Part VI — Governing Performance and Investment
Factory Governance and the Manufacturing PMO
How can the factory remain aligned, lawful, accountable, and adaptable without centralizing every decision?
Governance is a practiced relationship
A software organization can publish policies, appoint committees, assign owners, schedule reviews, and still leave consequential decisions effectively ungoverned. Authority may be ambiguous. Evidence may arrive after commitment. Assurance may become ceremonial. Exceptions may never expire. People affected by a decision may have no route to question it.
The central question is:
Who decides, assures, challenges, and learns across multiple Production Lines?
The bounded proposition is:
Governance is operating when accountability, authority, preparation, execution, assurance, challenge, exception, recourse, review, and evidence are explicit—and exercised.
This chapter calls the cross-line stewardship function the Manufacturing PMO. The name is author synthesis. It is not a validated industry role, a required department, or a renamed project office. The function may be performed by a small team, distributed among existing roles, or combined with a portfolio or governance office. Its fitness depends on the decisions it helps the organization make.
ISO/IEC 38500 provides principles for governing bodies and those supporting them in the current and future use of IT.C18-S01 ISO 37000 places purpose, oversight, accountability, stakeholder engagement, assurance, and transparent decisions within organizational governance.C18-S02 These standards support the architecture. They do not prove that adopting this chapter's design improves outcomes.
C18.1 — Keep accountability and authority distinct
The governing body remains ultimately accountable for the organization's actions and omissions. It can delegate authority. It cannot make accountability disappear into a committee, dashboard, PMO, supplier, algorithm, or Production Line.
For each consequential decision, record:
- the accountable body or executive;
- the decision owner and delegated scope;
- the law, policy, risk tolerance, or objective constraining the choice;
- who prepares the evidence and recommendation;
- who executes the decision;
- who provides independent assurance or challenge;
- who is affected and how their evidence enters;
- who owns any exception;
- who reviews the outcome; and
- how the decision can be questioned, corrected, or reconsidered.
These roles may be held by the same person for a low-consequence, reversible local choice. As consequence, irreversibility, distributional effect, legal obligation, shared dependency, or uncertainty increases, separation becomes more important.
NIST's Cybersecurity Framework 2.0 makes governance visible through risk strategy, roles, responsibilities, authorities, policy, and oversight. It is explicitly an outcome taxonomy rather than a prescribed implementation.C18-S03 That distinction is useful: a governance requirement can state what must be true without mandating one organization chart.
A decision-rights matrix can help, but it is not governance by itself. It often becomes stale at the boundary between formal categories. The live test is whether participants can answer:
- Who may decide now?
- What consequence exceeds that authority?
- Which evidence is required?
- Who can challenge the interpretation?
- What happens if the decision is wrong?
C18.2 — Distribute decisions without fragmenting responsibility
Local knowledge matters. A Production Line understands its demand, technology, operating conditions, and users more directly than a central office. Coherence also matters. One line can create consequences for shared identity, data, infrastructure, regulation, supply chain, accessibility, architecture, or public trust.
Authority should therefore be designed through questions:
- How consequential is the decision?
- How reversible is it?
- Which contextual knowledge is required?
- Which shared interfaces or assets are affected?
- Which obligations cannot be delegated?
- Who bears risk or burden outside the deciding group?
- How quickly must a decision be made?
- Which evidence would cause escalation or reconsideration?
These are prompts, not a universal allocation formula.
The default should be the smallest scope that can own the complete consequence. A Production Line can decide within an established policy envelope when effects remain local and reversible. A cross-line owner is needed when several lines share a dependency or capacity constraint. A governing body or delegated executive decides when the choice changes strategy, risk tolerance, legal exposure, material investment, or stakeholder consequence.
Escalation should add the missing authority or coherence—not confiscate the entire decision. A central group that repeatedly takes over local choices creates waiting, information loss, and learned helplessness. A local group that treats shared effects as someone else's problem creates fragmentation.
GovS 002 provides a current public example of mandatory portfolio, programme, and project governance roles with controls intended to be proportionate to work and risk.C18-R01 Its project-delivery context does not prescribe continuous software governance. It supports the more limited point that role clarity and proportionality can coexist.
C18.3 — Separate preparation, decision, execution, and assurance
Four activities are often collapsed:
- Preparation assembles alternatives, evidence, assumptions, affected groups, and a recommendation.
