
Data Governance in the Age of AI : From Compliance Burden to Strategic Enabler - with Nicola Askham
WHAT IS THE DIFFERENCE BETWEEN AI GOVERNANCE AND DATA GOVERNANCE?
Data governance controls the quality, meaning, ownership, access and lifecycle of data. AI governance controls how AI use cases and systems are selected, built, deployed, monitored and retired. They overlap because AI depends on governed data, but neither discipline can replace the other.SOURCES AND FURTHER READING
NIST Artificial Intelligence Risk Management Framework 1.0: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10
Australian Government AI use-case impact assessment: https://www.digital.gov.au/ai/ai-in-government-policy/ai-use-case-impact-assessment
Australian Information Commissioner's AI privacy guidance: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/artificial-intelligence
RELATED EPISODES
Reimagining Data Functions in the AI Era: https://www.enterprisetechtalk.com/episodes/reimagining-data-functions-ai-era-ownership-governance-trust
Safe and Scalable AI Adoption: https://www.enterprisetechtalk.com/episodes/safe-scalable-ai-adoption-enterprise
AI Engineering Beyond the Hype: https://www.enterprisetechtalk.com/episodes/ai-engineering-harnesses-guardrails-production-realityWHAT IS THE DIFFERENCE BETWEEN AI GOVERNANCE AND DATA GOVERNANCE?
Data governance controls the quality, meaning, ownership, access and lifecycle of data. AI governance controls how AI use cases and systems are selected, built, deployed, monitored and retired. They overlap because AI depends on governed data, but neither discipline can replace the other.Data Governance Is Back. And This Time It’s Different
For years, data governance lived in the margins of enterprise priorities. Often triggered by regulation. Often implemented as a compliance exercise. Often abandoned when enthusiasm faded.
But in the age of AI, something has shifted.
In the latest Enterprise Tech Talk episode, Saumitra Kalikar had the privilege of speaking with Nicola Askham , internationally recognised data governance advisor and author of Effective Data Governance: Design a Framework That Works for Your Organisation.
The conversation was refreshingly grounded, less about theory, more about what actually works.
Why Governance Is Back on the Executive Agenda
The resurgence of data governance is not driven by regulators alone. It is being driven by AI.
Enterprises are investing heavily in generative AI, agentic workflows and automation. But many are discovering an uncomfortable reality: You cannot industrialise AI on poor data foundations.
As Nicola put it plainly: AI doesn’t fix bad data. It amplifies it. Organisations that once treated governance as a tick-box exercise are now confronting its strategic importance.
The Big Shift: From Centralised Control to Federated Responsibility
One of the most powerful parts of our discussion was around operating models. Traditional governance relied on centralised teams creating standards and running review gates. Today’s enterprises are product-aligned, federated and delivery-oriented.
That means:
Data owners sit in the business.
Data product owners emerge in delivery teams.
AI governance functions are being created — sometimes in isolation.
The real challenge is not defining more governance forums. It is designing governance that enables safe innovation. Guardrails, not gates. Automation where risk is low. Human judgment where risk is material.
AI Governance vs Data Governance — False Choice?
A recurring theme was whether AI governance should sit inside data governance or remain separate. The answer is less about structure and more about alignment. AI governance without strong data governance ignores foundational risk. Data governance without understanding AI ignores emerging risk. Either way, literacy matters, not just for specialists but for the whole organisation.
Data and AI literacy are no longer optional capabilities.
Measuring Value (The Hard Question)
Perhaps the most honest moment in the discussion was around KPIs. There is no universal set of metrics that proves governance success. Counting data owners or glossary definitions is progress — not value. Real value comes from solving tangible business problems:
Reduced manual workarounds
Fewer reporting errors
Lower operational risk
Faster delivery confidence
Safer AI deployment
Governance must link directly to business outcomes — not theoretical maturity.
The Most Important Advice for Leaders
Nicola’s closing advice was simple and powerful: Do not start with “we need better data.” Start with: What business problem are we solving? What risk are we reducing? What strategic objective are we enabling? Governance succeeds when it is practical, contextual and aligned to strategy — not when it is designed for perfection.
If your organisation is scaling AI, experimenting with agents, or modernising operating models, this conversation is timely.
And if you are serious about implementing governance that works in the real world, Nicola’s book is a structured and practical guide worth exploring.
Episode Transcript
FULL TRANSCRIPT
This transcript is based on the episode’s English auto-captions and has been formatted for readability. Please allow for occasional transcription errors in names, acronyms and specialised terms.
[00:00:00]
But more recent years, I I would have said the majority of my clients are [music] doing data governance because they've seen the value in it, not for regulatory reasons. And I've always felt you need a centralized team to support data governance. But I've never [music] been a fan of data governance being only done by that central team because it it it doesn't work. I mean, if organizations do AI governance without data governance team being involved, they're very much looking at is [music] it ethical to use the data for this? is have we have we sorted out any unconscious biases and you know those kind of things um and they're not saying is this the right data to use I have worked with a couple of areas [music] where they've tried to put or have put privacy on on the same as the data governance team I don't think that works very well I mean our whole conversation I think gives all the reasons why I think [music] AI literacy needs to be rolled in with the data literacy it should be data and AI literacy [music] training not teaching today about data next week about AI. Um, we need people to understand that again.
[00:01:18]
Hello and welcome to Enterprise Tech Talk podcast. I am your host Sumitra Kalikar. Today we are going to discuss a topic which many organizations have struggled with for a long time and yet in the age of artificial intelligence this topic has never been so important and is now back on senior executive agenda. We're talking about data governance. We are going to focus on data governance in the age of artificial intelligence. And to help me unpack this important topic, I'm joined today by Nicola Assam. Um Nicola is a well recognized data governance advisor, a coach, a speaker and a thought leader. And I know she's also an author having recently published a book titled u effective data governance um design a framework that works for your organization. So well Nicola welcome to the podcast. >> Thank you Saumitra. It's lovely to be here. Um so before we take a deep dive into our our topic to for today I would love to spend some time to talk about your book if that's okay. Um um firstly congratulations for the book.
