Skip to main content

The Data Governance Maturity Model and How to Measure Where You Stand

Petr Mikeska
Petr Mikeska
CEO & Co-Founder

Updated · Published

A data governance maturity model turns a vague sense that your data is a mess into a diagnosis and a sequence of next steps. The trouble is that most organizations score themselves on what they own, a policy document, a named data owner, a catalog license, rather than on whether any of it changes what happens when somebody asks a question. In 2026 that gap got expensive, because AI agents now read governance metadata directly and act on whatever they find. This article covers the five levels, the six dimensions worth scoring, a set of diagnostic questions you can run with your team this week, and the one test that has been added to the top of the scale.

A Governance Program Is Not the Same as Maturity

Most organizations now have the structure. The EDM Association's 2026 Global Data Management Benchmark, built on responses from more than 435 organizations across over 50 countries and structured around the DCAM framework, found that more than 70% have appointed a chief data officer and more than 70% report formal governance structures.

The capability is a different story. In the same benchmark, only around 31% report advanced data strategy capability. 77% have established analytics capabilities, but just 19% show mature adoption and education around them. The org chart is finished. The habit is not.

This is the gap a maturity assessment exists to find, and it is also the reason so many assessments are useless. If the scorecard asks "do you have a data governance policy," an organization that wrote one in 2023 and has never opened it since scores the same as one where the policy decides what happens in production. Both tick the box. Only one of them is mature.

By 2027, 80% of data and analytics governance initiatives will fail due to a lack of a real or manufactured crisis. A D&A governance program that does not enable prioritized business outcomes fails.

- Gartner, Predicts 80% of D&A Governance Initiatives Will Fail by 2027

So the useful version of the question is not "what do we have." It is "what happens differently because we have it." Every level below is written that way, with an observable symptom rather than an artifact.

The Five Levels of Data Governance Maturity

The five-level shape is inherited from the Capability Maturity Model and is common to almost every framework in the space. Names vary. The progression does not. What follows uses the names most people recognize, with the symptom that actually tells you which level you are on.

The Five Levels of Data Governance Maturity THE FIVE LEVELS OF DATA GOVERNANCE MATURITY 01 Unaware no rules, no owners 02 Aware known problems, no system 03 Defined documented, not adopted 04 Managed measured and used 05 Optimized enforced where data is consumed ad hoc governed and enforced Each level is identified by an observable symptom, not by an artifact the organization owns.
Click to enlarge
LevelWhat it looks likeThe tell
1. Unaware No agreed rules, no named owners, no shared definitions. Reporting is whoever built the spreadsheet. Two people produce different numbers for the same KPI and nobody can say which one is right.
2. Aware Pockets of the organization are doing governance. Leadership recognizes the cost of not doing it. Most activity is a response to something that already broke. You know the numbers disagree, and reconciling them is a fresh project every time it matters.
3. Defined Policies are written, owners are appointed, definitions exist, and a tool is in place. Coverage and adoption are uneven. There is a documented owner and definition, and people still ask in chat because they do not know it exists.
4. Managed Governance is standard practice rather than a project. Quality is measured, lineage is traced, and stewardship is part of people's actual jobs. People find the definition without asking, and quality is measured against a threshold somebody owns.
5. Optimized Governance is continuous and largely automated. Definitions and controls are applied at the point where data is consumed, not just documented centrally. A breach of a rule opens a ticket before a human notices, and the definition reaches the query, not just the wiki.

One caution about self-scoring. Almost everyone who has bought a governance tool places themselves at Level 3, because Level 3 is where the artifacts appear. The distinction between 3 and 4 is not how much you have documented. It is whether somebody who was not in the room finds and uses it without being told to.

The Six Dimensions Worth Scoring

A single overall grade hides the thing you most need to see, which is imbalance. Organizations are routinely Level 4 on architecture and Level 1 on ownership, and the average, Level 2.5, describes nobody and suggests nothing. Score these six separately.

