A plain-English field guide

What data governance actually is — and isn't.

No frameworks to memorize, no acronyms up front. Just a straight answer to what data governance does for a business, and an honest way to tell if yours needs it yet.

7 chapters No sign-up required to read Written for operators, not data teams
scattered, undocumented, nobody's job named, defined, owned
01
Chapter one

What data governance is

Strip away the consulting language and it comes down to one habit most companies never build on purpose: deciding, in advance, who is responsible for a piece of data and what "good" looks like for it.

Data governance, plainly

The set of decisions, named owners, and agreed rules that make sure data means the same thing to everyone who uses it, comes from a trustworthy place, and has someone accountable when it's wrong.

It is not a piece of software. Software can help enforce it, but you can't buy governance off a shelf — the same way you can't buy "good communication" for a team by installing Slack. It's an operating habit: who decides what "active customer" means, who fixes it when two reports disagree, who approves a new spreadsheet becoming the thing three departments quietly depend on.

Most companies already do pieces of this informally — one analyst who "just knows" which report is right, a running list of exceptions kept in someone's head. Governance is what happens when that knowledge gets written down, assigned to a role instead of a person, and reviewed on a schedule instead of only after something breaks.

02
Chapter two

What it actually does, day to day

Underneath the term are four ordinary jobs. Any company doing all four, even informally, already has a form of governance — the question is usually whether it's reliable or luck.

Ownership

Someone is named, not implied

Every important dataset — customers, revenue, inventory — has one person accountable for its accuracy, even if three teams touch it.

Definition

Words mean one thing

"Active customer" or "closed deal" is defined once, written down, and used the same way in every report that cites it.

Quality

Bad data gets caught, not inherited

There's a routine way to spot when a number looks wrong and trace it back to where it broke, instead of everyone quietly adjusting around it.

Access

The right people can reach it, safely

Sensitive data is labeled as such, and getting access to it is a decision someone makes on purpose — not a side effect of an old permission nobody revoked.

These four hold true whether you're governing spreadsheets or a data warehouse — the scale changes, the jobs don't.

03
Chapter three

The business outcomes, not the theory

Companies don't invest in governance because it's virtuous. They invest because the absence of it shows up as cost, delay, or risk somewhere leadership can feel it.

Faster, more trusted decisions

Leaders stop opening a meeting by arguing about whose number is right, and start with the decision itself.

Cleaner audits and diligence

When a regulator, auditor, or acquirer asks "who owns this data and how do you know it's accurate," there's a real answer.

Safer AI adoption

Before employees feed customer or financial data into ChatGPT or Copilot, there's a rule about what's allowed — not a policy vacuum.

Lower integration cost

Systems, acquisitions, and new tools connect faster when the underlying data already has consistent definitions and owners.

Less firefighting

Issues get caught at the source instead of resurfacing every quarter as the same argument about the same broken report.

Real accountability

When something goes wrong with the data, there's a name attached to the fix — not a shrug and a workaround.

04
Chapter four

What it isn't

Most of the resistance to data governance comes from a definition that was never accurate in the first place.

THE MYTH
A big IT project with a multi-year rollout.
A committee that exists to say no.
Only relevant to banks, hospitals, and other regulated giants.
Something you buy as a software license.
A compliance checkbox with no business upside.
THE REALITY
It can start with three named data owners and one page of definitions.
Good governance speeds decisions up by removing ambiguity.
Any company past roughly 150 employees usually has the same problems, just less visibly.
Software enforces rules; it doesn't create the rules or the accountability.
The companies that do it well treat it as a revenue and cost lever, not a mandate.
05
Chapter five

Signs it's time to formalize it

Growth is usually what forces the issue — the informal habits that worked at 80 employees start quietly failing well before anyone names the cause.

Two teams present different numbers for what should be the same metric, and there's no agreed way to settle it.

One person's departure would leave a real gap in knowing which report, system, or spreadsheet is actually correct.

Employees are already using AI tools on company data with no written guidance on what's off-limits.

An audit, acquisition, or new investor asked a data ownership question your team couldn't answer cleanly.

New systems keep getting slowed down by arguments over whose data is the source of truth.

Nobody owns fixing bad data — it just gets manually corrected downstream, over and over.

Checked two or more? That's usually the point where an informal approach stops being enough — see where you land in the next chapter.

06
Chapter six

Get your readiness score

Five short questions. No email required to see your score — only to get the written breakdown of what it means for a company your size.

0

07
Chapter seven

How companies actually get started

Nobody builds full-scale governance in one step. It tends to move through the same four stages, whether it takes three months or three years.

Have

Take stock of what already exists

Inventory the reports, systems, and informal rules already in use — most companies have more governance than they realize, just undocumented.

Trust

Fix the highest-cost inconsistencies first

Pick the two or three data sets causing the most argument or risk, name an owner, and agree on one definition.

Need

Decide what actually requires formal rules

Not everything needs a policy. Prioritize by business risk and cost, not by what a framework says should come next.

Next

Build the habit that outlasts any one project

A standing, lightweight way to keep ownership and definitions current as the company keeps changing — not a one-time cleanup.

Most mid-sized companies don't have a data team large enough to run this in-house, and don't need one — this is usually where a fractional or advisory lead comes in for a fixed period rather than a permanent hire. Tesatori Technologies runs a structured version of exactly this path for mid-market companies, if you'd rather have a second set of hands than build it alone.

08
Chapter eight

Questions people actually ask

No — security controls who can access data. Governance decides what the data means, who owns it, and whether it's trustworthy in the first place. They overlap, but a company can be secure and still have no idea which report is accurate.
No. The earliest stage of governance is almost entirely decisions and documentation — naming owners, writing down definitions — which any company can do with the people it already has. A dedicated team becomes useful later, once the scope grows.
Naming an owner and agreeing on a definition for one contested metric can change a conversation within weeks. Building it into a durable, company-wide habit typically takes a couple of quarters.
Every AI tool is only as good as the data it's given, and every employee using ChatGPT or Copilot on company data is making a governance decision whether anyone's written the rule or not. Usage governance for commercial AI tools is now one of the fastest-growing reasons companies formalize this.
Pick the single data set that causes the most disagreement, name one accountable owner for it, and write down one agreed definition. That's a real, if small, governance decision — and it's usually enough to prove the value before asking for more time or budget.