[00:02:28]
>> Yeah and um look um over the years you must have come across many uh data governance programs. Some of those might have been spectacularly successful. some of been might have been probably not that much uh or even failed. But throughout that experience, what were your key observations that potentially probably motivated you to write this book? >> Oo, [laughter] I I think a lot of um I think what prompted me to write the book is I feel like I've learned an awful lot over the years by not necessarily doing it right. which is I kind of I've made a lot of mistakes particularly in the early part of my career and and I think it is the fact that I see people making the same mistakes time and time again. So it makes me feel a bit better that perhaps I wasn't being 100% stupid in the early years. It was just you do what seems the right thing to do for data governance but it doesn't win people over. Um, so I think it it was, you know, it was all these mistakes that I kept seeing people do and you're just kind of thinking and then you got the other end of the extreme where people think that everything has to be perfect. You know, we've got to have this very detailed um full framework for it to work. And actually, I think we just, you know, pe I felt like people needed the the tips and advice on this. This this is going to be challenging because it's all about people and we have to bring people with us to get them to care about their data.
[00:03:52]
Um, but it it can be done if we don't need to complicate it. We can just do a nice simple approach. And I think also there's this this very natural tendency of how can I fasttrack it or I'll use a standard framework. Well, standard frameworks don't work. So, you have to design your own, but if you've never done it before, how do you know where to start? So, it was kind of all of those things that I was trying to address by writing a book that they gave people step by step what they need to know and what they need to do, but also what they shouldn't do because I've already made that mistake for them. They don't need to do that one. >> Yeah. Yeah. And what kind of at high level, what kind of patterns you were seeing across organizations um where either people were doing something right or people were making mistakes? Um, yeah, I was going to say, I mean, I've and I think that's what I've been very conscious of. A friend said to me very early on in my career, you're good at this, but you you're not very good at explaining why you're good at it. And he said, watch what you do that works and also watch what other people do that works. So, um, I I don't have the monopoly on knowing how to do everything right for data governance. I think you're right. I' I've worked in organizations and gone, wow. So, I mean, one thing is like conceptual data models. um one of my first contract roles as an interim data governance manager. Um there was a firm consultants doing some work for a bigger program that data governance was being delivered as part of and he was kind of trying to show tell me what he already knew. He was such a helpful chap and he said I'm running a conceptual data model workshop for this I think it was finance. Do you want to come? And I kind of went I felt like well that's what data modelers do.
[00:05:28]
I'm I'm a data governance person, but I went um because he was really nice and he was really going out of his way to hand over all the knowledge that he'd acquired whilst being at this client, which as you know can be sometimes a little unusual in some consulting. And um honestly, it was the most amazing workshop. I suddenly saw how people were engaging with him. They were describing quite easily how they think about their data. And at the end, I just went um sorry, I'm I'm I'm new here and I just just wanted to ask a question. Is there any data here that you think you own? And they went, well, what does that mean? And I went, well, obviously I've only just started, so but we'll we'll get round to actually defining it properly, but is there any here that you don't want anybody else in the whole of the rest of this company making a decision on without asking you? And they went, oh yes. And they were almost like them volunteering to be data owner for certain data. And it was almost like Rob inviting me to this workshop had this huge light bulb moment for me. So I think and I've been a bit like that a collector all along you know of you know I I worked out don't do it this way so I've got to find another way of doing it and then I just saw what other people were doing and also across sectors as well so in in Europe um back a few years now we had the solveny 2 directive for all insurance companies and as part of that they had to do some data governance over their data but there was a concept in that called materiality which is basically put more effort into looking after the most material or most critical data um that I've taken to every client in every sector ever since. So, it's I'm I think I've been a real collector over my career of of kind of learning. You're suddenly going, "Oh, yes, I can see why the regulators ask for that." And why is why should that only be for insurance companies? Surely that works for everybody. >> Great fun collecting all these things.
[00:07:14]
>> Yeah. In Australia also there is something similar there. There is a regulatory body for insurance and financial services in general like um defining very clear information owners for example and defined the materiality of different systems and services etc. So uh yeah something similar. Uh but coming back to your book um of course this is aimed for the data governance teams of course right uh the data governance lead and team underneath uh but who else do you think uh within the business should read this book and they will get benefited? >> Do you think that anybody in like a wider data team because you and I know um the data governance team I think of all the data teams has to work with everybody else. we if if we do our job well, we help everybody else do their jobs with data well and and the business people. But I don't I can't see many business people just wanting to go and to read a book about data governance.
[00:08:13]
Let's be honest. But I do think that you know the wider teams the data architects even the data and analytics teams because I think a lot a lot of people need to understand what it is that their organization is trying to do so they can help because all the other data teams even when you come down to like the the data security cyber security teams they can all benefit from having data governance and if we I always feel like data governance is the thing that joins up all the other data management disciplines and and makes it align we we we make everybody aligned and it easier so that it's it's a lot easier for everybody to actually do their work and do it well. >> Yeah. Yeah. Okay. So, let's let's now move to our our topic and uh in a way your book is is is timely because um this u this topic about data governance. I'm seeing at least within Australia it is getting back into the senior executives kind of discussions. um um uh I'm I'm sure is the same for other other other places as well. Um partly it is also driven by the AI um uh acceleration in AI investment and we'll talk about that. uh but taking a step back um if you look at the way data governance used to uh happen and it used to run let's say four five years back or recently um some of those failed right some of those data conite initiatives failed uh there was a kind of expectation match mismatch between ex what executives expected from this function and what they could deliver so do you do you have any perspective as to what you what didn't work well in the past and and why now it is coming back into the senior executives focus.
