You can spot it from the calendar. Work arrives as incidents: the regulator asks a question, finance finds two revenue figures, a customer receives someone else's statement, a model is caught training on data it should never have seen. The team responds well — often heroically — and then returns to whatever it was doing until the next one. Reactive governance is not a character flaw. It is what governance looks like before anyone has funded prevention, and almost every program starts here.
In practice. The way out is to use the incidents rather than just survive them. Log each one with what it cost, what data was involved and which control would have caught it. Twelve entries make a pattern, and a pattern makes the business case that a maturity slide never will: the same three domains, the same missing owner, the same absent quality rule. That is also the moment to convert one incident into a permanent control instead of a cleanup.
Where it goes wrong. Staying here. A team known for fixing things becomes a cleanup crew — valued, busy, never funded to prevent anything — and the reputation hardens: governance is the people you call after the damage. Watch for the tell that this is happening, which is that nobody can name a decision the governance function made before an incident forced it.