Governance framework examples fall into a handful of recognizable categories, and most organizations end up using more than one. At the top sits corporate governance itself, guided by international standards like the OECD Principles. Below that are frameworks for internal controls (COSO), IT operations (COBIT and ITIL), data and privacy (DAMA-DMBOK, NIST Privacy Framework, and sector rules like HIPAA and GLBA), sustainability reporting (GRI and SASB), artificial intelligence (the NIST AI Risk Management Framework), and non-profit oversight (driven largely by IRS requirements). Which combination fits your organization depends on size, industry, ownership structure, and how much regulatory exposure you carry.
Below is what each framework covers, when it applies, and how the pieces fit together.
OECD Principles for Corporate Governance
The Organisation for Economic Co-operation and Development publishes the most widely referenced international standard for corporate governance. The principles were revised in 2023 and endorsed by G20 leaders the same year, and they help policymakers and regulators evaluate their own legal frameworks for overseeing corporations.1OECD. G20/OECD Principles of Corporate Governance 2023 They aren’t legally binding on their own, but they carry weight because so many countries use them as a baseline when drafting securities laws and listing rules.
The framework covers protection of shareholder rights (including minority and foreign shareholders), board oversight of disclosure and communications, and the requirement that boards maintain the integrity of accounting and reporting systems.2OECD. G20/OECD Principles of Corporate Governance 2023 – Section V Boards are expected to exercise independent, objective judgment, set clear lines of accountability throughout the organization, and ensure that non-executive members have access to accurate, relevant, and timely information about operations and subsidiary activities.
The OECD document is available at no cost, which makes it a natural reference point when you need a defensible baseline for board practices.
COSO for Internal Controls and Enterprise Risk
If your company is publicly traded in the United States, the COSO framework is almost certainly part of your compliance life. The Committee of Sponsoring Organizations of the Treadway Commission publishes two related frameworks: one focused on internal controls over financial reporting, and a broader Enterprise Risk Management framework.
The SEC has recognized COSO’s internal control framework as a suitable evaluation standard for meeting Sarbanes-Oxley Section 404, which requires public companies to report annually on the effectiveness of their internal controls. The SEC did not mandate COSO specifically. Its rule states that management may use any framework that is established by a body following due-process procedures, is free from bias, permits reasonably consistent measurements, and is sufficiently complete.3U.S. Securities and Exchange Commission. Final Rule – Management’s Report on Internal Control Over Financial Reporting In practice, COSO became the default because auditors and regulators are already fluent in its structure.
The broader COSO ERM framework organizes risk management into five components: governance and culture, strategy and objective-setting, performance, review and revision, and information and reporting. Twenty supporting principles guide organizations from setting a risk appetite at the board level down to day-to-day risk monitoring. It’s particularly useful when you want strategic planning and operational risk connected rather than run as separate exercises.
Organizations operating outside the U.S. or in less compliance-driven industries sometimes prefer ISO 31000, which offers a more flexible, principles-based approach to risk without the granular prescriptions of COSO. The two aren’t mutually exclusive, and some multinational companies use both.
IT Governance: COBIT and ITIL
Technology governance sits at the intersection of business strategy and operational risk. Two frameworks dominate, and they solve different problems.
COBIT
COBIT, developed by ISACA, provides a structure for enterprise governance of information and technology, covering strategic alignment through security and risk management. ISACA also publishes dedicated guidance for using COBIT to satisfy Sarbanes-Oxley internal control requirements over financial reporting, which makes it a practical companion to COSO for companies that need to demonstrate IT-specific controls to auditors.4ISACA. COBIT – Control Objectives for Information Technologies
ITIL
ITIL focuses on IT service management rather than governance at the enterprise level. Where COBIT asks whether your IT investments align with business strategy, ITIL provides the operational playbook for delivering and supporting those services, including incident management, change control, problem resolution, and service-level agreements.5ISACA. Using ITIL 4 and COBIT 2019 to Create an Integrated I and T Framework Environment Organizations that handle financial data use ITIL’s change control processes to document every modification to reporting environments, which helps satisfy audit requirements.