[00:09:59]
>> So that's that's a good question. I do think that in the past I would say a lot of people only really got data governance initiatives going because there was a regulatory requirement. So financial services, pharmaceutical, things like that. And then um in the UK and more recently the higher education sector, the housing sector, they're all they all just kind of add on kind of thing. And and I think a lot of organizations did it only because they had to to tick a box for the regulator. And I'm sure you've come across the same. You have the same conversations about what's the minimum I can do to keep the regulator off my back. And I felt like they were then not thinking big picture. And the silly thing is they were kind of going out of their way to do a tickbox approach because they felt that would be quicker, but actually it probably wasn't actually delivering much in the way of value and was probably harder work and more labor intensive. Whereas if you put nice simple basic data governance foundation in, you'd meet the regulatory requirements really easily and actually start delivering some business value.
[00:11:02]
And I think that's possibly what I've seen a lot is that that people have seen it as something that the regulator asked for, not something that's had wider business benefit. And I've I've really enjoyed probably even I mean there's always been the odd organization that's had that foright and and and done it. But more recent years I I would have said the majority of my clients are doing data governance because they've seen the value in it, not for regulatory reasons. And that's a wonderful shift to have seen happen. But I think you're right, the AI is driving it a lot because people want AI and and you know, even the companies that are perhaps slower to adopt it are suddenly realizing that they they're just going to not win the battle or survive the battle with their competitors if they don't embrace it. And then doesn't matter that, you know, some of us in the organization have probably been saying for years our data is, you know, important. We need it to be good enough. And it's not until they're doing these first trials of using um genai that they're realizing that the data is not good enough because you can have the cleverest um AI engineers and and write the wonderful LLMs, but if you train it on poor quality data, you're going to get the wrong answers. And I mean, I'm sure you there's already been horror stories in the news. People have rushed to do AI chat bots that have said the wrong things. Um so you know I think it's been a very tangible thing that perhaps executives can get their heads around. I think when data governance I in the early days I would have called myself a data governance evangelist and then I learned that's no good because that's just all about well our data must be perfect and we'll live happily ever after. Oh, go away. That's just, you know, whereas if saying, >> look, AI is really exciting. This is really great, but look what happens if you don't have the right data in there.
[00:12:53]
Brilliant. >> And we've given something really tangible to get their heads around. They want AI and now they understand that the data governance or good enough data for that AI is part of the package. >> Yeah. Yeah. As as they say, garbage in, garbage out. And it's so true for for in this area, right? Um and I was reading an article I remember somewhere where it said around 60 to 70% of organizations they they feel that their acceleration of their AI ambitions is heavily constrained by um the quality of data and thereby by extension the data governance the the maturity of data governance within their organizations right and and uh just to build on that what you just said in the in in the past I would imagine data governance heavily focused on um what I would call as more structured readily available data like your um how and how we can better um govern it in terms of line lineage etc right data quality like your customer records and CRM systems and addresses and so on and so forth right all but everything is well structure but coming um come AI and as jai and aenticare now that that's coming A lot of focus has shifted from not necessarily structured data but now on unstructured data like your emails and your all kind of conversations and everything and historically data governance probably didn't focus that area that much as against structured data is that is this a new area data governance now need should increasingly focus on in your view >> I think I think you're right and I think it's happened only just a small number of times over my career where um I've been helping somebody do data governance and then somebody else in the organization says oh will you do like records management which tends to include the unstructured data like your emails and things and we'd normally go well that's not well it is data but it's did you say it's all over the place we don't know what it is and you can't say before you press send on that email to me you must write all the metadata and tell me what everything means going to send me links to your glossery about what every word you've used means because that's crazy. So, um I have seen some organizations where the data governance team has taken on records management and and I've been part of that in the past. Um but I think there's still it be interesting to see what you think, but I've still come across a lot of organizations where there has been no formal records management. So I think um I think you say AI is absolutely driving the need for it because there is probably the most amazing data and information and insights that could be got from looking at all our emails or our um and working with a a a retailer in the UK and they have CCTV to try and look for um shoplifterss and things like that. you know, wouldn't it be interesting if we could actually monitor and see if we can predict, you know, and we've got AI that can actually churn through all of that data way quicker than we ever could. Um, but we've got to find one way of doing it. So, I think the principles are the same.
[00:16:01]
>> Yeah. But I think we have to take a you should say take the right approach because I think when it comes to unstructured data it's all about tagging so that we can give the AI an idea of what it is rather than the full definition that I'd want if I'm doing pure data governance at data field level. I want a proper definition of what does customer mean? You know how how long's the customer name field and what does this field mean and what are the constraints about it. We can't do that with emails and documents but we can do a tagging say this is a kind of and I think that's the kind of thing that we can use AI both to do the tagging but we'll need some human in the loop in the early days um but then it can actually help us do the tagging and then to find that data again >> yeah yeah you're right so tagging it becomes more important and and there by thereby classification of data like which data is more sensitive for your organizations versus public versus what right? Um and so and because when what AI has done in my in my view it is JA has democratized use of AI in a way that every user can independently use AI for their own productivities and if someone happens to upload business data onto a third party platform for some email summarization or word documents generation whether that email is sensitive whether that it is it has any any encrypted or any sensitive information that becomes an important consideration, right? Um >> in the in the and in the future as organizations start rolling out more agents agentic care which are going to do work mostly autonomously then they and human in the loop yes would be there but for day-to-day work it may not be there and so how agents are going to which what kind of data agent should have access to and what data they shouldn't have access to etc those would be in my view important considerations and it would good to see whether data governance as a function uplift itself to now start covering these aspects as well. >> Oh, definitely. I I was at um uh there's a master class I I run regularly for a vendor in the UK and the last one we did was on this whole topic and honestly the conversations were amazing. There are a lot of data governance teams that uh are literally their their kind of organizations are going oh you you can sort out they they've almost had the initial teething problems of of using agents that are looking at the wrong data or bringing back the wrong answers or you know the ones where you know it'll make up if you ask it what the latest HR policy is it can't find the answer to your question so it makes it up for you kind of had like those teething problems um and then somebody turn up at their desk and go oh Sam you do data governance here. Can you sort out the AI data as well? And there's so there's a lot of data governance people who I think we've got the two sides.
