Yes, provided governance structures and control ownership are clearly defined from the outset. A scalable program includes documented risk methodology, defined roles, monitoring cadence, and evidence lifecycle management. Implementation designed only for short-term validation often requires costly redesign later.