All resourcesWorking checklist · 6 min read

The governance baseline

A practical starting list for mapping obligations across security, privacy, risk, audit and regulated operations.

01 · The short version

A baseline is not a maturity score and it is not a promise that every control is finished. It is a shared picture of the commitments that matter, the owners behind them and the evidence that would make a reasonable challenge answerable.

02 · The detail
01

Build the obligation map

Bring together customer commitments, regulation, internal policy, contractual requirements and the organisation's own risk appetite. Remove duplicates, but preserve the reason each obligation exists. This gives teams a common language before they debate tooling.

02

Test for operability

For each important commitment, ask: who does the work, how often, what proves it happened, and what happens when it does not? If an answer depends on a heroic individual or a spreadsheet no one owns, the baseline has found useful work.

03

Keep it alive

Review the baseline when the business changes, not only before an audit. New suppliers, products, data flows and AI use cases should have a visible route into the map. A modest monthly review is often more valuable than a large annual refresh.

03 · Make it specific

Have a live question behind this briefing?