Answer extracted from the Beyond The Plan podcast — listen to the full episode below.
Governance is the structure and systems that enable the right people to make the right decisions at the right time about project and delivery risk. It is fundamentally about transparency and accountability—not committees, meetings, risk registers, or templates, which are only supporting instruments. Administration, project management, and oversight are not governance itself; they are separate activities that serve governance's real purpose: enabling decision-making on risk.
The confusion starts when organisations mistake the machinery of governance for governance itself. Meeting attendance, detailed minutes, compliance documents—these can all exist while actual governance remains absent. Governance is theatre when a steering committee convenes but produces zero decisions, leaving the project team to guess and push forward alone.
The distinction matters because when governance fails, the entire delivery framework collapses. Isabel Gray-Garraway emphasises in the episode that projects blamed on technology, budget, or timeline failures almost always trace back to a governance breakdown. By the time stakeholders recognise the governance failure, the damage is already done—and the cost compounds far beyond the original project scope.
Administration organises process and keeps records. Project management executes delivery against timelines and scope. Neither answers the core question governance must handle: who decides, when do they decide, and how is risk actually treated? This separation is not academic—it determines whether a $200 million program runs smoothly or collapses under political and operational pressure.
Risk treatment, in Gray-Garraway's framework, requires organised timeframes and clear accountability chains. A project team that escalates risk but receives no decision for weeks has no governance—it has bureaucracy. True governance means risk is acknowledged, evaluated, and acted upon by empowered decision-makers within defined intervals. When that structure exists, transparency follows naturally: everyone knows who decides, what the timeline is, and what the decision was.
"Governance is the structure and systems that ensure the right people make the right decisions at the right time about project and delivery risk."
Isabel Gray-Garraway — Director of ICT Corporate Portfolio at Fire and Rescue NSW. With 25 years in project delivery spanning defence, government, and public-private hybrid organisations, Gray-Garraway spent 17 years in government roles learning the relationship between risk, accountability, and governance. She led a 100-person team managing a $200 million rolling program at Transport for New South Wales and has worked extensively in audit, risk, security, architecture, and enterprise governance.
Beyond the governance definition itself, the episode explores how governance failures compound into public sector disasters, with examples drawn from real government programs that cost billions in remediation and reputational damage.
Governance frameworks should be living documents with continuous review and self-reflection. As market conditions change and organisational priorities shift, governance structures must adapt to remain effective.
Independent challenge by external experts, rather than internal assurance, prevents the 'fox watching the henhouse' dynamic and ensures objective scrutiny of decision-making without internal tension.
When risks are raised but ignored repeatedly, teams eventually stop escalating. The absence of sponsor response and actual decision-making creates a culture where escalation becomes futile.