DimensionWhat it measuresEvidence that it is real
Ownership and accountability Whether critical data has a named owner who can be held to it You can name the owner of your top five datasets, and so can somebody outside the data team
Policies and standards Whether rules for access, retention, classification, and quality exist and bind A recent decision was changed because of a policy, and you can point to it
Metadata and discoverability Whether people can find data and understand what it means without asking a person A new analyst finds and correctly interprets a table in their first week
Data quality Whether quality is measured against thresholds rather than discussed There is a number, it has a target, and somebody's name is next to it
Architecture and integration Whether governance reaches the platforms where data actually lives Your catalog reflects the warehouse and the BI layer, not a manual inventory of them
Literacy and adoption Whether people outside the data team use any of this Business users log in on their own initiative, and you can see it in usage data

Note what the evidence column has in common. Every entry is something you could observe this week, and none of them is a document. That is deliberate, and it is the difference between an assessment that moves a program and one that produces a slide.

Run the Assessment With Your Team

You do not need a consultant for the first pass. Put the six dimensions on a wall, take the questions below one dimension at a time, and record the level the evidence supports rather than the level you are aiming for. Where the room disagrees, write down both answers, because the disagreement is itself a finding about how legible your governance is.

A. Ownership and accountability

  • Are owners named for every critical dataset, and does the owner know they are the owner?
  • Is the owner accountable for quality, accuracy, and access, or only nominally listed?
  • Is there a documented path for escalating an ownership or access dispute, and has it been used?

Scoring. No named owners is Level 1. Named owners who do not know it is Level 2. Named, documented, and aware is Level 3. Owners with measured obligations is Level 4.

B. Policies and standards

  • Do policies cover access, security, retention, classification, and quality?
  • Can a business user find the policy that applies to them without asking the data team?
  • Has a policy changed an outcome in the last quarter, and can you name the case?

Scoring. Written policies alone are Level 3. Findable, understood, and demonstrably applied is Level 4. Applied automatically at the point of access is Level 5.

C. Metadata and discoverability

  • Is there a data catalog, and does its coverage include the systems people actually query?
  • Is there a business glossary where a contested term has exactly one definition?
  • Can somebody trace a number in a report back to its source without opening a ticket?

Scoring. This dimension is the usual bottleneck, and it is where the jump from Level 2 to Level 3 is won or lost. Partial coverage of a catalog nobody opens is Level 2, whatever the license says.

D. Data quality

  • Is quality measured, with dimensions defined, or only complained about?
  • Are there thresholds, and does breaching one trigger something?
  • Do quality issues get traced to a cause, or worked around downstream?

Scoring. Discussed is Level 2. Measured is Level 3. Measured with owned thresholds is Level 4. Monitored with automatic alerting and root-cause tracing is Level 5.

E. Architecture and integration

  • Does governance tooling connect to the warehouses, BI tools, and transformation layers in use, or does it hold a manual copy of them?
  • Is lineage automated, or reconstructed by hand when somebody asks?
  • Does adding a new platform mean the governance layer covers it, or that it becomes another exception?

Scoring. A manual inventory caps this dimension at Level 2, because it is stale the day after it is compiled.

F. Literacy and adoption

  • Do people outside the data team use the catalog and glossary without being asked to?
  • Is there onboarding that makes data literacy part of a role rather than a training event?
  • Would removing the governance tooling tomorrow be noticed by the business, or only by IT?

Scoring. That last question is the honest one. If only IT would notice, you are at Level 3 no matter how good the documentation is.

Do not average the six scores. Plot them. For any process that crosses a team boundary, your effective maturity is your lowest dimension, because that is the dimension the process will fail on.

What Changed in 2026

Every level above was true five years ago. What changed is who consumes governance metadata. Until recently the audience was people, and a policy in a document was a defensible way to serve them, because a person can read a document and apply judgment. An agent cannot. It acts on whatever context it is given at the moment of the query, and a policy that lives in a PDF is not part of that context.

