Your board decides on your figures. Your regulator asks who stands behind them. Your teams want to build AI on them. When nobody owns the data, all three get slower, riskier and more expensive. We name the owner, settle the decision, and build the platforms and controls that keep your numbers right, so the business can move quickly and defend what it decides.
It shows up as meetings that argue about the number, projects stuck waiting for sign-off, and regulators asking for evidence nobody can produce. The policy exists. The tools exist. Nobody has to put it right.
“Accountability is the only control that scales.”
The gates govern how data and AI are used in the processes that earn and protect your money, not how systems are built. The first five clear a use before it goes live, so risk is dealt with before it costs you. The last three keep it right while it runs. Light where risk is low, deeper where AI, personal data or material money is involved.
The order matters: each gate depends on the one before. Light where risk is low. Deeper where AI, personal data or money is involved.
Who is accountable? A named owner for the process, the data and any AI, each with the authority to say no. Decisions stop waiting for a committee, and every problem has someone who must fix it.
What does the process depend on? We map the data, systems and AI each critical process relies on, including undeclared spreadsheets. Effort goes on the few items that cost money when they are wrong.
What does it mean for this process? Each critical figure and AI output has one signed definition and clear limits on its use. Meetings stop arguing about the number and start deciding what to do about it.
Is it good enough for this decision? Thresholds are set by what an error costs the business, not by a generic percentage. Every breach goes to a named owner, with a response and a deadline.
What could go wrong, and who accepts it? Every new data use and AI model is assessed before it goes live. The owner signs off the risk that remains, so nothing reaches customers on a nod in a meeting.
Is it still safe? From go-live we watch data quality, AI drift and controls continuously. Problems reach the named owner before they reach a customer, a decision or a regulator.
Are problems getting fixed? Issues go into one backlog, ranked by business impact, not by the loudest voice. A fix closes only when the data meets its threshold, so problems stay fixed.
Do people know the rules? Everyone gets guidance that fits their role, and owners are coached on live decisions. People know which data matters, and when to challenge an AI output.
Start from the business process. Governance follows the decisions that earn and protect money.
No data or AI use goes ahead without a clear business purpose behind it.
One named owner for the process, one for the data, and one for any AI.
Controls scale with risk. Light where risk is low, deeper where money or AI is involved.
Governance keeps working after go-live, so the data stays right as the business changes.
The person who owns the process, and the person who owns the data.
Every material decision needs two signatures. First, the Business Process Owner confirms the use adds value and is necessary. If not, it stops. Second, the Data Owner, or AI Model Owner, confirms the use is acceptable on quality, sensitivity and risk.
Where risk is low and the use follows an approved pattern, a fast track applies. Try the route on the right.
Governance starts with the decisions that earn and protect your money, not with the systems behind them.
Every engagement begins by asking what decision the data supports, and what it costs the business when that data is wrong.
A named owner gets things fixed. An action owned by a team stays open.
Privacy fixes, AI ideas and roadmap actions for our clients each carry a named accountable role, so work closes instead of circulating.
We commit only to what the data causes, so your budget goes where it changes the result.
For a membership body, we separated data failures from system failures and handed each to its real owner, so nobody paid to fix the wrong thing.
Governance the team can run survives. Governance built for a bigger organisation gets abandoned.
Housing associations facing a downgrade get a roadmap their own people can deliver, using the meetings they already hold, with no new council and no costly platform.
When two figures disagree, the owner decides which is right, not a line of code.
On an energy platform, disputed revenue figures wait for the Data Owner's decision instead of reaching the board by accident.
We test every control by trying to get round it, so it protects you in practice, not just on paper.
On an energy platform, no change reaches production without a genuine review, and the control proves that rule each time it runs.
Every claim we put in front of a board is checked against the source first.
A housing association's board received a diagnosis tested against its own people's evidence, so it could act without commissioning a second opinion.
You always know what is delivered, what is designed and what is still to come, so you never fund a promise as if it were a result.
