Stage 6 summary. Governance and strategy

8 min 7 concepts 4 figures

Stage 6 asks the question the previous five left open. Once an organisation can model, engineer, analyse and protect its data, who decides what happens to it, and on what evidence? Almost every failure blamed on bad data turns out to be an unallocated decision: nobody could say which definition of active customer was authoritative, and nobody had to approve the schema change that broke the regulatory extract. A policy naming no decision right is advice.

The stage moves outward in three steps. It starts inside the organisation, with decision rights, the roles that make them assignable, and the choice between a central team, domain ownership and the hybrid most organisations end up running. It then turns to law that compels sharing rather than merely permitting it, where the EU Data Act, the Data Governance Act and the UK smart data power each work differently and are routinely confused. It closes with publication and value: what open really requires, what FAIR demands of metadata, and how to argue the worth of a data asset.

What you carry out of this stage

  • State governance as the allocation of decision rights and accountability, and assign owner, steward and custodian so that each decision has a name against it
  • Choose between centralised, domain-owned and hybrid operating models on evidence about capability and queues rather than on the popularity of a pattern
  • Place DAMA-DMBOK, ISO/IEC 38505-1, ISO/IEC 42001 and the EU AI Act's data duties correctly, and cite the edition you actually read
  • Work the EU Data Act by date and by product line, and explain FRAND sharing terms and the cloud switching rights
  • Tell the Data Governance Act apart from the Data Act, place the common European data spaces and the European Health Data Space, and state the UK smart data direction
  • Distinguish open, shared and FAIR data, say what each FAIR principle demands of metadata, and describe what DCAT 3 adds to a catalogue
  • Assess maturity with DCAM evidence, argue data value across direct, indirect and risk-reduction routes with the method stated, and retire the oil metaphor

Stage 6 rises from decision rights to the value a board agrees to fund

Stage 6 climbs: decision rights make sharing lawful, lawful sharing makes open publication safe, and open publication is what finally makes the value of data visible to a board that funds it.

Stage 6 climbs: decision rights make sharing lawful, lawful sharing makes open publication safe, and open publication is what finally makes the value of data visible to a board that funds it.

Stage 6 rises from decision rights to the value a board agrees to fund A rising staircase of four Stage 6 module cards, read from the bottom left step upwards. Bottom step, Governance and roles: who decides and who answers. Second step, Data sharing law: what you must now share. Third step, Open data and FAIR: what you publish for anyone. Top step, Data as an asset, tinted red: what the board should fund. An arrow rises into each step carrying the question that step answers, and an entry arrow at the foot carries the first question. A red-accented card to the right of the bottom step summarises the climb. STAGE 6 ROUTE · READ IT FROM THE BOTTOM STEP UP Each step needs the one below it to be true. MODULE 1 Governance and roles Who decides and who answers MODULE 2 Data sharing law What you must now share MODULE 3 Open data and FAIR What you publish for anyone MODULE 4 Data as an asset What the board should fund who decides what? what must we share by law? what do we publish openly? what should the board fund? The route ends in a budget Decision rights, then sharing law, then open publication, then value.

Governance is the allocation of decision rights, and the roles exist to make them assignable

Governance answers two questions about a data asset: who decides, and who answers for the outcome. The decisions are concrete. Which definition is authoritative when two systems disagree. Who approves access for a new purpose. What quality level is acceptable before a figure reaches a board pack. Whether a producer may make a change that breaks a downstream consumer. An organisation that cannot name the person holding each of those for a given asset does not have governance, whatever its policy library says.

Three roles make the allocation workable, and the split between them is the point rather than the titles. The owner is accountable: one named business role deciding purpose, access and acceptable quality, and answering when the asset causes harm. Stewards are responsible for meaning day to day, curating definitions, quality rules and the issue queue. Custodians run the platform and implement the controls the owner decided, which is a technical responsibility rather than an ownership claim. The test is unglamorous: for one named asset, say from records who approved its definition, who signs off access, and who owns the quality rule.

Centralised, domain-owned and hybrid are three answers to where decisions sit

A centralised model puts pipelines, definitions and quality with one team. It produces consistency and a single place to ask, and it becomes the queue every domain waits in, which is why organisations abandon it at a certain size rather than because it was wrong.

