Strip away the vocabulary and corporate governance answers three questions. Who has the authority to decide — and where that authority ends. Who verifies that decisions are executed and risks are controlled. And who is accountable to owners, regulators and society for the outcome. A governance framework is simply the written, working answer to those three questions: not a binder produced for a listing or a tender, but the mechanism the company actually runs on. The test is practical — when a decision above a manager's limit appears, does everyone know where it goes next, and is there a record that it went there?
| Component | What it fixes | Typical artefact |
|---|---|---|
| Ownership and board structure | Whose interests rule and who directs | Charter, board composition, independence rules |
| Board committees | Depth on audit, risk, remuneration, nomination | Committee charters and annual plans |
| Delegation of authority | Where each decision is taken | DoA matrix with monetary limits |
| Policy house | Rules of conduct for recurring decisions | Code of conduct, core policies, review cycle |
| Risk management and internal control | How risk is identified, owned and treated | Risk register, appetite statement, KRIs |
| Assurance | Independent confirmation that controls work | Three lines model, internal audit plan |
| Reporting and disclosure | What the board and the market learn, and when | Board pack, reporting calendar, disclosures |
The components are not optional modules; they lock together. A delegation matrix without assurance is trust without verification. Committees without a reporting calendar meet without consequence. A policy of accountability without a delegation matrix names no one.
Most frameworks cover financial control thoroughly and operational disruption barely. Yet the same three questions apply: who decides to invoke continuity plans, who verifies the plans hold, who answers when the service is down for a week. In mature frameworks the board sets an appetite for disruption, assigns ownership of continuity to a named executive, and reviews exercise evidence the way it reviews audit findings. How that oversight works in practice is set out in the board's role in resilience and in operational resilience board reporting; the regulatory push in this region is described in our CBUAE operational resilience guide.
The set of structures, policies and information flows through which a company is directed and controlled: board and committees, delegation of authority, policies, risk oversight, assurance and reporting. It defines who decides, who checks and who answers.
No. The components are constant, their weight is not: a family business needs the delegation matrix and succession first, a bank needs risk appetite and assurance depth, a state-linked company needs disclosure discipline. Proportionality is a design principle, not an excuse.
Resilience is a governance outcome. The board sets the appetite for disruption, assigns ownership of continuity and reviews evidence that plans hold — the same direct-verify-account loop applied to disruption risk.
ERGP — Executive Certificate in Enterprise Resilience Governance — teaches exactly this loop: how boards direct, verify and answer for resilience. The first such certification fully available in Arabic, also in English.
Explore the ERGP programme