[00:19:03]
There are really excited that people actually are now asking them to come to the party and play and but there's other people that go but but we we don't have the expertise for this yet. >> We're data governance people. So I think a lot of data governance people need to really get their heads around AI and understand how are we going to do data governance in a pragmatic way. I've always said we've got to do data governance in a pragmatic way, but we we can't lock down everything. Our our organizations are being more innovative than they've ever been or quicker than they've ever been. >> And we're just going to be the bad guys if we go stop. No, nobody nobody build an agent, nobody do anything and until we've made all sure sure all the data is documented and perfect. So I think we've got to be very I don't know just just practical and pragmatic in how we do it. Um rather than let's lock everything down till all our data is perfect because we know that's never going to happen. >> Yeah. Yeah. And uh this is good point and um building on that the other thing I wanted to unpack with you was um how data governance needs as a function needs to evolve or is evolving based on what how we are seeing across the organizations um as the overall operance about operating models also is changing right so in the past um when these functions were established data governance and and I'm part of architecture strategy function and um same for our function as well. Um we had typically very um uh rigid operating model within technology overall business where there these were centralized functions. Um architecture is centralized function. Data governance is a centralized function uh um right and they would come up with the standards policies etc and kind of do in a way governance gates for different types of changes uh within the organization but now operating models within businesses are evolving they're getting more product aligned um right and the oper they become more federated um what I mean by that is that um the the the there are more autonomous independent teams now within organized product teams which are end to end responsibility for designing products, building, maintaining products etc. Part of that also to certain extent being responsible for the data they are using right. Um so in this federated and more product aligned operating models which are becoming more and more and more common nowadays how do you see oper data governance as a function evolving? Would it still continue to be some sort of centralized function or do you see now it's kind of federated across these these teams? So, um, no, that's that's a great question. And I think I' I've I've always felt you need a centralized team to support data governance, but I've never been a fan of data governance being only done by that central team because it it doesn't work. I mean, as you're you're a data architect, some I think you're one of the people before data governance comes along. it's you and your team that know probably the most about overarching data across the organization, but you still wouldn't want to be accountable for the quality and the definitions of all of that data, even though you probably know more more than most people at your organization.
[00:22:27]
So, I've always said that yes, you should have a data governance team centrally. Um, but actually, I've always been a fan of the federated approach. Um I'm not been um you know a fan of one team can sit do data governance for you and fix everything. I've always been about training [clears throat] up the the team. So I think I think the principles of data governance have never really changed in the 24 years I've been doing it but how we do it is what has evolved. And I think particularly what you're saying with with the data products and everything. I think I've been through some really interesting times with some clients and they wanted to get rid of data owners and data stewards because we've got a data product owner and I we went we went through some really interesting discussions and debates while we were trying to work out what we felt would work and what we didn't. Um and in the end we actually ended up still having data owners and data stewards but you have a data product owner because >> you and and that is a role that data governance didn't create. that just the creating data products created that role but we give them some data governance responsibilities. So for making sure they use the right data for going to the data owner and getting you know agreement that they can use that data for that purpose and that it's good enough and if it's not good enough working with the data stewards to see what we could do. So I think I've always been a fan of this federated approach, but I think and and this will probably just change because if we have business users able to build their own AI agents in the future, you know, we we don't they don't even have a hat called a data product owner. So I think it's it's just be getting almost like more and more people have more and more responsibilities um u when it comes to data governance.
[00:24:17]
but I think we still need our data owner and data steward because I had a really interesting conversation um with a client where they were saying we didn't need a data owner and I said well that's all right as long as that data is only going to be used in one data product so then you can have a data product owner can own it um but actually data product owners tend to be more junior they're more data engineers aren't they they're build they're bringing it together and building it they they're not the business owners of that data >> so we've it's been really interesting and and useful conversations and triing while we've worked out what works and what doesn't. So I think you're right. I've always been a fan of federated probably getting more people with just a little bit of a data governance responsibility added to their existing role. >> Yeah. Yeah. You again in in Australia there under APRA regulations particularly financial services there is a role or concept defined as information or not. I don't know whether this is used um in other other areas like in UK etc. But information owner is the kind of business owner um but more responsible for the data under it not not the entire system. Um so yeah that's an interesting concept but but building on what you just said uh uh I mean uh yes these these things are still evolving a bit uh uh but is there sufficient clarity as to um what kind of roles should still be centralized? you talked about data stored etc and what roles are now emerging within the business of product teams uh and more importantly how they should interact in terms of roles and responsibilities. M so I I think the the only people in the center should be the data governance team um and and their role is to support all the other people basically to help them do their job maybe do the data quality reporting and help them fix the issues but I think the data owners and data stewards are out in the business and they they always should be because it's the business units as that understand why do we have that data what are we going to use it for so so I think very much the but but what they don't know particularly in the early days is they don't know how to do data governance. They don't understand why one minute they were a head of function and now somebody said you're also a data owner or an information owner which is a term I I I see a lot used interchangeably. Um so I think you know and I can't just come and meet you today and say oh it's lovely to meet you Simmitra I think you're a you're you're an information owner as well and you go oh yes great I understand exactly what I've got to do thanks Nicola and never talk to me again. So my job is now to to leers with you to get you to committees to do that oversight, make sure we're focusing on the right things and doing the right thing because I've always felt very strongly that it shouldn't be down to me either if I'm your data governance lead to say this is what we're going to prioritize next for data governance. It should be you the business user that's doing this and you know what the challenges are. you know if we're having a new system or we're developing AI agents or something you should be saying we need to do data governance on this next please can you help us Nicola not me coming and going right I need you to do this this and this but I think in the early days we have to do a lot more handholding and support of everybody so I do think a lot of what the data governance team is communications training briefing um and that means that we're even been responsible for what I've considered with the basic level of data literacy training so I was doing that for years before data literacy even became a a buzzword. I I would just call it it was part of the training as doing data governance. So I trained my data trainers, I trained my data stewards, but actually I need everybody in the whole organization to start realizing that data is an asset and we need to manage it like we do our other assets.
