Skip to main content
    Abstract glass cubes in brand blue on a light background

    Data governance consultancy

    Governance that builds trust in your data and your AI.

    Having policies isn’t the same as having good governance. Organisations need to know who is responsible for their data, whether it can be trusted, who has access to it and how AI is being used. Our data governance consultancy helps you put practical, proportionate controls in place, and our AI governance consulting gives your teams a clear position on how AI can be used safely, so adoption does not outrun oversight.

    We work with organisations that need to put practical controls around their data and AI, particularly where the data is sensitive, regulated or important to the decisions they make.

    You finish with named ownership, measured data quality, an access model you can evidence, a practical AI governance position, and an operating rhythm your team can run.

    Free. 30 minutes. Directly with our founder, Inez Hogarth. No pitch.

    Rated 5.0 on Clutch by the organisations we work with

    Common challenges

    What we find when we look at governance honestly.

    These patterns are common in organisations that have invested in data and are now being asked to demonstrate control. The technology is rarely the constraint. Ownership, accountability and operating discipline usually are.

    01

    Nobody owns the data that decisions depend on

    Critical datasets and measures have no named owner, so quality issues have no route to resolution and disagreements about definitions escalate rather than resolve.

    02

    AI is being adopted faster than it is being governed

    Teams are already using AI tools, sometimes with company data. There is no agreed position on acceptable use, model oversight, human review or the records the organisation would need if challenged.

    03

    Governance was written but never operated

    Policies, a data dictionary and a committee structure exist on paper. They are not connected to how data is produced or used daily, so behaviour has not changed.

    04

    Access has accumulated over time

    Permissions were granted for specific needs and never reviewed. Sensitive data is more widely available than leadership assumes, and demonstrating who can see what takes weeks.

    05

    Regulatory questions require evidence, not intent

    Auditors, regulators and enterprise customers now ask how data and AI are controlled and expect documented proof. Assembling that evidence from scratch is slow and reveals gaps at the worst moment.

    06

    Quality issues are found by the business first

    Errors surface in a report or a customer interaction rather than in a control. Without measurement, ownership and remediation, trust in reporting declines while effort spent checking it grows.

    Our approach

    Governance designed to be operated, not filed.

    We use our Unearth, Reveal, Build, Achieve engagement model, and our DIAlog framework to understand the behaviours and incentives that decide whether governance holds. We design controls into the platform and the delivery process so the right thing to do is also the easiest.

    Data and AI governance, defined

    Data and AI governance is the combination of ownership, decision rights, standards and controls that make data trustworthy and its use appropriate. It covers named owners, agreed definitions, measured quality, classification and access, retention, and oversight of models and AI enabled tools. It is judged by the behaviour it produces and the evidence it can supply, not by the documentation it generates.

    1. Stage 01

      Unearth

      We establish what needs protecting and what needs to be trusted: the data domains that matter commercially, where sensitive and personal data sits, current access, existing policy and controls, regulatory obligations, and where AI is already being used inside the organisation.

    2. Stage 02

      Reveal

      We bring the findings back to the people who will own the controls and agree governance that fits your size and risk appetite: ownership and stewardship roles, decision forums, agreed definitions, data quality measures, classification and access model, retention, and an AI governance position covering acceptable use, review and oversight. Proportionate beats comprehensive if comprehensive will not be operated.

    3. Stage 03

      Build

      We implement it in the places work happens. That means controls in the platform rather than in a document, automated quality tests with owners and thresholds, access aligned to role, lineage that is generated rather than maintained by hand, and templates that make the right behaviour the easiest option. Alongside that we help internal teams understand their responsibilities, clarify what being a data owner actually involves day to day, and establish appropriate ownership across the domains that matter.

    4. Stage 04

      Achieve

      We embed governance into day-to-day operations: who reviews what and when, how issues are raised and resolved, how new data and new AI use cases are assessed before they go live, and the reporting that shows leadership the controls are working. Where it helps, we establish or support a data governance council so decisions about definitions, access and AI use have a clear home. Your people run it, with our support while it settles.

    Data governance services, from one-off to ongoing

    Every organisation starts from a different place, so we offer governance in three ways.

    Data governance consulting.

    A defined engagement to design governance that fits your size and risk appetite: ownership and stewardship roles, agreed definitions, quality measures, a classification and access model, and a forum for decisions.

    AI governance consulting.

    An agreed position on acceptable use, human oversight and review points, plus the records you would need if a regulator, auditor or enterprise customer asked how AI is controlled. It builds on your data governance rather than sitting beside it.

    Data governance as a service.

    Ongoing support once the model is in place: running the governance rhythm with your owners, monitoring data quality against agreed thresholds, assessing new data and AI use cases before they go live, and reporting to leadership. It is delivered through our Managed Data Teams service and flexes as your needs change.

    Business outcomes

    What changes as a result.

    We describe outcomes in the terms our clients use about the work.

    Clear ownership of data and AI

    Named owners for the domains, measures and models that matter, with a route for issues to be raised and resolved.

    Measured, improving data quality

    Quality expressed as tested rules with thresholds and owners, so problems are found by controls rather than by customers.

    Access that reflects role and risk

    A classification and access model you can explain and evidence, reducing exposure of sensitive and personal data.

    Evidence ready for scrutiny

    Documentation, lineage and control records that answer auditor, regulator and enterprise customer questions without a scramble.

