You inherit an enterprise data estate with no governance at all and a two-year mandate. What do you do first?
Show the full answer Hide the answer
What not to start with
A taxonomy, a policy set and a committee. These produce artefacts, take months, and change nothing observable — which spends the programme's credibility before it delivers anything. The most common way governance programmes fail is by being correct and invisible for a year.
The sequence that works
- Find out what exists. Automated discovery of datasets, systems, access and usage. Almost every estate surprises its owners here, and the inventory is the input to every subsequent decision.
- Find the sensitive data. Automated scanning for regulated categories. This is where the actual risk is, and it is usually distributed far more widely than anyone believes.
- Fix access on the highest-risk data. Remove standing broad access, add logging. Concrete, defensible, and it produces an early demonstrable outcome.
- Establish ownership for the datasets that matter, not for all of them. Ownership is the prerequisite for everything else and cannot be assigned by decree at scale.
- Instrument quality on the datasets feeding decisions, so failures are detected rather than reported.
- Then taxonomy, glossary and semantic layer, informed by what the first five steps revealed.
The principle underneath
Sequence by risk and by demonstrable outcome, not by the logical order of a governance framework. The framework's order is pedagogically sensible and organisationally fatal, because it front-loads the work with the lowest visible return.
The measure to commit to
Not "policies published" or "datasets catalogued" — the proportion of sensitive data with known ownership and enforced access, trended monthly. It is unambiguous, it is hard to game, and it maps directly to the risk the programme exists to reduce.