DVMS – Integrating Governance, Performance, Risk, and Compliance Management to Achieve Operational Resilience
Rick Lemieux – Co-Founder and Chief Product Officer of the DVMS Institute
Introduction
In today’s hyper-connected and data-driven economy, organizations operate in complex digital ecosystems where governance, performance, risk, and compliance (GPRC) must be continuously integrated to sustain trust, agility, and resilience. The Digital Value Management System® (DVMS) provides a structured overlay system approach that enables organizations to align their governance and operational systems with strategic objectives while maintaining compliance and managing risk in real time. Built upon principles of digital business governance and operational resilience, the DVMS facilitates the coordination of people, processes, technologies, and information to ensure that digital operations remain secure, adaptable, and value-driven. This essay explores how a DVMS supports organizations in managing GPRC and, ultimately, achieving operational resilience.
Governance: Establishing Accountability and Strategic Alignment
Effective governance ensures that an organization’s digital initiatives and operational activities are aligned with its mission, values, and strategic goals. The DVMS provides the structure for this alignment by defining how decisions are made, how responsibilities are assigned, and how outcomes are monitored. Unlike traditional governance systems that focus primarily on compliance or reporting, a DVMS establishes a dynamic governance model that adapts to changing digital and regulatory environments.
Within a DVMS, governance mechanisms ensure that leadership can translate strategic intent into operational execution. It promotes transparency by linking enterprise objectives to measurable outcomes across processes and functions. By embedding governance controls directly into digital workflows and decision-making systems, the DVMS ensures that every activity contributes to the organization’s desired business outcomes. Furthermore, the DVMS fosters accountability across digital value streams, ensuring that decision-making is informed, ethical, and risk-aware.
Through the integration of governance frameworks such as COBIT, ISO 38500, and the NIST Cybersecurity Framework, the DVMS provides organizations with a governance “meta-system” that is both prescriptive and flexible. It allows enterprises to govern digital operations holistically, enabling consistent oversight while supporting decentralized, autonomous teams that operate within defined boundaries of authority and compliance.
Performance: Driving Value and Continuous Improvement
Performance management within a DVMS is centered on the concept of digital value creation. In this context, performance is not limited to efficiency or output; it encompasses the organization’s ability to deliver stakeholder value reliably, securely, and sustainably. A DVMS operationalizes performance management by linking governance objectives with performance indicators across business, operational, and technical domains.
A core feature of the DVMS is its capability to establish “performance control loops” that continuously measure and optimize outcomes. These loops are built on the principles of systems thinking, where feedback mechanisms allow organizations to detect deviations, evaluate performance data, and implement corrective actions before minor issues evolve into major disruptions. Performance dashboards and analytics within the DVMS enable real-time visibility across digital ecosystems—supporting proactive management of service quality, availability, and compliance metrics.
Moreover, the DVMS emphasizes alignment between performance and purpose. It ensures that performance targets not only meet short-term operational objectives but also contribute to long-term organizational resilience and stakeholder trust. By institutionalizing continuous improvement methodologies such as Plan-Do-Check-Act (PDCA), Lean, and Six Sigma within its architecture, the DVMS embeds performance excellence as a core organizational competency. This creates a culture of learning, innovation, and adaptability—key enablers of sustained operational resilience.
Risk: Anticipating, Managing, and Mitigating Uncertainty
Risk management is at the heart of operational resilience, and the DVMS provides an integrated system for identifying, assessing, and mitigating risk across all levels of the organization. Traditional risk management approaches often operate in silos, leading to fragmented understanding and delayed response to emerging threats. The DVMS eliminates these silos by connecting risk intelligence across business units, processes, and systems, providing a unified view of enterprise risk.
Through automation, analytics, and scenario modeling, the DVMS enhances an organization’s ability to anticipate risks—ranging from cyber threats and supply chain disruptions to regulatory changes and market volatility. Its risk management framework is both proactive and adaptive, enabling organizations to make informed trade-offs between risk and reward. The DVMS supports real-time risk monitoring through dashboards and predictive analytics that assess potential vulnerabilities before they impact operations.