[00:28:01]
So I was trying to do little bits of training. I was trying to get in induction training. I would try and mention the importance of capturing data correctly in anybody's training that would let me. So, and I think it's, you know, that's why as as data governance people, we have to be really good communicators because we're the ones responsible for supporting everybody in our whole organization. But I think you're right. Whereas up, you know, till a couple years ago, we were perhaps doing here's some basics. Data is an asset. You must look after it. Now, we're going to be saying, and if you're using AI, make sure it's the right data. Is it good enough quality for you to use it? Are you allowed to use it for that? So it's almost like we we need to build on the principles for everybody and and train them. So I do see we're very much communicators and trainers sitting in the middle. >> Yeah. Yeah. Good point. Um one other thing um because we're talking about operating model. Uh one other thing I really want to get your perspective on is um um is a is the is about AI governance. um and as a function I'll u look um and what I've seen in few organizations at least here in Australia is uh u with the with of course in last two years with with ja and now agent AI governance has started coming up as a has been has started popping up as a as a uh distinct function uh maybe a small function um um with with initial responsibilities to define some AI policies principles etc. Um some organizations stood it up as a separate completely siloed um function uh within potentially some business areas and they had similar responsibilities to coordinate with uh rest of the organization purely from air policies perspective etc uh principles perspective but in some other organizations also seen gradually uh they are bringing data governance and AI governance closer together under a single bigger broader business function. Not necessarily merging them together uh but uh under the same uh operate operating um uh uh function um with some clear role distinct responsibilities assigned to those. Um I wanted to get your perspective on this as to how you are seeing this now evolving um across industries because I don't see at least in Australia we have landed on a definitive answer whether um data governance and AI governance should be under single operating function uh or they are very distinct.
[00:30:38]
Yeah, I think I've I've my experience has been very similar to yours and say I I was I mentioned earlier the the day I was at recently where some really interesting conversations with people and I think we're even in the UK we get the same mix >> um that some people are saying well somebody's got to govern this AI thing and you already do governance can you do it um versus the they're setting up specialist teams um some of which are refusing to talk to the data governance people because they're going no no no you do data we do AI and then you have got that hybrid where people are saying we we are separate but we we understand that we absolutely have to be aligned and work together and I I think alo we don't want the middle one but having them separate or combined is okay but I think um you know either way we've got to work very closely together but I think what we um the conversations I'm seeing is that if organizations do AI governance without data governance team being involved they're very much looking at is it ethical to use the data for this? is have we have we sorted out any unconscious biases and you know those kind of things um and then not saying is this the right data to use is it good enough to use for this but I think also that you know I was talked to data governance teams who have had AI governance added to their [laughter] thing but they haven't been given any more resources and they haven't been given the training and they're feeling really out of their depth about how do I do this bias thing and how do I make sure that it's the right model? Um, how do you choose multi governance if you've never done anything like that? So, I think there is I don't feel too strongly from the conversation I've had whether you should have them on the same team or separate, but I do think we need good training.
[00:32:27]
And I think even if you've got a separate AI governance team, I think it would be absolutely wonderful if the data governance team got some training because that will then help them work with the AI governance team to work on a how do we do data governance for AI >> that actually is a a practical useful approach I is is the best way to do it. So I mean I when I was saying that I just had a huge flashback to years ago when I I was working in a bank which is where I did data governance but I joined their corporate banking and because corporate banking looks after massive organizations who use loads of different services and so when you were new into the department for the first few months you could go and spend half a day a week with all the different people that provided services to corporate customers and I took advantage of that and it was brilliant because that meant I understood. So if a customer said I need to talk about treasury and and you know doing derivatives or something I'd be going oh I know the person and I know what you're talking about rather than the I have no idea what you're talking about let me go and find something and I think that's almost what we need for our data governance people if they're not doing AI governance we don't need to be experts but we do need to have a basic understanding of what's going on so that we can design data governance and work with them well because you know we said earlier this isn't about stopping things and stifling innovation. This is almost about enabling safe innovation.
