How data ownership, policies, access controls, and compliance are defined, enforced, and monitored across the organisation's data assets.
GOV-01
Enterprise data governance operating model
How well-defined and formally established is the organisation's data governance operating model — its structure, charter, and program framework — at the enterprise level?
Maturity level descriptions
No data governance operating model exists; governance activity, where it occurs, happens informally and inconsistently across the organisation. There is no defined governance structure, charter, or framework; any governance-related activity happens ad hoc, driven by individual initiative.
Elements of a governance model exist in parts of the organisation, but there is no enterprise-wide structure or endorsed charter. Individual business units may have informal governance practices, but there is no consolidated, organisation-wide operating model.
A data governance operating model — structure, charter, and program framework — is documented and formally endorsed at the enterprise level. A governance charter defines the operating model's structure, scope, and authority, endorsed through a recognised organisational process.
The governance operating model is reviewed and matured on a defined cycle, with its effectiveness measured and reported to the executive team or board. The operating model is reviewed at least annually, with effectiveness measures (e.g. issue resolution time, policy compliance rate) reported to senior stakeholders.
The governance operating model is treated as a mature, board-level capability, benchmarked externally, and continuously refined as organisational and regulatory context evolves. The model is benchmarked against external standards or peer organisations, with continuous refinement driven by both internal performance data and external regulatory or industry change.
GOV-02
Executive-level data ownership and stewardship accountability framework
How comprehensively are data ownership and stewardship roles (Data Owners, Data Stewards, Data Custodians) established, assigned, and held accountable across the organisation?
Maturity level descriptions
No formal data ownership or stewardship roles exist anywhere in the organisation; accountability for data defaults to whoever happens to be closest to it. Data-related accountability is undefined organisation-wide; issues are handled informally by whoever notices them, with no assigned ownership.
Ownership and stewardship roles exist informally in some parts of the organisation, but are not formally defined, documented, or consistent. Some business units informally recognise data owners or stewards, but role definitions and expectations vary and are not documented centrally.
A formal data ownership and stewardship framework is defined and applied to priority data domains, with documented role responsibilities. Data Owners and Data Stewards are formally named for priority domains, with documented responsibilities available centrally.
The ownership and stewardship framework covers all material data domains, with accountability formally reviewed and enforced on a defined cycle. Coverage extends across all material data domains organisation-wide, with a scheduled review confirming assignments remain current and accountable individuals are performing their role.
Ownership and stewardship accountability is dynamically maintained and enterprise-visible, with performance against stewardship responsibilities factored into individual or team performance management. Ownership records update automatically as data domains change, and stewardship performance is a visible, tracked input to broader performance management processes.
GOV-03
Enterprise policy compliance and risk oversight
How confident can the executive team or board be that data governance policies are actually being complied with across the organisation, based on objective evidence rather than assumption?
Maturity level descriptions
No mechanism exists to assess policy compliance across the organisation; compliance status is unknown until an external trigger (audit, incident) forces a look. Policy compliance is assumed rather than assessed, with no visibility into actual practice until a problem surfaces externally.
Compliance is checked only occasionally, typically ahead of a known audit, rather than as ongoing practice. Compliance evidence is assembled reactively shortly before a known audit or review, rather than maintained continuously.
A defined compliance reporting process exists, with business units reporting compliance status on a regular cycle to a central governance function. Business units provide scheduled compliance reports to a central governance or risk function, using a consistent format.
Compliance is measured using defined enterprise metrics and thresholds, tracked over time, with the executive team or board reviewing trends and exceptions. Enterprise-wide compliance metrics are tracked period-over-period, with trends and exceptions formally reviewed by the executive team or board.
Compliance monitoring is continuous and substantially automated, with real-time visibility for the executive team and predictive identification of emerging compliance risk before it materialises. Automated monitoring provides real-time compliance visibility, with predictive indicators flagging emerging risk areas before they result in a breach.
GOV-04
Escalation and issue governance at executive level
How reliably do significant data governance issues (breaches, high-impact quality failures, unresolved disputes) actually reach the Chief Data Officer or executive team, with clear decision rights for resolution?
Maturity level descriptions
No escalation path to executive level exists for data governance issues; significant issues may never reach the CDO or executive team at all. Issues are handled and potentially closed at operational level regardless of severity, with no defined trigger for executive escalation.
An informal escalation path exists, but it is inconsistently used and depends on individual judgement about what counts as significant enough to escalate. Issues are escalated to senior levels occasionally, based on individual judgement, without clear, consistent escalation criteria.
A defined escalation framework exists, specifying severity thresholds and the point at which an issue must reach the CDO or executive team, with decision rights documented. A documented framework defines severity thresholds and named decision rights, and is generally followed for significant issues.
Escalated issues are tracked to resolution with defined response-time expectations, and patterns across escalations are reviewed to identify systemic governance gaps. Escalated issues are logged and tracked to resolution against response-time expectations, with periodic review of escalation patterns for systemic causes.
Escalation is supported by proactive, automated risk detection that surfaces likely significant issues to the executive team before they are formally reported, with escalation effectiveness itself reviewed and improved over time. Automated monitoring proactively flags likely significant issues for executive attention, and the escalation framework itself is periodically assessed and refined for effectiveness.