Cross-Agency Governance Coordination
Renata Holloway remembers the exact moment the coordination effort fell apart. She was leading AI governance for the Department of Housing and Urban Development (HUD) and had spent four months aligning with her counterpart at the Department of Health and Human Services (HHS) on a joint homelessness-prediction model. Then she learned that HHS had already published its own AI accountability policy, with definitions, oversight thresholds and risk tiers that contradicted HUD's at almost every point. "We were both doing governance," she said. "We were just doing it in completely different languages, and nobody had thought to check." Building cross-agency AI governance from that moment forward became the defining challenge of her career.
Why Cross-Agency Governance Fails
Federal agencies tend to develop AI governance in isolation. Each agency has its own legal counsel, its own risk appetite and its own IT modernization timeline. The result is a patchwork of policies that use the same words, "high-risk AI," "automated decision-making," "human oversight," to mean different things. When agencies need to share data, co-develop models or jointly serve citizens, those definitional gaps become operational breakdowns.
Notice that nothing in Renata's story involved bad faith or even disagreement. Both agencies had done the responsible thing. Both had a policy, both had thresholds, both had risk tiers. The failure was that neither had a reason to look sideways before publishing, and no mechanism existed that would have made them. Isolation is the default state of governance development, not a lapse from it, which means alignment has to be deliberately caused by somebody whose job it is. If nobody owns the sideways look, it does not happen, and the incompatibility is discovered at the point where two programs try to work together and find they cannot.
The problem compounds across federal and state boundaries. A state workforce agency using a federally funded AI tool may face conflicting obligations from its state legislature, its federal grant agreement and the originating federal agency's internal policy. Nobody designed this conflict intentionally. It grew from independent governance programs that were never aligned, and the state agency at the bottom of the stack is left to reconcile three sets of requirements that were each written without reference to the other two.
What Divergent Definitions Actually Break
It is tempting to treat vocabulary as a preliminary and get to the substance. The substance is the vocabulary. Consider what happens when two agencies classify the same joint model differently. One treats it as high-risk and requires pre-deployment review, ongoing monitoring and a published notice. The other treats it as moderate and requires none of that. The model does not become two models. Somebody has to decide which regime governs, and in practice the answer is decided by whoever has the stronger institutional position rather than by whoever has the better analysis.
The same fracture appears in every dependent process. A conflicting definition of "automated decision" means the two agencies disagree about whether a human review step is required at all, which means they disagree about staffing, which means they disagree about cost. A conflicting definition of "AI system" means one agency's inventory contains the model and the other's does not, so any government-wide count of AI in use is wrong before anyone starts. A conflicting transparency obligation means one agency publishes and the other does not, and the public reads the difference as concealment rather than as a definitional artifact.
This is why the cost of misalignment shows up late and lands hard. Nothing breaks while each agency is writing its own policy. Everything breaks at the moment of joint work, which is also the moment when a program has usually committed budget, staff and political capital, and when the honest advice is the least welcome. Renata's four months were not wasted because the model was wrong. They were wasted because the governance underneath it could not be reconciled after the fact.
The Foundation: Shared Definitions
Before you can align governance frameworks, you need a shared vocabulary. This sounds basic. In practice, it takes three to six months to negotiate across agencies with strong legal cultures and entrenched terminology, and leaders who have never done it are consistently astonished by that figure. The reason it takes that long is that the words are not neutral. Each definition already sits inside one agency's policy, carries commitments that agency has made publicly, and cannot be changed there without reopening decisions that were expensive to close.
The minimum shared vocabulary for a cross-agency AI governance framework covers four things:
- A common definition of "AI system," specifying what types of software are in scope.
- A shared risk classification scheme, defining what makes a system low, medium or high risk.
- Aligned definitions of "automated decision" and "human-in-the-loop," clarifying how much human review must occur at each risk tier.
- A shared understanding of transparency obligations, covering what agencies must disclose publicly and to whom.
