Submind YouTube summaries
Thumbnail for Inside Applied Data Governance: Expert Perspectives from the ADGP Program Episode 5: Policies, St...

Inside Applied Data Governance: Expert Perspectives from the ADGP Program Episode 5: Policies, St...

Watch on YouTube

Video summary

The podcast episode features a discussion with Jim Johnson, a key contributor to the ADGP certification program, focusing on the critical role of policy implementation standards and risk management within data governance. Johnson explains that treating data as a valuable asset requires a structured framework similar to how organizations manage people, money, or supplies. Without policies, standards, and risk management, an organization lacks the foundational anchor needed for professional data governance, leading to reactive "firefighting" rather than proactive control. These frameworks act as guard rails that clarify roles and expectations, allowing employees to operate autonomously while ensuring consistency and reliability across the enterprise. If these elements are missing, the discipline of data governance collapses, leaving organizations vulnerable to errors, compliance failures, and unmanaged risks that can severely impact operations. A significant challenge identified in the conversation is the common underestimation of the time, effort, and cultural shift required to implement effective policies. Organizations often struggle with the friction of compliance, viewing policies as bureaucratic hurdles rather than essential tools for success. Johnson emphasizes that successful implementation requires engaging stakeholders early to overcome perceptions of bureaucracy and ensuring that operational impacts on productivity are considered. Furthermore, there is a tendency to focus too heavily on authority ("the stick") rather than incentives ("the carrot"). The goal is to shift the culture so that adhering to standards becomes the norm and an integral part of doing business, where employees follow rules not because they are forced to, but because it is simply how work gets done. To address why policies often fail to change behavior, Johnson introduces his "Three Ps" framework: proponents, proportions, and practices. This approach ensures that policy creation is human-centric by involving those most impacted from the start, tailoring the rigor of standards to the actual level of risk rather than over-engineering solutions for low-risk areas, and integrating compliance directly into automated workflows. Success is measured not by the number of published documents but by the gap between what policies say and how people actually behave. By embedding guard rails into daily processes and fostering data literacy, organizations can move from reactive compliance to proactive risk management, preventing bad data from entering the ecosystem at the source and empowering employees to handle data safely and independently. Ultimately, accountability plays a pivotal role in transforming policies into lived practice by connecting individual actions to broader organizational goals and consequences. Johnson suggests using operant psychology principles to provide immediate rewards for compliance and clear consequences for violations, such as tying data governance metrics to performance reviews or executive KPIs. When employees understand that their adherence to standards protects the enterprise and enables their own autonomy, they are more likely to embrace these practices. The conversation concludes with the insight that if policies feel burdensome, stakeholders should be encouraged to participate in refining them, ensuring that the rules of engagement remain practical, effective, and aligned with the evolving needs of the business.
Read the full video transcript
Hello and welcome. I'm your host Barbara Nishaw and this is Inside Applied Data Governance. Whether you're just starting out in data governance or you've been working in the field for years, this podcast is for you where you will learn real life lessons and practical advice from the people behind the applied data governance practitioner certification. To learn more about the ADGP certification program, visit training.dativersity.net. Hello and welcome to Inside Applied Data Governance, a podcast where the practitioners who built the ADGP certification program share what real world data governance actually looks like. I'm your host Barbara Nishaw and today we're talking to Jim Johnson, one of the key contributors to the ADGP certification about policy implementation standards and risk management for data governance. Let's jump right in. Hi Jim, how are you doing today? >> I'm doing great. Barbara, how are you? >> I'm doing wonderful. Very excited to talk to you. >> Likewise. >> Are you all ready to talk about policies and risk? >> I am. This is a very exciting topic to me. >> That's good. That's good. And so important. It really is. We spent a lot of time in the body of knowledge on this topic and it is very important. So, but before we get started, we're going to talk a little bit about you. >> Well, I really got my start officially in data governance when I heard the term data governance in I think it was 2014 at a DJIQ conference. So, I'd spent my career in every job fixing things, making process better, making the data better. And it really never made sense to me until at that conference I realized, holy cow, I've been doing this for a while, and it actually has a name now. So, that was kind of exciting. Um, it all comes down to like, you know, standardizing things, uh, making your processes better, really building trust in the data, information assets. Um my my approach prior to understanding DG was read the manuals, learn the tools, create standards, automate everything