Every governance programme I've watched fail, failed the same way. Not with a bang — with a slow, guilty fade. A framework gets adopted with real enthusiasm. A steering group meets. A spreadsheet of "data owners" gets filled in. And then, three months later, the spreadsheet is out of date, the meetings are quietly cancelled, and everyone involved carries a low background hum of guilt about the governance they know they're supposed to be doing and aren't.

I want to make a case against that guilt, because the guilt is a symptom of a design error. Governance fails when it's built as an act of compliance — something you do to satisfy a policy — rather than as something that makes the daily work easier. If your stewardship model relies on people doing extra, virtuous, unrewarded work forever, it will lose to the deadline every single time. Not because people are lazy. Because that's what unrewarded work does.

This is written for the lean team — the two or three people holding the data estate together inside a much larger organisation, with no dedicated governance department and no appetite for one. That constraint isn't a disadvantage. It's a forcing function toward the only kind of governance that actually survives.

Why the heavyweight model doesn't fit — and doesn't need to

The mental image most people have of data governance comes from the enterprise playbook: a council, a formal role hierarchy, a fifty-page policy, a tool that scans everything. When you're a small team, you look at that and correctly conclude you can't run it. Then you feel guilty for not running it.

Drop the guilt. That model isn't the gold standard you're falling short of — it's one implementation, shaped by organisations big enough that the coordination cost of not having a council exceeds the cost of having one. At your scale, the trade-offs are different, and copying the heavyweight structure would actively harm you: it would spend your scarcest resource, attention, on ceremony instead of outcomes.

What you actually owe the organisation isn't a council. It's answers to a small number of questions, reliably: Can we trust this number? Who owns this thing? Is this data allowed to be here? Which of these is the real one? Everything else is optional. Govern the questions, not the framework.

Make the right thing the easy thing

The core move — the whole trick, really — is to stop relying on virtue and start relying on convenience. Wherever the governed path and the lazy path diverge, your job is to make them the same path. Concretely, that means leaning hard on the parts of the platform that reward good behaviour instead of merely demanding it.

  • Endorsement over enforcement. Fabric lets you mark a semantic model or a report as Promoted or Certified — a visible stamp that says "this is the trustworthy one." That badge does more real governance than any policy document, because it changes what people reach for. When the certified model is the one that surfaces first and wears the trust mark, choosing it is the lazy path. You've made the right thing the easy thing.
  • Ownership that's attached, not listed. A steward's name in a separate spreadsheet is dead on arrival. A steward's name on the item itself — set as the contact in the workspace, visible in the catalogue when someone opens it — travels with the data and survives reorganisations. Attach ownership to the object, never to a document that has to be maintained in parallel.
  • Labels that ride along. Sensitivity labels applied at the source flow downstream with the data — into the exports, the shared reports, the copies. Classify once, at the point of creation, and the classification does its own enforcement forever. That's governance you set up rather than governance you perform.

None of this is a council. All of it is stewardship that keeps working on the Tuesday nobody's thinking about governance, which is the only test that matters.

Start where the trust is breaking, not where the framework starts

The heavyweight approach says: inventory everything, classify everything, assign an owner to everything. For a small team that's a way to be busy for a quarter and finished with nothing. Invert it. Start at the point of pain, not the point of completeness.

Somewhere in your organisation there's a report the leadership actually opens on a Monday, and a quiet disagreement about whether one of its numbers is right. That's your first governance project — not because a framework told you to start there, but because that's where trust is visibly breaking and where fixing it will be noticed. Certify that model. Name its owner. Write down, in one line, what its key measures mean. Then move to the next place trust is breaking. Governance earns its next hour of investment by being visibly useful in the last one; it dies the moment it becomes a completeness exercise that no one feels.

Governance that has to be remembered is already failing. Governance that's built into the easy path just keeps happening, on the days no one has the energy to be virtuous.

A glossary of four words beats a glossary of four hundred

One specific trap worth calling out, because small teams fall into it constantly: the business glossary. The instinct is to define everything — a comprehensive dictionary of every term the organisation uses. It's a noble project and it will never be finished, and its unfinished state becomes one more source of guilt.

Don't. Define the four words that people fight about. Every organisation has them: "revenue", "active customer", "churn", whatever yours are — the handful of terms where two teams quietly mean two different things and their reports have silently disagreed for years. Nail those down, agree them out loud between the humans who currently disagree, and attach the agreed definition to the certified model. Four words that everyone actually shares are worth more than four hundred that sit in a catalogue nobody reads. Coverage is the enemy here; consequence is the goal.

The point of all of it

Strip governance back to what it's for and it isn't compliance at all. It's this: the people who consume your data should be able to trust it without having to interrogate you personally every time. That's the entire product. A council doesn't deliver it. A fifty-page policy doesn't deliver it. What delivers it is a small number of trustworthy, clearly-owned, clearly-defined things that surface first and carry their provenance with them.

So if you're the two-person team carrying a data estate and feeling guilty about the governance you're not doing — stop. You don't need their framework. You need the certified model people reach for, the owner whose name is on the thing, the four words everyone agrees on, and the discipline to fix trust where it's actually breaking. Do that, and you'll have better governance than plenty of organisations with a whole department and a council — because yours will still be running on the Tuesday theirs quietly stopped.