Corporate governance exists to make power over a company legitimate and answerable. It defines how the board, shareholders and management relate to each other: who decides, who oversees and who answers for outcomes. The underlying problem it solves is old: those who manage other people's money need structures that align their decisions with the owners' interests. Resilience has become part of that bargain, because a company that cannot survive disruption protects nobody's interests.
Governance takes physical form in company law, articles of association, a governance code, board committees, delegations of authority and disclosure. Each layer assigns decisions and accountabilities to a named body. For example, an annual report typically describes how the board oversaw principal risks during the year, including operational disruption, and which committee did the detailed work. When these documents match how decisions are actually made, governance is real; when they do not, it is decoration.
The typical mistake is treating governance as paperwork: policies published, committees convened, boxes ticked, while real decisions happen elsewhere. ISO 37000 pushes back by framing governance around purpose and outcomes rather than formal structures. A useful test is whether the governance system would surface bad news about resilience quickly and force a decision on it. Module M1 of ERGP, Resilience governance and the board, builds on exactly this test.
Ask «what is corporate governance» of a lawyer, an investor and a regulator and you get three accents on one idea: the system by which companies are directed and controlled. Direction — the board sets strategy, appetite for risk and the tone of conduct. Control — management executes within delegated limits, and independent functions verify. Answerability — owners, and increasingly regulators and society, receive an honest account of the results. A company is well governed not when its policies are elegant but when a decision above someone's limit reliably travels upward, and bad news travels as fast as good.
| Block | Question it answers |
|---|---|
| Board and committees | Who directs, and with what independence |
| Delegation of authority | Where each decision is taken |
| Policies and code of conduct | How recurring decisions are made |
| Risk oversight | Which risks are owned, and by whom |
| Assurance | Who independently verifies |
| Reporting and disclosure | Who learns what, and when |
How the blocks assemble into a working whole — with a build sequence and worked examples — is the subject of our guide Corporate governance framework: components and examples. The oversight loop applied to disruption risk is covered in the board's role in resilience.
The system by which a company is directed and controlled: who decides, who checks the deciders, and who answers to the owners for the result.
Management runs the company day to day; governance directs and oversees management. The board governs, the executive manages — when one body does both without checks, the company has management but not governance.
Because continuity of service is an outcome someone must own, verify and answer for. Boards that never see disruption risk on their agenda discover it during the incident.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme