Solving the Complexity Problem – Why Your Board Is Governing the Wrong Kind of Risk
David Nichols – Co-Founder and Executive Director of the DVMS Institute
Before I built governance systems, I served in submarines. The environment a submarine operates in does not permit a second chance to be wrong about the situation it is actually in. The discipline required for a known, stable problem is not the discipline required for one unfolding in real time with incomplete information, and confusing the two carries consequences no checklist can absorb.
That distinction now sits squarely at the center of how I evaluate every governance program I encounter, and it is the argument at the heart of Governing by Assurance, the book Rick Lemieux and I wrote for the DVMS Institute. Most boards are not under-governed. They are governing the wrong kind of problem with the wrong kind of method, and the gap between the two is where risk, liability, and lost value accumulate.
Four Kinds of Problems, One Governance Method
A well-established decision framework called Cynefin sorts every situation an organization faces into one of four domains, based on how visible the relationship between cause and effect actually is. Boards that understand this distinction govern differently and more effectively than boards that do not.
Clear problems have an obvious best practice, such as the segregation of duties in accounts payable, standard financial close procedures, and routine access provisioning. Best practice exists, is known, and should simply be applied. This domain does not need board attention, and a governance program that spends board time here is misallocating its most limited resource.
Complicated problems require expert analysis but are ultimately knowable. Designing a regulatory compliance program, structuring a tax position, and architecting a data center migration. These are hard problems, but the right experts, given enough time, analyze their way to a correct answer, document it, and audit against it. This is the domain traditional governance, risk, and compliance practice was built for, and it remains the right tool here. Control catalogs, policy manuals, and compliance checklists earn their place in this domain.
Complex problems do not work this way, and this is where most of the actual exposure in a modern enterprise sits. Third-party and vendor relationships, interdependent cloud and SaaS environments, AI-enabled processes, and the judgment calls people make under pressure do not hold still long enough to be fully documented in advance. Cause and effect in this domain only becomes visible after the fact. No amount of upfront analysis can substitute for probing the system, observing the results, and revising what the organization believed it knew. A vendor that passed every questionnaire during onboarding can still be the source of the next breach, not because the questionnaire was wrong, but because it was answering a Complicated-domain question about a Complex-domain relationship.
Chaotic problems have no visible cause-and-effect in the moment. A live ransomware incident, a sudden regulatory enforcement action, a merger closing on a deadline that outruns due diligence. The only responsible move in this domain is to act first, using the capability decided upon and rehearsed in advance, and make sense of the full picture afterward. A board that expects a Chaotic event to be handled with the same deliberative process used for a Complicated one will watch its organization freeze at the exact moment speed matters most.
A single strategic decision can pass through all four domains within months. Consider an acquisition. Valuing the target and structuring the deal are complicated tasks, suited to financial and legal experts working through a knowable problem. Integrating the two organizational technology environments, cultures, and control philosophies afterward is Complex work, where the actual behavior of the combined entity only becomes visible as integration proceeds, no matter how thorough the pre-close diligence. And if a control gap surfaces mid-integration, a legacy system nobody fully understood, carrying access it should never have had, the organization is suddenly in Chaotic territory, needing to act before it can fully diagnose. A board with instruments built only for the Complicated phase of that sequence is unprepared for the two phases that follow it, and those two phases are where deals actually go wrong.
Why the Mismatch Is a Governance Failure, Not an Operational One
Every board I have observed governs primarily through Complicated-domain instruments. Policy documents. Control frameworks. Annual audits. Quarterly compliance attestations. These instruments are necessary, and none of them is wrong to use. They are simply insufficient for the Complex and Chaotic conditions that generate most of the actual risk in an enterprise, and such insufficiency is not merely an operational inconvenience. It is a governance failure because governance exists precisely to give a board confidence that the organization performs as claimed under real-world conditions, not merely on paper.
This is why boards are repeatedly surprised by incidents occurring inside organizations with clean audit histories and fully documented control environments. The audit assessed whether the Complicated-domain instruments were in place and followed. It did not, and structurally could not, measure whether the organizational Complex-domain behavior matched what those instruments assumed. A green dashboard built entirely from Complicated-domain evidence tells a board almost nothing about how the organization will behave next, because cause and effect only become visible after the fact.
