Where your data lives, who owns it, what you can trust, in writing.
Your business runs on data. Customer data, financial data, operational data, vendor data. Some of it you understand. Some of it lives in systems no one has looked at for years. Some of it is being used in ways nobody has documented.
The Review answers, in writing: what data you have, where it is, who owns it, what you can trust — and what to do about the parts you cannot.
That is what this engagement is.
€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.
Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.

Why clients commission a review
A Data Governance Review is usually triggered by a specific moment. Most often, one of these:
- A regulatory event is approaching — a GDPR review, sector audit, supervisory inspection — and documented data evidence is required.
- A major customer is asking detailed questions about data handling, classification, or retention.
- A merger or acquisition is creating duplicate or conflicting data sets that need reconciling.
- The business is preparing for an AI or analytics initiative and needs to know what data is reliable enough to use.
- A data incident or near-miss has surfaced concerns about ownership, lineage, or classification.
- New data-intensive products or services are being launched and the governance foundations need to be in place.
- The compliance officer or DPO is asking questions that leadership cannot easily answer from existing documentation.
- Investment, refinancing, or audit events require documented data governance evidence.
If one of these is the position you are in, the Review is built for it.
Who this is for
Owners, MDs, and CEOs of established businesses — particularly in regulated sectors — who need a documented view of data governance.
Compliance officers, DPOs, and Chief Data Officers in regulated businesses facing audit, inspection, or a major customer query.
Leadership teams preparing for AI or analytics initiatives that depend on trustworthy data foundations.
Acquirers post-deal needing to reconcile the data estate of the combined business.
Who this is not for
Pre-revenue businesses or those without a material data estate.
Buyers wanting data engineering, migration, or platform implementation. The Review is governance, not engineering.
Regulatory legal advice. We identify regulatory exposure; we do not provide legal opinion.
Privacy impact assessments in the formal regulatory sense. The Review can inform one, but does not substitute for one.
What you receive
The Review tells you what data you have, who owns it, where it can be trusted, and where it cannot. Five artefacts, delivered together.
A data inventory and flow map. The data your business holds — by source, by system, by use. How it moves between systems, where it leaves the business, where it comes from.
An ownership matrix. Who is accountable for each data domain — financial, customer, operational, regulatory. Where ownership is unclear, the matrix names that explicitly.
A trust and lineage assessment. For each significant data domain: where can it be trusted, where the provenance is verifiable, where it cannot — and what would be needed to make it reliable.
A regulatory exposure register. Where the data estate sits relative to GDPR, sector regulation, and contractual obligations. Each entry ranked by severity and named against the work to address.
Recommendations and board presentation. A twelve-month sequenced roadmap, costed in rough effort, with a board-cycle session to walk through it.
Typical outcomes
Most Reviews result in one of four conclusions.
Data governance is sound across the estate. Focus on consistency and incremental improvement. No material gaps identified.
Specific gaps are identified. Particular domains — ownership, lineage, classification, retention — need addressing. The roadmap names them.
A broader programme of work is needed. Multiple gaps across the estate warrant a sequenced data governance programme.
Critical exposure requires immediate attention. Regulatory risk, customer-trust issues, or material integrity questions that should be addressed before any major change, AI initiative, or audit event.
The Review tells you which of these your business is in, and what follows from it.

How the Review runs
Three to four weeks, in four phases.
Week one — scoping and inventory. Data domains identified, key systems documented, stakeholder list confirmed.
Week two — interviews and evidence gathering. Data owners, compliance, operational users, regulatory contacts. Document review across policies, registers, and retention schedules.
Week three — synthesis and risk ranking. Findings written up. Trust and lineage scored. Regulatory exposure ranked.
Week four — presentation and revisions. The board-cycle session. Revisions where the report needs tightening for compliance or board audiences.
Everything is written before it is said. Nothing reaches the board or the regulator that has not been verified first.
What this is not
Data engineering, migration, or platform implementation. The Review is governance.
Regulatory legal opinion. We identify exposure; legal advice is a separate engagement.
Privacy impact assessments in the formal regulatory sense. The Review can inform one.
AI policy or model governance. For that, see our work on AI policy — a separate engagement.
Data governance is not a compliance task. It is a business control.
The purpose of the Review is not to satisfy a regulator. It is to give leadership a clear, written answer to: what data you have, what you can trust, and where the exposure lives — so commercial, regulatory, and AI decisions are made on evidence rather than assumption.
Proof
References available on request. Anonymised excerpts from prior reviews available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, and timing. You decide whether to proceed. No proposal is sent unless you ask for one.
Start with the Technology Control Assessment — €4,950A scored framework reading in five working days, with data as one of the sixteen pillars assessed. The right starting point if you want to see where data sits in the broader picture before committing to a focused Review.
For a comprehensive framework review, see Technology Control Review.