Published 2026-08-25 · EuroQuest International
Quick summary
A steering group meets monthly. The project manager presents a deck, the status is amber for the fourth quarter running, and the group notes the risks and agrees to keep monitoring. Eighteen months later the program is two years late and the business case no longer holds. Every meeting took place. Minutes exist. Nobody on that group could point to a moment when they were asked a question they could have answered no to.
That is the difference between governance and reporting, and it is the whole subject. This guide sets out what project governance actually covers, who holds which decision, how stage gates work when they work, what assurance is for, and the failure patterns that public audit offices document again and again because they are the same failures everywhere.
On this page
Project governance is the arrangement of authority around a project: who may approve it, who may change it, who may stop it, and on what evidence. It is not the project plan, not the reporting pack, and not the steering group's calendar. Those are outputs. Governance is the answer to a simpler question: when this project needs a decision that the project manager cannot take, who takes it, and what do they have to see first.
Public auditors describe it in almost the same terms. The United Kingdom's National Audit Office, reviewing lessons from mega-projects, treats governance as the system that frames how an organization or project is managed and how decisions get made, covering formal structures and processes as well as people and behavior, and it stresses clarity about who holds authority and accountability. The behavioral half is the part organizations skip.
The cleanest test is whether a body can say no. A project manager runs scope, schedule, cost, quality, risk and the team within a mandate. Governance owns the mandate itself: the objectives, the tolerances, the funding release, and the authority to withdraw it. If a group can only receive information, it is a reporting forum, whatever it is called.
Setting that boundary explicitly, rather than assuming everyone shares the same picture of it, is the starting point of project governance frameworks and best practices.
Governance discipline exists because the sums are large and the failures are slow. At 31 March 2024 the United Kingdom's Government Major Projects Portfolio, which the National Audit Office describes as the government's largest, most innovative and most risky projects, contained 227 projects with a combined whole-life cost of 834 billion pounds. That is a snapshot of one portfolio at one date rather than a current figure, and the portfolio has been reported on annually since, but the order of magnitude is the point: at that scale, an unmanaged decision is not a delay, it is a public inquiry.
Most governance failures are not disagreements. They are gaps: a decision that nobody was formally allowed to take, so it was taken informally, or not at all.
A single named individual owns the business case, the benefits, and the decision to continue. Committees deliberate; they do not carry accountability, because accountability shared five ways is accountability nobody feels. When the sponsor changes three times in a long project, the business case usually stops being defended by anyone.
A project board or steering group exists to authorize each stage, to decide changes beyond the manager's tolerance, and to close the project when it no longer earns its funding. A board that has never stopped anything has not proved it can. Framing the questions so that stopping is a live option, rather than an admission of failure, is the practical content of decision making in project environments.
How much cost variance may the project manager absorb before escalating? Which scope changes need the board and which need the sponsor alone? What happens when a decision is needed between meetings? Written tolerances turn those into procedure. Unwritten ones turn them into whoever is most confident in the room.
Where the organization is public, donor-funded, or regulated, those limits also have to satisfy an external rulebook, which is where project governance and compliance becomes a technical subject rather than an administrative one.
| Decision | Who holds it | What they need to see | Failure mode |
|---|---|---|---|
| Start or continue | Sponsor, endorsed by the board | Business case, current estimate, benefits still credible | Approval based on the original case nobody has revisited |
| Release the next tranche of funding | Project board at a stage gate | Gate evidence, independent assurance, revised forecast | Funding released on schedule rather than on evidence |
| Change beyond tolerance | Board, or sponsor within written limits | Impact on cost, schedule, benefits and other projects | Change absorbed quietly because no limit was written |
| Accept a risk | The named risk owner at the right level | Exposure, mitigation cost, who carries the consequence | Risk logged, discussed monthly, never actually owned |
| Stop the project | Sponsor and board together | What continuing costs against what it now returns | Never on the agenda, so the budget decides instead |
| Close and hand over | Board, on the sponsor's recommendation | Deliverables accepted, owner named, lessons captured | Team dispersed before anyone owns what was built |
A stage gate is a scheduled point at which the organization decides whether to fund the next phase. Its value is entirely in the decision, and its cost rises the later it comes: stopping at design costs a study, stopping at delivery costs a program.
The distinction matters because gates are easy to hollow out. If the gate paper arrives after the contracts are signed, the gate is theater. If the only possible outcomes are pass and pass with actions, it is a checkpoint. A real gate has a fail state that the organization has used at least once.
Heavy processes get relaxed for good reasons, and doing that deliberately is itself a governance decision. NASA's lunar lander program is an instructive case: its oversight office records that, instead of the standard series of technical milestones used for major acquisitions, the program relies on a reduced number of reviews and data submissions to encourage innovation and reduce costs, while each provider still takes part in the preliminary design review and the critical design review.
