Objections and Responses
Boards raise reasonable objections to a continuous adversarial challenge function: cost, overlap with existing assurance, disruption and independence. This chapter states each objection directly and answers it, setting out where SGaaS complements rather than duplicates the existing governance stack.
Six objections deserve direct answers. Governance professionals, from board directors to risk committee chairs to chief risk officers, are trained to interrogate propositions and probe their potential weaknesses. This section subjects SGaaS to the scrutiny its own methodology demands.
The objections addressed below are the questions that emerge consistently when the model is presented to governance practitioners, raising matters of independence, adoption willingness, scalability, fiduciary conflict, and intellectual originality. Each deserves a direct and honest response.
"If SGaaS Is Paid for by the Company, How Is It Independent?"
This is the most important objection, and the paper acknowledges it directly. Any externally provided governance function that is paid by the entity it serves faces a structural tension between commercial interest and independent judgement. This tension is real, and no amount of rhetorical framing can eliminate it.
But the objection, taken to its logical conclusion, would eliminate every externally provided assurance and governance function. External auditors are paid by the companies they audit. Credit rating agencies are paid by the issuers they rate. Management consultants are paid by the management teams they advise. The question is not whether a commercial relationship exists. It does, in every case. But the structural safeguards are sufficient to preserve functional independence despite it.
The SGaaS model addresses independence through four structural mechanisms:
First, the mandate. The SGaaS principal reports to the board or committee chair, not to management. The engagement terms are approved by the board. Management cannot direct, constrain, or veto the SGaaS function’s findings. This reporting structure is fundamentally different from consulting engagements, where management typically controls scope, access, and deliverable acceptance.
Second, the methodology. The adversarial methodology (red teaming, risk simulation, pre-mortem analysis) is structurally designed to produce challenge. A red team that does not challenge has failed, regardless of the commercial relationship. The methodology creates institutional pressure toward independence that complements the structural safeguards.
Third, the commercial model. The retainer structure eliminates the project-by-project revenue dependency that creates the most acute independence risk in traditional advisory. The SGaaS principal is not competing for the next project; the engagement is continuous by design. This removes the incentive (identified by Bazerman and colleagues in their analysis of auditor independence) to moderate findings to secure future work.
Fourth, the market discipline. SGaaS is a reputational business. A governance challenge function that fails to challenge (that tells boards what they want to hear rather than what they need to hear) will be exposed by the first governance failure it fails to prevent. The commercial incentive, properly understood, runs toward rigour rather than away from it.
The honest answer: SGaaS cannot claim perfect independence. No externally provided function can. What it can claim is that its structural design (mandate, methodology, commercial model, and market incentive) creates stronger independence safeguards than any existing alternative for governance challenge at board level.
"Boards Won’t Voluntarily Adopt a Function Designed to Challenge Them"
Some won’t. This paper does not pretend otherwise. Boards that are satisfied with their governance architecture, that believe their existing oversight mechanisms are sufficient, or that are simply unwilling to subject themselves to structured adversarial challenge will not engage SGaaS. That is their prerogative.
But three forces are making voluntary adoption increasingly rational.
The regulatory direction is unmistakable. Provision 29 requires boards to declare on the effectiveness of material internal controls (a declaration that requires evidence of continuous monitoring, beyond the existence of governance structures). The Caremark doctrine’s evolution through Marchand and Boeing has increased personal director liability for oversight failures of mission-critical risks. SM&CR imposes personal accountability on senior managers. Boards that recognise this trajectory understand that proactive governance investment is preferable to regulatory-forced remediation.
The case studies are compelling. Every governance failure documented in Section 4 (Boeing, Wirecard, SVB, Credit Suisse and The Post Office) occurred in an organisation that had a full complement of governance structures. The failures were not failures of framework but failures of challenge. Boards that have studied these cases, or that have experienced near-misses in their own organisations, are precisely the audience for whom SGaaS is designed.
