Corporate Governance and Risk Oversight — Jonas Osman Abdelfour
Board and executive governance that connects strategy, risk appetite, controls, accountability, performance and regulatory expectations into a coherent system.
Strong governance is what allows a firm to take risk deliberately. It sets the boundaries within which management operates, defines who decides what, and ensures that decisions are challenged, documented and reviewed. Without it, risk frameworks become paperwork.
Governance as an operating system
Governance work covers the design of board and committee structures, delegation of authority, terms of reference, decision rights, escalation procedures, and the flow of information that allows the board to discharge its responsibilities. Risk appetite and risk culture are treated as central governance instruments, not as add-ons.
What this work covers
A representative — not exhaustive — set of areas addressed in engagements of this type.
- Board responsibilities
- Board risk committees
- Senior-management accountability
- Delegated authorities
- Risk appetite framework
- Risk culture
- Policy governance
- Committee terms of reference
- Conflict-of-interest controls
- Decision rights and escalation
- Management information design
- Assurance and challenge
- Internal audit coordination
- Regulatory accountability regimes
- Governance effectiveness reviews
How it operates in practice
Governance reviews evaluate structure, composition and process against the firm's risk profile and regulatory context. Committee packs, minutes and decisions are tested for whether they show evidence of challenge, whether risk appetite is used to frame decisions, and whether escalation and follow-through are demonstrable.
Recommendations focus on making governance materially more effective: sharper agendas, clearer accountabilities, better MI, and a coherent link between strategic decisions, risk appetite and control performance.
Related insights
All insights →- Governance & GRCHow to design an effective GRC framework
A practical model for integrating governance, risk and compliance around a common taxonomy, appetite and reporting architecture.
- Governance & GRCCommon failures in governance structures
Where board and committee governance most often breaks down — and how to design out the common failure modes.
- Governance & GRCRisk ownership and accountability under the three-lines model
Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.
- Governance & GRCWhat good board risk reporting looks like
Design principles for board risk reporting that focuses committees on decisions rather than description.