Renata's team borrowed a technique from contract law. They drafted a glossary annex that each agency's general counsel signed before the substantive governance work began. A signed glossary is not legally binding in the same way a statute is, and it is worth being precise about what it does buy. It creates a negotiating record. It makes definitional backsliding visible and costly rather than impossible, because the agency that wants to reinterpret a term now has to do so against its own counsel's signature and in front of the other parties. That is a meaningful constraint and it is not a guarantee. Treat a signed glossary as a document that raises the price of drift, not one that prevents it.
Two practical notes from teams that have done this. Define the boundaries, not just the categories: most of the argument in a risk classification scheme is about the edge cases, and a scheme that assigns clean examples correctly while leaving the ambiguous ones to judgement has not actually aligned anything. And date the glossary. The technology moves, the categories will need revision, and a glossary with no review point becomes a document people quietly stop consulting rather than one they openly amend.
Common Standards Beyond Vocabulary
Shared definitions settle what things are called. Common standards settle what evidence counts, and that is the second half of the alignment problem. Two agencies can agree perfectly on what "high-risk" means and still be unable to accept each other's work, because one expects a testing report in one shape and the other expects a different artifact, produced by a different function, on a different cadence.
The standards worth harmonising early are the ones that generate reusable artifacts. Agree on what an assessment of a system contains and in what structure. Agree on what testing evidence must be retained, in what form, and for how long, so that the record produced by one agency is legible to another. Agree on how findings are rated, because a finding described as significant in one agency's language and moderate in another's cannot be tracked jointly. None of this requires a common tool, and pushing for one is usually how these efforts stall. It requires a common shape for the output, which is a much smaller ask and survives each agency keeping its own systems.
Resist the pull toward inventing a new standard where an existing one already has adoption in both agencies. A widely used voluntary framework that both parties already reference is worth more as a coordination substrate than a bespoke scheme that is better on paper and unfamiliar to everybody. The technical and legal instruments that carry this work between agencies, including the financial and acquisition mechanisms, are developed in Cross-Agency AI Coordination; this lesson stays with the governance layer that sits above them.
Memoranda of Understanding
A Memorandum of Understanding (MOU), a formal written agreement between agencies that is not a binding contract but carries institutional weight, is the most common vehicle for cross-agency AI governance. A well-structured AI governance MOU covers five things: scope, meaning which systems and data are included; roles, meaning who is responsible for each governance function; standards, meaning which technical and policy standards apply; escalation, meaning how disputes are resolved; and sunset, meaning when the MOU will be reviewed and renewed.
MOUs should not try to resolve everything. Renata's team learned to keep them focused on governance infrastructure and to handle system-specific details in separate agreements. A single MOU governing AI collaboration across three large agencies can take 12 to 18 months to negotiate if it tries to cover every use case. A narrower MOU establishing shared definitions and an oversight council can be signed in 60 to 90 days. The difference is not drafting speed. It is that a narrow MOU only has to survive review by the offices that care about definitions and structure, while a comprehensive one has to survive review by every office with an interest in any use case it touches.
The sunset clause is the provision most often treated as boilerplate and most often consequential. An MOU with no review date does not expire; it fossilises. Staff turn over, the systems in scope change, and the document keeps being cited by people who were not there when it was written and who assume it says something reasonable. A defined review point converts that slow decay into a scheduled conversation, and it also gives any party a legitimate way to raise a problem without appearing to renege.
Interagency Councils
An interagency council is a standing body of representatives from multiple agencies that meets regularly to coordinate policy, share findings and resolve disputes. For AI governance, an effective council typically meets monthly at the working level and quarterly at the senior executive level. The working-level group handles technical and operational issues. The senior group handles policy conflicts, budget implications and anything that requires agency head sign-off. Splitting the two is what keeps the senior meeting from becoming a status update, which is the failure state that quietly ends most councils.
