UK data and AI governance consultancy

Every number needs an owner.

Your board decides on your figures. Your regulator asks who stands behind them. Your teams want to build AI on them. When nobody owns the data, all three get slower, riskier and more expensive. We name the owner, settle the decision, and build the platforms and controls that keep your numbers right, so the business can move quickly and defend what it decides.

Faster
Privacy decisions on new systems, with a named owner on every fix.
One
Definition for every measure, so the board debates the decision, not the number.
Once
Each AI capability paid for once, and built with the right tool.
Proven
Board papers checked against the evidence before the board relies on them.
Owned
Every data issue has a named owner, so problems are fixed once and stay fixed.
The problem we exist to solve

Most organisations already have a governance framework. What they lack is a person who answers for the data.

It shows up as meetings that argue about the number, projects stuck waiting for sign-off, and regulators asking for evidence nobody can produce. The policy exists. The tools exist. Nobody has to put it right.

“Accountability is the only control that scales.”
Robin Miller, The Governance Gap
Ref
What we found in recent work
Owner
01
Membership sector. Members who want to pay can pay. Renewal defects sat in trackers nobody owned, so income was lost at the moment members tried to pay. Now: one owner for each type of data fixes defects at source. Renewal income is protected.
Membership
02
Energy sector. The board debates the decision, not the number. Every report defined the same measure its own way, so lenders and the board saw figures nobody would stand behind. Now: one definition and one owner for each measure. Figures the business can defend, without adding headcount.
Finance
03
Housing association. A board that answers the regulator from its own evidence. An approved data strategy nobody ran, and a supplier charging to reach the organisation's own data. Now: a roadmap the team can run, named owners, and data it owns. Evidence, not good intentions, at the next inspection.
Executive
04
Energy sector. New systems go live on time, and lawfully. Privacy actions had no owner, so projects stalled waiting for sign-off or went live without a lawful basis. Now: every action has a named owner. Projects get a clear yes, and the evidence stands up when challenged.
Privacy
05
Energy sector. Pay for each AI capability once. AI ideas were raised team by team: the same agent requested three times, and company data going into unapproved tools. Now: one portfolio with one owner. Build once, reuse, and scale AI without scaling risk.
AI
The 8 Governed Gates

Eight gates every use of data or AI passes.

The gates govern how data and AI are used in the processes that earn and protect your money, not how systems are built. The first five clear a use before it goes live, so risk is dealt with before it costs you. The last three keep it right while it runs. Light where risk is low, deeper where AI, personal data or material money is involved.

Proportionate by design

The order matters: each gate depends on the one before. Light where risk is low. Deeper where AI, personal data or money is involved.

1
Foundation
Before live

Roles

Who is accountable? A named owner for the process, the data and any AI, each with the authority to say no. Decisions stop waiting for a committee, and every problem has someone who must fix it.

2
Foundation
Before live

Landscape

What does the process depend on? We map the data, systems and AI each critical process relies on, including undeclared spreadsheets. Effort goes on the few items that cost money when they are wrong.

3
Meaning
Before live

Definition

What does it mean for this process? Each critical figure and AI output has one signed definition and clear limits on its use. Meetings stop arguing about the number and start deciding what to do about it.

4
Meaning
Before live

Quality

Is it good enough for this decision? Thresholds are set by what an error costs the business, not by a generic percentage. Every breach goes to a named owner, with a response and a deadline.

5
Control
Before live

Risk and Controls

What could go wrong, and who accepts it? Every new data use and AI model is assessed before it goes live. The owner signs off the risk that remains, so nothing reaches customers on a nod in a meeting.

6
Control
While live

Monitoring

Is it still safe? From go-live we watch data quality, AI drift and controls continuously. Problems reach the named owner before they reach a customer, a decision or a regulator.

7
Sustainability
While live

Improvement

Are problems getting fixed? Issues go into one backlog, ranked by business impact, not by the loudest voice. A fix closes only when the data meets its threshold, so problems stay fixed.

8
Sustainability
While live

Communication

Do people know the rules? Everyone gets guidance that fits their role, and owners are coached on live decisions. People know which data matters, and when to challenge an AI output.

The principles behind the gates
Anchor

Start from the business process. Governance follows the decisions that earn and protect money.