The entry point is low-risk. The tiered architecture is specifically designed to address adoption resistance. The Diagnostic tier offers a four-to-eight-week assessment with defined scope and deliverables (a low-commitment engagement that allows boards to experience the value of independent governance challenge before committing to an ongoing relationship). It is an invitation to test the proposition before making any permanent structural commitment.
"How Does This Scale Without Diluting Quality?"
SGaaS does not scale in the conventional sense. That is a deliberate design choice.
SGaaS is a principal-led model. The governance challenge is delivered by the principal (a senior practitioner with the authority, experience, and institutional knowledge to engage credibly at board level). Unlike audit fieldwork, compliance monitoring, or consulting analysis, the governance challenge requires a senior principal and cannot be delegated to a junior team. A pyramid model (in which junior analysts perform the work and a partner reviews it) would reproduce the deliverable substitution problem this paper identified in Section 7, where the organisation pays for senior judgement but receives junior analysis.
Scalability in the SGaaS model comes from three sources. First, the tiered architecture itself creates natural segmentation. The Diagnostic tier is relatively scalable (it is a defined-scope assessment), while the Embedded tier is deliberately capacity-constrained (it requires deep, ongoing engagement). Second, the practice model is built around principals, not around a single individual. As the practice grows, it adds senior practitioners (each capable of leading engagements independently) rather than building a pyramid of juniors supporting a small number of partners. Third, institutional knowledge tools (governance pulse reports, challenge memos, maturity assessments) create a cumulative evidence base that reduces the start-up cost of each new engagement.
The honest constraint is that SGaaS is designed for organisations where governance is a strategic priority and the cost of failure is existential. That market is substantial, but it is not unlimited, and the model does not pretend otherwise.
"Board-Level Presence Creates Fiduciary Conflicts"
This objection anticipates a real problem, but the Embedded tier was designed to avoid it, not to manage it after the fact.
Under corporate law in mature jurisdictions (the UK Companies Act 2006, Delaware General Corporation Law, and their equivalents), fiduciary duties are holistic, collective, and non-delegable. A director who accepts a formal board appointment cannot confine liability to a single function. Any attempt to “ring-fence” an adversarial mandate within a directorial role would expose the principal to the full spectrum of fiduciary obligation, compromising the independence that makes the challenge function valuable in the first place.
The Embedded tier therefore excludes formal directorial appointment by design. The SGaaS principal operates exclusively as an Independent Board Observer or as a Mandated Advisor to the Risk or Audit Committee. Neither structure creates fiduciary duties. Both structures preserve the access, permanence, and authority the tier requires.
The separation is clean. The principal does not make governance decisions. The principal provides the adversarial intelligence, the stress-tested assumptions, surfaced failure modes, and challenged consensus positions, that the actual fiduciaries need to discharge their own duties. For directors operating under the Caremark doctrine’s evolving standard for mission-critical risk oversight, or under the UK Corporate Governance Code’s expectations for effective board challenge, the Embedded tier strengthens their position. It provides documented, continuous, independent governance intelligence that supports the “reasonable steps” defence.
Appropriate professional indemnity and contractual terms are required for both structures. The legal structuring is straightforward precisely because the architecture resolves the fiduciary question at the design stage rather than managing it contractually.
"Red Teaming and Pre-Mortems Are Established Techniques: What’s New?"
The individual techniques have well-documented intellectual origins, and this paper has acknowledged them throughout. Red teaming traces its lineage from the Vatican’s advocatus diaboli through military intelligence to contemporary business applications. The pre-mortem technique was formalised by Gary Klein and has been widely adopted in project management contexts. Scenario planning has roots in military strategy and was developed for business use at Royal Dutch Shell in the 1970s.
The claim of this paper is not that these techniques are new. The claim is that their structured, continuous application at board level as a governance function is new, and that this application addresses a specific set of structural defects that no existing model adequately addresses.
