01 — GOVERNANCE & RISK

PROTECTING ORGANIZATIONAL ASSETS THROUGH GOVERNANCE

Fraud is rarely the root cause. Weak governance is.

Organizations rarely suffer major losses because of a single bad decision. More often, losses emerge gradually from governance structures that no longer reflect how the business actually operates. Weak oversight, misaligned incentives, outdated controls, and limited operational visibility create conditions where risk becomes normalized long before it becomes visible.

Across audit, risk, transformation, and operating leadership roles, I learned to look beyond the individual control failure. My focus is understanding why the organization allowed the failure to occur, why it persisted, and how governance can be redesigned to make better decisions easier to make, easier to verify, and harder to bypass.

PHILOSOPHY

Governance should protect performance, not compete with it. Executives do not invest in governance because they want more policies. They invest because they need greater predictability, stronger accountability, better decisions, and confidence that the organization can scale without losing control of how value is created or protected.

A control that exists only on paper is not a control.

Sustainable governance must be visible in operating behavior: in who can decide, what evidence is required, how exceptions are escalated, how partners are reviewed, and how leaders know whether the system is still working.

MY APPROACH

The Living Governance Model

This is not a linear audit program. It is a set of five lenses applied together throughout diagnosis, design, implementation, and management. The lenses remain constant while the business objective, operating environment, and risk profile change.

01

Understand the business before evaluating the controls

Map how value is created, how decisions are made, where money and information move, which parties depend on one another, and what constraints shape behavior.

02

Identify systemic patterns, not isolated findings

Use walkthroughs, transaction analysis, interviews, data, and exceptions to find recurring behaviors. Ask what connects the findings — and what the organization has normalized.

03

Design governance around human behavior

Evaluate pressure, incentives, rationalization, error, convenience, and workarounds. Design controls that reduce opportunity while making expected behavior clear and practical.

04

Build independent verification into critical decisions

Define decision rights, segregation of duties, evidence requirements, authorization thresholds, analytical review, escalation, and monitoring where error could materially affect the business.

05

Treat governance as a living operating system

Embed governance in workflows, systems, reviews, scorecards, partner routines, and management cadence. Reassess as scale, responsibilities, technology, and risk change.

Organizations become resilient not by assuming people will always make the right decisions, but by designing systems that consistently encourage, verify, and sustain the right behaviors.

EVIDENCE IN PRACTICE

Three cases, chosen because together they prove the capability rather than display large numbers. Each demonstrates a different governance mechanism: verification, incentives, and normalized exceptions.

CASE 01 · VERIFICATION

When Vendor Trust Becomes a Business Risk

A long-standing vendor environment revealed how informal trust, weak independent verification, and repeated exceptions can allow financial exposure to accumulate.

SITUATION
A multi-division manufacturing organization relied on long-standing vendor relationships across procurement, maintenance, logistics, and general services. The environment had limited enterprise risk structure and inconsistent independent verification.
DIAGNOSIS
Vendor rotation and selection patterns suggested that apparent competition did not reflect genuine independence. Favoritism, bribery indicators, and procurement anomalies had become embedded in normal activity, allowing exposure to accumulate over several years.
MY ROLE
Built the enterprise risk and audit structure, directed the investigation, connected findings across functions, and translated the investigation into corrective governance.
ACTIONS
Mapped vendor and approval relationships; analyzed transactions and recurring patterns; tested segregation of duties and supporting evidence; investigated payroll, procurement, and vendor-selection anomalies; established risk matrices, approval controls, self-assessment, and ethics reporting mechanisms.
RESULTS
Approximately MXN 10 million in deviations identified across payroll, procurement, maintenance, logistics, and general affairs. Corrective controls and remediation structures implemented across five divisions, approximately 600 employees, and five manufacturing facilities.
LESSONS LEARNED
The issue was not simply a dishonest vendor or employee. The system allowed trust to replace verification and treated repeated exceptions as normal. Correcting the transaction without redesigning the pattern would not have held.
CASE 02 · INCENTIVES

When Good People Make Dangerous Decisions

A case involving pressure and incentives showed how experienced managers can rationalize decisions that protect a short-term objective while increasing enterprise risk.

