I can tell within the first five minutes of a P1 bridge call whether an organization's ITIL governance is real or theoretical. Real governance means the on-call engineer at 2am knows exactly what to do, who to escalate to, and what "resolved" means for this specific incident — without needing to track down the person who wrote the runbook.

The 2am Test

Ask yourself: if your most junior on-call engineer hit a P1 incident at 2am with nobody senior immediately reachable, does your documented process actually tell them what to do — or does it describe an idealized process that assumes someone experienced is already on the call?

Most ITIL documentation I've reviewed fails this test. It's written by a process team, reviewed by other process people, and never stress-tested against the actual worst-case scenario it's supposed to govern.

"A runbook nobody trusts at 2am isn't a runbook. It's a document with good intentions."

What Passes the Test

How I Build Governance That Passes

Across 20+ global transitions delivered with zero Sev-1 incidents post go-live, the consistent factor wasn't more documentation — it was governance built directly from operating the service, with the people who'd actually be on-call involved in writing the runbook, not just receiving it afterward.

20+
Zero Sev-1 Transitions
25%
Hypercare Reduction
Key Takeaway

Test your governance framework against your worst on-call scenario, not your best one. If it only works when an expert is available, it isn't governance — it's a backup plan for when the framework fails.

ITIL 4 gives you the structure. Whether that structure survives a real 2am incident depends entirely on whether it was built with the people who'll actually be holding it together when it matters.