Stage 6 summary. Governance and strategy
Stage 6 asks the question the previous five left open. Once an organisation can model, engineer, analyse and protect its data, who decides what happens to it, and on what evidence? Almost every failure blamed on bad data turns out to be an unallocated decision: nobody could say which definition of active customer was authoritative, and nobody had to approve the schema change that broke the regulatory extract. A policy naming no decision right is advice.
The stage moves outward in three steps. It starts inside the organisation, with decision rights, the roles that make them assignable, and the choice between a central team, domain ownership and the hybrid most organisations end up running. It then turns to law that compels sharing rather than merely permitting it, where the EU Data Act, the Data Governance Act and the UK smart data power each work differently and are routinely confused. It closes with publication and value: what open really requires, what FAIR demands of metadata, and how to argue the worth of a data asset.
What you carry out of this stage
- State governance as the allocation of decision rights and accountability, and assign owner, steward and custodian so that each decision has a name against it
- Choose between centralised, domain-owned and hybrid operating models on evidence about capability and queues rather than on the popularity of a pattern
- Place DAMA-DMBOK, ISO/IEC 38505-1, ISO/IEC 42001 and the EU AI Act's data duties correctly, and cite the edition you actually read
- Work the EU Data Act by date and by product line, and explain FRAND sharing terms and the cloud switching rights
- Tell the Data Governance Act apart from the Data Act, place the common European data spaces and the European Health Data Space, and state the UK smart data direction
- Distinguish open, shared and FAIR data, say what each FAIR principle demands of metadata, and describe what DCAT 3 adds to a catalogue
- Assess maturity with DCAM evidence, argue data value across direct, indirect and risk-reduction routes with the method stated, and retire the oil metaphor
Stage 6 rises from decision rights to the value a board agrees to fund
Stage 6 climbs: decision rights make sharing lawful, lawful sharing makes open publication safe, and open publication is what finally makes the value of data visible to a board that funds it.
Stage 6 climbs: decision rights make sharing lawful, lawful sharing makes open publication safe, and open publication is what finally makes the value of data visible to a board that funds it.
Governance is the allocation of decision rights, and the roles exist to make them assignable
Governance answers two questions about a data asset: who decides, and who answers for the outcome. The decisions are concrete. Which definition is authoritative when two systems disagree. Who approves access for a new purpose. What quality level is acceptable before a figure reaches a board pack. Whether a producer may make a change that breaks a downstream consumer. An organisation that cannot name the person holding each of those for a given asset does not have governance, whatever its policy library says.
Three roles make the allocation workable, and the split between them is the point rather than the titles. The owner is accountable: one named business role deciding purpose, access and acceptable quality, and answering when the asset causes harm. Stewards are responsible for meaning day to day, curating definitions, quality rules and the issue queue. Custodians run the platform and implement the controls the owner decided, which is a technical responsibility rather than an ownership claim. The test is unglamorous: for one named asset, say from records who approved its definition, who signs off access, and who owns the quality rule.
Centralised, domain-owned and hybrid are three answers to where decisions sit
A centralised model puts pipelines, definitions and quality with one team. It produces consistency and a single place to ask, and it becomes the queue every domain waits in, which is why organisations abandon it at a certain size rather than because it was wrong.
Data mesh, set out by Zhamak Dehghani from 2019, pushes ownership outward on four principles: domain ownership of the data, data treated as a product with a consumer and a service level, a self-serve platform that makes ownership affordable, and federated computational governance. That fourth principle is the one most often dropped, and dropping it is why mesh programmes produce inconsistency rather than autonomy. It keeps the rules that must hold everywhere global and encodes them in the platform, so mesh decentralises ownership of products, not the standards they must meet.
The hybrid is where most organisations land, and it is a design rather than a failure to choose. The centre supplies standards, platform, lineage and identity so that owning a data product is affordable; the domains own their products, definitions, quality and roadmap. Choose on evidence about how many domains can genuinely own a product, where the queue forms today, and whether the centre can supply a platform rather than a service desk.
The hybrid model: what the centre provides, what domains own
The centre owns standards, platform, lineage and identity; the domains own their products, quality, definitions and roadmap. Neither extreme survives contact with a real organisation.
The hybrid model wins because it splits the work by who can actually know the answer: the centre owns standards, platform, lineage and identity, and the domains own their products, quality, definitions and roadmap. Neither extreme survives contact with a real organisation.
The frameworks tell you how to decide and record, not which controls to buy
DAMA-DMBOK maps the knowledge areas of the discipline and is best used for vocabulary and scope rather than as a standard to certify against. Its current text is the 2024 revision of DAMA-DMBOK 2.0, which DAMA describes as a maintenance release improving clarity without altering the framework, so a citation to a third edition points at something that does not exist.
ISO/IEC 38505-1:2017 does what DMBOK does not, placing data inside the corporate governance frame where a governing body evaluates, directs and monitors its use. That makes data an accountability of the board rather than a task delegated to a team, and it is the standard to reach for when the argument is about who should be answering.