Every report we write, and every case on this site, carries its status.
You decide with the full picture, including the options we do not recommend.
An energy business chose its data platform from options that each had an honest case for and against, so the decision held when it was challenged.
The team that designs your controls also runs them, so nothing is lost at handover.
While we build an energy business's new platform, we also run its existing one every day, so the reports it relies on keep running.
“Accountability without authority is blame. Authority without accountability is power. Governance requires both, held by the same person.”
We name the owners, agree the definitions and set up the decisions that keep your data right.
Organisations whose data problems keep coming back after each clean-up, or whose regulator, auditor or board has asked who owns the numbers.
Typical problems we hear, in the buyer's words. Not client quotes.
We apply the 8 Gates to the processes that matter most. We name a Business Process Owner and a Data Owner for each, agree one definition for each measure, and set up the Double Lock so that every material decision carries two signatures. We size the governance to the organisation, using the meetings you already hold where we can.
Named owners by data domain; a decision route; one issue register with every issue owned; measures that show whether governance is working, such as the rate of new defects each month.
A name on a register is not ownership. Ownership is explicit acceptance of accountability for decisions, backed by authority to act.
In a few weeks, a validated diagnosis of where your data fails, why, and who should own the fix.
Boards and executives who have been told data is a problem, often by a regulator, and need to know where to start.
Typical problems we hear, in the buyer's words. Not client quotes.
Structured interviews and workshops across the executive and heads of service, with data profiling where the tools allow. We tag every finding, test divergent figures against their source, and trace each problem to its root cause. Before anything reaches the board, we check our highest-stakes claims against the evidence.
A diagnosis by data domain; root causes; a roadmap with an owning role for every activity; draft risk register entries; board decisions with the cost of deferring each.
Governance that cannot survive a direct question is not governance. It is paperwork.
Decide which AI ideas to build, who owns each one, and what every agent may read, before the first one goes live.
Organisations where teams are asking to build AI agents, vendor platforms have switched AI features on, or staff already use AI tools nobody approved.
Typical problems we hear, in the buyer's words. Not client quotes.
We gather every AI request into one portfolio and assess each on the same terms: what it is in technology terms, its value, its risk and its owner. We find duplicates and the ideas that are not AI at all. We set a data classification for agents and a publication rule: no named owner, no agent. We build first agents with test data designed to make them fail safely.
A ranked AI portfolio; a three-tier rule on what agents may read; four questions every agent answers before publication; an approval route; first agent builds.
A constraint in a prompt is a suggestion. A constraint in the infrastructure is a control.
Privacy assessments reviewed, rewritten and made ready to approve, with a named owner on every fix.
Data Protection Officers and legal teams receiving assessments written by people who are experts in their work but not in data protection law, especially for AI tools, employee data and supplier sharing.
Typical problems we hear, in the buyer's words. Not client quotes.
We read each Data Protection Impact Assessment (DPIA) field by field, give a plain verdict (approve, do not approve, or incomplete), rate every finding, and name the role accountable for each fix. We write replacement wording, add the risk register the law requires, and tell the Data Protection Officer when the template itself is causing the failures.
A verdict and a numbered route to approval with effort in days; model answers; rewritten or new DPIAs; template fixes.
Perpetual acceptance is not governance. It is neglect with a signature.
Fix the records that break your customer journeys, and measure whether they stay fixed.
Organisations after a CRM or system migration, where duplicates, missing fields and unreconciled records stop customers renewing, joining or reaching their accounts.
Typical problems we hear, in the buyer's words. Not client quotes.
We profile the data, sort every failure by cause, and commit only to what the data causes. Each commitment has a baseline, a target and a countable population. We correct the data, usually in Experian Aperture Data Studio, with the Double Lock on every correction. We measure the refill rate so the clean-up is not undone.
From-and-to measures with today's figure and a committed figure; one issue register; named Data Owners; corrected data.
Quality is not a percentage. It is whether the data is safe to use for this decision, in this process, at this level of consequence.
