All white papers

From Policy to Practice: A Roadmap for Data Governance Implementation

Most organisations do not lack a governance framework. They lack a governance practice. The gap between the two is where the majority of programmes stall — and it is not closed by writing more policy.

The Policy–Practice Gap

A pattern we encounter repeatedly: an organisation has a data governance policy approved by an executive committee, a council that meets quarterly, a catalog with tens of thousands of assets, and a business that still works from spreadsheets, email threads and tribal knowledge.

Nothing in that picture is a failure of intent. The policy is sound. The council is staffed by capable people. The catalog was expensive and works as advertised. What is missing is the connective tissue between the framework and the daily work of the people it is meant to govern.

The diagnosis is almost always the same: governance was implemented for the business rather than with it. Policies were written by a central team, published, and communicated. Adoption was assumed to follow from mandate. It never does.

The measure that matters

Governance is not measured by the number of policies published or workflows deployed. It is measured by whether people incorporate it into their daily work without being asked.

Three Preconditions Before Phase One

Before any roadmap is worth drawing, three things need to be true. Programmes that skip these do not fail immediately — they fail at month nine, when the initial mandate expires.

A sponsor who owns an outcome, not a function

A sponsor from a governance or risk function can authorise a programme. A sponsor who owns a business outcome — a regulatory commitment, a margin target, an AI initiative that has stalled — can sustain one. The difference shows up when the programme needs someone else’s people to do work.

A problem statement in business language

“Improve data governance maturity” is not a problem statement. “Finance and Operations report different revenue figures to the board and it takes two weeks to reconcile” is. The second one tells you which domain to start in, which definitions to fix and how you will know when you are done.

Honest acknowledgement of what did not work last time

Most organisations attempting governance are attempting it again. The people you need remember the previous attempt. Naming what failed — the tool nobody used, the council that stopped meeting, the stewardship roles assigned to people with no time — buys more credibility than any amount of new framing.

Phase 1 — Assess (Weeks 1–6)

The purpose of assessment is not a maturity score. It is to find the two or three places where accountability is genuinely missing rather than merely undocumented, and to establish a baseline you can be measured against later.

What to produce:

  • A current-state map across people, process, policy and platform — deliberately in that order, because the platform is usually the least of the problems.
  • A domain heat map: which business domains have the most pain, the most regulatory exposure, and the most willing owners. The intersection is where you start.
  • A short list of “canary” issues — specific, nameable data problems that senior people already care about. These become your proof points.
  • A baseline of three to five metrics you will report on quarterly.

What to avoid: a 200-page assessment deck. We have never seen one read past page twelve. The output should be short enough that the sponsor can present it themselves.

Phase 2 — Prioritise (Weeks 5–10)

This phase determines whether the programme earns a mandate or spends one.

The sequencing principle is straightforward and frequently ignored: the business should feel benefit before the programme asks anything of them. If your first interaction with a domain team is a request to fill in metadata for 400 assets, you have spent your credibility before establishing any.

Invert it. Start with something that solves a problem they already have — a reconciled definition, a data set they could never find, an access request that used to take three weeks and now takes two days. Then ask for stewardship.

Sequence this earlyDefer this
Definitions for the metrics that appear in board reporting Comprehensive glossary coverage
Lineage for the reports people already distrust Lineage across the whole estate
Ownership for assets involved in a known incident Ownership for every asset in the catalog
Quality rules on the three fields that caused last quarter’s problem A quality framework covering all critical data elements
Access workflow for the most-requested data sets Automating every request type

The right-hand column is not wrong. It is what you do in year two, funded by the credibility earned in the left-hand column.

Phase 3 — Implement (Months 3–9)

Implementation is where most of the visible work happens and where the least of the risk actually sits, provided the first two phases were done honestly.

Operating model before platform configuration

Configure the platform to reflect a decided operating model, not the other way round. Teams that begin in the tool end up with an asset model that mirrors the vendor’s demo rather than their own decision rights.

Decide, in writing and with names attached:

  • Who is accountable for each domain’s data
  • Who maintains quality, and with what time allocation
  • Who approves changes to a business definition
  • Who authorises access, and on what basis
  • Who reports on health, to whom, how often

That last question is the one most often skipped and the one that determines whether governance survives a reorganisation.

Automate the tedious, not the judgemental

Metadata harvesting, lineage capture, classification suggestions, quality profiling and access provisioning should all be automated. Definition approval, risk acceptance and exception handling should not be. Programmes that automate judgement produce a system that is fast and wrong.

Instrument adoption from day one

Track catalog searches, unique active users, definition lookups, access requests routed through the workflow, and issues raised and closed. These tell you whether governance is being used. Asset counts tell you only that a crawler ran.

Phase 4 — Embed (Month 6 onwards, permanently)

Embedding overlaps implementation deliberately. A programme that treats enablement as a closing activity has already lost the audience.

Data literacy, targeted by role

Generic data literacy training has poor returns. Role-based training has good ones. A steward needs to know how to resolve a quality issue and escalate a definitional dispute. A business analyst needs to know how to find trusted data and interpret a lineage diagram. An executive needs to know what to ask when two reports disagree. Those are three different curricula.

A champion network that is named and resourced

One person per domain, allocated real time, with a direct line to the programme. Their job is not to enforce policy but to translate it and to bring problems back. A champion network with no time allocation is an org chart, not a network.

Make the governed path the easy path

This is the single highest-leverage principle in the entire roadmap. If finding data through the catalog is slower than asking a colleague, people will ask the colleague. If requesting access through the workflow takes longer than emailing a DBA, they will email the DBA. Governance succeeds when it is the path of least resistance, and no amount of policy compensates when it is not.

Reinforcement, not campaigns

Adoption does not respond to launch events. It responds to consistent, small reinforcement: quality scores visible in the tools people already use, definitions surfaced where reports are consumed, ownership shown next to every asset.

What to Report, and to Whom

Governance programmes are frequently defunded not because they failed but because they could not evidence success. A compact quarterly report, consistently delivered, is worth more than an annual maturity assessment.

AudienceWhat they needCadence
Executive sponsor / board Risk reduced, decisions accelerated, regulatory position, cost avoided Quarterly, one page
Domain owners Their domain’s quality scores, open issues, stewardship coverage Monthly, self-service dashboard
Stewards Their queue: issues, approvals, assets lacking definitions Continuous, in their working tool
Programme team Adoption telemetry, coverage, throughput, blockers Weekly

Five Signs It Is Working

  1. Business users discover and understand trusted data without asking the central team.
  2. Ownership is clear, with accountable stewards across every domain that matters.
  3. Quality issues are identified, prioritised and resolved through a defined process rather than escalation.
  4. Lineage gives transparency from source to consumption, raising confidence in reporting and in AI.
  5. Governance supports innovation by reducing risk rather than creating friction — teams come to it rather than route around it.

None of those are measured in assets catalogued. All of them are measured in behaviour.

Good governance does not slow the business down. It gives the business the confidence to move faster.

Published by KRISID · 19 February 2026. This paper reflects our delivery experience and publicly available sources at the time of writing. It is general guidance, not legal advice — regulatory obligations vary by jurisdiction and by how a system is used.

Is Your Programme Stuck Between Policy and Practice?

We run short maturity assessments that identify where accountability is genuinely missing — and produce a sequenced roadmap your sponsor can defend.

Email contact@krisid.com