SITUATION
Within a large corporate environment, experienced managers faced financial, tax, and budget pressures while operating through established processes and commercial relationships.
DIAGNOSIS
The immediate decisions could be rationalized as protecting a business objective, a future budget, or an important relationship. The governance risk arose because incentives and pressure made a locally defensible decision harmful at enterprise level.
MY ROLE
Challenged the rationale, validated the underlying transactions and tax positions, evaluated evidence and authorization, and reframed the issue from individual intent to system design.
ACTIONS
Compared operating practice with policy and financial evidence; validated tax and commercial assumptions with relevant stakeholders; identified where approvals, evidence, or independent challenge were insufficient; recommended clearer decision rights, validation, and escalation.
RESULTS
Identification of significant vendor-management deviations, approximately MXN 1 million in tax incentives secured through control validation, and strengthened governance surrounding invoicing, credit notes, and commercial decisions.
LESSONS LEARNED
Risk does not require malicious intent. Good people can make dangerous decisions when pressure, incentives, and incomplete visibility encourage them to protect the wrong objective. Governance must make the enterprise consequence visible before the decision is made.
CASE 03 · NORMALIZED EXCEPTIONS

When Organizations Promote the Problem

Recurring exceptions across functions demonstrated how organizations can unintentionally reward the behavior their policies are intended to prevent.

SITUATION
Across external audit, global internal audit, and enterprise risk assignments, recurring operational exceptions appeared in inventory handling, employee benefits, payroll, vendor billing, and third-party management.
DIAGNOSIS
Each exception could initially be explained as isolated, practical, or low risk. Over time, informal workarounds replaced the documented process, and people learned that bypassing the control was easier than following it.
MY ROLE
Observed operating reality, tested transactions, identified the recurring pattern, and elevated the issue from individual noncompliance to a broader governance weakness.
ACTIONS
Performed process walkthroughs, substantive testing, compliance assessment, data analysis, and stakeholder interviews; traced deviations across functions; tested compensating controls; presented findings and remediation requirements to senior and board-level stakeholders.
RESULTS
Findings included an inventory-removal weakness, improper storage of payment-card security data, unauthorized employee discounts, vendor overbilling, and approximately USD 2 million in vendor-management deviations and non-existent claims across global operations.
LESSONS LEARNED
Organizations promote a problem when they repeatedly tolerate the exception, reward the workaround, or fail to require evidence. The documented policy becomes irrelevant because the real process is the behavior leadership allows to continue.

BUSINESS OUTCOMES

Governance and Risk business outcomes
OUTCOME WHAT CHANGES EXECUTIVE VALUE
Risk reduction Material exposures are identified, prioritized, and remediated. Fewer surprises and lower probability of avoidable loss.
Executive visibility Critical risks, exceptions, ownership, and remediation status become visible. Better and faster decisions.
Accountability Decision rights, evidence, approvals, and escalation routes are explicit. Clear ownership without relying on individual heroics.
Control sustainability Controls become part of daily workflows, reviews, scorecards, and systems. Governance survives growth, turnover, and operating pressure.
Performance enablement Controls support the business objective instead of operating as a parallel compliance process. Greater predictability, scalability, and trust.
Customer & partner reliability Service and partner standards are consistently monitored and reinforced. More consistent external value delivery.

WHERE THIS LEADS NEXT

Governance & Risk establishes how the organization creates, protects, and can lose value. Once you understand that, the obvious next question is how to improve the way value is created — which is where Operational Excellence begins. Customer Success then ensures the resulting capabilities consistently deliver value externally, and AI & Intelligent Operations scales all three through systems, integration, data, and automation.

Strong governance is not the absence of risk. It is the ability to understand risk, assign ownership, verify critical decisions, and adapt before operating reality outgrows the system.

LET'S JOIN FORCES