Marentis Labs

Why Traditional Advisory Models Under-Deliver

Consultants, non-executive directors and internal audit each provide part of the answer, but none is built to deliver continuous adversarial challenge. This chapter explains why traditional advisory models under-deliver against the governance problem, and what a continuous, principal-led alternative must provide.

A natural question follows from the preceding analysis. If a structural gap exists between assurance and adversarial challenge, why hasn’t the established multi-centi billion dollar management consulting market closed it?

The global management consulting market exceeds USD 700 billion annually. Big Four advisory revenues alone surpassed their traditional audit services revenues around 2014 and have continued to grow. Governance, risk, and compliance advisory is one of the fastest-growing segments. Organisations are clearly spending money on external governance support. Yet the structural gap persists.

The gap persists by design. Traditional advisory models are built in ways that reproduce the same structural defects that cause governance failure rather than resolve them.

The Episodic Engagement Problem

The dominant model for governance advisory is project-based. A firm identifies a governance concern, commissions an external review, receives a report, implements recommendations, and the engagement ends. Average engagement duration for governance and risk advisory projects ranges from eight to sixteen weeks, and fewer than 15% extend beyond six months.

This model is, by design, episodic. The consultancy team arrives, analyses, recommends, and departs. Between engagements, the organisation’s governance environment continues to evolve. New risks emerge, strategic decisions are taken, board composition changes, and regulatory requirements shift. The consultant has no visibility into these changes. When the next engagement begins, if there is one, the consultant must rebuild context from scratch, often with an entirely different set of team members.

The structural defect this reproduces is obvious. Section 3 identified episodic engagement as the first of three governance defects, the tendency for boards to engage with risk only at intervals, processing whatever is presented during those intervals. Project-based consulting operates on the same model. It provides a snapshot of governance effectiveness at a point in time, not a continuous signal. The value of the snapshot degrades from the moment the engagement ends.

The FSI’s fourth line of defence (external audit and regulatory supervision) operates on the same episodic logic. Annual audit cycles, periodic regulatory examinations, and project-based consulting reviews all share a common architectural limitation. They provide assurance at intervals in a world where risk is continuous.

The Institutional Memory Problem

A governance review conducted over twelve weeks generates deep understanding of the organisation’s culture, power dynamics, information flows, decision-making patterns, and structural vulnerabilities. This understanding lives in the minds of the consulting team. It is not transferable in a report. Reports capture findings and recommendations. They do not capture the pattern recognition, contextual judgement, and relational knowledge that informed those findings.

The consequence is a perpetual restart. Each new engagement begins with weeks of context-building. Each new consulting team must learn what the previous team learned and forgot. The organisation pays, repeatedly, for the same discovery process.

A continuous governance function, by contrast, accumulates institutional memory. It observes how decisions are made over quarters and years, not weeks. It tracks whether recommendations are implemented, diluted, or quietly abandoned. It notices when the same structural weaknesses recur under different labels. This cumulative knowledge is one of the most valuable assets a governance challenge function can build, and it is, by definition, unavailable to a project-based engagement model.

The Consensus Incentive

Section 3 identified consensus dependency as the second structural defect of governance, the tendency for board decisions to be biased toward agreement, amplified by social pressure, anchoring, and the comfort of collective assent. Traditional advisory models are subject to this defect rather than counteracting it.

The commercial reality of consulting is that engagements end and relationships continue. A consulting firm that delivers findings uncomfortable to management risks losing future engagements. A firm that challenges the board’s preferred narrative risks being perceived as adversarial rather than collaborative. The incentive structure favours findings that are rigorous enough to be credible but palatable enough to be acceptable.

Bazerman, Morgan, and Loewenstein [1] demonstrated that self-serving bias is unconscious and structural. Even well-intentioned professionals cannot fully eliminate the influence of financial relationships on their professional judgement. The effect requires no conscious corruption to operate. The effect is that the commercial relationship creates a gravitational pull toward consensus, toward findings that the client can accept without disruption.