Why IT Governance Now Has Regulatory Teeth
Since late 2023, the SEC has required public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material. Companies must describe the nature, scope, and timing of the incident, along with its actual or reasonably likely impact on the company’s financial condition. On the annual side, companies must describe their processes for assessing and managing cybersecurity risks, the board’s oversight role, and management’s responsibility for cybersecurity in their 10-K filings.6U.S. Securities and Exchange Commission. Final Rule – Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
Companies with COBIT or ITIL already in place can point to documented processes, incident logs, and risk assessments when preparing these disclosures. Companies without them scramble to reconstruct what happened and when.
Data Governance Frameworks
Data governance has moved from internal best practice to regulatory necessity. Two widely used voluntary frameworks provide structure, and several sector-specific rules add mandatory requirements on top.
DAMA-DMBOK
DAMA International’s Data Management Body of Knowledge covers the full lifecycle of data management, from creation and storage through archiving and disposal. It addresses data quality, metadata, data architecture, and integration. One important limit: DAMA-DMBOK defines principles and best practices but is not a prescriptive standard. It doesn’t mandate specific tools or methodologies.7DAMA International. DAMA Data Management Body of Knowledge Treat it as a reference architecture rather than a checklist.
NIST Privacy Framework
The National Institute of Standards and Technology publishes a Privacy Framework built around five core functions: Identify, Govern, Control, Communicate, and Protect. It’s designed to help organizations understand and manage privacy risks without being tied to any single law.8National Institute of Standards and Technology. Data Governance and Management Profile Organizations use it to build privacy programs that flex as new regulations emerge, rather than rebuilding from scratch every time a jurisdiction enacts something new.
Sector-Specific Rules
If you’re in a regulated industry, voluntary frameworks are only part of the story. Financial institutions under FTC jurisdiction must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards under the Gramm-Leach-Bliley Act’s Safeguards Rule. The program must be proportionate to the business’s size, complexity, and the sensitivity of the customer information it handles, and it now includes breach notification requirements.9Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know
Healthcare organizations face parallel obligations under HIPAA’s Security Rule, which requires administrative, physical, and technical safeguards to protect electronic protected health information. The rule mandates a formal risk assessment process, a designated security official, workforce access controls, incident response procedures, and contingency planning for data system failures.10U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule These sector-specific rules provide the enforcement teeth that voluntary frameworks lack.
ESG and Sustainability Reporting
Two systems dominate ESG reporting, and they’ve increasingly converged.
The Global Reporting Initiative provides a broad framework for reporting a company’s impacts on people and the environment, from carbon emissions to labor practices to community engagement. GRI is designed to be useful to all stakeholders, not just investors.11Global Reporting Initiative and SASB. A Practical Guide to Sustainability Reporting Using GRI and SASB Standards
The Sustainability Accounting Standards Board takes a narrower, investor-focused approach, providing industry-specific metrics tied to financial materiality. SASB standards help investors evaluate how sustainability issues create or erode enterprise value.11Global Reporting Initiative and SASB. A Practical Guide to Sustainability Reporting Using GRI and SASB Standards In 2022, the SASB standards and their supporting resources were consolidated into the IFRS Foundation under the International Sustainability Standards Board. The SASB standards themselves remain in use and are being enhanced as part of the ISSB’s global sustainability disclosure standards.12IFRS Foundation. ISSB Frequently Asked Questions
The SEC has shown it takes ESG disclosures seriously. In one case, the agency charged an investment adviser with making misleading statements about how much of its assets under management were “ESG integrated,” resulting in a $17.5 million civil penalty.13U.S. Securities and Exchange Commission. SEC Charges Invesco Advisers for Making Misleading Statements About Supposed Investment Considerations In another, an adviser that failed to follow its own ESG policies and procedures paid a $4 million penalty.14U.S. Securities and Exchange Commission. SEC Charges Goldman Sachs Asset Management for Failing to Follow its Policies and Procedures Involving ESG Investments If you market a fund or strategy as ESG-integrated, your internal governance has to actually support that claim.
AI Governance
Artificial intelligence governance is the newest category, and the regulatory landscape is still taking shape. No comprehensive federal AI law exists yet. Federal agencies currently regulate AI using their existing authority, with the FTC targeting deceptive AI practices, the SEC monitoring AI-related disclosures, and the EEOC providing guidance on AI-driven employment discrimination.
