Data Governance and Data Quality
In the Certified in the Governance of Enterprise IT (CGEIT) framework, data governance is the system of decision rights, accountabilities, policies and controls that makes sure enterprise data is managed as a strategic asset. It belongs to IT governance and supports CGEIT's core aims: realizing ben… In the Certified in the Governance of Enterprise IT (CGEIT) framework, data governance is the system of decision rights, accountabilities, policies and controls that makes sure enterprise data is managed as a strategic asset. It belongs to IT governance and supports CGEIT's core aims: realizing benefits, optimizing risk and optimizing resources. Data governance is driven by the board and executive management, who set direction and monitor performance. It differs from data management, which covers the daily operational execution of those directions. ISACA's COBIT 2019 framework supports this through management objectives such as APO14 (Managed Data), along with BAI08 (Managed Knowledge) and DSS06 (Managed Business Process Controls). Key elements of data governance include: - Clear data ownership and stewardship roles (data owners, data stewards and data custodians) - Data classification and life cycle policies - Metadata and master data management - Privacy and regulatory compliance, such as GDPR - Alignment of data initiatives with business strategy A governance body, such as a data governance council, typically sets standards, resolves conflicts and reports to the IT steering committee or board. Data quality measures how fit data is for its intended use. COBIT describes information quality in three groups of criteria: - Intrinsic: accuracy, objectivity, believability and reputation - Contextual: relevance, completeness, timeliness and appropriate amount - Security and accessibility: availability and restricted access Common operational dimensions also include consistency, validity and uniqueness. Poor data quality weakens decision-making, increases operational and compliance risk, and erodes the value delivered by IT investments. For CGEIT professionals, the priority is to embed data quality into governance through several practices: - Defining quality metrics and thresholds linked to business goals - Assigning accountability for quality to business data owners rather than to IT alone - Using data profiling, cleansing and continuous monitoring - Reporting quality KPIs to executives Effective data governance and data quality together build trust in information, enable analytics and digital transformation, support regulatory compliance, and ensure that data contributes measurable value to enterprise objectives.
Data Governance and Data Quality (CGEIT – Governance of Enterprise IT)
Introduction
Data Governance and Data Quality sit inside the CGEIT domain Governance of Enterprise IT. ISACA treats data and information as enterprise assets that must be governed like any other asset. The board and executive management set direction for them, and management delivers on that direction. For the exam, you need to know why data governance matters, what it is made of, how it operates, and how to choose the best answer from a governance (not technical) point of view.
1. Why Data Governance and Data Quality Are Important
Data drives value. Strategic decisions, analytics, AI, customer experience and digital transformation all depend on reliable data. Poor data destroys value through wrong decisions, rework, lost revenue and reputational damage.
Regulatory and legal compliance. Many regulations and standards require organizations to know what data they hold, where it is, who owns it, how long they keep it and how they protect it. Examples include GDPR, CCPA, HIPAA, SOX, Basel/BCBS 239 and PCI DSS.
Risk optimization. Data quality failures and data breaches are enterprise risks. Governance makes sure data risk is identified, owned and kept within risk appetite.
Resource optimization. Redundant, obsolete and trivial (ROT) data increases storage, integration and security costs. Governance rationalizes the data landscape.
Benefits realization. Investments in ERP, BI, cloud and AI deliver expected benefits only when the underlying data is fit for purpose.
Trust and accountability. Clear ownership removes the common problem of "IT owns the data". Accountability belongs to the business.
These points map directly to the three governance objectives in COBIT: benefits realization, risk optimization and resource optimization.
2. What Data Governance and Data Quality Are
Data governance is the exercise of authority, control and shared decision making over data assets. It covers:
- planning
- monitoring
- enforcement
Data management is the execution side: the processes, technologies and activities that implement governance decisions. Examples include data architecture, integration, storage, security, metadata, master data and quality operations. Remember the classic COBIT distinction: governance evaluates, directs and monitors (EDM), while management plans, builds, runs and monitors (PBRM).
Data quality is the degree to which data is fit for its intended use. The common dimensions are:
- Accuracy: data correctly reflects reality.
- Completeness: all required data is present.
- Consistency: data agrees across systems and records.
- Timeliness / Currency: data is available when needed and is up to date.
- Validity / Conformity: data follows defined formats, rules and domains.
