Every month, a manufacturer with multiple plants receives shipment data that is difficult to reconcile. Some plants report net shipped pounds after returns; others report gross shipments and treat returns separately. Some reports measure shipments in volume; others use revenue value.
Financial reporting depends on data generated across multiple enterprise systems, each maintaining distinct data models and control structures. As the example of the hypothetical manufacturer suggests, that can create data silos and inconsistent or incomplete data, which can cost time and money and lead to poor decision-making.
Data governance is the crucial ingredient that integrates enterprise systems to operate coherently under shared accountability. It aligns policies, ownership structures, standardized definitions, and monitoring mechanisms across domains to support data integrity and quality, auditability, and regulatory compliance.
WHAT DATA GOVERNANCE IS AND WHAT IT ISN’T
When thoughtfully implemented, data governance clarifies ownership, standardizes definitions, documents lineage, and embeds monitoring practices that support reporting reliability. These elements strengthen audit defensibility and improve management’s ability to demonstrate completeness and accuracy under the 2002 Sarbanes-Oxley Act (SOX) and broader internal control frameworks.
But data governance is not a single framework that can be universally applied. And it is not self-sustaining. Without periodic review and executive oversight, accountability may weaken. Governance therefore requires continued reinforcement, alignment with audit and assurance processes, and adaptation as systems and regulatory expectations evolve.
Governance structures are typically tailored to an organization’s data architecture, enterprise application environments, industry requirements, and regulatory obligations. Structured guidance is provided by reference models such as the Data Management Body of Knowledge (DAMA-DMBOK), a guidebook of widely accepted principles and best practices, or the Data Management Capability Assessment Model (DCAM), a framework for evaluating and strengthening data management practices. Organizations should therefore view these frameworks as reference guides rather than prescriptive implementation models.
As artificial intelligence (AI) and advanced analytics become increasingly embedded in forecasting, risk assessment, and operational decision processes, the reliability of enterprise data carries greater significance. These technologies depend on standardized, traceable, and well-defined inputs. When data resides across multiple systems and functional domains, inconsistencies can propagate rather than resolve.
Strong governance therefore supports not only regulatory compliance and reporting integrity but also the disciplined use of analytics across the business.
CHOOSING THE RIGHT GOVERNANCE MODEL
Translating data governance principles into practice requires an operating structure. Organizations generally adopt one of three governance models: centralized, federated, or hybrid. (See the illustration, “Comparison of Common Data Governance Operating Models.”)

In a centralized model, governance authority resides within a dedicated data office or executive data function. The centralized authority defines and enforces standards, policies, and stewardship requirements across business domains. This structure can provide uniformity and clear oversight, particularly where systems and reporting requirements are relatively standardized.
In a federated model, governance responsibilities are distributed across business domains. Individual functions retain ownership of their data while operating under shared enterprise standards and oversight mechanisms. This model reflects the operational reality that data is created, managed, and understood within functional areas.
Hybrid models combine elements of both approaches. Enterprise-level policies and standards are established centrally, while execution, stewardship, and operational accountability remain embedded within business units.
The appropriate model depends on organizational size, system complexity, regulatory exposure, and reporting obligations. In multisystem enterprises with distributed data ownership, federated or hybrid structures often provide greater alignment with operational realities.
Within these models, leadership is defined by accountability for outcomes rather than ownership of systems. Financial reporting consolidates outputs across domains and is subject to audit and regulatory scrutiny. As a result, finance is accountable for the integrity of reported results, even when underlying data originates in operational systems outside its direct control.
This accountability places finance in a structurally central role within federated or hybrid governance models. Finance may serve as executive sponsor, participate in governance councils, define reporting standards, or act as an escalation point when cross-domain inconsistencies affect financial outcomes. While finance may not “own” all enterprise data, it is often well positioned to anchor governance coordination where enterprise data intersects with financial reporting obligations.
5 STEPS TO IMPLEMENT DATA GOVERNANCE IN AN ORGANIZATION
Implementing data governance requires structured progression. Governance structures are most effective when they are grounded in an understanding of the organization’s current data environment. A clear baseline allows governance efforts to build on existing controls to avoid duplicating or misaligning them.
Step 1: Assess data maturity and state of data practices
To operationalize governance, select a recognized framework to assess an organization’s data maturity and evaluate the current state of its data practices. Established frameworks, which define what data governance is and how it should work, include Gartner’s data governance maturity model and the AICPA’s steps in implementing data governance. They provide structured criteria for assessing governance capabilities across dimensions such as ownership clarity, data quality management, policy enforcement, monitoring mechanisms, and executive oversight.
