Buy 2 get 1 free. Everything is calculated at checkout.
THE CONVERGENCE FATIGUE: The Debt of Duplication in Building Governance
- English
Digital download. Taxes calculated at checkout.
Buy 2, get 1 free, applied automatically at checkout.
- Instant deliveryLink emailed right after payment
- Check your emailThe link goes to the address you enter
- Any devicePhone, tablet, laptop or e-reader
- Secure checkoutEncrypted payment
About this book
Your organization does not have five compliance problems. It has one governance problem described in five vocabularies.Most organizations answer to more than one framework: NIST CSF 2.0 for an insurer, PCI DSS for an acquiring bank, HIPAA for regulators, ISO/IEC 27001 for a customer contract, COBIT for the board. The usual response is to run each one as its own project, with its own owner, its own evidence and its own version of the truth. The result is duplicated work, answers that drift apart, and assessors who conclude the organization does not know its own control state.The Convergence Fatigue shows how to build the governance program once and satisfy the frameworks many, without pretending the frameworks are the same.Inside the book:- A unified control model of 182 framework-neutral control objectives across 24 domains: 150 security objectives and 32 AI governance objectives.- A full mapping matrix that ties each security objective to NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019, PCI DSS v4.0.1 and HIPAA, and each AI objective to ISO/IEC 42001:2023, the NIST AI Risk Management Framework, the EU AI Act and the OWASP Top 10 for LLM Applications (2025). Where no honest correspondence exists, the gap is shown as a gap.- An evidence-once approach: how one risk register, one access recertification process or one monitoring platform can serve several frameworks at once, and where evidence genuinely does not compress.- A divergence register of fourteen places where the frameworks truly disagree, including scope, incident definitions, HIPAA's "addressable" specifications, testing cadences, risk acceptance and four AI-specific divergences grounded in the EU AI Act, with reconciliation guidance for each.- A five-level maturity model applied domain by domain, with an AI governance dimension.- Worked examples built around composite organizations in manufacturing, retail, higher education and healthcare, plus three case studies (a clinical laboratory, a regional bank and a cold-chain logistics operator) that each discover their real obligations, build unified controls and resolve a genuine divergence.- An implementation roadmap, a cross-framework glossary and a guide to the four AI governance sources.Who it is for: GRC analysts and managers, security and compliance leaders, internal and external auditors, consultants, and anyone responsible for a program that answers to more than one framework.This book does not reproduce the text of any copyrighted standard. ISO/IEC and COBIT content is cited by identifier and described in original language, and readers implementing those standards need their own licensed copies. The mappings are the author's independent analysis and are not endorsed by NIST, ISO, IEC, ISACA, the PCI Security Standards Council, HHS, the European Commission or OWASP. The book is educational and is not legal, compliance or audit advice.About the author: Hani Esmael is a technology and information-security practitioner whose work spans governance, security, identity and access management, and technology operations. He writes and teaches under the EFHorizons name.
About the Author
Hani Esmael is a technology and information-security practitioner whose work explores the space between formal controls and the way organizations actually operate.
His experience spans software engineering, technology operations, information security, governance, identity and access management, and technical project leadership. Over more than a decade in technology, he has worked across healthcare, pharmacy, legal, commercial, private-sector, and public-sector environments, designing and improving security processes, managing access and permissions, supporting audit and compliance activities, and translating technical and organizational requirements into practical operating processes.
Esmael's work focuses particularly on governance, security, organizational accountability, and the problems that emerge when systems, responsibilities, and regulatory obligations become more complex than the structures created to manage them. His approach is to identify the underlying governance objective first, then examine how different frameworks express, limit, expand, or operationalize that objective.
This perspective informs the Unified Control Model presented in The Convergence Fatigue and the broader practitioner curriculum developed through EFHorizons LLC, an independent technology, governance, risk, and compliance education and training practice founded by Esmael.
Esmael has also published working papers on SSRN, including Authority Accretion and the Crystallization Threshold , and writes the Shadow Governance series, examining undocumented authority, absorbed responsibility, and the gradual expansion of organizational scope.
He writes and teaches under the EFHorizons name, developing practitioner-oriented books, curriculum, and educational material focused on governance, security, technology, and the organizational problems that exist between formal structures and operational reality.
| Author | Hani Esmael |
| BN ID | 2940184876771 |
| Publisher | Hani Esmael |
| Publication Date | 09/16/2026 |
Delivery and refunds
How you receive your ebook.
How do I receive my book?
Right after payment, a download link is emailed to the address you entered at checkout. Nothing is shipped.
I didn't get the email
Check your spam or promotions folder first. If it isn't there, contact us with your order number and we'll resend it.
What if the file doesn't work?
If the file doesn't open or is incomplete, we'll replace it or refund you.
Can't find the book you need?
Send us the cover in live chat and we'll look for it. We usually reply within 10 minutes.