Adaptive Governance

The Control Golden Triangle: Reframing Enterprise Controls for the Age of AI and Adaptive Governance

July 23, 2026 12 min read

Introduction

For decades, enterprise governance, risk management, compliance, cybersecurity, and assurance disciplines have relied on the concept of the control. Controls are embedded throughout governance frameworks, standards, and operating models. They underpin audit programs, security architectures, regulatory compliance obligations, and management practices.

Yet despite their importance, the definition of a control has remained largely rooted in a compliance and risk-centric worldview. Most frameworks describe controls as policies, procedures, safeguards, processes, configurations, or measures that modify risk.

While these definitions have served organisations well, they were developed during an era when governance was primarily concerned with stability, compliance, and the prevention of adverse outcomes.

Today's organisations operate in a fundamentally different environment. Artificial intelligence, autonomous systems, digital ecosystems, rapid innovation cycles, and increasing uncertainty require governance models that not only manage risk but also enable opportunity and organisational adaptation.

This raises an important question:

If governance exists to help organisations achieve objectives, should controls be viewed solely as mechanisms for managing risk, or should they also be recognised as mechanisms for enabling opportunity and organisational learning?

This question forms the foundation of the eGRACS framework and the COR Triangle.

The Historical Evolution of Control Definitions

Historically, control definitions emerged from accounting, auditing, and internal control disciplines. As governance frameworks matured, controls became associated with policies, procedures, processes, standards, safeguards, technical configurations, and management practices.

Modern frameworks generally define controls as mechanisms that prevent undesirable outcomes, detect deviations, correct errors, modify risk, and support compliance.

This perspective remains valuable and relevant. However, it also creates several limitations:

  • Controls are often viewed primarily as defensive mechanisms.
  • Opportunity enablement receives less attention than risk reduction.
  • Controls may be treated as static artefacts rather than dynamic capabilities.
  • The role of learning and adaptation is frequently underrepresented.
  • AI-enabled decision-making does not fit neatly into traditional control models.

Rethinking Controls Through the Lens of Objectives

An organisation does not exist to implement controls. An organisation exists to achieve objectives. Risk and opportunity only become meaningful when viewed in relation to those objectives.

This suggests a different perspective:

Controls should be understood not merely as mechanisms that reduce risk, but as capabilities that influence organisational behaviour in pursuit of objectives.

From this perspective, controls influence decisions, actions, omissions, human behaviour, system behaviour, and AI-enabled behaviour. The consequences of these behaviours may create risks, opportunities, or both simultaneously.

This broader perspective forms the basis of the eGRACS control definition:

A control is a defined capability that influences or constrains the decisions, actions, and omissions of people, systems, and AI-enabled capabilities in order to manage risk, realise opportunity, and support the achievement of organisational objectives.

Introducing the COR Triangle

The COR Triangle is a conceptual model that visualises the relationship between Control, Opportunity, and Risk. Unlike traditional governance models that position controls solely as risk mitigations, the COR Triangle recognises that controls influence both risks and opportunities.

Control
Opportunity
Risk

The triangle operates within the context of enterprise objectives. Its purpose is not to eliminate risk, nor to maximise opportunity at any cost. Rather, it seeks to help organisations optimise the relationship between risk and opportunity through effective controls.

Why Opportunity Matters

Many governance programs inadvertently create an imbalance. When controls are viewed solely as mechanisms for reducing risk, organisations can become overly restrictive, slow to innovate, bureaucratic, and reactive.

Examples include lengthy approval chains that delay innovation, excessive governance overhead that discourages experimentation, and security practices that impede productivity.

The COR Triangle encourages a more balanced conversation:

What opportunities are enabled by this control, and what risks are reduced by it?

This shifts governance from a defensive posture toward a value-oriented posture.

The Missing Dimension: Learning

As organisations mature, governance evolves beyond static controls. Every realised risk and every realised opportunity provides information. That information generates learning.

Learning is not a fourth vertex of the triangle. Instead, learning is the feedback mechanism that continuously improves the relationship between controls, risks, and opportunities.

Control
Behaviour
Risk & Opportunity
Outcomes
Learning
Control Optimisation
Improved Outcomes

Through this feedback loop, controls become more effective, risk management becomes more informed, opportunities are more effectively utilised, and organisational resilience improves.

The Relevance of AI and Autonomous Systems

Traditional control models were largely designed for human-operated environments. Modern enterprises increasingly rely on automation, machine learning, AI agents, and autonomous decision-making systems.

These technologies introduce new forms of behaviour that cannot always be governed through traditional policy and procedure-centric approaches. The eGRACS definition accommodates this reality by recognising controls as capabilities that influence the decisions, actions, and omissions of people, systems, and AI-enabled capabilities.

This creates a governance model that is adaptable to both present and future operating environments.

Benefits of the COR Triangle and eGRACS Perspective

  • Aligns governance directly to enterprise objectives.
  • Balances risk management with opportunity realisation.
  • Recognises controls as dynamic capabilities rather than static artefacts.
  • Supports human, automated, and AI-enabled decision-making.
  • Encourages continuous learning and adaptation.
  • Provides a common language for boards, executives, practitioners, auditors, and technologists.
  • Promotes organisational resilience and long-term value creation.

Conclusion

The future of governance is unlikely to be defined solely by compliance, risk reduction, or control catalogues. As organisations become increasingly digital, interconnected, and AI-enabled, governance must evolve from managing threats to enabling organisational adaptation.

The COR Triangle offers a simple but powerful way to visualise this evolution. By recognising the interconnected relationship between Controls, Opportunities, and Risks—and by embedding learning as the feedback mechanism that continuously improves them—organisations can move beyond static governance models toward adaptive governance systems designed for sustained objective achievement.

In the context of the eGRACS framework, governance is no longer merely about controlling uncertainty. It is about continuously learning how to achieve objectives more effectively in the presence of uncertainty.

Unlock the Power of the Four-Tier Structure with eGRACS

The eGRACS four-tier structure is more than just a framework—it’s a transformative approach to ICT governance. Ready to scale your organisation’s governance and achieve operational success?

Start Today