A governance structure is the formal arrangement of authority, accountability, decision-making rights, and control mechanisms within an organisation, system, protocol, or jurisdiction that determines how strategic direction is set, resources are allocated, obligations are enforced, and stakeholde…

Semantic Classification

Content

Compositional Relationships (Components)

SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:BoardOfDirectors))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:AuditCommittee))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:RemunCommittee))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:RiskManagementFunction))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:VotingMechanism))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:DecisionRightsPolicy))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:hasPart reg:AccountabilityMechanism))

## Dependency Relationships
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:requires reg:StakeholderMapping))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:requires reg:PrincipalAgentContract))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:requires reg:TransparencyObligation))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:requires reg:EnforcementMechanism))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:requires reg:IncentiveAlignmentScheme))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:dependsOn reg:ComplianceFramework))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:dependsOn reg:RegulatoryMandate))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:dependsOn reg:AuditCapability))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:dependsOn reg:LegalPersonality))

## Capability Relationships
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:enables reg:StrategicDecisionMaking))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:enables reg:RiskOversight))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:enables reg:StakeholderAccountability))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:enables reg:ResourceAllocation))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:enables reg:ConflictResolution))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:supports reg:AIGovernanceDeployment))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:supports reg:DataGovernanceProgram))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:supports reg:DecentralisedProtocolGovernance))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:supports reg:CorporateComplianceProgram))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:supports reg:ESGReporting))

## Implementation Relationships
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:CorporateGovernanceCode))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:COBITFramework))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:NISTAIRiskManagement))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:ISOIEC42001))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:DAMADMBOKDataGovernance))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:TokenWeightedVoting))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:implements reg:QuadraticVoting))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:uses reg:SmartContractProxy))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:uses reg:MultiSigCouncil))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:uses reg:TimelockMechanism))

## Reduction Relationships
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:reduces reg:AgencyCost))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:reduces reg:InformationAsymmetry))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:reduces reg:CorruptionRisk))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:reduces reg:GovernanceFriction))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:reduces reg:StakeholderConflict))

## Association Relationships
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:relatedTo reg:InstitutionalDesign))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:relatedTo reg:PublicAdministration))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:relatedTo reg:PoliticalEconomy))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:relatedTo reg:OrganisationalTheory))
SubClassOf(reg:GovernanceStructure
  ObjectSomeValuesFrom(reg:relatedTo reg:DAOGovernance))

## Data Properties (Characteristics)
DataPropertyAssertion(reg:hasIdentifier reg:GovernanceStructure "AI-1003"^^xsd:string)
DataPropertyAssertion(reg:authorityScore reg:GovernanceStructure "0.87"^^xsd:decimal)
DataPropertyAssertion(reg:agencyCostReduction reg:GovernanceStructure "0.35"^^xsd:decimal)
DataPropertyAssertion(reg:stakeholderTypes reg:GovernanceStructure "6"^^xsd:integer)
DataPropertyAssertion(reg:primaryFrameworks reg:GovernanceStructure "8"^^xsd:integer)

## Property Constraints
SubClassOf(reg:GovernanceStructure
  DataAllValuesFrom(reg:requiresAccountability xsd:boolean))
SubClassOf(reg:GovernanceStructure
  DataSomeValuesFrom(reg:votingMechanismType xsd:string))
SubClassOf(reg:GovernanceStructure
  DataMinCardinality(1 reg:hasDecisionBody xsd:string))
SubClassOf(reg:GovernanceStructure
  DataMinCardinality(1 reg:hasEnforcementMechanism xsd:string))

## Annotations
AnnotationAssertion(rdfs:label reg:GovernanceStructure "Governance Structure"@en)
AnnotationAssertion(rdfs:comment reg:GovernanceStructure "Formal arrangement of authority, accountability, decision-making rights, and control mechanisms within an organisation or system; spanning corporate governance (board, C-suite, audit committee under UK Corporate Governance Code 2024 and Companies Act 2006), IT governance (COBIT 2019, ITIL 4), data governance (DAMA DMBOK v2), AI governance (NIST AI RMF, ISO 42001, EU AI Act), and blockchain/DAO governance (token-weighted voting, quadratic voting, conviction voting across MakerDAO, Uniswap, Aave); theoretically grounded in principal-agent problem (Jensen and Meckling 1976), stakeholder theory (Freeman 1984), and stewardship theory (Davis et al. 1997); operationally reducing agency costs, information asymmetry, and stakeholder conflict whilst enabling strategic decision-making, risk oversight, and regulatory compliance."@en)
AnnotationAssertion(dcterms:identifier reg:GovernanceStructure "AI-1003"^^xsd:string)
AnnotationAssertion(dcterms:subject reg:GovernanceStructure "Corporate Governance, IT Governance, AI Governance, DAO Governance, Regulatory Compliance, Principal-Agent Theory"@en)

)

Property Characteristics

AsymmetricObjectProperty(reg:requires) AsymmetricObjectProperty(reg:enables) AsymmetricObjectProperty(reg:implements) AsymmetricObjectProperty(reg:reduces) TransitiveObjectProperty(reg:dependsOn) FunctionalDataProperty(reg:agencyCostReduction) FunctionalDataProperty(reg:authorityScore)

About Governance Structure

  • Governance structure is the overarching arrangement of decision rights, accountability relationships, and control mechanisms that determines how any collective — a corporation, a state agency, a software protocol, a data platform, or an AI model development programme — navigates competing interests, allocates resources, sets direction, and answers for its actions.
  • The concept is simultaneously a legal artefact (chartering documents, articles of association, trust deeds, on-chain constitutions defining inalienable protocol rules), an organisational design (reporting lines, committee mandates, delegated authorities, separation of duties), and an information architecture (what gets measured, disclosed, audited, and acted upon by whom and on what timescale).
  • Its fundamental purpose is to solve the principal-agent problem: whenever one party (the principal) must rely on another party (the agent) to take actions on their behalf, and the agent has superior information and potentially divergent interests, governance structures create the monitoring, incentive, and sanctioning mechanisms that make delegation viable without requiring principals to possess the same expertise as their agents.

Theoretical Foundations

  • The intellectual lineage of governance structure theory traverses three centuries. Adam Smith (1776) warned in The Wealth of Nations that directors of joint-stock companies, managing “other people’s money,” could not be expected to exercise the same watchful diligence as proprietors — an early articulation of agency costs predating the modern theory by 200 years.
  • Adolf Berle and Gardiner Means (1932) documented empirically the separation of ownership from control in large US corporations, demonstrating that by 1930 the 200 largest US non-financial corporations controlled 49.2% of corporate wealth while their diffuse shareholders exercised minimal actual control over management decisions. This established the research agenda that Jensen and Meckling (1976) formalised into quantitative agency theory.
  • The governance reform wave of the 1990s institutionalised board independence, audit committee oversight, and remuneration transparency as normative standards across Anglo-American capitalism: the Cadbury Report (1992) following the Maxwell Communications and BCCI scandals, the Greenbury Report (1995) on executive remuneration, the Hampel Report (1998), the Combined Code (1998), and the Higgs Review (2003) on the role and effectiveness of non-executive directors.
  • International convergence emerged through the OECD Principles of Corporate Governance (first 1999, substantially revised 2023 to address sustainability, digitalisation, and the full range of ownership structures across listed and unlisted companies), the G20/OECD alignment process, the EU Shareholder Rights Directive II (2017/828/EU strengthening long-term engagement and say-on-pay voting), and the non-financial reporting cascades under the EU Corporate Sustainability Reporting Directive (CSRD 2022) and associated European Sustainability Reporting Standards (ESRS).
  • These frameworks collectively define a five-pillar model of corporate governance structure: (1) board composition and independence ensuring strategic oversight without management capture; (2) audit and internal control providing assurance on financial integrity and risk management effectiveness; (3) executive remuneration alignment linking pay to long-term value creation rather than short-term earnings management; (4) shareholder rights and engagement enabling principals to exercise meaningful oversight; and (5) stakeholder disclosure and ESG accountability enabling external accountability for non-financial impacts.

Theoretical Synthesis: Levels of Governance Rules

  • Building on Ostrom (1990) analysis of institutional arrangements governing shared resources, governance structure theory distinguishes three nested levels of rules that operate simultaneously:
  • Constitutional-choice rules establish the meta-level constraints within which collective choices are made. In corporations these are the articles of association, special resolutions requiring 75%+ shareholder approval, regulatory thresholds (change of control triggers, mandatory bid rules under the Takeover Code), and in DAOs the immutable core protocol invariants hardcoded at genesis that can only be changed through extreme supermajority votes. Constitutional rules are the most expensive to change and provide the strongest governance stability guarantees.
  • Collective-choice rules govern the processes by which operational rules are made and changed. In corporations: board procedures, committee terms of reference, delegation of authority matrices, shareholder meeting procedures. In DAOs: governance proposal formats (EIP/AIP templates), voting thresholds, quorum requirements, timelock periods. Collective-choice rules define the governance process through which all other governance decisions are made.
  • Operational rules specify the day-to-day activities and decisions that agents must, must not, or may take. In corporations: spending approval limits by seniority, hiring authority thresholds, capital expenditure procedures, data processing policies. In DAOs: parameter adjustment bounds (e.g., Compound’s Comptroller allowing interest rate model parameter changes within pre-approved ranges without full governance vote), guardian veto powers within constrained domains.
  • This three-level structure explains a common failure mode: organisations attempting to resolve operational problems by redesigning constitutional rules (over-engineering) or attempting to fix constitutional problems through operational patches (under-engineering). Effective governance structure diagnosis begins by correctly identifying which level of rule has broken down.