you can and build trust and integrity in all of the data information. And then of course at the conference I learned all kinds of other things like metadata master and all these you know crazy terms that that started making sense to some of the problems I had encountered. I've been cross- sector. I've worked in uh pharmaceutical banking, health insurance, quick service restaurants, healthcare and most recently background screening. Every industry has something that you can learn and apply with to other industries. So that has been really valuable to me. Um I've learned so much from each industry that I've taken all of that forward with all the other industries that I've worked in. Data is data no matter what sector you're in. What changes is data governance. The scope um and the art of applying it which is why the applied part of this is so drastically important. >> Thank you so much Jim. So now let's get started with our topic today. Um our first question here um we always start out with the same question because it's important to know why was it so you know important to have this policy standards and risk management as part of the ADG body of knowledge and what would have been missing if we didn't have it. >> Yeah, this is a good question. So if if data is the new oil and insert any analogy about data like that that you wish um then we should really think about how we're going to manage it within an organization, right? It's probably one of the more complex assets we have. It's shared. It's reusable. Sometimes it's hard to put a value on it. We know it's essential for everyone practically. Um and we know we need good data for good decisions. So I think point number one is if if it is an asset we should manage it like an asset and we already do that with a lot of other you know enterprise assets and if you're going to do that then you need a framework for accomplishing that and data governance becomes that decision-m and accountability framework and if you have a framework the framework has to have guard rails to clarify roles and expectations and behaviors. It will also clarify the monitoring and the assessments of gaps or deficiencies or circumvention etc. uh to minimize unfavorable impacts because the ultimate goal really isn't to be big brother and lock everything down. It's really how do we how do we allow folks to operate independently autonomously within that framework um so they can get their jobs done right. So, it's like driving. As long as you follow, you get trained up, you get a license, you go out and drive, you have a certain amount of points that you know on your license that if you violate the the rules of driving, something drastically bad could happen or maybe you just acrew enough points to lose your license. That's what the frameworks do. So, my personal opinion is I think policies and standards and risks all make an organization or risk management rather make an organization stronger if we go about doing them well. And I mentioned some of these other asset management frameworks earlier. You know, HR does it with people, finance does it with money, supply chain does it with supplies, it does it with equipment. If if we do this with data, we solve so many of the data problems that everyone across the organization is manually and semianually trying to solve on their own repeatedly over and over all the way downstream in different ways from interval to interval, person to person. It's nuts. So what happens if we don't have policy development um and standards and risk management? Well, we would be missing the foundational anchor of data governance as a professional discipline. So that means it has to be in this book. Otherwise, the book would be a loose collection of tips and techniques and there would be no structural integrity. The this this framework of you know the rules of engagement as it were is what brings it all together. It also helps connect operations and strategy. Without the policy development, there's no authority. Without standards, there's no sense of how well or how good. And so, you can't measure and then close the the gaps um and improve the measurements. And then with without risk management, there's no what if, there's no resilience, there's no defense. Everything is reactive firefighting or damage when the crisis occurs. And so, all of that translates to losing the ability to execute and repeat and protect the work we do and the assets we manage. and data governance essentially collapses, there's just absolutely no way to sustain it in my opinion. >> That's a good way to break it down. You know, it's really the guard rails and uh you know, making sure we're all doing something the same way which you know, let's lead me to the next question. What do organizations or practitioners often misunderstand or underestimate about this? >> Yeah, this is a big one. I think there's a couple. One would be the time and effort to develop policies and standards and assess and mitigate and manage risks. It's, you know, you got to crowdsource inputs. You got to drive consensus. You got to agree on content for policies or which body or source of standards. Um, lines of business have their own ways of thinking and doing things. It's hard to influence change with some of them. So you have to start coaching them on enterprise thinking like you're we're solving problems for the enterprise not for your particular need your team your department your division policy is a must-have standards or need to have they change more um so you know not everything has to be a policy and not unless it's an official standard that like for example if it's regulated that should go in policy standards can be fluid and they should change over time as you know things around us change