Governance for a Growing SME: Enough Structure Without the Bureaucracy
The first time a client's procurement team asks to see your risk register, the honest answer in most 30 to 60 person firms is that there is not one, and the second honest answer is that the business has run perfectly well without it. Both answers are true, which is exactly why governance for a growing SME is such an awkward subject: the firm has genuinely never needed it, and it now genuinely does, because the clients getting larger, the contracts getting longer and the decisions getting more expensive have quietly changed what the business is being asked to prove.
The mistake most managing directors make at this point is to assume governance means what it means in a corporate, which is committees, policies nobody reads and a compliance function, so they either adopt too much of it and slow themselves down or reject all of it and lose the contract. There is a third option, which is right-sized governance: the smallest set of habits that lets you show consistency to the people who now demand it, without turning a fast business into a slow one.
What governance for a growing SME actually needs to cover
Strip away the corporate apparatus and governance answers four questions. Who owns each risk that could seriously hurt the business. How significant decisions get made and recorded. Whether client work and contracts are reviewed by anyone other than the person who sold them. And whether the leadership team looks at the business on a regular rhythm rather than only when something breaks. A firm of 40 people that can answer those four questions in writing has more real governance than many larger businesses with a policy library, because the point of governance is not documentation but the ability to demonstrate that outcomes were not accidents.
It is worth being honest about who you are demonstrating this to. Sometimes it is a client's procurement function, sometimes it is your own board or an investor, and sometimes, further down the road, it is an acquirer working through an operational due diligence checklist and pricing every gap they find. The audience changes but the evidence they want is the same: decisions with owners, risks with names against them, and a rhythm that existed before they asked about it.
Risk ownership: names, not registers
A risk register that nobody owns is a spreadsheet, so start from the other end. List the eight to twelve things that could genuinely damage the business, which in a technology services firm usually includes concentration in one or two clients, a key person whose departure would break delivery, a contract with uncapped liability, and the security or data obligations you have signed up to but never tested. Against each one, write a single name, not a team, and one sentence describing what that person is doing about it. Review the list quarterly. That is the whole discipline, and it will survive scrutiny from any client because it shows judgement rather than paperwork.
Decision records: two paragraphs, not board papers
Significant decisions, meaning hires above a certain salary, contracts above a certain value, pricing exceptions and anything that changes how the firm operates, should leave a trace: what was decided, who decided it, and why. Two paragraphs in a shared document is enough, and the habit matters more than the format, because a business where decisions can be reconstructed is a business where decisions can be delegated. This is the same mechanism that underpins decision rights: once it is written down who can decide what, the founder stops being the approval queue for everything.
Rule of thumb: if a decision cannot be reconstructed six months later from something written at the time, it was not governed, it was just made.
Client and contract review: a second pair of eyes before signature
The contracts that hurt scaling firms are rarely the ones that were negotiated hard; they are the ones that were never read by anyone except the person desperate to close them. Right-sized contract review means that any deal above an agreed threshold, or any deal with non-standard terms, gets thirty minutes with someone who is not commissioned on it, looking specifically at liability, payment terms, scope language and termination. Pair this with a monthly review of live client accounts, covering margin, delivery health and any commitments made outside the contract, and you have closed the gap where most nasty surprises originate. If margins are already drifting, that review is also where you will first see it, well before the delivery margin problem shows up in the accounts.
A board cadence that fits a 30 to 60 person firm
You do not need a plc board pack, but you do need a fixed rhythm, because a board meeting that moves whenever the diary gets busy is a board meeting that does not exist. For a firm this size, a monthly leadership meeting working from a one-page dashboard of pipeline, utilisation, cash and delivery health, plus a quarterly session that steps back to look at risks, strategy and the numbers against plan, is enough. The quarterly session is where the risk list gets reviewed and where non-executive directors or investors, if you have them, earn their keep. Keep the papers short, circulate them two days before, and record decisions and actions rather than minutes of who said what.
Governance is not the meetings; it is what would still be true about how the business runs if the meetings were cancelled for a quarter.
Setting it up in a month
None of this requires a programme. In week one, write the risk list with your leadership team in a single two-hour session and put a name against each item. In week two, agree the thresholds: which decisions get recorded, which contracts get a second review, and who holds each of those responsibilities. In week three, build the one-page dashboard from numbers you already have, resisting the urge to build reporting you do not yet need. In week four, hold the first monthly meeting against that dashboard and book the next twelve months of monthly and quarterly sessions into every diary before anyone leaves the room. The rhythm is the deliverable; everything else improves with repetition.
What to leave out
Right-sized also means saying no. You do not need a governance committee, a policy for every eventuality, an internal audit function or software to manage any of this at 40 people, and adopting them early creates the bureaucracy your best people joined a small firm to escape. The test for any addition is simple: does it change a decision, protect against a named risk, or produce evidence a client or investor has actually asked for. If it does none of those, it is theatre. Governance should sit inside your operating rhythm, not beside it, which is why it belongs in the same conversation as operating model design rather than being bolted on afterwards.
Where Vitori fits
Everything above can be done by a capable leadership team in a month, whether with Vitori or without, and if your team has the bandwidth to do it, you should simply do it. The difficulty is rarely knowing what good looks like; it is making the rhythm hold through a busy quarter, which is where most governance efforts quietly die. Vitori's Operational Scale Framework treats governance as part of the Operations pillar and matches the structure to your stage, so a 35-person firm gets a 35-person firm's governance rather than a diluted corporate template, and where the gap is capacity rather than knowledge, our Operator model embeds fractional leadership to run the cadence until it is embedded and no longer depends on us. The end state is the same one we work towards in everything: a business that runs, and scales, without the founder in every decision.
