Ron Lloyd BETWEEN INTENT AND OUTCOMES

Home / Published Work / Public Service Culture, Risk Management and Governance

POLICY PERSPECTIVECANADIAN GLOBAL AFFAIRS INSTITUTEJULY 2024

Public Service Culture, Risk Management and Governance

The Prerequisite of Effective Strategic Governance to Realizing Our Digital Ambition

Governance & Decision-Making Digital Government & Procurement

SYNOPSIS

Risk is the lens through which decisions are made and policies developed in the public service. This paper examines the role risk management plays in shaping public service culture, decision-making and policy development. It introduces the concept of an aggregate risk profile; reaffirms that adopting a new security classification framework is the important first step to enabling a digital reset; demonstrates that making that decision will not of itself assure the reset but merely unlocks its potential; and defines how dedicated and effective strategic governance would enable a more timely and successful achievement of the outcomes articulated in Digital Ambition 2022.

“It is therefore not the culture that needs to be changed it is the policy suite itself.”

From the paper, page 3

KEY FINDINGS

  1. 1

    Culture is more often a symptom than a cause. The characteristics commonly attributed to public sector culture would, at best, be symptoms of the underlying problem. This is not to say culture has no role; it has to be taken into consideration.

  2. 2

    Policies define the culture. Departments issue their own direction restricting actions that are perfectly compliant with higher-level policy, and divisions restrict further. Once implemented, those policies reinforce a belief that this is “what right looks like.”

  3. 3

    Risk tolerance is not standardized. Departments use 3x3, 4x4 or 5x5 matrices with no standardization between them, so the same decision can be low risk in one department and medium in another. Within a department, what middle management identifies as high risk is often low to medium on a senior executive's spectrum.

  4. 4

    A mitigated low risk can be the root cause of several high risks. Because the risk is low and mitigated it will not appear on a corporate risk profile, nor likely inform risk management conversations. Canada's security classification framework is one of the better examples of such a policy.

  5. 5

    Either an organization is managing risk, or risk is managing the organization. Because transition risks are often examined in isolation of the broader aggregate risk to the enterprise, the result is often a status quo outcome.

  6. 6

    Strategic governance must be leadership led, and usually is not. Governance exists to let leaders make timely, informed decisions and, where warranted, to deviate from process in an informed way, rather than to protect the process. What the paper describes instead is staff led governance: agendas set by staff, issues settled in advance of the meeting, items withdrawn at staff discretion, non-decisions becoming decisions and little conversation in the room.

RECOMMENDATIONS

Reset the frameworkAdopt a three-tier classification framework of Official (Official Sensitive), Secret and Top Secret as the important first step to a digital reset.
Amend what supports itAmend the numerous supporting policies, ITSG-33 in particular, to reflect leadership intent. Otherwise the Protected B profile can simply be renamed and the status quo preserved under a new name.
Govern strategicallyEstablish dedicated strategic governance: leadership led, a single chairperson, ARAs proactively delegated, an implementation plan and a Plan, Execute, Measure and Adjust posture at a bi-weekly cadence, supported by six critical success factors.

WHERE THIS FITS

Added September 2026

This was the second paper in the series. The first examined a single policy instrument, Canada's security classification framework, and its consequences for digital government. This paper moved from that instrument to the machinery that produces institutional behaviour, examining how risk management shapes culture, decision-making and policy development, and introducing the aggregate risk profile. Later papers applied that idea to contract security, cyber security certification and the defence industrial base.

SINCE PUBLICATION

What has changed, and where the argument went

UPDATE · SEPTEMBER 2026

WHAT HAS CHANGED

  • Canada fell to 47th in the 2024 UN E-Government Development Index, after 32nd in 2022 and sixth in 2003.
  • In April 2026 the Cyber Centre replaced the Protected B profile the paper identified. ITSP.10.033-01 supersedes Annex 4A Profile 1 and is organized around medium impact and non-state threat actors rather than a classification label. The Secret profile has not been replaced, and Protected B remains in use as a classification throughout the new profile.
  • Digital Transformation Canada launched in September 2026.

Sources: UN E-Government Survey 2024; Canadian Centre for Cyber Security, ITSP.10.033-01, effective 1 April 2026; Prime Minister's Office, 3 September 2026.

HOW THE THINKING HAS DEVELOPED

When I wrote this paper in 2024, I argued that it was the policy suite, rather than culture itself, that needed to change. I did not yet have the term institutional architecture, or a sufficiently developed account of the mechanism. Later work led me to see how the policies, authorities, risk frameworks and governance mechanisms between strategic intent and delivery can narrow the choices available to the people trying to deliver. People then make individually rational decisions within those constraints and, repeated across an institution, those decisions can produce the behaviours we experience as culture. Nobody has to be risk averse, embrace overclassification or be obstructive for that to happen.

The paper's treatment of strategic governance also developed further. In 2024, I argued for leadership-led governance that could align authorities, responsibilities and accountabilities around intended outcomes. My subsequent work on Institutional Command and Control led me to a broader conclusion: in Defence, the institutional functions required to resource, sustain, adapt and regenerate operational forces are not simply matters of administration or governance. Their performance has operational consequences. Governance remains essential, but it is one mechanism within the broader institutional command function required to translate operational intent into coordinated enterprise action.

ABOUT THE AUTHOR

Vice-Admiral (Ret'd) Ron Lloyd was the 35th Commander of the Royal Canadian Navy and is a Fellow of the Canadian Global Affairs Institute. Transparency →