RACF-CC • Domain 8

Governance, Risk and Framework Alignment

Connect policies to live controls, organisational risks to technical evidence, exceptions to accountable decisions and every domain to continuous improvement.

Purpose

Move from policy presence to assurance

Governance sustains every technical domain. RACF-CC does not require a large compliance team or enterprise governance platform. It creates a lightweight evidence trail showing which risks matter, which controls operate, where exceptions remain and who has accepted the residual exposure.

What good looks like

Trustees and leaders can see the principal cyber risks, control status, significant exceptions and improvement priorities in understandable terms; technical evidence supports policy claims; and incidents, scans and changes feed back into decisions.

Use consistent assurance language

The RACF-CC Control Assurance model distinguishes controls that are Implemented, Evidenced and Sustained without creating an organisational compliance badge. Explore the assurance model →

Risk picture

Common assurance failures

Paper compliance

A policy says a control exists, but no current evidence demonstrates enforcement.

Disconnected risk register

Risk ratings do not change when telemetry, incidents or exposure changes.

Unvalidated change

A security change is recorded without proving its intended outcome.

Informal exceptions

Legacy constraints persist without owner, compensating controls or review date.

Aggregate-score confidence

A headline score masks material gaps in individual controls or parts of the estate.

Unclear accountability

Cyber risk is treated as an IT issue rather than an organisational responsibility.

Prioritised action

The RACF-CC governance control set

PriorityControl directionOutcomeEvidence
FirstMap each RACF-CC domain to organisational risk-register entries.Connects cyber work to mission and care impact.Domain-to-risk matrix.
FirstMaintain a risk-tiered supplier and critical-service dependency register.Focuses assurance on third parties whose failure or compromise would matter most.Owned supplier records with access, evidence, incident and review details.
FirstMap policy statements to controls, owners and current evidence.Reveals enforcement gaps and unsupported claims.Policy-control matrix.
FirstCreate an exception and residual-risk register.Makes infeasible controls visible, owned and time-bound.Approved exceptions with review dates.
NextUse technical and operational evidence in periodic risk review.Keeps risk ratings aligned with actual exposure.Assurance pack and decisions.
NextRequire security changes to include risk, rollback and validation.Proves that changes achieved their intended outcome.Complete change records.
NextRun a proportionate quarterly cyber assurance review.Creates leadership visibility and tracked priorities.Minutes, actions and evidence summary.
DevelopMaintain framework mappings and a continuous improvement loop.Shows alignment without claiming certification or endorsement.Crosswalk and completed improvements.

Implementation

A four-phase roadmap

Phase 1

Create traceability

  • Map domains to organisational risks
  • Map policies to control evidence
  • Assign control and risk owners
  • Create the exception register

Phase 2

Review assurance

  • Build a concise evidence pack
  • Update risks from telemetry
  • Add security validation to change
  • Review overdue actions

Phase 3

Engage leadership

  • Run quarterly assurance reviews
  • Present risk in operational language
  • Agree residual-risk decisions
  • Test continuity assumptions

Phase 4

Improve continuously

  • Feed incidents and scans into priorities
  • Review framework alignment
  • Measure control sustainability
  • Refine investment decisions

Governance must support decisions, not paperwork

Keep the assurance pack short enough to maintain and clear enough for non-technical leaders. Report control outcomes, evidence quality, uncertainty and residual risk—not only activity counts or vendor scores.

Govern the movement from pilot to enforcement

Audit/report-only → pilot → validate → enforce → monitor → review

Governance should define approval, evidence, communications, exception and rollback expectations proportionate to the care impact of each change. Use the Safe Enforcement Pattern →

Make supplier dependency visible

Prioritise suppliers by the consequence of compromise or failure, not by questionnaire completion. Record access, data, responsibilities, assurance, incident arrangements, concentration and exit. Use the Supplier and Third-Party Risk guide →

Evidence

Measure ownership and assurance

Risk integrationDomains and material findings linked to current organisational risks.
Policy traceabilityPolicy commitments with an owner, operating control and evidence—or an accepted gap.
Exception qualityExceptions with rationale, safeguards, owner, residual rating and review date.
Change assuranceSecurity-relevant changes with rollback and post-change validation.
Leadership reviewAssurance actions agreed, owned and completed.
Improvement loopIncidents, scans and monitoring findings producing tracked control improvements.

Residual risk and escalation

Record governance and assurance gaps that remain

What may remain unresolved?

Incomplete policy-to-control mapping, weak evidence, overdue exceptions, unclear ownership, deferred investment and risks that remain above organisational appetite may persist.

Why might it remain?

Leadership capacity, missing evidence, competing care priorities, supplier dependencies, funding cycles or unresolved ownership can delay treatment.

Compensating safeguards

Increase review frequency, assign interim owners, restrict exposure, require additional approval, improve monitoring and maintain explicit contingency decisions.

Risk owner

An authorised organisational leader owns the residual business risk; technical teams provide evidence and treatment advice rather than accepting it alone.

Review requirement

Review by the approved date and after incidents, material evidence change, missed actions, control failure or change in organisational risk appetite.

Escalation triggers

Risk above appetite, expired acceptance, absent owner, failed safeguard, repeated overdue action, regulatory concern or credible threat to care continuity.

Recording does not equal acceptance. Acceptance must be explicit, authorised, time-bound and supported by a decision to treat, tolerate, transfer or avoid the exposure.

References

Standards alignment

Framework complete

Use the eight domains as one system

Governance closes the loop: evidence from identity, endpoints, networks, vulnerabilities, data, monitoring and incidents informs the next cycle of prioritisation and improvement.