00:00:05.919 --> 00:00:07.200
Hello and welcome.
00:00:07.280 --> 00:00:11.759
I'm your host, Barbara Neshaw, and this is Inside Applied Data Governance.
00:00:12.000 --> 00:00:26.239
Whether you're just starting out in data governance and you've been working in the field for years, this podcast is for you, where you will learn real-life lessons and practical advice from the people behind the Applied Data Governance Practitioner Certification.
00:00:26.480 --> 00:00:33.280
To learn more about the ADGP Certification Program, visit training.dataversity.net.
00:00:39.520 --> 00:00:51.200
Hello and welcome to Insight Applied Data Governance, a podcast where the practitioners who built the ADGP certification program share what real-world data governance actually looks like.
00:00:51.520 --> 00:01:04.400
I'm your host, Barbara Neshaw, and today we're talking to Jim Johnson, one of the key contributors to the ADGP certification about policy implementation, standards, and risk management for data governance.
00:01:04.640 --> 00:01:06.319
Let's jump right in.
00:01:07.599 --> 00:01:08.400
Hi, Jim.
00:01:08.480 --> 00:01:09.439
How are you doing today?
00:01:10.159 --> 00:01:11.280
I'm doing great, Barbara.
00:01:11.359 --> 00:01:11.760
How are you?
00:01:12.159 --> 00:01:12.959
I'm doing wonderful.
00:01:13.359 --> 00:01:14.719
I'm very excited to talk to you.
00:01:16.400 --> 00:01:18.719
Are you all ready to talk about policies and risks?
00:01:19.040 --> 00:01:19.680
I am.
00:01:20.640 --> 00:01:23.040
This is a very exciting topic to me.
00:01:23.359 --> 00:01:23.920
That's good.
00:01:24.079 --> 00:01:24.480
That's good.
00:01:24.560 --> 00:01:25.359
It's so important.
00:01:25.439 --> 00:01:26.000
It really is.
00:01:26.480 --> 00:01:30.640
We spent a lot of time in the body of knowledge on this topic, and it is very important.
00:01:30.879 --> 00:01:35.280
So before we get started, we're gonna talk a little bit about you.
00:01:36.239 --> 00:01:44.159
Well, I really got my start officially in data governance when I heard the term data governance in, I think it was 2014 at a DGIQ conference.
00:01:44.239 --> 00:01:51.120
So I had spent my career and every job fixing things, making process better, making the data better.
00:01:51.200 --> 00:01:58.480
And it really never made sense to me until at that conference I realized holy cow, I've been doing this for a while, and it actually has a name now.
00:01:58.560 --> 00:01:59.920
So that was kind of exciting.
00:02:00.079 --> 00:02:07.599
Um, it all comes down to like, you know, standardizing things, uh making your processes better, really building trust in the data information assets.
00:02:07.920 --> 00:02:18.719
Um, my my approach prior to understanding DG was read the manuals, learn the tools, create standards, automate everything you can, and build trust and integrity in all of the data information.
00:02:18.879 --> 00:02:27.759
And then, of course, at the conference, I learned all kinds of other things like metadata, master data, and all these crazy terms that that started making sense to some of the problems I had encountered.
00:02:27.919 --> 00:02:29.759
I've been cross-sector.
00:02:29.919 --> 00:02:36.960
I've worked in uh pharmaceutical, banking, health insurance, quick service restaurants, healthcare, and most recently background screening.
00:02:37.120 --> 00:02:40.800
Every industry has something that you can learn and apply with to other industries.
00:02:40.960 --> 00:02:43.439
So that has been really valuable to me.
00:02:43.599 --> 00:02:49.280
Um, I've learned so much from each industry that I've taken all of that forward with all the other industries that I've worked in.
00:02:49.439 --> 00:02:51.280
Data's data, no matter what sector you're in.
00:02:51.439 --> 00:02:59.199
What changes is data governance, the scope and the art of applying it, which is why the applied part of this is so drastically important.
00:03:00.000 --> 00:03:01.360
Thank you so much, Jim.
00:03:01.680 --> 00:03:04.560
So now let's get started with our topic today.
00:03:04.879 --> 00:03:07.039
Um, our first question here.
00:03:07.360 --> 00:03:22.240
Um we always start out with the same question because it's important to know why it was it so you know important to have this policy standards and risk management as part of the ADG body of knowledge, and what would have been missing if we didn't have it?
00:03:23.840 --> 00:03:25.360
Yeah, this is a good question.
00:03:25.599 --> 00:03:40.159
So if if data is the new oil and insert any analogy about data like that that you wish, um then we should really think about how we're going to manage it within an organization, right?
00:03:40.240 --> 00:03:43.360
It's probably one of the more complex assets we have.
00:03:43.520 --> 00:03:44.879
It's shared, it's reusable.
00:03:44.960 --> 00:03:46.639
Sometimes it's hard to put a value on it.
00:03:46.800 --> 00:03:50.000
We know it's essential for everyone practically.
00:03:50.080 --> 00:03:52.960
Um, and we know we need good data for good decisions.