Structure matters. Councils without a defined decision-making process tend to become talking shops. Define voting rules upfront: which decisions require consensus, which can be made by a majority, and which escalate to a designated lead agency. Designate a secretariat, a small staff function, typically two to three people, to manage meeting cadence, track action items and maintain the shared policy repository. That secretariat is the single most common thing agencies try to do without, and its absence shows up as decisions that were made and then not recorded, which is functionally the same as decisions that were never made.
Two further design choices separate councils that produce output from councils that produce meetings. Give the working level a real decision scope rather than a recommending role only, so that routine alignment questions are settled where the expertise is. And keep membership stable by naming a person and a designated alternate rather than an office, because a council whose attendees change each month spends its time rebuilding shared context instead of using it. Establishing an AI Governance Board covers the equivalent design questions inside a single agency, and most of them transfer.
Federal and State Coordination
Federal and state AI governance coordination is younger and less institutionalized than interagency coordination. Grant conditions are currently the most effective lever. When the federal government funds a state AI initiative, the grant agreement can require alignment with federal governance standards as a condition of funding. The challenge is that grant conditions set floors, not ceilings. States may adopt stricter requirements, and the resulting variation can complicate joint programs even when every participant is compliant.
That asymmetry is worth designing around rather than complaining about. A floor-setting condition works well for things you need everyone to do at least: document the system, classify its risk, retain the evidence. It works badly as a mechanism for uniformity, because a state that has legislated something stricter cannot lower it to match, and should not be asked to. Write joint programs so that they function correctly when a participant exceeds the baseline, which mostly means specifying the minimum artifact rather than the exact process that produces it.
A growing number of states are joining voluntary compacts, multi-state agreements modeled on existing compacts for emergency management and environmental regulation. These compacts allow states to establish shared AI governance standards without waiting for federal action. If your agency works closely with state counterparts, map their compact memberships before designing your coordination structure, because a state that has already committed to a shared standard through a compact has a position it cannot casually trade away, and discovering that late is how a coordination design gets rebuilt. Federal/State/Local AI Alignment and State and Local Government AI Policy go further into that landscape.
Avoiding Duplicate Governance Overhead
One of the strongest political objections to cross-agency governance is the fear of redundancy. Agency leaders worry that a joint oversight mechanism will add process on top of existing process, consuming staff time without adding value. This concern is legitimate and it is usually raised by someone who has watched it happen.
Renata's council found that three agencies were each conducting separate algorithmic impact assessments, meaning structured reviews of an AI system's potential effects on people, for the same shared model, consuming roughly 1,800 person-hours per year in duplicated work. The council redesigned the process so that one lead agency conducts the assessment and the others provide input, reducing total effort by 60 percent. Check that against its inputs: 60 percent of 1,800 is 1,080 hours removed and about 720 retained, which is consistent with two agencies still doing real review work rather than none. If the other two had contributed nothing at all, the reduction would have been closer to two thirds, so the reported figure sits sensibly below that ceiling. It is one council's result on one model, not a rate to promise your own leadership.
Cross-agency governance should reduce the total compliance burden on the system, not multiply it. If your joint framework creates more work than three separate frameworks would have, you have built coordination overhead rather than governance. The practical steps that prevent this are unglamorous: map existing governance requirements for each agency before designing the joint framework, identify where requirements overlap and where they genuinely conflict, and design the joint process to satisfy all requirements through a single workflow wherever possible.
A shared evidence repository is the mechanism that makes reuse real, and it carries a caveat that has to travel with it. One agency's testing documentation can satisfy another agency's audit requirement without separate re-testing only where the two requirements are actually equivalent, and equivalence is something you establish by comparing the requirements in writing, not something you assume because both are called an audit. Reused evidence also ages. Documentation that accurately described a model before its last retraining is not evidence about the model in production now, and a repository that makes stale artifacts easy to find is worse than one that does not exist. Record what each artifact covers, as of when, and against which requirement, or reuse becomes a way of laundering old assurance into new decisions.