Crucially, the DVMS embeds risk management within the organization’s governance and performance frameworks, ensuring that risk awareness is integrated into everyday decision-making. This approach aligns with the NIST Cybersecurity Framework and ISO 31000 principles, promoting a culture of resilience where risk management becomes a shared responsibility rather than a specialized function. By managing risk dynamically and systemically, organizations using a DVMS can maintain continuity and trust even under adverse conditions.
Compliance: Ensuring Integrity and Trust
Compliance has traditionally been viewed as a reactive function—focused on adhering to external rules, regulations, and standards. The DVMS transforms compliance into a proactive, value-generating capability. By embedding compliance requirements into digital workflows and management processes, the DVMS automates the demonstration of conformance to regulatory, security, and ethical standards.
A key advantage of the DVMS is its ability to unify multiple compliance frameworks—such as ISO 27001, NIST SP 800-53, GDPR, and SOC 2—into a single integrated system. This harmonization reduces redundancy, simplifies audits, and enhances visibility into compliance status. Automated evidence collection, policy mapping, and control monitoring allow organizations to demonstrate compliance continuously rather than periodically, reducing audit fatigue and operational risk.
Beyond regulatory conformance, the DVMS promotes a “compliance culture” rooted in integrity and transparency. Employees, contractors, and partners are guided by clearly defined digital governance principles and compliance obligations embedded into their roles and tools. This ensures that compliance becomes an enabler of trust—not just a regulatory checkbox. Ultimately, a DVMS helps organizations establish reputational resilience by ensuring that ethical and legal obligations are met consistently across all digital value activities.
Enabling Operational Resilience through Integrated GPRC
The integration of governance, performance, risk, and compliance within a DVMS creates a synergistic system that enables true operational resilience. Operational resilience is the capability of an organization to anticipate, withstand, respond to, and recover from disruptions—while maintaining critical operations and protecting stakeholder interests. The DVMS enables this by fostering situational awareness, agility, and accountability across the digital enterprise.
By linking governance decisions to performance outcomes, risk intelligence, and compliance controls, the DVMS ensures that resilience is designed into operations—not bolted on after the fact. For example, when a cyber incident occurs, the DVMS provides the structure for coordinated response and recovery, guided by governance policies, risk priorities, and compliance obligations. The organization can adapt quickly while maintaining transparency and trust with stakeholders.
Moreover, the DVMS promotes resilience as a continuous capability rather than a one-time project. Through feedback loops, audits, and continuous improvement mechanisms, the system evolves with the organization’s digital ecosystem. This adaptability ensures that resilience remains aligned with strategic objectives, regulatory expectations, and emerging threats. In essence, the DVMS transforms operational resilience from a defensive posture into a strategic advantage—enabling organizations to thrive amid volatility, uncertainty, complexity, and ambiguity.
Conclusion
A Digital Value Management System is far more than a technological solution—it is an organizational capability that integrates governance, performance, risk, and compliance into a cohesive management system designed for resilience. By institutionalizing accountability, driving continuous performance improvement, managing risk proactively, and ensuring compliance with integrity, the DVMS enables organizations to maintain trust and continuity in an unpredictable digital landscape. As enterprises continue to evolve in an era defined by rapid technological change and systemic risk, the DVMS provides the foundation for sustainable digital business governance and operational resilience.
About the Author

Rick Lemieux
Co-Founder and Chief Product Officer of the DVMS Institute
Rick has 40+ years of passion and experience creating solutions to give organizations a competitive edge in their service markets. In 2015, Rick was identified as one of the top five IT Entrepreneurs in the State of Rhode Island by the TECH 10 awards for developing innovative training and mentoring solutions for boards, senior executives, and operational stakeholders.
