Part III — Continuous Assurance
Part III — Continuous Assurance
Section titled “Part III — Continuous Assurance”Part II defined the operating model through which organizational intent becomes governance decisions, execution, evidence, accountability, outcomes, and feedback.
That operating loop explains how an individual governance matter should function.
Continuous assurance requires more.
An organization must preserve what its governance system has learned across decisions, systems, teams, and time.
Without that continuity, each governance decision begins with partial context. Exceptions are forgotten. Prior reasoning disappears. Control failures recur. Policies remain unchanged even when outcomes repeatedly show that they are ineffective.
Governance may operate continuously while still failing to learn institutionally.
Part III defines the structures that prevent that failure.
Continuous assurance depends on four connected capabilities:
- Governance Memory
- Governance Records
- Governance Economics
- The Assurance Cycle
Governance Memory preserves institutional knowledge.
Governance Records provide the structured evidence from which that knowledge can be derived.
Governance Economics evaluates whether governance produces sufficient value relative to its cost and consequences.
The Assurance Cycle connects observation, evaluation, response, and improvement into a recurring organizational capability.
Together, these capabilities allow governance to remain coherent as decisions accumulate and conditions change.
Governance Memory
Section titled “Governance Memory”Governance Memory is the organization’s retained knowledge of its governance intent, decisions, reasoning, evidence, exceptions, outcomes, and adaptations.
It allows the organization to answer not only:
What is the current rule?
but also:
Why does this rule exist, how has it been applied, what exceptions have been made, what outcomes has it produced, and what has the organization learned from it?
Governance Memory is broader than document retention.
An archive may preserve information without preserving meaning.
A folder may contain old policies, audit reports, tickets, approvals, logs, and risk assessments while leaving the organization unable to reconstruct how those artifacts relate to one another.
Governance Memory preserves those relationships.
It connects:
- intent to implementation;
- implementation to decisions;
- decisions to actors;
- actors to authority;
- decisions to evidence;
- evidence to outcomes;
- outcomes to lessons; and
- lessons to subsequent changes.
Why Governance Memory Matters
Section titled “Why Governance Memory Matters”Organizations routinely lose governance knowledge even when the underlying records still exist.
A policy owner leaves the organization.
A control is migrated to a new platform.
A risk exception expires without review.
A decision is repeated because no one can find the prior analysis.
A configuration remains in place long after the reason for it has disappeared.
An audit finding is remediated technically, but the underlying decision process remains unchanged.
A team knows that an exception exists but cannot determine who approved it or whether it remains valid.
These are not merely documentation problems.
They are failures of institutional memory.
When governance lacks memory:
- the same failures recur;
- inconsistent decisions proliferate;
- exceptions become permanent;
- obsolete controls remain active;
- accountability becomes difficult to establish;
- assurance depends on individual recollection;
- organizational learning is lost through employee turnover; and
- governance becomes increasingly disconnected from its own history.
Programmable Assurance treats retained governance knowledge as part of the governance system itself.
The Components of Governance Memory
Section titled “The Components of Governance Memory”Governance Memory should preserve several forms of knowledge.
Intent Memory
Section titled “Intent Memory”Intent Memory preserves:
- the authoritative intent;
- its source;
- its owner;
- its effective date;
- its prior versions;
- the reason it was established;
- the objectives it was expected to achieve; and
- the conditions under which it should be reviewed.
Intent without historical context can become difficult to interpret.
A policy may remain active even though the risk, regulation, technology, or organizational objective that produced it has changed.
Decision Memory
Section titled “Decision Memory”Decision Memory preserves how intent has been applied in actual contexts.
It includes:
- prior governance decisions;
- the circumstances under which they were made;
- the reasoning used;
- the authority exercised;
- the evidence considered;
- exceptions and overrides;
- dissent or challenge;
- and the resulting obligations.
Decision Memory does not require every future case to follow precedent automatically.
It allows decision-makers to understand prior treatment and explain meaningful departures from it.
Execution Memory
Section titled “Execution Memory”Execution Memory preserves how governance decisions were carried into operation.
It identifies:
- the enforcement point;
- the system or actor responsible;
- the action taken;
- whether execution succeeded;
- any delay or failure;
- and any compensating response.
This enables the organization to distinguish decision failure from execution failure.
