Data governance fails because it is sold as risk avoidance. That reads as cost and bureaucracy, so business leaders comply minimally and undermine it. Reframe it as what makes self-service analytics, faster decisions, and data monetisation possible. Govern 20% of your data fully, prove the value, then expand.
A governance policy lands in everyone’s inbox. It is forty pages long. Six months later, nobody can name a single decision it made faster or a dollar it earned. The controls exist. The value does not.
Why governance gets sold as a police force
Governance usually arrives as a rulebook. Access controls, data classifications, approval steps, a catalogue nobody opens. It is pitched as protection: stay compliant, avoid fines, do not leak. All true, and all framed as things you must not do.
Sold that way, governance reads as cost and bureaucracy. It slows people down and gives nothing back that a business leader can point to. So they comply at the minimum, route around the controls when a deadline bites, and quietly undermine the whole effort. The framing is the failure, not the intent.
Here is the trap. The more governance is described as risk avoidance, the more it looks like a tax. Nobody fights for a tax. They fight to pay less of it.
The evidence
Thomas Davenport has tracked the data-leader role for two decades. He calls governance “a bad word” for getting people to do the right things with data, and notes that it is often unsuccessful (MIT Sloan). That is a hard verdict from someone who has watched more governance programmes than almost anyone alive.
Read it carefully. The problem is not that governance is unnecessary. The problem is the word, and the risk-avoidance story wrapped around it. When the pitch is fear, adoption stays shallow. People sign the policy and forget it.
I saw the other version work at dunnhumby. Tesco Clubcard ran on governed, connected data, and that discipline is exactly what let us launch a financial-services line that went from zero to 63 million dollars in twelve months. Governance there was not a brake. It was the thing that made new revenue safe to chase.
Is this you?
Five quick checks. Answer each yes or no.
- Did your last governance rollout arrive as a policy document rather than a capability?
- Can a business team get the data they need in hours, or does it take weeks of approvals?
- If asked, could your leaders name one revenue decision governance made faster?
- Do people copy data to spreadsheets to escape the controls when a deadline is tight?
- Is governance owned by legal or risk, with no line to commercial outcomes?
If three or more land the wrong way, your governance is read as a tax, not an enabler.
What it costs
The cost of governance-as-compliance is not a fine. It is everything that never happens because the data was too locked down, or too distrusted, to use.
It shows up as slowness. Teams wait weeks for access, so decisions get made on gut instead. It shows up as shadow data. People copy sets to spreadsheets to escape the controls, and now you have ungoverned data everywhere, the exact risk the policy was meant to prevent. It shows up as capped AI. Models need trusted, well-described data, and a programme nobody believes in cannot supply it.
And it shows up as revenue left on the table. Data monetisation, self-service analytics, faster pricing calls all need governed data people trust enough to act on. Sell governance as a “no” and you never get the “yes” those depend on.
Three moves that change the frame
Reframe governance as the thing that makes revenue possible. Stop pitching it as protection. Pitch it as the platform for self-service analytics, faster decisions, and data monetisation. Compliance becomes a by-product of doing that well, not the headline. Same controls, opposite story. When a business leader asks “what do I get”, the answer is speed and new revenue, not “you stay out of trouble”.
Govern 20% fully, not 100% partially. Do not try to govern everything at once. Pick the 20% of data that drives most of the value, your core customer and transaction data, and govern it fully. Prove that governed data moved a metric. Then expand from a win, not a mandate (The Data Governor, 2026). Partial governance across everything earns trust nowhere. Full governance on what matters earns it fast.
Give it a commercial owner. Governance parked in legal or risk will always sound like risk. It needs an owner with a commercial mandate, someone who reports on decisions enabled and revenue supported, not just policies published. This is the same accountability gap that makes data leaders last under three years: a role defined by control, not outcomes, that nobody fights to keep. It also works best once you have named a master system to govern, which is the fragmented data problem one layer down.
That is the shape of it. The full operating sequence, who owns what, what to measure, and how to make the fix stick, is in the playbook.
Get the full data governance playbook.
Govern for the yes, not the no
Governance fails when it is a list of things you cannot do. It works when it is the reason you can do things you could not before. Move the fast decisions, the self-service, and the new revenue line into the “because we govern well” column. The compliance takes care of itself once the value is visible. Sell the yes. The no comes free.
Go deeper on customer data maximization
Three ways forward. Pick the one that fits where you are.
- Get the playbook. Practical notes on turning the customer data you already own into revenue, straight to your inbox. Join the newsletter at the foot of this page.
- Take the assessment. Score your customer data maximization in four minutes and see your top revenue blockers. Start the assessment →
- Book a meeting. Bring your data problem. Leave with a prioritised fix, not a platform pitch. Book a call →
Post 4 of 25 in the Customer Data Maximization series. Previous: How does poor data quality undermine AI, and how do you fix it?. Next: How do you handle consent and privacy without killing personalisation?.
Frequently asked questions
Why does data governance fail?
Governance fails mostly because of how it is framed. Thomas Davenport, who has tracked the data-leader role for two decades, calls governance 'a bad word' for getting people to do the right things with data, and notes it is often unsuccessful (MIT Sloan). Sold as risk avoidance, it reads as cost, so people comply minimally.
How do you make data governance drive revenue?
Stop pitching governance as protection. Pitch it as the platform for self-service analytics, faster decisions, and data monetisation. The controls stay the same. Only the story changes. Compliance becomes a by-product of doing that well, not the headline that gets people to opt out.
Should you govern all your data at once?
No. Govern the 20% of data that drives most of the value, usually core customer and transaction data, and govern it fully. Prove governed data moved a metric, then expand from that win rather than a blanket mandate (The Data Governor, 2026). Partial governance across everything earns trust nowhere.
Who should own data governance?
Someone with a commercial mandate, not legal or risk alone. Governance parked under risk will always sound like risk. The owner should report on decisions enabled, revenue supported, and access sped up, not only policies published and controls passed. Outcomes buy the budget that keeps the role alive.
What is the difference between compliance-led and enablement-led governance?
Compliance-led governance pitches risk avoidance, so it reads as a tax and adoption stays shallow. Enablement-led governance pitches speed and new revenue, so business leaders fund it and use it. Same access controls, definitions, and quality rules underneath. The difference is the story and, therefore, the adoption.