Cyber Risk Governance & Accountability™ (CRGA™) Framework
Board-level governance for technology-enabled enterprise risk.
Cyber Risk Governance & Accountability™ (CRGA™) is a governance architecture layer above technology domains that formalizes board and executive oversight of technology-enabled enterprise risk. It establishes ownership, escalation, accountability structures, and defensible oversight where technology materially affects enterprise outcomes.
CRGA™ Governance Architecture is a proprietary governance architecture developed and stewarded by Praesidium Governance, Inc., established independently of entities responsible for implementing technical controls or delivering operational services.
Governance Architecture — Not Execution
Cyber Risk Governance & Accountability™ is the named framework through which Praesidium defines governance architecture for technology-enabled enterprise risk. Praesidium Governance, Inc. serves exclusively as a governance architecture authority and category steward.
CRGA™ is a governance architecture. It does not deliver cybersecurity operations, managed services, software implementation, audits, or compliance execution.
Execution firms implement controls and operate environments. Governance architecture defines decision rights, assigns accountability, establishes escalation discipline, and documents defensible oversight evidence.
The distinction is structural and must be preserved.
Why CRGA™ Exists
Technology-enabled enterprise risk exceeds the scope of traditional cybersecurity and compliance frameworks.
Operational controls address execution. Regulatory frameworks define obligations. Neither establishes how boards and executives govern accountability for material risk.
As digital infrastructure, automated systems, and algorithmic decision-making increase in complexity, the gap between operational risk management and fiduciary oversight becomes structural.
This gap is not technical.
It is governance.
CRGA™ exists to define the governance architecture required to allocate decision rights, establish escalation discipline, and produce defensible oversight evidence where technology materially affects enterprise outcomes.
Scope of CRGA™
CRGA™ applies where technology-enabled enterprise risk materially affects the enterprise.
Materiality may arise from:
- Cyber risk exposure
- AI and algorithmic system risk
- Identity and access risk
- Operational resilience dependencies
- Regulatory and disclosure obligations
- Third-party and supply chain exposure
CRGA™ governs oversight architecture across domains. It does not replace domain-specific controls.
CRGA™ Governance Domains
CRGA™ is structured across governance domains corresponding to materially significant categories of technology-enabled enterprise risk.
Within each domain, the CRGA™ Governance Architecture:
- identifies the board or committee responsible for oversight;
- assigns executive accountability;
- defines decision rights and authority boundaries;
- establishes escalation thresholds and pathways; and
- requires defensible evidence of oversight, decisions, and follow-through.
1. Cyber Risk Governance
Governance of material enterprise exposure to cyber threats, operational disruption, data compromise, resilience failure, and systemic vulnerability.
This domain establishes:
- Board or committee oversight responsibility for material cyber risk
- Named executive accountability for cyber risk management and operational resilience
- Decision rights for risk acceptance, remediation, incident response, and recovery
- Escalation thresholds for material incidents, control failures, and sustained exposure
- Defensible evidence of oversight decisions, management action, and follow-through
2. AI & Algorithmic Risk Governance
Governance of AI-enabled systems, algorithmic decision environments, agentic workflows, delegated machine authority, automated decision pathways, and human-agent operating structures where material enterprise risk may arise.
This domain establishes:
- Board or committee oversight responsibility for material AI and algorithmic risk
- Named executive accountability for AI-enabled systems and their enterprise use
- Approval rights and authority boundaries governing design, deployment, operation, and delegated machine action
- Risk visibility into AI exposure, system dependencies, automated decision pathways, and human-agent operating structures
- Escalation thresholds for material capability changes, control failures, unintended behavior, or emerging risk conditions
- Defensible evidence of authorization, oversight, intervention, and continuing accountability
3. Identity & Access Risk Governance
Governance of human and non-human identities, privileged access environments, authorization structures, delegated access, and trust boundaries materially affecting enterprise security and operational integrity.
This domain establishes:
- Board or committee oversight responsibility for material identity and access risk
- Named executive accountability for identity governance and privileged-access exposure
- Decision rights governing access authorization, privilege allocation, delegation, exceptions, and emergency access
- Escalation thresholds for excessive privilege, unauthorized access, identity-control failure, and systemic trust-boundary exposure
- Board-level visibility into material identity and access risk
- Defensible evidence of access decisions, exceptions, reviews, escalation, and remediation
4. Emerging Technology Governance
Governance of material enterprise risk arising from technologies, capabilities, and architectures that do not yet fit established risk-ownership or control structures.
This domain may include advanced automation, autonomous systems, cyber-physical systems, decentralized architectures, and other materially significant innovations.
This domain establishes:
- Board or committee visibility into material risks arising from emerging technologies
- A designated executive sponsor and accountable owner
- Interim decision rights, approval requirements, and risk-acceptance boundaries
- Escalation thresholds for rapid capability expansion, uncertain control performance, cross-domain exposure, or material unintended consequences
- Defensible evidence supporting classification, authorization, monitoring, and governance transition decisions
Architectural Extension
Additional governance domains may be recognized when a technology-enabled risk category:
- becomes materially significant to the enterprise;
- requires distinct accountability, decision rights, or escalation pathways; and
- cannot be governed adequately within an existing domain.
As technologies and risk categories mature, they may remain within Emerging Technology Governance, transition into an established domain, or be recognized as a distinct CRGA™ Governance Domain.
The architecture expands in response to governance necessity, not technological novelty.
Governance domains are architectural. Execution remains domain-specific.
These domains define the scope of governance oversight, authority, accountability, escalation, and evidence. They do not represent operational specialization.
What CRGA™ Is
Cyber Risk Governance & Accountability™ (CRGA™)is a governance architecture and discipline.
It defines decision rights, escalation discipline, accountability structures, and defensible oversight evidence for technology-enabled enterprise risk.
It provides structural integrity to fiduciary responsibility across environments shaped by digital infrastructure, automated systems, and algorithmic decision-making.
Governance architecture strengthens defensibility through defined oversight, not technical implementation.
What CRGA™ Is Not
CRGA™ is not an operational service provider, cybersecurity product, software platform, control framework, or certification program.
It does not deliver cybersecurity operations, managed services, software implementation, audits, or compliance execution.
It does not prescribe technical controls, conduct audits, or perform remediation.
CRGA™ governance architecture must remain structurally independent from the entities responsible for implementing technical controls or delivering operational services.
It may not be certified, defined, or represented by execution providers. Any such representation is unauthorized unless explicitly granted in writing by Praesidium Governance, Inc.
This separation preserves fiduciary clarity, accountability integrity, and defensibility at the board and executive level.
CRGA™ does not govern execution. It governs accountability over execution.
The Result
Organizations operating under CRGA™ establish a defined governance architecture for technology-enabled enterprise risk.
This includes:
- Board-level oversight allocation
- Executive accountability structures
- Escalation discipline
- Defensible oversight evidence
This is evidenced through documented decisions, defined escalation records, and traceable accountability structures.
This architecture produces an auditable record of oversight, providing the basis for boards and executives to demonstrate accountability under regulatory, investor, and litigation scrutiny.
CRGA™ establishes governance as a system of record for decision-making, escalation discipline, and accountability in technology-enabled enterprise risk environments.
This is not a control framework. It is a governance architecture.