The funded, tooled-up programme that nobody uses
Parts one and two described two changes that removed the historical obstacles to data governance. APRA made the artefacts prudential evidence, and enterprise AI produced a sponsor whose own objectives fail without them. Neither change touches the reason governance decays, and the evidence for that is the number of organisations holding all three of budget, licensed platform and populated catalogue while achieving nothing that a supervisor would accept as control.
Gartner attributes the 80 per cent failure rate to organisational rather than technical causes (Gartner 2024). Our own observation from implementation work is narrower and more specific: the failure occurs at the point of adoption. The tools work. The people who must use them do not.
Expert-gating happens in two ways, and both are design choices
The pattern repeats across implementations, and we offer it as practitioner observation rather than as a sourced finding. Technology teams deploy the platforms — Microsoft Purview, Collibra, Unity Catalog, Immuta, Delphix and comparable products — competently and to schedule. The stewards, information owners and first-line risk staff who must then use and maintain the records find the platform inaccessible in two distinct ways.
It is inaccessible physically, because licensing models and seat allocations exclude occasional users, and the workflows that matter sit inside administrator consoles. It is inaccessible intellectually, because the interfaces assume the mental model of a metadata specialist, and the learning curve defeats people whose actual job is running a claims process, a payment operation or a reporting cycle.
Organisations adapt by concentrating platform use among a small number of trained experts, through whom every question, update and attestation must pass. This reproduces the gatekeeper arrangement that governance was introduced to remove. Visibility falls for the very people who are accountable, knowledge concentrates in a handful of staff, and processes slow because they now depend on intermediaries. Spreadsheets, email attestations and shadow registers reappear. A fully licensed governance platform that nobody uses is not an underperforming investment; it is a control failure with an invoice attached.
What the alternative looks like in practice
Consider an information owner in a claims operation who must confirm each quarter that critical data assets are correctly classified and access-controlled. Under the arrangement most programmes build, she needs a licence she uses four times a year, must relearn a portal she has not opened since the previous quarter, and will ask a specialist for help before signing. What she produces is a superficial attestation that satisfies a tracker and evidences very little.
Under the alternative, the confirmation reaches her as a pre-populated task inside the workflow tool she already has open, shows what has changed since the last quarter, and takes minutes. The second arrangement produces stronger evidence than the first, and it produces it reliably. The difference is not the platform. Both arrangements can be built on the same product. The difference is where the work was placed and whose day it was designed around.
The published frameworks describe the what, not the how
It would be wrong to suggest the discipline lacks rigour. DAMA's Data Management Body of Knowledge is a thorough reference for what data management comprises (DAMA International 2017), and the EDM Council's DCAM and CDMC provide structured capability and maturity models used widely in regulated industries (EDM Council n.d.). These are serious artefacts and any programme should be conversant with them.
They are also reference materials and maturity benchmarks rather than operational architectures. Reviewing those three, we find none that specifies how governance is performed by a non-specialist: which role executes which workflow, against what service levels, using which tool, with what skills, and at what point in that person's existing working day. Vendors market adoption features such as usage analytics, business-user experiences, copilots and auto-curation, but treat adoption as a product feature rather than as the design constraint it is. Governance actions consequently remain inside vendor portals rather than inside the tools people already have open.
None of this is peculiar to data governance. The transformation literature has held for years that large change programmes fail on aspiration, conviction, capability and accountability rather than on technology, though the frequently quoted failure rates are self-reported and their precision is contested (McKinsey 2019). Data governance is a clean instance of the pattern for one reason: its users are conscripts rather than volunteers.
What a centre of excellence is actually selling
Anyone who scopes a data governance transformation as a tool implementation followed by an announcement and a hyperlink has mistaken distribution for adoption.
A programme succeeds at the precise moment when the target user's cheapest route to completing their own work runs through the governance capability: when checking the catalogue is faster than asking a colleague, when attesting inside the workflow beats maintaining a private spreadsheet, when ownership metadata saves an operations manager an escalation. Before that moment, the centre pushes every unit of adoption uphill, and the programme's true running cost includes an indefinite series of relaunches. This is our argument rather than a sourced finding; the evidence set out across this series is consistent with it, and we have found none against it.
Zhamak Dehghani states the underlying principle more clearly than the governance literature does. Her account of the self-serve data platform and of data treated as a product rests on the observation that adoption rises when infrastructure is designed for discoverability and use rather than for the convenience of its custodians (Dehghani 2019; Dehghani 2022). An organisation need not adopt the whole of data mesh to take that observation seriously.
A centre of excellence's real product is not the catalogue, the policy suite or the training material. It is the incentive gradient.
The consequence for governance leaders is uncomfortable. Build that gradient well and the centre can contract as adoption grows, because the work continues without it. Build it badly and the centre becomes the bottleneck it was established to remove, permanently and at full cost.
What to do now
Three actions, sequenced, because each creates the conditions the next depends on.
Define the roles, skills and responsibilities required to run governance at scale, and validate each workflow with the people who will perform it before allocating licences. Tooling improves a working model and cannot substitute for one.
Attestation belongs in the workflow system, ownership prompts in the reporting layer, catalogue answers in the assistant staff already have open. Use automation to raise throughput rather than to replace judgement: classification and curation can be machine-generated at scale, but approval and sign-off must stay with a named person.
Measure unprompted usage, contribution rates and time-to-answer, and treat a sustained decline as seriously as a failed control test. Fund stewardship enablement as a standing capability rather than as launch training, because the learning curve does not end at go-live.
The test
For twenty years the obstacle to data governance was that nobody outside the data office had a reason to fund it. That obstacle has now gone twice over. Leaders who spend the next two years congratulating themselves on this will take their organisations into Gartner's 80 per cent, because neither the mandate nor the money addresses the reason governance decays.
The test of whether an organisation has understood the change is narrow and answerable. Ask whether a named accountable person completed a governance task this quarter, inside a tool they already had open, without help from the centre of excellence. An entity that cannot answer yes has not implemented data governance. It has bought a system of record for work that nobody performs — and under CPS 230, it will offer that system to a supervisor as evidence.
How APRA turned catalogue and lineage artefacts into prudential evidence beneath a board declaration.
Why the direction of dependence between AI and governance has reversed, and what to do about it.
DAMA International (2017) DAMA-DMBOK: Data Management Body of Knowledge, 2nd edn. dama.org
Dehghani, Z. (2019) 'How to Move Beyond a Monolithic Data Lake to a Distributed Data Mesh', martinfowler.com, May 2019. martinfowler.com
Dehghani, Z. (2022) Data Mesh: Delivering Data-Driven Value at Scale. Sebastopol: O'Reilly Media.
EDM Council (n.d.) DCAM — Data Management Capability Assessment Model and CDMC — Cloud Data Management Capabilities. edmcouncil.org
Gartner (2024) Gartner Predicts 80% of D&A Governance Initiatives Will Fail by 2027, Due to a Lack of a Real or Manufactured Crisis, press release, 28 February 2024. gartner.com
McKinsey (2019) 'Why do most transformations fail? A conversation with Harry Robinson', McKinsey & Company, 10 July 2019. mckinsey.com