3.2 Governance Frameworks, Policies and Delegated Responsibility
Key Takeaways
- The organisation’s governance approach — policies, regulations, functions, processes, procedures, and delegated authority — informs how each project is governed.
- Project governance is a tailored subset of corporate rules, not something each project manager invents from scratch.
- Delegated responsibility exists so timely decisions can be made without every item returning to the board.
- Bypassing a control does not remove the exposure it manages; it moves that exposure somewhere less visible.
- Governance must be proportionate to value, risk, and novelty — disproportionate control produces compliance theatre rather than assurance.
Two learning outcomes meet in this section. Outcome 2a closes with the requirement to know that an organisation's governance approach will inform the approach used for a project; outcome 2c requires you to understand why aspects of project management governance are required — policies, regulations, functions, processes, procedures, and delegated responsibilities. Treat them as one chain: corporate rules cascade down, and delegation is how they are made workable at project level.
How Corporate Governance Cascades to Project Governance
The syllabus states that an organisation’s governance approach will inform the approach used for a project. Project governance is not invented from scratch by each project manager. It is a tailored subset of corporate rules.
Typical cascade:
- Corporate / enterprise governance — board-level duties, risk appetite, financial control frameworks, legal and regulatory compliance, ethics, and strategy.
- Portfolio / programme governance — prioritisation of investments, funding envelopes, dependency management, and benefits ownership across multiple change initiatives.
- Project governance — project board or steering group, sponsor accountability, delegated tolerances, reporting cadence, stage gates or iteration reviews, and change-control thresholds.
If the organisation requires independent assurance for high-risk change, regulated data handling, or capital expenditure above a threshold, those requirements appear in the project’s governance framework (terms of reference, decision rights, mandatory reviews). A project that tries to “skip governance to go faster” is usually misaligned with organisational practice and will fail assurance or gate reviews.
Policies, Regulations, Functions, Processes, Procedures, and Delegated Responsibilities
The syllabus asks why aspects of project management governance are required. Use these building blocks precisely:
| Element | What it is | Why it is required on projects |
|---|---|---|
| Policies | High-level statements of intent and rules (e.g. risk policy, information security policy) | Set non-negotiable boundaries the project must respect |
| Regulations | External legal or industry requirements | Create mandatory constraints (safety, data protection, financial conduct) |
| Functions | Standing organisational capabilities (finance, PMO, legal, assurance, HR) | Provide specialist control, advice, and independent challenge |
| Processes | End-to-end flows for how work is controlled (change control, risk escalation, gate review) | Create repeatable decision paths and audit trails |
| Procedures | Detailed how-to steps within processes | Reduce variation and ensure consistent execution |
| Delegated responsibilities | Authority assigned downward within limits | Enable timely decisions without every item returning to the board |
Without these, projects rely on personality and ad hoc negotiation. That may work for tiny internal tasks; it fails for investments where sponsors, users, regulators, and suppliers need predictable accountability.
Delegated authority is especially examinable. A sponsor or steering group cannot approve every purchase order. They set limits of financial authority (and often schedule/scope/risk tolerances) so the project manager can act within bounds and must escalate beyond them. Escalation is not failure — it is correct governance when the decision would change business justification, strategic fit, or exposure outside agreed appetite.
Why "we skipped governance to go faster" is always the wrong answer
Exam scenarios often present governance as friction: a sponsor wants speed, a team resents paperwork, an approval is "slowing us down". The examinable judgement is that governance is the mechanism that makes speed safe, and that removing it transfers risk rather than removing it.
Work the trade-off explicitly in an answer:
| What was skipped | What it was protecting | Where the risk lands instead |
|---|---|---|
| Gate review before build | Confirmation that the business case still holds | Organisation funds a project that no longer pays back |
| Procurement procedure | Fair, auditable supplier selection and contract terms | Legal challenge, unenforceable terms, audit finding |
| Change control | Integrity of the baseline and of reporting | Nobody can say what "on plan" means any more |
| Information security policy | Regulatory compliance and data subjects | Breach, fine, reputational damage |
| Delegated authority limits | Alignment of spend with those accountable for it | Unauthorised commitment the sponsor must defend |
The correct response in a scenario is almost never "comply because the rules say so". It is: identify which control is being bypassed, name the exposure that control exists to manage, and propose the proportionate route — an expedited review, a delegated decision within limits, or a documented and approved exception — rather than a silent omission.
Proportionality is part of good governance
Governance that ignores scale is its own failure mode. A £30,000 internal process change does not need the assurance regime of a £300m infrastructure programme, and imposing one produces theatre: forms completed to satisfy a process nobody believes in. APM's framing is that governance must align with organisational practice — which includes the organisation's own rules about what level of control applies at what value, risk, or novelty. In an answer, say what tier of control the scenario's project falls into and why, rather than asserting that more governance is always better.
How does an organisation’s overall governance approach relate to a project’s governance framework?
A sponsor asks a project manager to appoint a supplier without running the organisation’s procurement procedure, arguing that the timescale is too tight. What is the most appropriate response?