Data Governance
Data Governance existed long before ML and GenAI. People at Nastavia were working with it worldwide for central and commercial banks' prudential and financial reporting from the early 2000s. Recently, AI has pushed Data Governance back onto executive agendas with unusual force. Wrong data has translated into too many misleading and damaging decisions, and understanding its value has moved from primarily “data people” to the C-suite. The bigger surprise was that some of this “wrong data” appeared to be perfectly validated, transformed and stored, yet remained contextually inadequate for the intended decisions or use cases.
Then it became obvious that structure and technical correctness are necessary, but only meaningful within the right context. And context is what allows machine-learning models and LLM-based systems to support the best available decisions. But context does not automatically emerge from training data, source documents, or retrieved information unless it is deliberately curated and governed. Technically valid data can still be misunderstood, inconsistently interpreted, or combined incorrectly if the organization has not established a common semantic foundation. And when speaking about semantics, there are Ontologies, describing the meaning of business entities and the relationships between them; Taxonomies, organizing concepts into consistent classifications and hierarchies; and Business Glossaries and controlled vocabularies, defining authoritative terminology. Contextual governance establishes what a value means, which concept it represents, and how it relates to the rest of the organization's information landscape.
This is also why the growing language around “AI-ready” or “AI-enabled Data Governance” deserves some caution. Artificial intelligence can certainly strengthen governance through automated classification, metadata enrichment, anomaly detection, lineage discovery, entity resolution, and policy monitoring. But sound Data Governance is already AI-enabling by design. If an organization has reliable data pipelines, controlled data quality, transparent lineage, accountable ownership, governed metadata and, critically, proper context management, it has established much of the foundation that AI requires. If those capabilities are weak, adding an AI label does not make the underlying data environment more governable.
Why a broader assessment is needed
Data Governance scope continuously expands. The professional landscape, however, remains fragmented. Established standards and frameworks provide strong guidance in individual areas such as data management, metadata, architecture, privacy, risk, regulatory reporting, security, model governance, and organizational control. Each is valuable. Yet no single widely adopted Data Governance framework provides sufficiently comprehensive coverage of the operational, semantic, organizational, technological, risk, regulatory, and analytical dimensions that modern Data Governance increasingly requires.
Nastavia developed the Data Governance Assessment Standard, DGAS, in response to that gap. DGAS is an attempt to bring together the guidance from relevant international standards, established professional practice, Nastavia's experience from complex digital and data transformation environments, and insights from ongoing scientific research into governance, information semantics, organizational decision-making, and human-AI systems.
The objective is not to replace existing standards. It is to provide a coherent assessment structure that can use them together, where each is strongest, and convert that body of knowledge into an assessment that is practical, evidence-based, and actionable for a real organization.
What DGAS is intended to answer
A useful Data Governance assessment should do more than confirm whether policies, roles, tools, or committees exist. It should show whether the organization has a functioning governance capability and whether its different parts work together.
DGAS is therefore designed to help answer three practical questions:
1. Where is the organization now?
2. Which governance capabilities most constrain reliable use of data?
3. Which improvements should be prioritized next?
This makes the assessment a starting point for transformation rather than an end in itself. A maturity score can be useful, but only when it leads to a defensible understanding of gaps, dependencies, risks, and improvement priorities.
What falls within the scope of DGAS
DGAS remains explicitly a Data Governance framework. Adjacent disciplines are considered only where they directly govern the lifecycle, meaning, control, accountability, protection, or use of data.
- Business processes are assessed where they create, modify, transfer, consume, or depend on data.
- Information systems and architecture are assessed where they store, transform, expose, integrate, or control data.
- Security and privacy are assessed where they define how data must be classified, accessed, protected, retained, shared, or erased.
- Artificial intelligence and machine learning are assessed where governed data is used to train, validate, inform, or operate analytical and generative models.
- Organizational structures are assessed where they establish accountability, stewardship, decision rights, escalation, or governance behavior around data.
How the DGAS assessment is structured
DGAS uses a hierarchical assessment model. The full standard extends to detailed assessment areas and Assessment Questions, but the top of the framework is intentionally simple: four Level 1 Pillars and fifteen Level 2 Sections.
The Level 1 Pillars define the major dimensions of Data Governance capability. Level 2 Sections break each Pillar into coherent groups of related capabilities. These two levels provide the high-level map of the assessment and are intended to remain stable even as more detailed assessment criteria evolve.
Pillar 1. Operational Governance & Data Product Foundations
This Pillar evaluates whether governance is embedded into the operational and technical lifecycle of data. It focuses on the environment in which data is created, validated, moved, transformed, monitored, retained, and ultimately retired. The central question is whether the organization can maintain reliable and governable data flows at operational scale.
1.1 Data Quality Management & Shift-Left Assurance
Examines how the organization defines, measures, prevents, detects, and remediates data quality issues. Particular attention is given to preventing defects as close as practical to the point of data creation or ingestion, rather than relying mainly on downstream correction.