One governed platform for your data and your AI agents, built in stages that each deliver on their own.
Organisations whose reports disagree, whose warehouse grew mart by mart, or who want AI agents that do real work on governed data rather than on copies nobody controls.
Typical problems we hear, in the buyer's words. Not client quotes.
We map every legacy object to a destination before we build. We design one warehouse with shared dimensions, a semantic layer holding every governed measure, data contracts on every feed, and access rules defined once and applied everywhere. Then we build the agents on top. Each agent reads governed measures through the semantic layer, acts only within the permissions set for its data, and records every action against a named owner. We test each agent with data designed to make it fail safely before it goes live. Nothing old switches off until its replacement is live, reconciled and accepted.
A design of record written for a non-specialist reader; a staged build; a release route that refuses unreviewed change; AI agents built on governed data, each with a named owner and a record of every action.
An organisation that cannot govern data on a whiteboard will not govern it in a platform.
An independent view of whether a platform is safe to rely on, and a fair case for each option before you spend.
Leadership teams deciding whether to build, buy, keep or replace a data platform, or relying on an in-house system that works but has never been independently tested.
Typical problems we hear, in the buyer's words. Not client quotes.
We test the controls, not the screens: hosting, contracts, privacy assessments, maintenance and single points of failure. We rank the risks with an owner and a deadline for each fix. For investment decisions, we give every option a fair case, including the ones we do not recommend, and state cost in three tiers: expected, budget and ceiling.
A ranked risk list with owners; option papers for executive decision; a platform sized to your data and your team.
Speed without governance is just a shorter path to a crash.
Your governance, platforms and development run for you as a service, by the team that designed them.
Organisations that need governance, platform administration, engineering and reporting to keep running after go-live, without building a large in-house team.
Typical problems we hear, in the buyer's words. Not client quotes.
Data Governance as a Service: we run the governance operation for you. We run the decision forums, keep the issue register moving, chase every owner's actions and report to the board on whether the data is getting better. Platform and development services: administration, engineering, testing and support across Snowflake, Databricks, Microsoft Azure and Fabric, Informatica IDMC, Experian Aperture Data Studio, Collibra, Microsoft Purview, dbt, Fivetran, Power BI, PowerApps and Power Automate, with AI agents built in Dust and every change managed in Git. A named service lead owns the service. Senior people lead onshore, and engineering scales through our nearshore and offshore teams.
A governance operation that keeps running after the project ends; platforms kept current and secure; change delivered through one reviewed release route; a monthly report on what changed and what it is worth to the business.
Every engagement is led in the UK by senior people who answer for the result. Delivery scales through our nearshore and offshore engineering teams, working to the same standards and the same release route. You pay senior rates only for senior judgement.
A Chief Executive, Chief Data and AI Officer, Chief Technology Officer or Chief Financial Officer, for the days a week you need. They sit with your board, own the decisions and answer to your leadership team.
Architects, governance leads and delivery leads in the UK. They design the platform and the controls, run the engagement and stay accountable for what is delivered.
Data engineering, reporting and application teams in close time zones, working in your hours on build and change.
Engineering, testing and managed service teams for build at scale and ongoing support.
No client is named. Every case shows what the problem was costing the business, what we changed, and what the business can do now. We say plainly what is delivered, what is designed and what is still to come.
New systems and supplier deals were stalling at privacy sign-off, or going ahead without a confirmed lawful basis. We turned privacy assessments into decisions the Data Protection Officer can take, put a named owner on every action, and help answer subject access requests completely. Projects move, and the business can show its evidence when challenged.
Assessment reviews and rewrites delivered. Privacy support, including subject access requests, running. Self-service agents for assessments being explored.
Projects stalled at privacy sign-off
Assessments arrive ready for a decision, so projects get a yes or a clear route to one.
Actions handed to teams never closed
Every action owned by a named person, so fixes happen.
Subject access requests slowed by not knowing where data sits
Requests answered completely, from one view of where personal data lives.