competitive environments business models etc. I think number two is the friction of compliance and operationalization. Um it's not done when it's published. There's training and implementation and communication that has to happen. There's perceptions you have to overcome about it being bureaucracy. Oh my god, another policy kind of a thing or it's a checkbox item. I'll do the bare bones minimum to comply and then get on with my job. You can't develop these in a vacuum. you have to engage the people that these policies and standards and risk management exercises are going to affect. Um if you don't consider the operational impact on productivity and velocity, um it's it's going to manifest when you roll it out. Um it's not static. It has to change over time. And you get them on board in the beginning and they'll help keep things updated and refreshed over time. And I think the last one is probably um they overly focus on authority instead of incentives. And so it's it's the carrot and the stick. You know, you got to some policies have to be mandated because of regulatory compliance. They can shut our doors temporarily, permanently um partially or completely. And so you got to do these things. But everything else it we again rules of engagement. As long as we all know what the rules are, we can operate autonomously doing our autonomously and independently doing our jobs and getting things done and contributing to strategic goals. So the idea there is we need to shift culture so that standards and policies become the norm. This is the cost of doing business. It makes everything more consistent, reliable and expected. And as you can tell, as we talked about in the stakeholder engagement module, this is a people problem. It's people and perceptions of bureaucracy. Policies and standards provide clarity, direction, independence, and they make us stronger and better. So, I think it's it's up to us as data governance professionals to lean into them and help everyone around us to lean into them as well. >> I like what you said about it being part of the culture and the part of doing business. So, it's built into everything and you don't even know it's a policy anymore because it's built into the way that you do things. >> Yeah. The hidden the hidden integration implementation of policies and standards is absolutely the best way. >> Yeah. cuz some people don't even realize it just the way they do it. >> Yeah. >> If you join our webinars, you already know strong data governance is what makes everything else possible. >> Exactly. And if you're ready to build or mature your governance practice, the data training center is where you'll find the deep dive courses that actually show you how to do it. And once you've built that foundation, the applied data governance certification helps you prove you can turn governance principles into real organizational impact. >> Then bring it all together with the community at DGIQ plus EDW 2026 where the governance leaders share what really works. >> Start strengthening your governance journey at dataverity.net. What does it look like in an organization and let's think about it early in our governance in its governance maturity? I think this is going to resonate with a lot of people. >> So, it's not sophisticated algorithms and formal cadences and compliance dashboards and predictive modeling on things are going to go bad. That's that's the advanced world, right? If you are in an environment where everything is manual or semi-manual, it's reactive, it's, you know, defensive and conversational, constant firefighting or being behind the A-ball, this is immature risk management early in the process. Um, if you don't even have a riskmanagement department and and you're not talking risk in your strategic plan or in your projects or, you know, other uh other areas of operations, that's also sign of immaturity. Um you know organizations like that you tend to operate on tribal knowledge. You got to know who to call how to get things done and know it's the phone a friend network or the know guy network. Those are single point of failures and bottlenecks. Um it silos data and risk too. People and departments and lines of business don't understand how their data practices affect other areas. So while this area is concerned about SSN, I'm not okay. Well, that's risk to the enterprise, right? And if you're not looking at this from an enterprise standpoint, you're actually contributing to the risk. And people are doing this all day long, saving files on file shares, for example. Um, we had I worked at a company where somebody took a picture of sensitive data on the screen and then emailed it because they couldn't export the data to to to email the data. So, they emailed a picture instead. I mean, people find creative ways of getting around this. So, how does it manifest? Otherwise you'll see errors in reports that people are complain about um variation in reports accidental discovery of you know problems because now that risks have manif manifested as issues. Audit findings often time uh surface risk when you don't fulfill the audit requirements or your regulatory submissions you you get failed repeatedly. Um gut checks red yellow green kinds of things on executive dashboards that don't have real data behind them. Shadow IT and analytics, absolute risk. Um, compliance blind spots. I I mentioned SSN earlier. Why aren't we talking about all the sensitive and confidential data sets at the organization? Every industry I've ever been in has focused on I probably a number of data on account of one hand. And then one organization, you know, you you got a policy that mentions a couple dozen. Why aren't we looking at all of them? Right? So, what do you do? I think we need guard rails in plain