Most businesses that fail governance questions do have policies. What they don’t have is a way to keep those policies matching how the business operates. A document approved two years ago and untouched since carries little weight when somebody asks for evidence today. Good governance is a way of working that keeps the record honest as things change.
One person owns the whole picture
Governance touches many parts of a business. HR handles starters and leavers. An IT partner manages access and systems. Senior leadership approves the wider business decisions that reshape both. That distributed work is normal and healthy, and it holds together when one person has responsibility for making sure the separate pieces stay connected.
That person needs enough visibility to know what has changed across the business and enough authority to make sure the right follow-up happens. In its Cybersecurity Framework 2.0, NIST places governance at the top of its core functions and defines the accountability and oversight that keep the rest of the framework working.
The day-to-day of the role is straightforward. A weekly or fortnightly check-in with HR on staff movements. A standing agenda item with the IT partner covering access and system changes. Those inputs feed a short monthly note logging what was updated and where. Most firms already have the raw material for this from meetings that happen anyway. The job is to make somebody responsible for pulling it together and writing it down.
Some firms give that role to an internal leader, often a COO or a finance lead who already sees across the business. Others use external technology leadership. BASE Solutions provides vCIO support for firms that want ongoing technology and governance oversight without carrying a full-time CIO. Whichever route the business takes, the deciding factor is that one person is accountable for keeping the picture current.
The record updates while the work happens
An annual review is a long time to run on old information. An employee might leave in February. A new business application might come in during May. If nobody looks at the records until December, most of the year has been spent working from a picture that no longer matches the business.
The alternative is treating the record as part of the work. When somebody leaves the company, disabling their account and collecting their equipment already sits inside the leaver process, so updating the access record belongs in the same process. When a new application is approved, the record of who owns it and who has access gets captured while the decision is fresh. Governance stays current because it lives inside routine work.
Material changes are worth capturing at the point they happen. Common triggers include a new starter joining a role with wider system access, a leaver whose access covered several systems, a new SaaS tool coming online, a supplier gaining access to shared data, or a change in the regulations the business works under. Each of these is worth logging in the record while the decision is fresh, and the person named in Section 1 keeps a light touch on the log so nothing sits in somebody’s inbox unactioned.
For the larger decisions, the same cycle that already carries strategy carries governance well. In July’s Base article on vCIO oversight, we described running a quarterly technology review as a way to keep the plan honest. Governance fits into the same rhythm. What matters is that reviews happen often enough to catch change and that anything material happening between reviews prompts an update straight away. When records are current at the point the quarterly review begins, the meeting focuses on reading what changed and confirming it was handled properly, and it stays short. NIST SP 800-53 Rev 5 takes a similar approach with its access-control family, which supports both scheduled reviews and event-driven ones.
The current version lives where people can find it
Businesses can have plenty of governance material and still struggle when somebody asks for it. Copies end up in email inboxes, old folders, and individual desktops, and nobody is quite sure which version is current. That creates unnecessary work when an insurer, auditor, or client asks for evidence, because the business has to reconstruct its own records before it can share them.
Choosing one agreed place for governance documents removes most of that friction. Many firms already have somewhere suitable inside Microsoft 365, and the important part is discipline about using it. People need to know where the current version lives, who is responsible for updating it, and how to find it in five minutes on a Tuesday afternoon.
Getting there does not need new technology. A dedicated SharePoint site or document library inside the existing Microsoft 365 tenancy usually works well, provided the permissions are set so the right people can read the current version and only the accountable owner can edit it. The location is agreed upon and used consistently by everyone who might need to reach it.
An independent review can then check whether those records still match the real environment. BASE Solutions runs IT audits and assessments that examine the current setup and identify areas that need attention. When the underlying documentation has been maintained properly, that review focuses on genuine gaps in the operation, because the history it needs is already there.
Governance leaves the record behind on its own
When ownership is clear, records update as the work happens, and the current version lives where people can find it, the business builds a working history without ever setting out to. Approvals carry dates. Access changes are recorded at source. Reviews leave a trace of what was checked. Done this way, an audit trail isn’t a separate exercise; it’s simply what the system leaves behind.
The harder situation is when a business has never worked this way. Policies are scattered across drives and inboxes, ownership is unclear, and the written version has drifted away from reality. Before building the operating habit, the business first has to see how far things have moved out of step. That is the starting point for the next stage of the journey.
A firm that can produce all five when asked is demonstrating exactly the operational discipline insurers now price coverage around.
If this makes you wonder whether your own firm would pass the same review, that’s worth a conversation before your next renewal.



