Join our Newsletter — 33% off our NHI Course

What happens when an ICT company cannot show meaningful progress in implementing GNI Principles?

If a company cannot demonstrate genuine implementation, the assessment may surface unresolved gaps in policy, practice, or accountability. That can weaken trust with stakeholders, complicate compliance with related regulatory obligations, and leave the company exposed to public criticism. The process is designed to pressure organisations toward continuous improvement, not just formal participation.

Why weak GNI Principles progress matters for ICT companies

When an ICT company cannot show meaningful progress against GNI Principles, the issue is rarely just paperwork. It usually signals a gap between stated governance and what the organisation can evidence in practice, which matters to customers, regulators, civil society, and internal assurance teams. For technology companies operating in sensitive information environments, that gap can raise questions about transparency, accountability, escalation handling, and whether commitments are being applied consistently across products, services, and regions.

That distinction is important because GNI-style assessments are not meant to reward symbolic participation. They are intended to test whether principles translate into operational behaviour, documented decisions, and credible oversight. If progress is weak, stakeholders may treat the company as unable to substantiate its assurances, even where its policies appear sound on paper. In practice, many security and governance teams discover this only after they are asked to produce evidence that policy intent has never been operationalised.

How the assessment pressure works in practice

Meaningful progress is usually judged through evidence, not intent. A company is expected to show that policies have been adopted, controls assigned, exceptions managed, and responsibilities carried through to day-to-day operations. If it cannot do that, the assessment can expose unresolved problems in governance design, implementation discipline, or recordkeeping. For an ICT company, that often means there is no clear line from executive commitment to operating practice, or that the line exists but is too weak to verify.

The practical consequence is that the assessment becomes a forcing function. Teams may need to explain why specific commitments remain partially implemented, what has changed since the last review, and which business units still operate differently. This is especially important where a principle touches legal process, content handling, user trust, disclosure, or escalation decisions, because partial implementation can be harder to justify than no policy at all. The presence of a policy without evidence of adoption can create a false sense of control.

External reviewers also look for whether the company can show repeatable improvement over time. That means a one-time statement of intent is not enough. Evidence should show ownership, milestones, and follow-through. If those elements are missing, the company may be seen as participating formally while failing to demonstrate operational maturity. The process then shifts from assessment to accountability, and that is often where reputational pressure begins to build.

For readers wanting a useful parallel on evidence-driven control expectations, the OWASP Non-Human Identity Top 10 shows the same basic principle: claims about governance matter less than whether the organisation can evidence control, ownership, and lifecycle discipline.

Where this guidance breaks down is when the company is operating under a vague or immature assessment scope, because then even good-faith progress can be difficult to distinguish from superficial compliance.

Where GNI commitments get stuck, and what that means

Tighter governance often increases coordination overhead, requiring companies to balance transparency against operational friction. That tradeoff becomes visible when different teams own different parts of the same commitment and no one is accountable for the final evidence set.

Common failure points include incomplete policy rollout, inconsistent implementation across jurisdictions, weak audit trails, and unclear escalation paths when obligations conflict. Some organisations also assume that publishing a statement is equivalent to implementation. It is not. The harder question is whether frontline teams can demonstrate that the principle changes actual decisions, especially under time pressure or legal sensitivity.

There is also a genuine consensus gap in how far public evidence should go for some commitments. In some cases, the right balance is still debated between disclosure, user safety, commercial confidentiality, and legal risk. When that happens, the company should be able to show that it made and recorded a defensible decision, rather than pretending the conflict does not exist. That is often more persuasive than overclaiming maturity.

If the company cannot close the gap, the likely result is sustained scepticism rather than a single failed review. The practical lesson is that weak progress is not only a compliance problem, but a signal that governance has not yet become operationally real.

Risk and Threat Considerations

The material risk is assurance failure: the organisation says it supports a principle-based framework but cannot demonstrate that the commitments are operationally embedded. That creates exposure to reputational challenge, regulatory scrutiny where related obligations exist, and internal governance drift as teams begin to treat the commitment as symbolic rather than binding.

Failure mechanism: The gap usually appears when policy adoption, accountable ownership, evidence retention, and exception management are not linked. Without those links, reviewers cannot verify whether the company actually follows the principle in practice, and stakeholders may infer that the organisation is relying on statements rather than controls.

Impact: The company can lose trust, face harder questions in related compliance discussions, and struggle to defend its decisions during external review or crisis response. Over time, the absence of demonstrable progress can also weaken board confidence because leadership cannot prove that accountability is improving.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context GNI progress depends on showing governance commitments are embedded in operations.
GV.RM-01 — Risk Management Strategy Weak progress signals unresolved governance and accountability risk across the company.
ID.IM-01 — Improvement The question is about whether the organisation can show continuous improvement.
Recommendation — Define accountable ownership for each principle and tie it to measurable operating evidence. Map each stalled commitment to a documented risk decision and escalation path. Track remediation actions until the control change is evidenced in practice.
CIS Controls v8 Control 6 — Access Control Management Weak accountability often shows up first in poor ownership and control enforcement.
Recommendation — Enforce accountable ownership for each control and verify it through evidence.
ISO/IEC 42001:2023 A.5 — Leadership and Commitment Principle-based programmes fail when leadership cannot prove governance commitment.
Recommendation — Show leadership commitment through recorded decisions, reviews, and follow-through.

Practitioner Guidance

What to prioritise: Treat evidence quality as the core issue, not the wording of the principle itself. The first task is to identify where a commitment exists without a demonstrable owner, milestone, or artefact that proves implementation.

What to verify: Check whether each claimed improvement can be shown through a recordable decision, a named accountable function, and a repeatable process. If those three elements are missing, the organisation is still in intent mode, even if the policy looks polished.

Escalation / exception: Escalate any area where legal, product, and policy teams disagree on what “implemented” means, because that disagreement usually predicts the failure of the next review cycle. A documented exception is better than an untestable promise.

Practitioner takeaway: The organisations that fare best are usually not the ones with the broadest commitments, but the ones that can show how each commitment has become an auditable operating behaviour.