English that people can understand. things like never email a spreadsheet with personal information in it. Um or get approval to share data with external parties. You got to make it common sensical. Um focus on your crown jewels, the top two or three data sets that if they were to be leaked, lost or compromised. Um you can be shut down partially or completely, maybe permanently. Um you could regulatory fines for example. And then I think the third thing is literacy through context. You really just have to start using real world world examples specific to their jobs. Show how it impacts across the organization or at the organizational level as a whole and get people talking to each other. A lot of it has just has to do with I don't know what's going on. I care about my own little world, but we're all we're all sort of part of this bigger organization and we should all be thinking organizationally. Like think global and act local is one of the axioms I use around that. That's a good one because people so many times forget this is for the good of the entire enterprise and it may be a little more work for you but that's why you need to do it because it's the the enterprise as a whole. >> And then conversely here's what h might happen if we don't do it or you don't do your part. >> Mhm. >> Exactly. >> Wake people up too. >> Yeah, it does because people just don't stop to think about it what they're doing. If you could give one piece of advice to someone responsible for policies and standards, what would it be? >> So I have a rubric on this. I call it the three Ps and I've mentioned one earlier. So the first P is proponents. It has to be humanentric. You can't create policies and standards. In fact, any guardrail in my opinion unless you have sole authority over it. You can't do that without inviting people to participate, especially the people who are most impacted by the standards and the policies. Get them get them involved up front. If you don't, you know, shadow them, watch their workflows, ask them about the impact and the pain points, help them understand the need, and then ultimately find the least painful way to meet the goal. Um, I think it's called least viable policy, for example, sort of like um in agile software development, the minimal viable product. It's the same kind of concept. So proponents. Number two is proportions. And this is about the right fit. So you don't have to treat everything like it's the most monstrously gigantic risk in the world or the most monstrously large need for you know a very complicated you know 20page long standard or policy. You don't you don't want to overengineer anything. You got to tailor the policy or the standard to the need or the risk. And you want tier. So based on the risk level, the higher the risk, the stronger, more rigorous the the policy standard or guardrail is going to be. If it's a low risk, then you can do more of a flexible, lightweight kind of guideline. Um, you want the minimum amount of restriction with a maximum amount of of I guess theoretical protection because this is all sort of theoretical until something happens, right? And then you learn from it and you mend your policies and standards and start all over. So proponents is number one, proportions is number two. That brings us to number three, which is practices. And that's how the work gets done. And you actually alluded to this earlier. The best way to implement any policy or standard is to integrate it into the workflow or the operational process, ideally automated wherever possible. It's done. You're forced to follow it. You follow it because that's how that's how the process works. And if you can hardcode these guardrails, like block action if you're not doing it right, like a system edit. Don't put an end date that's before a start date when you're going to go book an airline ticket. I mean, this exists everywhere, right? These these are all riskmanagement constructs. Keep the data good. Keep the risks from getting into the system kind of a thing. Um, and then engage, education, and feedback. Uh, because again, it's people on all three of these. And so it's and you can even use the three Ps. ensure that they follow proponents, proportions, and practices. They all begin with PR, too. So, it's kind of a tongue twister. Success. So, here here's here's my insight on all of that. Success is not, as many folks and organizations think, reflected by how many policy standards and guard rails are written, approved, and published. It's actually about how big is the gap between what these guard rails say and what people actually do. And the more people do in agreement with all of your guard rails, that is really the real mark of success. >> Thank you. I like the three Ps. That'll be a good way for people to remember that work for me. I hope it works for everybody else. >> I was say I always think it's good to break it down like that. Um, next question. How does data governance function as proactive risk management rather than reactive compliance? So, you know, it's interesting. Everywhere that I've I've built and scaled a data governance program, I've always inevitably intersected with risk management. And in some cases, they already had data related riskmanagement practices in place. And in many cases, other organizations, they did not. And so, it's always a surprise where they are. But, you know, the proactive is if it doesn't exist, we're going to start it. We're going to partner with risk management and we're going to we're going to start getting more data risks assessed at at regular intervals. And so I think you know you can shift the timeline from postmortem to premortem. If you're going to set up a database, let's do it then. You always want to go as close to up as