Governance thin enough that people follow it.
A framework nobody follows scores the same as no framework at all — except you paid for it and now believe you're covered. We design for the organisation you have.
Most governance fails on adoption, not design.
The typical failure looks like this: a comprehensive framework is approved by a steering committee, a policy document is published, a council is scheduled monthly, and eighteen months later nothing measurable has changed. The framework wasn't wrong. It was simply more governance than the organisation had the appetite or the headcount to operate.
We work backwards from what your organisation will actually do. That usually means less policy, fewer forums, more named accountability, and controls enforced by systems rather than by people remembering.
Where we start
Ownership, always. “The business owns it” is the single most common finding in an assessment and the single most expensive one, because it means every dispute about a definition has nowhere to go and quietly resolves itself in favour of whoever shouts. A named steward per domain, with real authority and time allocated, changes more than any document.
From there: classification that maps to how your data is actually handled, policy written short enough to be read, and controls placed where the data moves rather than where the org chart says they belong.
Making it survive us
Governance decays quietly — a steward moves roles, a policy passes its review date, a new system arrives outside the process. So we build the decay into view: review dates on everything, orphaned-ownership reporting, and a small set of measures that show whether the thing is working. If your governance can only be assessed by asking a consultant, it isn't governed.
- Cadence
- 6-month blocks
- First lever
- Named ownership
- Policy
- Short, enforced
- Forums
- As few as possible
- Measurement
- Built in, not bolted on
- Regulatory
- Mapped to your obligations
Where you carry specific obligations — Privacy Act and the Australian Privacy Principles, records legislation, sector regulation — we map controls to them explicitly, so an auditor can trace a requirement to the control that satisfies it.
What gets stood up.
- Ownership & stewardship modelNamed accountability per domain, with the decision rights and the time commitment written down.
- Policy setShort, specific and enforceable. Rewritten to be read, not to be comprehensive.
- Classification schemeSensitivity tiers that map to how data is actually handled, stored and shared in your environment.
- Control designAccess, retention, sharing and quality controls placed where data moves — enforced by systems where possible.
- Regulatory mappingYour obligations traced to the specific controls that satisfy them, ready for an auditor.
- Issue & exception processA route for raising, deciding and closing data disputes, with someone empowered to make the call.
- Governance measuresA small set of indicators — ownership coverage, policy review currency, issue ageing, quality trend.
- Operating rhythmThe minimum forum and reporting cadence that keeps it alive, and no more.
Worth knowing before you buy.
We already have a governance framework. Is it wasted?+
Do we need a data governance platform?+
How do you handle AI and analytics use of our data?+
Start with the assessment.
Two to three weeks. You get a map of your systems, named owners, a ranked list of gaps, and a costed 6-month plan. No obligation to run it with us.