Value

No data or AI use goes ahead without a clear business purpose behind it.

Ownership

One named owner for the process, one for the data, and one for any AI.

Proportion

Controls scale with risk. Light where risk is low, deeper where money or AI is involved.

Continuity

Governance keeps working after go-live, so the data stays right as the business changes.

The Double Lock

Two signatures on one decision.

The person who owns the process, and the person who owns the data.

Every material decision needs two signatures. First, the Business Process Owner confirms the use adds value and is necessary. If not, it stops. Second, the Data Owner, or AI Model Owner, confirms the use is acceptable on quality, sensitivity and risk.

Where risk is low and the use follows an approved pattern, a fast track applies. Try the route on the right.

How we work

Ten principles you can hold us to.

Governance starts with the decisions that earn and protect your money, not with the systems behind them.

In practice

Every engagement begins by asking what decision the data supports, and what it costs the business when that data is wrong.

A named owner gets things fixed. An action owned by a team stays open.

In practice

Privacy fixes, AI ideas and roadmap actions for our clients each carry a named accountable role, so work closes instead of circulating.

We commit only to what the data causes, so your budget goes where it changes the result.

In practice

For a membership body, we separated data failures from system failures and handed each to its real owner, so nobody paid to fix the wrong thing.

Governance the team can run survives. Governance built for a bigger organisation gets abandoned.

In practice

Housing associations facing a downgrade get a roadmap their own people can deliver, using the meetings they already hold, with no new council and no costly platform.

When two figures disagree, the owner decides which is right, not a line of code.

In practice

On an energy platform, disputed revenue figures wait for the Data Owner's decision instead of reaching the board by accident.

We test every control by trying to get round it, so it protects you in practice, not just on paper.

In practice

On an energy platform, no change reaches production without a genuine review, and the control proves that rule each time it runs.

Every claim we put in front of a board is checked against the source first.

In practice

A housing association's board received a diagnosis tested against its own people's evidence, so it could act without commissioning a second opinion.

You always know what is delivered, what is designed and what is still to come, so you never fund a promise as if it were a result.

In practice

Every report we write, and every case on this site, carries its status.

You decide with the full picture, including the options we do not recommend.

In practice

An energy business chose its data platform from options that each had an honest case for and against, so the decision held when it was challenged.

The team that designs your controls also runs them, so nothing is lost at handover.

In practice

While we build an energy business's new platform, we also run its existing one every day, so the reports it relies on keep running.

“Accountability without authority is blame. Authority without accountability is power. Governance requires both, held by the same person.”
Robin Miller, The Governance Gap
What we do

Eight services. One question: who answers for it?

Service

Data and AI governance

We name the owners, agree the definitions and set up the decisions that keep your data right.

For

Organisations whose data problems keep coming back after each clean-up, or whose regulator, auditor or board has asked who owns the numbers.

What we hear
  • Everyone thinks IT owns the data.
  • Our issues sit in four trackers, and nobody owns them.
  • Nobody can tell us who owns the reference data.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We apply the 8 Gates to the processes that matter most. We name a Business Process Owner and a Data Owner for each, agree one definition for each measure, and set up the Double Lock so that every material decision carries two signatures. We size the governance to the organisation, using the meetings you already hold where we can.

What you get

Named owners by data domain; a decision route; one issue register with every issue owned; measures that show whether governance is working, such as the rate of new defects each month.

Evidence
A name on a register is not ownership. Ownership is explicit acceptance of accountability for decisions, backed by authority to act.
Robin Miller, The Governance Gap
Service

Governance discovery and diagnosis

In a few weeks, a validated diagnosis of where your data fails, why, and who should own the fix.

For

Boards and executives who have been told data is a problem, often by a regulator, and need to know where to start.

What we hear
  • The regulator says our data is a theme, and we do not know where to start.
  • We have a data strategy. Nobody uses it.
  • How much of our post go-live pain is data, and how much is the system?

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

Structured interviews and workshops across the executive and heads of service, with data profiling where the tools allow. We tag every finding, test divergent figures against their source, and trace each problem to its root cause. Before anything reaches the board, we check our highest-stakes claims against the evidence.