A board carries a duty of oversight, not merely a duty to receive reports. That duty is difficult to discharge on Complicated-domain evidence alone, because Complicated-domain evidence answers whether a policy exists, not whether the organization behaves as the policy claims under the conditions that actually produce loss. A board that can only point to a policy manual and a clean audit, after a Complex-domain failure it had no visibility into, sits in a materially weaker position than a board that can point to a continuous evidentiary record showing how the organization actually performed at the boundary in question. The difference is not a matter of paperwork. It is the difference between demonstrable oversight and its appearance.
The System on Paper and the System Under Pressure
This gap between the documented system and the operating system is the starting premise of Governing by Assurance. Most organizations have governance. Few actually govern. Policies exist. Frameworks are documented. Audits are completed. And the system on paper and the system in practice are rarely the same, because the paper system was built for a Complicated world, and daily practice happens in a Complex one, with occasional excursions into Chaotic territory; the paper system was never designed to survive.
That gap is where accountability quietly dissolves. When an incident occurs, and eventually one will, the question a board must be able to answer is not whether a policy existed. It is whether the organization can produce evidence, gathered as a byproduct of how the organization actually operated, that its governance claims held under real conditions. Most organizations cannot answer that question because their entire evidentiary base is Complicated-domain documentation applied to a Complex-domain reality. This is as much a fiduciary exposure as an operational one.
Governing by Assurance, Not by Documentation
Our answer is not another framework layered on top of the ones an organization already runs. It is GRAA: Governance, Resilience, Assurance, and Accountability, a DVMS operating overlay that governs each domain with the method that domain actually requires, rather than forcing every domain through the same Complicated-domain lens of policy and audit.
GRAA asks a different question from most governance programs. Not only are we compliant, as demonstrated by the artifacts we can produce. Instead, can we show, with evidence, that the organization performs as claimed, under real conditions, right now, in the domain it is actually operating in? That evidence accumulates continuously, as a byproduct of how the organization runs its boundaries day-to-day, rather than being assembled defensively once a year for an auditor or hastily reconstructed after an incident for a regulator.
This is what governing by assurance means as distinct from governing by documentation. Documentation proves that a policy was written. Assurance proves the organization behaves the way the policy claims, backed by a standing evidentiary record a board, a regulator, or an examiner can read directly, rather than a narrative the organization has to construct under pressure after something has already gone wrong.
The Imperative
The case for domain-appropriate governance was already strong before artificial intelligence entered enterprise operations at scale. It is considerably stronger now. AI-enabled processes compress the time between a decision and its consequence, extend decision-making authority into systems that no single expert fully understands end-to-end, and generate exactly the kind of interdependent, only-visible-in-hindsight behavior that defines the Complex domain. A governance program still built entirely around Complicated-domain instruments, annual policy reviews, and static control catalogs, was already lagging the pace of a Complex enterprise before AI entered the picture. It cannot keep pace with one accelerated by it. Boards that update their governance model now, before the gap becomes visible in an incident, are making a considerably better trade than boards that wait to update it afterward.
What This Requires of the Board
A board does not need to master Cynefin to apply this. It needs to ask a different set of questions of its management team. Which of the organizational critical boundaries are being governed as though they were Complicated when they are actually Complex? Where has a control catalog and an annual audit been substituted for continuous evidence on something that changes faster than an annual cycle can track? What capability has been pre-declared and rehearsed for the Chaotic events already known to be possible, rather than assumed to be handled well through improvisation under pressure? And when management expresses confidence in a capability, is that confidence backed by evidence the organization can produce on demand, or by the absence of a recent incident?
These questions reframe governance from a compliance exercise the board reviews periodically into a standing discipline the board can interrogate at any time. That reframing is the actual value of matching the governance method to the problem domain, and it is available to any board willing to ask which domain it is actually governing before deciding how to govern it.
Read the Book
Governing by Assurance: Bridging the Gap Between Intent and Reality lays out this argument in full, along with the GRAA model and the practical shift from governing by documentation to governing by assurance that boards, risk committees, and senior management teams can apply directly. It is the first book in the Assurance Now series from the DVMS Institute, co-authored with Rick Lemieux, and is now available.
Get your copy on Amazon: https://www.amazon.com/Governing-Assurance-Bridging-Between-Reality-ebook/dp/B0H7NJ1WS3
About the Author

Dave is the Executive Director of the DVMS Institute.
Dave spent his “formative years” on US Navy submarines. There, he learned complex systems, functioning in high-performance teams, and what it takes to be an exceptional leader. He took those skills into civilian life and built a successful career leading high-performance teams in software development and information service delivery.
Digital Value Management System® is a registered trademark of the DVMS Institute LLC.
® DVMS Institute 2026 All Rights Reserved


