Project governance

Governance is the arrangement that says who may decide what. Most of what people dislike about it is the absence of that arrangement rather than its presence, since a project without stated decision rights spends its life discovering them one delayed decision at a time.

Decision rights have three parts

A workable arrangement answers three questions for every kind of decision, and leaving any of them implicit is where the trouble starts.

Who decides. A named role rather than a committee that has never met. If two roles can both plausibly claim a decision, that decision will be made twice and then unmade.

At which threshold. Authority is bounded. A change costing under one figure belongs to the project manager, under a larger one to the sponsor, and above that to a portfolio board. The thresholds matter more than the hierarchy, because they are what let most decisions stop at the bottom.

On what evidence. A gate that can be passed with a presentation and a gate that requires test results and a signed impact assessment are different controls, whatever the terms of reference call them. Naming the evidence in advance also prevents the familiar scene where a decision is deferred because somebody wanted a document nobody had been asked to produce.

A decision rights table you can copy

Written down for a delivery project of ordinary size, the three parts fit into one table. The figures below are in pounds and are illustrative, since the shape is what transfers between organisations rather than the numbers.

DecisionWho owns itThresholdEvidence they need
Change to scope, cost or scheduleProject managerUnder 25,000 and inside the stage toleranceImpact assessment, revised forecast, agreement from the team that absorbs it
Change to scope, cost or scheduleSponsor25,000 to 150,000, or any move to a date already committed to a customerImpact assessment, business case figures redone, the view of the receiving area
Change to scope, cost or schedulePortfolio boardAbove 150,000, or any change to the agreed benefitReissued business case, and the capacity impact on the other work in the portfolio
Accepting a residual riskProject managerExposure under 50,000, with no safety, data or regulatory elementRegister entry carrying the response, the residual score and a named owner
Accepting a residual riskSponsorExposure above 50,000, or anything touching safety, personal data or the licence to operateRisk assessment, the options considered, and a named person accountable for the acceptance
Drawing on contingencyProject managerUp to the reserve held for this stageA drawdown record naming the risk the reserve was held against
Continuing past a stage boundarySteering groupEvery stage boundary, whatever the delivery newsStage report, next stage plan, and the business case still positive
Accepting a deliverableThe named business owner of that deliverableEvery deliverable in the planTest results against the acceptance criteria, with outstanding defects and their severity
Accepting non compliance to protect a dateSponsor together with the accountable compliance roleNever delegated downwardThe obligation, the options, the exposure attached to each, and a written decision carrying a date and a name
Stopping the projectPortfolio boardAt any point, including mid stageCost to complete, remaining benefit, and what the released capacity would do instead

Three features of that table are what make it work. Every row names one owner, so a decision arrives at the right desk instead of being discovered at a meeting. Every row carries a number or a stated condition, which makes the boundary something you can test. And the rows carrying a condition where a figure would sit are the ones worth arguing over while you write your own, because those are the decisions that travel upward however small they look.

Steering groups, stage gates and tolerances

A steering group is a small set of named individuals with real authority over the resources the project needs, typically the sponsor, someone senior from the area receiving the change, and someone from the delivery or supplier side. Its job is to decide the things above the project manager's threshold and to unblock what the project cannot unblock itself.

A stage gate is a point at which continuation is decided rather than assumed. The question is whether the case still holds and whether the next stage is ready to start, which is a larger question than whether the last stage went well. A gate that has never stopped anything is a formality wearing a gate's name.

A tolerance is how far a forecast may vary before the level above has to be consulted. Cost, schedule, scope, quality, risk and benefit each get one. Inside tolerance the project manager acts. Outside it, the position is escalated with options rather than fixed quietly, which is the whole of what management by exception means.

Governance is what stops you having to ask

The common reading of governance is a queue of approvals. The useful reading is the opposite, because every decision right written down is a decision that no longer needs a meeting to establish.

A team that knows it may spend up to a stated figure on its own authority, may change a design within a stated boundary, and may accept a risk below a stated level moves considerably faster than a team that has to check. The organisations with the heaviest sense of governance are often the ones that never set thresholds, so everything is escalated by default and the board spends its time on decisions nobody needed it for. Setting a low threshold badly is still better than setting none, because it can be adjusted once you see what keeps arriving.

Unclear decision rights are a leading cause of delay

When nobody knows who decides, the work does not stop dramatically. It stalls in small increments that never appear as a failure in any report. A question waits a week for the right person to be identified. Two people with plausible claims disagree and the matter is deferred. An escalation lands with a group that has no authority over the thing in dispute and is sent back.

All of that stays out of the numbers, because it shows up as neither a risk materialising nor a task overrunning, while being one of the largest components of a slipping schedule. The diagnostic is simple enough to run on any project. Take the last three decisions that took more than a week, and ask whether the delay was in getting the information or in finding the person.

Governing and managing are different jobs

Governance sets direction, sets the boundaries and holds the project to account for staying inside them. Management delivers within those boundaries. The two are separated on purpose, since a body cannot hold to account work it has been directing in detail.

The usual breach is a sponsor who starts running the project, which leaves the project manager with responsibility and no authority and leaves nobody in the role of asking hard questions. The reverse breach is a governance body that stays silent between gates, which produces a project discovering at a gate what it could have been told months earlier.

Common misconceptions

Governance means more approvals and slower delivery.

Most delay comes from decisions with no owner rather than from decisions with one. A tolerance written down in advance is permission granted in advance, and a team that knows what it may decide alone stops queuing for meetings it never needed.

The steering group is where the project reports progress.

It is where decisions the project manager cannot take are taken. A group that only receives status is a reporting meeting wearing a governance label, and the decisions it was assembled to make will drift back to whoever is willing to take them informally.

A tolerance is another word for contingency.

Contingency is money or time set aside. A tolerance is authority, meaning how far a forecast may move before the level above has to be told. You can hold contingency you are not authorised to release, and you can hold tolerance with no reserve behind it.

Where this is examined
PMP
Business Environment, 26 per cent of the exam.
Related material
Book
Managing Successful Projects with PRINCE2, On management by exception and where tolerance sits between levels.
Book
Lean Enterprise, On governance functions and delivery teams meeting somewhere sensible.
Book
A Guide to the Project Management Body of Knowledge (PMBOK Guide), Seventh Edition, On the stewardship and tailoring principles behind a governance design.
Concepts