What you get

A diagnosis by data domain; root causes; a roadmap with an owning role for every activity; draft risk register entries; board decisions with the cost of deferring each.

Evidence
Governance that cannot survive a direct question is not governance. It is paperwork.
Robin Miller, The Governance Gap
Service

AI governance and agent readiness

Decide which AI ideas to build, who owns each one, and what every agent may read, before the first one goes live.

For

Organisations where teams are asking to build AI agents, vendor platforms have switched AI features on, or staff already use AI tools nobody approved.

What we hear
  • Every team has its own AI idea, and we have no way to see them all in one place.
  • We don't know if that's really AI or just automation with a new name.
  • Our vendor platforms have AI features switched on and nobody decided that.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We gather every AI request into one portfolio and assess each on the same terms: what it is in technology terms, its value, its risk and its owner. We find duplicates and the ideas that are not AI at all. We set a data classification for agents and a publication rule: no named owner, no agent. We build first agents with test data designed to make them fail safely.

What you get

A ranked AI portfolio; a three-tier rule on what agents may read; four questions every agent answers before publication; an approval route; first agent builds.

Evidence
A constraint in a prompt is a suggestion. A constraint in the infrastructure is a control.
Robin Miller, The Governance Gap
Service

Data protection and DPIA review

Privacy assessments reviewed, rewritten and made ready to approve, with a named owner on every fix.

For

Data Protection Officers and legal teams receiving assessments written by people who are experts in their work but not in data protection law, especially for AI tools, employee data and supplier sharing.

What we hear
  • Our sister company already has an approved DPIA for this system. Doesn't that cover us?
  • We took the names out, so the data is anonymous.
  • The vendor says our data is not used for training, so the AI is covered.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We read each Data Protection Impact Assessment (DPIA) field by field, give a plain verdict (approve, do not approve, or incomplete), rate every finding, and name the role accountable for each fix. We write replacement wording, add the risk register the law requires, and tell the Data Protection Officer when the template itself is causing the failures.

What you get

A verdict and a numbered route to approval with effort in days; model answers; rewritten or new DPIAs; template fixes.

Evidence
Perpetual acceptance is not governance. It is neglect with a signature.
Robin Miller, The Governance Gap
Service

Data quality remediation

Fix the records that break your customer journeys, and measure whether they stay fixed.

For

Organisations after a CRM or system migration, where duplicates, missing fields and unreconciled records stop customers renewing, joining or reaching their accounts.

What we hear
  • Members cannot renew, and we do not know how many.
  • The same member is on the system three times.
  • Our partners' records do not match ours.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We profile the data, sort every failure by cause, and commit only to what the data causes. Each commitment has a baseline, a target and a countable population. We correct the data, usually in Experian Aperture Data Studio, with the Double Lock on every correction. We measure the refill rate so the clean-up is not undone.

What you get

From-and-to measures with today's figure and a committed figure; one issue register; named Data Owners; corrected data.

Evidence
Quality is not a percentage. It is whether the data is safe to use for this decision, in this process, at this level of consequence.
Robin Miller, The Governance Gap
Service

Data and AI platform design and build

One governed platform for your data and your AI agents, built in stages that each deliver on their own.

For

Organisations whose reports disagree, whose warehouse grew mart by mart, or who want AI agents that do real work on governed data rather than on copies nobody controls.

What we hear
  • Our reports disagree, and we reconcile them by hand every month.
  • Can we move off our warehouse without breaking the reports the business relies on?
  • We want agents that do real work, not another chatbot.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We map every legacy object to a destination before we build. We design one warehouse with shared dimensions, a semantic layer holding every governed measure, data contracts on every feed, and access rules defined once and applied everywhere. Then we build the agents on top. Each agent reads governed measures through the semantic layer, acts only within the permissions set for its data, and records every action against a named owner. We test each agent with data designed to make it fail safely before it goes live. Nothing old switches off until its replacement is live, reconciled and accepted.

What you get

A design of record written for a non-specialist reader; a staged build; a release route that refuses unreviewed change; AI agents built on governed data, each with a named owner and a record of every action.

Evidence
An organisation that cannot govern data on a whiteboard will not govern it in a platform.
Robin Miller, The Governance Gap
Service

Independent platform review and investment decisions

An independent view of whether a platform is safe to rely on, and a fair case for each option before you spend.

