The question at hand
You're designing an information governance program, and leadership wants to know what you'll deliver and when. Your instinct might be to start with a concrete project: clean up that email mess, fix the shared drive chaos, or get legal hold under control. However, governance frameworks suggest starting with strategic objectives aligned with organizational goals.
Which comes first? The answer determines whether your program survives its first year.
Most practitioners face this sequencing problem when pitching their first real IG initiative. You can build a detailed business case for a specific project with clear outcomes and measures. Or you can articulate strategic objectives that connect to enterprise risk and compliance goals. Both approaches have their advocates, and both have failed spectacularly in different organizations.
The case for starting with concrete projects
The project-first camp argues that strategic objectives without demonstrated capability are just promises. You haven't proven you can execute. Leadership has heard plenty of governance pitches that never delivered measurable results.
Start with a targeted project that solves a visible problem. Pick something executives already feel: litigation costs from over-preservation, audit findings on retention failures, or storage expenses that keep climbing. Build a quantified business case showing specific cost savings or risk reduction. Deliver it on schedule. Then use that credibility to propose broader objectives.
This approach gives you something tangible to show. When you complete Phase 1 of an email retention project, you can point to gigabytes deleted, storage costs reduced, or legal hold processes streamlined. Those numbers matter in budget conversations. They prove you can manage resources and deliver outcomes, not just talk about governance principles.
The project-first model also lets you test assumptions on a smaller scale. You'll learn which stakeholders resist change, which systems create technical barriers, and which compliance requirements actually bind your organization. That knowledge informs better strategic planning later.
The case for leading with strategic objectives
The strategy-first advocates see a flaw in the project-focused approach: it produces orphaned initiatives that die when the project sponsor leaves or priorities shift. You fix email retention, declare victory, and then watch the program stall because nobody understands why governance matters beyond that one pain point.
Strategic objectives frame individual projects as steps toward larger goals. When you articulate that your organization needs to reduce unnecessary data volumes, retain valuable data, safeguard confidential data, and preserve data for litigation, you're describing an ongoing program, not a one-time fix. Each objective connects to compliance requirements, risk mitigation, and information value in ways executives understand.
This framing also makes it easier to sustain support across leadership changes. A new CIO might not care about the email project your predecessor championed. But they'll care about regulatory compliance, data breach risk, and litigation exposure. Strategic objectives outlive individual sponsors because they tie to persistent organizational needs.
The strategy-first model gives you a narrative for sequencing work. You can explain why email retention comes before shared drive cleanup, or why legal hold process improvements enable better disposition programs. Without that narrative, your next project looks like scope creep instead of planned progression.
Where practitioners actually land
Most successful programs don't choose one approach exclusively. They integrate both.
You need the concrete project to prove capability and generate early wins. But you position that project within strategic objectives from the start. The distinction isn't whether you do strategic planning or project execution. It's whether you connect them explicitly in your initial pitch.
Strategic IG objectives typically focus on reducing unnecessary data volumes, retaining valuable data, safeguarding protected confidential data, and preserving data for litigation. The value of these objectives is usually expressed qualitatively: improving compliance, mitigating risk, maximizing information value. That's too abstract for a funding request.
Convert strategic objectives into SMART goals by grafting project specifics onto strategic direction. Instead of "reduce unnecessary data volumes," write: "Reduce unnecessary data volumes by completing Phase 1 of Email Retention and Disposal Project by end of Q3 2025, including implementation of going-forward storage strategy for record-quality email, new Records Control Schedule for non-record email, and related updates to legal hold process."
This formulation gives you both. The strategic objective provides the "why" that survives personnel changes and budget cycles. The project parameters provide the "what" that gets funded and measured. When you complete Phase 1, you update the same strategic objective with Phase 2 parameters, maintaining continuity while showing progress.
Our take
Lead with strategic objectives, but fund specific projects.
Your initial pitch should name the strategic objectives your program will advance. Don't bury them in an appendix or save them for "future phases." Make them visible from the start, even if your immediate request only covers one project. This costs you nothing and buys you durability.
Then build your detailed business case around the specific project that best demonstrates value under those objectives. Show the outcomes, measures, timeline, and resources for something you can actually deliver in 6-12 months. Prove you can execute before you ask for enterprise-wide transformation.
The risk of starting project-only is that you get trapped in a cycle of one-off initiatives that never build momentum. Each new project requires re-selling the value of governance from scratch. The risk of starting strategy-only is that you never get funded because leadership sees no concrete deliverables.
The integrated approach acknowledges that you need both credibility and vision. You can't sustain a program on quick wins alone, and you can't launch one on strategic vision alone. Frame your work as advancing strategic objectives. Fund it as discrete projects with clear success criteria. Update your strategic goals as you complete each phase, showing how individual projects connect to ongoing objectives.
This isn't a compromise position. It's recognition that information governance operates in organizational systems where both immediate results and long-term direction matter. You'll know you've got the balance right when your project proposals get approved and your strategic objectives get referenced in enterprise risk discussions you didn't initiate.



