Governance remembers more than it sees

August 19, 2026
Andries van Oers
Strategist
Join our newsletter->
Andries van Oers
Strategist

There is a question I like to ask early in an engagement, usually in passing, on the way out of a meeting: why does this deployment need a third approval? The answer tends to take a few days to arrive, because it has to be retrieved from somewhere first and when it comes back it is nearly always a story.

Something happened, years ago, the company learned from it and the rule turns out to be the place where that lesson has been kept ever since.

I have grown fond of reading technology estates this way. A stack looks like infrastructure, but spend enough time inside one and it starts to read like an autobiography. Written by careful people, in which every control marks something the company came to understand about itself. Most of what it says is still true. 

What has been occupying me lately is a thought that follows from this: remembering and seeing are different skills and nearly everything we call governance was built for the first one.

Every control has a birthday


Nearly every rule in a technology estate is a lesson, drawn from something that already happened.

Layers build, and hardly any come back out.

My favourite example is the freeze. Around the middle of November, in retail and logistics companies especially, the engineering calendar goes quiet and for several weeks very little is allowed to change while the estate runs through its busiest season undisturbed.

If you ask where the freeze came from, you will eventually arrive at a specific year and a specific difficult night. Remembered now by only a handful of people. The lesson outlived them all. Every November it is honoured again and I find something almost touching in that: an organisation keeping a promise it made to itself long after it has forgotten the occasion.

The same pattern repeats at every scale once you start looking for it, down to the second pair of eyes required on a deployment. Michael Power, who spent his career studying audit and risk, once observed that much of risk management is really the management of a second risk: the risk of blame. In the years since I first read him, I have found no better explanation for how estates accumulate.

Adding a rule asks very little of anyone, while removing one means attaching your own name to whatever might happen afterwards. Everyone in the building understands that arithmetic without ever needing to discuss it. So the layers build, for good reasons, and hardly any of them ever come back out.

Transformation work feels this sooner than most, because a programme built to change how a company operates has to travel through machinery the company assembled in response to its previous decade. Along the way, it tends to lay down some machinery of its own, a steering rhythm that will outlive it.

Growth does the same at the scale of the whole company. New capability arrives at the front while memory settles in behind and the two accumulate at different speeds. All of which describes an organisation getting steadily better at remembering. What that does to its ability to see took me longer to notice.

The diagram and the building


The architecture diagram describes the estate as it was meant to be. The estate itself has been growing past it ever since.

The architecture is larger and more complex than originally drawn.

At some point in every engagement someone shares the architecture picture and it is usually well made and everyone in the room extends it the same courtesy. We treat it as a map while knowing it is closer to a portrait, painted a while ago, of how things were supposed to look. In that sense the diagram belongs to the memory too. It records a decision the company once made about itself, as of the day it was drawn. 

The estate itself is always larger and stranger than its picture. My reliable companion here is the spreadsheet, because there is one in nearly every company I visit, doing the work of a system of record. Its owner tends to be the most reliable person in the building about how things actually run.

It has relatives all over the estate, tools and connections that grew up around the official architecture in good faith. At the speed of the work, while the documentation kept its own slower calendar.

What interests me most is what this means for the people accountable for it all. A founder begins by seeing everything. Scaling is, in a sense, the deliberate exchange of that sight for summaries, while the accountability stays exactly where it was. By the time an engineer's worry reaches a slide it has been translated several times over.

Each translation made in good faith by someone doing exactly what the process asks and each one deciding what to leave behind. What gets kept and what gets dropped is decided by the process. And the process, like everything else in the estate, was shaped by what has already happened. The summaries are made of memory too. 

Programme managers have a folk name for where this can end up, watermelon reporting, green on the outside and red inside. The fact that the name survives on recognition rather than on any research tells its own small story: the people inside the system described the pattern long before anyone thought to measure it.

The newest tenant


In most estates, AI gets discovered rather than introduced.

Discovered rather than introduced.

Somewhere in the past couple of years, estate reviews began turning up a new kind of resident: AI. It tends to announce itself in small ways: an update goes out over a weekend and on Monday a meeting tool is offering summaries. The office suite gains an assistant between one renewal and the next.

And alongside the official estate there is another version of the same arrival: people across the company using tools of their own, on personal accounts, for work that used to stay inside the walls, mostly because the tools are good and the day is short. At no point in any of this is there a proposal for anyone to weigh. The capability simply arrives, the way a coastline acquires weather.

This is where the two skills pull apart hardest. Every rule in the building has a birthday and this tenant has not had its incident yet, so the memory has nothing to offer and the filters that do exist were built for software that holds still. You review it, you approve it and it stays the thing you approved.

An AI model keeps moving after the review is filed and its vendor will move it again next quarter, while the accountability for whatever it does lands, as it always has, at the top of the company. A small tribunal case made this vivid not long ago, when an airline was ordered to honour a discount its website chatbot had invented, after arguing that the chatbot was a separate entity responsible for itself, an argument the tribunal declined to accept.

The amount at stake was a few hundred dollars, which to my mind is exactly what makes the case worth keeping: a company held answerable for a sentence nobody inside it had written or read.

There are two objections I take seriously and both are generous to the people they defend.

The first is that abstraction is simply the job, since an executive who read raw telemetry would govern nothing at all and summarising is what governance is for.

I agree and I think the objection sharpens the question rather than settling it, because everything then depends on what the summaries were tuned for. The ones in use today were tuned, layer by patient layer, to risks that hold their shape.

The second is the old wisdom about fences: the rule nobody can explain may be holding up a wall, so clear nothing away until you understand why it stands. I agree with that one too, perhaps more with every year. Some of the sediment is load-bearing and the estate rarely volunteers which.

Growth keeps widening the distance between the two skills, because it adds to both sides at once. New capability out at the frontier, where the accountability now formally extends. New memory settling in behind it, drawn as memory always is from what has already happened.

Sooner or later AI will join that memory too.

Something will happen somewhere, a lesson will be drawn from it, a new rule will mark the spot and the layer will hold real learning, the way the layers before it do. I have stopped worrying about whether organisations will remember, since remembering is the thing they do best. 

The question I find myself carrying from one estate to the next concerns the other skill entirely: how much of what a company is accountable for can it actually see and who inside could show it?

Highlighted Articles