Strategic Governance as a Service: The Architecture of Governance Failure
This is the full, openly readable text of the Marentis Labs research white paper by Owen Vallis. It documents why more governance has not produced better governance, and sets out Strategic Governance as a Service — a continuous, adversarial, principal-led alternative. The formatted 90-page edition is available as a downloadable PDF.
Full contents
- The Governance Paradox
- The Theory of Governance Failure
- The Evidence of Governance Failure
- The Regulatory Direction
- The Value Gap in the Three Lines Model
- Why Traditional Advisory Models Under-Deliver
- Defining Strategic Governance as a Service
- The Adversarial Governance Methodology
- The Four-Tier Architecture
- The Economic Case
- Objections and Responses
- Implementation and Conclusion
Executive Summary
Spending on governance, risk management, and compliance has never been higher. The global GRC market is estimated at approximately USD 72 billion in 2025 [1] and is growing at over 13% annually [1]. Regulatory requirements have proliferated across every major jurisdiction and organisations across all sectors of the global economy have invested in risk committees, internal audit functions, compliance teams, and external advisory. Yet the frequency and severity of governance failures has not decreased.
Boeing’s 737 MAX programme killed 346 people [2] and cost the company an estimated USD 20 billion, including the largest Caremark derivative settlement in Delaware history. This despite the presence of a full complement of governance structures commensurate with its status as an S&P 100 company, with a board, an audit committee, an internal audit function, external auditors, and regulatory oversight from the FAA. The Post Office prosecuted more than 900 sub-postmasters over two decades while every layer of its governance architecture, from branch-level management to the board to external legal advisers, failed to adequately challenge a system that was known to be flawed [3]. Wirecard’s EUR 1.9 billion fraud [4] survived scrutiny from a supervisory board, internal audit, a "Big Four" external auditor, and BaFin as regulator. All five governance layers were present and all five failed. Silicon Valley Bank collapsed in 48 hours despite having risk committees, an internal audit function, and regulatory oversight [5].
These are simply some of the high profile and well documented consequences of a structural problem. More governance infrastructure has not produced better governance outcomes. This paper calls this the Governance Paradox, and argues that the paradox has an identifiable cause and a structural solution.
The catastrophic cases that make global headlines are the extreme anchor points. The more common consequence of the same structural defects by far, is quieter, insidious value destruction, manifesting as failed M&A integrations, missed technological pivots, and the slow erosion of competitive position that no governance function is mandated to challenge. Empirical evidence from 669 listed companies across Germany, Austria, and Switzerland [6] shows that 32% suffered at least one severe corporate crisis between 2018 and 2024, and that over 80% of those events were driven by strategy and external risks, not by compliance failures. The structural defects that produce billion-pound corporate implosions also produce routine, chronic value destruction. The economic case for addressing these defects depends on preventing the strategic drift that compounds, unchallenged, for years.
The Diagnosis
Governance failures occur despite the application of a range of frameworks because of three systemic defects in how oversight is delivered:
Episodic engagement. Boards engage with risk on periodic cycles, through quarterly risk reports, annual strategy reviews, and scheduled committee meetings. But risks do not evolve on quarterly cycles. The result is governance by snapshot rather than by signal, i.e. boards see the risk environment as it was at the last reporting date, not as it is when decisions are made.
Consensus dependency. Board decision-making is structurally biased toward satisficing; accepting the first option that achieves group agreement rather than stress-testing for the most resilient path. This is a predictable consequence of bounded rationality operating in a group setting, compounded by what Kahneman, Sibony, and Sunstein identify as "noise" [7], i.e. the variability in professional judgement that even qualified decision-makers produce under identical conditions.
Absence of institutionalised challenge. No permanent function exists within most governance architectures whose explicit purpose is to challenge assumptions, stress-test decisions, and surface failure modes before they materialise. Internal audit, the function nominally positioned for this role, spends 75% of its capacity on routine assurance and compliance [8]. Risk management functions face ever increasing funding constraints for emerging-risk identification, consuming their bandwidth on business-as-usual monitoring and regulatory reporting. Neither has the mandate, the capacity, or the methodology to act as a continuous, adversarial challenge function at board level.
