"Governance" sounds like a word that lives in conference rooms, occasionally has breakfast with the board of directors, and is reluctant to venture into everyday life.
Yet at its core, governance is much simpler: steering, guiding, and organizing accountability. The term derives from the Latin “gubernare” and means exactly that: leading and controlling organizations in such a way that they remain capable of acting in the long term.
The new book *Einfach Governance – Grundlagen, Strukturen und Umsetzung für die Praxis* by Alexander Deicke and Ali Kenan Nohut addresses this very issue. It takes a topic that often seems cumbersome, abstract, and a cross-departmental nuisance, and places it where it belongs: right at the heart of the company.
For a long time, governance was primarily associated with the supervisory board, the executive board, transparency, and oversight. These aspects remain important. The German Corporate Governance Code, international regulations, and principles of responsible corporate governance demonstrate that companies need clear lines of responsibility, oversight mechanisms, and transparent decision-making processes.
But modern governance does not end with corporate law.
It encompasses data protection, compliance, IT security, risk management, ESG, supply chains, financial processes, human resources, sales, operations, and, increasingly, artificial intelligence. That is precisely why it is not enough to treat governance as the responsibility of a single department.
Governance is not a department. Governance is a system of connections.
Image source: AI-generated | Description: The book "Einfach Governance" on a table.
In many companies, regulatory structures develop in parallel. Data protection handles data protection. IT handles security. Legal reviews contracts. Compliance writes policies. HR provides training. Finance reports. Operations optimizes processes. And somewhere, senior management is waiting for all of this to come together into a manageable organization.
That rarely works out very well.
After all, many risks arise precisely at the interfaces—where data moves from one department to another; where a new tool is introduced; where Sales makes a promise, Legal adds details later, and IT still has to check whether it’s even technically possible; where responsibility doesn’t disappear, but is very skillfully distributed.
The book consistently applies this cross-functional approach. It does not view governance in isolation, but rather examines it in relation to key business functions: the board, HR, legal, IT, sales, operations, and finance.
That is exactly what makes this approach practical.
One of the most important messages is this: Governance must not be separate from the core business. It must become an integral part of it.
If governance is understood solely as a layer of control, it comes too late. By then, processes are already in place, tools are already being used, contracts have already been signed, and data has already been processed. Governance is then left to politely play catch-up and label the pieces of the broken glass.
A better approach is an integrated one: governance is built into processes early on. It helps clarify roles, assess risks, structure documentation effectively, and ensure that decisions are transparent.
Not as a hindrance. But as a guide to responsible growth.
The book also makes it clear that governance does not look the same in every company.
Small and medium-sized businesses often lack dedicated departments, clear accountability for processes, or structured governance. In such companies, much of the responsibility falls on management, owners, or individual key personnel. Therefore, it rarely makes sense to start by overhauling everything at once. It is better to begin where the greatest practical need exists.
In larger companies, on the other hand, governance structures are usually already in place, but they are not always clearly integrated. There are legal departments, compliance functions, risk management, IT security, and internal policies. The problem, then, is not so much the complete absence of structures, but rather their overlap. Responsibilities overlap, rules are not understood, or processes run in parallel.
In large corporations, there is an additional layer to consider: international structures, local accountability, different cultures, and the question of whether anyone still has the big picture.
That’s what makes governance challenging. But it’s also indispensable.
Another key focus of the book is on technology-enabled governance systems and AI governance. This makes sense, as modern governance is becoming increasingly digital.
Tools can analyze risks, document processes, support compliance audits, identify patterns, and improve reporting. AI can help in certain areas by speeding up reviews, organizing data, or highlighting anomalies.
But technology is not a free pass.
Even the best system requires clear lines of responsibility, good data, human judgment, and an understanding of what can and cannot be automated. If you digitize poor processes, you won’t achieve good governance. You’ll end up with poor governance—complete with a login.
That is why the key point remains: Technology can support governance. It does not replace it.
It is particularly interesting to view governance not merely as an obligation, but as part of corporate culture.
After all, guidelines alone don’t change much. What matters is whether people understand why they should act, how they should act, and who takes responsibility. Training, awareness-raising, leadership, and culture are therefore not merely secondary “soft” issues. They are practical prerequisites for ensuring that governance exists not just on paper.
Good governance isn't measured by whether a file is complete. It's measured by whether decisions are improving.
The title “Simple Governance” is therefore well chosen. “Simple” does not mean “overly simplistic.” “Simple” means “understandable, accessible, and actionable.”
Governance remains a challenging topic. But it shouldn't be explained in a way that leaves everyone nodding in agreement without anyone actually making any changes.
The book aims to demystify governance and make it more manageable. It shows how legal, technical, and organizational requirements are interrelated and why integrated governance can be a real advantage for companies.
Governance is not just a buzzword in management. It is the art of organizing responsibility in such a way that companies remain capable of taking action.
Especially in an era of AI, data protection, ESG, IT security, supply chain requirements, and increasing regulation, we don’t need more silos. We need connectivity.
"Simple Governance" offers a practical approach to this: it is easy to understand, comprehensive, and closely aligned with the real-world challenges faced by modern companies.
For K11, the book is therefore more than just a publication. It embodies a fundamental principle: governance should not be made any more complicated than it already is.
It's supposed to work.