A data governance maturity model is the instrument that turns “how are we doing?” into a number a board can compare year on year — five levels, from an organisation where data is managed by whoever happens to be holding it to one where governance is measured, funded and improved as a matter of routine. The five-level shape is borrowed from the capability maturity tradition: the CMMI Institute’s Data Management Maturity model defined levels 1 Performed, 2 Managed, 3 Defined, 4 Measured and 5 Optimized, ISO 8000-62 standardises maturity assessment for data quality management processes, and most data governance models — DAMA’s, Gartner’s, the vendor and consultancy variants — use the same ladder with different labels. The DMBOK treats maturity assessment as a data management activity in its own right and, characteristically, prescribes no single model. What matters is less which model is used than that the assessment is done honestly against defined criteria, per dimension rather than as one score, and repeated. This guide sets out the five levels with what an organisation at each one looks like, the seven dimensions a data governance maturity model assesses, how to run the assessment so the result is defensible, what a realistic target is, and the errors that make maturity scores meaningless.

The five levels of the data governance maturity model
| Level | Name (CMMI DMM) | What governance looks like | Typical evidence |
|---|---|---|---|
| 1 | Performed (initial) | Data is managed ad hoc by projects and individuals; no policy, no owners, no standards; quality problems are fixed where they hurt and recur; nobody can say what data the organisation holds | None beyond project artefacts |
| 2 | Managed | Governance exists in pockets: a policy drafted or approved, some owners and stewards named for a domain or a regulation, quality measured for a few elements, a glossary started; practices depend on the people who started them | Policy; some appointments; a partial glossary; issue lists |
| 3 | Defined | A framework is established and followed across the scoped domains: council, owners, stewards, standards for definitions, quality, classification and access, a catalogue with owned and defined critical data elements, lineage for critical flows; processes are documented and repeatable | Council minutes; RACI; standards; catalogue coverage; issue and change records |
| 4 | Measured | Governance is quantified: quality against thresholds per critical element, coverage metrics, issue ageing, access turnaround, reported to the council and used to prioritise; controls are tested; the framework’s own performance is evaluated | Dashboards; KPIs with trends; internal audit of governance; quantified business impact |
| 5 | Optimized | Governance improves itself: metrics drive investment, standards evolve with the business, new data sources and use cases — AI, external data — enter under governance by default; the organisation benchmarks and innovates on its data management | Improvement records; governance embedded in strategy and product processes |
The levels are cumulative and the jump that takes longest is 2 to 3 — from pockets of governance to a framework that is defined and followed. Our guide to the data governance framework covers the five layers that level 3 requires to be in place.
The seven dimensions a data governance maturity model assesses
| Dimension | What is assessed | Level 3 looks like |
|---|---|---|
| 1. Strategy and sponsorship | Executive ownership, the data strategy governance serves, funding | Named sponsor; policy approved; budget line |
| 2. Organisation and roles | Council, owners, stewards, custodians; decision rights; coverage of domains | RACI in force for scoped domains; council meets and decides |
| 3. Policy and standards | Policy, glossary standard, quality, classification, access, issue and change processes | Standards published and applied; processes followed with records |
| 4. Data quality | Dimensions defined, thresholds set, measurement and remediation | Critical elements measured against thresholds; issues managed to root cause |
| 5. Metadata and lineage | Glossary, catalogue, dictionaries, lineage; coverage of critical elements | Critical elements defined, owned and catalogued; lineage for critical flows |
| 6. Technology | Catalogue, quality, lineage and workflow tooling; integration with platforms | Tooling in use for governed content, not ahead of it |
| 7. Culture and adoption | Awareness, training, use of governed data, compliance with processes | Staff know the roles and use the catalogue; access and issue processes are the normal route |
Scoring per dimension is the point. An organisation at level 4 on technology and level 1 on roles has a catalogue nobody owns — a common profile — and a single blended score of 2.5 would hide it. Our guides to the six data quality dimensions and to data lineage cover dimensions 4 and 5.
