IT compliance problems do not always start with technology. Across the 116 findings identified in fscom’s 2026 IT compliance report, governance, risk and oversight emerged as the most consequential control domain. It accounted for 39 findings, including 58% of all high-severity findings.
More importantly, firms with weaker governance also tended to present more numerous and more severe weaknesses elsewhere, from access control and data protection to incident response and third party risk. Governance maturity was one of the clearest indicators of overall control effectiveness, beyond firm size or sector alone.
This matters because governance determines who owns technology risk, what information reaches senior decision-makers, and whether weaknesses are identified, challenged and addressed.
Strong technical controls depend on the governance that supports them.
So, where are firms falling short, and what does good IT governance look like in practice?
Where are firms getting IT governance wrong?
Of the 39 governance, risk and oversight findings identified, seven were rated high impact, 28 medium and four low. Three recurring areas stood out.
1. Governance and information security frameworks
Many firms lacked a formally documented information security management system (ISMS) or equivalent, while IT governance was not always mapped to a recognised framework such as ISO 27001 or the NIST Cybersecurity Framework.
Board-level oversight was another weakness. Senior management was not always receiving regular, structured management information on IT and cyber risk. Where reporting did exist, it was often too technical to support effective board-level challenge and decision-making.
2. IT and cyber risk assessment
A significant number of firms either had no current cyber risk assessment or maintained one that was too generic to support meaningful control decisions.
Common gaps included failing to distinguish between inherent and residual risk, limited use of threat intelligence and assessments that were disconnected from wider risk and business continuity frameworks.
A cyber risk assessment should be a living risk management tool, not a point-in-time compliance exercise.
3. IT policies and procedures
We also identified outdated policies, gaps across key areas and policies that had not been formally approved or communicated. In some cases, employees were simply unaware that formal requirements existed.
Again, the question is not simply whether a policy exists. Firms need to demonstrate that it remains relevant, is understood by relevant staff, and is reflected in day-to-day operations.
Why does the gap between policy and practice matter?
One of the clearest themes from our reviews was that having a framework is not the same as having effective governance.
Most firms had policies, risk registers and governance structures of some kind. The challenge was evidencing that those controls were embedded, monitored and challenged in practice.
A policy may state that cyber risk is reviewed by the board. However, firms should be able to demonstrate what information the board receives, what decisions result from that information, whether actions are tracked, and whether effective challenge is evidenced.
What are we seeing in practice?
In our reviews, IT governance often struggles to keep pace with business growth and increasing operational complexity.
This reflects the report’s finding that rapidly scaling firms often demonstrated strong technical capability while lacking the formal governance, documentation and oversight expected of regulated firms.
The result can be gaps in ownership, board oversight and risk management that only become apparent as the firm’s technology environment becomes more complex.
In our experience, the firms in the strongest position are those that treat IT governance as something that evolves with the business, rather than something revisited only when regulation, an audit or an incident demands it.
What does good IT governance look like?
The more mature firms in our reviews demonstrated clear board-level ownership of ICT and cyber risk, structured management information and risk reporting, defined risk appetite, mature vendor oversight and evidence of continuous monitoring and improvement.
Yet only 20% of firms reviewed demonstrated mature governance. Half were assessed as developing, while 30% required improvement.
For most firms, therefore, the challenge is not starting from scratch. It is moving from having the right structures on paper to demonstrating that they work consistently in practice.
IT governance readiness check
Can your firm confidently answer yes to the following?
- Does the board understand the firm’s key ICT and cyber risks?
- Is ownership and accountability for those risks clearly defined?
- Does the board receive meaningful, risk-focused ICT and cyber management information?
- Are policies current, approved and understood by relevant staff?
- Has governance kept pace with changes to technology and third party dependencies?
- Can you evidence that key controls are designed, monitored and operating as intended?
If several answers are unclear, the issue may not be the absence of controls. It may be the governance around them.
What should firms do now?
Our findings point to five practical priorities:
- Establish a recognised governance framework: develop an ISMS aligned with ISO 27001 or an equivalent framework, proportionate to the firm’s risk profile.
- Define IT risk appetite: ensure the board formally approves clear thresholds and escalation criteria.
- Improve board reporting: provide structured, risk-focused IT management information at least quarterly.
- Strengthen cyber risk assessment: conduct a comprehensive assessment at least annually, updating it when material changes or emerging threats arise.
- Clarify ownership and challenge: map IT governance across the three lines of defence, with clear responsibility for ownership, oversight and challenge.
Importantly, strengthening governance does not necessarily require significant investment in new technology. Often, the gap is in the governance around it: clear ownership, meaningful MI, effective challenge and evidence that controls work.
The lesson from our 2026 IT compliance report is simple: IT compliance is not just a technology issue.
Strong IT governance enables firms to understand their risks, challenge weaknesses and demonstrate that the wider control environment is working effectively.
How fscom can help
fscom Compliance Maturity Specialists™ help regulated firms assess whether their IT governance and control frameworks are working effectively in practice, not simply whether the right policies exist.
Our specialists support firms through IT compliance reviews, IT audits, ISO 27001 gap assessments, DORA readiness and wider governance and control reviews.
Read the full 2026 IT compliance report for our findings and benchmarking across all five control domains.
If you want to understand where your firm’s IT governance may need strengthening, get in touch with our team.