For the Big Four specifically, the incentive is compounded. These firms provide audit, advisory, tax, and consulting services to overlapping client bases. While independence restrictions limit the advisory services an audit firm can provide to its audit clients, the broader commercial incentive to maintain multi-service relationships remains. A governance advisory engagement that produces findings challenging to the audit relationship creates institutional tension. The structural pressure, however subtle, is toward findings that preserve the overall commercial ecosystem.

An adversarial governance function requires the opposite incentive structure. Its value lies precisely in its willingness to surface uncomfortable truths, challenge prevailing narratives, and report findings that management may not welcome. This requires structural independence from the commercial dynamics that govern project-based advisory, an independence that is easier to design into a retained, principal-led model than into a fee-per-engagement one.

The Prescription and the Delivery Model

The clearest evidence that traditional advisory cannot close the governance gap comes from traditional advisory itself. In 2010, four McKinsey partners published a board-facing working paper that prescribed, with considerable precision, the capabilities boards require, namely continuous integration of risk into strategic planning and capital allocation; a risk dialogue “centered on specific business issues, rather than a discussion of high-level generalities”; direct board interaction with the handful of executives who understand the key risks best; a “board culture that promotes dialogue and constructive challenge”; and identification of the three to five “big bets” on which the organisation actually depends [2]. These are the operating capabilities the authors identify as the difference between governance that works and governance that does not.

Every capability on that list is continuous, specific, and relational. None of them can be delivered through a twelve-week engagement by a rotating team of consultants on a deliverable-based billing model. The prescription and the commercial model are architecturally incompatible. The advisory industry has been able to describe what boards need for over fifteen years. It has not been able to sell it, because the capabilities it prescribes cannot be packaged as projects, scoped as deliverables, or priced by the hour.

The pattern repeats in 2025, with a different firm and a different risk domain but the same structural contradiction. A Deloitte survey [3] covering 695 board members and C-suite executives across 56 countries concluded that boards must oversee AI strategy execution and risk management continuously, “challenging management to identify when and how the strategy may need to be adapted in response to risks and opportunities”. The report prescribes seven thematic areas of permanent board-level inquiry, namely strategy, risk appetite, governance structure, board education, performance measurement, talent, and culture. Each requires sustained engagement, not a periodic check-in. Yet the vehicle for the prescription is a Deloitte Global Boardroom Program survey report, a deliverable that boards read once and file. Deloitte, like McKinsey fifteen years earlier, prescribes an architectural capability from a commercial position that delivers episodic advisory. The gap between what the advisory industry prescribes for boards and what it is structurally able to deliver is the gap that SGaaS is designed to close, through a commercial model (retained, principal-led, independent, outside the audit-tax-consulting ecosystem) that is compatible with the continuous adversarial capabilities the prescription requires.

The pattern repeats a third time, in 2026, with a non-commercial author and the same architectural contradiction. COSO’s From Guidance to Action [4], written by the framework consortium of the AAA, AICPA, FEI, IMA, and IIA, prescribes an ERM operating system built from forums where risk-informed decisions are actually made, a cadence aligned to operating reviews, triggers that convert awareness into action, and short, decision-ready artefacts that travel with the schedule. The prescription is the same continuous, embedded, decision-led discipline McKinsey described in 2010 and Deloitte described in 2025. The author this time is the consortium that wrote the framework rather than a firm that sells advisory hours. The delivery vehicle is, once again, a published report that boards read once and file. Even the framework authors cannot escape the architectural problem. They can articulate what good ERM looks like; they cannot deliver it. The ERM operating system COSO describes does not exist as a product, and the same paper’s fallback proposal of a five-hour-a-week minimum operating rhythm for resource-constrained risk leaders is a tacit admission that internal capacity is structurally insufficient. The prescription has now been issued by a consultancy, by a peer consultancy, and by the framework consortium itself. None of the three has been able to deliver it. SGaaS is the delivery vehicle the prescription requires.

The Deliverable Substitution Problem

Michael Power’s concept of “organised uncertainty” [5] describes a dynamic in which organisations substitute auditable artefacts for substantive assurance (the appearance of control for its reality). Project-based advisory is particularly susceptible to this substitution.

