Hardest Problems in Enterprise Governance Don't Have Framework Answers

Governance frameworks are excellent tools for the governance problems they were designed to solve. NIST CSF provides structure for cybersecurity risk management.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

GDPR provides a legal framework for personal data protection. ISO 27001 provides an ISMS structure. Each framework solves the problem its designers had in mind. The hardest governance problems practitioners encounter in enterprise environments are the ones that fall between frameworks, that require synthesizing guidance from multiple frameworks that conflict, or that represent genuinely novel challenges that no framework yet addresses. These problems require judgment, not framework application.

The Problems That Fall Between Frameworks

Enterprise governance operates at the intersection of multiple frameworks simultaneously. A company subject to GDPR, ISO 27001, SOC 2, and NIST CSF has four overlapping governance requirements that were each designed independently, that use different terminology for similar concepts, and that occasionally conflict in their specific requirements. The governance practitioner who must satisfy all four simultaneously is not reading from a unified playbook — they are synthesizing guidance from four separate playbooks that were written by different authors for different purposes.

The synthesis problem is not purely administrative. It requires judgment about which framework's requirements take precedence when they conflict, how to design a single control that satisfies multiple frameworks' requirements efficiently, and how to explain a compliance position to an auditor from one framework who is not familiar with the requirements of the others. These are judgment problems. The frameworks do not solve them. They create them.

Every additional framework an organization adopts creates new synthesis requirements. The organization with five frameworks does not have five times the governance work of an organization with one framework. It has an order-of-magnitude more synthesis work, because each combination of frameworks creates new intersection problems.

The Problems That Frameworks Do Not Yet Address

Governing AI Systems That Evolve Faster Than Frameworks

The EU AI Act was finalized after years of drafting. It addresses the AI systems that existed when it was drafted. Agentic AI, generative foundation models, and AI-to-AI interaction patterns have emerged or matured since the Act was finalized. The governance practitioner who needs to govern a multi-agent AI system where agents communicate with each other to produce outputs that affect individuals is applying frameworks that were not designed for this architecture. The framework provides useful guidance that can be extrapolated. It does not provide the specific answer.

Governing Data in AI Training Pipelines Under Privacy Law

GDPR was designed for data processing by humans and human-controlled systems. An AI training pipeline that processes billions of data points to learn statistical patterns is doing something fundamentally different from a database query that retrieves a customer record. The legal concepts of processing, purpose, and data subject rights translate to the training context only with significant extrapolation. The right to erasure applied to a model that has learned from a data subject's data requires determining what 'erasure' means for a statistical pattern embedded in model weights — a question that neither privacy law nor AI governance frameworks have definitively answered.

Balancing Security and Privacy in Operational Practice

Security and privacy are usually described as aligned: protecting data is both a security and a privacy objective. They conflict in specific operational situations that practitioners encounter regularly. Security monitoring that requires collecting detailed logs of user behavior conflicts with data minimization principles. Security incident response that requires preserving all potentially relevant data conflicts with data retention limits. Security requirements for authentication that include biometric data conflict with the legal requirements for processing biometric data as special category data. The practitioner who must implement both security requirements and privacy requirements in the same system is solving a problem that neither the security framework nor the privacy framework addresses.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

Building the Judgment Capability

The governance capability that solves the hardest problems is judgment — the ability to reason from principles when specific rules do not apply, to synthesize guidance from multiple sources when they conflict, and to make defensible decisions in genuinely novel situations. Judgment is built through experience, through collaboration with practitioners who have faced similar problems, and through disciplined reasoning from first principles when precedent does not exist.

Organizations that build this judgment capability do so deliberately. They invest in experienced practitioners who have encountered these problems before. They create forums for practitioners to share difficult governance decisions and the reasoning behind them. They document their reasoning in difficult cases so that future decisions can build on the reasoning rather than starting from scratch. They treat governance as a practice that develops over time rather than as a compliance process that can be executed from a checklist.

The frameworks are essential starting points. They provide structure, vocabulary, and specific guidance for the large majority of governance situations that organizations face. For the governance problems they do not address, the practitioner with good judgment is more valuable than the practitioner with extensive framework knowledge. Both are needed. The frameworks can be learned. Judgment must be developed.

Develop governance judgment alongside governance framework knowledge. The frameworks solve the problems they were designed for. Judgment solves the rest.

The governance framework is the floor. Judgment is the ceiling. Build both.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.