Data governance

Data Governance Consulting for Small Business

Two colleagues looking over a printed page of charts together

Data governance consulting is the work of deciding who owns your data, who can touch it, what gets written down about it, and what happens when something in it turns out to be wrong. For most small businesses that is not a framework document. It is three or four decisions, made once, then checked every so often.

That is a smaller claim than the phrase usually gets dressed up as. It is also the honest one.

If you searched for this because a client asked whether you have a data governance policy, or because an AI project stalled on "who's allowed to see that", you are in the right place. Read on for what it covers, what it does not, and where the line sits between governance and the plainer problem of data quality.

What a data governance consultant actually does

A data governance consultant maps where your data lives, who is responsible for each part of it, and what rules apply to it. In a business with thirty people and three systems that do not talk to each other, this is mostly a conversation and a document, not a piece of software.

The questions are usually the same shape, whatever the sector:

  • Who owns this data, and who is allowed to change it
  • Where does it come from, and is that source trustworthy
  • What happens if it is wrong, and who would notice
  • What do we have to keep, for how long, and under what rule

None of that needs a platform. It needs someone to sit down with the person who actually runs the system and write the answers down, because right now they live in one person's head.

That is worth saying plainly, because "data governance" gets marketed as something only a large enterprise needs, with a steering committee and a chief data officer. For a business your size it is closer to the fire exit plan. Nobody thinks about it until the day they need it, and the day they need it is a bad day to be starting from scratch.

The story that actually explains it

I was working with a healthcare group with several clinics, building out an automation for the person who handles finance for the whole operation. One of her jobs ends with changing a batch of appointments in the booking system to free of charge.

We could have had the AI do that step directly. Technically, it was possible. We agreed it would not. Instead the AI gets its own read only login, works from the reports and the diary, and never goes near patient records. A data processing agreement and a data protection impact assessment were drafted before anything touched live data.

The most important decision in that whole project was not what the AI would do. It was what it would never be allowed to touch. Writing that down first, and getting the login, the agreement and the assessment right before anything went live, is what made the rest of it safe to build.

That is data governance, done at the size most readers of this post actually operate at.

Governance and data quality are not the same thing, and mixing them up wastes money

Governance is about rules: who owns it, who can see it, what gets kept. Data quality is about whether the thing in front of you is actually correct. I have written about data quality consulting separately, because they get sold as one service and they are not the same job.

On a landscaping job I worked on, two supplier quotes listed what looked like two different plants. African lily on one, agapanthus on the other. They are the same plant. No governance policy in the world catches that. It needed a quantity surveyor who knew her trade.

Nothing about AI changes that, and this is the bit worth sitting with. Put both quotes through a comparison and it will line them up as two separate plants, confidently, because that is what the words say. It does not know the trade. It inherits whatever was already in the source and moves it along faster.

So governance is the part that decides whose job it is to check, and how often. Quality is whether the person doing the checking knows enough to catch it.

Get the governance right and a mismatched name still goes through if nobody is checking. Get the quality checks right with no governance behind them and you have no idea who is supposed to be running them next month when the person who built it leaves.

When you actually need the formal version

Most small businesses in Trafford and Cheshire do not need a full data governance consulting services engagement in the enterprise sense. You need it properly when one or more of these is true:

  • You hold data that is regulated specifically, health records, financial records, anything under a professional body's rules
  • More than one system holds the same data and they can disagree with each other
  • You are about to let AI touch a system that holds client or patient information
  • One person holds the whole picture in their head and nobody else could explain it if they left tomorrow

That last one comes up more than you would expect.

A healthcare group I worked with had their entire finance operation running through one person's knowledge of how the booking system, the accounts package and the insurer invoices all fit together. Nothing was written down. The owner's actual priority, stated plainly, was that he wanted a digital version of her. Before anything got automated, the jobs had to be mapped and the rules had to be written down. That mapping exercise is data governance, even though nobody in the room called it that.

What it does not need to be

Here is the honest limit. If you are a five person trade business with one spreadsheet and one bank feed, you do not need a governance framework. You need to know which version of the price list is current and who is allowed to change it. Write that on one page and you are done.