When Requirements Genuinely Conflict
Mapping requirements across agencies produces three piles, and only two of them are alignment work. Some requirements overlap, and those are the win: one workflow satisfies both, and the duplication disappears. Some merely differ in form, and those are cheap: the same substance in a different shape, closed by agreeing on a structure. The third pile is the one that matters, and it is the requirements that actually conflict, where satisfying one means failing the other.
Genuine conflicts cannot be harmonised by a council, and pretending otherwise is how joint frameworks acquire language that sounds agreed and means nothing. What a council can do is identify them precisely, establish which authority each requirement flows from, and then scope the joint work so that the conflict does not sit inside it. Sometimes that means a shared model is governed under one agency's regime with the other participating rather than co-owning. Sometimes it means the joint program is narrower than anyone wanted. Both outcomes are better than an agreement whose parties each believe their own rules survived.
Write the conflicts down explicitly, in the same document as the alignments, and record which authority each side is bound by. That register is the most useful artifact a coordination effort produces, because it is the thing new staff need most and the thing nobody thinks to write. It also prevents the recurring conversation in which someone proposes, in good faith, an integration that was ruled out earlier for a reason nobody recorded.
Governing the Joint Model Itself
Framework alignment eventually has to answer a concrete question: when two agencies build one model together, whose governance governs it? Renata's homelessness-prediction model was exactly this case, and the definitional conflict she discovered was only painful because there was no agreed answer waiting for it. Left unsettled, the question resolves by drift, usually toward whichever agency hosts the infrastructure, which is an accident of procurement rather than a governance decision.
Settle it explicitly and settle it per system rather than in general. Name one agency as the governing authority for the model, with the others as participants holding defined rights: to receive the assessment, to see monitoring results, to raise an objection through a stated route, and to withdraw their data or their participation on stated terms. Name who classifies the risk tier, because that single determination cascades into everything else. Name who owns the public-facing disclosure, since a joint system with two disclosures that differ is worse than one with a single accurate one.
The point of naming a governing agency is not to concentrate power. It is to make accountability locatable, which is what any reviewer, any oversight body and any affected member of the public will eventually ask for. A model that several agencies govern jointly and none governs specifically is a model whose failures will be nobody's, right up until they become everybody's in public.
Managing the Politics
Cross-agency governance is as much a political challenge as a technical one. Agencies guard their autonomy. Senior leaders worry about ceding authority to a council where they are one vote among several. Procurement cycles, personnel rules and appropriations all create structural barriers to coordination that no amount of goodwill at the working level can dissolve.
Renata's most effective tactic was framing coordination as risk reduction for each agency individually, not as shared sacrifice. An agency that joins a joint oversight council gains access to pooled expertise, shared testing infrastructure and a governance track record. Be careful about how far that last claim is pushed. Participation in a joint structure is evidence that the agency ran a process; it does not transfer accountability for the agency's own systems to the council, and no reviewer will accept membership as a substitute for the agency's own documentation. Sold accurately, it is still a strong offer. Sold as cover, it will fail the first time someone tests it.
The framing that works, then, is specific rather than principled. Each agency's general counsel needs to be able to explain to their agency head why this is a good deal for that agency, with named things it gets and named exposures it reduces. "Interoperable governance is important" persuades nobody with a budget. "We stop paying for our own version of a review three other agencies have already built, and we get their findings on the vendor before we sign" persuades most people.
Sequencing the Work
The order matters, and the natural order is wrong. Most efforts start with the joint policy, because that is the visible artifact, and discover the definitional conflicts halfway through drafting when positions have already hardened. Renata's sequence inverts that: settle the vocabulary and get it signed, agree the standards that determine what evidence counts, stand up the council with its decision rules and secretariat, then write the MOU that records what the council has already worked out, and only then take on joint policy for specific systems.