00:03:53.199 --> 00:03:59.039
So I think point number one is if if it is an asset, we should manage it like an asset.
00:03:59.120 --> 00:04:02.800
And we already do that with a lot of other, you know, enterprise assets.
00:04:03.039 --> 00:04:07.680
And if you're gonna do that, then you need a framework for accomplishing that.
00:04:07.759 --> 00:04:12.159
And data governance becomes that decision-making and accountability framework.
00:04:12.400 --> 00:04:19.839
And if you have a framework, the framework has to have guardrails to clarify roles and expectations and behaviors.
00:04:20.079 --> 00:04:29.120
It will also clarify the monitoring and the assessments of gaps or deficiencies or circumvention, et cetera, uh, to minimize unfavorable impacts.
00:04:29.199 --> 00:04:33.279
Because the ultimate goal really isn't to be big brother and lock everything down.
00:04:33.360 --> 00:04:42.800
It's really how do we how do we allow folks to operate independently, autonomously within that framework so they can get their jobs done, right?
00:04:42.879 --> 00:04:43.680
So it's like driving.
00:04:43.759 --> 00:04:58.480
As long as you follow the, you get trained up, you get a license, you go out and drive, you have a certain amount of points that, you know, on your license that if you violate the the rules of driving, something drastically bad could happen, or maybe you just accrue enough points to lose your license.
00:04:58.639 --> 00:04:59.839
That's what the frameworks do.
00:04:59.920 --> 00:05:11.040
So, my personal opinion is I think policies and standards and risks all make an organization or risk management rather, make an organization stronger if we go about doing them well.
00:05:11.199 --> 00:05:14.560
And I mentioned some of these other asset management frameworks earlier.
00:05:14.720 --> 00:05:20.399
You know, HR does it with people, finance does it with money, supply chain does it with supplies, IT does it with equipment.
00:05:20.480 --> 00:05:35.839
If we're if we do this with data, we solve so many of the data problems that everyone across the organization is manually and semi-manually trying to solve on their own, repeatedly, over and over, all the way downstream, in different ways from interval to interval, person to person, it's nuts.
00:05:36.160 --> 00:05:43.279
So, what happens if we don't have policy development and standards and risk management?
00:05:43.439 --> 00:05:47.839
Well, we would be missing the foundational anchor of data governance as a professional discipline.
00:05:48.079 --> 00:05:50.720
So that means it has to be in this book.
00:05:50.959 --> 00:05:55.759
Otherwise, the book would be a loose collection of tips and techniques and there would be no structural integrity.
00:05:56.319 --> 00:06:00.879
This framework of you know, the rules of engagement, as it were, is what brings it all together.
00:06:01.040 --> 00:06:03.360
It also helps connect operations and strategy.
00:06:03.439 --> 00:06:05.680
Without the policy development, there's no authority.
00:06:05.839 --> 00:06:09.360
Without standards, there's no sense of how well or how good.
00:06:09.439 --> 00:06:15.279
And so you can't measure and then close the gaps and improve the measurements.
00:06:15.360 --> 00:06:20.560
And then with without risk management, there's no what if, there's no resilience, there's no defense.
00:06:20.639 --> 00:06:24.959
Everything is reactive firefighting or damage when the crisis occurs.
00:06:25.120 --> 00:06:32.160
And so all of that translates to losing the ability to execute and repeat and protect the work we do and the assets we manage.
00:06:32.240 --> 00:06:34.079
And data governance essentially collapses.
00:06:34.160 --> 00:06:36.720
There's just absolutely no way to sustain it, in my opinion.
00:06:37.680 --> 00:06:39.120
That's a good way to break it down.
00:06:39.199 --> 00:06:44.399
You know, and it's really the guardrails and uh, you know, making sure we're all doing something the same way.
00:06:45.920 --> 00:06:48.639
Which, you know, let's lead me to the next question.
00:06:49.360 --> 00:06:55.040
What do organizations or practitioners often misunderstand or underestimate about this?
00:06:56.160 --> 00:06:57.680
Yeah, this is a big one.
00:06:58.160 --> 00:06:59.519
I think there's a couple.
00:06:59.839 --> 00:07:06.959
One would be the time and effort to develop policies and standards and assess and mitigate and manage risks.
00:07:07.120 --> 00:07:16.319
It's, you know, you got to crowdsource inputs, you got to drive consensus, you got to agree on content for policies or which body or source of standards.
00:07:16.560 --> 00:07:20.240
Um, lines of business have their own ways of thinking and doing things.
00:07:20.480 --> 00:07:23.519
It's hard to influence change with some of them.
00:07:23.680 --> 00:07:26.240
So you have to start coaching them on enterprise thinking.
00:07:26.319 --> 00:07:32.639
Like you're we're solving problems for the enterprise, not for your particular need, your team, your department, your division.
00:07:32.959 --> 00:07:34.639
Policy is a must-have.
00:07:34.959 --> 00:07:37.519
Standards are need to have, they change more.
00:07:37.680 --> 00:07:45.519
Um, so you know, not everything has to be a policy, and not unless it's an official standard that, like, for example, if it's regulated, that should go in policy.