    A defensible position on AI

    Agreed acceptable use, human oversight and review points, so teams can adopt AI without creating unmanaged risk.

    Governance your team can operate

    A proportionate model with the roles, rhythm and tooling to keep running after the engagement ends.

    Relevant client work

    Governance and capability work we have delivered.

    The case studies set out what the organisation needed, what we did and what it produced.

    They provided costed structure and solutions to create an ongoing credible data management capability.

    Graham McDougall

    Head of Subscriptions, DC Thomson

    Data Understood push to learn the nuances of the company, its overall strategy, its people and thus deliver solutions that benefit the company to its core and lay the foundation for a strong future in data.
    Anup Purewal, Chief Data Officer, DC Thomson
    The sense of partnership. At no point did it feel like a purely transactional relationship.
    Michael Gardiner, AI Innovation Lead, South of Scotland Enterprise

    Where to go next

    Related services, sectors and reading.

    Governance is most effective when it is designed alongside the platform and the reporting it protects. Sector obligations shape how formal the model needs to be.

    Buying questions

    Security and governance: questions enterprise buyers ask.

    Written for the people accountable for control and assurance, covering how proportionate data and AI governance is actually implemented.

    Data governance is the set of ownership, decision rights, standards and controls that determine how data is defined, protected, measured and used across an organisation. In practice it covers named owners for data domains, agreed definitions, quality measurement, classification and access, retention, and a forum for resolving issues. Governance works when it is embedded in day to day systems and processes rather than described in a policy document.

    AI governance covers how models and AI enabled tools are approved, documented, monitored and overseen. It extends data governance with model specific concerns: the purpose and boundaries of use, the data a model may use, human review of outputs, monitoring for degradation and bias, records of decisions, and a route to withdraw a model. Data governance asks whether the data can be trusted, and AI governance asks whether the use of it is appropriate and controlled.

    Start narrow and useful. Pick the domains and measures that leadership already relies on, name owners for them, agree the definitions, set up a small number of automated quality tests, and review access to sensitive data. That produces visible improvement within weeks and creates the credibility to widen scope. Beginning with a full framework tends to stall before anything changes.

    Being able to explain what a model is used for, what data it uses, who is accountable for it, how outputs are reviewed by a person where the decision matters, how it is monitored once live, and how it would be withdrawn. It also means being honest about limitations with the people who rely on the output. These are practical controls rather than a statement of principles.

    Work back from the questions you would be asked: what data do you hold, on what basis, who can access it, how do you know it is accurate, how is it retained and deleted, and how are automated decisions overseen. Then make sure each answer is supported by evidence generated from your systems rather than assembled by hand. Governance designed this way costs less at audit time.

    With tested rules against defined expectations: completeness, validity, uniqueness, timeliness and consistency across systems, applied to the datasets that matter most. Each rule needs a threshold, an owner and an agreed action when it fails. Quality reported as a single score without owners rarely changes anything.

    Enough to protect what matters and demonstrate control, and no more than your team can operate consistently. Regulated sectors and organisations handling personal or commercially sensitive data need more formality. The test is whether the model still functions when the people who designed it are busy with something else.

    Writing policy without implementing controls. Appointing stewards without giving them time or authority. Building a data catalogue nobody maintains. Treating governance as a compliance exercise separate from delivery. Attempting enterprise wide coverage before proving value in one domain. And leaving AI use unaddressed until it is already widespread.

    Accountability usually sits with a CDO, CIO or an executive sponsor with sufficient authority to settle cross functional disputes about definitions and access. Day to day ownership belongs with the business areas that produce the data, supported by the data function. Placing governance entirely inside technology is a common reason it fails to change behaviour.

    Poorly designed governance does. Well designed governance removes rework: agreed definitions prevent contested reporting, access models prevent late security objections, and documented lineage prevents investigation each time a figure is questioned. We design controls into the platform and delivery process so they are part of the work rather than a gate at the end.

    A data governance consultant helps you decide who owns which data, what "good" looks like for it, and how that is checked day to day. In practice that means mapping the data that matters, agreeing owners and definitions, setting quality rules with thresholds, designing access by role, and building those controls into your platform and processes so they are operated rather than filed. A good consultant also leaves your team able to run it without them.

    Data governance as a service is ongoing, external support to run governance once it is designed: keeping the ownership forum going, monitoring quality, reviewing access, and assessing new data and AI use before it goes live. It suits organisations that need governance to keep working but don't have a full-time governance team. We provide it through our Managed Data Teams service.

    Yes. Some organisations come to us because AI is already in use and they need an agreed position quickly: what is acceptable, where human review is needed and what records to keep. We will usually check the underlying data governance at the same time, because AI governance depends on knowing what data the AI is using and who owns it.

    Yes, and we expect to. Information security, legal and risk teams hold obligations and standards this work has to align with. We involve them early, particularly on classification, access, retention and AI oversight, so the model we design is one they can support rather than one they have to challenge.

    Yes. We are based in Dundee and work with ambitious organisations across Scotland and the UK. Governance work involves onsite sessions with data owners and risk functions alongside remote delivery, and we agree that balance with you at the outset.

    Let's talk about your Data & AI priorities.

    Whether you're developing a data strategy, modernising your data platform, preparing for AI or tackling a specific business challenge, start with a 30-minute conversation with Inez.

    Free. 30 minutes. Directly with Inez. No pitch.