The Data Governance Maturity Model and How to Measure Where You Stand
Updated · Published
A data governance maturity model turns a vague sense that your data is a mess into a diagnosis and a sequence of next steps. The trouble is that most organizations score themselves on what they own, a policy document, a named data owner, a catalog license, rather than on whether any of it changes what happens when somebody asks a question. In 2026 that gap got expensive, because AI agents now read governance metadata directly and act on whatever they find. This article covers the five levels, the six dimensions worth scoring, a set of diagnostic questions you can run with your team this week, and the one test that has been added to the top of the scale.
A Governance Program Is Not the Same as Maturity
Most organizations now have the structure. The EDM Association's 2026 Global Data Management Benchmark, built on responses from more than 435 organizations across over 50 countries and structured around the DCAM framework, found that more than 70% have appointed a chief data officer and more than 70% report formal governance structures.
The capability is a different story. In the same benchmark, only around 31% report advanced data strategy capability. 77% have established analytics capabilities, but just 19% show mature adoption and education around them. The org chart is finished. The habit is not.
This is the gap a maturity assessment exists to find, and it is also the reason so many assessments are useless. If the scorecard asks "do you have a data governance policy," an organization that wrote one in 2023 and has never opened it since scores the same as one where the policy decides what happens in production. Both tick the box. Only one of them is mature.
By 2027, 80% of data and analytics governance initiatives will fail due to a lack of a real or manufactured crisis. A D&A governance program that does not enable prioritized business outcomes fails.
- Gartner, Predicts 80% of D&A Governance Initiatives Will Fail by 2027
So the useful version of the question is not "what do we have." It is "what happens differently because we have it." Every level below is written that way, with an observable symptom rather than an artifact.
The Five Levels of Data Governance Maturity
The five-level shape is inherited from the Capability Maturity Model and is common to almost every framework in the space. Names vary. The progression does not. What follows uses the names most people recognize, with the symptom that actually tells you which level you are on.
| Level | What it looks like | The tell |
|---|---|---|
| 1. Unaware | No agreed rules, no named owners, no shared definitions. Reporting is whoever built the spreadsheet. | Two people produce different numbers for the same KPI and nobody can say which one is right. |
| 2. Aware | Pockets of the organization are doing governance. Leadership recognizes the cost of not doing it. Most activity is a response to something that already broke. | You know the numbers disagree, and reconciling them is a fresh project every time it matters. |
| 3. Defined | Policies are written, owners are appointed, definitions exist, and a tool is in place. Coverage and adoption are uneven. | There is a documented owner and definition, and people still ask in chat because they do not know it exists. |
| 4. Managed | Governance is standard practice rather than a project. Quality is measured, lineage is traced, and stewardship is part of people's actual jobs. | People find the definition without asking, and quality is measured against a threshold somebody owns. |
| 5. Optimized | Governance is continuous and largely automated. Definitions and controls are applied at the point where data is consumed, not just documented centrally. | A breach of a rule opens a ticket before a human notices, and the definition reaches the query, not just the wiki. |
One caution about self-scoring. Almost everyone who has bought a governance tool places themselves at Level 3, because Level 3 is where the artifacts appear. The distinction between 3 and 4 is not how much you have documented. It is whether somebody who was not in the room finds and uses it without being told to.
The Six Dimensions Worth Scoring
A single overall grade hides the thing you most need to see, which is imbalance. Organizations are routinely Level 4 on architecture and Level 1 on ownership, and the average, Level 2.5, describes nobody and suggests nothing. Score these six separately.
| Dimension | What it measures | Evidence that it is real |
|---|---|---|
| Ownership and accountability | Whether critical data has a named owner who can be held to it | You can name the owner of your top five datasets, and so can somebody outside the data team |
| Policies and standards | Whether rules for access, retention, classification, and quality exist and bind | A recent decision was changed because of a policy, and you can point to it |
| Metadata and discoverability | Whether people can find data and understand what it means without asking a person | A new analyst finds and correctly interprets a table in their first week |
| Data quality | Whether quality is measured against thresholds rather than discussed | There is a number, it has a target, and somebody's name is next to it |
| Architecture and integration | Whether governance reaches the platforms where data actually lives | Your catalog reflects the warehouse and the BI layer, not a manual inventory of them |
| Literacy and adoption | Whether people outside the data team use any of this | Business users log in on their own initiative, and you can see it in usage data |
Note what the evidence column has in common. Every entry is something you could observe this week, and none of them is a document. That is deliberate, and it is the difference between an assessment that moves a program and one that produces a slide.