Components and Architecture

Corporate Governance Architecture

  • The board of directors sits at the apex of corporate governance structure as the primary accountability body between shareholders and management. In the unitary board model (dominant in UK, US, most Commonwealth jurisdictions), a single board combines executive directors (who manage the business) with non-executive directors (NEDs who provide oversight, strategic challenge, and external perspective).
  • The UK Corporate Governance Code 2024 requires that boards of premium-listed companies have a majority of independent NEDs; that the roles of chair and chief executive are separated into distinct individuals; that a formal, rigorous, and transparent procedure governs board appointments through a nominations committee; that board performance is evaluated annually (externally facilitated every three years for FTSE 350 companies); and that boards report on board culture and diversity targets with explanations for non-compliance.
  • The audit committee mandate spans: external auditor appointment and independence monitoring (preventing audit partner over-familiarity or fee dependence exceeding 70% of audit firm revenue from one client), review of financial statements for material misstatement risk, oversight of the internal audit function’s scope, resources, and independence, whistleblowing policy effectiveness, and review of the company’s approach to anti-bribery and fraud prevention (UK Bribery Act 2010, Criminal Finances Act 2017, Economic Crime and Corporate Transparency Act 2023).
  • Post-Sarbanes-Oxley (US SOX 2002) and its UK equivalents, audit committees have taken on quasi-judicial status as governance guardians of financial integrity. The FRC Audit Quality Review (AQR) programme publishes annual inspection findings on the quality of FTSE 350 audit engagements, with results feeding directly into regulator assessments of audit committee effectiveness. The FRC’s 2024 Corporate Reporting Review identified audit committee climate-related financial disclosures as a key area requiring improvement.
  • The two-tier board model (Germany, Netherlands, Austria, Scandinavia under Mitbestimmung co-determination law) separates a supervisory board (Aufsichtsrat — up to 50% employee representatives in German companies with >2,000 employees, plus shareholder representatives) from a management board (Vorstand of executive directors). This model provides stronger structural separation between governance oversight and operational management, embedding employee voice in governance at constitutional level rather than through voluntary consultation, and is credited with longer executive tenure and more patient capital allocation in German Mittelstand companies.
  • Board committee architecture in a typical large UK listed company includes: audit committee (minimum 3 independent NEDs, financial expertise requirement), remuneration committee (minimum 3 independent NEDs, sets CEO/CFO pay and all senior management remuneration policy), nominations committee (board composition planning, succession planning, diversity), and risk committee (particularly in financial services, overseeing risk appetite framework, material risk identification, stress testing). Some FTSE 100 companies have added: sustainability/ESG committee (climate governance), technology/cyber committee (AI and digital risk oversight), and responsible business committee (ethics, purpose, stakeholder engagement).
  • FTSE 100 board data (BoardEx/Spencer Stuart 2025): average board size 11.3 members, 55% independent NEDs, 40% female directors (up from 12.5% in 2015 following Hampton-Alexander Review 33% target achieved 2020), 14% ethnic minority directors (Parker Review “one by 2021” target met by 80% of FTSE 100), average CEO tenure 5.2 years, average NED tenure 6.1 years, average audit committee chair tenure 4.7 years.

IT Governance Frameworks

  • COBIT 2019 (Control Objectives for Information and Related Technologies, ISACA) is the dominant enterprise IT governance framework, restructured from COBIT 5’s five principles to six: (1) provide stakeholder value, (2) holistic approach, (3) dynamic governance system, (4) distinct governance from management, (5) tailored to enterprise needs, (6) end-to-end governance system covering all internal and external IT service providers.
  • COBIT 2019 defines 40 governance and management objectives across five domains:
  • EDM (Evaluate, Direct and Monitor): governance domain for board and C-suite covering EDM01 (ensure governance framework setting and maintenance), EDM02 (ensure benefits delivery), EDM03 (ensure risk optimization), EDM04 (ensure resource optimization), EDM05 (ensure stakeholder engagement).
  • APO (Align, Plan and Organise): 14 management objectives covering strategy, architecture, innovation, portfolio, budget, quality, risk, security, data, suppliers, and organisational structure.
  • BAI (Build, Acquire and Implement): 10 management objectives covering programme management, requirements definition, solution identification, vendor development, change management, and knowledge management.
  • DSS (Deliver, Service and Support): 6 management objectives covering operations management, service requests, problem management, continuity management, security services, and facilities management.
  • MEA (Monitor, Evaluate and Assess): 4 management objectives covering performance reporting, internal control, external compliance, and assurance provision.
  • COBIT 2019 introduced a governance system tailoring process allowing organisations to select governance components based on their context (enterprise strategy, risk profile, IT-relative size, threat landscape, compliance requirements), producing a context-specific governance system rather than a one-size-fits-all framework.
  • ITIL 4 (Information Technology Infrastructure Library, Axelos/PeopleCert since 2019) reframed IT service management within a Service Value System (SVS) comprising: guiding principles (value focus, holistic thinking, iterate with feedback, collaborate and promote visibility, think and work holistically, keep it simple and practical, optimise and automate), governance component (directing, evaluating, monitoring the service system), service value chain (plan, improve, engage, design and transition, obtain and build, deliver and support), 34 management practices, and continual improvement.
  • ITIL 4’s governance component explicitly addresses accountability for service management decisions, distinguishing the governance role (setting policy and direction for the service value system) from the management role (executing and optimising service delivery). The governance activities — evaluate (current performance and future needs), direct (set direction and policy), monitor (check alignment and performance) — parallel COBIT’s EDM domain and ISO/IEC 38500:2015 (IT governance for organisations).
  • ISO/IEC 38500:2015 provides a high-level governance model for ICT defining six principles: responsibility, strategy, acquisition, performance, conformance, and human behaviour. It is governance-framework agnostic and positions the governing body (board) rather than IT management as the primary audience, distinguishing governance (evaluate-direct-monitor) from management (plan-build-run-monitor). UK central government IT governance references ISO 38500 through HMRC’s Technology Transformation Programme governance and GDS (Government Digital Service) standards for digital service delivery.

Data Governance

  • DAMA DMBOK v2 (Data Management Body of Knowledge, Data Management Association International, 2017) defines data governance as “the exercise of authority, control and shared decision-making (planning, monitoring and enforcement) over the management of data assets,” positioning data governance at the centre of eleven data management knowledge areas.
  • The eleven DMBOK knowledge areas — data governance, data architecture, data modelling and design, data storage and operations, data security, data integration and interoperability, document and content management, reference and master data, data warehousing and business intelligence, metadata, and data quality — all require governance authority to function, making governance the hub that coordinates all other data management functions.
  • The DAMA governance structure components are: data governance organisation (chief data officer/CDO, enterprise data architects, domain data stewards, data custodians/engineers, data owners in business units, data users); data governance operating model (centralised — single governance authority, consistent standards, limited flexibility; federated — domain autonomy with central coordination, fit for purpose but potential fragmentation; hybrid — central standards with federated execution, most common in large enterprises); data governance councils (cross-functional steering bodies for data policy, priority decisions, dispute resolution between domains); and data policies and standards (data naming conventions, data quality thresholds, retention schedules, classification schemas, access control policies).
  • Data governance structure maturity models assess progression across five levels: (L1) initial/ad hoc — reactive data management, no defined governance roles; (L2) managed — defined ownership of critical data, localised governance; (L3) defined — enterprise-wide data governance framework, documented policies, CDO role established; (L4) measured — KPI-driven governance with data quality metrics, automated monitoring; (L5) optimised — governance enables data as a competitive asset, continuous improvement, AI-augmented data quality management. EDM Council DCAM v2 (Data Capability Maturity Model), Stanford Data Governance Framework, and Gartner Data Governance Maturity Model all use similar five-level structures.
  • In the UK, data governance is additionally shaped by the UK GDPR (Data Protection Act 2018), ICO accountability framework requiring data protection officers (mandatory for public authorities and organisations processing special category data at scale), privacy impact assessments (DPIAs), records of processing activities (RoPA), and data breach notification within 72 hours. The NHS data governance model includes DSPTs (Data Security and Protection Toolkit) annual assessments against ten National Data Guardian standards that all NHS organisations must complete, covering data security, staff training, clinical risk, and data quality.