Outcome Memory
Section titled “Outcome Memory”Outcome Memory preserves what happened after governance was applied.
It includes:
- whether the objective was achieved;
- whether the outcome was aligned, misaligned, unknown, or accepted as a deviation;
- unintended consequences;
- material incidents;
- remediation;
- and longer-term effects.
Outcome Memory is essential to determining whether governance is effective rather than merely active.
Learning Memory
Section titled “Learning Memory”Learning Memory preserves how evidence and outcomes changed the governance system.
It records:
- lessons identified;
- changes proposed;
- changes approved;
- changes rejected;
- rationale;
- updated policies or criteria;
- revised enforcement;
- and the results of those revisions.
Without Learning Memory, organizations may repeatedly rediscover the same lesson without retaining it.
Memory Must Be Connected
Section titled “Memory Must Be Connected”Governance Memory should not be understood as one central database containing every governance artifact.
It may be distributed across:
- policy repositories;
- source-control systems;
- decision engines;
- identity platforms;
- workflow tools;
- risk registers;
- ticketing systems;
- security platforms;
- audit systems;
- financial platforms;
- data governance systems;
- and organizational knowledge bases.
The architectural requirement is not physical centralization.
The requirement is logical connection.
The organization must be able to trace relevant relationships across these systems.
A reviewer examining a material decision should be able to identify:
- the applicable intent;
- the version of that intent;
- the decision context;
- the decision result;
- the authority exercised;
- the action taken;
- the evidence produced;
- the outcome observed; and
- any subsequent governance change.
The systems may remain distributed.
The governance story must remain coherent.
Memory Has a Lifecycle
Section titled “Memory Has a Lifecycle”Governance Memory must itself be governed.
Not all information should be preserved indefinitely.
Memory requirements must account for:
- legal retention obligations;
- privacy;
- confidentiality;
- operational value;
- evidentiary value;
- data minimization;
- jurisdiction;
- storage cost;
- security risk;
- and the right or obligation to delete information.
Governance Memory therefore requires lifecycle decisions:
- what should be retained;
- at what level of detail;
- for how long;
- in what form;
- under whose authority;
- with what protections;
- and through what disposal process.
Continuous assurance does not require infinite memory.
It requires sufficient memory to support defensible governance.
Governance Records
Section titled “Governance Records”A Governance Record is a structured, durable representation of a material governance event.
It preserves the information necessary to understand what occurred within the governance system.
A governance event may include:
- the creation or modification of intent;
- a governance decision;
- an approval;
- a denial;
- an exception;
- an override;
- a risk acceptance;
- an enforcement action;
- an execution failure;
- an observed outcome;
- a remediation;
- or a feedback-driven governance change.
Governance Records are the building blocks of Governance Memory.
From Artifacts to Records
Section titled “From Artifacts to Records”Organizations already generate large volumes of governance-related artifacts:
- policies;
- emails;
- tickets;
- logs;
- approvals;
- meeting minutes;
- screenshots;
- reports;
- configuration histories;
- risk entries;
- and audit evidence.
These artifacts may contain useful information, but they do not automatically form a governance record.
A governance record organizes relevant information around a governable event.
For example, an access approval record should not consist only of an email saying “approved.”
A useful record should connect:
- the requested access;
- the requester;
- the target resource;
- the governing policy;
- the justification;
- the evidence evaluated;
- the approver;
- the decision;
- the duration;
- any conditions;
- the execution result;
- and the eventual revocation or review.
The difference is structural.
An artifact shows that something happened.
A governance record explains what happened within the governance system.
The Minimum Governance Record
Section titled “The Minimum Governance Record”The exact structure will vary by domain, but a material governance record should generally identify:
Record Identity
Section titled “Record Identity”A unique identifier that allows the record to be referenced and linked.
Governing Intent
Section titled “Governing Intent”The policy, obligation, objective, standard, or risk decision that applied.
The relevant version should be identifiable.
Governed Subject
Section titled “Governed Subject”The person, system, resource, transaction, vendor, model, process, or other subject to which governance was applied.
Decision Context
Section titled “Decision Context”The material facts evaluated at the time of the decision.
Decision Result
Section titled “Decision Result”The explicit determination reached.
Decision Basis
Section titled “Decision Basis”The rules, evidence, reasoning, thresholds, or criteria supporting the result.