The Evidence
This paper examines these three defects through multiple lenses. It traces their theoretical foundations in bounded rationality, decision noise, and the structural limitations of the Three Lines model. It documents their consequences through five extended case studies, namely Boeing, Wirecard, Silicon Valley Bank, Credit Suisse1, and The Post Office. Each shows how the same structural defects produced catastrophic outcomes across different sectors, jurisdictions, and regulatory regimes. It maps the regulatory direction across the United Kingdom, European Union, and United States, demonstrating a convergence toward the very capabilities the current model cannot deliver, namely continuous oversight, effective challenge, and personal accountability.
It then examines the value gap in the Three Lines model, the measurable space between what the model is supposed to deliver and what it actually delivers in practice. It shows why traditional advisory models cannot fill that gap.
The Response
Strategic Governance as a Service (SGaaS) is the structural response to these three defects. Developed and originated by Marentis Labs, SGaaS replaces episodic oversight with continuous engagement, consensus dependency with adversarial challenge, and the absence of institutionalised challenge with a permanent, principal-led governance function that operates at board level.
SGaaS is not a replacement for internal functions, it is the resilient challenge layer that fills the structural gap the Three Lines model leaves open, through which so many corporate failures have burst.
This paper presents the evidence, the theory, and the architecture for that response. It does so with the intellectual discipline the subject demands, remaining conservative in its claims, honest about limitations, and rigorous in its sourcing. The structural defects those failures reveal are identifiable, addressable, and, for organisations willing to commission genuine challenge, solvable. This paper makes no claim that SGaaS would have prevented every failure documented in these pages; it claims that the architecture described here would have changed the information available to decision-makers, and the timing at which it arrived.
Paper Structure
| Phase | Purpose | Sections |
|---|---|---|
| I. The Problem | Establish the governance paradox through evidence and theory | Executive Summary; The Governance Paradox; The Theory of Governance Failure; The Evidence of Failure |
| II. The Context | Regulatory convergence, the Three Lines value gap, and the limits of existing models | The Regulatory Direction; The Value Gap in the Three Lines; Why Traditional Models Under-Deliver |
| III. The Response | Define SGaaS, its methodology, architecture, and economic case | Defining SGaaS; The Adversarial Methodology; The Four-Tier Architecture; The Economic Case |
| IV. The Test | Stress-test the proposition through objections, implementation, and conclusion | Objections and Responses; Implementation Blueprint; Conclusion |
The author was previously employed at Credit Suisse. Views expressed are based on public-record analysis only.↩︎
References (Executive Summary)
- Grand View Research. (2025). Governance, Risk Management and Compliance Market Size, Share & Trends Analysis Report. Grand View Research.
- U.S. House Committee on Transportation & Infrastructure. (2020). Final Committee Report: The Boeing 737 MAX: A Failure of Management, Engineering Culture, and the FAA's Aircraft Certification Process. U.S. House of Representatives.
- Sir Wyn Williams. (2025). Post Office Horizon IT Inquiry: Final Report. Post Office Horizon IT Inquiry. https://www.postofficehorizoninquiry.org.uk/
- KPMG. (2020). Report Concerning the Independent Special Investigation, Wirecard AG, Munich. KPMG. https://web.archive.org/web/20220307204458/https://www.wirecard.com/uploads/Bericht_Sonderpruefung_KPMG_EN_200501_Disclaimer.pdf
- Michael S. Barr. (2023). Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank. Board of Governors of the Federal Reserve System. https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf
- Stefan Hunziker et al.. (2025). Corporate Crises in Germany, Austria, and Switzerland: Empirical Evidence on Risk Drivers. ERM Report 2025. Institute of Financial Services Zug IFZ, Lucerne School of Business.
- Daniel Kahneman et al.. (2021). Noise: A Flaw in Human Judgment. Little, Brown Spark.
- Institute of Internal Auditors. (2024). Internal Audit Vision 2035: Creating Our Future Together. Internal Audit Foundation. https://ia-vision2035.org/