top of page

Governance architecture and Independent Assurance

I stand at the boundary between your specialists and your leadership, translating technical and operational risk into something you can make a decision on, and then tell you what I think.

Your specialists know what they are doing. So do you. What nobody at your level has is the days it would take to personally interrogate what you are being asked to approve. That gap is where the accountability now sits.

"Technical implementation can be delegated.

Executive responsibility cannot."

JONATHAN MAIN
GOVERNANCE ARCHITECT

25+ years across 19 industries and

35 countries.
ISO 9001, 14001, 27001, 42001, 45001

& 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE

NIS2 Directive Trained Professional

Senior quality, audit and governance roles at

Audit programmes delivered through these roles have covered utilities, automotive, aerospace, rail, mining, chemicals, electronics, insurance, telecoms and government across thirty-five countries.

Untitled design (6).png

WHAT CHANGED

Liability used to attach to companies.
Now It Attaches To People

This is why a governance conversation that could be deferred for a decade can no longer be deferred at all.

⏹     ⏹      Domain by domain, the same shift, and the same gap.

Health & safety

Long established

Personal duties on directors and officers

Supply chain

In force

Due diligence obligations reaching the company's leadership

Sustainability

Reporting and diligence duties, phasing in by size

Phasing in

Information security

The NIS2 Cybersecurity Directive places approval, oversight and training on the management body itself

In force · enforcement beginning

Product security

Next

Obligations reaching manufacturers of connected products

Artificial intelligence

Timeline in flux

Governance duties for high-risk systems

THE PATTERN

Most of the work can be handed to someone.
One Layer Cannot

Every management-system domain has the same structure. A specialist function speaking a technical language, and a leadership body carrying accountability it has no way to personally evaluate.
 

Not a question of capability. A question of time. Interrogating the request properly would take days, and nobody at that level has days. So it is either declined, and the exposure stays exactly where it was, or it is approved on trust.

Approving on trust is the sensible thing to do. You hired those people for a reason. But in the record, an approval given on trust and an approval given on evidence look identical. The difference only appears when someone asks you to show which one it was.

Untitled design (8).png

Leadership layer

APPROVE · OVERSEE

TRAIN · EVIDENCE

Untitled design (7).png

Specialist layer

SYSTEMS · CONTROLS

DETECTION · RESPONSE

CAN BE DELEGATED

TRANSLATION

JUDGEMENT

EVIDENCE

USUALLY UNDER-RESOURCED

How this practice works

I build governance,
Or I Independently Verify It

Never both for the same system.

Build

Structure built around how the business actually runs

Oversight structures, decision rights, delegated authority and assurance mechanisms, shaped to fit the organisation as it operates today, then embedded into daily decision-making.

VERIFY

An independent opinion you can put in front of anyone

Testing whether governance is demonstrable rather than assumed, against the statute or the standard, never against a framework of mine. Findings written as decisions not yet put to leadership, not as failures.

Two things one practitioner should never do for the same system. So I don't.

Where I have seen it

The same gap,
Accross industries

It appears wherever a technical function reports to a leadership body with no time to test what it is being told. Different regulator, different vocabulary, same structure underneath.

6

Domains where it occurs

Quality, environment, occupational health and safety, information security, AI and energy. Lead Auditor in the six standards with the widest range.

19

Industries

In senior operating roles and global audit programmes. Enough repetitions of the same pattern to know it is structural, not particular to one sector.

35

Countries

Twenty-five years of building management systems, running audit programmes across regions, and sitting at the table that has to sign.

THE NINETEEN Industries

Energy  ▪  Water  ▪  Health  ▪  Finance  ▪  Telecoms  ▪  Public sector  ▪  Logistics  ▪  Automotive  ▪  Aerospace  ▪  Machinery  ▪  Electronics  ▪  Medical devices  ▪  Chemicals  ▪  Food & drink  ▪  Mining  ▪  Retail & FMCG  ▪  Media  ▪  Professional services  ▪  Certification

IN A Client's words

"We were confident in our technical implementation. What we didn't have was independent confirmation that leadership could demonstrate its own side of it. That's what this gave us, something we could put in front of our leadership with confidence, not just our security team."

VP & CTO · Global leader in smart grid technology for utilities

What building it looks like

Group governance,
Across Thirty Countries

 A global bulk logistics group, working inside the business rather than reporting on it from a distance. I was still there when the audits came, which is not usually how this works. Quality, environment, safety and energy, brought into one way of working across Europe, the Americas, the Middle East and Asia-Pacific.

What leadership ended up with was not a document set. It was review formats they ran themselves and reporting they could act on. I did not build a system that worked because I was there. I built one that kept working when I was not.

ISO 9001, 14001, 45001 and 50001. sixteen entites were auditied for certification, and nineteen entites undertook surveillance audits in that period.

How long IT TOOK

22

Months. All of this happened inside that window.

independently checked

0

No Major findings when the certification body audited thirty-five entities.

How far it reached

63

Entities in thirty countries, across four standards.

What happened after

Bronze → Gold

EcoVadis rating rose during my involvement. Still Gold a year after I left.

THE METHOD

Governance is not implemented.
It Is Built

Four stages. An engagement sits in one or more of them but never all four.

Ascertain

Architect

Adopt

Assure

An enterprise-wide look at how oversight actually operates: informal controls, founder-dependent decisions, single points of failure, exposure not yet visible internally.

Oversight and leadership structures, decision rights, delegated authority, risk architecture and assurance mechanisms, designed around commercial execution and culture.

Leadership facilitation, process integration and coaching through the shift from control to oversight. The objective is not a completed document set.

Testing whether governance survived contact with operational reality, identifying residual exposure, and giving leadership ongoing visibility rather than periodic reassurance.

Clarity replaces uncertainty.

Structure replaces reliance on individuals.

Governance becomes operational.

Confidence replaces contingency.

Where you'd start

Three ways in.
Which One Is You?

Start with Ascertain

Find out before someone else does.

An enterprise-wide look at how oversight actually operates today: what is informal, what depends on one person, and where performance would fail under external review or growth pressure. You get clarity, not a criticism.

An answer that is not your own word for it.

Independent assurance

A customer, an insurer or a regulator has asked. Nearly every supplier answers with a self-declaration, and procurement discounts those because everyone's says yes. An independent report is the only response in the pile that is not the supplier describing itself. For cybersecurity, that is the NIS2 Executive Assurance Assessment.

Architect and Adopt

Structure that replaces reliance on individuals.

You already know where the gaps are. What is missing is oversight structure, decision rights and delegated authority that fit how the business actually runs, and the facilitation to make leadership use them.

I am not going to tell you that you got this all wrong.
You Will Find Out Your Exposure

Start here

Thirty minutes, confidential, no commitment. If it doesn't fit, I'll say so.

"I need someone to tell me the truth, in writing, before the regulator does."

A chief executive, on why he called

bottom of page