Decision Authority
Section titled “Decision Authority”The person, role, committee, service, policy engine, or delegated system authorized to decide.
Accountability
Section titled “Accountability”The actors responsible for ownership, approval, risk, execution, review, or remediation.
Required Response
Section titled “Required Response”The action or obligation created by the decision.
Execution Status
Section titled “Execution Status”Whether the response occurred, failed, was delayed, or was bypassed.
Evidence References
Section titled “Evidence References”Links or references to supporting evidence.
Outcome
Section titled “Outcome”The observed result and its relationship to the governance objective.
Temporal Context
Section titled “Temporal Context”Relevant timestamps, effective periods, expiration dates, and review dates.
Record Integrity
Section titled “Record Integrity”Information sufficient to establish authenticity, version, source, and protection against unauthorized alteration.
Records Should Be Proportionate
Section titled “Records Should Be Proportionate”Not every routine event requires an extensive governance record.
The depth of the record should correspond to:
- decision materiality;
- legal significance;
- risk;
- consequence;
- reversibility;
- uncertainty;
- exception status;
- duration;
- and the need for future explanation.
A routine low-risk automated decision may require a compact structured record.
A high-impact risk acceptance may require extensive reasoning, executive approval, legal review, compensating controls, and periodic reassessment.
Programmable Assurance requires sufficient records, not maximum records.
Decision Lineage
Section titled “Decision Lineage”Decision Lineage is the traceable relationship among the inputs, authorities, decisions, actions, and outcomes associated with governance.
It allows the organization to reconstruct the path:
Intent → Context → Decision → Execution → Outcome
Decision Lineage is especially important when decisions involve multiple systems.
For example, an infrastructure decision may involve:
- a requirement stored in a policy repository;
- a control expressed in policy code;
- a pipeline evaluating the deployment;
- a human approving an exception;
- a cloud platform creating the resource;
- an observability platform monitoring the result;
- and a risk system tracking the accepted deviation.
No single system contains the entire governance event.
Decision Lineage connects them.
Record Integrity
Section titled “Record Integrity”Governance records must be trustworthy enough to support the claims made from them.
Integrity measures may include:
- authenticated sources;
- access controls;
- immutable or append-only storage;
- digital signatures;
- cryptographic hashes;
- trusted timestamps;
- source-control history;
- versioning;
- separation of duties;
- audit trails;
- and independent validation.
Not every record requires the same level of protection.
The strength of integrity controls should match the significance of the governance claim.
Record Correction
Section titled “Record Correction”Governance records may contain errors.
A trustworthy system must allow correction without silently rewriting history.
Corrections should preserve:
- the original record;
- the corrected information;
- the reason for correction;
- the actor making the correction;
- the authority permitting it;
- and the time of change.
Append-only correction is often preferable for material records because it preserves both the original state and the subsequent amendment.
Records Must Be Interpretable
Section titled “Records Must Be Interpretable”A technically complete record may still fail if only the system that generated it can interpret it.
Governance records should remain understandable to authorized stakeholders, including:
- engineers;
- risk professionals;
- auditors;
- security teams;
- legal teams;
- executives;
- regulators;
- and future system owners.
Interpretability may require:
- shared vocabulary;
- schemas;
- identifiers;
- contextual metadata;
- human-readable explanations;
- machine-readable representation;
- and documented relationships among systems.
A governance record should support both operational use and institutional review.
Governance Economics
Section titled “Governance Economics”Governance consumes resources and changes behavior.
It creates cost.
It may delay action, require additional personnel, constrain technical choices, increase system complexity, collect data, preserve evidence, and impose operational obligations.
Governance also creates value.
It may reduce loss, improve decision quality, preserve trust, satisfy legal obligations, prevent incidents, accelerate audits, improve resilience, and enable the organization to act with greater confidence.
Governance Economics is the evaluation of those costs, benefits, tradeoffs, and consequences.
It asks:
Is the governance system producing sufficient assurance relative to the burden it creates?
This question does not reduce governance to financial return alone.
Some obligations are mandatory regardless of cost.
Some values, such as safety, rights, legality, and institutional trust, cannot be evaluated solely through monetary measures.
Governance Economics provides disciplined reasoning about consequence.
Governance Is Not Free
Section titled “Governance Is Not Free”Every governance mechanism creates direct and indirect costs.