Running the data governance maturity assessment
- Choose and fix the model. CMMI DMM, DAMA-aligned, or an internal model — the choice matters less than using the same one every year with written criteria per level per dimension.
- Define the scope. Enterprise-wide, or the governed domains; assessing the whole estate when governance covers three domains produces a level 1 that misrepresents the programme.
- Collect evidence, not opinions. Each criterion is met by an artefact or a metric — council minutes, the RACI, coverage percentages, quality scores — or it is not met. Interviews calibrate; documents decide.
- Score per dimension and record the rationale. The level, the evidence, and what is missing for the next level.
- Set targets per dimension. Level 3 across all seven is the realistic two-to-three-year target for most organisations; level 4 on quality and metadata for regulated data; level 5 only where data is the product.
- Repeat annually and report the trend. The value of the model is the delta, presented to the council and the sponsor with the investment it justifies.
What a realistic data governance maturity model target is
| Organisation | Realistic target | Why |
|---|---|---|
| Mid-size company starting governance for a regulatory driver | Level 3 on the regulated domains in 18–24 months; level 2 elsewhere | The framework has to be built before it can be measured |
| Bank or insurer under BCBS 239 or Solvency II | Level 4 on quality, metadata and lineage for risk and finance data | Regulators expect measurement and traceability |
| Data-product or platform business | Level 4–5 on quality, technology and culture | Data quality is the product |
| Public body or university | Level 3 with level 4 on privacy-related dimensions | Accountability and transparency drivers |
Errors that make maturity scores meaningless
- Self-scoring without evidence. Every programme that rates itself is at level 3; the assessment asks for the artefact.
- One score. A blended number hides the dimension that will cause the next failure.
- Changing the model. A new model each year makes the trend unreadable.
- Scoring the tools. A catalogue licence is not level 4 on technology; adoption and content are.
- Targeting level 5. Most organisations never need it, and the cost of pretending to pursue it is a programme that cannot show progress.
- Assessing the enterprise when the programme is scoped. State the scope, score the scope, and show the roadmap for what is outside it.
Frequently asked questions
What is a data governance maturity model?
A five-level scale — commonly initial or performed, managed, defined, measured, optimized, as in the CMMI Institute’s Data Management Maturity model — used to assess how far an organisation’s data governance has progressed across dimensions such as sponsorship, roles, standards, quality, metadata, technology and culture, with evidence per criterion and a repeatable score.
Which maturity model should we use?
Any defined one used consistently: the CMMI DMM, a DAMA-aligned model, or an internal model with written criteria per level per dimension. The DMBOK prescribes none; consistency year to year matters more than the choice.
What level should we aim for?
Level 3, defined, across the governed domains for most organisations within two to three years; level 4, measured, on quality, metadata and lineage where regulation demands traceability; level 5 only where data is the product.
How often should we assess?
Annually, with the same model and scope, reporting the per-dimension trend to the governance council and the sponsor alongside the investment it justifies.
Why score per dimension rather than overall?
Because the profile is the finding: level 4 technology with level 1 roles is a catalogue nobody owns, and a single blended score hides exactly that.
Where this leaves you
Use the data governance maturity model as a measuring instrument rather than a badge: fix one model with written criteria, scope it to the governed domains, score each of the seven dimensions on evidence, set level 3 as the realistic target and level 4 where regulation requires measurement, and repeat every year — because the number only means something when it is honest, comparable and read alongside the dimension that is lagging.
References
- DAMA International — DAMA-DMBOK Data Management Body of Knowledge — Maturity assessment as a data management activity.
- ISO 8000-62:2018 — Data quality — Part 62: Data quality management: Organizational process maturity assessment — A standardised maturity assessment approach for data quality management processes.
More on data governance
- The data governance maturity model — you are here
- Data governance and the DMBOK
- The data governance framework: five layers
- The six data quality dimensions
- Data lineage: the three types
- Master data management vs data governance
The data governance maturity assessment workbook with criteria per level per dimension, the evidence checklist, the scoring and trend report and the roadmap template are in the Data Governance Toolkit, or start with the free templates.