That order works because each step produces something the next one needs and because the hardest negotiation happens while the stakes are lowest. Nobody has a program on the line during the glossary conversation. Everybody does during the joint policy conversation. Front-loading the argument to the point where it is cheapest is the single highest-return choice available in this work, and it is also the least satisfying to report upward, because for the first several months the deliverable is a document defining words.
Anti-Patterns to Avoid
- Writing joint policy before agreeing the vocabulary. Drafting starts, positions harden, and the definitional conflict surfaces when a program already has budget and political capital committed. The glossary conversation is cheap at the outset and nearly impossible once drafting is under way.
- Treating a signed glossary as binding. It creates a negotiating record and raises the cost of drift. It is not a statute, it does not prevent reinterpretation, and a team that stops checking because the annex is signed will discover the divergence the same way Renata did.
- Comprehensive MOUs. An agreement that tries to cover every use case has to survive review by every office with an interest in any of them, which is why those negotiations run 12 to 18 months and frequently collapse. Keep the MOU to governance infrastructure and handle systems separately.
- Councils without decision rules. A standing body with no voting procedure, no escalation path and no secretariat becomes a talking shop, and its decisions go unrecorded, which is indistinguishable from never having made them.
- Rotating council membership. Naming an office rather than a person and an alternate means each meeting rebuilds context that the previous meeting had already established. Continuity is most of what a council is for.
- Assuming evidence is fungible. Reusing another agency's testing documentation only works where the underlying requirements are demonstrably equivalent and the artifact still describes the deployed system. Undated, uncharacterised reuse turns a shared repository into a way of laundering stale assurance.
- Selling council membership as accountability cover. Participation shows an agency ran a process. It does not move responsibility for the agency's own systems, and offering it that way sets up a failure at the first serious review.
- Using grant conditions to force uniformity. Conditions set floors. A state that has legislated something stricter cannot come down to meet you, so a joint program that assumes identical practice will break on its most conscientious participant.
Practice Prompts
- Definitional collision test. Take your agency's definitions of "AI system," "automated decision" and your risk tiers, and set them beside those of the agency you most often work with. Mark each place where the same system would be classified differently. That list is your negotiation agenda, in priority order.
- Glossary annex draft. Write the four-item minimum vocabulary for one joint program, including the boundary cases rather than only the clean examples, and take it to counsel. Note how long the round trip takes; that is your real coordination tempo.
- Artifact shape audit. For one governance artifact your agency produces, describe its structure, its cadence and its retention. Ask a partner agency for the same. Decide whether the gap is substantive or merely formatting, because formatting gaps are cheap to close and substantive ones are the actual work.
- Duplication map. Identify one AI system that more than one agency reviews. Estimate the hours each agency spends, using your own timekeeping rather than a benchmark, and design the single-lead workflow that would replace it. State honestly what review the non-lead agencies would still need to perform.
- MOU scoping exercise. Draft the five sections of a narrow governance MOU: scope, roles, standards, escalation, sunset. Then list everything you deliberately excluded and where each excluded item will be handled instead.
- Individual-benefit pitch. Write the paragraph your general counsel would give your agency head explaining why joining a joint structure is a good deal for this agency specifically. If it contains no named benefit and no named reduced exposure, it will not survive contact with a budget conversation.
Reflection Questions
- If a partner agency published an AI governance policy tomorrow that contradicted yours, who in your agency would notice, and how long would it take?
- Which of your governance definitions could you not change without reopening a public commitment your agency has already made?
- Where is your agency currently doing review work that another agency has already done on the same system, and what would it take to find out?
- What does your agency actually get from joint governance that it could not get alone, stated in terms a budget officer would accept?
- If the people who negotiated your existing interagency agreements all left, would the documents still be legible to their successors?
Glossary
- Memorandum of Understanding (MOU). A formal written agreement between agencies that is not a binding contract but carries institutional weight. For AI governance it should cover scope, roles, standards, escalation and sunset.
