Data Governance: What It Is, and What It Means for Marketing Data

Data governance is the rules, roles and controls that make data trustworthy. Here's what a program contains — and what changes for marketing data.

Kaden Carroll9 min readPillar
Open boxes spilling papers beside identical filing folders in neat rows

Data governance is the set of rules, roles and controls that decide how data is defined, created, checked and used — so that the people relying on it can trust what it says.

Most governance writing assumes the data already sits in a warehouse. Marketing data does not. It is created upstream, by many hands, in the ad platforms themselves, and by the time it reaches the warehouse the decisions that determined its quality were made weeks earlier by someone who has moved on to the next launch.

What is data governance?

The rules, roles and controls that keep data trustworthy enough to act on.

Governance answers four questions about every piece of data that matters: what it means, who owns it, what counts as correct, and what happens when something is wrong. The enterprise definition is stable across publishers (IBM, “What is data governance?”, accessed 2026-09-11).

Where the published treatments differ from practice is scope. They describe governance as something applied to data at rest: cataloged, access-controlled, lineage-tracked. That is real and necessary. It is also downstream of every decision that determines whether the data was worth governing.

The four pillars

Ownership, definitions, quality standards, and enforcement.

PillarDecidesFails as
OwnershipWho is accountable for this data domain, and who may approve a changeA RACI nobody consults; decisions escalate or stall
DefinitionsWhat each field means, in business languageTwo teams reporting different numbers and both being right
Quality standardsWhat counts as a correct value, and how it is measuredA dashboard of green checks over data nobody trusts
EnforcementWhere the rule is applied, and what happens when it is brokenA published policy with no mechanism; compliance decays quietly

Informatica’s treatment of the pillar taxonomy is representative of the standard framing (Informatica, “What Is Data Governance?”, accessed 2026-09-11).

The fourth pillar is where programs actually fail. Ownership, definitions and standards are all decisions, and decisions are the part organizations are good at making in a workshop. Enforcement is a systems problem, it sits with a different team, and it is routinely treated as an implementation detail to be worked out later.

The framework in detail: Read: data governance framework — how the pillars assemble into an operating model.

A worked example

One data domain, its owner, its definitions, its allowed values and its check.

Abstraction is what makes governance hard to start. Here is a single domain, fully specified.

Domain: campaign metadata. Owner: Director, Marketing Operations. Approves new permitted values; accountable for the domain as a whole. Steward: Campaign Operations Manager. Maintains the definitions and handles day-to-day value requests.

FieldDefinitionAllowed valuesCheckApplied
channelThe media category the placement ran in8 values, closed listValue must be in listCampaign setup form
marketThe country the placement targetedISO 3166-1 alpha-2Format and list checkCampaign setup form
campaign_nameThe initiative this placement belongs toPattern {region}_{brand}_{initiative}_{YYYYQn}RegexCampaign setup form
agencyThe partner that built the placementApproved partner list, owned by ProcurementValue must be in listCampaign setup form

Escalation: a request for a ninth channel value goes to the owner, is decided within five working days, and is recorded with a date and rationale.

That is a governance program. It fits on a page, it names people rather than functions, and every rule has a place where it is applied. Scaling it means repeating it per domain, not replacing it with something more elaborate.

At enterprise scale

Federated ownership across regions, brands and third parties.

At scale the single-owner model breaks, and the usual replacement — a central governance team owning everything — breaks differently. Central teams become bottlenecks, regions route around them, and the governance program becomes something that happens to other people.

Federated governance keeps a central function for the decisions that must be global (which domains exist, which fields are enterprise-wide, how conflicts resolve) and pushes value-level authority to the people closest to the work. A regional lead can add a market-specific value without a global forum. Nobody can add a new dimension without one.

Two failure modes are worth naming. Over-centralization produces a queue and a shadow taxonomy. Over-federation produces twelve regional variants of the same field and a reconciliation project. The boundary between them is not a principle; it is a list, and writing that list down is most of the work.

Taxonomy governance, ownership and change management comes up across 63 enterprise accounts in our customer conversations, and it is consistently the ownership question rather than the taxonomy question that stalls programs.

Standards vs policies vs procedures

A policy says what must be true; a standard says exactly what “true” looks like; a procedure says who does what.

PolicyStandardProcedure
StatesAn intention or obligationA specific, checkable requirementA sequence of actions
Example“Every campaign must record its channel”“channel must be one of these eight values”“Request a new value via the intake form; owner decides in five days”
AudienceThe organizationSystems and the people entering dataThe people operating the process
Machine-checkableNoYesNo

The middle column is the one that connects governance to anything. A policy cannot be enforced by a system because it does not say what the value should be. A data standard can.

What good governance looks like in practice

It is invisible: the right value is the easy value to enter.

Governance fails when it is designed as an audit. It works when it is designed as a default.

Bernard Kiyanda · CTO/CPO, Claravine

Working governance does not feel like governance to the people inside it. The campaign manager picks a channel from a list of eight instead of typing one. The agency’s setup form will not submit without a market. Nobody reads a policy, because the policy is expressed as the shape of the form.

