Beyond the board: the whole governance framework
Assessment, design and implementation — from a group policy to the ethics programme, the listing or the investment. Six engagements, each measured against OECD, IFC and national codes, and each ending in a plan with owners and deadlines. This page is how the work is actually done.
Six engagements, one framework
Design is measured against the codes; effectiveness through documents and interviews. Every review ends in a plan someone owns.
- 01Governance review & design ↗A 360° review of the governance framework, beyond the board: leadership and decision-making, risk governance and the control environment, information flows and transparency, values and incentives, relations with shareholders and stakeholders. Design measured against OECD, IFC and national codes; effectiveness measured through documents and interviews. A maturity grid, and a prioritised action plan with owners, deadlines and indicators.
- 02Group & holding governance ↗Mapping of structures, reporting lines and authorities across the group, then a group governance policy: common principles for legal entities, decision rights, the coordination of key functions and business lines. Specific policies where they are needed, and assessments of individual subsidiaries against group standards and local requirements.
- 03Governance vulnerability reviewStructural, procedural and reputational weaknesses read against codes, investor expectations and market practice — including the exposure to a crisis or an activist challenge, which is measurable in public data long before anyone tests it.
- 04Pre-IPO preparation & health check ↗Governance readiness ahead of a listing or a privatisation: board structure and composition, committees, control environment, disclosure and investor-readiness. A diagnostic, a readiness checklist, and an action plan operationalised rather than described.
- 05Governance due diligence & action plans ↗For investors and development finance institutions: pre-investment or pre-acquisition governance diligence — red flags and the realistic improvement potential — then the full Corporate Governance Action Plan cycle, from diagnosis to plan design and implementation support, benchmarked against frameworks such as the IFC methodology.
- 06Policies, charters & disclosure ↗Codes of ethics, conflict-of-interest and whistleblowing policies, board and committee terms of reference, delegated authorities — drafted from your documents, the regulation and peer disclosure, with the practical procedures to run them. And support for the governance section of the annual report, so the published account matches the practice.
Six reasons a framework gets reviewed
A governance review is rarely commissioned out of curiosity. In our proposals the trigger is nearly always one of six — and it decides the scope, the pace, and who has to be in the room.
A new shareholder, a new chief executive, a group that has outgrown its rules
A change of ownership or of leadership; growth, or a change of strategy. The framework that fitted the previous company no longer fits this one, and the review says where.
New issues, and investors who now ask
Transparency, ESG, stakeholder engagement, corruption risk — and the expectations of investors and proxy advisers that come with them. Or simply the wish to improve the internal framework before anyone asks.
A listing, or a lender's condition
Preparing an IPO, or a governance action plan that a financing institution writes into the legal documentation. Both come with a calendar, and the review follows it.
Design is read against the OECD Principles, the OECD Guidelines for state-owned enterprises, the Wates Principles, the ICGN Principles, the IFC methodology, the IIA standards, the Basel Committee's principles for banks, the national code and the listing rules that apply to you — never against a single one.
Five domains, and what we actually look at in each
Every framework is read twice — design adequacy, whether bodies, reporting lines, policies and processes correspond to best practice; and process effectiveness, how it actually works, through the documents and the people who use them. The domains do not change from one mandate to the next; their weight does. Every finding is graded on four levels — minimal or no gap, small gap, big gap, does not appear to follow this best practice — and read twice: against your own rules, and against the regulation.
- 01Board and management leadershipThe board's main responsibilities: strategic guidance and key decisions, oversight of financial and non-financial reporting, of risk and control, evaluation of management performance, remuneration and executive succession planning. Committee responsibilities, effectiveness and reporting. The relationship, interaction and accountability between board and senior management. Board dynamics, support and resources. Management committee structure and effectiveness — key committees, layout of functions, group structure.
- 02Risk and control environmentThe role and functioning of the risk committee; the risk management function and its relationship with senior management and the committee; executive-level risk committees; key risk policies, and risk reporting at management and board level; the relationship between audit and risk committees; how risk appetite is set — and, for financial institutions, the ICAAP and ILAAP. Adequacy and transparency of delegated authorities. Independence and effectiveness of internal audit and compliance. Related-party transactions, conflicts of interest, whistleblowing.
- 03Transparency and information flowsQuality of reporting to senior management and to the board. Quality of governance disclosures and documentation. How group-level key performance indicators are set and reported.
- 04Culture, talent management and incentivesPeople, values, ethics and alignment across the group. The code of ethics: adequacy, effectiveness, implementation. The executive performance assessment process — adequate knowledge, skills and experience in senior management. Remuneration and incentives for senior management and the board. Strategic HR: executive and board succession planning, nomination and appointment processes.
- 05Relationship with shareholders and stakeholdersEffectiveness of formal and informal interactions with key stakeholders. Quality of communication with shareholders and stakeholders. Employee representation and engagement. Adequacy of the stakeholder mapping.