DVMS Cyber Resilience Professional Accredited Certification Training
Teaching Enterprises How to Govern, Assure, and Account for Operational Resilience in Living Digital Ecosystems
Moving From Paper to Practice-Based Operational Resilience
Explainer Video – Governing By Assurance
Despite an abundance of frameworks, metrics, and dashboards, many leaders still lack a clear line of sight into how their digital value streams perform when conditions deteriorate.
Strategic intent, organizational structures, and day-to-day behaviors are evaluated separately, producing static snapshots that fail to reveal how decisions, dependencies, and human actions interact within a dynamic digital system.
The result is governance that appears comprehensive in documentation yet proves fragile under pressure, leaving leaders to reconcile disconnected controls rather than systematically strengthen operational resilience.
What is needed is a framework-agnostic operating overlay that enables operational resilience to be governed, assured, and accounted for coherently across complex, living digital ecosystems.
DVMS Institute White Papers – The Assurance Mandate Series
Explainer Video – From Compliance Rituals to Evidence-Based Resilience
The whitepapers below present a clear progression from compliance-driven thinking to a modern system of Governance, Resilience, Assurance, and Accountability (GRAA). Together, they define an evidence-based approach to building and governing resilient digital enterprises.
The Assurance Mandate Paper explains why traditional compliance artifacts offer reassurance, not proof, and challenges boards to demand evidence that value can be created, protected, and delivered under stress.
The Assurance in Action Paper shows how DVMS turns intent into execution by translating outcomes into Minimum Viable Capabilities, aligning frameworks through the Create–Protect–Deliver model, and producing measurable assurance evidence of real performance.
The Governing by Assurance Paper extends this model to policy and regulation, positioning DVMS as a learning overlay that links governance intent, operational capability, and auditable evidence—enabling outcome-based governance and proof of resilience through measurable performance data.
The Digital Value Management System® (DVMS)
Explainer Video – What is a Digital Value Management System (DVMS)
The DVMS is an overlay management system that governs, assures, and accounts for operational resilience in complex, living digital ecosystems. It does so by ensuring living-system outcomes account for paper-system intent.
At its core, the DVMS is a simple but powerful integration of:
- Governance Intent – shared expectations and accountabilities
- Operational Capabilities – how the digital business performs
- Assurance Evidence – proof that outcomes are achieved and accountable
- Cultural Learning – for governance intent and operational capability fine-tuning
Underpinning this integration are three distinctive DVMS models
Create, Protect, and Deliver (CPD) – The CPD Model™ is a systems-based model within the DVMS that links strategy-risk and governance to execution to create, protect, and deliver digital business value as an integrated, continuously adaptive capability.
3D Knowledge (3DK) – The 3D Knowledge Model is a systems-thinking framework that maps team knowledge over time (past, present, future), cross-team collaboration, and alignment to strategic intent to ensure that organizational behavior, learning, and execution remain integrated and adaptive in delivering digital business value.
Minimum Viable Capabilities (MVC) – The Minimum Viable Capabilities (MVCs) model supports the seven essential, system-level organizational capabilities—Govern, Assure, Plan, Design, Change, Execute, and Innovate—required to reliably create, protect, and deliver digital business value in alignment with strategy-risk intent.
The models work together to enable the following organizational capabilities:
A Governance Overlay that replaces fragmentation with unity. The DVMS provides organizations with a structured way to connect strategy with day-to-day execution. Leaders gain a consistent mechanism to direct, measure, and validate performance across every system responsible for digital value.
A Behavioral Engine that drives high-trust, high-velocity decision-making. The DVMS embeds decision models and behavioral patterns that help teams think clearly and act confidently, even in uncertain situations. It is engineered to reduce friction, prevent blame-based cultures, and strengthen organizational reliability.
A Learning System that makes culture measurable, adaptable, and scalable. Culture becomes a managed asset—not an abstract concept. The DVMS provides a repeatable way to observe behavior, collect evidence, learn from outcomes, and evolve faster than threats, disruptions, or market shifts.
