What is Data Governance?

Governance is a term that most people are aware of, even if they only have a woolly idea of its definition. You might think of the Bank of England, the government, or the rules around how charities work. It evokes ownership and strategy, but it also the sets culture of an organisation.

Key principles of all types of governance include accountability, transparency, policy, risk-management, and structure.

Data governance is simply an extension of this. Not just the ownership of data, but of the standards around that data. Additional principles here include audit-ability, standardisation, quality and change management.

Why is it Important?

The oversight, monitoring, and strategy introduced by good Data Governance bring significant benefits to any organisation:

How to Implement Data Governance From Scratch

Build a governance board

Form a group of people who will own the strategy around policy, security, transparency, and who are accountable for it. Ensure that a wide variety of roles are represented within this group, so that it has all the experience needed. Consider representatives from IT, legal, compliance, and business units. Building cross-functional ownership here brings balance to decisions, allows them to be made more quickly, and better ensures that the rest of the organisation feels included.

The role of this group is not to look after the day to day (although the same people might do both things). In football terms, they are not referees, they are FIFA.

Define the rules

Create the principles by which your data should be governed, and set goals for what they should help you achieve:

  1. The Principles of Data Governance are they rules by which an organisation lives. Implementation of them will vary, but will universally include
    1. Stewardship - define roles and assign people to them to oversee and enact the policies created. People in these roles are responsible for the management and oversight of data. Look out for situations where there is no ownership, or where everyone is responsible. Often people assume data is owned by IT, but it should be owned by a business representative who has approval authority for decisions about data within their domain
    2. Data Quality - it’s crucial that data is complete, correct, and reliable in any organisation. Strategies, guidelines and mechanisms that verify and maintain the quality of data throughout its lifecycle should be implemented.
    3. Accessibility - data should be easy to find, and fast and reliable to access. Accessibility enables faster insight and a reduction of data siloes and duplication, however, it must be strongly balanced with privacy and security, working to the Principle of least Privilege (PoLP). Access controls must be in place, as well as audit-ability, secure storage and transport.
    4. Consistency - partial duplicates, mixed formats, use of different units can all lead to inconsistency. Strong controls on data entering the organisation are the simplest and cheapest ways to prevent it, but holistic, org-wide data models and tools should be used, as well as monitoring.
    5. Compliance - laws and regulations regarding data must be adhered to, with severe consequences for infractions. Audits and regular risk assessments should be performed to ensure that the organisation isn’t in breach. Regular training of staff and mechanisms to prevent breaches should also be put in place.
  2. Goals might include:
    1. Protecting stakeholders’ needs
    2. Reduction of costs through the removal of siloes
    3. Ensuring the transparency of processes
    4. Building more insightful data
    5. Reducing the risk and impact of cyber attacks

Take an audit

Before making any improvements, you need to know where the risks and gaps are in in your estate currently.

Prioritise these discoveries according to urgency and priority - what is urgent, illegal, business critical. It can be useful to use an Eisenhower Matrix to identify biggest impact, least effort choices. Do not try to fix everything at once.