The distinction matters. A one-off red team exercise conducted as part of a consulting engagement is not SGaaS. A pre-mortem analysis performed by the project team before a single decision is not SGaaS. A scenario planning workshop facilitated by an external consultant every two years is not SGaaS. What distinguishes the SGaaS methodology is the synthesis: the integration of these techniques into a continuous, principal-led, adversarial governance architecture that builds institutional knowledge over time and operates with the independence and authority to challenge at the highest level of the organisation.
The same is true at the architectural level. Governance theorists have recognised the need for an institutionalised challenge function for decades. Turnbull’s Watchdog Board and Carver’s Policy Governance method [1] both propose structural responses to the absence of independent challenge. The governance profession has long had the diagnosis. The delivery model has been missing, a commercially viable, externally retained architecture that makes continuous, independent challenge available within existing governance frameworks. The individual tools are acknowledged building blocks. The governance need is established theory. The architecture, the way the tools are combined, delivered, and sustained as a retained service, is what SGaaS contributes.
"Our Internal Audit and Risk Functions Already Provide This"
The evidence examined in Section 6 suggests otherwise, not because internal audit and risk functions are failing, but because they are structurally unable to provide what SGaaS delivers. Internal audit spends 75% of its time on routine assurance and compliance. Risk functions face material funding constraints for emerging-risk identification. Both functions report through management hierarchies that create inherent limitations on the independence and adversarial nature of their challenge.
These functions are essential. The question is whether they can, within their current structural constraints, provide continuous, adversarial, independent governance challenge at board level. The IIA’s Vision 2035 report [2] implicitly acknowledges they cannot. Its projection that internal audit should shift from 75% assurance to 59% assurance is an admission that the current model is inadequate for the strategic challenge governance increasingly requires.
SGaaS does not replace these functions. It fills the structural gap they cannot fill, the space between what the Three Lines model is supposed to deliver and what it actually delivers in practice. The integration architecture described in Section 13 is specifically designed to ensure that SGaaS complements rather than competes with existing governance functions.
The Limits of Independence: Why SGaaS Can Still Fail
To apply the exact mandate of SGaaS (stress-testing logic and identifying failure modes) to the model itself, this paper must preemptively acknowledge its own operational vulnerabilities. While SGaaS is designed to mitigate the structural defects of traditional governance, it is not immune to the human and organisational realities it critiques. There are three primary ways the model can still fail:
Commercial independence remains aspirational. The paper argues that a retainer model breaks the consensus dependency of project-based consulting. While it mitigates the pressure, it does not eliminate it. A retained advisor who continually antagonises management or delivers deeply uncomfortable truths still faces the risk of the retainer not being renewed. True structural independence only exists when the challenger cannot be fired by the entity being challenged (such as a regulator), but the gravitational pull of palatability remains a risk.
Continuous oversight is practically constrained. While SGaaS positions itself as continuous rather than episodic, an external principal’s visibility is ultimately gated by the information the organisation chooses to share and the meetings they are invited to observe; unless the principal is physically embedded on a near full-time basis, their oversight relies heavily on management’s willingness to provide transparent access. The principal can only challenge what they are allowed to see.
Methodology cannot override toxic culture. Techniques like the Pre-Mortem Diagnostic rely on “prospective hindsight” to grant participants permission to dissent. However, in highly autocratic or psychologically unsafe cultures (precisely those most at risk of catastrophic failure), an external facilitator asking executives to imagine a project has failed will not magically produce radical honesty. Executives may simply offer politically safe failure modes that protect their departments and the CEO. The methodology requires a baseline of psychological safety to function; without it, the exercise risks becoming performative.
Acknowledging these limits does not invalidate the model. Rather, it demonstrates the adversarial honesty that SGaaS champions, recognising that no external governance architecture can entirely engineer away human nature or profound cultural dysfunction.
References
- David R. Koenig. (2018). Governance Reimagined: Organizational Design, Risk, and Value Creation. (b)right governance publications.
- Institute of Internal Auditors. (2024). Internal Audit Vision 2035: Creating Our Future Together. Internal Audit Foundation. https://ia-vision2035.org/