An energy business's reports disagreed, so meetings argued about figures instead of deciding. With the portfolio set to grow several times over, we are building one governed platform where every measure has one definition and one owner. The board, lenders and partners get figures the business can defend, and reporting grows without adding people.
In delivery. Design approved; build under way; go-live planned.
Reports disagreed, so meetings argued about the number
One owned definition for every measure, trusted in every report.
The lifetime cost of an asset rebuilt by hand every time
Whole-life cost and return of any investment in one view.
Wrong figures could reach the board with no warning
Errors raised to a named owner before they reach a report.
An insurance business kept the meaning of its data in spreadsheets, so figures differed across underwriting, actuarial, finance and claims, and lineage for regulatory returns was traced by hand. We have built a governed catalogue the business now uses every day, with a named owner behind every issue. The result: figures it can defend to its regulator, and less rework across four functions.
Programme running over several phases. Catalogue live and in daily use. Current phase in delivery; retention and lineage automation not yet complete.
Figures that differed between functions
One agreed meaning for the data, used every day across four functions.
A board-level retention risk with no process
A retention schedule agreed with Legal, and a plan to run it.
Data issues with nobody to fix them
Every issue owned by a named person and tracked to a proven fix.
When the regulator downgrades a housing association, or signals that it might, the judgement often names data as a theme running through the findings. In weeks, not months, we give the board a checked diagnosis, a roadmap its own team can run, and the decisions it must take. The board can then answer the regulator from its own evidence, at a cost the organisation can carry.
Sector case. A grade changes when the regulator sees the evidence at the next inspection.
A regulator's concern and no clear place to start
A checked diagnosis and a roadmap with an owner for every action, in weeks, not months.
An approved strategy nobody ran
A roadmap sized to the team the organisation actually has.
Paying the supplier to reach its own data
An owned platform that costs less to run than the clean-ups it replaces.
Every team was raising its own AI ideas, and an outside adviser added a long list of its own, with nobody owning AI across the business. We analysed more than 150 ideas, classified and grouped them by what they actually do, and turned them into one cohesive portfolio tied to business value. The business can now prioritise AI work against value, pay for each capability once, and build it with the right tool.
Portfolio delivered: classified, prioritised and tied to business value. First agent built and tested. Agents for privacy self-service being explored.
Every team, and an outside adviser, raising AI ideas separately
A classified, prioritised portfolio of more than 150 ideas, each tied to business value, ready to plan work against.
Nobody owned AI, and vendors were switching it on
No agent goes live without a named owner.
Money heading to AI where a report would do
Each idea routed to the tool that fits, which costs less and is easier to audit.
After a new CRM went live, members of a professional membership body could not reliably renew, join or reach their accounts, putting subscription income at risk at the moment members tried to pay. We separated the failures the data causes from those it does not, and committed to fixing the data failures at source, with named owners so they stay fixed.
Discovery delivered. Funded work under way. All results below are committed targets.
Every failing journey blamed on data
Failures sorted by cause, so money goes where the data is the cause.
Duplicate records blocking renewal
Members reach their accounts and get one correct invoice.
Issues in trackers nobody owned
One register, every issue owned, so problems stay fixed.
Each result is written as what the business can now do, not as activity. Each carries its status, so you can see what is delivered today and what is committed next.
Energy businesses are growing their portfolios quickly, across several technologies at once. Every weakness in the data grows with them. At the same time, AI is arriving inside the systems they already run, and each legal entity in a group carries its own privacy obligations.
Typical problems we hear, in the buyer's words. Not client quotes.
A reinsurer's numbers pass through underwriting, actuarial, finance and claims before they reach a regulator. Each function keeps its own view of the same data, often in spreadsheets. When the regulator asks where a figure came from, the answer has to be evidence, not memory. Personal data is also held across regions and legal entities, under UK GDPR and cross-border transfer rules.
Typical problems we hear, in the buyer's words. Not client quotes.
