Skip to content
Getting Digital

Data, Analytics and AI

Data governance, quality and privacy

Governance is the part of data work that decides who owns a number, what it means and whether it may be used at all. Here sit the centre of the DMBOK wheel and several of its spokes: stewardship, definitions and metadata, reference and master data, quality rules and lawful use, and why organisations usually discover they need all of it only after two official figures refuse to match.

Why this topic exists: Ownership, definitions, metadata, master data, quality rules and lawful use are DMBOK's centre and half its wheel; nobody hires for them until the numbers disagree.

Governance work begins with an awkward question: when the finance report and the sales dashboard give different revenue figures, whose number is right, and who has the authority to say so? The DAMA body of knowledge, DMBOK, answers by placing governance at the centre of its wheel of eleven knowledge areas, surrounded by the disciplines that carry it out. Governance itself decides who decides: which policies exist, how they are enforced and where accountability for each dataset sits. The other areas do the work those decisions call for.

SFIA 9 folds that territory into a single skill, data management, whose guidance runs from quality and compliance policy through metadata and retention to stewardship. Microsoft's DP-900 touches it only at the edge, asking candidates to tell apart what database administrators, data engineers and data analysts are each responsible for. That is itself a governance question: who may change what.

The spokes that carry governance

  • Ownership and stewardship. An owner is accountable for a dataset; a steward looks after its definitions and fixes from day to day; a custodian, usually in IT, runs the systems it lives in. Naming all three for each critical dataset is most of an initial programme.
  • Metadata. Lineage and context: where a field came from, what transformed it on the way, what it means. A business glossary is the reader-facing part; lineage is the part auditors ask to see.
  • Reference and master data. One agreed list of countries, currencies and product codes, and one golden record per customer or supplier, so that every system joins on the same keys.
  • Data quality. Rules that test fitness for use: completeness, validity, uniqueness, timeliness. Tests in dbt and checks inside pipelines are where many teams now write these rules as code, which ties quality closely to data engineering.
  • Security and privacy. DMBOK's security area covers classification, access and protection, encryption included. Privacy adds a question security never asks: even if the data is safe, is this particular use of it lawful and expected by the people it describes?

Controls, audit and the beginner's error

Governance is risk assessment applied to information: which data could hurt the organisation if it were wrong, leaked or misused, and which control reduces that exposure. The framing explains why auditors take an interest. ISACA's CISA examines the audit of information systems and their controls, and a governance lead who can speak to an auditor in control language tends to get budgets approved. The beginner's error runs the other way round: buying a catalogue tool before anyone owns anything. A catalogue without stewards fills up with automatically harvested tables, nobody writes definitions, and it soon becomes one more system people ignore. Start with a handful of disputed metrics, give each an owner and a written definition, and add tooling once people begin asking where the definitions live.

Where it leads

Governance roles are often second careers. Analysts who kept reconciling numbers become stewards, engineers who built the quality checks become platform owners, and people from audit and compliance move across. The AI side of the same concern, accountability for models and their training data, sits under responsible AI, and security controls in depth under governance, risk and compliance. The data and AI hub shows the neighbouring topics.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Tools of the trade

  • dbt

    Its tests and docs are where quality rules live in code.

Frequently asked

Is data governance an IT job or a business job?
Both, which is why it so often stalls. Definitions and ownership belong to the business units that produce and use the data; IT runs the systems and applies the technical controls. Programmes housed only in IT produce policies nobody outside IT reads, and programmes housed only in the business produce definitions nobody enforces.
What does a data steward actually do all week?
Answers questions about what fields mean, approves changes to definitions, triages quality problems reported by analysts and chases source teams to fix them at the root. It is closer to editorial work than to engineering, and it is frequently one part of another job rather than a full-time post.
Should I read DMBOK from cover to cover?
Rarely. It works as a reference: most readers take the governance chapter plus the one or two areas their job touches, such as quality or master data. Use it as a map for spotting what your organisation is missing, not as a sequence to implement in order.

Courses in the directory

45 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital