Home / Published Work / Public Service Culture, Risk Management and Governance
Public Service Culture, Risk Management and Governance
The Prerequisite of Effective Strategic Governance to Realizing Our Digital Ambition
SYNOPSIS
Risk is the lens through which decisions are made and policies developed in the public service. This paper examines the role risk management plays in shaping public service culture, decision-making and policy development. It introduces the concept of an aggregate risk profile; reaffirms that adopting a new security classification framework is the important first step to enabling a digital reset; demonstrates that making that decision will not of itself assure the reset but merely unlocks its potential; and defines how dedicated and effective strategic governance would enable a more timely and successful achievement of the outcomes articulated in Digital Ambition 2022.
“It is therefore not the culture that needs to be changed it is the policy suite itself.”
From the paper, page 3
KEY FINDINGS
- 1
Culture is more often a symptom than a cause. The characteristics commonly attributed to public sector culture would, at best, be symptoms of the underlying problem. This is not to say culture has no role; it has to be taken into consideration.
- 2
Policies define the culture. Departments issue their own direction restricting actions that are perfectly compliant with higher-level policy, and divisions restrict further. Once implemented, those policies reinforce a belief that this is “what right looks like.”
- 3
Risk tolerance is not standardized. Departments use 3x3, 4x4 or 5x5 matrices with no standardization between them, so the same decision can be low risk in one department and medium in another. Within a department, what middle management identifies as high risk is often low to medium on a senior executive's spectrum.
- 4
A mitigated low risk can be the root cause of several high risks. Because the risk is low and mitigated it will not appear on a corporate risk profile, nor likely inform risk management conversations. Canada's security classification framework is one of the better examples of such a policy.
- 5
Either an organization is managing risk, or risk is managing the organization. Because transition risks are often examined in isolation of the broader aggregate risk to the enterprise, the result is often a status quo outcome.
- 6
Strategic governance must be leadership led, and usually is not. Governance exists to let leaders make timely, informed decisions and, where warranted, to deviate from process in an informed way, rather than to protect the process. What the paper describes instead is staff led governance: agendas set by staff, issues settled in advance of the meeting, items withdrawn at staff discretion, non-decisions becoming decisions and little conversation in the room.
RECOMMENDATIONS
WHERE THIS FITS
Added September 2026
This was the second paper in the series. The first examined a single policy instrument, Canada's security classification framework, and its consequences for digital government. This paper moved from that instrument to the machinery that produces institutional behaviour, examining how risk management shapes culture, decision-making and policy development, and introducing the aggregate risk profile. Later papers applied that idea to contract security, cyber security certification and the defence industrial base.
SINCE PUBLICATION
What has changed, and where the argument went
WHAT HAS CHANGED
- Canada fell to 47th in the 2024 UN E-Government Development Index, after 32nd in 2022 and sixth in 2003.
- In April 2026 the Cyber Centre replaced the Protected B profile the paper identified. ITSP.10.033-01 supersedes Annex 4A Profile 1 and is organized around medium impact and non-state threat actors rather than a classification label. The Secret profile has not been replaced, and Protected B remains in use as a classification throughout the new profile.
- Digital Transformation Canada launched in September 2026.
Sources: UN E-Government Survey 2024; Canadian Centre for Cyber Security, ITSP.10.033-01, effective 1 April 2026; Prime Minister's Office, 3 September 2026.
HOW THE THINKING HAS DEVELOPED
When I wrote this paper in 2024, I argued that it was the policy suite, rather than culture itself, that needed to change. I did not yet have the term institutional architecture, or a sufficiently developed account of the mechanism. Later work led me to see how the policies, authorities, risk frameworks and governance mechanisms between strategic intent and delivery can narrow the choices available to the people trying to deliver. People then make individually rational decisions within those constraints and, repeated across an institution, those decisions can produce the behaviours we experience as culture. Nobody has to be risk averse, embrace overclassification or be obstructive for that to happen.
The paper's treatment of strategic governance also developed further. In 2024, I argued for leadership-led governance that could align authorities, responsibilities and accountabilities around intended outcomes. My subsequent work on Institutional Command and Control led me to a broader conclusion: in Defence, the institutional functions required to resource, sustain, adapt and regenerate operational forces are not simply matters of administration or governance. Their performance has operational consequences. Governance remains essential, but it is one mechanism within the broader institutional command function required to translate operational intent into coordinated enterprise action.