DVMS Benefits – Organizational and Leadership
Explainer Video – DVMS Organization and Leadership Benefits
Instead of replacing existing operational frameworks and platforms, the DVMS elevates them, connecting and contextualizing their data into actionable intelligence that validates performance and exposes the reasons behind unmet outcomes.
By adopting a DVMS, enterprises are positioned to:
- Maintain Operational Stability Amidst Constant Digital Disruption
- Deliver Digital Value and Trust Across A Digital Ecosystem
- Satisfy Critical Regulatory and Certification Requirements
- Leverage Cyber Resilience as a Competitive Advantage
The Digital Value Management System (DVMS) provides leaders with a unified, evidence-based approach to governing and enhancing their digital enterprise, aligning with regulatory requirements and stakeholder expectations.
For the CEO, the DVMS provides a clear line of sight between digital operations, business performance, and strategic outcomes—turning governance and resilience into enablers of growth and innovation rather than cost centers.
For the Board of Directors, the DVMS provides ongoing assurance that the organization’s digital assets, operations, and ecosystem are governed, protected, and resilient—supported by evidence-based reporting that directly links operational integrity to enterprise value and stakeholder trust.
For the CIO, CRO, CISO, and Auditors, an integrated, adaptive, and culture-driven governance and assurance management system that enhances digital business performance, resilience, trust, and accountability.
DVMS – Accredited Certification Training Program
Explainer Video – The DVMS Training Pathway to Cyber Resilience
The Digital Value Management System® (DVMS) training programs teach leadership, practitioners, and employees how to integrate fragmented systems into a unified, culture-driven governance and assurance system that accounts for the resilience of digital value within a living digital ecosystem.
DVMS Cyber Resilience Awareness Training
The DVMS Cyber Resilience Awareness course and its accompanying body of knowledge publication educate all employees on the fundamentals of digital business, its associated risks, the NIST Cybersecurity Framework, and their role within a shared model of governance, resilience, assurance, and accountability for creating, protecting, and delivering digital value.
DVMS NISTCSF Cyber Resilience Foundation Certification Training
The DVMS NISTCSF Cyber Resilience Foundation certification training course and its accompanying body of knowledge publications provide ITSM, GRC, Cybersecurity, and Business professionals with a detailed understanding of the NIST Cybersecurity Framework and its role in a shared model of governance, resilience, assurance, and accountability for creating, protecting, and delivering digital value.
DVMS Cyber Resilience Practitioner Certification Training
The DVMS Practitioner certification training course and its accompanying body of knowledge publications teach ITSM, GRC, Cybersecurity, and Business practitioners how to elevate investments in ITSM, GRC, Cybersecurity, and AI business systems by integrating them into a unified governance, resilience, assurance, and accountability system designed to proactively identify and mitigate the cyber risks that could disrupt operations, erode resilience, or diminish client trust.
A FastTrack Approach to Launching Your DVMS Program
Explainer Video – Scaling a DVMS Program
The DVMS FastTrack approach is a phased, iterative approach that helps organizations mature their DVMS over time, rather than trying to do everything simultaneously.
This approach breaks the DVMS journey into manageable phases of success. It all starts with selecting the first digital service you want to make cyber resilient. Once that service becomes resilient, it becomes the blueprint for operationalizing cyber resilience across the enterprise and its supply chain.
Company Brochures and Presentation
Explainer Videos
- DVMS Architecture Video: David Moskowitz explains the DVMS System
- DVMS Case Study Video: Dr. Joseph Baugh Shares His DVMS Story.
- DVMS Overlay Model – What is an Overlay Model
- DVMS MVC ZX Model – Powers the CPD
- DVMS CPD Model – Powers DVMS Operations
- DVMS 3D Knowledge Model – Powers the DVMS Culture
- DVMS FastTrack Model – Enables A Phased DVMS Adoption
Digital Value Management System® is a registered trademark of the DVMS Institute LLC.
® DVMS Institute 2025 All Rights Reserved







