Governance · Objectives · Board

Governance: setting the right objectives

Of the three letters in the acronym, the G is the most neglected. We tool risks, we document compliance — and we take objectives for granted. Yet without explicit objectives, a risk map floats: it lists hazards without saying what they are obstructing.

Category: Governance Reading time: 7 minutes

Governance consists in reliably achieving the right objectives. Two requirements lie within it: choosing the relevant objectives, and giving oneself the means to achieve them effectively. The first is the responsibility of the board of directors and management; the second engages the whole organisation.

The right goals

The anchor point of the entire apparatus

Risk appetite

A board decision, not a technical exercise

To report

Piloting requires being able to demonstrate

01

What the «G» covers»

This definition has a direct consequence: governance is not a matter of formal compliance. Holding meetings, drafting policies and documenting delegations are means, not ends. The fundamental question remains: do these mechanisms help the organisation achieve what it aims for?

02

The blind spot: implicit objectives

Most control mechanisms rely on objectives that are never formulated. Everyone believes they know them; no one has written them down. The symptom is easy to spot: ask a risk mapping exercise which objective each major risk relates to. If the answer fits into a generic category — «operational», «regulatory» — the link to objectives has disappeared.

Why this matters: A risk only exists in relation to an objective. Without an explicit objective, scoring becomes an abstract assessment, and prioritisation an exercise in opinion. This is one of the most frequent causes of bulky and largely useless risk maps.

Drafting objectives does not require a heavy strategic exercise. A clear formulation, accompanied by a timeframe and a success indicator, is enough to anchor the mechanism.

03

Risk appetite: a decision, not a calculation

Setting objectives involves deciding what level of risk the organisation accepts to achieve them. This decision rests with the board. It is often delegated, by default, to technical functions which produce thresholds — which are not governance choices, but parameters.

A useful risk appetite is formulated in terms that are intelligible to a board member: which risks the organisation is prepared to take in order to grow, which ones it refuses regardless of the potential reward, and where the grey areas lie. Once translated into operational thresholds, it gives management a framework for decision-making without having to systematically refer back to the board.

04

The instruments of governance

  • The authorities. Board, specialist committees, management committee: their composition, frequency and information condition the quality of decisions.
  • Politicians. They translate guidelines into applicable rules. A policy that no one consults is a documentary risk, not a control measure.
  • The delegations. Who decides what, within which limits: that is the operational translation of risk appetite.
  • Reporting. Without reliable and consolidated information, the board oversees blindly.
  • Independent insurance. Internal audit gives the board a management-unfiltered view of how the system actually operates.

Once these instruments have been defined, their effectiveness also depends on the ability to maintain a clear vision of what has been decided, validated and monitored. Bringing together documents, approvals and actions in a shared environment makes preparing for meetings easier and makes governance easier to demonstrate.

05

Luxembourgish specificities

For a regulated entity, the internal governance framework is not optional. The Commission de Surveillance du Secteur Financier (CSSF) expects a clear organisation of responsibilities, an authorised management body effectively in charge, independent control functions and documentation making it possible to demonstrate all of this.

Two points deserve particular attention. First, the substance responsibilities must be genuinely exercised in Luxembourg, not just formalised. Then, the decision traceability A governance mechanism is judged just as much by its minutes, its approvals and its follow-ups as by its organisational charts.

06

Common pitfalls

  • Treating governance as a paper exercise, disconnected from real management.
  • Leaving the objectives implicit, which deprives risk mapping of its anchor.
  • Delegating risk appetite to a technical function, in the absence of board arbitration.
  • Multiplying policies without ensuring their dissemination or updating.
  • Confusing the formal presence of governing bodies with the actual quality of decisions.
07

The ARCAD approach

ARCAD starts from objectives and the reality of management, rather than documents. The approach consists of making explicit what the organisation is trying to achieve, formulating a risk appetite that can be utilised by management, and then verifying that governance bodies, policies and delegations actually serve these objectives — rather than constituting an additional administrative layer.

Anchor your device around explicit objectives.

ARCAD supports boards and management teams in formulating objectives, risk appetite and the governance framework.

Schedule an exchange →

References & further reading

  • OCEG works (Open Compliance and Ethics Group) on the governance dimension of GRC.
  • Enterprise risk management frameworks (COSO ERM) — alignment of objectives and risks.
  • Internal governance framework applicable to CSSF-regulated entities.

Note: Good practice to be adapted to the profile, size and regulatory framework specific to each organisation.