An audit does not ask whether your data governance is good. It asks four things: what data you hold, why, who can reach it and when it is deleted. Most teams can answer none of the four from a document. They answer from memory, in a meeting, a week late. This guide sets out the record that answers all four on request.
One register, not a policy document
A 40-page policy is not evidence. A register is. One table, one row per dataset: what it is, where it lives, the contract or lawful basis it is held under, the owner, the retention period and who has access. Keep it in a tool your teams already open, a shared sheet or the data catalogue, not a document nobody reads.
- Dataset and its system of record
- Purpose, and the basis it is held under
- A named owner, not a team name
- Retention period, and the deletion job that enforces it
- Access list, with the date it was last reviewed
Make the owner a person with a calendar
“The data team” cannot be held to account. A name can. Every row in the register has one owner who reviews it on a fixed date, and the review is a diary entry, not an intention. When the auditor asks who decided a dataset could feed a model, there is a name and a date.
What governed looks like in practice
Access is granted by role, logged, and revoked when the role ends. Retention is a scheduled job, not a memo. A model’s training set is a versioned snapshot that lists the register rows it drew on. That is what the word means when an auditor uses it.
If the answer is in someone’s head, the answer is no.
Elev8 delivery team
Test it before the auditor does
Once a quarter, pick three datasets at random and answer the four questions from the register alone, without asking anyone. Anything you had to ask about goes on the fix list. Two of these rehearsals is usually enough to turn a two-week audit scramble into half a day.
dataset: claims-history
system: policy-admin (uk-south)
basis: contract
owner: j.patel@client.co.uk
retention: 7y from claim close
access: claims-ops, data-platform
review: 2026-12-01