Direct costs may include:
- technology;
- personnel;
- implementation;
- licensing;
- training;
- evidence storage;
- review;
- audit;
- legal support;
- and remediation.
Indirect costs may include:
- delayed delivery;
- reduced flexibility;
- user friction;
- opportunity cost;
- decision latency;
- false denials;
- duplicated work;
- organizational avoidance;
- and incentives to bypass governed processes.
A governance system that ignores these costs may undermine its own objectives.
For example, an excessively burdensome approval process may encourage employees to use unauthorized tools.
A deployment control with frequent false positives may be bypassed.
An evidence requirement that collects unnecessary personal information may create privacy risk.
A policy that requires unavailable expertise may exist only on paper.
Economic reasoning helps identify when governance becomes self-defeating.
The Cost of Weak Governance
Section titled “The Cost of Weak Governance”Insufficient governance also creates cost.
These costs may include:
- security incidents;
- regulatory penalties;
- contractual liability;
- operational outages;
- financial loss;
- fraud;
- reputational damage;
- failed audits;
- repeated remediation;
- data loss;
- poor strategic decisions;
- and erosion of trust.
Some costs are immediate.
Others accumulate gradually through technical debt, unresolved exceptions, duplicated controls, unowned risk, and fragmented accountability.
Governance Economics compares not only the cost of governance with the absence of governance.
It compares alternative governance designs.
Assurance Value
Section titled “Assurance Value”Assurance Value is the benefit created when the organization gains justified confidence that intent is being represented in decisions and producing acceptable outcomes.
Assurance Value may appear as:
- reduced uncertainty;
- faster decision-making;
- lower incident probability;
- earlier detection;
- more effective remediation;
- reduced audit effort;
- stronger contractual confidence;
- improved resilience;
- traceable accountability;
- reusable evidence;
- and better strategic information.
The value of assurance is often indirect.
A continuously evidenced control may reduce audit preparation work.
A well-governed deployment pipeline may increase engineering speed because acceptable changes can proceed automatically.
A mature exception process may enable calculated risk-taking rather than indiscriminate denial.
Good governance can create operational capacity.
Decision Friction
Section titled “Decision Friction”Decision Friction is the effort, delay, complexity, or resistance introduced by governance into a decision process.
Some friction is intentional.
A high-impact action may deserve additional scrutiny.
The objective is not zero friction.
The objective is proportionate friction.
Governance should impose greater friction where:
- consequence is high;
- uncertainty is high;
- action is difficult to reverse;
- authority is sensitive;
- evidence is weak;
- or risk exceeds accepted thresholds.
Governance should minimize unnecessary friction where:
- consequence is low;
- the action is routine;
- controls are well understood;
- evidence is strong;
- and decisions can be safely automated.
Programmable Assurance seeks to place friction deliberately rather than allowing it to emerge accidentally from fragmented processes.
False Approval and False Denial
Section titled “False Approval and False Denial”Governance systems can make two broad classes of error.
A false approval permits an action that should have been constrained.
A false denial constrains an action that should have been permitted.
False approvals may increase risk.
False denials may create unnecessary cost, delay, and circumvention.
The appropriate balance depends on context.
For example, a life-safety system may tolerate very few false approvals.
A low-impact development environment may prioritize speed and accept broader experimentation.
Governance Economics requires explicit consideration of both error types.
A control should not be evaluated only by what it blocks.
It should also be evaluated by what it prevents the organization from doing.
Control Cost and Control Effectiveness
Section titled “Control Cost and Control Effectiveness”A control may be active without being economically justified.
Control evaluation should consider:
- implementation cost;
- operating cost;
- maintenance burden;
- user friction;
- evidence value;
- reduction in risk;
- reliability;
- false-positive rate;
- false-negative rate;
- coverage;
- adaptability;
- and interaction with other controls.
A control may be:
- effective and proportionate;
- effective but excessively costly;
- inexpensive but ineffective;
- redundant;
- obsolete;
- or actively harmful.
Continuous assurance should identify these distinctions.
Governance Debt
Section titled “Governance Debt”Governance Debt is the accumulated future cost created when governance structures, decisions, controls, exceptions, or records are left incomplete, outdated, fragmented, or unresolved.
