Data Governance Framework
Phase 1: Governance Structure
- Define governance organization
- Data governance council (executive sponsors)
- Data domain owners (business leaders per domain)
- Data stewards (operational responsibility per domain)
- Data engineers (technical implementation)
- Data protection officer (privacy and compliance)
- Define decision rights and escalation paths
- Establish governance meeting cadence
- Create governance charter and mandate
RACI Matrix
| Activity | Council | Domain Owner | Data Steward | Data Engineer | DPO |
|---|---|---|---|---|---|
| Policy creation | A | R | C | I | C |
| Data classification | I | A | R | C | C |
| Quality standards | I | A | R | C | I |
| Access approval | I | A | R | I | C |
| Compliance monitoring | A | I | R | C | R |
| Issue resolution | A | R | C | C | C |
Phase 2: Data Classification & Inventory
- Define data classification levels
- Public - no restrictions
- Internal - organization-wide access
- Confidential - role-based access
- Restricted - strict access controls (PII, PHI, financial)
- Inventory and classify data assets
- Document data lineage (source to consumption)
- Map data to regulatory requirements
Data Asset Inventory
| Domain | Dataset | Classification | Owner | Steward | Regulatory | Quality Score |
|---|---|---|---|---|---|---|
| Public/Internal/Confidential/Restricted | GDPR/CCPA/HIPAA/None | /100 |
Phase 3: Data Quality Standards
- Define data quality dimensions
- Completeness - required fields populated
- Accuracy - values reflect reality
- Consistency - same data matches across systems
- Timeliness - data available when needed
- Uniqueness - no unintended duplicates
- Validity - values conform to expected formats
- Set quality thresholds per domain
- Implement automated quality monitoring
- Define data quality incident process
Quality Thresholds
| Domain | Completeness | Accuracy | Consistency | Timeliness | Overall Target |
|---|---|---|---|---|---|
| Customer | > % | > % | > % | < hrs | > % |
| Product | > % | > % | > % | < hrs | > % |
| Financial | > % | > % | > % | < hrs | > % |
Phase 4: Access & Security Policies
- Define data access policies
- Role-based access control (RBAC) for data assets
- Data access request and approval workflow
- Sensitive data masking and anonymization rules
- Data sharing agreements for external parties
- Data retention and deletion schedules
- Audit logging for data access
- Implement technical controls for data protection
- Define breach notification procedures
Phase 5: Data Lifecycle Management
- Define lifecycle stages
- Creation / ingestion standards
- Storage and retention policies
- Usage and sharing guidelines
- Archival procedures
- Deletion and destruction procedures
- Implement automated lifecycle enforcement
- Document data retention schedule per regulation
Phase 6: Monitoring & Continuous Improvement
- Establish governance metrics
- Data quality scores by domain (monthly)
- Policy compliance rate
- Access review completion rate
- Data incident count and resolution time
- Governance adoption rate across teams
- Conduct quarterly governance reviews
- Update policies based on regulatory changes
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
- Governance Charter: Roles, responsibilities, and decision rights
- Data Classification Guide: Levels with handling requirements
- Quality Standards: Thresholds and monitoring procedures
- Access Policy: RBAC model and approval workflows
- Lifecycle Policy: Retention schedules and procedures
Action Items
- Establish data governance council with executive sponsorship
- Appoint domain owners and data stewards
- Classify and inventory all critical data assets
- Define and implement data quality standards
- Publish data access and retention policies
- Set up governance metrics dashboard
- Schedule quarterly governance review meetings