far upstream as possible as close as possible to what I call the the drip dring or input point because you're always either collecting it from humans or machines. And if you can harness the if you can manage any sort of risk of bad data at that given point um then you're preventing bad data from getting into the data ecosystem altogether. So that's great. You don't want that, right? You don't want bad data to prol proliferate. Another way is through the mechanics. So data quality of source which I was just talking about. You want you want those those controls as far up as possible. You also want access controls. And so you're going to, in my experience, I've always partnered with information security or cyber security depending on how your organization calls them. Um, you want to really get into role-based access controls and start maturing what that looks like and go get into like it goes from arbback to Aback to Pback. So from ROS to attributes to policybased with all it really means is a a maturation process to automate more and more of your security permissions provisioning and deprovisioning. And if you can do that, more automation means less manual maintenance, which translates to less risk. I've worked at organizations where too many people still had access after they were separated from the company. If you still have access and you're disgruntled, that's really not a good combination. I also worked with a gentleman who spent about 30% of his time. We actually sat down and qualified quantified his time and um he was he was provisioning and deprovisioning accounts. They had set up an automated process, but he was still spending 30% of his time uh manually doing it. It was because we had folks internally that weren't following the process and they were, you know, emergency emergency do it and it was not only manual setup, it was manual deprovisioning when the automated process ran and then integrated two different accounts for the same person. You don't really want that. Automated data lineage is another one. If you have if you're mature in your data cataloges, no more figuring out how it's calculated or where it comes from. That's all manual and semmanual forensics. No, just you can click see the entire lineage and and definitions and and it's all good. I think the last element that I'll add is it it proactive is you address the mindset of of folks. Data literacy increases awareness. Educating people on what data risks are, what it means to have a data risk and then how to go about managing it and mitigating it. Um that should be part of all data literacy campaigns, all all data governance programs. The ultimate goal is to again give people autonomy and independence, learn how to handle data safely and correctly based on regulations and laws and standards and policies and understand that risk monitoring is now the norm. If you spread that wealth of knowledge and have more people across the organization following these standards and policies, they're they're proactively managing the risks along the way and identifying them so that they can be addressed before they become major issues. >> Thank you very much. That's a great answer, you know, and so much of it does relate back to training and having a good data literacy program for all different roles and different levels within your company. >> Which leads us to our next question. Why do governance policies and standards so often fail to change behavior? >> So, I don't think this is going to be any surprise, but I'm going to come back to the people's side of it again. >> People are the biggest problem on the planet. If we've I say this all the time. I I say facitiously, but I actually do believe if if we weren't here, this planet would completely self-regulate, right? It's mindsets. It's it's you can't change behaviors until you change minds. And that takes a lot more time and effort to change minds than to change behaviors. But they're sequential. If you don't change their mindsets and get folks on board, you're not going to change their behaviors. You have to factor in how people get work done. If they perceive things as bureaucratic and timeconuming, they're going to bypass it. They're going to come up with even new creative ways of circumventing any sort of controls you can put in place. So, no, that's bad, right? We want you to follow the standards and process. How do you turn that around? It's almost like plugging the holes in a dyke. You can stick your finger and all 10 fingers in 10 holes, but five more holes are going to pop up. So, what do you do at that point? Now, I need another person to come in and start plugging those holes. So I think awareness versus integration is a really good topic for um any sort of education efforts around all of this. A lot of folks aren't even aware of corporate policies. I I had a conversation once with a director of BI about classified data and her response was I don't understand that. I don't what are you talking about? I said well we have a corporate policy. Wait what do you mean there's a corporate policy? Never even heard of it. Which is fascinating to me as a as a BI director you're you're pulling data together and exposing it. How do you not understand what that means? Right? That is very and it's every place I've ever been, I think there's been some semblance of of annual training around, you know, some type of data confidentiality or or regulated data sets. It obviously it's got to be more because if you still have folks in the organization that don't know it, that's a risk and that means something might come out of it, right? So you got to make policies more accessible, more streamlined, more more integrated in the tools and technology. Um, make them guard rails for success and