Short answer
Data governance makes decisions about data rights, definitions, retention, and use explicit by assigning accountable owners and workable controls.
About Data governance
Data governance establishes accountable rules for data access, definitions, retention, and use. It turns policy into decisions, ownership, and controls that can be followed and checked.
Use this competency for
- Roles that define or operate data ownership, access, classification, retention, or shared definitions.
- Work where legal, security, operational, or reporting needs require accountable data decisions.
Do not use this competency for
- Use data quality when the main concern is whether data is accurate, complete, timely, or fit for a stated use.
Important distinctions
Data quality
Data quality evaluates data condition for a use, while data governance assigns authority and rules for managing data.
Data modeling
Data modeling defines structures and relationships, while data governance defines accountability, permitted use, and lifecycle rules.
Expectations by level
IC1
IC1: Applied controls
Applies established governance procedures to scoped requests with guidance. Records decisions, verifies approvals, and escalates cases outside the defined rule.
Observable behaviors
- Classifies a dataset using the documented categories.
- Checks approval and purpose before granting a defined access request.
- Records the owner, decision, and review date in the designated system.
Examples
- Processes access to a restricted dataset after confirming owner approval and the stated use.
- Finds a dataset without a retention label and routes it to the accountable owner instead of guessing.
IC2
IC2: Domain governance
Independently designs and operates governance practices for a team data domain. Resolves routine conflicts between access, retention, and use through documented criteria.
Observable behaviors
- Maps domain datasets to owners, classifications, access paths, and retention rules.
- Designs controls that can be audited without blocking routine approved work.
- Reviews exceptions and updates guidance when the same ambiguity recurs.
Examples
- Creates an access review for customer-support data that identifies stale permissions and accountable approvers.
- Defines ownership and change approval for a shared revenue metric used by finance and sales.
IC3
IC3: Governance programs
Sets governance direction across domains and leads decisions with competing legal, security, and business constraints. Measures whether policies work in practice.
Observable behaviors
- Defines decision rights and escalation paths for cross-domain data use.
- Aligns policy language with technical controls, owners, and audit evidence.
- Reviews program outcomes and changes controls that create unmanaged risk or avoidable delay.
Examples
- Leads a retention program across product, support, and finance data with owners and verifiable deletion paths.
- Resolves a cross-team request for secondary data use by documenting purpose limits, approvals, and monitoring.