[00:33:50]
>> Absolutely. And that's that's a really important wording there. Um and the reason why I asked this question I I actually brought it up was based on my my own experience um and and something I which I'm seeing more and more as a as um uh kind of frustration coming from business teams where um uh when business wants to roll out a new initiative an idea right a change um you already had so many governance gates you had architecture governance you have data governance now you have All of a sudden people are talking about AI governance and and in some areas um there are overlaps of information business need to share with all the through through all these governance forums and same repetitive questions are being asked right and if you think your from a business owner perspective it's it's a it's a frustration it's a nuance right um and it just delays the the initiative so uh that fundamentally raises the question as to how you can optimize this whole um the the initiative or work delivery model where these governance models do not necessarily just create a rate for the sake of but you can optimize and automate them possible so that one set of questions are asked across these forums and as much as possible common decisions are made right and I'm not saying we have answer on this but I'm just stating out that these are practical problems emerging which and we we need to have answers on.
[00:35:24]
>> Oh, I totally agree and actually um what I would say is I think one of my clients was done the best that I've seen in this space. Um so exactly what you were saying the um the data protection team had a long checklist. The data governance team had a long I think theirs was called the data governance assessment. Then you had the records management people talking about data retention periods. Then you had the data security cyber security and as you say a lot of the questions were hard work. So when we first started helping them they were trying to pull them together but they they didn't really have the the manpower. So that was something that uh myself and one of my associates started helping with and it you know I think the way you just described it was was really exactly how it was. It's it's really hard work because you as a data architect have asked a similar question to me as a data governance person but you've asked it for a different reason and so to actually everybody wanted I mean we all the teams there all the different teams work very well together at that particular organization and they all wanted the same thing but I I won't pretend it was easy that we all said oh let's just combine these and here it is go because what we had to do was almost like put everything into one document and then suddenly say oh well I think those three questions all mean the same and then we'd go right so we're proposing that we ask this question and then because the data protection officer would go well no I won't get I won't get exactly what I need we need to ask it like this so there was a lot ofing and throwing but we did and and you know I think to begin with the first checklist was like 100 questions long and that you can you know yes it's you know we can say it's okay business user it's all in one checklist now but I mean 100 who's going to want to do that they're going to be trying to bypass us all >> so they work together to bring them together and also work up what were supplementary questions that would only be answered if you answered this to question seven or something.
[00:37:16]
>> So they were working took a lot of effort. I won't pretend it was easy but I do think it was valuable and the business users appreciated what they were trying to do. And I know what they're currently working on is they haven't got a fancy tool to do it but they do use um Power Automate and and their Power Apps. >> Yeah. Yeah. Yeah. >> So they're what they're trying to do so without using a big expensive tool or something is do it so that you get the checklist and you as a business user you might only get 15 questions you answer them and depending what you answer it might send you more questions back but it might send your answers off to a different team >> to review and ask whether something so they've made it they're trying to make it as frictionless as possible. Um but it's it's taken a lot of hard work. But I think you're right because you know your your data architecture gateways every you know the data security people we all ask these questions for for genuinely good reasons.
[00:38:13]
>> Um but what we got to do is make it I suppose as as as less painful as possible for our business users otherwise they will just try and avoid us and then we carry on the mistakes of the past. Yeah, absolutely. And people will try to find workarounds if they find that it's so difficult and challenging just to get their small even the small initiatives through the whole uh work delivery processes, right? Um yeah and and just to extend that now to the to the to the future the AI future AI work um the AI word where um uh we will very soon start seeing um industrialization of AI where there are more and more AI agents and agentic solutions being being um designed and implemented uh which has started happening and um uh where agents start doing delivering more autonomously the end toend workflows right um there the question starts becoming um uh uh uh as to what is the role for these governance forums and and not I'm actually making it much broader for question not only limited to data governance but AI governance or architecture governance of others um where um businesses want to initi helps them to accelerate data idea quickly and to deliver them that much much faster right with with code generation and everything um etc uh and now you have started seeing AI models which can do potentially even independent autonomous security reviews etc [snorts] of the code right which means that and the expectation is that governance needs to start becoming much more automated and part of the workflow as right uh work delivery part of the CI/CD process itself as much as possible Right. And how do you see then data governance in in this context uh or AI governance as if you want to provide a view on that needs to evolve so that these things become much more automated all these governance audits and decision making processes.
[00:40:21]
>> So I I I think that the perhaps the the big perhaps it's it's not a change as such but perhaps something we need to become more mature in is this risk assessment. So I've always um said that looking at risks to data and the controls around it that we put in to m mitigate those are part of data governance but they tend to be things that I only see organizations that have been doing data governance a long time so really mature or are doing it often for regulatory requirements because the regulator has asked them to look at risks and controls. But I I think that's how we're going to strike this balance that you know you're talking about between how can we auto because if we automate there's going to be some risk >> and I think I think whereas um you know in the past we might just say oh well we got to do this I think we're going to have to perhaps make sure that particularly our data governance forums which are usually made up of business people with a few others like the data governance team and like yourself I would I would always invite along to advise people but I I think they're going to have to set risk appetites. I think risk appetite has traditionally been sent only by risk teams, but I think the business users have to start or like the data owners, the data stewards start having some input into that to say because there's there's going to be some things that it's absolutely okay to automate. And I think my I I I like to simplify everything. So I always go let's simplify let's automate the the boring stuff and anything that needs human consideration.
[00:41:52]
um you know let let's automate it and I think what we have to do is is get people understanding that as part of that perhaps those governance forums is to look at the risk is it acceptable that we do this um and I think back to my very very early days on the bank that I I worked at for many years and when I was in a branch uh I was with the people who would say I mean it shows you how long checks were were wholesale but you know they'd be walking around with checks going oh got enough money in his account. Um, but let me have a look. Oh, no. This is the first time this has ever happened and it looks like some money that normally comes in hasn't come. That looks like a genuine mistake. Shall I ring Symmetra up and ask? You go, "Yes, I'm so sorry. My employer had a problem. The money's coming in later today." And they go, "It's fine. We won't bounce a check, Symmetra." Um, and it was all heavily manual. Notes would be written up to say, "I've spoken to a nice chat. Genuine mistake kind of thing." These days that is all automated.
