Two very different animals share one word, and conflating them causes an enormous amount of failure.
Capital-G Governance is formal and institutional. The review board that must approve an API before production. The architecture committee that owns the standards document. The regulatory framework, the vendor audit, the policy engine that gates deployment. It has teeth — people lose budget over it, teams miss launches because of it. In a regulated industry it is often the only thing standing between an organization and a serious failure.
Lowercase-g governance is the ambient, distributed, team-level discipline of doing things consistently and well. The thousand small choices about naming, structure, versioning and error handling that get made while building.
The insight that unlocked this for me: lowercase-g is where governance actually happens. The Capital-G structure can mandate whatever it likes, but if the daily practice does not change, nothing has changed except the paperwork. Most enterprise governance failures are Capital-G programs with no lowercase-g reality underneath.
Both are legitimate. The right relationship is that Capital-G sets the small number of things that genuinely must be true and provides the resources, while lowercase-g does the actual work — supported with guidance rather than policed with gates.