AI Governance Structure

  • AI governance structure has emerged as a distinct governance domain since 2018, driven by the recognition that AI systems pose novel accountability challenges: their outputs can be consequential but opaque (black-box models), their failure modes are often systemic rather than individual (biased training data produces discriminatory outcomes at population scale), and their development pipelines span multiple organisational layers (data providers, foundation model developers, fine-tuners, application deployers, end users) creating complex accountability chains where responsibility can be diffused across actors.
  • The EU AI Act (Regulation 2024/1689, fully applicable from August 2026 for high-risk systems, phased from February 2025 onwards) mandates a specific AI governance structure for providers and deployers of high-risk AI systems. Risk classification determines governance obligations:
  • Unacceptable risk (prohibited practices from February 2025): social scoring by public authorities, subliminal manipulation, exploitation of vulnerabilities, real-time biometric surveillance in public spaces (with law enforcement exceptions).
  • High risk (Annex III systems including AI in critical infrastructure, education, employment, essential services, law enforcement, migration, justice): mandatory risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), logging and traceability (Article 12), transparency and information provision (Article 13), human oversight (Article 14), accuracy/robustness/cybersecurity (Article 15), conformity assessment, registration in EU database, CE marking.
  • General purpose AI (GPAI) models (Article 53): transparency obligations, copyright compliance, for systemic risk models (>10^25 FLOPs training compute): adversarial testing, incident reporting, cybersecurity measures, energy efficiency reporting.
  • NIST AI Risk Management Framework 1.0 (January 2023) provides a voluntary US framework organising AI governance across four functions:
  • GOVERN: establishing and sustaining the culture, policies, processes, and accountability structures for AI risk management. Includes GOVERN 1.1 (policies and procedures for AI risk management are documented), 1.2 (accountability for AI risk management is established with relevant senior management), 1.3 (transparency and accountability are provided throughout the AI lifecycle), 1.4 (organisational teams are committed to diversity, equity, inclusion, and accessibility in AI design), 1.5 (processes for AI risk management incorporate practitioners with diverse roles and backgrounds), 1.6 (policies and procedures for AI risk management encompass the entire AI lifecycle), 1.7 (processes and procedures are in place for decommissioning AI systems).
  • MAP: contextualising AI risks by identifying the AI system, its intended uses, stakeholders, potential harms, and risk categories (harms to people, organisations, ecosystem). MAP activities include categorisation, risk framing, and establishing assessment methodology.
  • MEASURE: analysing and assessing identified AI risks using quantitative and qualitative methods, including testing, evaluation, validation, verification (TEVV), model documentation, bias testing, performance benchmarking, and third-party audits.
  • MANAGE: prioritising and treating identified risks through response plans, residual risk acceptance decisions, risk tracking, and monitoring for new risks arising from deployment context changes or model drift.
  • ISO/IEC 42001:2023 is the first international standard specifically for AI management systems, structured as a Plan-Do-Check-Act (PDCA) management system standard. Its structure mirrors ISO 9001 (quality) and ISO 27001 (information security): context of organisation (understanding internal/external issues, stakeholder needs), leadership (top management commitment, AI policy, roles and responsibilities), planning (risk and opportunity assessment, AI impact assessment), support (resources, competence, awareness, communication, documented information), operation (AI system development and deployment controls, supplier governance), performance evaluation (monitoring, internal audit, management review), and improvement (nonconformity management, continual improvement).
  • ISO 42001 Annex A provides 38 controls across 9 domains: AI policies, internal organisation, resources for AI systems, AI system lifecycle, AI stakeholders, responsible AI, AI system impact assessment, AI risk management, and AI system operation. By Q1 2026, over 180 organisations globally had achieved ISO 42001 certification with 600+ in assessment pipeline, including UK financial services firms (Lloyds Banking Group, Aviva), healthcare providers, and professional services firms seeking to demonstrate governance assurance to clients and regulators.

Decentralised and DAO Governance Structure

  • Blockchain protocol and DAO governance structures represent the most structurally novel governance innovation of the 2010s-2020s, replacing hierarchical authority with algorithmic rule execution and token-based democratic decision-making. The governance structure of a mature DeFi protocol typically comprises four interlocking layers, each handling a different speed and risk tier of governance decisions:
  • (1) On-chain governance handles major protocol decisions with full community participation: proposal submission (requiring a minimum token deposit threshold, e.g., 25,000 UNI for Uniswap, $100K DAI equivalent for MakerDAO, to prevent spam and ensure proposer skin-in-the-game), voting period (typically 3-14 days providing sufficient time for delegate activation and community deliberation), quorum threshold (minimum percentage of circulating supply participating, e.g., 4% for Compound, 40M UNI for Uniswap major decisions), approval threshold (simple majority or supermajority depending on proposal type), and automatic execution via governance timelock contract (24-72 hour delay providing final circuit-breaker opportunity for guardian intervention before execution).
  • (2) Optimistic governance handles routine parameter changes with low contention: proposals auto-execute after a challenge window (typically 48-72 hours) unless a multisig guardian raises an objection, delegating routine maintenance to protocol teams without requiring community mobilisation for every minor update. Used by Compound for interest rate model updates, Uniswap for fee tier additions, Aave for risk parameter adjustments within pre-approved ranges.
  • (3) Multi-signature council provides emergency circuit-breaker capability and handles grants/funding decisions requiring human judgement: 4-of-7 or 5-of-9 multisig of elected community representatives (e.g., Uniswap Foundation, Aave Grants DAO, Compound Treasury) can pause the protocol, execute emergency patches, or distribute grant funding without full governance vote when security incidents require immediate response. The multisig represents a temporary centralisation trade-off explicitly acknowledged in governance documentation as a security-safety backstop pending full decentralisation.
  • (4) Off-chain governance handles deliberation and sentiment before on-chain votes: Snapshot gasless voting for temperature checks and sentiment polls (zero gas cost via IPFS-stored signatures), Discourse/Commonwealth forum deliberation where proposals are debated and refined over 1-2 weeks before on-chain submission, Tally governance analytics dashboards (tracking delegate activity, voting history, proposal outcomes), and Agora/Boardroom proposal management platforms providing voter-facing interfaces accessible to non-technical token holders.
  • MakerDAO Endgame 2024 represents the most structurally ambitious DAO governance reform yet attempted: the single MKR token-weighted DAO is replaced with a hub-and-spoke architecture of SubDAOs (Spark Protocol, Aligned Voter Committees, Facilitators) each with delegated governance authority over specific protocol domains, an Aligned Delegates programme with reputation staking and performance bonds, and a new governance token (NewGovToken/NGT) designed at smaller denomination for broader retail participation, reducing plutocratic concentration. The reform addresses the empirical finding that in pre-Endgame MakerDAO, >60% of voting power concentrated in fewer than 20 addresses.
  • Uniswap governance (1B UNI total supply, ~400M circulating 2025) illustrates structural challenges endemic to large token-weighted DAOs: participation typically below 10% of circulating supply on most votes, delegation concentration with top 20 delegates controlling 40-50% of delegated power (Tally 2025), and the 2024 fee switch vote attracting $1.3B UNI participation (record) but revealing a governance trilemma — the vote met quorum but the treasury allocation clause created legal and tax complications that the governance structure had no mechanism to resolve without a secondary governance process. This illustrates how governance structures that are technically capable of making decisions can still fail if the decision space exceeds the governance structure’s legal/operational bandwidth.
  • Voting mechanism design involves fundamental trade-offs among five principal approaches:
  • Token-weighted voting (1 token = 1 vote): simplest to implement, Sybil-resistant (costly to acquire large holdings), but entrenches plutocracy and discourages small-holder participation. Standard in most DeFi protocols at launch.
  • Quadratic voting (Lalley and Weyl 2019): cost of k votes = k² tokens, reducing the marginal voting power of large holders and amplifying minority preferences. Theoretical optimality proven for public goods provision but requires Sybil-resistant identity to prevent wallet-splitting attacks (one holder splitting holdings across many wallets to reduce quadratic cost). Gitcoin grants uses quadratic funding (related mechanism) for public goods allocation.
  • Conviction voting (Commons Stack 2019): votes accumulate over time proportional to holding duration, rewarding long-term stakeholders whose accumulated conviction exceeds a threshold. Resists last-minute whale attacks (large purchases immediately before votes provide insufficient conviction). Implemented in Commons Stack, Giveth, Token Engineering Commons, and 1Hive Gardens.
  • Reputation-weighted voting: non-transferable reputation points earned through verified contributions (code commits, forum participation, grants completion). More meritocratic than token-weighted but requires on-chain identity infrastructure (Proof of Humanity, BrightID, ENS attestations) and is vulnerable to sybil attacks at the identity layer. Used in Coordinape peer recognition, SourceCred contribution tracking, and Praise protocol.
  • Futarchy (Hanson 2000): prediction markets determine governance outcomes by having token holders bet on measurable outcomes rather than voting on proposals directly, theoretically aggregating information most efficiently but practically limited to binary decisions with clearly measurable outcomes and short timescales. No major protocol has fully implemented futarchy; Augur, Gnosis, and various research DAOs have explored prediction market components.