00:07:45.680 --> 00:07:52.720
Standards can be fluid and they should change over time as, you know, things around us change, competitive environments, business models, et cetera.
00:07:52.879 --> 00:07:56.560
I think number two is the friction of compliance and operationalization.
00:07:56.720 --> 00:07:58.319
Um, it's not done when it's published.
00:07:58.480 --> 00:08:01.439
There's training and implementation and communication that has to happen.
00:08:01.600 --> 00:08:04.560
There's perceptions that you have to overcome about it being bureaucracy.
00:08:04.720 --> 00:08:11.439
Oh my God, another policy kind of a thing, or it's a checkbox item, I'll do the bare bones minimum to comply and then get on with my job.
00:08:11.680 --> 00:08:14.079
You can't develop these in a vacuum.
00:08:14.240 --> 00:08:22.319
You have to engage the people that these policies and standards and risk management exercises are going to affect.
00:08:22.480 --> 00:08:29.199
Um, if you don't consider the operational impact on productivity and velocity, um, it's it's gonna manifest when you roll it out.
00:08:29.279 --> 00:08:30.639
Um, it's not static.
00:08:30.800 --> 00:08:36.480
It has to change over time and you get them on board in the beginning, and they'll help keep things updated and refreshed over time.
00:08:36.720 --> 00:08:42.399
And I think the last one is probably um they overly focus on authority instead of incentives.
00:08:42.480 --> 00:08:44.320
And so it's it's the carrot and the stick.
00:08:44.399 --> 00:08:48.720
You know, you gotta some policies have to be mandated because of regulatory compliance.
00:08:48.799 --> 00:08:53.200
They can shut our doors temporarily, permanently, um, partially or completely.
00:08:53.279 --> 00:08:54.639
And so you gotta do these things.
00:08:54.720 --> 00:09:07.840
But everything else, it we again, rules of engagement, and as long as we all know what the rules are, we can operate autonomously doing our autonomously and independently doing our jobs and getting things done and contributing to strategic goals.
00:09:08.080 --> 00:09:13.440
So the idea there is we need to shift culture so that standards and policies become the norm.
00:09:13.600 --> 00:09:15.360
This is the cost of doing business.
00:09:15.519 --> 00:09:19.039
It makes everything more consistent, reliable, and expected.
00:09:19.120 --> 00:09:24.559
And as you can tell, as we talked about in the stakeholder engagement module, this is a people problem.
00:09:24.639 --> 00:09:27.759
It's people and perceptions of bureaucracy.
00:09:27.919 --> 00:09:32.559
Policies and standards provide clarity, direction, independence, and they make it stronger and better.
00:09:32.720 --> 00:09:39.279
So I think it's it's up to us as data governance professionals to lean into them and help everyone around us to lean into them as well.
00:09:40.159 --> 00:09:44.799
I like what you said about it being part of the culture and the part of doing business.
00:09:45.039 --> 00:09:52.480
So it's built into everything and you you don't even know it's a policy anymore because it's built into the way that you do things.
00:09:52.799 --> 00:09:53.120
Yeah.
00:09:53.279 --> 00:09:58.799
The hidden, the hidden integration and implementation of policies and standards is absolutely the best way.
00:09:59.279 --> 00:10:02.399
Yeah, because some people don't even realize it, just the way they do it.
00:10:02.720 --> 00:10:03.360
Yeah.
00:10:05.759 --> 00:10:12.559
If you join our webinars, you already know strong data governance is what makes everything else possible.
00:10:13.039 --> 00:10:13.919
Exactly.
00:10:14.080 --> 00:10:23.440
And if you're ready to build or mature your governance practice, the Dataversity Training Center is where you'll find the deep dive courses that actually show you how to do it.
00:10:23.679 --> 00:10:32.879
And once you've built that foundation, the applied data governance certification helps you prove you can turn governance principles into real organizational impact.
00:10:33.519 --> 00:10:42.399
Then bring it all together with the community at DGIQ plus EDW 2026, where the governance leaders share what really works.
00:10:42.639 --> 00:10:46.799
Start strengthening your governance journey at Dataversity.net.
00:10:50.639 --> 00:10:53.200
What does it look like in an organization?
00:10:53.600 --> 00:10:57.679
And let's think about it early in our governance, in its governance maturity.
00:10:58.240 --> 00:11:00.720
I think this is gonna resonate with a lot of people.
00:11:01.120 --> 00:11:10.399
So it's not sophisticated algorithms and formal cadences and compliance dashboards and predictive modeling on things are gonna go bad.
00:11:10.559 --> 00:11:12.799
That's that's the advanced world, right?
00:11:13.440 --> 00:11:28.720
If you are in an environment where everything is manual or semi-manual, it's reactive, it's you know, defensive and conversational, constant firefighting or being behind the A-ball, this is immature risk management early in the process.
00:11:28.879 --> 00:11:42.159
Um, if you don't even have a risk management department and you're not talking risk in your strategic plan or in your projects or you know, other uh other areas of operations, that's also a sign of immaturity.
00:11:42.399 --> 00:11:45.519
Um, you know, organizations like that, you tend to operate on tribal knowledge.