I will not sell a governance project to a business that does not have the complexity to justify one. The papers and the conference brochures talk about AI governance like every business needs a steering committee and a named data officer. Most of them need an afternoon and a shared document.

Where it is worth paying for proper advice is the regulated end: health, finance, anything holding data on children, anything where a data protection impact assessment is legally sensible before you connect AI to a live system. That is not a DIY job, and the ICO's guidance for organisations is the first place to check what your specific obligations actually are before paying anyone to tell you.

What this costs to get wrong

Nobody measures this well, which is itself worth saying rather than inventing a figure. What I have seen repeatedly is smaller and less dramatic than a data breach headline. It is two quotes that cannot be compared properly because the same item is listed under two different names and nobody owns the checking. It is an insurer invoice sitting unactioned for the same reason. It is an AI project that stalls because nobody decided in advance what the AI was allowed to see.

ONS research on AI adoption in UK businesses found that among firms already using AI, the average adopter uses only 1.6 AI technologies and just 10% describe their use as extensive. That is my own reading of it, not something the ONS figures claim directly, but shallow use is partly a confidence problem. It is also partly that nobody has done the groundwork of deciding what the tool is and is not allowed near, so people stop at the safe, small use and never go further.

What to do about it on Monday

Write down, on one page, who owns each major piece of data in your business and what they are responsible for checking. Not a policy. A list. Then ask, for any AI project you are planning, what it would never be allowed to touch, and write that down before you build anything.

That is most of what a data governance consultant would charge you to produce for a business your size. Where it gets genuinely worth paying for outside help is the regulated version, with a proper data processing agreement and impact assessment behind it, because getting that wrong carries a cost that a mismatched quote line does not. The risk side of letting AI near sensitive systems is covered in more depth in our piece on AI security, and if governance is one piece of a wider project you can read how it fits into a digital transformation.

If you want help working out which side of that line you are on, that is a conversation, not a sales pitch. You can read more about how we approach AI consulting services generally, or see how our pricing works.

Common questions

What does a data governance consultant do?+
They map where your data lives, decide who owns each part of it, and set the rules for who can access, change or delete it. For a small business this is usually a short document and a conversation, not a platform or a committee.
Is data governance the same as GDPR compliance?+
No. GDPR is one set of legal rules about personal data specifically. Governance is the broader practice of deciding ownership and rules for all your data, some of which is personal and some of which is not. Good governance makes GDPR compliance easier, but they are not the same project.
Do small businesses actually need data governance?+
Most need a lightweight version: one page naming who owns what. The formal version, with impact assessments and data processing agreements, matters most where you hold regulated data such as health or financial records, or where you are about to connect AI to a system holding client information.
What's the difference between data governance and data quality?+
Governance decides the rules: ownership, access, retention. Quality is whether the data itself is actually correct. You can have perfect governance sitting over bad data, and you can have good data with nobody responsible for keeping it that way. Both matter, and they are usually sold as one service when they are two different jobs.
How much does data governance consulting cost?+
It depends on scale and regulation, so the price is agreed up front once we know your situation, with no open-ended day rates. A single page ownership document for a small firm is typically a short conversation. A data processing agreement and impact assessment for a regulated business holding patient or client data is a bigger piece of work. You can see how our pricing works, or contact Chris for an informal chat to get a fixed quote for your situation.

Chris Matthews runs Altrincham AI, teaching small businesses across Greater Manchester and Cheshire how to use AI properly, and building the workflows that come out of it.

Based in Altrincham. Monday to Friday, 08:00 to 17:00. Call 0161 883 7818, or book a free 45 minute consultation.

More on this: AI consulting services.

Not sure where the easy win is in your business?

That is what the 45 minute diagnostic is for. No charge, and you get an honest answer even if the answer is not yet.

Book a consultation

More on this

Digital transformation services: what it means for a small firm

Digital transformation services without the jargon. What it meant at a healthcare group whose finances lived in one person's head, and where AI stopped.

Read it →

What actually happens in an AI consultation

What actually happens in an AI consultation, why most of the first hour is not about AI, and how far behind UK small businesses genuinely are.

Read it →

Business process automation usually starts by writing the process down

Business process automation starts by writing the process down. Why software is rarely the constraint, and the one hour exercise to do before you buy.

Read it →