2.1 Data Governance Principles & Drivers

Key Takeaways

  • Data Governance represents the legislative and judicial oversight (planning, monitoring, and enforcement) of data policies, while Data Management represents the executive operational implementation (how data is stored and integrated).
  • Business units and Data Owners own corporate data assets and definitions, whereas IT acts as the Data Custodian responsible for technical execution and security.
  • Infonomics classifies data valuation into Cost-Basis (replacement cost), Market-Value (commercial selling price), and Economic-Value/Value-in-Use (net impact on revenue and operational efficiency).
  • Key regulations driving data governance compliance include GDPR, HIPAA, CCPA, and BCBS 239, which mandates precise risk data aggregation and audit-ready lineage.
Last updated: July 2026

Understanding Data Governance: Principles and Business Drivers

1. Defining Data Governance vs. Data Management

To succeed in the Certified Data Management Professional (CDMP) exam, you must clearly distinguish between Data Governance (DG) and Data Management.

  • Data Governance is defined by the Data Management Association (DAMA) as the exercise of authority, control, and shared decision-making over the management of data assets. It focuses on the high-level planning, monitoring, and enforcement of data policies, standards, and strategies. It establishes the rules of engagement, decision rights, and accountability. It defines the 'what,' 'who,' and 'why.'
  • Data Management is the implementation and execution of these plans, architectures, and policies to acquire, store, integrate, secure, and deliver data. It represents the technical and operational execution, or the 'how.'

Think of Data Governance as the legislative and judicial branches of a government—setting the laws (policies) and ensuring compliance—while Data Management is the executive branch, carrying out daily operations.

FeatureData Governance (DG)Data Management
FocusStrategy, policies, oversight, and decision rightsExecution, development, operations, and technical implementation
RoleEvaluates, directs, and monitors data activitiesPlans, builds, runs, and maintains data systems
AccountabilityShared business and IT accountability (led by business)Primary IT and technical execution responsibility
DeliverablesPolicies, standards, data glossaries, roles, and metricsDatabase schemas, ETL pipelines, reports, and API integrations

2. Valuing Data as a Business Asset

At the core of DAMA principles is the tenet that data is an intangible enterprise asset. Unlike traditional physical or financial assets, data has unique economic properties:

  • Non-rivalrous: Multiple processes, systems, or business analysts can consume the same data simultaneously without depleting it or reducing its availability.
  • Non-depreciable: Data does not wear out physically from usage. However, its value can decay over time (loss of currency) if not maintained.
  • Regenerative: The application of data frequently generates new data (e.g., transaction history, clickstream logs, behavioral analytics), multiplying its potential value.

To measure and manage this value, organizations employ infonomics concepts, which apply economic principles to information assets. Douglas Laney categorizes valuation into three primary methods:

  1. Cost-Basis Valuation: Calculates the cost of acquiring, transforming, storing, and replacing data if lost. This is crucial for disaster recovery planning and insurance valuations but does not reflect market or business utility.
  2. Market-Value Valuation: Establishes what external entities would pay for the data in a commercial transaction. This is challenging due to the lack of transparent, liquid data markets and legal/privacy constraints.
  3. Economic-Value (Value-in-Use): Measures the impact of data on business performance, such as cost reduction (efficiency) or revenue growth (improved marketing conversion rates).

Exam Tip: The CDMP exam often tests the concept that while data is treated as an asset, it cannot yet be recognized as such on traditional corporate balance sheets under current Generally Accepted Accounting Principles (GAAP) or International Financial Reporting Standards (IFRS) accounting standards due to its intangible nature and valuation complexities.

3. Business Cases and Strategic Drivers

Data Governance is not an end in itself; it must be driven by business objectives. These drivers generally fall into three areas:

  • Risk Mitigation and Regulatory Compliance: Financial services must comply with regulations like BCBS 239 (Basel Committee on Banking Supervision - Risk Data Aggregation and Risk Reporting), which mandates strict data lineage, data accuracy, completeness, and timeliness capabilities. Healthcare must protect patient data under HIPAA (Health Insurance Portability and Accountability Act), and global organizations must satisfy privacy acts like GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act). Non-compliance results in severe financial penalties and reputational damage.
  • Operational Efficiency: Organizations waste substantial resources reconciling conflicting reports and cleaning poor-quality data. DG establishes single sources of truth, reducing operational friction and standardizing terminology.
  • Strategic Enablement: High-quality, governed data is the prerequisite for artificial intelligence (AI), machine learning (ML), and advanced business intelligence (BI).

4. Corporate Governance Alignment

Data Governance must align directly with Corporate Governance—the system of rules, practices, and processes by which a firm is directed. Data governance is not an IT project; it is a business program. A key tenet of DAMA is that the business owns the data, not IT. IT acts as the Data Custodian (handling technical storage, backup, and physical security), whereas the business serves as the Data Owner and Data Steward (responsible for content, data definitions, and business rules).

5. DAMA Data Governance Principles

DAMA defines several core principles for a successful Data Governance program:

  • Business-Driven: The program must align with and support business strategies.
  • Shared Responsibility: IT and business units share mutual accountability for data quality and usage.
  • Collaborative: Open communication across functions is vital to resolve data silos.
  • Multi-faceted: Governance addresses people, processes, technology, and culture.
  • Continuous: Governance is an ongoing organizational capability, not a project with an end date.
  • Sustainable: The governance processes must be embedded into daily operations and funded appropriately.
  • Decisions based on Metadata: Metadata management is the key driver of governance because you cannot govern what you do not document.
  • Integrity and Trust: Governance must foster trust in data through transparency and accountability.
Test Your Knowledge

Which of the following best describes the difference between Data Governance and Data Management according to the DAMA DMBoK2?

A
B
C
D
Test Your Knowledge

An organization is calculating the financial cost to re-acquire and replace customer transaction records in the event of a catastrophic system failure. Which infonomics valuation model are they applying?

A
B
C
D