Taking a structured look at the management and use of data assesses an organization’s data maturity. Such a maturity assessment should focus on:
- Identification of primary data sources across enterprise systems.
- Consistency of key metric definitions across functions.
- Documentation of data definitions, attributes, and lineage from source systems to financial reports. That includes data dictionaries and metadata repositories.
- Existing data ownership and stewardship assignments.
- Established standards, policies, and access controls.
- Evaluation of data security, privacy, and compliance management.
- Frequency and nature of reconciliation adjustments.
- Audit findings related to data integrity or reporting inconsistencies.
The objective of this assessment is to identify structural gaps and coordination challenges that affect reporting accuracy. In many cases, organizations already have strong system-level controls and compliance procedures. The assessment clarifies where those controls operate effectively and where cross-functional alignment may be limited.
By documenting the governance efforts in a current state, leadership can prioritize areas of highest impact, align stakeholders across functions, and design governance structures that reflect operational realities rather than theoretical frameworks.
Step 2: Establish accountability and governance structure
Effective data governance requires clearly defining who’s responsible and how governance is executed. Without explicit decision rights and role clarity, standards remain advisory and inconsistencies persist across domains.
Governance is typically formalized through an executive sponsor or data governance council. This body provides strategic oversight, approves enterprise standards, resolves cross-functional conflicts, and serves as the escalation authority for data issues.
In addition to the sponsor or governance council, organizations should establish governance roles appropriate to their structure and reporting needs (see the illustration, “Enterprise Data Governance Accountability Structure”):
- Data owners hold decision rights for defined data domains and typically oversee staff creating or entering the data. They are accountable for the accuracy, definition, and authorized use of data and ensure alignment with regulatory and reporting obligations.
- Data stewards support operational governance. They maintain definitions and metadata, monitor quality indicators, document lineage, and coordinate issue resolution within their domains.
- Analytical experts ensure that governed definitions are consistently applied in reporting and performance analysis, identifying discrepancies that affect financial interpretation.
- Technical experts implement and maintain system–level controls, data pipelines, and infrastructure that enable governance standards to operate effectively.

Clear escalation pathways must also be formalized. When inconsistencies affect financial reporting or regulatory exposure, governance structures should specify who has the authority to resolve disputes and mandate corrective action.
By defining executive oversight, ownership by function, operational stewardship, analytical alignment, and technical enablement, organizations establish the structural foundation necessary to implement effective governance.
Step 3: Standardize definitions and establish data lineage
Once accountability is defined, organizations must decide how data is defined and traced.
Inconsistent definitions are one of the most common sources of reconciliation and reporting disputes.
Governance requires formal documentation of key data elements, including agreed-upon definitions, calculation logic, and usage parameters. These standards should be maintained in accessible data dictionaries or metadata repositories and approved by designated data owners.
Equally important is data lineage and the establishment of a source of truth for key metrics and data elements. Organizations should identify the authoritative system or dataset that serves as the approved reference point for reporting. They must also document how data moves from source systems through transformations, aggregations, and reporting layers. Together, source-of-truth designation and data lineage provide traceability from operational inputs to financial outputs and reduce ambiguity when information is consolidated across functions.
This step aligns closely with internal control principles developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and regulatory expectations established by SOX. Financial reporting controls require that management demonstrates traceability, completeness, and accuracy of reported figures. Standardized definitions and documented lineage support these control objectives and reduce dependency on informal knowledge.
ISO 8000, an international standard for data quality, can also serve as a useful reference in this stage, as it emphasizes data quality dimensions such as accuracy, completeness, consistency, and traceability. These principles help organizations evaluate whether standardized definitions and documented lineage produce reliable and usable data across reporting processes.
Step 4: Formalize policies for controls and access
Enforceable policies support standardization. They formalize how data is accessed, modified, approved, and retained. These policies should align with existing internal control frameworks, including segregation of duties, access management, and change control processes. Where financial data is involved, SOX control requirements should be embedded directly into governance procedures.
Policies should address:
- Role–based access controls.
- Change management for data definitions and reporting calculations.
- Data validation and quality review procedures.
- Documentation standards.
- Retention and archival practices.
Governance at this level ensures that standardized definitions are protected by system-level controls and monitored for compliance.
Step 5: Embed monitoring, reporting, and reinforcement
Governance requires ongoing oversight. Monitoring mechanisms should include:
- Data quality indicators and exception reports.
