HomeArticle

Who exactly is responsible for data governance?

王建峰2026-08-14 12:27
Whose responsibility is data governance, anyway?

Whose Responsibility Is Data Governance, Anyway?

If you don't figure out this problem clearly, no matter how much money you spend on purchasing platforms, all your investment will go down the drain.

Let's start with the conclusion: Data governance is the responsibility of all people, but a dedicated lead must be assigned. Enterprises that shift all data governance work to the IT department will eventually spend twice the cost, take twice the detours, and still end up at the wrong destination.

01 A Familiar Blame-shifting Meeting

You must have attended meetings like this before.

The meeting room is filled with the IT director, heads of business departments, finance director, and external data governance consulting consultants. The topic of the meeting is "Why can't data quality keep improving?"

The IT director speaks first: "We have deployed the MDM platform, launched data quality monitoring tools, and all rules are configured, but the business departments do not cooperate. The data entered is inherently wrong, and there is nothing we can do about it."

The head of the business department takes over: "The system did not give any prompts when we entered the data, and no relevant training was provided. No one knows how to fill in the content correctly. Besides, those data standards do not match our actual business scenarios at all."

The finance director frowns: "The data calibers provided by each department are different, I can't make the reports properly. Who on earth is in charge of this?"

Then everyone looks at the consultant in unison. The consultant clears his throat: "Data governance requires building an organizational structure and clarifying the responsibility recognition system..."

The meeting lasts for two hours, and the final conclusion is: hold another meeting next week.

How many enterprises have this scenario repeated over and over again? When there is a problem with data, the IT department says the business side does not cooperate, the business side says the system is not user-friendly, the finance side says the calibers are not unified, and no one takes responsibility in the end.

Why does this happen? Because from the very beginning, people have not figured out a fundamental problem — Whose responsibility is data governance, exactly?

02 Four "Homes" for Data Governance

Let's first see where data governance usually "resides" in enterprises. Basically, there are four "homes":

The First Home: IT Department

This is the most traditional destination. Data is stored in the system, and the system is managed by the IT department, so it is logically reasonable that data should also be managed by the IT department. But in practice, this logic usually goes off track.

What the IT department can manage is technology — how to build the database, how to connect interfaces, how to control permissions. But the IT department cannot manage business issues: how to fill in customer names, how to classify materials, how to map financial accounts. These are business matters. No matter how capable the IT team is, they cannot make these decisions on behalf of the business side.

The biggest risk of placing data governance under the IT department is: The technical solutions become more and more sophisticated, but none of the business problems are solved. The platform is built perfectly, but the data is still dirty as ever.

The Second Home: Compliance/Risk Control Department

In highly regulated industries such as finance and healthcare, data governance is often placed under the compliance or risk control department. The compliance team focuses on whether the data can be stored, whether it can be used, and whether there is a risk of violation of regulations.

There is nothing wrong with this logic, but if data governance is completely driven by compliance, it will easily go to another extreme — only focusing on restrictions and ignoring value empowerment. The data is safe, but no one can use it, and the business departments will feel that data governance only "adds unnecessary obstacles" to their work.

The Third Home: Dedicated Data Management Team

More mature enterprises will set up a dedicated data management or data governance team, led by a CDO (Chief Data Officer) or data governance lead. This is the mainstream direction at present.

But this team often faces an awkward situation: it has responsibilities but no corresponding authority. They are forced to take the blame when data problems occur, but they do not have the authority to require business departments to modify processes, systems and work habits. Without authorization from senior management, the data governance team will be a "leader with no followers".

The Fourth Home: Business Department

In recent years, more and more people have claimed that "data is the business's responsibility". Marketing, finance, supply chain — whoever generates the most data and uses the most data should be responsible for the data quality.

This direction is correct, but if the work is completely pushed to the business side without a unified framework, the result will be each department does its own thing, data standards are fragmented, and the data cannot be aligned during cross-departmental collaboration.

Conclusion: Data governance cannot only "live in one home". It needs a "federal system" — the central level unifies the standards, and each business department implements them separately. We cannot fully centralize the power (let the IT department make all decisions while the business side does not recognize the results), nor can we fully decentralize the power (each department works on its own, leading to conflicting standards).

