Setting up a Data Governance Council that doesn't become theater
Every CDO eventually creates a Data GovernanceData GovernanceData governance is the set of policies, roles, and processes that ensure data is accurate, secure, well-defined, and used responsibly across an organization.View full definition → Council. Most of those councils become useless within 12 months.
They start with good intentions: bring together the right stakeholders, make decisions about data collectively, drive organization-wide change. Then reality sets in. The meeting has 25 attendees who aren't sure why they're there. Agenda items keep getting deferred. No one has clear authority to actually decide anything. The CDO spends three hours a month facilitating a conversation that produces no outcomes.
This doesn't have to be your story.
Why most governance councils fail
Too many people. A governance body with 25 members is a committee. A committee's natural state is inaction. Effective governance councils have 7-12 members, enough diversity of perspective, small enough for actual decision-making.
Wrong people. Governance councils fail when they're populated by representatives rather than decision-makers. If your CFO sends a financial analyst to the governance meeting instead of attending themselves, data governance will never be a CFO priority. The council must include people with budget authority and business accountability.
No clear mandate. "We govern data" is not a mandate. "We make binding decisions on data definitions, data qualitydata qualityThe degree to which data is fit for purpose: accurate, complete, consistent, timely, valid and unique. Poor quality data undermines analytics, reporting and AI.View full definition → standards, and data access policies" is. Without explicit authority over specific decision types, the council becomes advisory, and advisory bodies rarely drive change.
Tactical focus instead of strategic. Many governance councils spend their time reviewing individual data issues ("Should we include returned orders in revenue?") instead of setting the policies that prevent those issues from arising. Tactical councils scale poorly. Strategic councils set rules that prevent problems.
The right structure
Executive Steering Committee (quarterly): CDO + C-suite representatives. Makes strategic decisions: data strategy alignment, major investment approvals, organizational changes. Maximum 8 people.
Data Governance Council (monthly): CDO + domain data owners (one per major business function). Makes operational governance decisions: data definitions, data quality standards, data access policies, Data lineageData lineageData lineage maps how data moves and transforms across systems, from origin to consumption, showing where it came from, what changed it, and where it goes.View full definition → requirements. 8-12 people.
Domain Data Steward network (weekly/as-needed): Data stewards in each business domain, coordinated by the CDO team. Implements governance decisions, resolves data issues, owns data quality within their domain.
The key principle: decisions should be made at the lowest level that has enough context. The Steering Committee shouldn't be arguing about whether "customer" includes trial users. The domain stewards should resolve that and escalate only if they can't reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition → consensus.
The DAMA-DMBOK Framework | Exclusive Lesson
Knowledge check
1. Why does the lesson argue that a governance council with 25 members tends to fail?
2. What distinguishes a strong council mandate from a weak one, according to the lesson?
3. The lesson warns against councils having a 'tactical focus.' What is the problem with that approach?
4. Select ALL of the reasons the lesson gives for why most governance councils fail.
Select all the correct answers.
5. Select ALL statements that correctly describe the recommended governance structure.
Select all the correct answers.
What a well-functioning governance council actually does
A governance council that works meets monthly, makes 3-5 binding decisions per meeting, and tracks outcomes. Here's a concrete agenda structure:
Standing items (15 min):
- Data quality scorecard review: is quality improving or degrading?
- Policy compliance: are published data standards being followed?
- Escalations from domain stewards: unresolved data issues requiring council authority
Decision items (30 min):
- Proposed data definitions for review and approval
- Access policy changes (new data sharing arrangements)
- Data quality standard updates
Strategic items (15 min):
- Roadmap updates: is the governance program delivering against plan?
- Upcoming regulatory or organizational changes requiring governance response
One practical rule: Every item on the agenda is either a decision or an escalation. Nothing is "for information only." If it's for information only, send an email.
The ING bank example
ING Bank's data governance program is one of the most cited in European financial services. Their approach: treat data governance as a product, not a compliance function.
They built a Data Governance Council with explicit business ownership, each data domain (customer, product, transaction, risk) had a named executive owner accountable for data quality. Council meetings made binding decisions, tracked in a governance register. Outcomes were reported to the Management Board quarterly.
The result: data quality improved measurably across their core domains within 18 months, and regulatory data submissions became significantly more reliable. The governance council had teeth because it had accountability.
What to do, from this lesson
These actions are compiled in the role's Playbook.
- Convene a decision-focused Data Governance Council with named executive domain owners
Related articles
Recent articles from the blog that build on this lesson.
- DataHow Salesforce learned to make master data stickSalesforce spent years selling data quality to its customers while quietly struggling with fragmented customer and product records across its own acquisitions. The way the company addressed that internal contradiction holds practical lessons for any CDO trying to move MDM from a slide deck into operating reality.
- DataData governance in 2026: why compliance alone is failing CDOsMost organizations have data governance frameworks on paper. The ones that actually work have something different, and it has less to do with regulation than with how governance is wired into daily decision-making.
- DataData governance in 2026: why "good enough" compliance is now a board-level riskMost organizations believe they have data governance under control, until a regulatory audit, a breach, or a failed AI deployment proves otherwise. Here is what CDOs need to understand about the governance gap widening between leading and lagging organizations in 2026.