Examples include:
- expired exceptions that remain active;
- policies that no longer match systems;
- manual controls that cannot scale;
- undocumented decision logic;
- missing accountability;
- repeated audit findings;
- unsupported enforcement integrations;
- evidence that cannot be reproduced;
- and risk acceptances that are never reviewed.
Governance Debt resembles technical debt.
It may sometimes be accepted deliberately to enable urgent action.
The problem is not that debt exists.
The problem is that it becomes invisible, unowned, and permanent.
A governance debt record should identify:
- what obligation remains incomplete;
- why the debt was accepted;
- the risk introduced;
- the responsible owner;
- the expected resolution;
- the review date;
- and the consequences of continued deferral.
Governance Economics as Feedback
Section titled “Governance Economics as Feedback”Economic outcomes must feed back into the governance system.
If a control produces excessive delay, the response should not automatically be to remove it.
The organization should determine whether:
- the intent remains valid;
- the decision criteria are too broad;
- implementation is inefficient;
- automation is insufficient;
- the wrong enforcement point is being used;
- the control duplicates another mechanism;
- or the accepted risk has changed.
Economic feedback improves governance without treating governance merely as overhead.
The Assurance Cycle
Section titled “The Assurance Cycle”The Assurance Cycle is the recurring process through which an organization evaluates whether governance intent remains aligned with operational outcomes.
It operationalizes continuous assurance.
The cycle consists of eight activities:
- Define
- Translate
- Decide
- Execute
- Observe
- Evaluate
- Respond
- Adapt
These activities may occur at different speeds and across different systems.
The cycle is continuous because governance conditions do not remain fixed.
1. Define
Section titled “1. Define”The organization establishes or confirms its intent.
This includes:
- the objective;
- the authoritative source;
- the owner;
- the governed subject;
- the expected outcome;
- the applicable scope;
- and the limits of authority.
Definition answers:
What are we trying to achieve, prevent, preserve, or optimize?
Intent should be reviewed when:
- obligations change;
- risk changes;
- strategy changes;
- technology changes;
- outcomes show persistent divergence;
- or the original objective becomes unclear.
2. Translate
Section titled “2. Translate”The organization converts intent into decision-relevant form.
Translation identifies:
- conditions;
- criteria;
- evidence;
- authority;
- enforcement points;
- available decision outcomes;
- exception mechanisms;
- accountability;
- and outcome measures.
Translation answers:
How should this intent influence actual decisions?
Poor translation is a common source of governance failure.
The high-level policy may be reasonable while the operational criteria fail to represent it accurately.
3. Decide
Section titled “3. Decide”The governance system applies translated intent to a specific context.
The decision may be:
- automated;
- human;
- or hybrid.
Decision-making answers:
Given the applicable intent and available context, what should happen?
The decision should be explicit, attributable, and proportionate to the consequence.
4. Execute
Section titled “4. Execute”The governance decision is carried into operation.
Execution may:
- allow;
- deny;
- modify;
- delay;
- escalate;
- notify;
- remediate;
- record;
- or impose additional obligations.
Execution answers:
Was the governance decision actually carried into effect?
A correct decision that is not executed is not effective governance.
5. Observe
Section titled “5. Observe”The organization collects relevant information about execution and resulting conditions.
Observation may include:
- system telemetry;
- workflow status;
- configuration state;
- human acknowledgement;
- evidence generation;
- financial impact;
- incidents;
- user behavior;
- and external events.
Observation answers:
What happened after the decision?
Observation should be designed around governance claims rather than indiscriminate data collection.
6. Evaluate
Section titled “6. Evaluate”Observed conditions are compared with the governance objective.
Evaluation determines whether the outcome is:
- aligned;
- partially aligned;
- misaligned;
- unknown;
- pending;
- accepted as a deviation;
- or no longer applicable.
Evaluation answers:
Did governance produce the intended result?
Evaluation should distinguish:
- decision quality;
- execution quality;
- evidence quality;
- outcome quality;
- and external influence.
7. Respond
Section titled “7. Respond”The organization acts on the evaluation.
Responses may include:
- confirmation;
- remediation;
- revocation;
- escalation;
- incident response;
- exception review;
- risk reassessment;
- evidence preservation;
- notification;
- or acceptance of the observed condition.
Response answers:
What must happen now that the outcome is known?
A detected divergence without response is observation, not assurance.
8. Adapt
Section titled “8. Adapt”The organization uses accumulated evidence and outcomes to improve governance.