03 One Sentence Sets the Tone: Business Equals Behavior, Behavior Equals Record, Record Equals Data

Huawei put forward a sentence in its data governance practice, which I think is the most accurate answer to the question "whose responsibility data belongs to":

Business equals behavior, behavior equals record, record equals data.

To explain this sentence: data does not appear out of thin air, it is a by-product of business activities. A salesperson enters an order and generates sales data; a warehouse keeper completes a warehouse entry operation and generates inventory data; a purchaser issues a purchase order and generates procurement data.

Behind every piece of data, there is a specific business action. Whoever completes this action should be responsible for this piece of data.

So the answer is very clear: Data is the responsibility of the business side. It is not the responsibility of the IT department, not the responsibility of consultants, not the responsibility of the data governance office.

But this does not mean that the IT department and data governance team have nothing to do. Their roles are enablers and supporters — providing tools, formulating standards, building processes, so that the business departments can easily "do the right things".

Use a metaphor: data governance is like traffic management. Traffic police (data governance team) are responsible for formulating rules, setting up traffic lights, and installing monitoring devices. But the people who actually follow the rules are every driver (business departments). You can't expect the traffic police to drive for you, but without traffic police, the roads will be in chaos.

04 Four Roles: Nail Down Responsibilities to Specific People

It is easy to say "data is everyone's responsibility", but "everyone" is equivalent to "no one". For effective implementation, responsibilities need to be broken down to specific roles.

The industry-recognized data responsibility recognition model has four core roles:

Role

Who it refers to

What they do

Data Owner

Head of the business department

Formulate standards, approve permissions, take charge of data quality, and have the final decision-making power over the data.

Data Steward

Backbone business staff + Backbone IT staff

Responsible for daily implementation. The business steward is in charge of standard definition, and the technical steward is in charge of tool implementation.

Data Producer

Frontline operation staff

People who enter, collect and generate data. Whoever enters the data is responsible for the quality of the data source.

Data Consumer

Analysts, report developers, management personnel

Use data in accordance with standards, and give timely feedback when problems are found.

These four roles are all indispensable.

Where is the problem of many enterprises? There are only data consumers but no data owners; only the IT department acts as the data steward, while the business side acts as a bystander.

When data problems occur, no Owner can be found; when standards need to be defined, the business department says "the IT team can just make the decision"; when quality assessment is required, no one is willing to hang data quality indicators on their own performance list.

The practice of State Grid Queshan Power Supply Company is worth learning from: strictly follow the principles of "whoever generates is responsible, whoever is in charge is responsible, and whoever manages the business must manage the data", implement the "data owner system" — every piece of data has a clear owner, the roles of producer, manager and user are clearly defined, and strict checks are carried out on data quality.

Core principle: Whoever generates the data takes responsibility, whoever uses the data maintains it, whoever is in charge of the data takes full accountability. This is not a slogan, it is an iron rule that must be written into the system, included in the assessment, and implemented to specific people.

05 Three-tier Organization: One Single Person Cannot Complete This Work

Only defining roles is not enough, an organizational structure is needed to support the work. It is recommended that the organizational structure of data governance be divided into three tiers:

The First Tier: Data Governance Committee (Decision-making Level)

Led by enterprise executives (CIO or CDO), with heads of all business departments participating. This is the highest decision-making body, responsible for:

Approving data governance strategies and standards

Coordinating cross-departmental data governance disputes (that is, the "blame-shifting meeting" will be escalated here for final ruling)

Evaluating the input and output of data governance

Providing resource support (personnel, funds, systems)

Key point: This committee must be led by executives with real power. If you only assign a deputy general manager as a nominal leader who does not actually participate in the work, it is equivalent to having no committee at all. Hold a regular meeting every quarter, and convene meetings at any time for major issues.

The Second Tier: Data Governance Office (Management Level)

This is the execution and coordination organization, composed of full-time data governance leads, data architects, and data quality analysts. Its responsibilities are:

Formulate data governance processes and standards

Maintain the data asset catalog

Organize data quality assessment

Promote the implementation of data governance tools

Provide training for data stewards in business departments

This team is the "central nervous system" of data governance. It does not need a large number of people, but needs compound talents who understand both business and data.

