
Costs
Part of The honest guide to data governance as of 2027
Data governance framework: the practical version
Data governance bounded: a short governed list, three tiers of control matched to consequence, and a table naming who decides what, and where it is kept.
The reason governance stalls is almost never a missing framework. It is that the scope was never bounded, so the work has no end and no visible progress.
This is a way to bound it. Three parts: a short list of what you govern, three tiers of control matched to how much a mistake would cost, and a table of who decides what.
What to take away
- Govern a short list properly. An estate governed nominally is an estate governed not at all.
- Control should be proportionate to consequence, and most data deserves the lightest tier.
- Decision rights are the part that gets skipped, and the absence of them is what turns a governance group into a discussion group.
Part one: bounding the scope
Governed concepts qualify on one of three grounds, and nothing else does.
Qualifying grounds for governance
- Number appears in a decision with money or obligation
- Two parts of the business calculate it differently
- Reported externally or to a board
- Typical resultten to forty concepts
- Everything else is ungoverned by explicit decision
Run that filter over your reporting estate and you will typically get somewhere between ten and forty concepts. That is the governed list. Everything else is ungoverned by an explicit decision, which is a very different state from being ungoverned by neglect, and the difference matters when something goes wrong.
Publish the list. A concept's presence or absence on it answers most of the questions people would otherwise ask a committee.
Part two: three tiers of control
Three tiers of control
What it applies to
- Governed
- The short list above
- Managed
- Widely used but not consequential
- Open
- Everything else
What it requires
- Governed
- Named owner, written definition, change notice before any change, quality tests with an owner, annual review
- Managed
- Named owner, a definition somewhere findable, best-effort quality checks
- Open
- Access rules only, and a visible label saying it is not governed
The label on the open tier is the piece that carries the most weight. People misuse ungoverned data because nothing told them it was ungoverned, and a one-line marker on the artifact prevents more incidents than any policy.
Three tiers of control
Governed
- Applies to
- Short list
- Owner
- Named
- Definition
- Written
- Change notice
- Required
- Quality tests
- Owned tests
- Review
- Annual
- Access
- Controlled
Managed
- Applies to
- Widely used
- Owner
- Named
- Definition
- Findable
- Change notice
- None
- Quality tests
- Best-effort
- Review
- None
- Access
- Controlled
Open
- Applies to
- Everything else
- Owner
- None
- Definition
- None
- Change notice
- None
- Quality tests
- None
- Review
- None
- Access
- Rules only
Promotion between tiers should be easy and demotion should be possible. A concept whose annual review has not happened in two years should drop a tier automatically, which is uncomfortable and effective.
Part three: who decides what
Who decides what
| Decision | Who makes it | Who must be consulted |
|---|---|---|
| Whether a concept is governed | The governance group | The business area that uses it |
| What the definition says | The concept owner | Anyone who publishes it today |
| Whether history is restated after a change | The concept owner | Whoever publishes externally |
| Who may access the underlying data | The data owner, by role | Privacy and security functions |
| Whether an artifact may claim the top publication tier | The governance group | The producing team |
| Granting an exception to any rule | The governance group, with a review date | The requester |
Two properties make this table work. Every row has exactly one decider, and every decision has a place it is recorded. A row with two deciders is a row where nothing gets decided.
Who decides what
Decision: who decides what?
one named decider per row
two deciders means nothing gets decided
The roles, kept to three
Concept owner. Sits in the business, not in the data team, and would have to change something if the definition changed. Owns the definition and the restatement decision.
Data steward. Sits close to the systems and maintains the records: definitions written down, lineage current, tests running. The formal description of a data steward covers this well, and the role is often part of somebody's week rather than a job.
Governance group. A small standing group with the authority to name owners, ratify definitions, and grant exceptions. It should meet briefly and decide something every time.
Larger structures exist and most organizations do not need them. The general discipline is well described as an overview of the field, and the federal data strategy practices are a useful public example of how a large body states its principles without turning them into a program.
A twelve-month sequence that works
Quarter one: draft the governed list, publish it, and settle one contested concept end to end.
Twelve-month governance sequence
- Quarter oneDraft and publish governed list, settle one concept
- Quarter twoSettle three more, stand up role-based access
- Quarter threeAdd quality tests, start change notice habit
- Quarter fourAnnual reviews, demote stale, publish changes
Quarter two: settle three more, and stand up the role-based access model so that access stops consuming the group's time.
Quarter three: add quality tests to the governed concepts, one meaningful test each, and start the change notice habit.
Quarter four: run the first annual reviews, demote what has gone stale, and publish what changed.
By the end you have a small number of properly governed concepts and a working process. What you will not have is a catalog of the whole estate, and that is the correct trade.
Related reading on this site
Governance substance is in data governance, and its failures are in nine governance mistakes. The build order sits inside the six layer model.
For definition work at the governed tier's center, see writing a metric definition; for parallel tiering of published artifacts, see the three publication tiers.
Common questions
How do we choose between ten governed concepts and forty?
Take the ten that cause arguments this quarter. Forty is achievable later and unachievable as a starting point, and a list that is never completed teaches everyone that the list does not matter.
Our data team wants to own the definitions. Is that wrong?
It is wrong in the sense that it will not hold. A definition owned by the data team gets overridden the first time a business leader disagrees, because the data team cannot decide what the business means by its own concepts.
What happens when nobody in the business will take ownership?
Escalate once, with the specific concept named and the consequence stated. If it still finds no owner, drop it off the governed list and label it openly as ungoverned. That is honest and it usually produces an owner within a month.
Should the framework be documented before we start?
One page, published, and revised as you learn. A framework written in full before any concept has been settled is a prediction rather than a description, and it will be wrong in the parts that matter.