Data mesh, set out by Zhamak Dehghani from 2019, pushes ownership outward on four principles: domain ownership of the data, data treated as a product with a consumer and a service level, a self-serve platform that makes ownership affordable, and federated computational governance. That fourth principle is the one most often dropped, and dropping it is why mesh programmes produce inconsistency rather than autonomy. It keeps the rules that must hold everywhere global and encodes them in the platform, so mesh decentralises ownership of products, not the standards they must meet.

The hybrid is where most organisations land, and it is a design rather than a failure to choose. The centre supplies standards, platform, lineage and identity so that owning a data product is affordable; the domains own their products, definitions, quality and roadmap. Choose on evidence about how many domains can genuinely own a product, where the queue forms today, and whether the centre can supply a platform rather than a service desk.

The hybrid model: what the centre provides, what domains own

The centre owns standards, platform, lineage and identity; the domains own their products, quality, definitions and roadmap. Neither extreme survives contact with a real organisation.

The hybrid model wins because it splits the work by who can actually know the answer: the centre owns standards, platform, lineage and identity, and the domains own their products, quality, definitions and roadmap. Neither extreme survives contact with a real organisation.

The hybrid model: what the centre provides, what domains own Two regions. Centre: an emphasised platform and governance hub listing standards and vocabularies, platform and pipelines, lineage and catalogue, and identity and access. Around it four domain cards, supply chain, customer, finance and operations, each naming what it owns. Four labelled arrows run from each domain to the hub reading owns its products, owns its quality, owns its definitions and owns its roadmap. Left and right of the hub, two quiet inset cards name the failure extremes: everything central becomes a request queue, everything devolved loses interoperability. THE DIVISION OF LABOUR, NOT A CONTEST BETWEEN EXTREMES THE CENTRE PROVIDESPlatform and governance hubStandards and vocabulariesPlatform and pipelinesLineage and catalogueIdentity and access THE DOMAIN OWNSSupply chain domainProducts and contracts THE DOMAIN OWNSCustomer domainQuality and freshness THE DOMAIN OWNSFinance domainMetric definitions THE DOMAIN OWNSOperations domainRoadmap and support owns its products owns its quality owns its definitions owns its roadmap Everything centralBecomes a request queue Everything devolvedLoses interoperability

The frameworks tell you how to decide and record, not which controls to buy

DAMA-DMBOK maps the knowledge areas of the discipline and is best used for vocabulary and scope rather than as a standard to certify against. Its current text is the 2024 revision of DAMA-DMBOK 2.0, which DAMA describes as a maintenance release improving clarity without altering the framework, so a citation to a third edition points at something that does not exist.

ISO/IEC 38505-1:2017 does what DMBOK does not, placing data inside the corporate governance frame where a governing body evaluates, directs and monitors its use. That makes data an accountability of the board rather than a task delegated to a team, and it is the standard to reach for when the argument is about who should be answering.

The artificial intelligence framing changes urgency rather than substance. ISO/IEC 42001:2023 supplies a management system for AI, and Article 10 of the EU AI Act places data governance duties on the training, validation and testing sets of high-risk systems, covering quality, provenance and bias examination. A model inherits every ambiguous definition, quality defect and unclear lawful basis in the data it learned from, at a speed no quarterly report ever exposed.

The EU Data Act arrives on four dates, and each one binds a different party

Regulation (EU) 2023/2854, the Data Act, gives the user of a connected product a right of access to the data its use generates, and a right to have the data holder pass it to a third party the user nominates. The recipient may be an independent repairer, an insurer or a competitor, with one exclusion: an undertaking designated as a gatekeeper under the Digital Markets Act is not eligible by this route.

It arrives on four dates rather than one, which is where most compliance mistakes start. It entered into force on 11 January 2024 and bound nobody to act. It became applicable on 12 September 2025, when the access duties and the matching user rights went live. From 12 September 2026 a design obligation attaches to connected products placed on the market after that date, requiring the data to be accessible by default in a structured, commonly used and machine readable form, securely and free of charge. From 12 January 2027 the switching charge rules change again. Two products in the same catalogue can therefore carry different obligations, so the record is held per product line and placement date.

