The fire certificate and the smoke alarm: why governance architecture isn't governance intelligence
Most organisations that suffer a serious governance failure are not short of paperwork. They have policies, risk registers, reporting lines and board packs. What they usually lack is much harder to build: proof that the system works when it matters, not just that it exists on paper.
Think of it as the difference between a fire safety certificate and a smoke alarm. The certificate tells you the building met the standard when it was inspected. The smoke alarm tells you, right now, that something is wrong. Both have their place, but only one will wake you up in time.
How failure happens
Serious governance failures are rarely traced back to one bad decision. Isolated mistakes get resolved. They cause disruption, sometimes real pain, but they get managed and the business moves on. The bigger problem is cultural: mistakes that are not confronted properly compound, and the damage grows in proportion to how long the nettle goes ungrasped. What starts as a manageable operational issue can, eighteen months later, have a name and a headline. The uncomfortable truth is usually that somebody, somewhere in the organisation, saw it coming.
Boards miss this for two reasons, and each calls for a different fix. Sometimes it is comfortable distance, a board that has decided it can stay a step removed because external advisors have been engaged and can be blamed if things go wrong. That is short sighted, because responsibility always comes back to the board in the end.
Other times the picture is genuinely too complex for a board to know where to start, years of accumulated operational detail that nobody has ever had to unpick before. In those moments, the priority is finding someone who can see the wood for the trees: a trusted internal specialist or an external advisor with enough experience to tell the board what questions it actually needs to ask, not simply answer the ones it already knows.
The blind spot in every risk register
Ask most businesses what their risk framework focuses on, and the honest answer is high probability, low impact issues: the things everyone can see coming and has already built a process around. What gets under-escalated is the opposite, the unlikely but catastrophic "what if" that feels remote enough to file away rather than confront properly. A three per cent chance of catastrophe deserves more board attention than a near certainty of something minor, and in practice it rarely gets it, because catastrophic feels theoretical until the day it is not.
Testing the system before you need it
Response planning and scenario exercises earn their keep here, not because they catch every risk, but because they force a business to name its genuinely high impact scenarios before anyone has a reason to be defensive about them. They also show how the organisation behaves under pressure. The real value appears later, when someone on the front line recognises a live situation because they have role played something like it before, and escalates instead of sitting on it and hoping it resolves itself.
The trusted advisor trap
Independent challenge is essential, and boards that rely too heavily on internal reassurance rarely spot their own blind spots. But external advice is only as good as the advisor's willingness to say something the client does not want to hear. Advice that simply reinforces a board's existing direction of travel is not challenge; it is expensive validation, and it can do more damage than no advice at all because it comes wrapped in the appearance of scrutiny. The choice of advisor matters as much as the decision to seek advice, and litigation advisors in particular carry their own biases worth naming honestly: a wish to impress the client, competitiveness and a tendency to overestimate the odds of success. None of that makes external advice less necessary. It makes who you choose the whole game.
AI raises the stakes on human judgement, not lowers them
There is a temptation to treat more automated decision-making as a reason to worry less about governance, since the system is doing the thinking. The opposite is true. Where automated decisions touch large numbers of people, even a small error rate can cause serious harm at scale. The more embedded technology becomes in a business, the more essential human oversight and judgement become alongside it, not instead of it. Any process where an automated system's error could seriously harm someone needs a genuine human gate built in, a point where a person can stop the process on nothing more than a live possibility of harm, not wait for certainty before acting.
Is the UK Corporate Governance Code enough?
The Code is a strong framework, but the real failure usually occurs in the gap between what an organisation says and how its leaders behave. The missing ingredient is rarely another policy. It is the willingness to recognise patterns, invite challenge and confront uncomfortable facts.
In practice, governance failures occur despite sound policies because warning signs are rationalised, challenge is discouraged, information remains siloed or protecting the organisation's position becomes more important than establishing the truth.
The Code requires boards to identify their principal and emerging risks, decide what level they are willing to take, explain how those risks are managed, and declare whether their material controls are effective. That maps directly onto probability and impact. Impact tells a board how seriously to take a threat, probability tells it how urgently to prepare, and both need reassessing as new evidence comes in, because repeated anomalies are rarely background noise.
More often they are a sign the organisation misunderstood the situation in the first place. However low a board might have assessed the probability of the Horizon system's data being wrong, the potential consequences for the people affected were severe enough, prosecution and bankruptcy among them, that intervention should have come far earlier.
The Code applies only to UK listed companies, so extending some of its principles to private companies could be beneficial, particularly where the business's activities may affect the welfare of people. I would also support more explicit board-level responsibility for legal risk, including oversight of major litigation, investigations, disclosure and regulatory responses.
What grasping the nettle looks like
CrowdStrike's global outage in July 2024 is a useful recent example.
A defective software update took down Windows systems worldwide, disrupting airlines, hospitals and banks, and the company's share price fell by around 40% in the days that followed. What happened next is the more instructive part. CrowdStrike identified the cause within hours and worked directly with affected customers on recovery, published a technical review and hardened its release and testing processes, and introduced customer-care arrangements rather than retreating behind legal or technical defences. One investment manager called the response as outstanding, and customer retention stayed in the high 90s.
The share price had returned to its pre-incident level by December 2024 and stood around 55% above that benchmark a year later. Litigation and customer-concession costs carried into 2025, so the harm did not disappear, but revenue still grew 21% over the same period.
That kind of recovery tends to share a recognisable pattern: acknowledge the scale of the problem early, protect the people affected before you are obliged to, have the most senior leader visibly own it without creating unnecessary legal exposure, offer real redress rather than an apology, and fix the root cause rather than the symptom.
None of this is proof that every crisis should be met by immediately accepting liability, and that is not the lesson. The stronger governance point is that a board should establish the facts independently and quickly, put public safety ahead of institutional self-protection, and be willing to crystallise a loss when the evidence genuinely warrants it. Handled that way, the response does not just contain the damage. It tends to leave the business more resilient, and more trusted, than it was before.
Get in touch
The one question that matters
A business cannot predict every failure in advance. That is not realistic, and it is not the standard boards should be held to. What it does require is a board that can answer one question honestly at any given moment: what material issue is happening in the business that we do not yet know about? Getting comfortable with not knowing is where governance starts to fail, quietly, long before anyone notices. Getting serious about finding out and building the habits and relationships that make that possible, is where it starts to hold.
The businesses that come through a serious governance test well are rarely the ones with the thickest policy manual. They are the ones that built a smoke alarm, and had the discipline to listen when it went off.
The content of this page is a summary of the law in force at the date of publication and is not exhaustive, nor does it contain definitive advice. Specialist legal advice should be sought in relation to any queries that may arise.
Related expertise
Contact us today
Whatever your legal needs, our wide ranging expertise is here to support you and your business, so let’s start your legal journey today and get you in touch with the right lawyer to get you started.
Get in touch
For general enquiries, please complete this form and we will direct your message to the most appropriate person.