00:11:45.600 --> 00:11:47.120
You got to know who to call, how to get things done.
00:11:47.200 --> 00:11:49.519
And it's the Phonofront network or the Noah Guy network.
00:11:49.759 --> 00:11:51.919
Those are single point of failures and bottlenecks.
00:11:52.320 --> 00:11:55.039
Um, it silos data and risk too.
00:11:55.200 --> 00:12:00.320
People and departments and lines of business don't understand how their data practices affect other areas.
00:12:00.480 --> 00:12:03.919
So while this area can is concerned about SSN, I'm not.
00:12:04.080 --> 00:12:06.080
Okay, well, that's risk to the enterprise, right?
00:12:06.159 --> 00:12:10.320
And if you're not looking at this from an enterprise standpoint, you're actually contributing to the risk.
00:12:10.399 --> 00:12:14.159
And people are doing this all day long, saving files on file shares, for example.
00:12:14.320 --> 00:12:22.080
Um, we had I worked at a company where somebody took a picture of sensitive data on a screen and then emailed it because they couldn't export the data to email the data.
00:12:22.159 --> 00:12:23.919
So they emailed a picture instead.
00:12:24.000 --> 00:12:26.720
I mean, people find creative ways of getting around this.
00:12:26.960 --> 00:12:28.799
So, how does it manifest?
00:12:29.039 --> 00:12:40.240
Otherwise, you'll see errors in reports that people are complaining about, um, variation in reports, accidental discovery of you know, problems, because now the risks have manifested as issues.
00:12:40.480 --> 00:12:50.159
Audit findings oftentimes uh surface risk when you don't fulfill the audit requirements or your regulatory submissions, you you get failed repeatedly.
00:12:50.320 --> 00:12:59.120
Um, gut checks, red, yellow, green kinds of things on executive dashboards that don't have real data behind them, shadow IT and analytics, absolute risk.
00:12:59.279 --> 00:13:00.879
Um, compliance blind spots.
00:13:00.960 --> 00:13:02.240
I mentioned SSN earlier.
00:13:02.320 --> 00:13:06.000
Why aren't we talking about all the sensitive and confidential data sets at the organization?
00:13:06.080 --> 00:13:11.519
Every industry I've ever been in has focused on I probably a number of data once I could count on one hand.
00:13:11.600 --> 00:13:15.600
And then one organization, you know, you got a policy that mentions a couple dozen.
00:13:15.679 --> 00:13:17.279
Why aren't we looking at all of them, right?
00:13:17.440 --> 00:13:18.480
So what do you do?
00:13:18.720 --> 00:13:22.799
I think we need guardrails in plain English that people can understand.
00:13:22.960 --> 00:13:28.399
Things like never email a spreadsheet with personal information in it, um, or get approval to share data with external parties.
00:13:28.480 --> 00:13:30.559
You got to make it commonsensical.
00:13:30.799 --> 00:13:42.879
Um, focus on your crown jewels, the top two or three data sets that if they were to be leaked, lost, or compromised, um, you can be shut down partially or completely, maybe permanently.
00:13:43.039 --> 00:13:45.440
Um, you could regulatory fines, for example.
00:13:45.600 --> 00:13:48.879
And then I think the third thing is literacy through context.
00:13:48.960 --> 00:14:02.720
You really just have to start using real world world examples specific to their jobs, show how it impacts across the organization or at the organizational level as a whole, and get people talking to each other.
00:14:02.879 --> 00:14:18.080
A lot of it has just has to do with I don't know what's going on, I care about my own little world, but we're all we're all sort of part of this bigger organization, and we should all be thinking organizationally, like think global and act local is one of the axioms I use around that.
00:14:18.639 --> 00:14:19.600
That's a good one.
00:14:19.840 --> 00:14:24.000
Because people so many times forget this is for the good of the entire enterprise.
00:14:24.320 --> 00:14:30.480
And it may be a little more work for you, but that's why you need to do it, because it's the enterprise as a whole.
00:14:30.960 --> 00:14:36.320
And then conversely, here's what hap might happen if we don't do it or you don't do your part.
00:14:39.519 --> 00:14:43.440
Yeah, it does because people just don't stop to think about it what they're doing.
00:14:44.240 --> 00:14:50.320
If you could give one piece of advice to someone responsible for policies and standards, what would it be?
00:14:51.679 --> 00:14:53.440
So I have a rubric on this.
00:14:53.519 --> 00:14:54.799
I call it the three Ps.
00:14:55.279 --> 00:14:57.039
And I've mentioned one earlier.
00:14:57.200 --> 00:14:58.799
So the first P is proponents.
00:14:58.879 --> 00:15:00.159
It has to be human-centric.
00:15:00.320 --> 00:15:02.799
You can't create policies and standards.
00:15:02.960 --> 00:15:07.120
In fact, any guardrail, in my opinion, unless you have sole authority over it.
00:15:07.279 --> 00:15:16.240
You can't do that without inviting people to participate, especially the people who are most impacted by the standards and the policies.
00:15:16.399 --> 00:15:17.919
Get them, get them involved up front.
