From baseline to practice · Guide 05

Keep ownership, privileged authority, email trust and incident readiness true after the initial work is complete.

Run a recurring domain governance review.

Add a short, evidence-based domain-layer review to an existing technology, cyber, risk, supplier or service forum - so changes, unknowns, exceptions and overdue actions remain visible and accountable.

For existing governance forums Eight practical steps Agenda template Action-log CSV
Outcome

A lightweight review that keeps the domain layer governable

The organisation should have a named forum, accountable owner, defined cadence and repeatable evidence set that can confirm what changed, decide what matters, assign action and escalate unresolved domain-layer risk.

Scope

Review the practices together, not as five separate programmes

The recurring review is the maintenance mechanism for the earlier guides. It should draw from authoritative records, incidents and changes - not ask teams to complete a new assessment or produce a parallel report every quarter.

Portfolio and ownership

New, changed, legacy and retirement-candidate domains; accountable owners; renewal continuity; unresolved inventory questions.

Registrar and DNS authority

Privileged access, MFA, recovery paths, locks, provider changes, automation credentials and material DNS changes.

Email authority and public signals

Approved senders, supplier authority, SPF, DKIM, DMARC, report themes, non-sending posture and obsolete records.

Incident and continuity readiness

Incidents, near misses, exercises, provider limitations, stale contacts, recovery evidence and overdue remediation.

Use an existing forum. A quarterly technology risk meeting, supplier review, cyber governance forum, service review or architecture forum is usually a better home than a new domain-governance committee.
Method

Establish the recurring review in eight practical steps

  1. 1

    Choose the forum and cadence

    Select the existing forum with authority to make or escalate decisions about technology, cyber, suppliers, continuity or public trust. Quarterly is a practical default; use a more frequent cadence where change or service criticality warrants it.

  2. 2

    Name the accountable review owner

    Assign one role to prepare the evidence, convene the domain-layer item, maintain the action trail and confirm that decisions reach the right owner. This is coordination accountability, not ownership of every domain or control.

  3. 3

    Define the minimum evidence set

    Use current extracts or summaries from the domain register, authority record, authorised-sender register, incidents, exercises, provider changes, renewal horizon and public-signal observations. Do not recreate the source records in the meeting pack.

  4. 4

    Review change and upcoming decisions

    Focus first on what changed since the last review: new or retiring domains, ownership movement, renewals, supplier transitions, privileged-access changes, DNS or email changes and upcoming projects that will create authority.

  5. 5

    Surface unknowns, exceptions and overdue action

    Review entries marked unknown, shared-access exceptions, temporary senders, permissive policies, stale contacts, untested recovery paths and overdue actions. Ask whether each remains acceptable, requires escalation or should be closed.

  6. 6

    Consider incidents and public evidence

    Review domain-layer incidents, near misses, exercises and material public-signal changes. Use external observation as evidence to reconcile, not as a score or substitute for internal records.

  7. 7

    Make explicit decisions

    Record decisions to retain, retire, remediate, test, accept, escalate or seek further evidence. Name the decision owner, action owner, due date and completion evidence. Avoid meeting notes that describe concern without assigning an outcome.

  8. 8

    Update records and close the loop

    Feed decisions back into the domain, authority and sender registers; update incident and supplier records; escalate risks through existing channels; and set the next review date and evidence cut-off.

Review agenda

Keep the recurring item short and decision-led

A routine review should usually fit within 30 to 45 minutes when source records are maintained. Spend time on changes, unknowns, exceptions, incidents and decisions - not reading every row of every register.

Changes since last review
Domains, owners, suppliers, authority, email senders, platforms and material public signals.
Upcoming decisions
Renewals, retirements, migrations, launches, contracts and provider transitions.
Open unknowns and exceptions
Missing evidence, shared access, temporary authority, permissive posture and accepted risk.
Incidents and exercises
Recent events, lessons, provider limitations and readiness actions.
Overdue actions
Items requiring closure, revised due dates, escalation or explicit acceptance.
Decisions and escalation
What was decided, who owns the action and which existing forum receives escalation.
Record updates
Which registers, runbooks, supplier records and risk records must change.
Next review
Date, owner, evidence cut-off and any focused topic for the next cycle.
Portable meeting structure

Recurring domain-governance review agenda

A plain Markdown agenda that can be inserted into an existing meeting, committee paper, risk forum or service-review template.

Decision and action trail

Record outcomes in a form that can be closed

The starter CSV is deliberately small. It can be imported into the organisation's existing action, risk, ticketing, committee or work-management system and should not become a second long-term source of truth.

Review date
The meeting or governance cycle that created or reconsidered the item.
Source practice
Domain register, authority, email trust, incident readiness, supplier or cross-cutting review.
Domain or boundary
The material domain, provider account, zone, sender or incident path affected.
Finding, decision or action
A concise statement of what is unknown, decided or required.
Outcome type
Investigate, remediate, retain, retire, test, accept, escalate or close.
Accountable owner
The role answerable for the outcome.
Action owner
The person, team or supplier performing the work.
Due date
The agreed completion or reconsideration date.
Status
Open, in progress, blocked, complete, accepted or closed.
Escalation or destination record
The risk, incident, supplier, change, project or committee record that owns the item.
Completion evidence
The link, record, configuration evidence or decision that demonstrates closure.
Last updated
The date status and evidence were last confirmed.
Portable action trail

Domain-governance action log

The blank CSV supports immediate use; the worked example shows how decisions from all five practices can be routed into existing organisational records.

Evidence and cadence

Know when recurring governance genuinely exists

Evidence of practice

  • A named existing forum owns the recurring domain-layer review.
  • The accountable review owner and participants are defined.
  • A repeatable evidence set is prepared from maintained source records.
  • Changes, unknowns, exceptions, incidents and overdue actions are considered.
  • Decisions have owners, dates and completion evidence.
  • Material risk and supplier matters are escalated through existing channels.
  • Source records are updated after the review.

Review it when

  • The scheduled quarterly or proportionate review falls due.
  • A major acquisition, divestment, restructure or brand change occurs.
  • A registrar, DNS, email or critical digital supplier changes.
  • A domain-layer incident or exercise identifies governance gaps.
  • A material launch, migration or retirement changes public authority.
  • Overdue actions or exceptions require escalation outside the normal cycle.
Common failure modes

A recurring meeting can still produce no governance

Creating a new committee

The domain layer becomes an additional governance burden instead of entering an existing forum with authority.

Reading the registers row by row

The meeting consumes time on stable records and misses changes, exceptions and decisions.

Reviewing only public signals

Observable DNS and mail posture are treated as the whole governance picture while internal ownership and authority remain unclear.

Reporting counts without decisions

The forum hears how many domains or findings exist but does not decide what to retain, fix, accept or escalate.

Actions have no destination

Tasks remain in meeting notes rather than moving into a risk, change, supplier, incident or work-management record.

Exceptions never expire

Shared access, temporary senders and permissive controls persist because no owner or reconsideration date exists.

Source records remain stale

Decisions are made, but the domain, authority and sender registers are not corrected afterward.

The review stops when nothing breaks

Cadence fades during quiet periods, allowing ownership, access, suppliers and public authority to drift again.

Complete the cycle

The five guides form one bounded operating sequence

Know which domains matter. Control who can alter them. Govern who may send. Prepare for failure. Then use an existing forum to keep those answers true. The recurring review closes the loop without turning the baseline into another platform.