Gartner's top data and analytics predictions for 2026, published in March, put three markers down that all point the same way. By 2030, 50% of organizations will use autonomous AI agents to interpret governance policies and technical standards into machine-verifiable data contracts. By 2030, 50% of AI agent deployment failures will be caused by insufficient runtime enforcement and multisystem interoperability in AI governance platforms. And by 2030, universal semantic layers will be treated as critical infrastructure, alongside data platforms and cybersecurity.

Read together, those are a statement about maturity. The test at the top of the scale is no longer whether your governance is written down. It is whether it is machine-readable and applied at query time.

The 2026 Test for Governance Maturity CAN A MACHINE READ YOUR GOVERNANCE? GOVERNANCE AS DOCUMENTS GOVERNANCE AS SERVED CONTEXT Policy document Definitions on a wiki page Owners in a spreadsheet Catalog Glossary Lineage Classification MCP AI agent AI agent The policy exists. Nothing applies it at query time. Meaning, owner, and sensitivity travel with the answer. Both organizations would score Level 3 on a checklist that asks whether the policies exist.
Click to enlarge

The practical consequence is a seventh thing to score, and it applies to the six dimensions rather than sitting beside them. For each one, ask whether the output is available to a machine at the moment it is needed. Owners in a spreadsheet score zero. Owners in a catalog that an agent can query score full marks, and the underlying work of naming the owner was identical.

This is also why Gartner's August 2026 guidance to CFOs deploying AI agents in finance lands where it does. Its recommendation is to pilot governance before scaling autonomy, and to measure success by governance readiness rather than by autonomy or return. That is a maturity assessment by another name, run before the agent goes near a general ledger.

This is where a context layer fits a maturity program. The catalog, business glossary, lineage, and classification that Levels 3 to 5 ask for are the same assets an agent needs, and Dawiso connects to more than 40 platforms to build them once and serve them to any MCP-compatible agent. The governance work does not change. What changes is that it stops being a document and starts being an answer.

How to Move Up One Level

Maturity models are frequently misused as a target. Nobody needs to be Level 5 everywhere, and organizations that try to jump two levels at once usually produce documentation rather than change. Move one level, on the dimension that is holding the rest back.

Level 1 to 2. Do not start a program. Pick one contested metric that costs a real argument every month, get the two parties in a room, and write down one definition. The goal is not the definition. It is the demonstration that the argument can end.

Level 2 to 3. This is the longest jump and the one most programs stall on, because it is the first that asks people to change how they work. Stand up a data catalog so data becomes discoverable, establish a business glossary so definitions have one home, and assign owners who know they are owners. Coverage matters more than depth here. A catalog covering 80% of what people query beats a perfect one covering 20%.

Level 3 to 4. Stop adding documentation and start measuring. Put thresholds on quality, automate lineage rather than reconstructing it, and give stewardship a place in job descriptions and in the calendar. The signal you have arrived is that people find answers without asking a person.

Level 4 to 5. Move enforcement to the point of consumption. Definitions applied in the query, classification applied at access, alerting on quality breaches rather than reporting on them, and governance metadata served to the systems and agents that act on data. This is the level where the 2026 test above becomes the whole of the work.

Where DCAM, DMM, and DAMA-DMBOK Fit

Three established frameworks come up whenever an assessment gets formal, and they are complementary rather than competing.

DCAM, the Data Management Capability Assessment Model from the EDM Association, is the most widely used in financial services and is the structure behind the benchmark cited at the top of this article. Version 3 was announced in June 2025 and version 3.1 followed in April 2026, adding guidance for cloud-native architectures and AI, consolidating the architectural capabilities into one component, and deepening the treatment of governance, privacy, and protection.

CMMI DMM, the Data Management Maturity model, supplies the classic five-level progression that most in-house scorecards borrow from, including this one.

DAMA-DMBOK is a body of knowledge rather than a scoring instrument. It is best used as the reference for what to assess, with the levels coming from one of the other two.

