Every governance body I have sat in front of this year meets on schedule. The pack goes out days before, the meeting runs its hour, the minutes record that the programme was discussed. Ask anyone who was in the room what would have had to be true for that hour to change the programme, and you get a pause.
That is not inattention. Attendance is usually excellent and the people are usually senior. It is a wiring problem. A governing body acts through a small number of connections into the work: a gate it can refuse to open, a budget tranche it can withhold, a scope item it can cut, a benefit it can insist on seeing before the next tranche moves. Where those were never built, the meeting still happens, on time, with a full agenda, and nothing said in it reaches the programme.
I keep returning to one document for the cleanest statement of that condition I have read. It sits inside an independent readiness check on a European energy retailer, run on the rebuild of the sales, contracting and billing platform behind its business-customer operation. Four weeks of fieldwork. Nineteen interviews spanning programme staff and steering committee members, plus a review of programme documentation. It was commissioned as the programme was supposed to be leaving start-up and entering delivery, so it produced findings and recommendations about a thing still in front of everybody, not an account of how it went.
In the first detailed finding, one line:
The Steering Committee has no levers to monitor and control the benefits case yet.
A lever is something you can pull, and there were none
Take the sentence literally, because the reviewers meant it literally. The committee had visibility. Papers arrived, dates were reported, and top management was involved and, the reviewers were careful to record, able to steer through the committee because all the relevant parties sat in it. What it did not have was any point at which its opinion converted into a change in the work.
The benefits case is the clearest case. Five benefit types were loaded onto a single build. The reviewers found no clear linkage between the realisation of those benefits and the phases of the programme, which is the specific missing wire. Without it, a committee cannot say the first stage delivers this much of the cost-to-serve reduction and we will not fund the second until we see it. It can only ask whether things are broadly on track and be told that they are.
Scope was open at the same time, and open at the level that decides architecture rather than schedule. Three strategic questions were still undecided when the review ran, and the plan document that would have closed them existed in draft with a five-page management summary, discussed at the committee meeting held days before the report. So the body that could not measure the benefits also could not yet say what was being built.
What arrives instead of control
What a committee in that condition receives is reporting, and the alternative reading of this finding, that executives were kept in the dark, is the wrong one. They were told a great deal, accurately, on a regular cadence.
The problem with reporting is structural rather than moral. A report describes a state already reached, and the decisions that produced that state were taken weeks earlier by people who needed no permission, because no permission gate existed. So the discussion is genuine, well informed, and applied to a period that is closed. Everyone leaves with the sensation of having governed.
The reviewers caught the same shape in the programme's relationship with its own organisation. The receiving business was connected to the programme, in their words, mainly at committee level. One channel, carrying decisions rather than understanding, into an organisation that would eventually have to run the result.
Three closed, nine open, and which three
The report ended with twelve recommendations, each traceable to one of four headline findings, and each carrying a status showing whether the programme had already moved on it while the review was still running. Three carried the mark for addressed. Nine did not.
The three that closed are worth naming, because they have something in common. Approving the plan with its scope, goals, timelines, stages and budgets. Producing the architecture and business design with its roadmap of end and intermediate states. Building out the detailed planning of those intermediate states. All three are documents the programme could author itself, at its own pace, with its own people.
The nine that stayed open include the one that would have changed the committee's position: define the monitoring and controlling levers, per stage gate, on the benefits case and on the delivery method. Alongside it sat the independent test of whether the chosen platform could carry the load, the design of an alternative route if it could not, a second plan for non-delivery, a standing quality assurance arrangement, and a commitment to retain the handful of people who understood the platform.
There is a pattern in that split and it is not laziness. Every item the programme closed was inside its own boundary. Every item left open required either an outsider's verdict, a decision the programme could not take alone, or a standing commitment that would outlive the current phase. Those are precisely the items a steering committee exists to force, and a committee with no levers cannot force them. One detail sharpens it: the recommendation to plan the intermediate states in detail was marked as addressed, while the recommendation that would have turned those intermediate states into control points was not. The programme built the ladder and nobody wired the rungs.
What the reviewers proposed instead
The remedy in the same document is sharper than the criticism, and all three parts of it were written for this programme rather than offered as a method.
First, make each intermediate state carry its own stated benefit. Not a phase, which only pays out when the next one completes, but a plateau that states what functionality has landed, what cost has come out and what revenue has arrived. A committee can stop at a plateau and still hold value. That is what makes it a lever rather than a milestone.
Second, split assurance in two. A short quality report at every steering committee meeting, on the programme's own rhythm, covering anything urgent, what had happened to the previous set of findings, and any new risk. Then a small number of deep assessments at the moments that decide things, each producing its own report whose recommendations have to be decided upon in the committee rather than noted. The reviewers also declared, in advance, what the next periods would examine, which converts assurance from an inspection into a forcing function: the programme knows the plan and the benefits case will be tested, so it produces them.
Third, anchor the calendar to gates rather than to quarters. Theirs hung on three: a first trial migration, the date the business had to be ready, and the opening of the selling season. Six of the eight checkpoints across the year were left undecided, because the detailed plan that would justify them did not exist yet. I have rarely seen an assurance plan decline to invent a date.
The same wiring, one technology later
The EU AI Act is in force, and every organisation I work with now has some body that meets about AI. Most of them are in exactly the condition described above. They receive a pack: pilots counted, copilots deployed, evaluation set scores, adoption percentages, an incident log. All of it accurate, all of it describing a period that closed before the meeting.
Ask what that body can pull and the answers thin out fast. Refusing to widen an agent's autonomy from drafting to acting works only where graded autonomy was defined as levels with a named holder of each promotion, which it usually was not. Withholding the next tranche until a benefit lands works only where the benefit was bound to a stage, and most agentic business cases carry the same five-way load as this one. Ordering an independent evaluation of the retrieval layer or the model provider works only where somebody outside the delivery team is empowered to run one.
This is what we build into a RealAI Agentic OS deployment before anything reaches production, and it is why model risk management, done properly, is delivery work rather than committee work. The controls that matter are the ones written into the gate, in units, with a named person who can say no.
A governing body without a lever is not governing. It is receiving an account of decisions already taken, and an account always arrives after the thing it describes.
Nothing in that review required the committee to be smarter or to meet more often. It required four sentences somebody had not written: what each stage delivers, in what unit, who checks it, and what happens if it is not there. Write those and the same meeting, with the same people, becomes an event the programme has to survive.
Drawn from an independent readiness check on a business-customer platform rebuild at a European energy retailer: four weeks of fieldwork, nineteen interviews across programme staff and steering committee members, and a review of programme documentation. It produced findings, recommendations and a proposed assurance model ahead of delivery, not delivered results. The reading of that governance gap against agentic programmes is ours.
“A governing body without a lever is not governing. It is receiving an account of decisions already taken, and an account always arrives after the thing it describes.”
Get in touch
Put RealAI’s applied-AI team on your hardest data problem.
We help enterprises move from pilots to production: sovereign models, governed data, and agents you can audit. Start with a value-first assessment.