[00:42:50]
Nobody looks at it to say we're bouncing your direct debit or it's a computer. >> Um that happens and I I get I because I'm I'm you know I don't like doing things wrong. Every month I get a text to tell me that my account's going overdrawn and every month I panic and I open up my banking app to realize that it takes all the debits out before it counts the credit. So on my salary comes in but so so does the mortgage and all the other bills go out. It takes out all the debits, sends the text, puts the credit in. And this is all happening in the middle of the night. So by the time I check my account saying credit and I just go and you go honestly, but but that is, you know, they obviously they know that that happens and they look and they don't bounce anything. But they've at time they've tweaked that over the years to go from being heavily manual to we look at things. But that does mean that they do bounce and stop payments for a lot more people than they ever used to because there's no human element. But they've decided the risk of that's worth it. It's worth balancing the replication to the overhead um that we'd rather go.
[00:43:56]
But you know, and I think we've got to do that with all of our data and go through that process, but much quicker than the banks did from moving to that being manual. We've got we can't go, you know, once a month and go, "Right, so we're thinking about using AI for this." So we need people to say how sens and it's might well be using the classifications. We've got the data security ones. We know if it's um personal data that we need to be careful for and perhaps now we use our materiality or criticality from data governance. And perhaps we start using an amalgamation of it to say if all of the data is critical and sensitive it must have a human in the loop. But if it's all low we don't care. We'll take the we'll take the gamble. And I think that's have a lot more humans setting the risk appetite for things. >> Yeah. Yeah. Yeah. Yeah. And part of that also is is being clear about the responsibility and accountability for data governance function. And um I wanted to uh quickly check with you one one specific responsibility or scope question for data governance function.
[00:44:59]
Um um when it comes to we we talked about air governance but when it comes to security governance and privacy governance right that is another topic we didn't discuss but um if based on your experience um I get the security governance is much more specialized and there are security teams but privacy governance have you seen that as a separate function within organizations or or u uh it's kind of part of broader data governance function. So I have I have worked with a couple of areas where they've tried to put or have put privacy on on the same as the data governance team. I don't think that works very well because data privacy is is much more than um data governance. I always we say that as data governance people we help the data and privacy teams meet some of their their regulatory requirements but we don't do everything and they do a lot more of the legal side of things and what's the legal um rationale that we have for using this data um and the privacy policies and consents and it's a it's it's another area of expertise I and I you know data governance is over more way more data than personal data it's over any data that's useful to have it over so I I I think generally in my experience they're done better being done by separate teams because we we're coming at it from slightly different angles but you do need to work closely together because otherwise you're going to be duplicating effort or even worse having a gap because I think you're doing it you think I'm doing like the data lineage you know we both got data lineage for for personal data but I think you're doing it because because you're the data privacy team and I think you know you think I'm doing because I'm the data governance team so I think we've got to be very closely aligned but I have not seen it work very well when it's done by one team.
[00:46:50]
>> Yeah. Yeah. Um yeah you are right and I have seen mostly privacy is being separate. Um but it it brings us to the the same question we discussed earlier as to the more governance forums and um we have that more overhead from business perspective because um the the questions around data residency and etc. Of course, privacy teams will be more interested, but maybe data governance teams also ask where data your data is hosted. Uh um right um what kind of data is hosted? Uh is it sensitive data that is being hosted offshore? Those kind of questions data governance team may be interested as well. [snorts] So I think yeah and I and I I have seen um a number of organizations where they have like one governance forum particularly from like privacy and um security and data governance I've seen put together um >> because it's for like the the business the the data owners information owners to be making decisions on and they can work well as long as you manage the agendas well and agree who's like chairing it because I I have seen another one where I I get it. The business users don't want to spend all their life in meetings. We don't want to spend all their life in meetings. Um so, you know, we we combined the the forums to make one. Um but then I had I did work with one where the data protection officer decided they wanted to chair it.
[00:48:20]
>> But then threearters of the agenda was about data privacy. Then there was some data security decisions and then we'd always go, "Oh, sorry. We ran out of time for data governance and we're going we were supposed to be merging, not just abandoning our stuff." So, I think we we've got to find clever ways of doing it. And I but I think this is where we can we can use we we need to really work hard and getting our data owners, information owners to understand what they can and can't make decisions on outside of these forums. We we've got to try and keep things moving so it's just little and often so it doesn't feel like a big ownerous thing and then work out what are the things that are wide impacting need a a big debate with perhaps experts like yourself and me also at the meeting. H yeah look [laughter] I'm I'm a bit conscious of time now Nicolola uh but a couple of quick questions before we wrap it up um one was around um uh the cultural aspects and what role data governance can play all right as and what you are seeing now data governance playing in terms of um increasing the the the data and AI literacy um within the organization not limiting to their team but the wider business area etc.
