Data and AI Governance Should Be an Enabler, Not a Brake

The organisations that move fastest on data and AI tend to have something in common that surprises people when you point it out.

They have invested seriously in governance. Not governance as a compliance exercise, not governance as a set of documents produced by a consulting firm and filed somewhere accessible, but governance that actually functions. Governance that tells people clearly who can make a decision, at what level, and with clear accountability attached. That clarity is one of the main reasons they can move quickly and with confidence.

This is counterintuitive for most leaders, because the version of governance they have experienced is the other kind. The framework that sits alongside the programme without really shaping it. The policies that get referenced in audits and largely ignored in delivery. The approval processes that create friction without creating confidence. That version of governance does slow things down, and the frustration with it is legitimate. But the answer to bad governance is not less governance. It is governance that actually works.

The distinction is worth being precise about, because conflating the two is where many organisations go wrong.

What functioning governance actually enables

When governance is working as it should, a few things become possible that are genuinely difficult without it.

Decisions get made at the right level, by the right people, without unnecessary escalation. The people accountable for outcomes are the same people with the authority to act, which sounds obvious but is surprisingly rare in practice. The organisation can move with confidence rather than hesitation, because the boundaries within which people can act are understood rather than assumed.

We have seen this operate in organisations that have done the harder work of making governance real rather than formal. The difference in pace, and in the quality of the decisions being made, is significant.

Why most organisations do not get there

The structural problem is that governance tends to be treated as a deliverable rather than a practice.

A framework gets built, approved, signed off at senior levels, and at that point many organisations conclude the governance work is largely done. What follows is predictable.

The framework reflects best practice, or an interpretation of it, but not the specific way this organisation actually works, with its particular culture and history and informal authority structures. It sits alongside delivery rather than shaping it. People consult it occasionally and mostly work around it.

We have seen this play out in specific ways. A consulting firm delivered a comprehensive data governance framework for one organisation: detailed, professionally presented, formally approved. Two years later very little of it had taken root. The policies had not made it into day-to-day practice, and parts of the framework referenced tooling the organisation did not have and had no plans to acquire. Completed, but not operationalised.

In another organisation, data owners and stewards were formally named in the policy documents. However, the people in those roles had not been involved in defining the responsibilities assigned to them, had not been equipped to fulfil them, and were not being held accountable for any outcomes connected to those titles. The structure existed. The accountability did not.

A third version appears around decision-making itself. Non-technical leaders regularly asked to approve data and AI initiatives they are not well-placed to evaluate will, rationally, defer or escalate. Escalation becomes the default response to uncertainty. Governance starts to feel like a source of friction, people begin working around it, and the gap between the framework as designed and the framework as practised widens until the two are barely connected.

The Distance Between Design and Practice

What underlies all of this is the distance between governance as it is designed and governance as it is experienced.

Policies describe how decisions should be made. Actual decisions follow different paths. Accountability is defined but inconsistently enforced, because there is no mechanism connecting the governance structure to the realities of performance management and daily delivery.

Closing that gap requires looking honestly at what is actually happening rather than what the framework says should be happening. Who is making decisions today, in practice? Where is authority genuinely sitting, versus where it is supposed to sit? Which forums are doing real work and which are going through the motions? Those questions surface the real issues without much difficulty. What is harder is being willing to ask them honestly, because the answers often reveal that a significant investment in governance design has not produced the functioning governance it was meant to.

Getting it right

The practical path is less complicated than the problem suggests. It does not start with a new framework. It starts with making what already exists actually function.

Part of what makes that possible now, in a way that was not true even five years ago, is the maturity of the tooling available. Data governance tools have evolved significantly. Data catalogs, lineage platforms, and quality monitoring capabilities have moved from specialist infrastructure to mainstream enterprise technology, and the better implementations are doing something important: they are making governance visible and operational rather than theoretical. When a data owner can see the assets they are responsible for, trace how data moves, and monitor quality in something close to real time, accountability stops being a concept in a policy document and starts being something people can actually act on.

A parallel evolution is now underway in AI governance. The tooling is less mature, but platforms focused on model oversight, risk management, and compliance monitoring are developing quickly. The organisations paying attention to this now, before it becomes urgent, will be in a meaningfully better position than those who treat AI governance as something to address later.

For AI governance specifically, which lacks the accumulated maturity of its data counterpart, the temptation is to over-engineer or replicate approaches that have not been tested in practice. A more productive approach is to begin with clear principles, support them with practical tools people will actually use, and let the framework develop as the organisation learns. Governance that evolves alongside capability tends to stick in a way that governance designed to anticipate every possible scenario does not.

The organisations that do this well understand that governance is not a set of documents. It is the right people, with clear accountability, supported by practical processes, good policy, and tooling that makes all of it visible and enforceable. When those things work together, the result is not a constraint on pace. It is what pace is built on.


Previous
Previous

Many Data and AI Programs Plan for Delivery. Few Plan for Behaviour Change

Next
Next

Culture and Capability Gaps Are Quietly Undermining AI Programs