# EnterpriseGovernance — Completed Exemplar BRD

> **What this is**: A fully authored BRD for the Enterprise Data Governance capability-roadmap dashboard. Every section is filled in to the level a real Chief Data Officer would sign off on. It is the *finished state* the [EnterpriseGovernance starter](enterprisegovernance-starter.md) reaches when the discipline has been applied end to end. Includes an optional Section 9 (Governance Maturity Model) appropriate to the domain.
>
> **How to use it**: Read alongside the other exemplars ([AIRS](airs-exemplar.md), [CloudRevenue](cloudrevenue-completed.md), [M365Marketing](m365marketing-completed.md), [SupportInsights](supportinsights-completed.md)) to see the same eight-section shape survive across five domains. When you complete the [EnterpriseGovernance starter](enterprisegovernance-starter.md) yourself, compare Sections 4–8 (and Section 9) against this exemplar. This BRD has the highest cross-stakeholder coordination cost of the five and is worth studying specifically for how Section 5 handles a stakeholder base with legitimate, structural disagreement built into the very reason the dashboard exists.

---

## Business Requirements Document

### Enterprise Data Governance — Capability Roadmap Dashboard

- **Project**: Cross-organization data-governance capability dashboard supporting the CDO's annual governance roadmap and quarterly investment-decision cadence
- **Stakeholder**: Chief Data Officer
- **Date**: 2026-06-10 (draft) / 2026-06-24 (sign-off)
- **Priority**: High

### 1. Executive Summary

The Chief Data Officer (CDO) owns the enterprise data-governance program across the organization's twelve business units. The dashboard supports two decision cadences: the annual governance-capability roadmap (the budget request and capability sequencing for the next fiscal year) and the quarterly governance investment review (the in-year reallocation of governance budget across the twelve business units based on observed capability progress). The dashboard replaces a yearly slide-deck assembly process that has consistently understated the governance gaps in the business units that did not have a dedicated data steward at the time of the survey, biasing the roadmap toward the units that complain the loudest rather than the units with the largest gap-to-target. The dashboard's primary job is to produce a triangulated capability view that is defensible against the specific gaming behavior the current self-assessment survey enables.

### 2. Business Context

The current state has the CDO's office running an annual self-assessment survey across the twelve business-unit data stewards (where they exist) and the business-unit IT directors (where the steward role is unfilled). The survey returns inconsistent data: stewards who exist tend to self-assess generously to justify continued investment; IT directors filling in for absent stewards tend to self-assess minimally to surface that the gap exists. The resulting roadmap has, for three years running, allocated the largest governance investments to the business units with the most-vocal stewards rather than the units with the largest measurable capability gaps.

The dashboard replaces the self-assessment survey as the ranking mechanism (though not as a data source) with a triangulated view that pulls from operational signals (catalog coverage, lineage completeness, data-quality monitoring uptime, access-review compliance) alongside the self-assessment for context, with the operational signals weighted higher in the roadmap-recommendation logic. The self-assessment stays in the dashboard as a *comparison layer* so the gap between self-reported and operationally-observed capability is itself visible — that gap is one of the most informative signals about a business unit's actual governance maturity.

### 3. Key Business Questions

***Capability assessment***

1. What is each business unit's current capability level against the eight governance capabilities in the enterprise model (catalog, lineage, quality, access, retention, classification, stewardship, literacy)?
2. What is the gap between each business unit's current capability level and its target capability level, by capability?
3. Which business units have the largest aggregate gap-to-target weighted by the business criticality of their data domains?

***Trajectory***

1. Which business units have made the most capability progress in the trailing twelve months, and which have stalled or regressed?
2. Which capabilities (across all business units) have the most aggregate progress, and which have stalled at the enterprise level?
3. For business units with stalled progress, what are the operational-signal indicators (catalog coverage, lineage completeness, etc.) showing as the bottleneck?

***Investment allocation***

1. Given the gap-to-target ranking and the trajectory data, which business units would produce the largest measurable capability improvement per dollar of incremental investment in the next quarter?
2. Which capabilities (across all business units) would benefit most from a cross-business-unit shared-services investment versus per-business-unit funding?

