Standing Up Data Governance: Tooling, Records, and the PMO Discipline to Make It Stick
Most organisations don't have a data problem; they have a governance-of-data problem. At Auto & General I work the gap with requirements-led tooling selection, a working OpenMetadata POC, records control, and PMO discipline.
Standing Up Data Governance: Tooling, Records, and the PMO Discipline to Make It Stick
Most organisations don't have a data problem; they have a governance of data problem. The data exists — it's just unowned, undescribed, scattered across structured systems and a far larger sprawl of unstructured documents, with no agreed source of truth about what it is, who's accountable for it, or whether it can be trusted. My current work as a Senior Business Analyst in the Data Governance function at Auto & General is about closing exactly that gap, and doing it in a way that survives contact with the real organisation.
The reference point: a governed data domain
The work sits adjacent to the creation of a Governed Reference Data Set (GRDS) — establishing authoritative, governed reference data the rest of the organisation can rely on rather than each team maintaining its own quietly diverging copy. The point of a governed reference set is not the data itself; it's the agreement about ownership, definition, and trust that surrounds it. Get that right and downstream reporting, analytics, and increasingly AI all inherit a foundation they can stand on. Get it wrong and every model and dashboard is built on sand.
Selecting the tooling: requirements before products
A common failure mode in data governance programs is buying a platform and hoping it imposes discipline. I worked the problem the other way around: requirements first, selection second. That meant running the requirements and RFI process for data governance tooling — establishing what the organisation actually needed a catalogue, lineage, and governance platform to do, then evaluating candidates against those requirements rather than against a vendor's demo.
To ground that in evidence rather than slideware, I stood up a proof of concept using OpenMetadata — a working deployment, configured with realistic governance constructs (data assets, policies, ownership, lineage), so the selection conversation could be about observed behaviour instead of promised capability. A POC turns "the vendor says it can do lineage" into "here is lineage, working, on our kind of data." That is the difference between a defensible selection and a hopeful one.
The program also addressed the half of the data estate most governance efforts ignore: unstructured content. Bringing in RecordPoint to manage unstructured data acknowledges that records, documents, and the long tail of files carry as much risk — privacy, retention, discoverability — as the neat rows in a database, and usually with far less control around them.
Making governance stick: PMO discipline
Tooling and reference data fail without the operating discipline to run them. The third strand of the work is uplifting PMO governance through Jira and Confluence — turning ad-hoc delivery into a traceable, well-governed program. The aim is unglamorous and essential: clear backlog and status in Jira, durable decisions and documentation in Confluence, and a program that can show what was decided, by whom, and why. Governance that can't be audited is just intention.
The shape of the work
Read together, this is a complete data-governance posture rather than a single intervention: a governed reference foundation, a tooling selection driven by requirements and proven with a working POC, control extended to unstructured data, and the PMO discipline to keep the whole thing accountable. It is second-line in character — independent of the systems being governed, focused on whether the right controls, ownership, and evidence are in place, and built to be defensible to whoever asks next.
It also closes a familiar loop. The instinct to demand evidence over assertion, to anchor decisions to a requirement, and to make the record auditable is the same one that runs through everything I build — from a brokerage's compliance process to an AI control plane. Here it's applied to the data foundation an entire organisation runs on.
Based on current work as a Senior Business Analyst in the Data Governance function at Auto & General, covering reference-data governance, data-governance tooling selection (including an OpenMetadata proof of concept), RecordPoint for unstructured data, and PMO governance uplift via Jira and Confluence.