Governance versus management—this is a conversation I have been involved in many times over the years, and not just in the IT sphere. Many organizations struggle with drawing a line between these two disciplines. In this article, I attempt to define governance and management and to show where one stops and the other starts.
Defining IT governance and management
Let’s look at both in simple terms:
- The governance function of an organization is responsible for determining strategic direction.
- The management function takes that strategic direction and translates it into actions that will bring the organization closer to achieving the strategic goals.
Governance, when applied specifically to the IT organization and its management, is no different. Those responsible for IT governance will look to the overall governance of the organization aligning with their vision, mission, and goals, and ensuring that the strategic direction being taken within IT aligns with the overall business strategy.
IT governance: Different roles, different duties
Put simply, governance is about leading and management is about doing. Sounds easy, doesn’t it? Unfortunately, the lines are not always as clear as they could be. Somewhere in the middle ground, management and governance often become confused and, fed by this confusion, major problems can grow.
Both functions will see more success when those responsible for governance and management understand their roles clearly and stay within their lanes. In Distinguishing Governance from Management, Barry S. Bader outlines seven guiding questions to determine whether something falls under governance and is thus the board’s responsibility:
- Is it big?
- Is it about the future?
- Is it core to the mission?
- Is a high-level policy decision needed to resolve a situation?
- Is a red flag flying?
- Is a watchdog watching?
- Does the CEO want and need the board’s support?
While Bader was not referring specifically to IT governance and management, the principles remain the same.
If we were living in a perfect world, managers and employees would all know and understand their duties and responsibilities and act on them responsibly. Sadly, that isn’t always what happens. That is why the governance function is ultimately accountable if they are not diligent in their oversight responsibilities.
All organizations will face known and unknown risks. New technology has exacerbated these risks, making them more prevalent and intrusive to business. Those responsible for governance must work closely with IT personnel and senior executives on overseeing risk management and establishing a healthy risk appetite for the business.