[00:49:37]
Do you see um data governance teams taking more proactively more responsibilities in this area? >> Definitely. Um I think that's that's coming becoming quite um I I think to begin with I felt like I kept having to keep remind clients I'm working with that was something they had to do whereas now people are saying right we're going to do um data literacy could you help us or or whatever. So I think that's very that's definitely something that's being driven by the data governance teams more and more and interestingly um I do think and I I think I mean our whole conversation I think um gives all the reasons why I think AI literacy needs to be rolled in with the data literacy. It should be data and AI literacy training not today about data and next week about AI. Um we need people to understand them together. And I was doing I was working with a consultancy to do some um AI sorry data literacy training for an organization last year and we went to meet the team to do some brainstorming and we got to the end of it and the co suddenly went oh actually one more thing we we've just started working on our AI governance policy and it's going to take weeks or months to to get it into place. um but we don't want to miss this opportunity to mention it. And so we didn't have loads in the data literacy program because they felt that they didn't know what their organization's stance was going to be on it. But we managed to we were trying to think of how can we get people to understand how important data is when it comes to AI and we just came up with the really simple analogy of you know when GPS and satnav first came out and there was all the horror stories actually there was one in the UK even last week of somebody um who an Amazon delivery van ended up in the estry with water this tide came in around it um so they do still happen where people just you know we know we don't blindly follow what our satnav or GPS PS says because if the map's updated or something, you end, you know, and you haven't updated your device, you could end up driving off a cliff into a river, into the sea, whatever. So, we know we shouldn't blindly follow our satnavs. And we need to be the same with our data and AI. We shouldn't be blindly following them. We need to be thinking about is this the right thing? Is this the right data? So, but I think you're right. I think the need the two need to be together and and even it doesn't matter if you're the most junior person in the organization.
[00:52:01]
I think everybody needs some basic data and AI literacy training now. >> Yeah. Yeah. Probably one one last question. Um uh this was this is more about uh how to effectively measure the success of this function data governance function and and the point you may mention earlier uh which is really great is uh we shouldn't be looking this as a just compliance check but a real business value enabler right um but the fact but what what it means that then you need to um u articulate to executives as to how you are going to measure the success of this function when you start talking about the business value. What kind of KPIs and metrics that you have started you think yes >> are important which data governance teams anyone listening to this podcast should >> yeah I I wish I knew the answer to this one 24 years I still haven't worked it out because I think that the trouble is we are going to solve problems by doing data governance at your organization but it's almost like until I start doing it I don't know what the problems are so I can't tell you what to go and measure and I This is the the real trouble. And the longer we've been doing it, it gets even harder because we go from fixing historic mistakes to preventing them happening in the future, which is it's exactly like data architecture, isn't it? We start getting the data architecture right and then things just work and then people we don't need you anymore and then things go wrong and there and I think that's exactly where we are. Um so it is really hard to measure. Um, I tell people the one of the earliest things you should do in your data governance initiative is to launch a data quality issue resolution process because there's no KPIs that I can tell you other than ones that measure the progress of implementing data governance which doesn't actually show you the value of implementing it.
[00:53:56]
It just shows you I found 10 data owners. I've got I know 300 data definitions in my catalog. That's not showing value. That's just showing progress in actually implementing it. So we need to find real problems and fix them. So we can say, you know, it was taking Symmetra two hours every week to do this particular process because the data was was always late or it was rubbish. You had to fix it. Find some missing data. So we we we literally have to start saying that or breaking down, you know, what's your grade? What's the average salary for your grade? Well, this is how much it's costing us per week in in inefficiencies or, you know, the reputational damage, the number of customer complaints. So, we've we've always it it's I've not found and I've asked so many different people and worked with different people over the years here. I can't say here's a set of three KPIs. They're the perfect ones.
[00:54:53]
But we need to really just get out there and solve some problems so that we can shout about it and prove that this isn't just Nicola with her rose tinted spectacles on going, "Oh, we'll make things better. We will make things better. We must make things better." And we can shout about what we've done, whether that's t time, money. Um but we need to actually explain that. >> Yeah. Yeah. Okay. Cool. So as we wrap up, Nicola um do any last um a kind of um parting advice to uh senior leaders um uh anyone listening to this podcast um who understand the that they need to uplift data governance function within their business but do not know where to start or how to approach that. Oh, so I would say I I think if if you you know if you don't know where to start, if you haven't got a clear burning issue that you want to start, I think you've got to take a step back and work out what are the drivers for your organization doing data governance and the drivers are not to have better quality data. Okay, if the answer makes you go so what? It's not the right answer. So we've got to think about why does our organization need data governance? So I often say look at the look at your corporate strategy. What are you trying to do? Are you trying to um reduce costs? Well, we can definitely help with that because we'll find all these manual workarounds that are happening because the data is not good enough or the data is being fixed. So you've got to work out why are we doing it? Have we got a new data platform being built and we want to make sure the data is good enough? Do we have a known issue with with something that you know perhaps perhaps we are a regulated area and our regulators not happy with the quality of the reports we're sending in and that's common but you know let's find that because that's what you need to start on. Um I I think and definitely a mistake I made in the early days and I see so many people make it. We go oh well Simitra is a nice trap chap and he thinks data governance is good. I'm going to go and help him and and yeah, great. You you're easy to work with. We do it, but nobody else cares. So, we need to find the things that that business people will understand and get their head around and go, "Wow, that team was wasting, you know, 30% of their time on manual workarounds because the data wasn't right in the system and they were, you know, exporting it, putting into an Excel spreadsheet, adding more data and all the kind of things we know people do. So, we need to kind of make it real for people, not this, you know, oh, we'll all have lovely data and live happily ever after, which is what I sadly did in the early days. We've got to make it very practical and understand what is it, what are the real benefits, what are the real problems you're going to solve and focus on them first rather than doing it for best practice reasons.
[00:57:39]
>> Yeah, Nicolola, thank you. uh this was really a grounded practical and I'm sure most relevant mostly relevant um conversation to the challenges organizations and business [music] are facing today uh particularly in this AI age. So thanks again um and to listeners I would also strongly advise to um [music] have a look and buy the the book from Nicola. uh is definitely a very structured practical guide as to how you should be uh designing a data governance framework which is much more tailored to your organization. Um so we're going to thank you. It was pleasure hosting you. If you found this discussion valuable, please follow and subscribe to Enterprise Tech Talk and thanks for listening. I look forward to seeing you in the [music] next