Failing governance is conspicuous. It has a steering committee, a quarterly compliance report, a mapping table maintained by an analyst, and a documented standard that the data does not match. Every one of those is a symptom of the rule being applied somewhere other than where the data is created.

The practical test: count how many people have to remember something for the data to come out right. If the answer is more than zero, the control is in the wrong place.

Governing data you do not own

Marketing data is created by agencies and campaign managers in systems the data team does not administer.

This is the case the published governance literature does not cover, and for marketing data it is the majority case.

Warehouse-resident dataMarketing data
Created bySystems, on a release cyclePeople, continuously, at launch
Created inPlatforms the data team administersAd platforms, agency tools, spreadsheets
AuthorsA handful of writing processesEvery campaign manager, region and agency
Access control reaches them?YesFrequently no
When errors are visibleAt load or profilingWeeks later, in a report
Cost to correctReprocessThe campaign already ran

Access control, catalogs and lineage tracking all assume you administer the system where the data lives. None of those levers reaches an agency building a placement in a platform you do not control.

Cross-agency governance and taxonomy compliance failures come up across 74 enterprise accounts, making it one of the most prevalent problems in our customer conversations — and the structural reason is in the table above. Approval workflows, audit trails and access control are raised separately, across 39 accounts, usually by teams who have implemented all three internally and discovered they cover a minority of the records.

The governance lever that does reach outside the perimeter is the one that constrains what can be submitted: a form that offers the approved values, to whoever is filling it in, regardless of who employs them.

A Fortune 100 retail company’s media science team described what that foundation made possible.

“Our big task on the media science team and responsibility in our early years are over data standards and governance. Claravine helped lay that foundation…helping to increase paid media tracking by 65%.” — unnamed, media science team, Fortune 100 retail company

Governance for marketing data: Read: data governance in marketing — the practice applied to data created outside your systems.

How a governance program starts

Pick one data domain, agree its definitions, and enforce them at creation before widening scope.

  1. Choose one domain that hurts. Campaign metadata, customer records, product data. Pick the one where a wrong value has cost someone a bad decision recently; that argument funds the program.
  2. Name the owner and the steward. Two people, by name. Not a committee and not a function.
  3. Write the definitions in business language. One sentence each. If it needs a paragraph, the field is doing two jobs.
  4. Set the allowed values. Closed lists where possible, format patterns where not.
  5. Apply the check where the value is created. Not in the warehouse. This is the step that converts the previous four from documentation into governance.
  6. Publish the escalation path. How a new value is requested, who decides, how fast, and where the decision is recorded.
  7. Measure conformance and widen. Only after the first domain holds.

Enterprise-wide governance frameworks designed top-down tend to still be in design when a single-domain program has been catching errors for two quarters. Scope is the most common thing to get wrong at the start, and it is always wrong in the same direction.

The reason step 1 says “a domain that hurts” rather than “the most important domain” is political rather than technical. A program justified by a recent, specific, expensive mistake survives its first budget review. One justified by general principle does not, and governance work is slow enough that it always meets at least one budget review before it shows a result.

Compare the tooling: Read: data governance tools — the categories of governance tool, and which problem each solves.

Where governance applies beyond compliance

Reporting, attribution, AI-readiness and asset reuse all depend on the same agreed definitions.

Governance is often funded as a compliance activity, which sells it short and tends to produce the audit-shaped version that does not work. Google Cloud’s framing treats governance as an enablement discipline rather than only a control (Google Cloud, “What is data governance?”, accessed 2026-09-11), and that is the more useful read.

Four things depend on the same agreed definitions, and none of them is a compliance outcome.

Reporting groups by them. Attribution joins on them. AI-readiness depends on them entirely, because a model trained on inconsistently labeled campaign data learns the inconsistency. Asset reuse requires that the same creative be findable by the same description twice.

That is the argument that funds a program, and it is available without invoking a regulator. Data quality is the property all four are really asking about.

Frequently asked questions

What is meant by data governance?

The rules, roles and controls that decide how data is defined, created, checked and used.

What are the four pillars of data governance?

Ownership, definitions, quality standards, and enforcement.

What is the difference between governance and management?

Governance decides the rules; management operates the systems that follow them.

Who owns data governance?

A named data owner per domain, supported by a steward who maintains the definitions.

Does governance apply to marketing data?

Yes, and it is harder there, because the data is created outside the systems the data team controls.

Sources

Outbound citations, named and dated:


Related Posts

Free guideHow to Build a Marketing TaxonomyA 17-page guide with example marketing taxonomies — the critical steps in building one, the role of metadata in your marketing ecosystem, the questions to settle for an enterprise-wide taxonomy, and examples from a range of industries.Get the guide
Loose rods tumbling apart above a dense upright mass of packed rods

Reduce Marketing Waste: What's Actually Recoverable

Cracked, uneven floor tiles giving way to a neat uniform grid

CRM Data Integrity: How to Audit It, and What the CRM Cannot Fix

Solid dark canning jars in dense rows fading into outlined jars

Data Clean Rooms: What They Solve, and What They Assume