Policy Governance
Policy Governance is a structured model for how a board of directors leads an organization, created by Dr. John Carver. Rather than dictating specific day-to-day decisions, it provides an operating framework that helps boards govern in the best interest of the organization's owners or stakeholders. It is sometimes informally called the Carver model.
Policy Governance is an integrated system of governance principles, developed by Dr. John Carver, that defines and guides appropriate board leadership rather than mandating specific operational decisions. Described as a comprehensive set of integrated principles intended to enable owner-accountable governance, it functions as an operating system for boards of directors, distinguishing the board's governing role from operational management. As a board-level governance paradigm, it addresses how boards define ends and delegate authority; it is distinct from information security leadership functions such as those delivered through a virtual or fractional CISO engagement, though its principles of separating governance accountability from operational responsibility parallel that distinction.
Why it matters
Policy Governance matters because it addresses a persistent challenge in organizational leadership: how a board of directors can lead effectively without collapsing the distinction between governing and managing. By providing an integrated framework for how boards define ends and delegate authority, the model helps boards focus on their accountability to the organization's owners or stakeholders rather than becoming entangled in operational decisions that belong to management.
For security leaders and the executives who engage them, the relevance is largely conceptual rather than direct. Policy Governance is a board-level governance paradigm, not an information security function. However, its central principle, separating governance accountability from operational responsibility, parallels an important distinction in security leadership engagements. Just as a board governs without executing daily operations, a virtual or fractional CISO typically advises and directs on strategy, governance, and risk while operational execution and ultimate organizational accountability remain with the client organization and its officers.
Understanding this parallel helps buyers avoid a common category error: treating governance and operational responsibility as the same thing. Recognizing where governing authority ends and operational responsibility begins clarifies expectations in both boardrooms and security leadership arrangements, though the two domains should not be conflated as equivalent functions.
Who it's relevant to
Inside Policy Governance
Common questions
Answers to the questions practitioners most commonly ask about Policy Governance.