Most programs fail not because the technical solution didn't work — but because the governance was mismatched to the work. Jennifer Jones writes on the risk patterns leaders consistently miss.
"Governance, risk, and compliance — designed for how transformation actually works."
Early in my career, I inherited a PMO that was basically a paperwork factory. Status reports, templates, meeting minutes. No one was actually driving delivery — they were just documenting it.
Years later I sat as a program sponsor watching a dashboard that said everything was green. I knew it wasn't. I changed it to yellow myself, because the reporting structure wasn't built to surface what was actually happening.
And then there was the loyalty program migration — old system going end-of-life, four interdependent vendors, no CMO in place to make the call when decisions stalled. We ran daily standups that functioned as the decision-making structure that was supposed to exist but didn't. It shipped in four months. It's still running today, twenty years later.
Three different jobs, three different decades, same root problem: the governance wasn't built for the kind of work it was supposed to manage.
That's what I work on now. Building the structures — decision rights, escalation paths, risk visibility — that actually fit the work in front of them, instead of generic process that looks good in an audit and tells you nothing about what's really happening.
I'm IT Director of Enterprise Systems Delivery at Choctaw Nation of Oklahoma. I was brought on board to lead our Oracle Cloud implementation, built the organization's first enterprise PMO, and now manage our project management, business systems analyst, and business relationship management teams. I write about the governance patterns I keep running into, at GRC by Design.
These are the short versions, published weekly on LinkedIn. The full breakdown, with a diagnostic you can run on your own portfolio, goes to Design Notes subscribers. Subscribe →
Most organizations think they manage risk. What they actually manage is reports — and the gap between the two is where transformation programs quietly fail.
Consistency feels like maturity. But when fundamentally different types of work are governed the same way, risk visibility deteriorates.
The most dangerous program I ever assessed was showing all green. RYG dashboards don't lie — they just don't tell the whole truth.
Academic papers and practitioner sessions presented at professional and academic conferences. Papers available on request.
Whether you're navigating a complex transformation, building a PMO from scratch, or trying to understand why your programs keep missing the mark — get in touch.