- Uniqueness: no unintended duplicates.
- Integrity: relationships and referential rules are maintained.
- Accessibility and Security: authorized users can get the data, and unauthorized users cannot.
- Relevance / Usability: data meets the needs of its consumers.
3. Key Components of a Data Governance Framework
Strategy and principles. A data strategy aligned to business strategy. Example principles: data is an asset, data has an owner, data quality is everyone's responsibility.
Policies and standards. These cover classification, ownership, quality, retention, privacy, access, sharing, metadata and archiving or disposal.
Organizational structures and roles:
- Board / Executive committee: sets direction, approves data strategy and risk appetite, and monitors outcomes.
- Data Governance Council / Steering Committee: cross-functional business-led body that prioritizes, resolves issues and approves standards.
- Chief Data Officer (CDO): executive accountable for the data strategy and governance program.
- Data Owner: a senior business manager accountable for a data domain. Decides on classification, access, quality requirements and acceptable use. Ownership belongs to the business, NOT IT.
- Data Steward: business subject matter expert who handles day-to-day definitions, quality rules, issue resolution and metadata.
- Data Custodian: usually IT. Implements and operates controls such as storage, backup, security and technical access as the owner directs.
- Data Users / Consumers: use data in line with policy.
- Privacy / Security / Risk functions and Internal Audit: provide oversight and independent assurance.
Processes:
- data classification
- data lifecycle management (create/acquire, store, use, share, archive, destroy)
- metadata and data dictionary management
- master and reference data management (MDM)
- data quality management (profiling, cleansing, monitoring, root cause analysis)
- issue and change management
- data lineage
Metrics and monitoring. Data quality scorecards, KPIs (such as % records passing validation, duplicate rate, timeliness of reports) and KRIs (such as number of data incidents or privacy breaches).
Enablers. Culture, ethics and behavior; skills and competencies; tools such as data catalogs, quality tools and MDM platforms; and enterprise architecture (information architecture).
4. How It Works – The Operating Model
Step 1 – Establish direction (Evaluate/Direct). The board and executives evaluate how much the business depends on data. They define the data vision and principles, set risk appetite for data, and approve the governance charter and funding.
Step 2 – Define accountability. Appoint a CDO or equivalent and form a data governance council. Assign data owners per domain, such as customer, product, finance and HR. Appoint stewards and define custodian responsibilities, using a RACI matrix.
Step 3 – Inventory and classify. Identify critical data elements (CDEs). Build a data catalog and dictionary. Classify data by sensitivity and criticality, and map data flows and lineage.
Step 4 – Set policies, standards and quality requirements. Owners define quality thresholds based on business needs. Standards cover naming, formats, retention and access.
Step 5 – Implement controls (Management).
- input validation and edit checks
- MDM to create a single source of truth
- access controls
- reconciliation
- data quality firewalls in integration pipelines
- privacy-by-design
Step 6 – Measure and monitor. Profile data, track quality scorecards, report KPIs and KRIs to the council and board, and perform root cause analysis on defects. Fix the process, not just the data.
Step 7 – Assure and improve. Use internal audit, maturity assessments (for example COBIT capability levels or the DAMA-DMBOK maturity models) and continual improvement.
Relevant frameworks and references
- COBIT 2019 objectives. EDM01 (Ensure governance framework setting and maintenance), EDM03 (Risk optimization), APO01 (Managed I&T management framework, including data-related policies), APO03 (Enterprise architecture), APO11 (Quality), APO14 (Managed Data), APO13 (Security), BAI08 (Knowledge), DSS05 (Security services), DSS06 (Business process controls) and MEA03 (Compliance).
- DAMA-DMBOK. Data governance sits at the center of the knowledge-area wheel, surrounded by architecture, modeling, storage, security, integration, document management, master and reference data, warehousing and BI, metadata and data quality.
- Standards. ISO 8000 (data quality) and ISO/IEC 38505 (governance of data).
5. Common Challenges and Root Causes
- No clear data ownership; IT is assumed to own the data.
- Silos and inconsistent definitions across business units.
- Governance seen as an IT project rather than a business program.
- Lack of executive sponsorship or funding.
- Fixing symptoms through repeated cleansing instead of root causes.
- No metrics, so value cannot be demonstrated.