- Interagency council. A standing body of representatives from multiple agencies that meets regularly to coordinate policy, share findings and resolve disputes, typically at both a working and a senior executive level.
- Secretariat. The small staff function, often two to three people, that manages a council's cadence, tracks its action items and maintains the shared policy repository.
- Glossary annex. A negotiated set of shared definitions signed by each participating agency's counsel before substantive governance work begins. It creates a record and raises the cost of definitional drift.
- Risk classification scheme. The agreed basis on which a system is judged low, medium or high risk, including the treatment of boundary cases, which determines what review each tier receives.
- Algorithmic impact assessment. A structured review of an AI system's potential effects on people. Duplicated across agencies reviewing the same model, it is a common source of governance overhead.
- Grant condition. A requirement attached to federal funding of a state initiative. It sets a floor for governance practice and cannot prevent a recipient from adopting something stricter.
- Voluntary compact. A multi-state agreement, modeled on compacts used for emergency management and environmental regulation, through which states set shared standards without waiting for federal action.
- Shared evidence repository. A common store of governance artifacts intended to let one agency's documentation satisfy another's requirement, which holds only where the requirements are equivalent and the artifact still describes the deployed system.
Related Lessons
- Cross-Agency AI Coordination covers the legal, financial and acquisition instruments that carry joint work between agencies, and the sequence for interagency data sharing.
- Data Sharing Agreements for AI develops the agreement layer for training data that crosses custodial boundaries.
- Federal/State/Local AI Alignment goes deeper into the multi-level coordination problem this lesson introduces.
- State and Local Government AI Policy maps the state-level landscape you are coordinating with.
- Establishing an AI Governance Board covers the same design questions for a single agency's internal body.
- Shared Services and Infrastructure Models addresses the build-or-consume decision that often follows successful governance alignment.
- Multi-Level Government AI Governance treats the layered structure of federal, state and local authority in its own right.
- Algorithmic Impact Assessments details the artifact whose duplication this lesson uses as its central example.
Closing Thoughts
Renata's four months were spent building on ground that had already shifted. What she learned was not that coordination is hard, which everyone knows, but that the coordination which matters happens well before the joint work starts and looks like nothing much while it is happening. A glossary. A signed annex. A council with voting rules and two staff. None of it photographs well and all of it is what makes the interesting work possible later.
The honest framing for leadership is that cross-agency governance does not add a layer. It replaces several partial layers with one that the participants can all read, and its success condition is that the total burden on any given system goes down. Hold yourself to that test. If the joint framework costs more than the separate ones did, the answer is not more commitment. The answer is that you have built the wrong thing, and the earlier you say so, the cheaper it is to fix.
Key Takeaways
- Isolation is the default, so alignment must be somebody's job. Renata's failure involved no bad faith: two agencies each did the responsible thing and neither had a reason to look sideways. Name the person who owns the sideways look or it will not happen.
- Start with a signed glossary. Negotiate shared definitions for AI system, risk tiers, automated decisions and transparency obligations before writing any joint policy, and get legal sign-off on the vocabulary. Expect three to six months.
- A signed glossary raises the cost of drift; it does not prevent it. It is not a statute. Its value is the negotiating record, which makes reinterpretation visible and awkward rather than impossible.
- Define the boundaries, not just the categories. A risk scheme that classifies clean examples correctly and leaves the edge cases to judgement has aligned the easy half of the problem.
- Harmonise the shape of evidence, not the tools. Agreeing what an assessment contains, how findings are rated and what is retained is a small ask that survives each agency keeping its own systems. Insisting on a common platform is how these efforts stall.
- Keep MOUs narrow and fast. A focused MOU on definitions and oversight structure can be signed in 60 to 90 days; comprehensive ones run 12 to 18 months and often collapse. Treat the sunset clause as substantive, because an MOU with no review date fossilises.