Housing associations face public consumer grades, board members who answer for the accuracy of what they approve, and several new obligations landing at once. Most have small teams and a housing management system hosted by a supplier. The regulator now reads a data strategy as a promise.
Typical problems we hear, in the buyer's words. Not client quotes.
Regulators have moved from asking for frameworks to asking for names. Most organisations are still offering committee structures.
For a membership body, renewal is the income. When a new CRM goes live on migrated data, the renewal journey is where the defects show first. Member and learner identity is spread across many systems, and records often depend on data keyed by external partners.
Typical problems we hear, in the buyer's words. Not client quotes.


8GG is an Experian Accredited Partner, and our 8 Gates solution for Aperture Data Studio holds Experian's Masters accreditation. Organisations that already own Aperture get a team that makes it pay: data fixed at source, a named owner on every rule, and fixes that stay fixed.
We design data quality rules around the processes and decisions the business depends on, build the workflows and scorecards that run them, and correct the records that break customer journeys. Where clients move from Informatica Data Quality, we migrate in stages by source system and run both side by side until the results match.
Experian uses our 8 Gates solution to show its clients what governed data quality looks like in Aperture: who owns each rule, how a failed check reaches a decision, and how the board sees the data improve.
We built the 8 Gates framework into Aperture Data Studio as a working solution: named owners, agreed definitions, quality rules, scorecards and issue routes in one place, set up so every rule has an owner and every failure reaches a decision.
From committees to consequences
Most organisations have a governance framework, a policy manual and a committee. When the board asks a direct question, nobody can answer it. The book explains why: governance anchored to systems instead of processes, and assigned to committees instead of individuals. It sets out the 8 Governed Gates, a practical way to put named accountability into daily operation, including for AI.
A way to know who answers for the data before a regulator asks.
A route from running the plumbing to securing the strategy.
A working guide, gate by gate.
Their own reading paths.
“The architecture is the sequence. Break the sequence and the gates become decoration.”
Tell us a little about your organisation, then answer the five questions. The eight gates update as you go, and show where we would start.
I help boards put a named owner behind every number they decide on, and every AI system they run.
At 8 Governed Gates, I lead client delivery: the data platform, the privacy evidence, and the rules AI agents follow before they go live.
I judge the work by what the business can do afterwards: decide faster, answer the regulator, and pay for each AI capability once.
My book, The Governance Gap: From committees to consequences, argues that data and AI only pay back when they are aligned to the critical business processes and decisions they serve, with a named owner accountable for each.
Built the 8 Governed Gates framework with Kenneth Allan Scott.
I help organisations turn data governance from a policy into a working operation.
At 8 Governed Gates, I lead our metadata, lineage and data quality work, so every critical data element has an agreed definition, a traceable source and a named owner.
My career has been in highly regulated industries, including banking and investment funds in the UK and Luxembourg.
I know what a regulator expects to see, and how to build the evidence that answers it. I build teams and structures that last after the programme ends, working with every level of an organisation, from analysts to the board.
Whether it is a data catalogue, a quality scorecard or a new governance function, I measure success by business outcomes, not documents.
Built the 8 Governed Gates framework with Robin Miller.
I help boards and leadership teams turn data and AI into business performance. At 8 Governed Gates, I lead our commercial work and executive engagements, so every programme starts from the outcome the board needs and the value it will deliver.
I have held board and executive roles across data, AI, technology, operations and revenue, in interim, fractional, non-executive and permanent positions. I have grown businesses in revenue and profit, and I bring that commercial view to every governance decision.
My work spans housing, insurance, financial services, retail, hospitality and the public sector. Whether it is a data strategy, a capability assessment or a new data product, I focus on what the organisation can run and sustain with the team it has.
Leads our work with housing associations and membership bodies.
Energy and renewables businesses, insurers and reinsurers, housing associations and professional membership bodies. Organisations that are growing fast, facing a regulator, recovering from a system go-live, or starting on AI.
We will tell you who should own it, and what fixing it is worth to the business.