The most prominent voluntary framework is the NIST AI Risk Management Framework, organized around four core functions: Govern (building a culture of AI risk management), Map (framing risks in context), Measure (analyzing and monitoring AI risks using quantitative and qualitative methods), and Manage (prioritizing and acting on identified risks). The framework is voluntary, and no federal regulation currently requires its adoption.15National Institute of Standards and Technology. AI Risk Management Framework It’s becoming the de facto standard companies point to when demonstrating responsible AI practices.
State-level AI laws are moving faster than federal legislation. Starting in early 2026, at least one state requires developers and deployers of high-risk AI systems to perform impact assessments, provide transparency disclosures to consumers, implement risk management programs, and take reasonable care to prevent algorithmic discrimination. These laws typically give consumers the right to correct inaccurate personal data used in automated decisions and to appeal adverse outcomes through human review. The patchwork is growing, and compliance obligations vary significantly by jurisdiction.
Non-Profit Governance
Non-profits face governance requirements that differ substantially from for-profit counterparts, driven largely by tax-exempt status and IRS oversight. Board members carry three core fiduciary duties: care (staying informed and exercising sound judgment), loyalty (putting the organization’s interests ahead of personal interests and disclosing conflicts), and obedience (following the mission, applicable laws, and using resources appropriately).
The IRS uses Form 990 to evaluate whether non-profits are meeting basic governance standards. Part VI asks whether the organization has adopted a written conflict of interest policy, a whistleblower protection policy, and a document retention and destruction policy. It also asks whether individuals covered by the conflict of interest policy are required to disclose their interests annually and whether the organization monitors transactions for actual conflicts.16Internal Revenue Service. 2025 Instructions for Form 990 None of these policies are technically required by federal law, but answering “no” invites scrutiny and signals weak governance to donors and grant-making foundations.
Where non-profit governance has real financial teeth is in the excess benefit rules. If a disqualified person (typically an insider like an officer or board member) receives compensation or benefits that exceed what’s reasonable for the services provided, the IRS imposes an excise tax of 25% of the excess benefit on the individual. If the excess benefit isn’t corrected within the allowed period, an additional tax of 200% of the excess benefit applies.17Office of the Law Revision Counsel. 26 USC 4958 – Taxes on Excess Benefit Transactions Those penalties fall on the individual, not the organization. Documented compensation benchmarking and conflict-of-interest procedures are the primary defense.
Building the Framework You’ve Chosen
Whichever framework you adopt, certain structural pieces show up in every effective governance system. Getting these right matters more than picking the “perfect” framework.
Board Committees
Publicly traded companies listed on major U.S. stock exchanges must maintain specific board committees as a condition of listing. Both the NYSE and Nasdaq require audit committees, compensation committees, and nominating or governance committees, all composed of independent directors, with limited phase-in exceptions for newly listed companies.18NYSE. NYSE Listed Company Manual Section 303A FAQ The audit committee must include at least one member who qualifies as a financial expert: someone who understands accounting principles, can assess estimates and accruals, has experience with financial statement complexity comparable to the company’s, and understands internal controls and audit committee functions.
Private companies and non-profits aren’t subject to exchange listing rules, but the principle still applies. Separating oversight into dedicated committees with clear charters prevents the concentration of power that leads to governance failures. An audit committee, even in a small organization, creates an independent check on management’s financial reporting.
Core Documentation
Every governance framework relies on a common set of foundational documents:
- An organizational chart that defines reporting lines and the hierarchy of authority.
- A policy manual serving as the primary reference for employee conduct, covering conflicts of interest through acceptable use of company resources.
- A risk register that identifies and prioritizes threats, from regulatory changes to cybersecurity vulnerabilities.
- A compliance log giving a continuous record of how the organization meets its legal obligations, which becomes critical evidence during audits or regulatory inquiries.
- A role accountability matrix that assigns every individual with significant influence over company assets a defined set of duties and limitations.
Getting the Source Documents
Standards documents themselves come from the organizations that publish them. ISO sells its standards, including ISO 37000 on organizational governance, through national member bodies and its online store.19International Organization for Standardization. ISO 37000 2021 – Governance of Organizations Guidance The OECD Principles are free.1OECD. G20/OECD Principles of Corporate Governance 2023 NIST frameworks are free and publicly accessible. Cost varies, but the governance infrastructure itself requires the same investment regardless of which framework you follow: clearly defined roles, documented processes, and regular review cycles that keep the system from becoming a shelf exercise.