For

Leadership teams deciding whether to build, buy, keep or replace a data platform, or relying on an in-house system that works but has never been independently tested.

What we hear
  • Our own developer built something that works, and nobody else understands it.
  • Do we need our own data warehouse, and what does one cost at our size?
  • Should we build our own platform or keep relying on the vendors?

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

We test the controls, not the screens: hosting, contracts, privacy assessments, maintenance and single points of failure. We rank the risks with an owner and a deadline for each fix. For investment decisions, we give every option a fair case, including the ones we do not recommend, and state cost in three tiers: expected, budget and ceiling.

What you get

A ranked risk list with owners; option papers for executive decision; a platform sized to your data and your team.

Evidence
Speed without governance is just a shorter path to a crash.
Robin Miller, The Governance Gap
Service

Managed data services and governance as a service

Your governance, platforms and development run for you as a service, by the team that designed them.

For

Organisations that need governance, platform administration, engineering and reporting to keep running after go-live, without building a large in-house team.

What we hear
  • We built the platform, and now nobody has time to run it.
  • Our governance forum stopped meeting six months after the consultants left.
  • We need change every week, but not a full-time team.

Typical problems we hear, in the buyer's words. Not client quotes.

What we do

Data Governance as a Service: we run the governance operation for you. We run the decision forums, keep the issue register moving, chase every owner's actions and report to the board on whether the data is getting better. Platform and development services: administration, engineering, testing and support across Snowflake, Databricks, Microsoft Azure and Fabric, Informatica IDMC, Experian Aperture Data Studio, Collibra, Microsoft Purview, dbt, Fivetran, Power BI, PowerApps and Power Automate, with AI agents built in Dust and every change managed in Git. A named service lead owns the service. Senior people lead onshore, and engineering scales through our nearshore and offshore teams.

What you get

A governance operation that keeps running after the project ends; platforms kept current and secure; change delivered through one reviewed release route; a monthly report on what changed and what it is worth to the business.

Evidence
Robin Miller, The Governance Gap
How we staff the work

Senior judgement onshore. Engineering at the right cost.

Every engagement is led in the UK by senior people who answer for the result. Delivery scales through our nearshore and offshore engineering teams, working to the same standards and the same release route. You pay senior rates only for senior judgement.

Onshore, fractional

Fractional executives

A Chief Executive, Chief Data and AI Officer, Chief Technology Officer or Chief Financial Officer, for the days a week you need. They sit with your board, own the decisions and answer to your leadership team.

Business valueBoard-level judgement and accountability, without the cost of a full-time executive.
Onshore

Senior delivery team

Architects, governance leads and delivery leads in the UK. They design the platform and the controls, run the engagement and stay accountable for what is delivered.

Business valueOne named person answers for every piece of work.
Nearshore

Nearshore development

Data engineering, reporting and application teams in close time zones, working in your hours on build and change.

Business valueFast turnaround on change, at lower cost than a UK team.
Offshore

Offshore development

Engineering, testing and managed service teams for build at scale and ongoing support.

Business valueCapacity that scales up quickly, at the lowest cost per change.
Every team works to one release route: no change reaches production without review, and every data set and AI agent has a named owner.
Case studies

What changed for the business, and what comes next.

No client is named. Every case shows what the problem was costing the business, what we changed, and what the business can do now. We say plainly what is delivered, what is designed and what is still to come.

DeliveredBuilt, not yet liveDesignedCommitted target
Energy sector
Energy and renewables
Read ✓

New systems approved faster, and lawfully

New systems and supplier deals were stalling at privacy sign-off, or going ahead without a confirmed lawful basis. We turned privacy assessments into decisions the Data Protection Officer can take, put a named owner on every action, and help answer subject access requests completely. Projects move, and the business can show its evidence when challenged.

Status

Assessment reviews and rewrites delivered. Privacy support, including subject access requests, running. Self-service agents for assessments being explored.

Read the case →
Before

Projects stalled at privacy sign-off

↓

Assessments arrive ready for a decision, so projects get a yes or a clear route to one.

Before

Actions handed to teams never closed

↓

Every action owned by a named person, so fixes happen.