- Decision authorizes a choice and accepts its declared residual uncertainty.
- Execution performs the work within the authorized boundary.
- Assurance independently tests whether evidence, obligations, and controls justify proceeding.
Separating them makes conflicts visible. The group advocating investment should not silently define the evidence, approve the commitment, execute the work, and certify its own success.
Separation does not require four departments. Independence is a property of the decision: competence, authority to challenge, freedom from the relevant incentive, access to evidence, and protection from retaliation or suppression.
GOV.UK service assessments illustrate a bounded assurance process. A multidisciplinary panel examines evidence against the Service Standard, returns a result, and publishes an assessment report after fact checking.C18-R04 This does not establish effectiveness, perfect independence, or a complete appeal mechanism. It shows how assurance can be a defined evidence encounter rather than an invisible approval.
Assurance should be proportional. A low-consequence reversible change may need automated controls and peer review. A material, irreversible, safety-critical, rights-affecting, or cross-line choice may require independent specialists, affected-stakeholder evidence, legal review, operational readiness, and explicit residual-risk acceptance.
Assurance is not a guarantee. Passing a gate means the declared evidence and controls met the applicable decision condition. It does not make the future certain.
C18.4 — Govern exceptions as expiring decisions
Policies cannot anticipate every context. Exceptions are therefore part of governance, not proof that governance failed.
A governable exception records:
- the policy or control being departed from;
- the decision owner and affected scope;
- the evidence and rationale;
- the consequence and residual uncertainty;
- compensating controls;
- people or services bearing additional burden;
- start date and expiry;
- conditions for early withdrawal;
- remediation or replacement plan; and
- review outcome.
An exception without an owner becomes ambiguity. Without an expiry, it becomes shadow policy. Without affected-party evidence, it can transfer burden invisibly. Without a review outcome, the organization cannot learn whether the policy, exception, or underlying system should change.
Exception volume is not automatically good or bad. A rise may reveal a poor policy, changing context, more honest reporting, fragmented architecture, or weak enforcement. Chapter 16's measurement discipline applies: define the decision and construct before interpreting the count.
Recourse completes the loop. People need a route to question evidence, correct an error, disclose an impact, request reconsideration, or escalate beyond the original decision owner. The route must name an owner, response expectation, evidence handling, and protection appropriate to the consequence.
This is not a universal legal appeal model. Employment, regulatory, safety, procurement, and public-law contexts create different rights. The chapter's narrower requirement is that consequential governance should not make its own decisions unchallengeable.
Formal governance can still be absent in practice
Rules and meetings are activity evidence.
The U.S. Federal Information Technology Acquisition Reform Act gave agency CIOs a significant role in IT planning, budgeting, governance, and portfolio oversight. GAO's 2025 audit nevertheless found that OMB and 24 agencies had not fully followed selected requirements for annual portfolio and high-risk investment reviews.C18-R02 The finding does not establish how common this failure is outside U.S. federal government. It supports a critical distinction:
documented authority
≠ performed review
≠ acted-on challenge
≠ verified outcome
A Department for Education design history supplies a smaller first-party example. Its discovery described inconsistent assessment processes, repetitive manual work, teams struggling to demonstrate evidence, and weak accountability for risks raised in reports.C18-R05 It is a pre-outcome record, not proof that the subsequent service solved those problems.
Together, the cases warn against governance theater:
- a meeting without a decision;
- a dashboard without an authorized response;
- a risk without an owner;
- an exception without expiry;
- an assessment without follow-through;
- a role without exercised authority; or
- a published report without outcome review.
Evidence Status — Bounded. Current evidence supports explicit accountability, authority, portfolio roles, assurance, challenge, and review controls. It does not validate the Manufacturing PMO as an organizational unit or establish that this architecture improves production outcomes.
C18.5 — Define the Manufacturing PMO as stewardship
Traditional PMOs vary widely. Some enable portfolio decisions and capability. Others centralize templates, status, compliance, and project reporting. Renaming one does not change its function.
The Manufacturing PMO described here stewards six cross-line questions:
Demand
Which demands compete for attention? Who authorized them? Which obligations, users, and outcomes do they represent? Where is demand duplicated, hidden, or unowned?
Capacity
Where are material constraints? Which choices consume scarce capability? What work is displaced? Which assumptions and forecasts will later be reviewed?
Dependencies
Which Production Lines, Work Centers, Factory Assets, suppliers, policies, and services constrain one another? Who owns resolution and by when?
