Examples of Governance: Corporate, Nonprofit, AI, and ESG

Examples of governance are easiest to understand when you look at the specific rules and mechanisms different institutions use to decide who holds authority, how that authority is checked, and what happens when someone misuses it. A board firing a CEO, a federal agency opening a proposed rule to public comment, a nonprofit filing its annual return with the IRS, and an engineering team routing a code change through formal approval are all governance in action. The shape shifts by sector, but the underlying idea is the same.

Corporate Governance

The board of directors sits at the center of corporate governance. It oversees the CEO and other executives, approves major strategic decisions, and is ultimately responsible to shareholders. Stock exchanges like the NYSE require that a majority of board members be independent, meaning they have no material financial relationship with the company beyond the board seat. That requirement exists because a board packed with insiders has little incentive to push back on management.

Shareholders exercise governance power mainly through voting. You can vote to elect or remove directors, approve mergers, and weigh in on executive pay. For public companies, that voting happens through proxy statements filed with the SEC.1Investor.gov. Shareholder Voting Federal rules require those statements to disclose executive compensation, substantial interests directors or officers hold in matters up for a vote, and proposed changes to benefit plans.2eCFR. 17 CFR 240.14a-101 – Schedule 14A

Directors also carry fiduciary duties, meaning they are legally required to put the corporation’s interests ahead of their own. When directors violate those duties, shareholders can file a derivative lawsuit on behalf of the corporation itself. That mechanism exists because the board controls whether a company sues anyone, so when the board is the problem, shareholders need a way around the bottleneck.

Sarbanes-Oxley Certification

The Sarbanes-Oxley Act added a federal enforcement layer to corporate governance after the Enron and WorldCom accounting scandals. The CEO and CFO of every public company must personally certify that their financial reports are accurate and that internal controls are working.3Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports An executive who willfully signs off on a misleading report faces up to 20 years in prison and a fine of up to $5 million.4Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports

The same law protects whistleblowers. Public companies cannot fire, demote, suspend, or threaten an employee for reporting a suspected securities violation to a federal agency, a member of Congress, or an internal supervisor. Employees who face retaliation can recover back pay, reinstatement, and attorney fees.5Office of the Law Revision Counsel. 18 USC 1514A – Civil Action to Protect Against Retaliation in Fraud Cases

Government Governance

Public sector governance rests on the constitutional separation of powers, but the mechanisms most people actually encounter are the transparency and participation rules that apply to federal agencies.

Notice-and-Comment Rulemaking

When a federal agency wants to issue a regulation, it cannot simply announce the rule. The Administrative Procedure Act requires the agency to publish a proposed rule in the Federal Register and give the public a meaningful chance to submit written comments, data, or arguments. After reviewing those comments, the agency must include a statement of the basis and purpose of the final rule.6Office of the Law Revision Counsel. 5 USC 553 – Rule Making The process forces agencies to justify their decisions in writing and respond to public objections before a rule takes effect.

Open Meetings and Public Records

The Government in the Sunshine Act requires meetings of multi-member federal agencies to be open to the public. The agency has to announce the time, place, and subject matter at least one week in advance and publish the notice in the Federal Register. Closing any part of a meeting requires a majority vote of the entire membership, and the agency has to record each member’s vote and give a written explanation for the closure.7Office of the Law Revision Counsel. 5 USC 552b – Open Meetings

The Freedom of Information Act gives anyone the right to request federal agency records. The agency has 20 business days to decide whether it will comply, and in unusual circumstances it can extend that deadline by up to 10 additional working days with written notice to the requester.8Office of the Law Revision Counsel. 5 USC 552 – Public Information; Agency Rules, Opinions, Orders, Records, and Proceedings Together, these laws let you track how a federal agency spends money, who it meets with, and how it reaches decisions.

Nonprofit Governance

Nonprofit governance revolves around keeping the organization dedicated to its charitable mission rather than enriching insiders. Articles of incorporation and bylaws set how trustees are selected, how decisions are made, and what the organization exists to do. They function as the nonprofit’s internal constitution.

Annual IRS Filings

Tax-exempt organizations must file an annual information return to keep their status. Organizations with gross receipts of $50,000 or more generally file Form 990 or Form 990-EZ, and smaller organizations may file the electronic Form 990-N.9Internal Revenue Service. Exempt Organization Annual Filing Requirements Overview These filings are public, so anyone can look up how a nonprofit spends its money, what it pays its leaders, and whether it appears to be fulfilling its stated purpose.

An organization that fails to file for three consecutive years automatically loses its tax-exempt status. The revocation is not discretionary. It happens by operation of law on the filing due date of the third missed return. Once revoked, the organization owes federal income tax and can no longer receive tax-deductible contributions.10Internal Revenue Service. Automatic Revocation of Exemption

Excess Benefit Rules

Federal tax law also targets insiders who use a nonprofit for personal gain. If a person with substantial influence over a tax-exempt organization receives compensation or benefits that exceed what’s reasonable, the IRS treats the arrangement as an excess benefit transaction. The insider owes an initial excise tax of 25 percent of the excess amount. If the situation isn’t corrected within the allowed time period, a second tax of 200 percent applies. Organization managers who knowingly participate face their own 10 percent tax, capped at $20,000 per transaction.11Office of the Law Revision Counsel. 26 USC 4958 – Taxes on Excess Benefit Transactions Conflict-of-interest policies and state attorney general oversight add further accountability, since most states empower the AG to investigate and sometimes seek dissolution of a nonprofit that has strayed from its mission.

