Join our Newsletter — 33% off our NHI Course

How do central governance teams and business units share responsibility for data governance?

Central governance teams should provide structure, guidance, and consistent standards, while business units own local execution and day to day application. A hub and spoke model works when the central group coordinates policy and support, and the spokes adapt those controls to their context. Shared responsibility only works with clear communication and accountability.

How central and local ownership should be split

Data governance works best when the central team defines the decision framework and the business units own the data in practice. The central function sets policy, definitions, classification rules, control expectations, and escalation paths. Business units then apply those rules to their processes, systems, and datasets, because they understand local context, regulatory exposure, and operational constraints.

The useful distinction is between governance and execution. Central governance should not become a bottleneck that approves every local decision, and business units should not be left to invent their own standards. A hub and spoke model succeeds when the hub sets non-negotiable guardrails and the spokes translate them into workflows, ownership, and controls that fit the business area.

That split also needs explicit accountability for data quality, access decisions, retention, and issue remediation. If the central team owns the policy but no business unit owns the outcome, governance becomes ceremonial. If the business owns execution but no central team owns consistency, the organisation ends up with incompatible definitions, uneven control strength, and poor comparability across domains.

Where the model breaks down in practice

The most common failure is vague ownership. If people cannot tell who approves a data definition, who resolves a quality issue, or who can override a standard, the model collapses into slow escalation chains or shadow governance. The other common failure is over-centralisation, where the governance team tries to run local decisions from the centre and loses speed, relevance, and business buy-in.

A second pressure point is exception handling. Mature governance distinguishes between a standard rule, a documented exception, and a time-bound remediation plan. Without that distinction, business units either ignore central policy because it is unrealistic, or they quietly bypass it to keep work moving. In both cases the organisation loses trust in the governance process.

Communication is not a soft extra here, it is part of the control design. Shared responsibility only works when standards are written in plain operational language, local teams know when to escalate, and the central group can see whether the policy is actually being applied. NHIMG’s Ultimate Guide to NHIs shows the same pattern in identity governance, where policy only works when ownership and local enforcement are both clear. For governance programmes that must also satisfy privacy expectations, the NIST Privacy Framework is useful because it reinforces classification, role clarity, and accountable risk handling around data use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV — Governance Oversight Shared data governance depends on clear oversight, roles, and accountability across the organisation.
GV.RR — Roles, Responsibilities, and Authorities The question is fundamentally about splitting governance duties between central and local owners.
ID.AM — Asset Management Data governance requires knowing what data exists, where it sits, and who is responsible for it.
Recommendation — Define governance ownership and oversight responsibilities for central and business teams. Assign decision rights, stewardship duties, and escalation authority for each data domain. Maintain an authoritative inventory of critical data assets and their business owners.
NIST SP 800-63 Digital Identity Guidelines Governed data access and accountability often depend on trusted identity and role assignment.
Recommendation — Use identity proofing and access governance to ensure only approved users can act on governed data.

Practitioner Guidance

What to prioritise: Start by defining which decisions are central, which are local, and which require joint approval. The highest-value split is usually policy and standards at the centre, with ownership, stewardship, and remediation in the business unit.

What to verify: Confirm that every critical dataset has a named business owner, a data steward or equivalent operator, and a documented escalation path. If any of those roles are missing, shared responsibility is not yet real.

Common mistake: Treating the central team as the owner of governance outcomes instead of the owner of the framework. That mistake produces polished standards with weak adoption, because the people closest to the data never receive clear accountability.

Practitioner takeaway: The best operating model is not central control or local autonomy, but a clean division where the centre sets the rules and the business proves the rules work in day-to-day operations.