It's rarely the policy itself. The failure points are predictable and preventable.

Plenty of organizations have a governance document. Far fewer have governance. The gap between the two is where tenants quietly slide back into chaos.
The policy-reality gap
A governance plan that lives in a document is a wish list. The most common failure mode is not bad policy, it is good policy that never translates into how sites get created, how access gets granted, and how content gets retired day to day.
The root cause is usually that the policy was written in isolation. IT drafts rules, leadership approves them, and the people who create sites and share files every day were never in the room. So they keep doing what they have always done.
Rules without defaults
Governance that depends on everyone remembering the rules will fail. Governance that is built into defaults, site provisioning templates, expiring guest access, sensible sharing settings, naming standards applied automatically, mostly enforces itself. If your policy requires training to follow, redesign the policy.
No clear ownership
When governance is everyone's job, it is nobody's job. Every policy needs an owner: someone who reviews access quarterly, retires stale sites, and decides the exceptions. In smaller organizations this is a few hours a month, but it has to be on someone's calendar, not in someone's good intentions.
Trying to govern everything at once
Organizations that attempt maximum-strictness governance on day one usually abandon it by month three because it gets in the way of real work. Start with the controls that close your biggest exposures, typically external sharing and permission sprawl, and tighten gradually as habits form.
Ignoring what the tenant is telling you
Microsoft 365 produces rich signals: sharing reports, access reviews, usage data. Most failed governance programs never look at them. A monthly review of a handful of reports catches drift while it is still small.
What durable governance looks like
Defaults that do the work, one named owner, a quarterly review rhythm, and policies that grew from how your teams actually operate. That combination survives staff changes, growth, and busy seasons, which is the actual test of governance.