Run the Assessment With Your Team
You do not need a consultant for the first pass. Put the six dimensions on a wall, take the questions below one dimension at a time, and record the level the evidence supports rather than the level you are aiming for. Where the room disagrees, write down both answers, because the disagreement is itself a finding about how legible your governance is.
A. Ownership and accountability
- Are owners named for every critical dataset, and does the owner know they are the owner?
- Is the owner accountable for quality, accuracy, and access, or only nominally listed?
- Is there a documented path for escalating an ownership or access dispute, and has it been used?
Scoring. No named owners is Level 1. Named owners who do not know it is Level 2. Named, documented, and aware is Level 3. Owners with measured obligations is Level 4.
B. Policies and standards
- Do policies cover access, security, retention, classification, and quality?
- Can a business user find the policy that applies to them without asking the data team?
- Has a policy changed an outcome in the last quarter, and can you name the case?
Scoring. Written policies alone are Level 3. Findable, understood, and demonstrably applied is Level 4. Applied automatically at the point of access is Level 5.
C. Metadata and discoverability
- Is there a data catalog, and does its coverage include the systems people actually query?
- Is there a business glossary where a contested term has exactly one definition?
- Can somebody trace a number in a report back to its source without opening a ticket?
Scoring. This dimension is the usual bottleneck, and it is where the jump from Level 2 to Level 3 is won or lost. Partial coverage of a catalog nobody opens is Level 2, whatever the license says.
D. Data quality
- Is quality measured, with dimensions defined, or only complained about?
- Are there thresholds, and does breaching one trigger something?
- Do quality issues get traced to a cause, or worked around downstream?
Scoring. Discussed is Level 2. Measured is Level 3. Measured with owned thresholds is Level 4. Monitored with automatic alerting and root-cause tracing is Level 5.
E. Architecture and integration
- Does governance tooling connect to the warehouses, BI tools, and transformation layers in use, or does it hold a manual copy of them?
- Is lineage automated, or reconstructed by hand when somebody asks?
- Does adding a new platform mean the governance layer covers it, or that it becomes another exception?
Scoring. A manual inventory caps this dimension at Level 2, because it is stale the day after it is compiled.
F. Literacy and adoption
- Do people outside the data team use the catalog and glossary without being asked to?
- Is there onboarding that makes data literacy part of a role rather than a training event?
- Would removing the governance tooling tomorrow be noticed by the business, or only by IT?
Scoring. That last question is the honest one. If only IT would notice, you are at Level 3 no matter how good the documentation is.
Do not average the six scores. Plot them. For any process that crosses a team boundary, your effective maturity is your lowest dimension, because that is the dimension the process will fail on.
What Changed in 2026
Every level above was true five years ago. What changed is who consumes governance metadata. Until recently the audience was people, and a policy in a document was a defensible way to serve them, because a person can read a document and apply judgment. An agent cannot. It acts on whatever context it is given at the moment of the query, and a policy that lives in a PDF is not part of that context.
Gartner's top data and analytics predictions for 2026, published in March, put three markers down that all point the same way. By 2030, 50% of organizations will use autonomous AI agents to interpret governance policies and technical standards into machine-verifiable data contracts. By 2030, 50% of AI agent deployment failures will be caused by insufficient runtime enforcement and multisystem interoperability in AI governance platforms. And by 2030, universal semantic layers will be treated as critical infrastructure, alongside data platforms and cybersecurity.
Read together, those are a statement about maturity. The test at the top of the scale is no longer whether your governance is written down. It is whether it is machine-readable and applied at query time.