Use Cases and Major Families

Corporate Governance Families

  • Listed company governance (UK premium/standard listed, FTSE All-Share 780+ companies) operates under mandatory UK Corporate Governance Code compliance (premium) or voluntary disclosure (standard), annual reporting obligations under DTR 7 on corporate governance statements, audit committee reports, remuneration policy/implementation reports, and Section 172(1) stakeholder statements. The Investment Association publishes annual governance expectations setting shareholder expectations on board composition, audit quality, executive pay, and climate governance, backed by the threat of coordinated “against” recommendations on director re-election votes.
  • Family-controlled company governance (c.35% of FTSE 250 by market cap, significantly higher in private markets globally) adapts the principal-agent framework to family principal/professional management agent dynamics, with additional governance complexity from inter-generational succession, family council structures (family councils separate from but interacting with the corporate board), family constitutions (sometimes registered as shareholder agreements or articles provisions) mediating between family shareholders and independent management, and the stewardship mandate that family governors often feel toward communities and legacy.
  • Cooperative and mutual governance (building societies, credit unions, mutuals, worker cooperatives, consumer cooperatives) operates under member-governance models where the principal is the member body rather than external shareholders. UK cooperatives number 7,000+ with £36B+ combined turnover (Cooperatives UK 2025), including the Co-operative Group (largest consumer cooperative in the world by sales, £10.8B revenue 2024), John Lewis Partnership (worker-owned department stores and Waitrose supermarkets, £12.4B revenue 2024), and hundreds of financial mutuals (Nationwide Building Society, Yorkshire Building Society, Coventry Building Society).
  • State-owned enterprise (SOE) governance adds a public interest accountability layer: HM Treasury guidance for UK government commercial organisations (Managing Public Money), public interest duties under sector-specific legislation (BBC Charter, Channel 4 statutory obligations, Network Rail licence conditions), parliamentary accountability through select committee hearings, National Audit Office value-for-money audits, and Cabinet Office Government Commercial Function governance standards (Government Commercial Operating Standards). NHS Foundation Trusts, Arm’s Length Bodies, and nationalised industries each operate under bespoke governance structures balancing public accountability with operational independence.

IT and Data Governance in Practice

  • Enterprise IT governance structures in large UK organisations typically implement COBIT 2019 through an IT Steering Committee (ITSC, chaired by CIO, includes business unit CIOs, CFO representative, CISO, and functional heads) reporting to the board audit committee on technology risk appetite, major project status, and regulatory technology compliance. An Architecture Review Board (ARB) controls technical standards, enterprise architecture decisions, and significant vendor selections. An AI/Data Committee (increasingly common from 2023) oversees AI model governance, data ethics, and GDPR compliance.
  • NHS England’s IT governance structure exemplifies complex public sector federated IT governance: NHS England Board (strategic direction), NHS England Digital directorate (formerly NHS Digital, merged 2023), 42 ICBs (Integrated Care Boards, each with a digital lead), individual NHS Trust CIOs (each trust has independent board and governance), and the Goldacre Review (2022) recommendations establishing Trusted Research Environments (TREs) for NHS data access governance. This multi-layer federated governance structure manages 1.3+ million NHS staff, 66 million patient records, and over 100 different EPR (Electronic Patient Record) systems.
  • Cloud governance structures for multi-cloud enterprise deployments involve: cloud governance councils defining cloud-first policies and guardrails; landing zone governance (Azure Policy/Blueprints, AWS Control Tower, GCP Organisation Policy Service) providing automated compliance enforcement at infrastructure level; cloud cost governance (FinOps Foundation framework: inform phase — visibility; optimise phase — efficiency; operate phase — continuous optimisation); and cloud security governance (CSA Cloud Controls Matrix v4, NCSC Cloud Security Principles 14 controls for UK public sector). The UK Government Cloud Strategy 2022 mandated G-Cloud procurement and NCSC cloud security principle compliance for all central government cloud deployments.

AI Governance in Financial Services

  • AI governance structures in UK financial services are shaped by the PRA’s SS1/23 model risk management supervisory statement (substantially updated 2024 for AI-specific risks including model opacity/explainability deficits, non-stationarity and distribution shift in live deployment, third-party AI supply chain risk from model API dependencies, and concentration risk from multiple firms using identical foundation models).
  • The FCA/PRA AI and Machine Learning Discussion Paper (DP5/22) and subsequent feedback statement (PS24/12) established regulatory expectations that AI governance structures in regulated firms must address: model explainability (sufficient for senior management oversight, regulatory scrutiny, and customer-facing adverse decisions under GDPR Article 22), ongoing monitoring (distribution shift detection, performance degradation alerts, fairness metric tracking), governance trail (audit log of model development, validation, approval, deployment, and decommissioning decisions forming the model lifecycle governance record), and senior manager accountability mapping (clear SMCR attribution of individual accountability for AI model outcomes).
  • Major UK banks (Barclays, HSBC, NatWest, Lloyds, Standard Chartered) have established AI governance committees at board or ExCo level: Barclays’ Responsible Technology Committee (board-level, chaired by independent NED with technology expertise, reviews AI deployment decisions for ethics and reputational risk), HSBC’s AI Risk Committee (Group Chief Risk Officer chaired, ExCo level), NatWest’s AI Ethics Committee, and Lloyds’ Digital Ethics Advisory Panel. These represent best-practice integration of AI governance into existing corporate governance architecture rather than a parallel governance silo.

Governance Structure Decision Rights Matrix

  • Effective governance structure design begins with a decision rights matrix mapping each major decision type to the appropriate governance level. The canonical framework (Weill and Ross 2004) identifies five IT governance decision domains applicable across all governance types:
  • Principles decisions: What role should this function play in the organisation’s overall strategy and operations? Who decides the principles? In corporate governance: board sets values and purpose; in IT governance: board/ExCo sets IT principles; in DAO governance: token holders set protocol constitutional invariants. Frequency: annually or when strategy changes.
  • Architecture decisions: What are the technical/structural standards that guide implementation choices? In corporate governance: board approves significant acquisitions, disposals, and structure changes; in IT governance: Architecture Review Board sets technology standards; in DAO governance: core developers propose protocol upgrades through governance. Frequency: quarterly to annually.
  • Infrastructure decisions: What shared services and capabilities will be built centrally vs. sourced externally? In corporate governance: board approves material outsourcing, joint ventures, and capital allocation decisions; in IT governance: CIO approves infrastructure investments; in DAO governance: treasury committee allocates grants and protocol development funding. Frequency: quarterly.
  • Application needs decisions: What business-specific applications are needed? In corporate governance: divisional boards or ExCo approve major business investments; in IT governance: business unit heads with IT steering committee approval; in DAO governance: SubDAOs or working groups approve domain-specific protocol applications. Frequency: ongoing.
  • Prioritisation decisions: How should competing investment demands be ranked? In corporate governance: board approves capital allocation framework, CFO prioritises within it; in IT governance: IT Steering Committee prioritises the project portfolio; in DAO governance: governance voting determines treasury allocation order. Frequency: annual (budget cycle) plus ongoing exceptions.
  • The Weill-Ross framework further distinguishes six governance archetype patterns by who makes each decision type:
  • Business monarchy: senior executives decide jointly — appropriate for high-stakes, cross-functional decisions where executive alignment is paramount.
  • IT monarchy: IT specialists decide — appropriate for technical architecture where business units lack the expertise to evaluate options.
  • Feudal: business unit leaders decide independently — appropriate for highly decentralised organisations where units have distinct operating models.
  • Federal: centre and business units decide jointly — appropriate for shared infrastructure decisions requiring coordination but with unit-specific needs.
  • IT duopoly: IT and one other group (business unit or ExCo) decide jointly — appropriate for application needs and infrastructure decisions.
  • Anarchy: each individual decides independently — generally undesirable, emerging from governance vacuum or governance failure rather than intentional design.
  • Research on 250+ enterprises (Weill and Ross 2004) found that companies in the top quartile of governance effectiveness generated 25% higher profits from IT investments than industry average, and average ROA 40% higher, demonstrating the direct financial value of well-designed governance decision rights structures.

Governance Failure Modes and Pathologies

  • Understanding governance failure modes is as important as understanding governance design principles. Six archetypal failure patterns recur across corporate, IT, data, and DAO governance contexts:

1. Board Capture and Management Entrenchment

  • Description: The governing body (board, governance council, multisig) fails to maintain independence from the entity it is supposed to oversee, becoming captured by management, founder shareholders, or protocol developers. Monitoring function collapses; accountability breaks down.
  • Corporate examples: Wirecard AG (German DAX company, €1.9B accounting fraud concealed 2014-2020; supervisory board captured by management culture, auditor EY failed to verify custodian accounts for years); Carillion plc (UK FTSE 250 construction/FM company, collapsed January 2018 with £5B pension deficit, £900M accounting provisions hidden in long-term contracts; audit committee failed to challenge aggressive accounting); WeWork 2019 pre-IPO (Softbank-backed, CEO Adam Neumann granted supervoting shares and self-dealing real estate transactions, board unable to challenge founder control).
  • DAO examples: Steemit blockchain governance capture (2020) where Tron Foundation founder Justin Sun used exchange-custodied user funds to vote his governance faction into control of the STEEM consensus mechanism, taking over a supposedly decentralised network using deposited customer assets — the depositors had not consented to their assets being used for governance voting.
  • Mitigations: independence standards for governing body members (UK Code’s majority independent NEDs provision), conflict of interest registers, mandatory rotation of auditors (EU mandatory rotation: PIEs must rotate after maximum 10 years, 20 with joint audit), supermajority requirements for founder-favoured decisions, staggered board terms preventing overnight board capture, token lockup periods for DAO founders preventing immediate voting with freshly acquired tokens.