A 360° review, beyond the board
The full engagement: leadership and decision-making, risk and control, information flows, culture and incentives, stakeholders — read against the codes, and through the people who live inside the framework. For a financial institution it can double as an independent dry run of a supervisory assessment. Three movements, then the deliverables a mandate most often produces.
- 01DiagnosticYour documents, a questionnaire to the bodies concerned, confidential one-to-one interviews led by a senior advisor — the board, the executive, the control functions, and where useful the shareholder.
- 02AnalysisA fact base rather than opinions: every finding graded on four levels, a maturity grid built for the mandate, the reading against your own rules and against the regulation, peer benchmarks where they add something.
- 03RestitutionThe report shared as a draft first, so that facts can be corrected before conclusions are argued; then the action plan, the presentation, and the charters and policies revised to match what was decided.
What we will ask you for, two to five days after kick-off: organisational chart; board decisions on delegation of authority; articles of association; board and committee terms of reference; the chair's remit; executive job descriptions; the list of management committees with membership and terms; the remits of the company secretary and head of legal; charters of key functions; internal rules of operation; articles of association of subsidiaries.
Four actors, five questions
The point of review in a group is not a body; it is the inter-relation between four — the parent board, the parent management, the entity board, the entity management. Five domains organise the questions, and one six-step path runs from contextualisation to embedding: governance mapping, gap analysis and governance intelligence, interviews with boards and executives, the framework and its recommendations, then implementation.
- 01Core values, processes and policies across the groupWhich principles are meant to be common, which are actually applied, and where an entity has quietly written its own.
- 02Allocation of decision-making powersBetween the parent, the intermediate levels and the group entities: which decisions sit where, and whether the people who take them know it.
- 03Controls on allocated authoritiesHow delegated authorities are checked, escalated and reported — and what happens when a threshold is crossed.
- 04Reporting and information flowsWhat goes up, what comes down, how fast — and whether the parent board could see a problem in a subsidiary before it reads about it.
- 05Governance and administration of group entitiesThe boards of entities and their chief executives: composition, mandate, evaluation, and their relationship with the group functions — risk, finance, audit, compliance, HR.
Concrete mechanisms found in such a policy: approval thresholds, by level of capital, for creating or closing an entity; at least two major subsidiaries visited by the board each year; a group management team that meets twice a year; a review of the performance of the group's top thirty executives; an annual report by the group company secretary on how the policy is applied.
The listing code, read in three phases
Not a method of its own: the governance review, read against the code of the market you are listing on and paced by the listing calendar. An IPO is a multidisciplinary exercise; the review gives the board the whole sequence at once.
The cycle a lender expects
For an investor, the diligence reads the target against the IFC Corporate Governance Methodology: commitment to good governance, board structure and functioning, control environment, transparency and disclosure — and the treatment of minority shareholders, the heading that matters most to a minority investor. Then the plan, and its implementation.
Review, report, plan, assisted implementation, training
A chronological workflow of every step; for each recommendation a priority — high, medium, low — and its sequencing, the party responsible, target start and end dates, and the policies to create or update. Consulted with the stakeholders, then finalised.
Four workstreams, each paired with training
Board leadership and organisation; risk management; compliance, internal audit and the control environment; succession planning and strategic HR. Each instrument drafted — by-laws, charters, terms of reference, policies — is delivered with the training to run it.
Build on what exists
Formalities, bureaucratic cost and management time kept to the minimum. Embedding governance reforms into daily practice is harder than designing them — so progress on the plan is reviewed with the client, year after year.
Six steps, then the practical procedures
Kick-off; review of your documents, the law and peers' published practice; one-to-one interviews with the bodies responsible; a preliminary structure — scope, legal constraints, the outline agreed; the draft; the final policy. And with it a Practical Procedures document: who does what, when, with a schematic of the actions — because a policy nobody can run is a poster. And when the need is a whole ethics and compliance programme rather than one policy, the work runs in four phases.
- 01Gap analysisThe policies in place, how they are actually implemented, and the resources behind them — the existence of a policy or a committee is never taken as proof that it works.
- 02The action planA roadmap with priorities, responsibilities and implementation indicators, consulted with the people who will carry it.
- 03Implementation assistanceMonthly thematic sessions, templates, targeted training — drafting alongside your teams rather than for them.
- 04Effectiveness reviewEvidence-based, at the centre and across a sample of entities: what is applied, what is known, what is still on paper.
Four principles run through a programme: risk-based and proportionate; built on existing arrangements; scalable across a group; written for the people expected to use it. Its usual contents — a code of ethics, conflicts of interest, anti-corruption and anti-bribery, whistleblowing, enforcement, third parties and the supply chain, sustainability — are the first entries of the list above.
The gap between charter and practice is the most recurrent finding of our interviews — and it must be objectified, not asserted.
Reviewing the framework, or redesigning it?
A group policy, a pre-IPO check, a due diligence, a code of ethics — tell us where the framework stands, and let's discuss it.
Stay informed.
Every week, one governance ratio drawn from Gov360 Data — a measured fact on boards, remuneration or ESG, with the context to read it. Plus our studies and press mentions as they are published.
One email a week. Unsubscribe anytime.