The practical consequence is a seventh thing to score, and it applies to the six dimensions rather than sitting beside them. For each one, ask whether the output is available to a machine at the moment it is needed. Owners in a spreadsheet score zero. Owners in a catalog that an agent can query score full marks, and the underlying work of naming the owner was identical.
This is also why Gartner's August 2026 guidance to CFOs deploying AI agents in finance lands where it does. Its recommendation is to pilot governance before scaling autonomy, and to measure success by governance readiness rather than by autonomy or return. That is a maturity assessment by another name, run before the agent goes near a general ledger.
This is where a context layer fits a maturity program. The catalog, business glossary, lineage, and classification that Levels 3 to 5 ask for are the same assets an agent needs, and Dawiso connects to more than 40 platforms to build them once and serve them to any MCP-compatible agent. The governance work does not change. What changes is that it stops being a document and starts being an answer.
How to Move Up One Level
Maturity models are frequently misused as a target. Nobody needs to be Level 5 everywhere, and organizations that try to jump two levels at once usually produce documentation rather than change. Move one level, on the dimension that is holding the rest back.
Level 1 to 2. Do not start a program. Pick one contested metric that costs a real argument every month, get the two parties in a room, and write down one definition. The goal is not the definition. It is the demonstration that the argument can end.
Level 2 to 3. This is the longest jump and the one most programs stall on, because it is the first that asks people to change how they work. Stand up a data catalog so data becomes discoverable, establish a business glossary so definitions have one home, and assign owners who know they are owners. Coverage matters more than depth here. A catalog covering 80% of what people query beats a perfect one covering 20%.
Level 3 to 4. Stop adding documentation and start measuring. Put thresholds on quality, automate lineage rather than reconstructing it, and give stewardship a place in job descriptions and in the calendar. The signal you have arrived is that people find answers without asking a person.
Level 4 to 5. Move enforcement to the point of consumption. Definitions applied in the query, classification applied at access, alerting on quality breaches rather than reporting on them, and governance metadata served to the systems and agents that act on data. This is the level where the 2026 test above becomes the whole of the work.
Where DCAM, DMM, and DAMA-DMBOK Fit
Three established frameworks come up whenever an assessment gets formal, and they are complementary rather than competing.
DCAM, the Data Management Capability Assessment Model from the EDM Association, is the most widely used in financial services and is the structure behind the benchmark cited at the top of this article. Version 3 was announced in June 2025 and version 3.1 followed in April 2026, adding guidance for cloud-native architectures and AI, consolidating the architectural capabilities into one component, and deepening the treatment of governance, privacy, and protection.
CMMI DMM, the Data Management Maturity model, supplies the classic five-level progression that most in-house scorecards borrow from, including this one.
DAMA-DMBOK is a body of knowledge rather than a scoring instrument. It is best used as the reference for what to assess, with the levels coming from one of the other two.
Which you pick matters less than picking one and staying with it, because the value of a maturity assessment is almost entirely in the second measurement. A score with nothing to compare it to is an opinion. For the broader capability picture that governance maturity sits inside, see our glossary entry on the data maturity model, and for the AI-specific version of the same exercise, the AI maturity assessment.
One last thing worth saying plainly. The reason to measure maturity is not to have a number. It is that the number makes an argument for you. A CFO who will not fund "data governance" will fund "we are Level 2 on ownership and it cost us a restatement," and the assessment is how that sentence gets written.
FAQ
What is data governance maturity?
What are the five levels of data governance maturity?
How do you measure data governance maturity?
What is the difference between a data governance maturity model and a data maturity model?
Which data governance maturity framework should we use?
How long does it take to move up a maturity level?
Sources
- EDM Association - 2026 Global Data Management Benchmark
- EDM Council - Announcing DCAM v3
- Gartner - Predicts 80% of D&A Governance Initiatives Will Fail by 2027
- Gartner - Top Predictions for Data and Analytics in 2026
- Gartner - CFOs Must Pilot Governance First Before Scaling AI Agents
See it in action
Dawiso Data Catalog
The discovery, ownership, and definitions that Level 3 asks for, in one place.