00:15:18.080 --> 00:15:28.080
If you don't, you know, shadow them, watch their workflows, ask them about the impact and the pain points, help them understand the need, and then ultimately find the least painful way to meet the goal.
00:15:28.240 --> 00:15:35.919
Um, I think it's called least viable policy, for example, sort of like um in agile software development, the minimal viable product.
00:15:36.080 --> 00:15:37.759
It's the same kind of concept.
00:15:38.080 --> 00:15:39.440
So, proponents.
00:15:39.600 --> 00:15:42.799
Number two is proportions, and this is about the right fit.
00:15:42.879 --> 00:15:56.960
So you don't have to treat everything like it's the most monstrously gigantic risk in the world or the most monstrously large need for uh, you know, a very complicated, you know, 20-page long standard or policy.
00:15:57.200 --> 00:16:02.799
You don't you don't want to over-engineer anything, you got to tailor the policy or the standard to the need or the risk.
00:16:02.879 --> 00:16:03.679
And you want tier.
00:16:03.840 --> 00:16:10.879
So based on the risk level, the higher the risk, the stronger, more rigorous the policy standard or guardrail is going to be.
00:16:11.039 --> 00:16:15.519
If it's low risk, then you can do more of a flexible, lightweight kind of guideline.
00:16:15.679 --> 00:16:25.919
Um, you want the minimum amount of restriction with a maximum amount of, I guess, theoretical protection, because this is all sort of theoretical until something happens, right?
00:16:26.000 --> 00:16:28.960
And then you learn from it and then you mend your policies and standards and start all over.
00:16:29.279 --> 00:16:32.799
So proponents is number one, proportions is number two.
00:16:32.960 --> 00:16:36.559
That brings us to number three, which is practices, and that's how the work gets done.
00:16:36.639 --> 00:16:38.720
And you actually alluded to this earlier.
00:16:39.039 --> 00:16:50.639
The best way to implement any policy or standard is to integrate it into the workflow or the operational process, ideally automated wherever possible, it's done.
00:16:51.039 --> 00:16:52.480
You're forced to follow it.
00:16:52.639 --> 00:16:55.519
You follow it because that's how the that's how the process works.
00:16:55.679 --> 00:17:02.000
And if you can hard code these guardrails, like block action if you're not doing it right, like a system edit.
00:17:02.080 --> 00:17:06.319
Don't put an end date that's before a start date when you're gonna go book an airline ticket.
00:17:06.400 --> 00:17:07.920
I mean, this exists everywhere, right?
00:17:08.000 --> 00:17:10.160
These are these are all risk management constructs.
00:17:10.319 --> 00:17:14.480
Keep the data good, keep the risks from getting into the system, kind of a thing.
00:17:14.640 --> 00:17:17.359
Um, and then engage education and feedback.
00:17:17.440 --> 00:17:20.079
Uh, because again, it's people on all three of these.
00:17:20.240 --> 00:17:26.160
And so it's and you can even use the three Ps, ensure that they follow proponents, proportions, and practices.
00:17:26.240 --> 00:17:27.440
They all begin with PR too.
00:17:27.519 --> 00:17:28.880
So it's kind of a tongue twister.
00:17:29.119 --> 00:17:32.480
Success is so here here's my here's my insight on all of that.
00:17:32.720 --> 00:17:43.119
Success is not, as many folks and organizations think, reflected by how many policy standards and guardrails are written, approved, and published.
00:17:43.200 --> 00:17:50.160
It's actually about how big is the gap between what these guardrails say and what people actually do.
00:17:50.319 --> 00:17:57.839
And the more people do in agreement with all of your guardrails, that is real the real mark of success.
00:17:59.279 --> 00:18:00.400
I like a three piece.
00:18:00.559 --> 00:18:02.559
That'll be a good way for people to remember that.
00:18:03.759 --> 00:18:04.400
Does it work for me?
00:18:04.559 --> 00:18:05.680
I hope it works for everybody else.
00:18:06.079 --> 00:18:08.319
Okay, I always think it's good to break it down like that.
00:18:09.200 --> 00:18:10.880
Um next question.
00:18:11.119 --> 00:18:18.559
How does data governance function as proactive risk management rather than reactive compliance?
00:18:20.000 --> 00:18:21.680
So, you know, it's interesting.
00:18:21.759 --> 00:18:30.319
Uh everywhere that I've I've built and scaled a data governance program, I've always inevitably intersected with the risk management.
00:18:30.400 --> 00:18:36.319
And in some cases, they already had data-related risk management practices in place.
00:18:36.480 --> 00:18:39.519
And in many cases, at other organizations they did not.
00:18:39.680 --> 00:18:42.880
And so it's always a surprise where they are.
00:18:43.039 --> 00:18:46.799
But you know, the proactive is if it doesn't exist, we're gonna start it.
00:18:46.880 --> 00:18:53.200
We're gonna partner with risk management and we're gonna, we're gonna start getting more data risks assessed at regular intervals.
00:18:53.279 --> 00:18:57.839
And so I think, you know, you can shift the timeline from post-mortem to pre-mortem.