The artificial intelligence framing changes urgency rather than substance. ISO/IEC 42001:2023 supplies a management system for AI, and Article 10 of the EU AI Act places data governance duties on the training, validation and testing sets of high-risk systems, covering quality, provenance and bias examination. A model inherits every ambiguous definition, quality defect and unclear lawful basis in the data it learned from, at a speed no quarterly report ever exposed.
The EU Data Act arrives on four dates, and each one binds a different party
Regulation (EU) 2023/2854, the Data Act, gives the user of a connected product a right of access to the data its use generates, and a right to have the data holder pass it to a third party the user nominates. The recipient may be an independent repairer, an insurer or a competitor, with one exclusion: an undertaking designated as a gatekeeper under the Digital Markets Act is not eligible by this route.
It arrives on four dates rather than one, which is where most compliance mistakes start. It entered into force on 11 January 2024 and bound nobody to act. It became applicable on 12 September 2025, when the access duties and the matching user rights went live. From 12 September 2026 a design obligation attaches to connected products placed on the market after that date, requiring the data to be accessible by default in a structured, commonly used and machine readable form, securely and free of charge. From 12 January 2027 the switching charge rules change again. Two products in the same catalogue can therefore carry different obligations, so the record is held per product line and placement date.
Where a holder must make data available, the terms have to be fair, reasonable and non-discriminatory, and transparent. Non-discriminatory stops a holder quoting one price to an independent repair network and another to its own subsidiary. Two engineering consequences follow: the cost of serving a request has to be measurable, and one interface should serve every recipient class, because the cheapest way to prove non-discrimination is to have only one path with which to discriminate.
Each Data Act date binds a different set of parties
The EU Data Act arrives on four dates, not one: entry into force binds everyone and changes nothing, while the three later dates bind data holders and users, then product manufacturers, then cloud providers, so what decides your work is which date binds you.
The EU Data Act arrives on four dates, not one, and each date binds a different actor: everyone at entry into force, data holders and users when it becomes applicable, product manufacturers for design, and cloud providers for switching fees. Ask which date binds you before asking what the Act says.
The Data Governance Act enables, data spaces build the plumbing, and the UK route is a power rather than a duty
Regulation (EU) 2022/868, the Data Governance Act, entered into force on 23 June 2022 and has applied since 24 September 2023, and reading it as a mandate is the common error. It sets conditions for re-using protected public sector data, regulates the data intermediary, which must notify its activity, keep the service structurally separate and not use the data for its own purposes, and registers data altruism organisations. It creates no right to obtain data that national law keeps closed.
A data space is a sector-wide arrangement to share under common rules and infrastructure, covering health, energy, mobility, finance and agriculture, and the geometry that matters is that each sector draws on one shared interoperability core of identity and trust, vocabularies, access rules and audit. Health became law: Regulation (EU) 2025/327 on the European Health Data Space was adopted on 11 February 2025 and entered into force on 26 March 2025, separating primary use for care from secondary use served by permitted access rather than copies, with cross-border exchange of the first priority categories from March 2029.
The United Kingdom took a different route. The Data (Use and Access) Act 2025 gives ministers a power to require a business to pass customer data, at that customer's request, to an authorised third party, with each smart data scheme made sector by sector. Open Banking shows what a scheme needs beyond a duty to share: an authorisation model, a register of authorised third parties, common interfaces and a dispute route. A horizontal access right is scheduled by date; a scheme-making power by political priority.
Data is an asset with a portfolio, and the oil metaphor gets in the way of managing it
The Data Management Capability Assessment Model from the EDM Council is the common instrument for asking how capable an organisation is, and DCAM v3 was announced in June 2025 with stronger coverage of artificial intelligence, cloud and governance. Its components run from data strategy and the business case through architecture, business data knowledge, quality management, governance and operations to analytics management. What makes an assessment worth running is the evidence standard: a named owner, approved definitions, lineage to the reports that use the data, quality rules, access and retention policy, and usage metrics.
Value is argued along three routes. Direct value sells data or a data product, and it needs the legal work first, because lawful basis, purpose limitation and the sharing agreement decide whether the revenue survives scrutiny. Indirect value changes the quality, timing or economics of internal decisions, and it is where most realised value sits. Risk reduction value is expected loss avoided, net of false positives and the cost of the control. The caveats are real: data is not on the balance sheet in most jurisdictions, and the income approach needs instrumentation to attribute a saving to an asset.
That is why the oil metaphor gets in the way, and it fails in three places. Oil is rival and consumed by use, whereas a dataset serves many purposes at once without depletion, so the question is reuse rather than extraction. Oil has a market price largely independent of the buyer, whereas a dataset's worth depends on the question asked of it. And data depreciates, so a record held past its purpose carries retention, breach and migration cost rather than latent optionality. The chief data officer agenda follows: name the outcome constrained by poor data, the asset that changes it, its owner, the missing control, and the measure read afterwards.