Where a holder must make data available, the terms have to be fair, reasonable and non-discriminatory, and transparent. Non-discriminatory stops a holder quoting one price to an independent repair network and another to its own subsidiary. Two engineering consequences follow: the cost of serving a request has to be measurable, and one interface should serve every recipient class, because the cheapest way to prove non-discrimination is to have only one path with which to discriminate.

Each Data Act date binds a different set of parties

The EU Data Act arrives on four dates, not one: entry into force binds everyone and changes nothing, while the three later dates bind data holders and users, then product manufacturers, then cloud providers, so what decides your work is which date binds you.

The EU Data Act arrives on four dates, not one, and each date binds a different actor: everyone at entry into force, data holders and users when it becomes applicable, product manufacturers for design, and cloud providers for switching fees. Ask which date binds you before asking what the Act says.

Each Data Act date binds a different set of parties Three regions. Top: four station cards, each a date and its obligation. Station 1, 11 January 2024, entry into force, outlined in grey because nothing binds yet. Station 2, 12 September 2025, applicable. Station 3, 12 September 2026, design obligations for products placed on the market. Station 4, 12 January 2027, switching fees end. Middle: a spine of four numbered ticks tied to the cards by dashed leaders and joined by red arrows labelled duties become live, adds a design duty, adds an exit duty. Bottom: a chip under each tick naming who that date binds, in order all parties, data holders and users, product manufacturers, cloud providers. EU DATA ACT · FOUR DATES · WHO EACH BINDSnot yet bindingbinding from that date STATION 111 January 2024Entry into forceThe rules existbut do not bite STATION 212 September 2025ApplicableAccess and useduties start STATION 312 September 2026Design obligationsfor products placedon the market STATION 412 January 2027Switching fees endCharges for cloudswitching stop 1 2 3 4 duties become liveadds a design dutyadds an exit duty BINDSall parties BINDSdata holders and users BINDSproduct manufacturers BINDScloud providers

The Data Governance Act enables, data spaces build the plumbing, and the UK route is a power rather than a duty

Regulation (EU) 2022/868, the Data Governance Act, entered into force on 23 June 2022 and has applied since 24 September 2023, and reading it as a mandate is the common error. It sets conditions for re-using protected public sector data, regulates the data intermediary, which must notify its activity, keep the service structurally separate and not use the data for its own purposes, and registers data altruism organisations. It creates no right to obtain data that national law keeps closed.

A data space is a sector-wide arrangement to share under common rules and infrastructure, covering health, energy, mobility, finance and agriculture, and the geometry that matters is that each sector draws on one shared interoperability core of identity and trust, vocabularies, access rules and audit. Health became law: Regulation (EU) 2025/327 on the European Health Data Space was adopted on 11 February 2025 and entered into force on 26 March 2025, separating primary use for care from secondary use served by permitted access rather than copies, with cross-border exchange of the first priority categories from March 2029.

The United Kingdom took a different route. The Data (Use and Access) Act 2025 gives ministers a power to require a business to pass customer data, at that customer's request, to an authorised third party, with each smart data scheme made sector by sector. Open Banking shows what a scheme needs beyond a duty to share: an authorisation model, a register of authorised third parties, common interfaces and a dispute route. A horizontal access right is scheduled by date; a scheme-making power by political priority.

Open, shared and FAIR are three different promises, and metadata is what makes any of them true

The Open Definition 2.1 holds that data is open if anyone is free to use, modify and share it for any purpose, and three dimensions must hold at once. Legally open means a licence actually grants those permissions, since posting a file leaves copyright in place. Technically open means a format processable without proprietary software, so a table trapped in a PDF is legally open and technically closed. Practically open means discoverable and described. Shared data is narrower, being access for named parties under agreed terms, and FAIR is a different promise, about reuse rather than permission.