Which you pick matters less than picking one and staying with it, because the value of a maturity assessment is almost entirely in the second measurement. A score with nothing to compare it to is an opinion. For the broader capability picture that governance maturity sits inside, see our glossary entry on the data maturity model, and for the AI-specific version of the same exercise, the AI maturity assessment.

One last thing worth saying plainly. The reason to measure maturity is not to have a number. It is that the number makes an argument for you. A CFO who will not fund "data governance" will fund "we are Level 2 on ownership and it cost us a restatement," and the assessment is how that sentence gets written.

FAQ

What is data governance maturity?
Data governance maturity describes how far an organization has moved from ad hoc, reactive data management toward governance that is defined, measured, and enforced where data is consumed. It is expressed as a level, usually one of five, and it is assessed across several dimensions separately rather than as a single grade. The point of measuring it is not the score. It is the sequence of next steps the score implies.
What are the five levels of data governance maturity?
Level 1 Unaware, where there are no agreed rules or owners and the same metric returns different numbers. Level 2 Aware, where the organization knows the numbers disagree and reconciles them by hand each time. Level 3 Defined, where owners, definitions, and policies are documented but adoption is patchy. Level 4 Managed, where definitions are found without asking and quality is measured against thresholds somebody owns. Level 5 Optimized, where governance is enforced at the point of consumption and a breach raises a ticket before a human notices.
How do you measure data governance maturity?
Score six dimensions separately, ownership and accountability, policies and standards, metadata and discoverability, data quality, architecture and integration, and literacy and adoption. For each one, ask three evidence questions and record the level the evidence supports, not the level you intend to reach. Then plot the profile rather than averaging it. For any process that crosses team boundaries, your effective maturity is your lowest dimension, because that is the one the process will fail on.
What is the difference between a data governance maturity model and a data maturity model?
A data maturity model assesses the whole data capability of an organization, including strategy, architecture, analytics, and literacy. A data governance maturity model is the governance slice of that, ownership, policies, metadata, quality, and how consistently they are applied. Governance maturity is usually the constraint on the wider score, because analytics and AI both inherit whatever the governance layer failed to settle.
Which data governance maturity framework should we use?
DCAM from the EDM Association is the most common choice in financial services and is the structure behind its global benchmark. CMMI DMM gives the classic five-level progression. DAMA-DMBOK is a body of knowledge rather than a scoring model, so it is used as the reference for what to assess. Which one matters less than using one consistently, because the value comes from re-measuring against the same definitions rather than from the framework itself.
How long does it take to move up a maturity level?
Moving one level is a matter of quarters, not weeks, and the jump from Level 2 to Level 3 is usually the longest because it is the one that requires people to change how they work rather than just buying a tool. The levels above it move faster, because by then discovery, ownership, and definitions already exist and the remaining work is measurement and enforcement on top of them.

Sources

See it in action

Dawiso Data Catalog

The discovery, ownership, and definitions that Level 3 asks for, in one place.

A cookie a day keeps bad UX away.

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. By clicking "Accept All", you allow us to use cookies for analytics and ads via Google Tag Manager. You can also customize cookies.

Customize Consent Preferences

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners. Privacy Policy

Necessary cookies allow core website functionality such as user login and account management. The website cannot be used properly without strictly necessary cookies.

Functionality cookies are used to remember visitor information on the website, eg. language, timezone, enhanced content.

Analytics cookies are used to see how visitors use the website, eg. analytics cookies. Those cookies cannot be used to directly identify a certain visitor.

We use Microsoft Clarity to see how you use our website (including heatmaps and session replays) so we can improve it. By using our site, you agree that we and Microsoft can collect and use this data. See our Privacy Policy for details.

Advertisement cookies are used to identify visitors between different websites, eg. content partners, banner networks. Those cookies may be used by companies to build a profile of visitor interests or show relevant ads on other websites.