Before

Subject access requests slowed by not knowing where data sits

↓

Requests answered completely, from one view of where personal data lives.

In delivery
Energy sector
Energy and renewables
Read ✓

Numbers the board can defend, as the portfolio grows

An energy business's reports disagreed, so meetings argued about figures instead of deciding. With the portfolio set to grow several times over, we are building one governed platform where every measure has one definition and one owner. The board, lenders and partners get figures the business can defend, and reporting grows without adding people.

Status

In delivery. Design approved; build under way; go-live planned.

Read the case →
Before

Reports disagreed, so meetings argued about the number

↓

One owned definition for every measure, trusted in every report.

In delivery
Before

The lifetime cost of an asset rebuilt by hand every time

↓

Whole-life cost and return of any investment in one view.

Designed
Before

Wrong figures could reach the board with no warning

↓

Errors raised to a named owner before they reach a report.

Designed
Insurance sector
Insurance and reinsurance
Read ✓

Figures a regulator can trace, and people use every day

An insurance business kept the meaning of its data in spreadsheets, so figures differed across underwriting, actuarial, finance and claims, and lineage for regulatory returns was traced by hand. We have built a governed catalogue the business now uses every day, with a named owner behind every issue. The result: figures it can defend to its regulator, and less rework across four functions.

Status

Programme running over several phases. Catalogue live and in daily use. Current phase in delivery; retention and lineage automation not yet complete.

Read the case →
Before

Figures that differed between functions

↓

One agreed meaning for the data, used every day across four functions.

Before

A board-level retention risk with no process

↓

A retention schedule agreed with Legal, and a plan to run it.

Designed
Before

Data issues with nobody to fix them

↓

Every issue owned by a named person and tracked to a proven fix.

Housing associations facing a downgrade
Social housing
Read ✓

A board that can answer the regulator

When the regulator downgrades a housing association, or signals that it might, the judgement often names data as a theme running through the findings. In weeks, not months, we give the board a checked diagnosis, a roadmap its own team can run, and the decisions it must take. The board can then answer the regulator from its own evidence, at a cost the organisation can carry.

Status

Sector case. A grade changes when the regulator sees the evidence at the next inspection.

Read the case →
Before

A regulator's concern and no clear place to start

↓

A checked diagnosis and a roadmap with an owner for every action, in weeks, not months.

Before

An approved strategy nobody ran

↓

A roadmap sized to the team the organisation actually has.

Recommended
Before

Paying the supplier to reach its own data

↓

An owned platform that costs less to run than the clean-ups it replaces.

Recommended
Energy sector
Energy and renewables
Read ✓

An AI portfolio the business can prioritise against value

Every team was raising its own AI ideas, and an outside adviser added a long list of its own, with nobody owning AI across the business. We analysed more than 150 ideas, classified and grouped them by what they actually do, and turned them into one cohesive portfolio tied to business value. The business can now prioritise AI work against value, pay for each capability once, and build it with the right tool.

Status

Portfolio delivered: classified, prioritised and tied to business value. First agent built and tested. Agents for privacy self-service being explored.

Read the case →
Before

Every team, and an outside adviser, raising AI ideas separately

↓

A classified, prioritised portfolio of more than 150 ideas, each tied to business value, ready to plan work against.

Before

Nobody owned AI, and vendors were switching it on

↓

No agent goes live without a named owner.

Designed
Before

Money heading to AI where a report would do

↓

Each idea routed to the tool that fits, which costs less and is easier to audit.

Recommended
Membership sector
Professional bodies and membership organisations
Read ✓

Members who want to pay can pay

After a new CRM went live, members of a professional membership body could not reliably renew, join or reach their accounts, putting subscription income at risk at the moment members tried to pay. We separated the failures the data causes from those it does not, and committed to fixing the data failures at source, with named owners so they stay fixed.

Status

Discovery delivered. Funded work under way. All results below are committed targets.

Read the case →
Before

Every failing journey blamed on data

↓

Failures sorted by cause, so money goes where the data is the cause.

Before

Duplicate records blocking renewal

↓

Members reach their accounts and get one correct invoice.

Committed target
Before

Issues in trackers nobody owned

↓

One register, every issue owned, so problems stay fixed.

