Home / Industries / Government & public sector

MyRISK · government and public sector

The policy exists, but the evidence is hard to assemble and harder to defend.

Public-sector risk is judged after the fact — through audit, parliamentary committee, media, citizen and regulator scrutiny. Evidence assembled later is always weaker than evidence captured when the decision was made.

Why now

Policy obligations do not translate cleanly into operating evidence.

Agencies are digitising services, using more suppliers and more AI, and carrying cyber, privacy, procurement and programme accountability at the same time. The policy framework is usually complete. What is missing is the trail from an obligation to the operating decision that discharged it.

When a review arrives, the reconstruction begins — and reconstruction is exactly what an auditor discounts. The decision was made properly; the record was assembled afterwards, and everyone can tell.

A policy says what should happen. The record has to show what did, and why it was reasonable at the time.

What usually starts the conversation

  • An audit finding on evidence, approvals or traceability
  • A cyber uplift programme with reporting obligations attached
  • A procurement review, or a challenged supplier decision
  • A first AI use case needing an approval someone will defend
  • A programme in trouble, and questions about earlier go/no-go calls
  • A new committee reporting requirement with no source to draw on

Where it bites first

Five decisions worth being able to replay

01

A major programme go/no-go

What was known at the gate, what was assumed, who approved proceeding, and what conditions were set.

02

A procurement or supplier decision

Why this supplier, what was evaluated, and how the value-for-money judgement was reached.

03

A policy exception

A departure approved for operational reasons, its justification, and whether it has been revisited.

04

An AI use-case approval

What the system was approved to do, on what evidence, with what human oversight, and what would trigger review.

05

A cyber or privacy decision

A risk accepted, an uplift deferred, or a notification judgement — and the basis for it.

Not a cyber story

Cyber and privacy are live obligations here and they are one strand. Programme delivery, procurement and policy-to-evidence decisions carry the same weight — lead with whichever whatever happened most recently makes most concrete.

What you already have

The framework is not the gap.

Agencies have policy libraries, delegations, assurance frameworks, gateway review processes, internal audit and committee structures. These are usually thorough — more thorough than most private-sector equivalents.

What they produce is a record that a process was followed. What a reviewer asks for is the substance: what evidence was in front of the decision-maker, what alternatives were weighed, and whether the conditions attached were ever checked. Trace holds that alongside the systems you already run.

What a Trace record preserves

  • The evidence that existed at the time, and the policy version that applied
  • The rationale, assumptions and alternatives considered
  • Who held the delegation, and what exactly was approved
  • Conditions, expiry and review dates
  • Drift — whether changed circumstances unsettle the approval

Who this is for, and who it isn't

Two signals that send you somewhere else

Start with Consulting instead

Where the entry point is an audit finding about a process, or an evidence workflow that keeps failing, the first work is diagnosis rather than a decision record.

GRC value recovery

Start with Essentials instead

Local government, smaller bodies and individual programme teams usually need practical visibility and action follow-through, not a replay of one decision.

Practical risk management

For your reviewers

The boundaries, in writing

What this is not

  • Not whole-of-government approval, endorsement or accreditation of any kind, and not a claim of any panel or procurement standing not separately evidenced.
  • Not “audit-ready” and not guaranteed compliance. Replayability is a property of the record; acceptance is your auditor's and your accountable authority's.
  • Not a legal or probity opinion. The record holds what was decided and why; the judgement remains the delegate's.
  • Trace complements your existing assurance, procurement and records systems. It replaces none of them, and it is not a recordkeeping compliance product.

Pick the decision most likely to be reviewed.

A programme gate, a procurement, an exception or an AI approval. Replay it now, while there is still time to fix what is missing rather than explain it.