00:18:58.000 --> 00:18:59.599
If you're gonna set up a database, let's do it then.
00:18:59.680 --> 00:19:11.920
You always want to go as close to upstream as far upstream as possible, as close as possible to what I call the the drip DRIP, the data recording or input point, because you're always either collecting it from humans or machines.
00:19:12.000 --> 00:19:21.200
And if you can harness the, if you can manage any sort of risk of bad data at that given point, um, then you're preventing bad data from getting into the data ecosystem altogether.
00:19:21.279 --> 00:19:21.839
So that's great.
00:19:21.920 --> 00:19:22.720
You don't want that, right?
00:19:22.799 --> 00:19:25.119
You don't want bad data to prolip proliferate.
00:19:25.359 --> 00:19:26.960
Another way is through the mechanics.
00:19:27.039 --> 00:19:30.000
So data quality source, which I was just talking about.
00:19:30.160 --> 00:19:34.559
You want you want those controls as far up as possible.
00:19:34.799 --> 00:19:36.559
You also want access controls.
00:19:36.640 --> 00:19:44.160
And so you're gonna uh in my experience, I've always partnered with information security or cybersecurity, depending on how your organization calls them.
00:19:44.319 --> 00:19:53.680
Um, you want to really get into role-based access controls and start maturing what that looks like and go it get into like it goes from R back to A back to P back.
00:19:53.920 --> 00:20:05.200
So from roles to attributes to policy-based, with it, all it really means is a maturation process to automate more and more of your security permissions provisioning and deprovisioning.
00:20:05.359 --> 00:20:11.839
And if you can do that, more automation means less manual maintenance, which translates to less risk.
00:20:12.079 --> 00:20:19.279
I've worked at organizations where too many people still had access after they were separated from the company.
00:20:19.519 --> 00:20:23.440
If you still have access and you're disgruntled, that's really not a good combination.
00:20:23.599 --> 00:20:26.559
I also worked with a gentleman who spent about 30% of his time.
00:20:26.640 --> 00:20:29.519
We actually sat down and qualified, quantified his time.
00:20:29.599 --> 00:20:33.119
And um, he was he was provisioning and deprovisioning accounts.
00:20:33.279 --> 00:20:37.920
They had set up an automated process, but he was still spending 30% of his time uh manually doing it.
00:20:38.079 --> 00:20:42.640
It was because we had folks internally that weren't following the process and they were, you know, emergency, emergency, do it.
00:20:42.720 --> 00:20:49.200
And it was not only manual setup, it was manual deprovisioning when the automated process ran and then integrated two different accounts for the same person.
00:20:49.359 --> 00:20:50.400
You don't really want that.
00:20:50.640 --> 00:20:52.400
Automated data lineage is another one.
00:20:52.480 --> 00:20:59.200
If you have, if you're maturing your data catalogs, no more figuring out how it's calculated or where it comes from.
00:20:59.359 --> 00:21:01.680
That's all manual and semi-manual forensics.
00:21:01.839 --> 00:21:06.799
No, just you can click, see the entire lineage and and definitions, and and it's all good.
00:21:07.039 --> 00:21:14.319
I think the last element that I'll add is it it proactive is you address the mindset of folks.
00:21:14.480 --> 00:21:16.480
Data literacy increases awareness.
00:21:16.720 --> 00:21:28.880
Educating people on what data risks are, what it means to have a data risk, and then how to go about managing it and mitigating it, um, that should be part of all data literacy campaigns, all data governance programs.
00:21:29.119 --> 00:21:32.960
The ultimate goal is to, again, give people autonomy and independence.
00:21:33.119 --> 00:21:43.039
Learn how to handle data safely and correctly based on regulations and laws and standards and policies, and understand that risk monitoring is now the norm.
00:21:43.200 --> 00:21:56.160
If you spread that wealth of knowledge and have more people across the organization following these standards and policies, they're they're proactively managing the risks along the way and identifying them so that they can be addressed before they become major issues.
00:21:56.799 --> 00:21:57.680
Thank you very much.
00:21:57.839 --> 00:21:58.559
That's a great answer.
00:21:58.799 --> 00:21:59.759
You know, and so much of it does.
00:22:00.160 --> 00:22:06.880
Does relate back to training and having a good data literacy program for all different roles and different levels within your company.
00:22:08.160 --> 00:22:09.920
Which leads us to our next question.
00:22:10.079 --> 00:22:15.039
Why do governance policies and standards so often fail to change behavior?
00:22:16.160 --> 00:22:20.799
So I don't think this is gonna be any surprise, but I'm gonna come back to the people side of it again.
00:22:21.200 --> 00:22:23.119
People are the biggest problem on the planet.
00:22:23.200 --> 00:22:29.839
If we've I say this all the time, I say facetiously, but I actually do believe if if we weren't here, this planet would completely self-regulate, right?
00:22:29.920 --> 00:22:30.720
It's mindsets.
00:22:30.799 --> 00:22:34.640
It's it's you can't change behaviors until you change minds.
00:22:34.799 --> 00:22:38.960
And that takes a lot more time and effort to change minds than to change behaviors.
