Enterprise Governance
Blog.

Notes from the team building HelixGate. Enterprise governance, architecture decisions, supplier risk, EU AI Act, audit readiness — written for practitioners, not search engines.

ARCHITECTURE14 min read

The complete guide to Architecture Decision Records

What an ADR is, what a good one looks like, and the seven-phase lifecycle that turns it from a wiki page into governed evidence.

Read →
AI ACT11 min read

EU AI Act compliance — a practical checklist

Article 27 FRIA, Article 53 GPAI, Article 72 monitoring, Article 73 incident clock. Mapped to actions, not lawyer jargon.

Read →
FINANCE9 min read

The business case approval workflow

Five Case Model, three approval bands, benefits realisation. What changes when the workflow lives in a register, not in inboxes.

Read →
PROCUREMENT10 min read

Contract lifecycle — best practices

30/60/90-day alerts, auto-renewal traps, surviving obligations, supplier-spend roll-ups. The patterns that keep procurement honest.

Read →
SUPPLIER RISK12 min read

A four-tier supplier risk framework

Critical / High / Medium / Low. Why the tier matters, what each obligates, and how cascading attestations work in practice.

Read →
ISO 270018 min read

The ISO 27001 governance evidence gap

Why most ISMS implementations pass the audit on paper and fail on practice — and what closing that gap actually looks like.

Read →
SOC 29 min read

SOC 2 readiness for SaaS, without the consultancy bill

The technical controls that map directly to CC6 and CC7, the evidence that comes for free if your system is built right, and the gaps you have to close manually.

Read →
CATEGORY7 min read

Enterprise governance vs GRC

Where they overlap, where they don’t, and why most GRC tools struggle to govern the upstream decisions that create risk.

Read →
EA11 min read

Service catalogue — the patterns that work

Owner, tier, lifecycle, dependencies, commercial. The five fields without which a service catalogue is just a spreadsheet.

Read →
EA10 min read

Business capability mapping — a practical guide

What a capability is, how it differs from a service, and why mapping them is the single most useful EA activity for an Investment Board.

Read →
ARCHITECTURE13 min read

Implementing ADR governance from scratch

A 30-day plan to introduce ADRs into an organisation that doesn’t have them — without breaking the architecture team’s morale.

Read →
CATEGORY8 min read

What is enterprise governance, exactly?

The category we’re building in — defined plainly, with examples and counter-examples.

Read →
COMPARISON6 min read

HelixGate vs the master spreadsheet

If your governance lives in spreadsheets and email, here’s exactly what changes — and exactly what you give up.

Read →
COMPARISON9 min read

HelixGate vs ServiceNow

Where ServiceNow is the right answer, where HelixGate is, and why the trade-off comes down to time-to-value vs configurability.

Read →
COMPARISON10 min read

HelixGate vs LeanIX, Ardoq, and the EA tools

EA tools focus on the map. HelixGate focuses on the decisions that change the map. Where each fits.

Read →
§ Closing statement

Have a topic you’d like covered?

We write about what customers ask us. Email hello@helixgate.io with a question, and we’ll add it to the queue.