Committed target

What our clients can do now.

Each result is written as what the business can now do, not as activity. Each carries its status, so you can see what is delivered today and what is committed next.

Result
Case
Status
New systems reach a privacy decision, with a named owner on every fix
Energy sector
Delivered
Figures the business can defend to its regulator, in a catalogue people use every day
Insurance sector
Delivered
Every report the business relies on has a home before the old platform is switched off
Energy sector
Delivered
A board that can answer the regulator from its own evidence
Housing associations facing a downgrade
Delivered
A classified, prioritised AI portfolio the business can plan against, with every idea tied to business value
Energy sector
Delivered
Renewal income protected where members pay
Membership sector
Committed target
Less time reconciling, more time deciding, once the new platform is live
Energy sector
To be measured
Sectors

Where we work, and what we hear there.

Energy businesses are growing their portfolios quickly, across several technologies at once. Every weakness in the data grows with them. At the same time, AI is arriving inside the systems they already run, and each legal entity in a group carries its own privacy obligations.

What we hear
  • Our reports disagree, and we reconcile them by hand every month.
  • The maintenance system and the operational data use different codes for the same turbine.
  • We have been asked to switch AI on, and nobody has decided what it may read.
  • Our sister company already has an approved DPIA for this system. Doesn't that cover us?
  • The newsletter is not selling anything, so it is not marketing.

Typical problems we hear, in the buyer's words. Not client quotes.

How we help
Cases
Robin Miller, The Governance Gap
Pressures
  • Rapid portfolio growth across wind, solar and battery storage.
  • One asset held in operational, maintenance, finance and project systems, each with its own identifier.
  • More complex revenue: battery sites earn from several streams at once, alongside Contracts for Difference, Renewables Obligation Certificates and power price revenue.
  • Investment decisions that need the whole life of an asset.
  • Groups run as several legal entities, each a separate controller. An approval for one does not cover another.
  • AI arriving inside asset, supply chain and HR systems, often before anyone decided to use it.
  • Supplier checks that now include sanctions and adverse media screening of suppliers' directors and owners.
  • Community engagement for renewables projects, which means mailing lists of members of the public.
Questions buyers ask
  • How do we get one version of generation, availability and outage figures?
  • How do we join maintenance data to operational data when the asset codes differ?
  • Can we move off our warehouse without breaking the reports the business relies on?
  • How do we let teams build AI agents without losing control of the definitions?
  • What does a DPIA for an AI agent need that a normal system DPIA does not?
  • Who should own asset data: operations, engineering or finance?

A reinsurer's numbers pass through underwriting, actuarial, finance and claims before they reach a regulator. Each function keeps its own view of the same data, often in spreadsheets. When the regulator asks where a figure came from, the answer has to be evidence, not memory. Personal data is also held across regions and legal entities, under UK GDPR and cross-border transfer rules.

What we hear
  • Our metadata lives in spreadsheets, and every function keeps its own.
  • Retention has been on the risk register for years and nobody has fixed it.
  • Audit wants to see our lineage, and we track it by hand.
  • Our governance roles were never filled after the last reorganisation.
  • We know governance saves effort. We have never put a number on it.

Typical problems we hear, in the buyer's words. Not client quotes.

How we help
Cases
Robin Miller, The Governance Gap
Pressures
  • Solvency II expects complete, auditable data lineage.
  • UK GDPR and cross-border transfer rules apply to personal data held across regions and legal entities.
  • Data retention can stay a board-level risk for years when no structured process exists.
  • The same data serves underwriting, actuarial, finance and claims, so metadata kept by hand produces rework and figures that disagree.
  • Restructuring leaves governance roles vacant, and the knowledge goes with them.
  • AI arrives before anyone has named an AI Model Owner or given the data owners a seat on the AI governance body.
  • Internal Audit and external maturity assessments ask for evidence of governance, not a description of it.
Questions buyers ask
  • How do we show a regulator complete, auditable lineage without tracking it by hand?
  • Where do we start with a data catalogue when we have nothing today?
  • Which data elements are critical, and who should define and own each one?
  • How do we turn an agreed retention schedule into one that operates?
  • What evidence will Internal Audit or an external maturity assessor want to see?
  • Who should own treaty data when four functions all use it?
  • How do we bring AI governance and data governance together before the first model goes live?