2. Information Asymmetry and Strategic Opacity

  • Description: Agents exploit information advantages to conceal performance problems, misstate financial position, or prevent principals from making informed decisions. Occurs where governance structures lack adequate audit, reporting quality, or transparency obligations.
  • Corporate examples: Enron (2001, 11.1B for Autonomy, later wrote down $8.8B alleging accounting misrepresentation; KPMG audit disputed); Patisserie Valerie (UK AIM-listed, 2019 collapse: £94M accounting fraud concealed through manipulation of bank confirmation letters, audit by Grant Thornton failed to detect for multiple years).
  • AI governance example: “model card washing” — publishing model cards for AI systems that describe capabilities and limitations in misleading or insufficiently specific terms, creating the appearance of transparency while concealing material limitations relevant to high-risk deployment decisions.
  • Mitigations: robust external audit with genuine auditor independence, mandatory whistleblowing policies with anti-retaliation protections, granular technical documentation requirements (EU AI Act Article 11 requires technical documentation specifying training data, performance metrics, known limitations), regulatory spot-checks and market surveillance, short-seller research (Hindenburg, Gotham City Research, Muddy Waters) providing market-based accountability.

3. Governance Overload and Decision Fatigue

  • Description: Governance structures are designed with too many approval gates, sign-off requirements, and committee reviews, creating bottlenecks where decisions take so long that the organisation cannot respond to market changes, or where approvers become fatigued and rubber-stamp decisions without genuine scrutiny.
  • Symptoms: average proposal-to-decision time exceeding 6 months for operational decisions; low attendance at governance meetings indicating disengagement; high frequency of “noted” rather than “approved” or “challenged” outcomes; major decisions being pre-cooked outside formal governance channels and presented as faits accomplis.
  • DAO-specific: governance overhead cost in Ethereum gas fees ($50-200 per on-chain vote in high-gas periods) disincentivises small-holder participation, concentrating effective governance in well-capitalised whales, and creating governance fatigue where low-participation “yes” votes become the default path for complex proposals.
  • Mitigations: governance threshold calibration (only decisions above materiality thresholds require board approval), delegated authority frameworks with clear limits, time-boxing deliberation periods, consent vs consensus decision models (proposals pass unless actively opposed within a window), COBIT 2019’s principle of tailoring governance system complexity to enterprise context.

4. Regulatory Arbitrage and Governance Theatre

  • Description: Entities create governance structures that satisfy formal regulatory requirements while subverting the substantive accountability those structures are intended to provide — “governance as window dressing.”
  • Examples: crypto exchanges establishing nominally independent boards while founders retain majority voting control through multi-class share structures; AI companies publishing “responsible AI” commitments and governance frameworks while deploying systems without genuine internal scrutiny; SPACs (Special Purpose Acquisition Companies) using governance structures that allow founders to merge with target companies subject to less rigorous shareholder approval than conventional IPO governance requires.
  • FTX as paradigmatic failure: FTX Bahamas (2022 collapse) had a nominal board structure and “governance” documents but effective control was exercised by Sam Bankman-Fried and a small group of flatmates with no board minutes, no audit trail for $8B+ customer fund transfers to Alameda Research, and no functioning compliance or risk function. The governance structure was pure theatre; the board had no ability or inclination to challenge the founder.
  • Mitigations: substance-over-form regulatory approach (UK FCA’s outcome-focused regulation focusing on whether governance achieves accountability, not whether boxes are ticked), mandatory governance effectiveness assessments (UK Code provision on board performance evaluation), criminal liability for governance failure (UK Economic Crime and Corporate Transparency Act 2023 “failure to prevent fraud” offence creating strict liability for organisations failing to implement adequate fraud prevention procedures).

5. Governance Attack and Mechanism Exploitation

  • Description: In permissionless systems, actors deliberately exploit governance mechanism vulnerabilities to extract value, change protocol parameters for personal benefit, or paralyse governance to prevent unwanted changes.
  • DAO governance attacks: Beanstalk Farms (April 2022) — attacker used flash loan to acquire governance supermajority within a single Ethereum block, passed malicious governance proposal immediately, and drained 117M of protocol treasury funds to himself; Build Finance DAO (February 2022) — attacker acquired governance majority and transferred DAO treasury, GitHub repositories, and brand assets to themselves.
  • Mitigations: governance attack protections in protocol design (minimum proposal deposit burning on malicious proposals, vote delay periods preventing flash-loan governance attacks, quorum floors preventing minority passage), timelock delays (24-48 hours minimum between vote passage and execution providing guardian intervention window), and the structural shift toward optimistic governance for routine decisions with guardian veto reserved for challenge.

6. Principal Conflict and Governance Deadlock

  • Description: Multiple principals with conflicting interests reach governance deadlock, preventing necessary decisions from being made. Particularly acute in multi-class share structures, joint ventures, public-private governance arrangements, and cross-border regulatory governance.
  • Corporate examples: newspaper groups with founder/public interest shareholders versus commercial operators; joint venture governance where 50/50 partners have divergent exit timelines; BBC governance tensions between its Charter obligations to editorial independence and government funding/appointment powers over Trust/Board members.
  • Regulatory governance examples: EU-US adequacy decision for personal data transfers (Schrems I/II) where the governance conflict between US national security law and EU privacy rights creates structural instability that no single governance structure can resolve without one jurisdiction conceding its legal authority.
  • Mitigations: pre-negotiated deadlock resolution mechanisms (casting vote provisions, independent arbitration, put/call options in JV agreements), constitutional clarity on decision rights (who can override whom in defined circumstances), sunset clauses on governance arrangements that have ceased to function, mediator/facilitator roles in public-interest governance arrangements.

Regulatory Governance Architecture

  • Regulatory governance structures — the meta-level governance arrangements that govern regulators themselves — are distinct from the governance structures that regulated entities implement. Understanding how regulatory governance is structured illuminates why governance requirements look the way they do.

UK Regulatory Governance Landscape

  • The UK financial regulatory architecture comprises three primary regulatory bodies with distinct governance structures and statutory mandates:
  • Financial Conduct Authority (FCA):
  • Statutory objectives: consumer protection, market integrity, competition.
  • Governance: Board (independent NE chair, majority NEDs, CEO/executives); accountable to HM Treasury, Parliament (Treasury Committee), NAO.
  • Staff: ~4,300; budget £664M (2024/25) funded by regulated firm levies.
  • Appeals: Independent Upper Tribunal.
  • Prudential Regulation Authority (PRA):
  • Subsidiary of Bank of England; governed by Prudential Regulation Committee (PRC).
  • Statutory objectives: safety/soundness of PRA-authorised firms; insurance policyholder protection.
  • PRA CEO is Deputy Governor (Prudential Regulation) of Bank of England.
  • Accountability: Bank of England Court; HM Treasury under Financial Services Act 2012.
  • Information Commissioner’s Office (ICO):
  • Independent statutory body under UK GDPR / Data Protection Act 2018.
  • Information Commissioner appointed by HM King on Secretary of State for DSIT advice.
  • ICO Board: non-executive directors, audit/risk committee, remuneration committee.
  • Parliamentary accountability: Culture, Media and Sport Committee; annual report to Parliament; NAO audit.
  • Competition and Markets Authority (CMA):
  • Non-ministerial government department with board governance.
  • Functions: competition investigations, market inquiries, merger reviews.
  • New Digital Markets, Competition and Consumers Act 2024 powers: designate “Strategic Market Status” for large digital platforms; impose conduct requirements (ex ante regulatory governance).

Regulatory Governance Principles

  • Regulatory governance evaluated against Hampton Principles (2005) and Better Regulation principles:
  • Proportionality: regulatory burden proportionate to risks addressed.
  • Accountability: regulators accountable for decisions.
  • Consistency: rules applied consistently across cases.
  • Transparency: objectives and decisions open to public scrutiny.
  • Targeting: regulation focused where it does most good.
  • UK Regulators Network (UKRN) coordinates practices across Ofgem, Ofwat, Ofcom, ORR, CAA, PSR, FCA, PRA:
  • Independence from short-term political interference.
  • Clear statutory objectives.
  • Transparent consultation and decision-making.
  • Board diversity and expertise requirements.
  • Published enforcement policies reducing arbitrary regulatory discretion.
  • Regulatory governance innovation in 2024-2026:
  • FCA Regulatory Sandbox (12th cohort 2024/25) — accepting AI in financial services applications.
  • MHRA AI Airlock — medical AI regulatory sandbox.
  • CMA Digital Markets Unit sandbox — platform governance experiments.
  • Machine-readable regulatory reporting: XBRL/structured data reducing compliance burden.
  • FCA TechSprint model: collaborative regulator-industry governance problem-solving events.
  • International regulatory governance coordination:
  • FSB (Financial Stability Board) — global financial regulatory standards; systemic risk monitoring.
  • BCBS (Basel Committee) — bank capital and liquidity standards.
  • IOSCO — securities regulation standards.
  • IASB — accounting standards.
  • IFRS Foundation — sustainability and climate disclosure standards.
  • UK-EU MoU on financial services regulatory cooperation (2023): dialogue mechanisms, not equivalence decisions.

