,
Accross industries
It appears wherever a technical function reports to a leadership body with no time to test what it is being told. Different regulator, different vocabulary, same structure underneath.
6
Domains where it occurs
Quality, environment, occupational health and safety, information security, AI and energy. Lead Auditor in the six standards with the widest range.
19
Industries
In senior operating roles and global audit programmes. Enough repetitions of the same pattern to know it is structural, not particular to one sector.
35
Countries
Twenty-five years of building management systems, running audit programmes across regions, and sitting at the table that has to sign.
THE NINETEEN Industries
Energy ▪ Water ▪ Health ▪ Finance ▪ Telecoms ▪ Public sector ▪ Logistics ▪ Automotive ▪ Aerospace ▪ Machinery ▪ Electronics ▪ Medical devices ▪ Chemicals ▪ Food & drink ▪ Mining ▪ Retail & FMCG ▪ Media ▪ Professional services ▪ Certification
IN A Client's words
"We were confident in our technical implementation. What we didn't have was independent confirmation that leadership could demonstrate its own side of it. That's what this gave us, something we could put in front of our leadership with confidence, not just our security team."
VP & CTO · Global leader in smart grid technology for utilities
What building it looks like
Group governance,
Across Thirty Countries
A global bulk logistics group, working inside the business rather than reporting on it from a distance. I was still there when the audits came, which is not usually how this works. Quality, environment, safety and energy, brought into one way of working across Europe, the Americas, the Middle East and Asia-Pacific.
What leadership ended up with was not a document set. It was review formats they ran themselves and reporting they could act on. I did not build a system that worked because I was there. I built one that kept working when I was not.
ISO 9001, 14001, 45001 and 50001. sixteen entites were auditied for certification, and nineteen entites undertook surveillance audits in that period.
How long IT TOOK
22
Months. All of this happened inside that window.
independently checked
0
No Major findings when the certification body audited thirty-five entities.
How far it reached
63
Entities in thirty countries, across four standards.
What happened after
Bronze → Gold
EcoVadis rating rose during my involvement. Still Gold a year after I left.
THE METHOD
Governance is not implemented.
It Is Built
Four stages. An engagement sits in one or more of them but never all four.
Ascertain
Architect
Adopt
Assure
An enterprise-wide look at how oversight actually operates: informal controls, founder-dependent decisions, single points of failure, exposure not yet visible internally.
Oversight and leadership structures, decision rights, delegated authority, risk architecture and assurance mechanisms, designed around commercial execution and culture.
Leadership facilitation, process integration and coaching through the shift from control to oversight. The objective is not a completed document set.
Testing whether governance survived contact with operational reality, identifying residual exposure, and giving leadership ongoing visibility rather than periodic reassurance.
Clarity replaces uncertainty.
Structure replaces reliance on individuals.
Governance becomes operational.
Confidence replaces contingency.
Where you'd start
Three ways in.
Which One Is You?
An answer that is not your own word for it.
Independent assurance
A customer, an insurer or a regulator has asked. Nearly every supplier answers with a self-declaration, and procurement discounts those because everyone's says yes. An independent report is the only response in the pile that is not the supplier describing itself. For cybersecurity, that is the NIS2 Executive Assurance Assessment.