1.2 Technical Metadata, Data Lineage & Supply Chain
Evaluates whether the organization understands the technical structure and movement of its data. It considers metadata, lineage, reconciliation, impact analysis, and the integration of data considerations into system and software change processes.
1.3 Data Lifecycle Management, Layered Architecture & Value Streams
Examines governance across the data lifecycle, including processing layers, storage, retention, archival, deprecation, and secure disposal. It also considers data flow within business value streams, where information bottlenecks often become process bottlenecks.
Pillar 2. Contextual, Semantic & Data Product Governance
Reliable data is not automatically meaningful data. This Pillar addresses the structures through which an organization establishes what its data means, how concepts relate to one another, which sources are authoritative, and how governed data is packaged for reuse. It is the semantic and contextual layer that allows the same data to be understood consistently by people, systems, analytics, and AI.
2.1 Business Metadata, Glossary & Data Marketplace Management
Evaluates how business meaning is defined, approved, discovered, and connected to actual data assets. It includes Critical Data Elements, business glossaries, shared definitions, terminology conflicts, discoverability, and Data Point Modeling.
2.2 Corporate Data Spaces, Ontologies & Data Product Taxonomy
Examines how information is organized into meaningful enterprise domains and structures. It considers corporate data spaces, taxonomies, semantic relationships, ontologies, reference data, and the classification of managed data products.
2.3 Entity Resolution & Master Data Management
Evaluates whether the organization can identify and govern the same real-world entities consistently across multiple systems. It considers deduplication, golden records, authoritative sources, trust logic, matching rules, and synchronization.
2.4 Contextual Governance for AI, Machine Learning & Generative AI
Evaluates the governance of data used in analytical and AI systems, including suitability, provenance, features, model oversight, fairness, drift, and the controlled use of data in generative AI. The focus remains on the data and context required for trustworthy use of these technologies.
Pillar 3. Organizational, Policy & Dual Governance Operating Model
Data Governance is ultimately an organizational capability. Tools can support governance, but they cannot assign accountability, resolve competing interests, or establish decision authority. This Pillar examines how governance is exercised through roles, structures, policies, operating procedures, and organizational behavior.
3.1 Governance Structures, Business Architecture & Dual Operating Model
Evaluates executive sponsorship, governance authority, decision structures, and the relationship between data, processes, and information systems. It also considers how organizations balance defensive governance, focused on control and risk, with offensive governance, focused on enabling trusted use and business value.
3.2 Cross-Functional Roles, Creator Principle & Product-Oriented Governance
Examines how governance responsibilities are distributed across business and technical roles. It considers Data Owners, Stewards, Custodians, domain executives, responsibility at the point of data creation, and data accountability within product and customer-journey teams.
3.3 Policies, Standards, Operating Procedures & Accountability
Evaluates whether governance expectations are translated from policy into operational practice. It considers the hierarchy of policies and standards, repeatable procedures, responsibility models, compliance monitoring, and escalation mechanisms.
3.4 Culture, Change Management & Data Literacy
Examines whether governance has become part of normal organizational behavior. It considers data literacy, role-based competency, change management, communication, training, and communities of practice that sustain governance beyond formal projects.
Pillar 4. Regulatory, Compliance & Risk Governance
This Pillar examines how Data Governance supports external obligations, internal risk management, and the protection of information. In regulated environments, organizations must increasingly demonstrate not only that information is correct, but how it was produced, controlled, protected, and evidenced.
4.1 Regulatory Frameworks & Compliance Alignment
Evaluates how regulatory and supervisory obligations are translated into concrete data requirements, controls, responsibilities, lineage, evidence, and reporting practices. It also considers privacy, systems of record, jurisdictional constraints, and data sovereignty where relevant.
4.2 Data Risk, Baseline Assessment & Value Realization
Examines enterprise data risk, governance maturity baselines, value contribution, and the economic rationale for preventative controls. It connects governance activity to measurable risk reduction, operational improvement, and better use of data.
4.3 Data Security, Access Governance & Privacy by Design
Evaluates how information protection requirements are applied to data through classification, authorization, fine-grained access control, encryption, consent, minimization, and privacy-by-design practices.
4.4 Legal Discovery, Audit Readiness & Breach Management
Examines the organization's ability to identify, preserve, retrieve, explain, and evidence governed data under legal, regulatory, audit, or incident-response conditions.
A practical framework for a changing discipline
Data Governance will continue to evolve as organizations adopt new architectures, regulatory models, analytical methods, and forms of artificial intelligence. A useful assessment standard therefore cannot be tied to one technology stack, one organizational model, or one implementation pattern.
DGAS is being developed as a structured but adaptable framework. Its purpose is to provide a stable view of the capabilities that matter while allowing detailed assessment criteria to evolve as professional practice, regulation, technology, and research develop.
For Nastavia, the value of the standard lies in this combination: broad enough to reflect the real scope of modern Data Governance, disciplined enough to remain within that scope, and practical enough to guide concrete improvement.