The Third Tier: Data Steward Network (Execution Level)

Composed of data administrators from various business departments and IT departments, distributed in all corners of the organization. They are responsible for:

Implement data standards in their own departments

Monitor data quality

Handle daily data problems

Give feedback on practical problems in the implementation of standards

Data stewards are usually not full-time roles, and data governance responsibilities are added to their original job responsibilities. So it is very important to select the right people: choose people who have influence in the department and have professional capabilities, otherwise the work cannot be promoted smoothly.

The essence of the three-tier architecture is: senior management provides authority, middle management provides methods, and frontline staff complete the execution. Without senior management support, the work cannot be promoted; without middle management, there is no clear rule to follow; without frontline execution, the work cannot be implemented on the ground.

06 Federal System: The Most Suitable Model for Large Groups

Large group enterprises have multiple business divisions and subsidiaries, and each unit has its own business characteristics. Should data governance be managed centrally or decentrally?

There are three models:

Model

Features

Risks

Centralized Model

The headquarters unifies all standards and promotes them forcefully across the group.

It is disconnected from the actual business scenarios, and the response speed is slow.

Distributed Model

Each business department manages its own data, and the headquarters only provides basic support.

Standards are fragmented, and data silos are formed.

Federal Model (Recommended)

The central level sets core standards and tool platforms, and each business department conducts independent governance within the unified framework.

A strong coordination mechanism is required.

The core logic of the federal model is: The "language" is unified, while the "usage" is flexible.

The headquarters unifies the formulation of core data standards (such as material coding rules, customer master data field definitions), and builds a unified data governance platform. On the basis of the core standards, each business department can formulate its own extended standards (such as special material classification for a certain business division), but the extended standards must be compatible with the core standards.

Huawei is a typical practitioner of the federal system. They set up a company-level data Owner at the company level, and domain data Owners in each business field. The company-level data Owner makes overall planning, and the domain data Owners take into account the flexibility of each business field. The cooperation of the two parties not only ensures the unification of the data "language" across the company, but also does not restrict the business departments too much.

07 Responsibility Recognition Is Not a Slogan: Three Key Measures to Ensure Implementation

Roles are defined, the organization is built, and the most critical step is: how to make the responsibility recognition mechanism truly implemented?

Relying only on system documents is not enough — the systems posted on the wall will not be read by anyone. Relying only on leaders' speeches is not enough — after the meeting, everyone will go back to their old ways. To make the responsibility recognition mechanism truly implemented, three key measures are needed:

The First Measure: System-driven — Responsibility Recognition Matrix

Clearly write down the corresponding Owner, Steward, Producer and Consumer for each type of data, and form a unified data responsibility recognition matrix across the enterprise.

For example: customer master data — the Owner is the director of the marketing department, the Steward is the data specialist of the marketing department, the Producer is the salesperson (who enters the data), and the Consumers are the finance department and customer service department.

This matrix should not only be stored in PPT, but also embedded into the MDM system — every data record can be traced back to the responsible person. When a data problem occurs, there is no need to argue in meetings, you can directly locate the specific link and the responsible subject.

The Second Measure: Tool-driven — Data Lineage

Data lineage answers the question "where the data comes from and who has processed it". Through the data lineage analysis tool, you can trace back from the report all the way to the source system and source fields, and see clearly all the processing steps and caliber conversion processes in the middle.

The practice of a certain bank is: generate regular data quality reports according to the submission platform, trace back to the source with the help of data lineage analysis tools, find the department that generates the data, follow the principle of "whoever produces the data is responsible for it and governs it", and solve the problem from the source.

The value of the tool is: change the process of identifying "whose problem it is" from "meeting discussion" to "system verification". When the data cannot be aligned, there is no need to argue, just check the data lineage diagram.

The Third Measure: Assessment Implementation — KPI Linkage

This is the most painful but most effective measure.

Data quality indicators must be included in the performance assessment system of business departments. Field completion rate, caliber accuracy, problem response time — all of these should have clear assessment standards and reward & punishment mechanisms.

A certain enterprise includes data quality into the KPI of the responsible person of relevant units, formulates a responsibility list for statistical work, and establishes a quality control mechanism of "daily monitoring, weekly notification, and monthly analysis". Data quality has changed from "whether it exists" to "whether it is good", and from "voluntarily done well" to "mandatory assessed".

The ultimate goal of the responsibility recognition mechanism is not to "find someone to take the blame