00:22:39.119 --> 00:22:40.720
But they're sequential.
00:22:40.880 --> 00:22:44.480
If you don't change their mindsets and get folks on board, you're not gonna change their behaviors.
00:22:44.640 --> 00:22:47.359
You have to factor in how people get work done.
00:22:47.519 --> 00:22:56.480
If they perceive things as bureaucratic and time consuming, they're gonna bypass it, they're gonna come up with even new creative ways of circumventing any sort of controls you can put in place.
00:22:56.640 --> 00:22:58.160
So, no, that's bad, right?
00:22:58.240 --> 00:23:00.000
We want you to follow the standards and process.
00:23:00.079 --> 00:23:01.119
So, how do you turn that around?
00:23:01.279 --> 00:23:02.960
It's almost like plugging the holes in a dike.
00:23:03.039 --> 00:23:07.200
You can stick your finger in all 10 fingers and 10 holes, but five more holes are gonna pop up.
00:23:07.279 --> 00:23:08.240
So, what do you do at that point?
00:23:08.319 --> 00:23:11.759
Now, I need another person to come in and start plugging those holes.
00:23:11.920 --> 00:23:21.200
So I think awareness versus integration is a really good topic for um any sort of education efforts around all of this.
00:23:21.440 --> 00:23:24.079
A lot of folks aren't even aware of corporate policies.
00:23:24.240 --> 00:23:29.680
I I had a conversation once with a director of BI about classified data, and her response was, I don't even understand that.
00:23:29.759 --> 00:23:30.559
I don't know, what are you talking about?
00:23:30.720 --> 00:23:31.920
I said, Well, we have a corporate policy.
00:23:32.079 --> 00:23:33.680
Wait, what do you mean there's a corporate policy?
00:23:33.839 --> 00:23:40.720
Never even heard of it, which is fascinating to me as a BI director, you're you're pulling data together and exposing it.
00:23:40.799 --> 00:23:43.119
How do you not understand what that means, right?
00:23:43.279 --> 00:23:54.559
That is very, and it's every place I've ever been, I think there's been some semblance of annual training around, you know, some type of data confidentiality or regulated data sets.
00:23:54.720 --> 00:23:59.359
It obviously it's got to be more because if you still have folks in the organization that don't know it, that's a risk.
00:23:59.519 --> 00:24:01.839
And that means something might come out of it, right?
00:24:02.000 --> 00:24:10.880
So you got to make policies more accessible, more streamlined, more, more integrated into tools and technology.
00:24:11.119 --> 00:24:19.599
Um, make them guardrails for success and efficiency, not speed bumps or potholes that people are going to avoid or or or drive around, right?
00:24:20.000 --> 00:24:25.359
Ultimately, they make people and organizations stronger, more resilient, and more successful in the long run.
00:24:25.519 --> 00:24:35.759
So I think getting people to understand that we're trying to help them towards independence and autonomy and getting that light bulb to go on can be extremely helpful.
00:24:36.559 --> 00:24:37.839
Yeah, that's so important.
00:24:38.000 --> 00:24:43.920
And I love what you said is that you know, we have to shift the mindset before we can change the behaviors.
00:24:44.640 --> 00:24:47.519
You know, because we think ends up to be what we do.
00:24:47.759 --> 00:24:48.960
So that's so important.
00:24:50.240 --> 00:24:52.400
That leads us to our last question.
00:24:52.720 --> 00:24:58.400
What role does accountability play in turning policies and standards into lived practice?
00:25:00.319 --> 00:25:00.720
Wow.
00:25:00.960 --> 00:25:05.039
So what I mean, what is what is lack of accountability in life?
00:25:05.200 --> 00:25:09.920
Um if you could get through with zero consequences, uh is anything really gonna change?
00:25:10.079 --> 00:25:11.200
Of course not, right?
00:25:11.359 --> 00:25:13.119
It's basic psychology.
00:25:13.359 --> 00:25:18.880
Um, zero incentive to change means people are going to continue that behavior.
00:25:19.039 --> 00:25:23.279
So you have to change the consequences, or you have to change the incentive.
00:25:23.359 --> 00:25:28.400
So that's a nod to operate psychology and literally my undergraduate degree.
00:25:28.640 --> 00:25:31.599
So I use this all the time in data governance.
00:25:31.759 --> 00:25:42.000
It's you have to look for immediate, faster rewards and recognition, short-term successes that really start to showcase what we're talking about.
00:25:42.319 --> 00:25:55.039
And if folks don't understand that and they continue their behaviors, they're actually hurting the long-term evolution of benefits and stability in your environment and less risk.
00:25:55.200 --> 00:25:58.480
And so sometimes you have to, you know, connect the dots on that.
00:25:58.640 --> 00:26:03.519
Um, some examples that I've come across is, you know, developers using local hard drives for development.
00:26:03.599 --> 00:26:03.759
Why?
00:26:03.920 --> 00:26:14.960
Because it was too cumbersome to get permission to set up a virtual workstation or using your personal user account to set up jobs that are supposed to run automatically, and the person leaves the company, and all of a sudden you've got job failures all over the place.