efficiency, not speed bumps or potholes that people are going to avoid or or or drive around, right? Ultimately, they make people and organizations stronger, more resilient, and more successful in the long run. So, I think getting people to understand that we're trying to help them towards independence and autonomy and getting that light bulb to go on can be extremely helpful. >> Yeah, that's so important. And I love what you said is that, you know, we have to shift the mindset before we can change the behaviors, >> you know, cuz we think ends up to be what we do. So, that's so important. That leads us to our last question. What role does accountability play in turning policies and standards into lived practice? >> Wow. So I mean what is what does lack of accountability in life? I if you could get through with zero consequences is anything really going to change? Of course not. Right? It's basic psychology. Um zero incentive to change means people are going to continue that behavior. So you have to change the consequences or you have to change the incentives. So that's a nod to operant psychology and and literally my undergraduate degree. So I use this all the time in data governance. It's you have to look for immediate faster rewards and recognition short-term successes that really start to showcase what we're talking about. And if folks don't understand that and they continue their behaviors, they're actually hurting the long-term evolution of benefits and stability in your environment and less risk. And so sometimes you have to, you know, connect the dots on that. Um, some examples that I've come across is, you know, developers using local hard drives for development. Why? because it was too cumbersome to get permission to set up a virtual workstation or using your personal user account to set up jobs that are supposed to run automatically and the person leaves the company and all of a sudden you've got job failures all over the place. So change the standards. This these should become part of your production deployment checklist and if it's not met you kick it back. Um Sarbain actually did this when they required segregation of duties between dev test and prod environments and developers couldn't have access to test or prod. So if you didn't do codebased deployment, it would get kicked back. If I can't push a button and deploy it in the production environment, it's a no-go. You need to do that with a lot of operational processes as well. >> Um, you can also change the measures. Um, data governance metrics like data quality KPIs or compliance KPIs or successful, you know, completion of training and and standards met or standards applied types of of of metrics. Um, you can tie those to executive KPIs and strategic goals and and start mapping those relationships and educating executives and line of, you know, line of business staff about that. You can also tie data governance metrics to budgets, performance reviews, program reporting. Um, if you are consistently not following the standard or the policy, then yes, maybe there's there's some escalation warranted or maybe we make it more formal with uh some feedback in your performance review. You can certainly include it in your data governance program reporting. I think if policies and standards are published artifacts and the accountability and the associated accountability metrics ought to be published as well. So you might have to warm people up to that idea because uh you know some organizations aren't right. It's kind of difficult to get them to think about that. But you know compliance does it. So all we're asking is can we apply that to our data and just formalize it because we want to measure our progress and show the value and metrics can actually do that right and policy and standards are one area where it really becomes visible you know integrate them in annual training how many people completed do they really read it if you can track whether they scrolled through the entire document or just went right to the end and said check I'm in I'm done I mean you know you got to tease those apart a little bit and see what what it really means but it takes time ultimately you got to get buy in. You got to share your successes and you got to crowdsource everything when it comes to policies and standards because that buy in um will make it or break it. And if they break policy and standard, then you've got risks and now we've just tied everything together that we just talked about. >> That was a great way to end that. It did. It tied it all together complete circle. >> Thank you so much, Jim. This was great. I have thoroughly enjoyed talking with you about this. you make uh policies and risk management sound, you know, much more interesting. I love it. >> Yeah, they can be fun. If you have fun and if you approach everything with fun, a fun mindset, then I think it becomes a lot less bureaucratic. So, I I don't think we should shy away from policies and standards. It's one of it's something I've helped every organization I've worked at do. Um, this was a delightful conversation because we touched on a lot of points that I think will help people understand what it means to maybe have a little bit of fun as you're creating policies and standards. And then you know what? If you don't like the policies and standards, then get more involved and change them. So either way, we're going to get you involved. >> Oh, that's a great piece of advice. Thank you so much. >> What a delightful conversation. >> For our listeners, if you'd like to learn more about the ADGP certification program and the applied data governance body of knowledge, visit training.dataverity.net. Until next time, I'm Barbara Nishaw and this has been Inside Applied Data Governance.