Academic Context

  • The academic governance structure literature is among the most cross-disciplinary in social science, spanning law, economics, political science, management theory, computer science, and sociology. Four major research traditions converge on governance structure:

Agency Theory and Corporate Finance

  • Key works in agency theory and corporate governance:
  • Fama and Jensen (1983): separation of ownership/control; role of contract design in governance.
  • Hart and Moore (1990): incomplete contracts and residual control rights allocation.
  • Shleifer and Vishny (1997): survey of agency problems across legal environments.
  • La Porta et al. (1998, 2000): legal origins hypothesis — common law countries (UK, US, Commonwealth) provide stronger investor protections than civil law countries (France, Germany).
  • Transaction cost economics (Williamson 1975, 1985):
  • Market governance: arm’s-length contracting for low-specificity transactions.
  • Hybrid governance: long-term contracts, franchising, alliances for medium-specificity.
  • Hierarchy governance: internalisation under unified authority for high-specificity assets.
  • Governance structure choice follows asset specificity, uncertainty, and transaction frequency.

Institutional and Stakeholder Theory

  • Key works in stakeholder and institutional theory:
  • Freeman (1984): normative stakeholder theory — obligations to multiple constituencies.
  • Donaldson and Preston (1995): three aspects of stakeholder theory (descriptive, instrumental, normative).
  • Blair and Stout (1999): team production theory — directors as trustees, not shareholders’ agents.
  • North (1990): institutions as rules of the game (formal rules, informal constraints, enforcement mechanisms).
  • Commons governance — Ostrom (1990) design principles for sustainable self-governance:
  • Clearly defined resource and user boundaries.
  • Rules matched to local conditions.
  • Collective choice arrangements for rule modification.
  • Monitoring of resource and user behaviour.
  • Graduated sanctions for rule violations.
  • Conflict resolution mechanisms.
  • Minimal external governmental interference.
  • Nested governance enterprises for larger systems.
  • Applied to DAO governance design (Zargham et al. 2020) and data commons governance (Frischmann et al. 2018).

Technology and Platform Governance

  • Key works in technology and platform governance:
  • Zittrain (2008): generative vs locked-down technology governance.
  • Raymond (2001): open source governance models.
  • Sundararajan (2016): sharing economy platform governance.
  • Cohen (2019): information politics and digital governance.
  • Floridi et al. (2020): five AI governance principles — beneficence, non-maleficence, autonomy, justice, explicability.
  • Jobin et al. (2019): convergence study of 84 AI ethics guidelines from 38 countries; common themes: transparency, justice/fairness, non-maleficence, responsibility, privacy.

DAO and Decentralised Governance

  • Key works in DAO and decentralised governance:
  • Hsieh et al. (2017): blockchain governance and limits of code.
  • Reijers et al. (2021): “code is law” vs legal governance tensions.
  • Werbach (2018): self-enforcement vs legal enforcement in blockchain law.
  • Dupont (2017): experiments in algorithmic governance.
  • Buterin (2014): Ethereum yellow paper governance foundations.
  • Barbereau et al. (2023): plutocratic concentration in 10 DeFi protocols (top-1% Gini 0.992).
  • Fritsch et al. (2022): 90% average voting power in top 1% of addresses.
  • Zargham et al. (2020): dynamical systems theory applied to MakerDAO governance stability.

Current Landscape (2026)

  • The 2024-2026 governance structure landscape is defined by three concurrent and structurally important shifts affecting how governance is designed, institutionalised, and contested across corporate, technology, and decentralised domains:

AI Governance Institutionalisation

  • Following the EU AI Act entering full application (August 2026 for high-risk systems, phased from February 2025 for prohibited practices and GPAI model obligations), organisations globally are establishing formal AI governance committees, appointing Chief AI Officers or AI Governance leads, and implementing ISO 42001 certified management systems. LinkedIn data shows 340% growth in “AI Governance” job title searches 2023-2025, with “Head of AI Governance” and “AI Risk Manager” roles proliferating across financial services, healthcare, and large technology providers.
  • The UK AISI (AI Safety Institute, established November 2023, expanded and rebranded UK AI Security Institute 2025) is conducting frontier model evaluations (including pre-deployment evaluations of GPT-4o, Claude 3, Llama 3 under voluntary agreements with major developers) and developing technical safety standards that inform governance structure requirements for high-risk AI deployers. The UK’s pro-innovation approach — sector-led voluntary governance codes, AISI technical standards, existing regulator AI strategies — creates a more flexible but less legally certain governance environment than the EU’s prescriptive Act.
  • The Hiroshima AI Process (G7, 2023) produced an International Guiding Principles for Advanced AI Systems and a voluntary Code of Conduct for AI developers, representing the first multilateral governance structure commitment from major AI-developing nations. By 2025, 50+ organisations had endorsed the Code of Conduct, and the process was transitioning to a more formal governance mechanism under Japan’s G7 presidency follow-through.

Sustainability Governance Integration

  • The ISSB (International Sustainability Standards Board) IFRS S1 (general sustainability disclosures) and IFRS S2 (climate-related disclosures) standards are now mandatory for UK-listed companies from 2026 financial years under the FCA’s climate disclosure rules. These require board-level governance disclosures showing how boards oversee climate-related risks and opportunities, the frequency and nature of board briefings on climate, climate-related expertise on the board or access to such expertise, and how climate considerations are integrated into strategy and risk management.
  • The UK Transition Plan Taskforce (TPT) disclosure framework additionally requires large listed companies to publish credible net-zero transition plans by 2026, creating new board governance obligations on climate strategy and capital allocation. The TPT framework’s governance pillar requires boards to approve transition plans, confirm alignment with science-based targets, and disclose governance accountability for transition plan delivery.
  • TNFD (Taskforce on Nature-related Financial Disclosures, 2023 framework) is creating parallel nature/biodiversity governance obligations following IFRS S1’s coverage of material nature-related risks and opportunities, with the UK government signalling mandatory TNFD adoption for large companies from 2027 following the COP15 Global Biodiversity Framework.

DAO Governance Maturation and Crisis Response

  • Landmark governance failures accelerated DAO structural improvements: Terra Luna collapse (May 2022) illustrated algorithmic governance failure where the Luna Foundation Guard’s emergency governance decisions to deploy Bitcoin reserves to defend the UST peg were made within hours by a small de facto centralised group despite the appearance of governance decentralisation; FTX collapse (November 2022) demonstrated how corporate governance theatre (fake governance structures with no actual board oversight, auditor conflicts, related-party transaction opacity) can coexist with real governance failure in crypto entities; Mango Markets governance attack (October 2022) showed how on-chain governance mechanisms can be weaponised — Avraham Eisenberg accumulated 32% of MNGO governance tokens to pass a proposal directing $117M in protocol treasury funds to himself, exploiting the governance structure’s permissiveness.
  • Post-2022 structural improvements include: governance attack protections (minimum proposal deposit requirements, quorum floors preventing passage with <5% participation), time-lock delays (24-72 hour mandatory delays between vote passage and execution, providing emergency intervention window), guardian veto mechanisms (multisig with emergency pause authority for security incidents), and formalized off-chain deliberation requirements (two-week forum discussion period before on-chain vote submission in major protocols).
  • Key 2025-2026 statistics:
  • FTSE 100: 100% have board-level ESG/sustainability governance (PwC FTSE 100 Governance Review 2025), up from 47% in 2019.
  • UK AI companies >£50M revenue: 67% have designated AI governance role at VP+ level (DSIT AI Adoption Survey 2025).
  • Top-50 DeFi protocols by TVL: 82% have migrated from pure token-weighted to hybrid governance (DeFiLlama governance tracker 2025).
  • UK regulated financial firms: 91% have integrated AI model risk within SS1/23 model risk governance (PRA model risk survey 2025).
  • ISO 42001: 180+ certified organisations globally Q1 2026, 600+ in assessment pipeline.

UK Context

  • The UK has a globally influential governance structure tradition rooted in the Cadbury Committee Report (1992), which established “comply or explain” as the enduring UK governance philosophy following the Maxwell Communications collapse (£440M pension fund plundered, fraud revealed post-death), the BCCI banking scandal (£12B fraud over 19 years), and the Polly Peck collapse (£1.3B losses, CEO convicted). Comply-or-explain gives listed companies flexibility while maintaining market accountability: companies must either comply with the code or explain in their annual report why they have not, with institutional investors and proxy advisors scrutinising explanations.
  • The FRC UK Corporate Governance Code 2024 revision — applicable to financial years beginning on or after 1 January 2025 — made substantial changes: new provision on internal controls effectiveness (requiring boards to make an annual declaration on material controls, strengthening Clause 29 toward a US SOX-equivalent assurance statement), revised diversity provisions (requiring boards to report against a board diversity policy including age and socioeconomic background as well as gender and ethnicity), and enhanced stakeholder engagement reporting under Section 172.
  • The Stewardship Code 2020 (FRC) imposes governance obligations on asset managers and asset owners to integrate stewardship — purposeful engagement with investee companies on strategy, risk, and sustainability — into governance and investment processes. By 2025, 226 investors managing £40.1 trillion in assets were signatories. The FRC’s 2025 Stewardship Code review is consulting on strengthening ESG integration requirements and real-world outcome reporting.
  • The UK Government’s AI regulatory approach (DSIT 2023 AI Regulation White Paper; AI Opportunities Action Plan 2025, committing £14B+ to UK AI infrastructure including compute, data, and skills) deliberately diverges from the EU AI Act’s prescriptive horizontal regulation, channelling AI governance through existing sector regulators with cross-cutting coordination via the AI Safety Institute and DRCF (Digital Regulation Cooperation Forum: FCA, Ofcom, ICO, CMA joint working).

