← Back to sections

Data Quality

How data quality rules, issue detection, remediation, and measurement ensure the organisation's data is accurate, complete, consistent, and timely.

DQT-01

Enterprise data quality risk appetite and accountability

Has the organisation defined and endorsed an enterprise-level risk appetite for data quality — how much quality risk it is willing to accept before requiring executive-level intervention?

Maturity level descriptions
  1. No enterprise risk appetite for data quality has been defined; decisions about acceptable quality risk are made inconsistently, without executive reference. Quality risk tolerance is decided informally and inconsistently across the organisation, with no agreed enterprise position.
  2. An informal, unwritten sense of acceptable quality risk exists among senior stakeholders, but it has never been documented or formally endorsed. Senior stakeholders may informally agree on rough tolerance levels, but nothing has been written down or formally endorsed.
  3. A documented data quality risk appetite statement exists, endorsed by the executive team, expressed in terms relevant to enterprise risk categories. A written risk appetite statement, endorsed by the executive team, defines acceptable quality risk thresholds by category or criticality.
  4. Actual data quality performance is systematically measured against the risk appetite, with breaches reported to the executive team or board and tracked to resolution. Quality performance is measured against defined risk appetite thresholds, with breaches formally reported and tracked through to resolution at executive level.
  5. Risk appetite is quantitatively calibrated against demonstrated downstream business impact, reviewed regularly, and integrated into enterprise risk management alongside financial and operational risk. Data quality risk appetite is derived from evidence of actual downstream impact, reviewed on a defined cycle, and reported alongside financial and operational risk in the organisation's broader risk framework.
Current maturity (As-Is)
Target maturity (To-Be)

DQT-02

Enterprise-wide quality measurement and executive reporting

How reliably can the executive team or board see an accurate, consolidated picture of data quality performance across the organisation, rather than fragmented, team-level views?

Maturity level descriptions
  1. No consolidated data quality reporting exists; quality status, if known at all, is fragmented across individual teams with no enterprise view. Data quality information, where it exists, stays within individual teams with no mechanism to consolidate it into an organisation-wide picture.
  2. Some teams report quality metrics informally or inconsistently, but there is no standard format or consolidation into an enterprise view. Individual teams may report quality metrics in their own formats, without a consistent structure that allows consolidation.
  3. A standard data quality reporting format exists, with priority domains reporting on a defined cycle into a consolidated enterprise view. Priority business domains report quality metrics in a standard format on a scheduled cycle, consolidated centrally.
  4. Enterprise-wide quality reporting covers all material domains, with trends tracked over time and reviewed by the executive team or board against SLA commitments. Comprehensive, trend-tracked quality reporting is reviewed by the executive team or board against defined SLA commitments.
  5. Executive-level data quality reporting is near-real-time, with predictive indicators of emerging quality risk and automatic escalation of material breaches. A live or near-real-time quality reporting capability includes predictive risk indicators and automatically escalates material SLA breaches to the executive team.
Current maturity (As-Is)
Target maturity (To-Be)

DQT-03

Root-cause governance and systemic quality investment

When significant data quality issues recur across the organisation, how effectively does executive-level governance ensure root causes are addressed systemically, rather than the same issues being repeatedly patched?

Maturity level descriptions
  1. No executive visibility exists into recurring data quality issues or their root causes; the same problems are patched repeatedly without systemic investigation. Recurring quality issues are fixed locally each time they appear, with no executive-level awareness that a pattern exists.
  2. Recurring issues are occasionally noticed at a senior level, but there is no formal process for systemic root-cause investigation or investment. Senior stakeholders may become aware of a recurring issue informally, without a formal process for investigating or funding a systemic fix.
  3. A defined process exists for escalating significant recurring quality issues for root-cause investigation, with findings reported to the CDO or executive team. Significant recurring issues are escalated through a documented process for root-cause investigation, with findings reported to the CDO.
  4. Root-cause findings are systematically translated into funded, tracked systemic improvement initiatives, with progress reported to the executive team or board. Systemic improvement initiatives derived from root-cause findings are funded and tracked, with progress formally reported at executive level.
  5. Root-cause patterns across the organisation are analysed holistically to proactively redesign upstream processes and systems, with systemic quality investment a standing element of the data investment portfolio. Cross-organisational analysis of root-cause patterns proactively drives upstream redesign, with systemic quality investment embedded as a standing element of the broader data investment portfolio.
Current maturity (As-Is)
Target maturity (To-Be)