The FAIR principles, published by Wilkinson and colleagues in Scientific Data in 2016, each bind to concrete metadata. Findable needs a globally unique persistent identifier and indexed metadata. Accessible needs that identifier to resolve over a standardised, open protocol, with metadata reachable even where the data is restricted, so it is about mechanism rather than price. Interoperable needs shared vocabularies and qualified references. Reusable needs provenance, a clear licence and domain standards, and it fails most often because it costs somebody the time to describe their data to a stranger.

DCAT 3 became a W3C Recommendation on 22 August 2024 and describes datasets, services and distributions so catalogues can interoperate, adding dataset series, versioning properties and checksums. It stops at catalogue metadata, so ownership, support, quality rules and change policy still come from local governance and a data contract. In the United Kingdom the public infrastructure is mid-programme: data.gov.uk has been recast as the National Data Library, whose January 2026 progress update records a completed discovery phase, over 100 million pounds allocated, five pilots, and more detail promised in spring 2026.

Open, shared, and FAIR: three distinct promises

Open means public access with a licence, shared means named parties on controlled terms, and FAIR is a reuse lens rather than an access rule, so a restricted dataset can still be FAIR and its findable metadata lets a researcher ask for access.

Open data, shared data, and FAIR data are three different promises. Open removes access restrictions; shared limits access to named parties; FAIR is a reuse lens that works even when access is restricted. Wilkinson et al. 2016 fixed the FAIR principles formally; the UK ICO data sharing code distinguishes shared from open.

Open, shared, and FAIR are three different promises Four comparison cards. Open: public access plus clear licence. Shared: known parties plus controlled terms. FAIR: findable, accessible, interoperable, reusable (emphasised in red soft). Boundary: who can access and why. Brand-red arrows between adjacent cards labelled not same as, improved by, checked through. A red-accent callout names FAIR as a reuse lens, not a shortcut around privacy. OPEN vs SHARED vs FAIR vs BOUNDARY · THREE DIFFERENT PROMISES 1W3C DWBP §6OpenPublic access, clearlicence2ICO 2022SharedKnown parties,controlled terms3Wilkinson 2016FAIRFindable + reusable4UK GDPR Art.5Access boundaryWho can access andwhy not same asimproved bychecked through FAIR is a reuse lens, not a shortcut around access A dataset can be FAIR and restricted. Findable metadata about restricted data is the value: aresearcher can ask for access knowing the data exists.

Data is an asset with a portfolio, and the oil metaphor gets in the way of managing it

The Data Management Capability Assessment Model from the EDM Council is the common instrument for asking how capable an organisation is, and DCAM v3 was announced in June 2025 with stronger coverage of artificial intelligence, cloud and governance. Its components run from data strategy and the business case through architecture, business data knowledge, quality management, governance and operations to analytics management. What makes an assessment worth running is the evidence standard: a named owner, approved definitions, lineage to the reports that use the data, quality rules, access and retention policy, and usage metrics.

Value is argued along three routes. Direct value sells data or a data product, and it needs the legal work first, because lawful basis, purpose limitation and the sharing agreement decide whether the revenue survives scrutiny. Indirect value changes the quality, timing or economics of internal decisions, and it is where most realised value sits. Risk reduction value is expected loss avoided, net of false positives and the cost of the control. The caveats are real: data is not on the balance sheet in most jurisdictions, and the income approach needs instrumentation to attribute a saving to an asset.

That is why the oil metaphor gets in the way, and it fails in three places. Oil is rival and consumed by use, whereas a dataset serves many purposes at once without depletion, so the question is reuse rather than extraction. Oil has a market price largely independent of the buyer, whereas a dataset's worth depends on the question asked of it. And data depreciates, so a record held past its purpose carries retention, breach and migration cost rather than latent optionality. The chief data officer agenda follows: name the outcome constrained by poor data, the asset that changes it, its owner, the missing control, and the measure read afterwards.

Four strategic tiers for the data asset portfolio

Foundational, enabling, differentiating and monetisable name what a dataset is for, and the investment has to be tiered the same way. Spending the same on a run-the-business table as on one that could be licensed externally wastes the budget at both ends.

Data assets sit in four portfolio tiers: foundational (run the business), enabling (improve decisions), differentiating (competitive advantage), monetisable (sell or licence). DAMA-DMBOK 2 names the same four; investment should be tiered, not flat.