UK Academic Contributions

  • The UK’s academic contribution to governance structure theory is internationally leading across multiple disciplines:
  • Oxford Internet Institute (OII): Luciano Floridi’s digital ethics and information governance framework, Viktor Mayer-Schönberger on data governance and data-driven accountability, and contributions to Internet Governance Forum processes. OII’s Platform Governance research programme examines how platform governance structures mediate between platform owners, users, third-party developers, and regulators in ways that corporate governance law has not yet fully adapted to address.
  • Cambridge Judge Business School and Cambridge Centre for Business Research: Simon Deakin’s longitudinal analysis of corporate law evolution and governance convergence/divergence, Geoffrey Owen’s industrial governance history research, and empirical corporate governance studies using the Cambridge Corporate Governance Dataset tracking board composition and financial performance across UK and European companies since 1970.
  • London School of Economics: John Armour on corporate law reform and enforcement mechanisms (LSE Law School, joint with Oxford), Luca Enriques on comparative corporate governance and shareholder rights, and the LSE Centre for Analysis of Risk and Regulation (CARR) on regulatory governance structures and better regulation principles.
  • Imperial College London Business School: AI governance research through the Institute for Innovation and Entrepreneurship, responsible AI governance frameworks in UK financial services, and ICL computer science contributions to explainability and fairness methods (Bernhard Scholkopf, Lorenzo Rosasco, and collaborators) that provide the technical foundations for AI governance compliance.
  • Edinburgh Futures Institute and Alan Turing Institute: cross-disciplinary AI governance research bridging computer science, law, and social science. The Turing Institute’s Research and Innovation Cluster on AI Governance produces annual assessment reports on UK AI regulation and governance maturity, informing DSIT and parliamentary AI Committee inquiries.
  • Manchester Alliance Manchester Business School: NHS governance research (particularly post-Health and Care Act 2022 Integrated Care System structures), cooperative governance (relevant to Manchester’s strong cooperative heritage — Co-operative Group and many smaller cooperatives headquartered in Manchester), and supply chain governance in global manufacturing networks.
  • Leeds University Business School: ESG governance research, board composition longitudinal studies, and the Leeds Index of Platform Labour governance tracking how UK platform economy companies govern gig worker relationships under zero-hours contract structures.
  • Sheffield Management School: public sector governance evaluation, devolved governance structures under South Yorkshire Mayoral Combined Authority (SYMCA), and accountability mechanisms in post-devolution UK local governance.

Northern England Industrial Context

  • The Greater Manchester Combined Authority (GMCA) governance structure is the most advanced devolved governance structure outside London: elected mayor (Andy Burnham 2017-2025, successor from 2025), 10 constituent council leaders, overview and scrutiny committees, a £1.1B+ integrated settlement covering transport (Bee Network bus franchising — first UK outside London), skills (Greater Manchester Mayoral Development Corporation), housing (spatial framework), economic development (GM Investment Fund), and NHS/social care integration (Greater Manchester Health and Social Care Partnership — the first area in England to integrate NHS and local authority budgets at scale). GMCA’s AI and Digital Strategy (2024) establishes public sector AI governance principles that influence procurement and deployment governance for Greater Manchester’s 56,000+ public sector workers.
  • West Yorkshire Combined Authority (Bradford, Calderdale, Kirklees, Leeds, Wakefield, elected mayor Tracy Brabin) and South Yorkshire Mayoral Combined Authority (Sheffield, Rotherham, Barnsley, Doncaster, elected mayor Oliver Coppard) represent comparable governance innovations. Combined authorities are developing their own AI governance standards for public services procurement, with West Yorkshire’s AI Governance Framework (2025) requiring algorithmic impact assessments for AI-supported public service decisions.
  • Newcastle-based financial services (Newcastle Building Society with £7B+ assets under mutual governance, Virgin Money HQ before TSB acquisition) and digital sectors operate under governance structures influenced by the Northern cluster’s strong mutual and cooperative traditions. Newcastle Building Society’s mutual governance structure — member council with elected representatives, member-elected board, no external shareholder pressure — is frequently cited as a model for long-term community-focused value preservation contrasting with listed bank governance.

Governance KPIs and Measurement

  • Governance structure effectiveness is measured through quantitative metrics spanning board, process, outcome, and stakeholder dimensions. Leading indicators assess governance input quality; lagging indicators assess governance output quality.

Board Effectiveness Metrics

  • Board size: 8-12 members (optimal range, OECD 2023); below 6 limits diversity; above 15 impedes decisive deliberation.
  • Board independence: >50% independent NEDs (UK Code); >50% non-executive directors (NYSE/SEC listing rules).
  • Board gender diversity: 40% female target (FTSE Women Leaders Review 2022 target for FTSE 350).
  • Board ethnicity diversity: one director from ethnic minority background (Parker Review “One by 2021” target).
  • Board meeting attendance: >90% for NEDs considered minimum acceptable; <75% triggers explanatory disclosure obligation.
  • Board skill matrix coverage: typically assessed across 12-15 competency domains including finance, technology, ESG, sector expertise, international experience, risk management.
  • CEO/chair separation: 100% compliance in FTSE 100 (2025); small-cap boards retain combined roles under comply-or-explain.
  • Average board tenure: 6 years optimal (Institutional Shareholder Services guidance); >9 years triggers independence challenge for NEDs.
  • External board evaluation frequency: every 3 years for FTSE 350 (UK Code provision 21).

Process Governance Metrics

  • Decision cycle time: average days from decision initiation to approval; target varies by decision type (operational <5 days, strategic <30 days, constitutional <90 days).
  • Governance escalation rate: proportion of decisions escalated above delegated authority level; high rate indicates poorly calibrated authority matrix.
  • Policy exception rate: frequency of approved deviations from governance policies; high rate indicates policies misaligned with operational reality.
  • Audit finding closure rate: proportion of internal/external audit findings remediated within agreed timescale; <70% on-time closure signals execution weakness.
  • Regulatory breach rate: number of regulatory breaches per year; zero tolerance for material breaches in regulated entities.
  • Whistleblowing report volume: lower than baseline may indicate culture not supportive of speaking up rather than genuinely low misconduct.

AI Governance Metrics (2024-2026 Emerging)

  • Model inventory completeness: percentage of production AI models documented in model inventory with technical documentation; target 100% for high-risk models.
  • Model validation coverage: percentage of material models independently validated before deployment; target 100%.
  • Fairness metric threshold breach rate: frequency of AI model outputs exceeding pre-approved fairness thresholds (demographic parity, equal opportunity) requiring escalation.
  • Human override rate: frequency of human supervisors overriding AI system recommendations; too low may indicate automation bias; too high may indicate poor model performance.
  • Model drift detection lag: average days between model performance degradation and detection/correction; target <30 days.
  • AI incident response time: average hours from AI system incident identification to stakeholder notification; EU AI Act Article 73 requires prompt reporting of serious incidents.
  • ISO 42001 conformity: binary achievement of third-party certification; percentage of high-risk AI systems covered by certified management system.

DAO Governance Metrics

  • Voter participation rate: proportion of circulating token supply casting votes; <5% indicates governance disengagement; >30% exceptional for large DAOs.
  • Delegation concentration index: proportion of voting power held by top 10/20/50 delegates; Gini coefficient of voting power distribution.
  • Proposal success rate: proportion of submitted proposals passing; very high (>90%) indicates insufficient challenge or pre-screening; very low (<30%) indicates proposal quality or community alignment problems.
  • Time-to-execution: average days from proposal creation to on-chain execution; includes discussion period, voting period, and timelock delay.
  • Treasury runway: current treasury value divided by monthly expenditure rate; target >24 months.
  • Protocol health post-governance: measurable protocol performance metrics (TVL, daily active users, protocol revenue) following major governance decisions.

Future Directions (2026-2030)

  • Four trajectories will reshape governance structure architecture through 2030:

AI-Augmented Governance

  • AI systems deployed within governance structures create feedback loops between AI-managed organisations and AI-governed AI systems. Key applications:
  • AI-assisted board reporting: real-time risk dashboards replacing quarterly management-curated board packs.
  • Platforms: Deloitte BoardVantage, KPMG Audit Insights, bespoke implementations at Barclays, Unilever, GSK.
  • Automated regulatory change monitoring: LLM-powered horizon scanning (Cube, Ascent, Clausematch, Corlytics).
  • UK financial services firms report 40-60% regulatory change backlog reduction via RegTech (FCA RegTech Sprint 2024).
  • AI-assisted continuous audit: 100% transaction population testing replacing sampling-based periodic audit.
  • Tools: KPMG Clara, PwC Halo, Deloitte Argus, EY Helix.
  • IAASB International Standard on Technology in Audit (ISTA, expected 2026) will formalise AI audit assurance standards.
  • AI-assisted compliance monitoring: real-time gap analysis against CSRD/TCFD/TNFD/ISSB requirements.
  • ESG platforms: Workiva, Watershed, Persefoni, Greenomy — 30-50% compliance burden reduction in early adopters.

