Data Governance Consulting for Small Business
Data governance consulting is the work of deciding who owns your data, who can touch it, what gets written down about it, and what happens when something in it turns out to be wrong. For most small businesses that is not a framework document. It is three or four decisions, made once, then checked every so often.
That is a smaller claim than the phrase usually gets dressed up as. It is also the honest one.
If you searched for this because a client asked whether you have a data governance policy, or because an AI project stalled on "who's allowed to see that", you are in the right place. Read on for what it covers, what it does not, and where the line sits between governance and the plainer problem of data quality.
What a data governance consultant actually does
A data governance consultant maps where your data lives, who is responsible for each part of it, and what rules apply to it. In a business with thirty people and three systems that do not talk to each other, this is mostly a conversation and a document, not a piece of software.
The questions are usually the same shape, whatever the sector:
- Who owns this data, and who is allowed to change it
- Where does it come from, and is that source trustworthy
- What happens if it is wrong, and who would notice
- What do we have to keep, for how long, and under what rule
None of that needs a platform. It needs someone to sit down with the person who actually runs the system and write the answers down, because right now they live in one person's head.
That is worth saying plainly, because "data governance" gets marketed as something only a large enterprise needs, with a steering committee and a chief data officer. For a business your size it is closer to the fire exit plan. Nobody thinks about it until the day they need it, and the day they need it is a bad day to be starting from scratch.
The story that actually explains it
I was working with a healthcare group with several clinics, building out an automation for the person who handles finance for the whole operation. One of her jobs ends with changing a batch of appointments in the booking system to free of charge.
We could have had the AI do that step directly. Technically, it was possible. We agreed it would not. Instead the AI gets its own read only login, works from the reports and the diary, and never goes near patient records. A data processing agreement and a data protection impact assessment were drafted before anything touched live data.
The most important decision in that whole project was not what the AI would do. It was what it would never be allowed to touch. Writing that down first, and getting the login, the agreement and the assessment right before anything went live, is what made the rest of it safe to build.
That is data governance, done at the size most readers of this post actually operate at.
Governance and data quality are not the same thing, and mixing them up wastes money
Governance is about rules: who owns it, who can see it, what gets kept. Data quality is about whether the thing in front of you is actually correct. I have written about data quality consulting separately, because they get sold as one service and they are not the same job.
On a landscaping job I worked on, two supplier quotes listed what looked like two different plants. African lily on one, agapanthus on the other. They are the same plant. No governance policy in the world catches that. It needed a quantity surveyor who knew her trade.
Nothing about AI changes that, and this is the bit worth sitting with. Put both quotes through a comparison and it will line them up as two separate plants, confidently, because that is what the words say. It does not know the trade. It inherits whatever was already in the source and moves it along faster.
So governance is the part that decides whose job it is to check, and how often. Quality is whether the person doing the checking knows enough to catch it.
Get the governance right and a mismatched name still goes through if nobody is checking. Get the quality checks right with no governance behind them and you have no idea who is supposed to be running them next month when the person who built it leaves.
When you actually need the formal version
Most small businesses in Trafford and Cheshire do not need a full data governance consulting services engagement in the enterprise sense. You need it properly when one or more of these is true:
- You hold data that is regulated specifically, health records, financial records, anything under a professional body's rules
- More than one system holds the same data and they can disagree with each other
- You are about to let AI touch a system that holds client or patient information
- One person holds the whole picture in their head and nobody else could explain it if they left tomorrow
That last one comes up more than you would expect.
A healthcare group I worked with had their entire finance operation running through one person's knowledge of how the booking system, the accounts package and the insurer invoices all fit together. Nothing was written down. The owner's actual priority, stated plainly, was that he wanted a digital version of her. Before anything got automated, the jobs had to be mapped and the rules had to be written down. That mapping exercise is data governance, even though nobody in the room called it that.
What it does not need to be
Here is the honest limit. If you are a five person trade business with one spreadsheet and one bank feed, you do not need a governance framework. You need to know which version of the price list is current and who is allowed to change it. Write that on one page and you are done.
I will not sell a governance project to a business that does not have the complexity to justify one. The papers and the conference brochures talk about AI governance like every business needs a steering committee and a named data officer. Most of them need an afternoon and a shared document.
Where it is worth paying for proper advice is the regulated end: health, finance, anything holding data on children, anything where a data protection impact assessment is legally sensible before you connect AI to a live system. That is not a DIY job, and the ICO's guidance for organisations is the first place to check what your specific obligations actually are before paying anyone to tell you.
What this costs to get wrong
Nobody measures this well, which is itself worth saying rather than inventing a figure. What I have seen repeatedly is smaller and less dramatic than a data breach headline. It is two quotes that cannot be compared properly because the same item is listed under two different names and nobody owns the checking. It is an insurer invoice sitting unactioned for the same reason. It is an AI project that stalls because nobody decided in advance what the AI was allowed to see.
ONS research on AI adoption in UK businesses found that among firms already using AI, the average adopter uses only 1.6 AI technologies and just 10% describe their use as extensive. That is my own reading of it, not something the ONS figures claim directly, but shallow use is partly a confidence problem. It is also partly that nobody has done the groundwork of deciding what the tool is and is not allowed near, so people stop at the safe, small use and never go further.
What to do about it on Monday
Write down, on one page, who owns each major piece of data in your business and what they are responsible for checking. Not a policy. A list. Then ask, for any AI project you are planning, what it would never be allowed to touch, and write that down before you build anything.
That is most of what a data governance consultant would charge you to produce for a business your size. Where it gets genuinely worth paying for outside help is the regulated version, with a proper data processing agreement and impact assessment behind it, because getting that wrong carries a cost that a mismatched quote line does not. The risk side of letting AI near sensitive systems is covered in more depth in our piece on AI security, and if governance is one piece of a wider project you can read how it fits into a digital transformation.
If you want help working out which side of that line you are on, that is a conversation, not a sales pitch. You can read more about how we approach AI consulting services generally, or see how our pricing works.