Housing associations face public consumer grades, board members who answer for the accuracy of what they approve, and several new obligations landing at once. Most have small teams and a housing management system hosted by a supplier. The regulator now reads a data strategy as a promise.

What we hear
  • The regulator says our data is a theme, and we do not know where to start.
  • Everyone thinks IT owns the data.
  • We have to pay our supplier every time we want our own data cleaned.
  • We made the right call on that damp case, but we cannot show it.
  • Everything on the spreadsheet is green, and I do not trust it.

Typical problems we hear, in the buyer's words. Not client quotes.

How we help
Cases
Regulators have moved from asking for frameworks to asking for names. Most organisations are still offering committee structures.
Robin Miller, The Governance Gap
Pressures
  • Routine inspections and published consumer grades since April 2024, visible to lenders, tenants and the press.
  • Several obligations landing together: Awaab's Law in phases, the Competence and Conduct Standard, proactive publication and information requests under STAIRs, Housing Ombudsman compensation guidance, Decent Homes reform, and EPC Band C by 2030.
  • Key dates: STAIRs proactive publication and the Competence and Conduct Standard from 01/10/2026; Awaab's Law Phase 2 from 30/11/2026, subject to Parliament; Phase 1 has applied to damp and mould since 27/10/2025.
  • Board members answerable for the accuracy of the information they approve.
  • Small teams, where one analyst or one IT manager is a single point of failure.
  • Supplier-hosted housing management systems with limited access to the organisation's own data.
  • Contractors holding job-level data the landlord cannot see.
Questions buyers ask
  • What will the regulator ask for, and can we produce it from one agreed source?
  • Who should own tenant, asset, safety and complaints data?
  • Are our tenant satisfaction measures on the right scope?
  • How do we record Awaab's Law decisions, including the cases we judge below the threshold?
  • What do we need in place before STAIRs publication starts?
  • Do we need our own data warehouse, and what does one cost at our size?
  • How do we do this with the team we have?

For a membership body, renewal is the income. When a new CRM goes live on migrated data, the renewal journey is where the defects show first. Member and learner identity is spread across many systems, and records often depend on data keyed by external partners.

What we hear
  • Members cannot renew, and we do not know how many.
  • The same member is on the system three times.
  • Our issues sit in four trackers, and nobody owns them.
  • Records from before go-live are hard to find.

Typical problems we hear, in the buyer's words. Not client quotes.

How we help
Cases
Robin Miller, The Governance Gap
Pressures
  • New CRM platforms going live, with data migrated from legacy membership systems.
  • Subscription income that depends on a working renewal journey.
  • Member and learner identity spread across CRM, CPD, e-learning, community and partner systems.
  • Records that depend on data keyed by many external partners.
  • Changed data law: the Data (Use and Access) Act 2025, in force for most data protection provisions from 05/02/2026.
Questions buyers ask
  • How much of our post go-live pain is data, and how much is the system?
  • How do we deduplicate members without merging the wrong people?
  • Who should own member data: membership, digital or finance?
  • How do we reconcile what our partners send us with what we hold?
  • How do we stop the data drifting back after the clean-up?
  • What can we commit to in two months?
Experian partnership

Accredited by Experian. Built for the teams who run Aperture.

Experian Accredited PartnerExperian Masters Accredited Solution

8GG is an Experian Accredited Partner, and our 8 Gates solution for Aperture Data Studio holds Experian's Masters accreditation. Organisations that already own Aperture get a team that makes it pay: data fixed at source, a named owner on every rule, and fixes that stay fixed.

For Experian clients

Make Aperture a control the business relies on.

We design data quality rules around the processes and decisions the business depends on, build the workflows and scorecards that run them, and correct the records that break customer journeys. Where clients move from Informatica Data Quality, we migrate in stages by source system and run both side by side until the results match.

Business valueAperture stops being a one-off clean-up and becomes a control with an owner. A change of platform never loses a check the business relies on.
For Experian

Aperture shown in the terms a board uses.

Experian uses our 8 Gates solution to show its clients what governed data quality looks like in Aperture: who owns each rule, how a failed check reaches a decision, and how the board sees the data improve.