Adaptation may change:
- intent;
- translation;
- decision logic;
- authority;
- enforcement;
- evidence requirements;
- controls;
- accountability;
- measurement;
- and review cadence.
Adaptation answers:
What should the governance system learn from this outcome?
Adaptation closes the cycle.
The revised governance system then enters the next cycle of definition, translation, decision, and evaluation.
Assurance at Multiple Cadences
Section titled “Assurance at Multiple Cadences”The Assurance Cycle does not operate at one universal speed.
Different governance matters require different cadences.
Transactional Assurance
Section titled “Transactional Assurance”Transactional assurance occurs at or near the time of an individual decision.
Examples include:
- evaluating an access request;
- checking a deployment;
- approving a transaction;
- or validating a data transfer.
Operational Assurance
Section titled “Operational Assurance”Operational assurance evaluates whether governed systems remain aligned over time.
Examples include:
- detecting configuration drift;
- reviewing active privileges;
- monitoring exception expiration;
- and tracking remediation.
Programmatic Assurance
Section titled “Programmatic Assurance”Programmatic assurance evaluates the effectiveness of a broader governance capability.
Examples include:
- whether an identity governance program reduces excessive access;
- whether vendor review predicts material third-party risk;
- or whether software governance improves release quality.
Strategic Assurance
Section titled “Strategic Assurance”Strategic assurance evaluates whether governance continues to support organizational objectives.
Examples include:
- whether controls remain economically justified;
- whether governance enables or constrains innovation appropriately;
- whether accepted risk remains aligned with strategy;
- and whether authority structures remain appropriate.
Continuous assurance includes all four cadences.
A real-time control cannot replace strategic review.
A strategic review cannot replace transactional governance.
Assurance Coverage
Section titled “Assurance Coverage”No organization can govern every decision with equal depth.
Assurance Coverage describes the portion of a governance domain for which intent, decisions, evidence, accountability, outcomes, and feedback are sufficiently connected.
Coverage may be assessed across:
- organizational units;
- systems;
- decision types;
- data classes;
- jurisdictions;
- risk levels;
- vendors;
- controls;
- and lifecycle stages.
A governance system may have strong policy coverage but weak execution coverage.
It may have strong telemetry but weak accountability.
It may have strong preventive controls but poor outcome evaluation.
Coverage should therefore be measured across the entire operating model rather than reduced to whether a policy or control exists.
Coverage Gaps
Section titled “Coverage Gaps”A coverage gap exists when a required connection is missing.
Examples include:
- intent without an enforcement point;
- decisions without records;
- execution without evidence;
- evidence without accountable ownership;
- outcomes without evaluation;
- exceptions without expiration;
- and findings without feedback.
Coverage gaps should be treated as governance risks.
They represent places where intent may diverge from outcomes without the organization being able to detect, explain, or correct the divergence.
Continuous Does Not Mean Fully Automated
Section titled “Continuous Does Not Mean Fully Automated”Programmable Assurance does not define continuous assurance as universal real-time automation.
A process may be continuous even when humans remain involved.
Continuity means:
- governance remains active;
- relevant changes trigger reevaluation;
- material decisions remain attributable;
- evidence is produced as decisions occur;
- outcomes are reviewed at an appropriate cadence;
- and learning is incorporated into future governance.
Some decisions should remain human.
Some should be automated.
Some require both.
The design question is not:
Can this be automated?
It is:
What combination of human judgment, automation, evidence, and accountability produces the most reliable governance outcome?
Continuous Assurance Established
Section titled “Continuous Assurance Established”Part III establishes the institutional capabilities required to sustain Programmable Assurance.
Governance Memory preserves the relationships among intent, decisions, execution, evidence, accountability, outcomes, and learning.
Governance Records provide durable, structured representations of material governance events.
Governance Economics evaluates the value, cost, friction, errors, and accumulated debt created by governance.
The Assurance Cycle continuously defines, translates, decides, executes, observes, evaluates, responds, and adapts.
Together, these capabilities allow governance to become more than a sequence of isolated decisions.
They allow it to become an institutional learning system.
Part IV applies this framework to real organizational environments and explains how Programmable Assurance relates to the disciplines and practices that already govern technology, risk, compliance, security, finance, and operations.
Part II — Operating Model · Continue to Part IV — Applying the Framework