Four strategic tiers for the data asset portfolio Four cards left to right: Foundational (run the business), Enabling (improve decisions), Differentiating (competitive advantage, emphasised), Monetisable (sell or licence). Verb arrows step up the tiers. A red-accent callout names flat investment as the strategic failure. DATA AS STRATEGIC ASSET · FOUR PORTFOLIO TIERS 1DMBOK 2FoundationalRun-the-businessdatasets2DMBOK 2EnablingImprove internaldecisions3DMBOK 2DifferentiatingCompetitive advantage4ISO 8000-100MonetisableSell or licenceexternally thenthenthen Flat investment is the strategic failure Spending the same on the customer table as on the dataset that runs the regulator report wastes both.Tier the investment.

The traps this stage warns against

  • Adopting data mesh and reading it as permission for each domain to choose its own definitions, quality bar and standards.

    Instead: The fourth principle is federated computational governance. Decentralise ownership of data products, keep the rules that must hold everywhere global, and encode them in the platform so conformance is automatic rather than requested.

  • Citing a third edition of DMBOK, or quoting a framework without saying which edition was read.

    Instead: The current text is the 2024 revision of DAMA-DMBOK 2.0, a maintenance release rather than a new edition. Cite the edition in front of you, and use DMBOK for knowledge areas rather than as something to certify against.

  • Running one legal review of the EU Data Act on its applicability date, filing the memorandum, and treating the company as compliant.

    Instead: Obligations attach per product and per placement date, so the design duty from 12 September 2026 reaches some product lines and not others. The artefact that answers the question is a register of what you sell and when each line was placed on the market.

  • Treating the Data Governance Act as a mandate that entitles a business to obtain public sector data.

    Instead: It sets conditions for re-use and regulates intermediaries and data altruism organisations; it creates no right to obtain anything national law keeps closed. The Data Act is the instrument that compels, and the two are not interchangeable.

  • Publishing a spreadsheet on a departmental website and describing the dataset as open.

    Instead: Without an explicit licence, copyright applies by default and nobody has permission to reuse it. Open needs legal, technical and practical openness together, so state the licence, publish a format that can be processed without proprietary software, and describe the fields.

  • Presenting a data valuation figure in a business case without stating how it was produced.

    Instead: Say whether it came from the cost, market or income approach, name the direct, indirect or risk-reduction route, and show the instrumentation that attributes the revenue or the avoided loss to that specific asset.

Core distinctions

  • Governance is the allocation of decision rights and accountability; a policy that names no decision-maker for a named asset is advice rather than governance
  • The owner is accountable and decides, the steward is responsible for meaning day to day, and the custodian runs the platform and implements the controls
  • Data mesh decentralises ownership of data products but keeps governance federated and computational, so global standards stay global
  • DMBOK maps knowledge areas, ISO/IEC 38505-1 puts data use under the governing body, and ISO/IEC 42001 supplies a management system for artificial intelligence
  • The Data Act compels access and sets FRAND terms; the Data Governance Act enables re-use and regulates intermediaries, and neither displaces data protection law
  • A horizontal EU access right is scheduled by date, whereas a UK smart data scheme exists only once secondary legislation makes it for that sector
  • Open data is about permission and access for anyone, shared data is access for named parties under agreed terms, and FAIR is about reuse, so a dataset can be FAIR and closed
  • DCAT 3 describes catalogue metadata for datasets, services and distributions; ownership, support, quality rules and change policy come from local governance and data contracts
  • Direct, indirect and risk-reduction value are three different arguments, and the cost, market and income approaches are three different methods, so a valuation must name both

That is Stage 6 in one place. Decision rights allocated to named roles, an operating model chosen against capability and queues rather than fashion, the frameworks placed by what each one is for, sharing law separated into what compels and what enables and tracked by date and product line, open and shared and FAIR kept apart with the metadata each demands, and value argued with a stated method instead of a metaphor. The scenario practice now puts those judgements under pressure with situations where an operating model, a legal clock and a business case pull against each other, which is the shape the decisions take in a real organisation.

Sources and further reading