Business valueExperian's clients see what Aperture is worth to them in governance terms, not just data terms.
What we have built

The 8 Gates, running in Aperture.

We built the 8 Gates framework into Aperture Data Studio as a working solution: named owners, agreed definitions, quality rules, scorecards and issue routes in one place, set up so every rule has an owner and every failure reaches a decision.

Business valueOrganisations start from a proven governance design instead of a blank workspace, so they reach governed data quality sooner.
Aperture in use:Membership sector →
The thinking behind 8GG

The Governance Gap

From committees to consequences

Most organisations have a governance framework, a policy manual and a committee. When the board asks a direct question, nobody can answer it. The book explains why: governance anchored to systems instead of processes, and assigned to committees instead of individuals. It sets out the 8 Governed Gates, a practical way to put named accountability into daily operation, including for AI.

Chief executives and boards

A way to know who answers for the data before a regulator asks.

Chief Data Officers

A route from running the plumbing to securing the strategy.

Governance practitioners

A working guide, gate by gate.

AI governance and first-time implementers

Their own reading paths.

Layer one
Foundation
1 Roles
2 Landscape
Layer two
Meaning
3 Definition
4 Quality
Layer three
Control
5 Risk and Controls
6 Monitoring
Layer four
Sustainability
7 Improvement
8 Communication
“The architecture is the sequence. Break the sequence and the gates become decoration.”
Five questions from the book

Could your organisation answer these today?

Tell us a little about your organisation, then answer the five questions. The eight gates update as you go, and show where we would start.

People

Run by three equal partners.

RM
Robin Miller
Partner and Chief Technology Officer

I help boards put a named owner behind every number they decide on, and every AI system they run.
‍
At 8 Governed Gates, I lead client delivery: the data platform, the privacy evidence, and the rules AI agents follow before they go live.
‍
I judge the work by what the business can do afterwards: decide faster, answer the regulator, and pay for each AI capability once.
‍
My book, The Governance Gap: From committees to consequences, argues that data and AI only pay back when they are aligned to the critical business processes and decisions they serve, with a named owner accountable for each.

Built the 8 Governed Gates framework with Kenneth Allan Scott.

LinkedIn profile ↗
KS
Kenneth Allan Scott
Partner and Chief Financial Officer

I help organisations turn data governance from a policy into a working operation.

At 8 Governed Gates, I lead our metadata, lineage and data quality work, so every critical data element has an agreed definition, a traceable source and a named owner.

My career has been in highly regulated industries, including banking and investment funds in the UK and Luxembourg.

I know what a regulator expects to see, and how to build the evidence that answers it. I build teams and structures that last after the programme ends, working with every level of an organisation, from analysts to the board.

Whether it is a data catalogue, a quality scorecard or a new governance function, I measure success by business outcomes, not documents.

Built the 8 Governed Gates framework with Robin Miller.

LinkedIn profile ↗
DS
David Searro
Partner and Chief Operating Officer

I help boards and leadership teams turn data and AI into business performance. At 8 Governed Gates, I lead our commercial work and executive engagements, so every programme starts from the outcome the board needs and the value it will deliver.

I have held board and executive roles across data, AI, technology, operations and revenue, in interim, fractional, non-executive and permanent positions. I have grown businesses in revenue and profit, and I bring that commercial view to every governance decision.

My work spans housing, insurance, financial services, retail, hospitality and the public sector. Whether it is a data strategy, a capability assessment or a new data product, I focus on what the organisation can run and sustain with the team it has.

Leads our work with housing associations and membership bodies.

LinkedIn profile ↗
Who we work with

Energy and renewables businesses, insurers and reinsurers, housing associations and professional membership bodies. Organisations that are growing fast, facing a regulator, recovering from a system go-live, or starting on AI.

Platforms we work with
Snowflake
Microsoft Power BI
Microsoft Fabric
Collibra
Informatica
Experian Aperture Data Studio
Microsoft PowerApps
Start here

Tell us which number you do not trust.

We will tell you who should own it, and what fixing it is worth to the business.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Book a call →
Register entry preview
Item
The number you name
Owner
To be named
Decision
Two signatures: process and data