- Structure councils for decisions, not discussion. Voting rules, escalation paths, a two-to-three-person secretariat, real decision scope at the working level, and named individuals with alternates rather than offices.
- Grant conditions are a floor, not a lever for uniformity. States may go stricter and cannot come down. Design joint programs to work correctly when a participant exceeds the baseline, and map state compact memberships before designing your structure.
- Audit for duplication early. Renata's council found three agencies spending roughly 1,800 person-hours a year assessing one shared model and cut total effort by 60 percent, which is about 1,080 hours removed and 720 retained. That is one council's result on one model, not a rate to promise.
- Shared evidence works only where requirements are equivalent and artifacts are current. Establish equivalence in writing and date every artifact, or the repository becomes a way of reusing stale assurance.
- Sell coordination as individual risk reduction, accurately. Pooled expertise and shared infrastructure are real benefits. Accountability transfer is not one, and offering it that way fails at the first serious review.
- Sequence the work backward from the instinct. Vocabulary, then standards, then the council, then the MOU, then joint policy. The hardest negotiation should happen when nobody has a program on the line.
Frequently Asked Questions
How is this different from Cross-Agency AI Coordination?
That lesson is about doing joint work: the mechanisms, the legal and financial instruments that let one agency perform for another, joint vendor management, and the sequence that makes interagency data sharing lawful and workable. This lesson is about making the governance frameworks themselves compatible, so that joint work is possible at all. In practice you need both, and the order runs from this lesson to that one: agencies that align definitions and standards first find the instruments straightforward, while agencies that reach for an instrument first tend to discover a definitional conflict halfway through execution.
Who should lead a cross-agency governance effort when no agency has authority over the others?
Absence of formal authority is the normal condition, and it is why the council's decision rules matter so much. What substitutes for authority is a designated lead agency for defined categories of decision, agreed in advance and written down, plus an escalation path for everything that exceeds it. The lead role can be permanent or can rotate by subject, whichever the participants will actually accept. What does not work is leaving it unstated, because then every contested decision becomes a negotiation about who decides before it becomes a negotiation about the substance.
Is an MOU enforceable if an agency ignores it?
An MOU is a formal written agreement that carries institutional weight and is not a binding contract, which means its force is reputational and procedural rather than legal. That is less flimsy than it sounds in an environment where agencies interact repeatedly and where oversight bodies read these documents. It is also a reason to design the escalation clause carefully and to be realistic in scoping: an MOU that commits an agency to something it cannot deliver will be quietly ignored, and the ignoring will cost more trust than the commitment was ever worth. Where a genuinely binding obligation is required, that is a question for counsel and a different instrument.
What if a partner agency's risk classification is stricter than ours?
Design for it rather than against it. The workable pattern is that joint processes specify the minimum artifact everyone must produce, while any participant remains free to apply more review to its own systems. Problems arise only when a joint workflow assumes uniform practice and therefore breaks when one participant does more. Note also that a stricter classification often reflects a legislative or public commitment the partner cannot unilaterally relax, so treating it as a negotiating position rather than a constraint wastes time and goodwill.
How do we justify months of definitional work to leadership?
By pricing the alternative in their terms. Renata spent four months on a joint model before discovering that the governance underneath it could not be reconciled, and that work had to be redone. The definitional phase is the same expenditure, moved earlier, at a point where no program is exposed. It also helps to produce something visible from it: a signed annex, a published classification scheme, an agreed assessment format. These are legitimate deliverables and reporting them as such is more honest than describing the phase as preparation.
Do we need a council if only two agencies are involved?
Not necessarily a standing council, but you do need the functions a council provides. Somebody has to convene the working conversation on a predictable cadence, somebody has to record what was decided, and there has to be an agreed route for a disagreement that the working level cannot settle. Two-party coordination often runs on personal relationships and works well until one of the two people moves on, at which point the absence of a record becomes the whole problem. Write down the decisions even when the structure is informal.
Skill.re