Two Years In, the Board Asks the Question
Two years into a well-funded governance program, a large bank's board asked its Chief Data Officer a direct question: is our data under control? The honest answer satisfied no one. The program had policies, a council, a catalog, and a roadmap.
What it didn't have was the authority to make any business unit actually change how it managed data. The CDO owned the outcome and controlled none of the levers. This is one of the most common failures in enterprise data management, and it has nothing to do with the person in the seat. It is structural.
Governance Positioned to Advise, Not to Govern
Many organizations stand up a governance function as an overlay — a team responsible for outcomes but positioned outside the authority structures that control systems, budgets, and priorities. The council recommends; the business takes it or leaves it. Policies exist, but nothing happens when a team ignores them.
This is not a motivation problem. It is a governance design problem. The operating model gives the CDO a mission and withholds the means, so the function drifts toward documentation — the only thing it can produce without cooperation it can't compel. Supervisors increasingly expect enforceable data accountability; BCBS 239 explicitly calls for governance with real ownership and board-level engagement. A function that can only advise cannot demonstrate that data is actually controlled, and known problems persist because no one has both the mandate and the authority to fix them.
The CoComply Approach
CoComply treats data ownership as an enforced, single-threaded accountability — not a label in a document that no mechanism backs. The specific gap — a CDO accountable for outcomes but unable to make ownership stick — is closed by binding each critical data domain to a single named owner and enforcing that ownership through workflow.
Obligations, exceptions, and remediation route to the accountable person and are tracked to resolution, so ownership stops floating and starts operating. Instead of a council issuing recommendations the business can ignore, CoComply's governance model makes accountability visible and actionable — who owns what, what's outstanding, and whether it's being resolved — giving the CDO an authority structure the operating model failed to provide.
Authority Is the Part That Makes It Governance
Governance works when the person responsible for an outcome also holds an enforced mechanism to drive it — and that mechanism, not another policy document, is what turns a program into control.
The organizations that hold up under scrutiny aren't the ones with the most elaborate frameworks. They're the ones where the person accountable for data also holds the authority to control it.
