I second Saim in that Governance can take many forms and have widely differing definitions in the specifics of implementation and interpretation of requirements.
We in Controlant work in Pharmaceutical Logistic, so Governance for us means the system we apply to validate that our platform, IoT logger (manufacturing and operation) processes and so on, adhere to the Compliance requirements set forth by FDA annex 11, EudraLex Annex 11 (both relate to governing computerised systems in pharma, US and EU respectively) as well as the relevant portions of GxP on top of ISO 27001 and 9001.
For a long time this has been accomplished up to the standards of certification using a largely human and “paper” process known as our Management System. Don’t get me wrong, there is a lot of automation in pipelines, IaC, automated testing etc that all play a part. But the end “seal of approval” is human in nature currently.
We are now exploring and working on what parts of the process can be fully automated and are working with
kosli.com on automating the collection of the evidence required to validate the system and reducing human interaction in execution of the process, in other words relying on humans to govern the product and instead giving humans time to focus on governing the process itself.
Hope that make sense, happy to exchange ideas if this is something you are working on.