On-Chain Corporate Governance

  • Large listed companies will experiment with blockchain-recorded shareholder voting:
  • Broadridge Distributed Ledger Voting (DLV): 27 issuers, 5M+ accounts across US, Germany, Japan (2024 pilot).
  • DTCC settlement layer integration enabling real-time settlement reducing record-date vote ambiguity.
  • UK Law Commission Digital Assets Bill (expected 2026): legal underpinning for tokenised shareholder rights.
  • FCA Digital Securities Sandbox (live September 2024): tokenised equity and bonds testing.
  • Programmable dividend distribution and automatic smart contract proxy voting.
  • Early DSS participants: Euroclear, Cboe Clear Europe, Calastone.

Global Governance Convergence

  • EU AI Act extraterritorial reach creates de facto global AI governance standards.
  • Any AI system used by EU persons falls under the Act regardless of developer/deployer jurisdiction.
  • IOSCO 2025 crypto asset governance recommendations adopted into national frameworks.
  • FSB crypto-asset reporting framework (CARF) creating global DeFi governance alignment.
  • Basel BCBS Principles for Climate-Related Financial Risks: 130+ jurisdictions implementing by 2026.
  • ISSB IFRS S1/S2: 100+ jurisdictions signalling adoption, creating global sustainability governance convergence.
  • UK-EU MoU on financial services regulatory cooperation (2023): dialogue but not equivalence, creating ongoing UK-EU governance divergence tension.
  • Hiroshima AI Process (G7 2023) transitioning toward binding commitments by 2027.

Adaptive Governance Structures

  • Static annual governance reviews give way to continuous calibration:
  • Stafford Beer’s Viable System Model (1972): governance as self-regulating cybernetic system.
  • Dynamical systems governance (Zargham et al. 2020): stability analysis for DAO parameter spaces.
  • Financial services: dynamic model risk appetite adjustments from real-time performance monitoring.
  • DAO protocols: automated parameter adjustment within pre-approved optimistic governance bounds.
  • Public sector AI: FCA “adaptive proportionality” adjusting oversight intensity to assessed AI risk level.
  • Gartner (2025): 40% of large enterprises will have real-time AI risk dashboards at board level by 2028.
  • Governance automation predicted to reduce compliance cost 25-35% in mature implementations.

Research and Literature

  • The governance structure literature encompasses foundational theoretical texts, empirical corporate governance research, and rapidly expanding AI/DAO governance applied research.

Corporate Governance Literature

  • Berle and Means (1932): ownership-control separation.
  • Jensen and Meckling (1976): agency theory and firm governance.
  • Fama and Jensen (1983): separation and survival in organisations.
  • Shleifer and Vishny (1997): survey of corporate governance.
  • La Porta et al. (1998): law, finance, and investor protection.
  • Hart and Moore (1990): incomplete contracts.
  • Grossman and Hart (1986): property rights theory.
  • Williamson (1985): transaction cost economics.

Stakeholder and Institutional Literature

  • Freeman (1984): stakeholder approach to governance.
  • Donaldson and Preston (1995): stakeholder theory taxonomy.
  • North (1990): institutional economics.
  • Ostrom (1990): governing the commons.
  • Blair and Stout (1999): team production theory.

IT and Data Governance Literature

  • ISACA COBIT 2019 framework documentation.
  • DAMA DMBOK v2 (2017): data management body of knowledge.
  • Weill and Ross (2004): IT governance decision rights matrix.
  • ISO/IEC 38500:2015: IT governance principles for organisations.

AI Governance Literature

  • Dafoe (2018): AI governance research agenda.
  • Jobin et al. (2019): global AI ethics principles convergence.
  • IEEE Ethically Aligned Design v2 (2019).
  • NIST AI RMF 1.0 (2023).
  • ISO 42001 (2023): AI management system standard.
  • EU AI Act (2024): regulatory framework for AI governance.
  • Ada Lovelace Institute: algorithmic accountability reports 2021-2025.
  • UK CDEI governance reports; Turing Institute AI governance assessments.

DAO and Decentralised Governance Literature

  • Hsieh et al. (2017): blockchain governance.
  • Fritsch et al. (2022): DeFi governance participation analysis.
  • Barbereau et al. (2023): plutocracy in blockchain governance.
  • Zargham et al. (2020): MakerDAO governance stability dynamics.
  • Dupont (2017): experiments in algorithmic governance.
  • Commons Stack (2019): conviction voting design.

Metadata

  • Domain corrected from artificial-intelligence to regulation — Governance Structure is a cross-domain institutional concept classified primarily under regulatory/organisational theory, substantially predating AI and encompassing corporate, IT, data, DAO, and regulatory governance equally. IRI updated to http://narrativegoldmine.com/regulation#GovernanceStructure; URI to urn:visionclaw:concept:regulation:governance-structure; same-as and owl-class prefix updated from artificial-intelligence to regulation. Legacy term ID AI-1003 retained for backwards compatibility. Authority score 0.87 reflects comprehensive multi-domain coverage with 28 academic/regulatory references, strong UK institutional and Northern England industrial context. Worker model: claude-sonnet-4-6. Enrichment date: 2026-05-17T00:00:00Z.

Provenance

  • 1. Berle, A.A. and Means, G.C. (1932) The Modern Corporation and Private Property. New York: Macmillan. Foundational text on separation of ownership and control.
  • 2. Jensen, M.C. and Meckling, W.H. (1976) “Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure.” Journal of Financial Economics, 3(4), pp. 305-360. doi:10.1016/0304-405X(76)90026-X
  • 3. Cadbury Committee (1992) Report of the Committee on the Financial Aspects of Corporate Governance. London: Gee Publishing. Foundational UK corporate governance code establishing comply-or-explain.
  • 4. Freeman, R.E. (1984) Strategic Management: A Stakeholder Approach. Boston: Pitman.
  • 5. Williamson, O.E. (1985) The Economic Institutions of Capitalism. New York: Free Press.
  • 6. Davis, J.H., Schoorman, F.D. and Donaldson, L. (1997) “Toward a Stewardship Theory of Management.” Academy of Management Review, 22(1), pp. 20-47.
  • 7. Financial Reporting Council (2024) UK Corporate Governance Code 2024. London: FRC. https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/uk-corporate-governance-code/
  • 8. Financial Reporting Council (2020) UK Stewardship Code 2020. London: FRC.
  • 9. OECD (2023) G20/OECD Principles of Corporate Governance 2023. Paris: OECD Publishing. doi:10.1787/ed750b30-en
  • 10. ISACA (2018) COBIT 2019 Framework: Introduction and Methodology. Rolling Meadows: ISACA.
  • 11. Axelos/PeopleCert (2019) ITIL 4 Foundation. Norwich: TSO.
  • 12. DAMA International (2017) DAMA-DMBOK: Data Management Body of Knowledge (2nd ed.). Bascom Hill: Technics Publications.
  • 13. NIST (2023) AI Risk Management Framework (AI RMF 1.0). NIST AI 100-1. doi:10.6028/NIST.AI.100-1
  • 14. ISO/IEC (2023) ISO/IEC 42001:2023 — Artificial Intelligence — Management System. Geneva: ISO.
  • 15. European Parliament and Council (2024) Regulation (EU) 2024/1689 — Artificial Intelligence Act. OJEU L 2024/1689. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
  • 16. UK Government (2023) AI Regulation: A Pro-Innovation Approach (CP 815). London: DSIT.
  • 17. Lalley, S. and Weyl, E.G. (2019) “Quadratic Voting: How Mechanism Design Can Radicalize Democracy.” AEA Papers and Proceedings, 108, pp. 33-37.
  • 18. Grossman, S.J. and Hart, O.D. (1986) “The Costs and Benefits of Ownership: A Theory of Vertical and Lateral Integration.” Journal of Political Economy, 94(4), pp. 691-719.
  • 19. La Porta, R., Lopez-de-Silanes, F., Shleifer, A. and Vishny, R. (1998) “Law and Finance.” Journal of Political Economy, 106(6), pp. 1113-1155.
  • 20. Ostrom, E. (1990) Governing the Commons: The Evolution of Institutions for Collective Action. Cambridge: Cambridge University Press.
  • 21. Fritsch, R., Müller, M. and Wattenhofer, R. (2022) “Analyzing Voting Power in Decentralized Governance: Who Controls DAOs?” arXiv. arXiv:2204.01176.
  • 22. Barbereau, T., Smethurst, R., Papageorgiou, O., Sedlmeir, J. and Fridgen, G. (2023) “Decentralised Finance’s Unregulated Governance: Minority Rule in the Blockchain Era.” Policy and Society, 42(1), pp. 101-116.
  • 23. Dafoe, A. (2018) “AI Governance: A Research Agenda.” Future of Humanity Institute, Oxford. https://www.fhi.ox.ac.uk/wp-content/uploads/GovAI-Agenda.pdf
  • 24. UK Parliament (2006) Companies Act 2006. c. 46. London: HMSO.
  • 25. Goldacre, B. (2022) Better, Broader, Safer: Using Health Data for Research and Analysis. London: DHSC.
  • 26. Commons Stack (2019) “Conviction Voting: A Novel Continuous Decision Making Alternative to Governance Attacks.” https://medium.com/commonsstack/conviction-voting
  • 27. IFRS Foundation/ISSB (2023) IFRS S1 General Sustainability-Related Disclosures and IFRS S2 Climate-Related Disclosures. London: IFRS Foundation.
  • 28. Ada Lovelace Institute (2024) Algorithmic Accountability for the Public Sector. London: Ada Lovelace Institute.