- Periodic review of key definitions and metrics.
- Audit trail validation and control testing.
- Cross–functional governance meetings to review unresolved issues.
This reinforces alignment between governance and internal audit practices. SOX compliance testing, external audit procedures, and regulatory reviews often reveal breakdowns in cross-functional coordination rather than system-level failures. Monitoring allows organizations to detect and resolve such issues proactively.
Training and communication also play an important role in sustaining governance efforts. As data definitions, policies, or reporting procedures evolve, organizations should periodically re-educate employees responsible for creating, modifying, or using data. Operational teams, analysts, and system administrators should understand not only governance standards, but also the rationale behind any changes to ensure those standards are applied consistently over time.
By embedding monitoring and reinforcement mechanisms, organizations transform governance from a documentation exercise into a recurring operational discipline.
TECHNOLOGY HELPS ENABLE GOVERNANCE
While governance is fundamentally a structural and accountability discipline, technology plays an enabling role in its execution. Modern data catalog tools, metadata repositories, lineage tracking platforms, and data quality monitoring systems can support documentation, traceability, and oversight at scale. Access management systems and workflow tools help enforce role-based controls and approval processes aligned with governance standards.
Increasingly, organizations are also leveraging analytics platforms and AI to monitor anomalies, detect inconsistencies, and assess data quality indicators. However, technology does not substitute for defined ownership, standardized definitions, or escalation structures. Without clear accountability and policy alignment, governance tools risk becoming documentation repositories rather than operational controls.
Effective implementation therefore integrates governance structures with enabling technologies, aligning technical capabilities with defined ownership, control expectations under SOX and internal control frameworks, and ongoing monitoring practices.
ADDRESSING INCONSISTENT DATA
In the hypothetical example of the multi-plant manufacturer, a governance review identified that the issue was structural rather than technical. There was no formally assigned data owner for the metric, no documented lineage from plant-level enterprise resource planning outputs to consolidated dashboards, and no enterprise standard governing how returns or timing differences should be treated. As a result, finance teams spent considerable time reconciling differences between plants, reporting timelines were extended, and stakeholders relied on manual adjustments and individual interpretation to produce consolidated results. Beyond the operational burden, these inconsistencies increased the risk of reporting errors and reduced the auditability of the metrics.
Governance intervention focused on three actions. First, a formal data owner was designated, with authority to approve a single enterprise definition of “Shipments.” Second, calculation logic and treatment rules were standardized and documented across plants. Third, reporting policies and validation checks were implemented to prevent deviations from the approved definition.
The reduction in reconciliation effort resulted directly from eliminating definitional variability.
As a result, preparation time associated with this metric declined by approximately 40%, and audit documentation improved through documented lineage and ownership clarity.
The improvement did not stem from new technology, but from defined accountability, standardized definitions, and enforceable governance structures that removed ambiguity at the source.
About the author
Swetha Pandiri is an FP&A business systems manager at Kaiser Aluminum in Franklin, Tenn. To comment on this article or to suggest an idea for another article, contact Jeff Drew at Jeff.Drew@aicpa-cima.com.
LEARNING RESOURCES
The Convergence of AI, Data, and Cybersecurity
Explore how AI is changing data access, cybersecurity risk, and governance. Plus, learn how finance, audit, and IT leaders can balance innovation with control.
2pm–3pm (EDT) Aug. 6
webcast
Data Management & Analytics Certificate
Gain critical knowledge in business intelligence, data management, and data analytics that will help you augment your accounting expertise, acquire a new skil,l or complete the CITP credential.
CPE SELF-STUDY
For more information or to make a purchase, go to aicpa-cima.com/cpe-learning or call 888-777-7077.
MEMBER RESOURCES
Engage365 Communities
Corporate Accounting & Finance
Make new contacts and join interesting discussions at the Engage365 Corporate Accounting & Finance Community: a dedicated space to connect with experts, peers, and thought leaders as you navigate the complexities of the modern business world.
Articles
“What It Takes for a CFO to Lead Operations and Tech,” JofA, June 8, 2026
“AI and Governance Issues: 3 Keys to Bridging a Costly Gap,” JofA, April 23, 2026
“As Finance Duties Shift, CAOs Take on Strategic Role,” JofA, Dec. 1, 2025
“Trends in Data Analytics, Visualizations & Business Intelligence,” Technology Strategic Advisory Group, Nov. 26, 2025
Podcast episode
“Big Data & AI Technologies: Fundamentals and Applications,” Reshaping Finance, April 8, 2025

