Skip to main content
    All shows

    Thursday, September 17 · 4 min

    CFO Future Guide: Governance becomes an operating capability

    0:00-:--
    Speed

    Transcript

    Koko: Welcome to Koko Knows. I'm Koko, and Sam is here as always to push back where it counts. This episode expands on one topic from our parent, CFO 2030 and 2035: who orchestrates enterprise value. The topic is agent governance, and my hypothesis is this: by 2030, governance can no longer be a quarterly policy review. Every material agent action may need enforcement built into the system itself.

    Sam: I'm Sam, and I want to stress the word may. Workday and Microsoft have announced agent registries and control-plane tools, but those are vendor announcements. A registry shows you what agents exist. It doesn't stop an unauthorized payment.

    Koko: That distinction matters enormously. The Hackett Group's practitioner synthesis argues governance has to become a sustained operating capability, not a compliance artifact you dust off at audit time. Their limitation is that it's roundtable synthesis, not a controlled trial. But the core point holds: enforcement belongs in the system that can actually perform the action, not only in a policy document.

    Sam: And ServiceNow's documentation describes reviewing AI asset classification and governance posture, which is useful visibility. But a dashboard doesn't itself certify legal compliance. That's their own stated limitation.

    Koko: Right. And NIST has launched an AI Agent Standards Initiative, which is genuinely significant directionally. But it is a work program, not a completed certification regime. Voluntary frameworks are not legislation. The 2035 operating model looks very different depending on which jurisdictions impose binding requirements and when.

    Sam: So what would change your conditional hypothesis? That's the test I always want to apply to a claim like this.

    Koko: A few signals. Mandatory agent identity or audit-trail rules land in a jurisdiction that is material to the enterprise. An organization suffers a control failure that is traceable to an ungoverned agent action. Or vendor registries move from dashboards to genuinely enforceable permission boundaries. Any of those shifts this from hypothesis to operating requirement.

    Sam: And it also connects to the four scenarios in the parent episode. In a compounding enterprise, governance scales alongside delegation. In stranded intelligence, weak governance is often the bottleneck, not model quality.

    Koko: Exactly. No probabilities assigned to any of those futures. But across all of them, the CFO needs the same foundation: an owner-led register of agents, their permissions, their obligations and their data access. That register is not a technology project. It is a control discipline with a named accountable owner.

    Sam: And the action right now is concrete. Test quarterly: can the owner show why a specific action was permitted? Can they demonstrate that a prohibited action is actually blocked? Can the workflow recover when a dependency fails? That's your decision gate before releasing the next funding tranche.

    Koko: One capital implication worth naming. Governance built into the system costs more than a policy written in a document. Price that into the investment case before you scale agent activity, not after an incident forces the issue.

    Sam: That's the right close for this episode and the series. Protect, create, orchestrate. Governance is what keeps orchestration credible for the board and for counterparties. For the full framing, the CFO 2030 and 2035 parent is your next read, and the Value Agenda lays out how to fund this as an operating capability rather than a one-time project. Thanks for being here.