Card summarizing data governance scope, control tiers, and decision rights. Data governance framework: the practical version
Image: Intelligence Dashboard Metrics

Costs

Part of The honest guide to data governance as of 2027

Data governance framework: the practical version

Data governance bounded: a short governed list, three tiers of control matched to consequence, and a table naming who decides what, and where it is kept.

The reason governance stalls is almost never a missing framework. It is that the scope was never bounded, so the work has no end and no visible progress.

This is a way to bound it. Three parts: a short list of what you govern, three tiers of control matched to how much a mistake would cost, and a table of who decides what.

What to take away

  • Govern a short list properly. An estate governed nominally is an estate governed not at all.
  • Control should be proportionate to consequence, and most data deserves the lightest tier.
  • Decision rights are the part that gets skipped, and the absence of them is what turns a governance group into a discussion group.

Part one: bounding the scope

Governed concepts qualify on one of three grounds, and nothing else does.

Qualifying grounds for governance

  • Number appears in a decision with money or obligation
  • Two parts of the business calculate it differently
  • Reported externally or to a board
  • Typical resultten to forty concepts
  • Everything else is ungoverned by explicit decision

Run that filter over your reporting estate and you will typically get somewhere between ten and forty concepts. That is the governed list. Everything else is ungoverned by an explicit decision, which is a very different state from being ungoverned by neglect, and the difference matters when something goes wrong.

Publish the list. A concept's presence or absence on it answers most of the questions people would otherwise ask a committee.

Part two: three tiers of control

Three tiers of control

What it applies to

Governed
The short list above
Managed
Widely used but not consequential
Open
Everything else

What it requires

Governed
Named owner, written definition, change notice before any change, quality tests with an owner, annual review
Managed
Named owner, a definition somewhere findable, best-effort quality checks
Open
Access rules only, and a visible label saying it is not governed

The label on the open tier is the piece that carries the most weight. People misuse ungoverned data because nothing told them it was ungoverned, and a one-line marker on the artifact prevents more incidents than any policy.

Three tiers of control

Governed

Applies to
Short list
Owner
Named
Definition
Written
Change notice
Required
Quality tests
Owned tests
Review
Annual
Access
Controlled

Managed

Applies to
Widely used
Owner
Named
Definition
Findable
Change notice
None
Quality tests
Best-effort
Review
None
Access
Controlled

Open

Applies to
Everything else
Owner
None
Definition
None
Change notice
None
Quality tests
None
Review
None
Access
Rules only

Promotion between tiers should be easy and demotion should be possible. A concept whose annual review has not happened in two years should drop a tier automatically, which is uncomfortable and effective.

Part three: who decides what

Who decides what

DecisionWho makes itWho must be consulted
Whether a concept is governedThe governance groupThe business area that uses it
What the definition saysThe concept ownerAnyone who publishes it today
Whether history is restated after a changeThe concept ownerWhoever publishes externally
Who may access the underlying dataThe data owner, by rolePrivacy and security functions
Whether an artifact may claim the top publication tierThe governance groupThe producing team
Granting an exception to any ruleThe governance group, with a review dateThe requester

Two properties make this table work. Every row has exactly one decider, and every decision has a place it is recorded. A row with two deciders is a row where nothing gets decided.

Who decides what

Decision: who decides what?

Yes

one named decider per row

No

two deciders means nothing gets decided

The roles, kept to three

Concept owner. Sits in the business, not in the data team, and would have to change something if the definition changed. Owns the definition and the restatement decision.

Data steward. Sits close to the systems and maintains the records: definitions written down, lineage current, tests running. The formal description of a data steward covers this well, and the role is often part of somebody's week rather than a job.

Governance group. A small standing group with the authority to name owners, ratify definitions, and grant exceptions. It should meet briefly and decide something every time.

Larger structures exist and most organizations do not need them. The general discipline is well described as an overview of the field, and the federal data strategy practices are a useful public example of how a large body states its principles without turning them into a program.

A twelve-month sequence that works

Quarter one: draft the governed list, publish it, and settle one contested concept end to end.

Twelve-month governance sequence

  1. Quarter one
    Draft and publish governed list, settle one concept
  2. Quarter two
    Settle three more, stand up role-based access
  3. Quarter three
    Add quality tests, start change notice habit
  4. Quarter four
    Annual reviews, demote stale, publish changes

Quarter two: settle three more, and stand up the role-based access model so that access stops consuming the group's time.

Quarter three: add quality tests to the governed concepts, one meaningful test each, and start the change notice habit.

Quarter four: run the first annual reviews, demote what has gone stale, and publish what changed.

By the end you have a small number of properly governed concepts and a working process. What you will not have is a catalog of the whole estate, and that is the correct trade.

Related reading on this site

Governance substance is in data governance, and its failures are in nine governance mistakes. The build order sits inside the six layer model.

For definition work at the governed tier's center, see writing a metric definition; for parallel tiering of published artifacts, see the three publication tiers.

Common questions

How do we choose between ten governed concepts and forty?

Take the ten that cause arguments this quarter. Forty is achievable later and unachievable as a starting point, and a list that is never completed teaches everyone that the list does not matter.

Our data team wants to own the definitions. Is that wrong?

It is wrong in the sense that it will not hold. A definition owned by the data team gets overridden the first time a business leader disagrees, because the data team cannot decide what the business means by its own concepts.

What happens when nobody in the business will take ownership?

Escalate once, with the specific concept named and the consequence stated. If it still finds no owner, drop it off the governed list and label it openly as ungoverned. That is honest and it usually produces an owner within a month.

Should the framework be documented before we start?

One page, published, and revised as you learn. A framework written in full before any concept has been settled is a prediction rather than a description, and it will be wrong in the parts that matter.

More in Costs

Latest from Practice Desk