Economics
Which alternatives, lifecycle costs, risks, discovery options, public values, and distributional effects inform the choice? Chapter 17 owns the comparison method.
Evidence
Which decision records, definitions, provenance, assurance results, exceptions, dissent, outcomes, and forecast errors must remain traceable?
Improvement
Which recurring conditions require a local correction, shared asset, policy revision, capability investment, or governance change? Who follows the learning to a verified decision?
The function prepares and connects. It does not automatically decide. It makes unresolved choices and consequences visible, convenes the right authority and challenge, records the outcome, and follows it to review.
GAO's agile portfolio report describes selected companies using recurring portfolio reviews, iterative business cases, staged investment, and user evidence.C18-R03 This supports recurring stewardship as a bounded practice. It does not prescribe one cadence, organizational unit, or causal effect.
C18.6 — Prevent the stewardship function from becoming the factory
The Manufacturing PMO fails when it becomes:
- the owner of every priority;
- a central approval queue;
- a substitute for governing accountability;
- a status-report collection service;
- a surveillance function;
- a permanent exception broker;
- a second architecture board;
- an assurance team certifying its own recommendations; or
- a transformation office measured by continued existence.
Guardrails include:
- publish the decisions the function stewards and those it does not;
- retain named decision owners outside the function;
- measure time and burden imposed, not only reports produced;
- make assumptions, dissent, exceptions, and unresolved effects visible;
- review whether each recurring forum changes an authorized decision;
- distribute stewardship where contextual knowledge resides;
- rotate or independently challenge assurance roles;
- provide recourse for affected teams and stakeholders; and
- retire reports, meetings, and controls that no longer inform decisions.
Workforce evidence needs particular care. Cross-line telemetry can easily become individual surveillance. Governance data collected for capacity, risk, or flow does not automatically become valid for ranking or discipline. Chapter 22 owns the fuller treatment of voice, agency, skill, and work quality.
The factory governance record
For a consequential cross-line decision, ask:
- What decision is being made, and why now?
- Which body remains accountable?
- Who has delegated authority, within what boundary?
- Who prepares the evidence and recommendation?
- Who executes the decision?
- Which independent competence assures or challenges it?
- Which obligations, shared dependencies, and affected stakeholders matter?
- Which dissent, uncertainty, and missing evidence remain?
- Is an exception required; who owns it; when does it expire?
- How can an affected person question, correct, or request reconsideration?
- What outcome and forecast will be reviewed, by whom, and when?
- Which stewardship activity should continue, change, distribute, or retire?
The record is not a universal RACI. It is a test of whether authority, evidence, challenge, and follow-through are visible at the consequence of the decision.
Figure F18.1 production specification: Consequence-Based Decision Architecture
Figure F18.2 production specification: Manufacturing PMO Stewardship Loop
What to remember
Governance is practiced, not declared.
Governing accountability cannot disappear through delegation.
Distribute authority to the smallest scope that can own the complete consequence.
Separate preparation, decision, execution, and assurance where consequence requires it.
Treat exceptions as owned, evidenced, expiring decisions.
Provide a route to question, correct, or reconsider consequential choices.
Use the Manufacturing PMO as an optional stewardship function—not a required department.
Make authority, challenge, and follow-through visible—then test whether they operate.
From governance to diagnosis
Governance establishes who can decide and learn. It does not tell the organization which constraint to address first. Chapter 19 begins the introduction sequence by diagnosing the production system before prescribing a design.
C18-S01: [C18-S01] ISO, ISO/IEC 38500:2024 — Governance of IT for the organization. C18-S02: [C18-S02] ISO, ISO 37000:2021 — Governance of organizations. C18-S03: [C18-S03] NIST, Cybersecurity Framework 2.0, 2024. C18-R01: [C18-R01] Government Project Delivery, Government Functional Standard GovS 002: Project Delivery, v2.1, 2025. C18-R02: [C18-R02] U.S. GAO, IT Portfolio Management, GAO-25-107041, 2025. C18-R03: [C18-R03] U.S. GAO, Leading Practices: Agile Portfolio Management and Iterative Business Cases, GAO-25-107130, 2025. C18-R04: [C18-R04] GOV.UK Service Manual, “What happens at a service assessment,” current 2024. C18-R05: [C18-R05] Department for Education, “Introducing Assure your service,” 2023.