- Shadow IT and uncontrolled spreadsheets or cloud data stores.
6. Exam Tips: Answering Questions on Data Governance and Data Quality
Tip 1 – Think like a governance professional, not a technician. CGEIT rewards answers about direction, accountability, alignment with strategy and oversight. Prefer "establish a data governance framework / policy / ownership" over "install a data quality tool" or "run a cleansing script".
Tip 2 – Business owns data; IT is the custodian. If a question asks who is accountable for data quality, classification or access approval, the answer is almost always the data owner (business), not the DBA, CIO or security administrator. The custodian implements; the owner decides.
Tip 3 – The FIRST step is usually understanding and alignment. For "What should be done FIRST?", good answers are:
- identify business requirements and strategy
- perform an inventory or classification
- assign ownership
- obtain executive sponsorship
- assess current state or maturity
Tip 4 – Look for root cause, not symptom. If recurring data errors appear, the BEST response addresses the root cause, such as unclear definitions, missing ownership, weak input controls or lack of policy. Repeated cleansing is not the best answer.
Tip 5 – Prevention beats detection. Controls at the point of data creation or capture, such as validation and edit checks, are preferred over downstream correction.
Tip 6 – Executive sponsorship and a cross-functional council. When a governance initiative is failing because of resistance or silos, the best answer often involves a business-led steering committee or council with senior executive sponsorship.
Tip 7 – Value and risk language. Link answers to the governance objectives of benefits realization, risk optimization and resource optimization. An answer that ties data quality to business outcomes and risk appetite usually beats one focused on technical efficiency.
Tip 8 – Metrics must be meaningful to the business. The best metric for a data quality program reflects business impact or fitness for use, such as reduction in decision errors or % of critical data elements meeting quality thresholds. Avoid purely technical counts like database uptime.
Tip 9 – Know the difference between governance and management. Governance: board and executive EDM, setting policy and risk appetite. Management: CDO, stewards and IT, executing the processes. If asked for the board's role, choose direction and oversight, not operational tasks.
Tip 10 – Classification drives protection and cost. Data classification by owners is the foundation for security controls, retention and privacy compliance. If a question is about inconsistent or excessive protection costs, classification is often the answer.
Tip 11 – Lifecycle and retention. Data must be governed from creation to destruction. Retention must satisfy legal or regulatory needs. Keeping data forever is a risk, not a safe choice.
Tip 12 – Master data and single source of truth. For inconsistent customer or product data across systems, think MDM, common definitions and a business glossary, all supported by ownership and stewardship.
Tip 13 – Watch key qualifier words. MOST important, BEST, PRIMARY, FIRST and GREATEST concern all matter. Eliminate answers that are true but operational, partial or reactive. Choose the most holistic, strategic and business-aligned option.
Tip 14 – Privacy and ethics are part of data governance. Expect scenarios on consent, cross-border transfer, cloud and third-party data handling, and AI or analytics ethics. The best answers involve policy, ownership, risk assessment and contractual or oversight mechanisms.
Tip 15 – Third parties and cloud. Accountability for data cannot be outsourced. The enterprise (data owner) remains accountable. Governance is ensured through contracts, SLAs, right-to-audit clauses and monitoring.
7. Sample Question Walkthrough
Question: An enterprise discovers that management reports from different business units show conflicting revenue figures. What should the IT governance committee recommend FIRST?
A. Implement a new enterprise data warehouse
B. Establish common data definitions and assign data ownership
C. Require IT to reconcile reports monthly
D. Purchase a data quality tool
Answer: B. The root cause is a governance gap: there are no agreed definitions and no accountable owner. A and D are technology solutions that come later. C treats the symptom and wrongly places accountability on IT.
8. Quick Revision Summary
- Data is an enterprise asset that the business must govern.
- Governance (EDM) sets direction; management (PBRM) executes.
- Owner = accountable (business); Steward = day-to-day quality and definitions; Custodian = IT technical implementation.
- Quality = fitness for use. Know the dimensions: accuracy, completeness, consistency, timeliness, validity, uniqueness and integrity.
- Key COBIT reference: APO14 Managed Data, supported by EDM, APO, BAI, DSS and MEA objectives.
- Exam mindset: strategic, business-aligned, root cause, preventive, accountability-driven and value- and risk-based.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!