A governance review produces a report. The board receives the report, notes the findings, and approves the recommendations. It then files the report. The report becomes the evidence of governance, the artefact that demonstrates the board took action. Whether the recommendations are implemented, whether the implementation is effective, and whether the governance environment has changed since the report was written are questions the report cannot answer and the consulting engagement does not address.

Kahneman, Sibony, and Sunstein’s work on decision hygiene reinforces the point. Reducing noise in professional judgement requires sustained, structured, repeated intervention, not a one-off diagnostic. A single governance review can identify problems. It cannot sustain the decision discipline required to prevent them from recurring. That requires continuous presence, not periodic visitation.

The Structural Comparison

The following table maps the three structural defects identified in Section 3 against the traditional advisory model and the requirements for a function that could address the value gap.

Traditional advisory models mapped against the three structural governance defects
DimensionTraditional AdvisoryStructural Defect ReproducedWhat Is Required
Engagement modelProject-based; 8–16 weeks; defined deliverable; engagement endsEpisodic engagement: snapshot governance in a world of continuous riskContinuous, retained engagement with ongoing access, visibility, and accountability
Institutional memoryKnowledge leaves with the team; each engagement restarts context-buildingNo longitudinal intelligence; governance history lost between engagementsCumulative knowledge of organisational culture, decision patterns, and governance dynamics
IndependenceCommercial incentive to maintain client relationships; self-serving bias (Bazerman et al.)Consensus dependency: findings gravitationally pulled toward palatabilityStructural independence from commercial dynamics; mandate to challenge, not to please
DeliverableReport, framework, or set of recommendations; filed after presentationDeliverable substitution: the report becomes the artefact of governance, not its substanceContinuous intelligence feed; ongoing challenge and accountability for implementation
Challenge functionAdvisory: recommends improvements within client’s preferred parametersAbsence of institutionalised challenge: no mandate to break assumptions or stress-test decisionsAdversarial by design: mandated to surface failure modes, challenge narratives, and simulate scenarios the organisation prefers not to consider

The pattern is consistent. Traditional advisory models reproduce the same structural defects, including episodic engagement, consensus dependency, and absence of institutionalised challenge. These are root causes of governance failure. They address governance symptoms through periodic intervention rather than governance architecture through continuous presence.

What the Gap Requires

The regulatory direction described in Section 5 makes the inadequacy of traditional models increasingly consequential. Provision 29 of the UK Corporate Governance Code requires boards to declare on the effectiveness of material internal controls across financial, operational, reporting, and compliance dimensions. This requires continuous evidence, not periodic review. The Caremark doctrine requires governance architecture specifically around mission-critical risks. This requires permanent structural commitment for which project-based intervention will not work. SM&CR creates personal accountability for senior managers. This requires demonstrable evidence of “reasonable steps”. A twelve-week consulting engagement, however excellent its report, may not provide this evidence.

The gap requires a function that is:

Core Principle Continuous: Present across board cycles, not between engagements.

Adversarial: Mandated to challenge, not to recommend within acceptable parameters.

Independent: Structurally separated from the incentives that pull findings toward consensus.

Cumulative: Building institutional memory of governance dynamics over time, not restarting context with each engagement.

Principal-led: Delivered by experienced governance professionals, not by teams of junior analysts supervised remotely by a partner.

Section 8 defines this function and gives it a name.



References

  1. Max H. Bazerman et al.. (1997). The Impossibility of Auditor Independence. Sloan Management Review.
  2. Andr\'e Brodeur et al.. (2010). A Board Perspective on Enterprise Risk Management. McKinsey & Company.
  3. Anna Marks et al.. (2025). Governance of AI: A Critical Imperative for Today's Boards. Deloitte Global Boardroom Program.
  4. Ryan Luttenton et al.. (2026). From Guidance to Action: Exploring Practical Enterprise Risk Management. Committee of Sponsoring Organizations of the Treadway Commission (COSO).
  5. Michael Power. (2007). Organized Uncertainty: Designing a World of Risk Management. Oxford University Press.