00:26:15.119 --> 00:26:16.640
So change the standards.
00:26:16.720 --> 00:26:19.680
This should these should become part of your production deployment checklist.
00:26:19.759 --> 00:26:22.079
And if it's not met, you kick it back.
00:26:22.240 --> 00:26:32.079
Um, Starbanes actually actually did this when they required segregation of duties between dev test and prod environments, and developers couldn't have access to test or prod.
00:26:32.240 --> 00:26:35.519
So if you didn't do code-based deployment, it would get kicked back.
00:26:35.759 --> 00:26:38.960
If I can't push a button and deploy it in the production environment, it's a no-go.
00:26:39.119 --> 00:26:42.240
You need to do that with a lot of operational processes as well.
00:26:42.640 --> 00:26:45.279
Um, you can also change the measures.
00:26:45.519 --> 00:26:58.880
Um, data governance metrics like data quality KPIs or compliance KPIs or successful, you know, completion of training and standards met or standards applied types of of metrics.
00:26:59.039 --> 00:27:09.279
Um, you can tie those to executive KPIs and strategic goals and start mapping those relationships and educating executives and line of you know, line of business staff about that.
00:27:09.519 --> 00:27:14.960
You can also tie data governance metrics to budgets, performance reviews, program reporting.
00:27:15.119 --> 00:27:28.720
Um, if you are consistently not following the standard or the policy, then yes, maybe there's there's some escalation warranted, or maybe we make it more formal with uh uh some feedback in your performance review.
00:27:28.880 --> 00:27:32.720
You can certainly include it in your data governance program reporting.
00:27:33.039 --> 00:27:44.640
I think if policies and standards are published artifacts, then the accountability and the associated accountability metrics ought to be published as well.
00:27:44.799 --> 00:27:51.759
So you might have to warm people up to that idea because uh, you know, some organizations aren't really, it's kind of difficult to get them to think about that.
00:27:51.839 --> 00:27:53.359
But you know, compliance does it.
00:27:53.440 --> 00:28:02.400
So all we're asking is can we apply that to our data and just formalize it because we want to measure our progress and show the value, and metrics can actually do that, right?
00:28:02.559 --> 00:28:05.200
And policy and standards are one area where it really becomes visible.
00:28:05.279 --> 00:28:06.960
You know, integrate them in annual training.
00:28:07.039 --> 00:28:07.839
How many people completed?
00:28:08.000 --> 00:28:08.960
Do they really read it?
00:28:09.200 --> 00:28:15.680
If you can track whether they scroll through the entire document or just went right to the end and said, check, I'm in, I'm done.
00:28:15.839 --> 00:28:20.319
I mean, you know, you got to tease those apart a little bit and see what it really means.
00:28:20.400 --> 00:28:21.839
But it takes time ultimately.
00:28:22.000 --> 00:28:32.400
You got to get buy-in, you got to share your successes, and uh, you got to crowdsource everything when it comes to policies and standards because that buy-in um will make it or break it.
00:28:32.559 --> 00:28:38.960
And if they break policy and standard, then you've got risks, and now we've just tied everything together that we just talked about.
00:28:39.599 --> 00:28:40.799
That was a great way to end that.
00:28:40.880 --> 00:28:41.200
It did.
00:28:41.279 --> 00:28:44.079
It tied it all together, complete circle.
00:28:44.720 --> 00:28:45.920
Thank you so much, Jim.
00:28:46.000 --> 00:28:46.559
This was great.
00:28:46.640 --> 00:28:49.119
I have thoroughly enjoyed talking with you about this.
00:28:49.359 --> 00:28:53.279
You make uh policies and risk management sound, you know, much more interesting.
00:28:53.440 --> 00:28:54.079
I love it.
00:28:54.400 --> 00:28:55.519
Yeah, they can be fun.
00:28:55.680 --> 00:29:01.680
If you have fun and if you approach everything with fun, a fun mindset, then I think it becomes a lot less bureaucratic.
00:29:01.759 --> 00:29:04.640
So I don't think we should shy away from policies and standards.
00:29:04.720 --> 00:29:08.480
It's one of it's something I've helped every organization I've worked at do.
00:29:08.559 --> 00:29:17.759
Um, this was a delightful conversation because we touched on a lot of points that I think will help people understand what it means to maybe have a little bit of fun as you're creating policies and standards.
00:29:17.839 --> 00:29:18.799
And then, you know what?
00:29:18.880 --> 00:29:22.799
If you don't like the policies and standards, then get more involved and change them.
00:29:22.880 --> 00:29:24.960
So either way, we're gonna get you involved.
00:29:25.440 --> 00:29:26.880
Oh, that's a great piece of advice.
00:29:27.039 --> 00:29:28.000
Thank you so much.
00:29:28.400 --> 00:29:30.319
What a delightful conversation.
00:29:34.000 --> 00:29:43.920
For our listeners, if you'd like to learn more about the ADGP certification program and the applied data governance body of knowledge, visit training.dataversity.net.
00:29:44.319 --> 00:29:49.839
Until next time, I'm Barbara Neshaw, and this has been Inside Applied Data Governance.