Information Technology Governance

IT governance decides who can access what data, how changes to systems get approved, and what happens when something breaks. In practice, it starts with access controls. Rather than giving every employee the keys to every database, organizations assign permissions based on job function, so a marketing analyst does not have the same access as a database administrator.

Privacy regulations have pushed IT governance into more specific territory. The California Consumer Privacy Act requires covered businesses to tell consumers what personal data they collect, honor requests to delete that data, and allow people to opt out of having their information sold. Complying with those requirements forces organizations to build internal privacy policies with documented procedures, designated data officers, and regular audits.

Change management is the less visible side. Before an engineer deploys a software update or reconfigures a server, the change goes through formal review and approval. Every modification gets logged, creating an audit trail that regulators or internal investigators can trace. That discipline prevents the ad hoc tinkering that introduces security holes or crashes production systems on a Friday afternoon.

AI and Emerging Technology Governance

Automated systems can make hiring decisions, approve loans, flag criminal suspects, and generate content at a scale no human review process can match in real time. Governing them means figuring out who is accountable when the algorithm gets it wrong.

The NIST AI Risk Management Framework

In the United States, the most developed guidance comes from the National Institute of Standards and Technology. Its AI Risk Management Framework is organized around four functions: Govern, Map, Measure, and Manage. The Govern function specifically addresses organizational structure. It calls for documented roles and responsibilities for AI risk management, executive leadership accountability for deployment decisions, training for personnel involved in AI systems, and mechanisms to inventory every AI system the organization uses.12National Institute of Standards and Technology. Govern – NIST AI Risk Management Framework Playbook The framework is voluntary, and there is currently no comprehensive federal AI law in the United States. Some states have started filling that gap with their own requirements, such as incident-reporting mandates for developers of large AI models.

The EU AI Act

The European Union has taken a more prescriptive approach. The EU AI Act classifies AI systems into risk tiers and attaches governance obligations to each. Eight categories are banned outright, including social scoring systems, manipulative AI, and most real-time facial recognition by law enforcement. Those prohibitions took effect in February 2025. High-risk systems, such as those used in hiring, credit scoring, and law enforcement, face requirements including risk assessments, human oversight, detailed documentation, and high-quality training data. The high-risk rules phase in between August 2026 and August 2027.13European Commission. AI Act – Shaping Europe’s Digital Future Any organization that sells AI products into European markets has to comply regardless of where it is headquartered.

Environmental, Social, and Governance Reporting

ESG reporting has become a standard expectation for large companies, though the regulatory picture keeps shifting. Sustainability reports disclose metrics like greenhouse gas emissions, workplace safety records, and board diversity statistics to investors who want to evaluate long-term risk beyond the balance sheet. In the United States, these disclosures are largely voluntary. The SEC adopted a climate-related disclosure rule in 2024 that would have required large public companies to report material greenhouse gas emissions, but the agency stayed the rule during litigation and withdrew its defense of it in 2025.14U.S. Securities and Exchange Commission. SEC Votes to End Defense of Climate Disclosure Rules For now, U.S. ESG reporting is driven more by investor pressure and stock exchange guidance than by federal mandate.

Board-level diversity initiatives cover the social side. Companies tie executive compensation to diversity targets or require that director search committees consider candidates from underrepresented backgrounds. Supply chain audits extend governance beyond the company’s own walls, requiring vendors and subcontractors to demonstrate compliance with labor, safety, and environmental standards before contracts are renewed. The process usually involves self-assessments, document reviews, and on-site inspections.

What Governance Failure Costs

The point of governance becomes clearest when you see what happens without it.

For corporations, the sharpest consequence is piercing the corporate veil. A court can disregard the separation between a business and its owner and hold the owner personally liable for the company’s debts. Courts look at whether the owner mixed personal and business funds, failed to keep corporate records, ignored basic corporate formalities, or undercapitalized the business from the start. No single factor is usually enough alone, but stack several together and the liability shield disappears.

For nonprofits, the excess benefit excise taxes can dwarf the original overpayment. A nonprofit leader who receives $100,000 more than reasonable compensation faces a $25,000 initial tax, and if the problem is not fixed in time, an additional $200,000 tax on top of that.11Office of the Law Revision Counsel. 26 USC 4958 – Taxes on Excess Benefit Transactions That sits alongside the automatic revocation of tax-exempt status for organizations that skip three annual filings.

For public companies, the Sarbanes-Oxley certification requirement means governance failures in financial reporting can put individual executives in federal prison. The law was designed so a CEO cannot plausibly claim ignorance of what the financial statements say.4Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports That personal accountability, more than any board resolution or compliance policy, is what gives the framework its force.