The cost outcome on that program has held up so far. The potential value of the larger lander contract has grown by about 6 percent since award, and the second provider's by less than 1 percent. Two cautions belong with that figure: it measures growth against the original potential contract value rather than money spent, and the same reporting notes that schedule has moved. Cost control bought partly with time is still cost control, but it is not the same as delivering on plan.
Gates approve numbers, and numbers approved with categories missing are the most durable governance failure there is. Canada's auditor general examined a replacement government pay system and found a preliminary estimate of roughly 4.2 billion Canadian dollars that did not include the costs for departments and agencies to move onto the new system. Nothing in that estimate was wrong. It was simply not the whole number, and it is the whole number that a gate is approving.
In practice
Take the last three gate decisions your organization made and ask two questions of each. First, what evidence was in front of the board that could have produced a no, and was it independent of the team asking for the money? Second, what did the approved estimate exclude, and who was told. Most organizations find that the papers argued for approval rather than testing it, and that at least one estimate quietly left out transition, decommissioning, or the cost of running the old system in parallel. That review takes an afternoon and changes the next gate more than a new framework will.
Three things separate governance that holds from governance that merely meets. None of them is a document template.
Assurance means somebody who does not report to the project tells the board what they see. It can be internal audit, a peer review, a technical panel, or an external reviewer, and its defining feature is that its conclusions are not filtered by the people being reviewed. The moment assurance is drafted by the delivery team, the board is reading the project's own opinion of itself.
On complex programs the same discipline extends to the risk picture, where independent challenge of assumptions is often the only thing that surfaces an exposure early enough to act on. That is the working content of risk management in complex projects.
Schedule drift is the most visible symptom, and it accumulates quietly. Australia's national audit office reports that across the 21 projects in its 2024-25 major projects report, the sum of individual project slippage is 404 months, measured from the original approval milestone for final operational capability. Read that carefully: it is the total of every project's delay added together, not the delay of one program, and because projects get re-baselined the running total understates historical drift. It is still 404 months of decisions that were made later than intended.
Governance at that level is portfolio work, not project work. Deciding which projects start at all, which are paused when capacity runs short, and which are stopped so others can be funded properly is the subject of project portfolio management best practices.
Every project in a portfolio should trace to something the organization said it wanted. Where that trace cannot be drawn, the honest conclusion is either that the strategy is unclear or that the project is orphaned, and both are governance findings. Making the trace explicit at approval, rather than asserting it in a slide, is what strategic alignment of projects and business goals sets out to do.
Projects end in three ways: delivered, stopped, or abandoned by attrition. Only the first two are governed. Closure means the board accepts what was delivered, names who now owns it, releases the team formally, and records what the organization learned while the people who learned it are still available. That last step is almost always the one dropped, which is why project closeout and lessons learned exists as a subject in its own right.
A governance health check
EuroQuest International runs project management and planning programs in Amsterdam, Brussels, Geneva, Dubai, and Cairo, covering governance frameworks, decision rights and tolerances, stage gates and assurance, portfolio prioritization, risk on complex programs, and structured closure for project boards, sponsors, project and program managers, and the audit and finance colleagues who review them.
It is the arrangement of authority around a project: who may approve it, who may change it, who may stop it, and what evidence they need before deciding. It covers the named decision rights, the stage gates at which funding is released or withheld, and the independent assurance that tells the board what it would not otherwise hear. It is a decision system, not a reporting routine.
Project management delivers the work inside an agreed mandate: scope, schedule, cost, quality, risk, and the team. Governance owns the mandate itself and the authority to change or withdraw it. The practical test is whether a body can say no. If a group only receives updates and never refuses a request, it is a reporting forum rather than a governance body, whatever the terms of reference call it.
A scheduled point at which the organization decides whether to fund the next phase, based on evidence rather than on the calendar. A real gate has a fail state: the project can be stopped or sent back. Gates can legitimately be tailored, and heavily tailored gate sets are used on some major programs to speed delivery, but tailoring is a deliberate governance decision that should be recorded, whereas skipping a gate is simply an unmade decision.
Usually for four reasons. The sponsor is a committee rather than a person, so nobody carries the business case. Delegated limits were never written, so escalation depends on personality. Gates arrive after the commitments they were meant to test. And the estimate approved at the gate excluded whole categories of cost, such as transition or running the old system in parallel, so the board approved a number that was never the number.
Project and program managers who prepare gate papers, sponsors and project board members who approve them, portfolio and project office staff who run the process, and the risk, audit, legal and finance colleagues who review project decisions. Public sector, donor-funded and regulated organizations gain most from the compliance and assurance content, because their decisions have to be defensible to an outside reviewer as well as internally.
EuroQuest International delivers project management and planning programs covering governance frameworks, decision rights, stage gates and assurance, portfolio prioritization, risk on complex programs, and structured closure, in Amsterdam, Brussels, Geneva, Dubai, and Cairo.
Explore Project Management and Planning Programs