Four strategic tiers for the data asset portfolio
Foundational, enabling, differentiating and monetisable name what a dataset is for, and the investment has to be tiered the same way. Spending the same on a run-the-business table as on one that could be licensed externally wastes the budget at both ends.
Data assets sit in four portfolio tiers: foundational (run the business), enabling (improve decisions), differentiating (competitive advantage), monetisable (sell or licence). DAMA-DMBOK 2 names the same four; investment should be tiered, not flat.
The traps this stage warns against
Adopting data mesh and reading it as permission for each domain to choose its own definitions, quality bar and standards.
Instead: The fourth principle is federated computational governance. Decentralise ownership of data products, keep the rules that must hold everywhere global, and encode them in the platform so conformance is automatic rather than requested.
Citing a third edition of DMBOK, or quoting a framework without saying which edition was read.
Instead: The current text is the 2024 revision of DAMA-DMBOK 2.0, a maintenance release rather than a new edition. Cite the edition in front of you, and use DMBOK for knowledge areas rather than as something to certify against.
Running one legal review of the EU Data Act on its applicability date, filing the memorandum, and treating the company as compliant.
Instead: Obligations attach per product and per placement date, so the design duty from 12 September 2026 reaches some product lines and not others. The artefact that answers the question is a register of what you sell and when each line was placed on the market.
Treating the Data Governance Act as a mandate that entitles a business to obtain public sector data.
Instead: It sets conditions for re-use and regulates intermediaries and data altruism organisations; it creates no right to obtain anything national law keeps closed. The Data Act is the instrument that compels, and the two are not interchangeable.
Publishing a spreadsheet on a departmental website and describing the dataset as open.
Instead: Without an explicit licence, copyright applies by default and nobody has permission to reuse it. Open needs legal, technical and practical openness together, so state the licence, publish a format that can be processed without proprietary software, and describe the fields.
Presenting a data valuation figure in a business case without stating how it was produced.
Instead: Say whether it came from the cost, market or income approach, name the direct, indirect or risk-reduction route, and show the instrumentation that attributes the revenue or the avoided loss to that specific asset.
Core distinctions
- Governance is the allocation of decision rights and accountability; a policy that names no decision-maker for a named asset is advice rather than governance
- The owner is accountable and decides, the steward is responsible for meaning day to day, and the custodian runs the platform and implements the controls
- Data mesh decentralises ownership of data products but keeps governance federated and computational, so global standards stay global
- DMBOK maps knowledge areas, ISO/IEC 38505-1 puts data use under the governing body, and ISO/IEC 42001 supplies a management system for artificial intelligence
- The Data Act compels access and sets FRAND terms; the Data Governance Act enables re-use and regulates intermediaries, and neither displaces data protection law
- A horizontal EU access right is scheduled by date, whereas a UK smart data scheme exists only once secondary legislation makes it for that sector
- Open data is about permission and access for anyone, shared data is access for named parties under agreed terms, and FAIR is about reuse, so a dataset can be FAIR and closed
- DCAT 3 describes catalogue metadata for datasets, services and distributions; ownership, support, quality rules and change policy come from local governance and data contracts
- Direct, indirect and risk-reduction value are three different arguments, and the cost, market and income approaches are three different methods, so a valuation must name both
That is Stage 6 in one place. Decision rights allocated to named roles, an operating model chosen against capability and queues rather than fashion, the frameworks placed by what each one is for, sharing law separated into what compels and what enables and tracked by date and product line, open and shared and FAIR kept apart with the metadata each demands, and value argued with a stated method instead of a metaphor. The scenario practice now puts those judgements under pressure with situations where an operating model, a legal clock and a business case pull against each other, which is the shape the decisions take in a real organisation.
Sources and further reading
- DAMA International: DMBOK revisionConfirms the current text as the 2024 revision of DAMA-DMBOK 2.0 and describes it as a maintenance release.
- ISO/IEC 38505-1:2017, Governance of dataPlaces data use under the governing body's evaluate, direct and monitor model rather than inside a delivery team.
- ISO/IEC 42001:2023, Artificial intelligence management systemThe management system standard behind the AI-readiness framing of governance in this stage.
- Regulation (EU) 2024/1689, Article 10: data and data governanceThe data quality, provenance and bias duties on training, validation and testing sets for high-risk AI systems.
- W3C: Data Catalog Vocabulary (DCAT) version 3W3C Recommendation of 22 August 2024, adding dataset series, versioning properties and checksums over DCAT 2.
- Wilkinson et al., The FAIR Guiding Principles for scientific data management and stewardshipThe 2016 Scientific Data paper that defines findable, accessible, interoperable and reusable and what each demands of metadata.
- Open Knowledge Foundation: Open Definition 2.1The definition behind the legal, technical and practical dimensions of open data used in this stage.
- EDM Council: announcing DCAM v3The June 2025 announcement of the capability assessment model and its coverage of AI, cloud, governance and security.
- GOV.UK: National Data Library progress update, January 2026The completed discovery phase, the funding allocated, the five pilots, and the commitment to set out more detail in spring 2026.