Data Governance, Quality and Ethics
Governance
Data Governance, Quality and Ethics
Syllabus tag: KASNEB CPA | Advanced Level | CA34S1 Business Data Analytics
1. Data governance defined
Data governance is the overall management framework defining who has authority and control over data assets — covering data policies, standards, roles, responsibilities, and processes. It ensures that data is: accurate, consistent, secure, and used in accordance with organisational and regulatory requirements.
A data governance committee (or council) typically includes: Chief Data Officer (CDO), data stewards, IT representatives, business unit leaders, legal/compliance, and risk management.
2. Key data governance roles
Data owner: a senior person in the business accountable for a data domain (e.g. the CFO owns financial data). Sets policies for access, use, and quality. Data steward: operationally responsible for data quality, definitions, and standards in their domain. Data custodian (IT): responsible for the technical storage, security, and maintenance of data. Data consumer: any person who uses data to perform their job.
3. Data quality dimensions
The five core dimensions of data quality:
- Accuracy: data correctly represents the real-world entity it describes
- Completeness: all required data is present — no missing values in critical fields
- Consistency: data is the same across different systems and sources (no contradictions)
- Timeliness: data is up to date and available when needed
- Uniqueness: no duplicate records — each entity is represented only once
Poor data quality leads to: incorrect business decisions, regulatory non-compliance, operational inefficiencies, reputational damage, and financial loss.
4. Data dictionary and metadata
A data dictionary is a centralised catalogue defining and documenting data elements: their names, definitions, data types, allowable values, source systems, owners, and relationships. It is essential for data governance — without it, different users may interpret the same field differently.
Metadata is "data about data" — descriptive information that enables users to find, understand, and manage data assets. Types: descriptive (what the data is about), structural (how it is organised), and administrative (rights, provenance, data lineage).
5. Data privacy and legal frameworks
General Data Protection Regulation (GDPR): EU regulation governing the processing of personal data of EU residents. Key principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. Rights of data subjects: access, rectification, erasure, portability.
Kenya Data Protection Act 2019: Kenya's domestic equivalent. Establishes the Office of the Data Protection Commissioner (ODPC). Requires data controllers and processors handling personal data of Kenyan residents to register and comply with data protection principles.
6. Ethical considerations in data analytics
Algorithmic bias: ML models trained on biased historical data may perpetuate or amplify discrimination (e.g. rejecting loan applications from certain demographics). Must be monitored and corrected. Privacy vs utility: anonymisation enables analysis while protecting individuals; re-identification risk must be managed. Transparency and explainability: stakeholders should be able to understand how data-driven decisions are made — "black box" models create accountability challenges. Consent and purpose: data collected for one purpose should not be repurposed without adequate consent.