### 4. Success Criteria

| Criterion | Measurement |
| --- | --- |
| **Roadmap-bias correction** | The next annual roadmap allocation, produced from the dashboard, does not rank business units by self-assessment loudness. Verified by comparing the top-three funded units under the new roadmap against the top-three funded units under the prior year's self-assessment-only roadmap; expected outcome is at least one substitution driven by the operational-signal ranking. If the new roadmap reproduces the old ranking exactly, the dashboard has failed its primary job. |
| **Operational-signal versus self-assessment weighting** | The weighting rule (currently drafted at 70% operational signal / 30% self-assessment for the aggregate capability score) is signed off by the CDO and communicated to all twelve business-unit data stewards *before* the dashboard produces any ranking used in budget conversations. Sign-off and communication logged as an appendix. If a steward disagrees, the dashboard surfaces both the weighted and the self-assessment-only views so the disagreement is visible rather than suppressed. |
| **Gap-visibility symmetry** | The dashboard makes the self-reported-versus-observed gap visible for every business unit, in both directions: units that over-report show the delta; units that under-report show the delta. Verified by walking through all 12 business units and confirming the gap panel populates for each. This criterion prevents the roadmap-bias-correction from itself becoming a new bias (only surfacing gaps that hurt the noisy stewards). |
| **Quarterly review usability** | The quarterly governance investment review completes in under 90 minutes with the dashboard as the sole visual artifact, no slide compilation. Measured over the first two quarterly cycles post-deployment. |
| **Audit-trail defensibility** | Every recommendation the dashboard surfaces can be traced back to its underlying operational-signal sources and self-assessment inputs with a one-click drill-through. Confirmed by the CFO's office spot-checking ten randomly selected recommendations during the first budget-season use; success = zero unexplained rankings. |

### 5. Stakeholder Requirements

#### Primary Users

- **Chief Data Officer**: Quarterly deep use during the governance investment review; annual intensive use during the roadmap-drafting window (typically January–February for the following fiscal year). Additionally references the dashboard mid-quarter when a business-unit escalation requires context. Requires a *roadmap-drafting view* (long-form, multiple panels open simultaneously, comparison-heavy) and a *quarterly-review view* (curated to the six panels the review meeting works through in order).
- **CDO Chief of Staff (day-to-day operator)**: Weekly use to keep the dashboard's inputs synchronized with the operational systems; primary owner for exception handling when an operational-signal source is delayed or a self-assessment response is late. Requires drill-through to every source-system extract for reconciliation.
- **Twelve Business-Unit Data Stewards (or IT-Director substitutes for the four non-stewarded business units)**: Quarterly use during the governance review; annual intensive use during the roadmap conversation. Each views their own business unit's slice, plus the enterprise comparison surfaces. Requires filter persistence per user. The four IT-director substitutes have identical dashboard access; the substitute-versus-steward distinction is captured in the underlying data (see the `has_dedicated_data_steward` field in the schema) but does not affect what the user sees.

#### Secondary Users

- **CFO's Office (Budget Analysts)**: Annual use during the budget-drafting cycle and quarterly use during in-year review of the governance capital pool. Requires read-only access to the aggregate budget-relevant surfaces and to the audit-trail drill-through per Success Criterion 5. Does not require business-unit-level drill-down.
- **Chief Compliance Officer**: Quarterly reference during the compliance risk review, especially the *Classification* and *Access* capability panels. Requires read-only access to the enterprise view; does not need budget-related surfaces.
- **Enterprise Data Office Team (five roles supporting the CDO)**: Occasional use for cross-BU program-level analysis. Access identical to the chief of staff but not the primary daily operator; drill-through is on-demand rather than routine.

### 6. Data Requirements

| Requirement | Detail |
| --- | --- |
| **Data Sources** | (1) Enterprise Data Catalog (catalog coverage per BU per asset type, lineage completeness, monthly refresh); (2) Data-Quality Monitoring Platform (DQ uptime per data domain, incident rate, monthly refresh); (3) Identity-and-Access Platform (access-review compliance per BU, quarterly refresh); (4) Data-Classification Tool (classification coverage per BU per asset, monthly refresh); (5) Governance Self-Assessment Survey (annual, most recent 2026-05-01, populated once per year in May); (6) Business-unit master file (BU list, criticality tier, steward assignment; quarterly refresh from HR + CDO's org roster). |
| **Refresh Frequency** | Operational-signal sources refresh monthly on the second business day. The self-assessment survey refreshes annually in May. The business-unit master refreshes quarterly. The dashboard's aggregate capability scores are recomputed after each monthly operational-signal refresh; the self-assessment overlay updates once per year. |
| **Historical Horizon** | 24 months for the operational-signal trajectory (needed to distinguish stalled from progressing business units). Full history for the self-assessment survey since program inception (three annual snapshots at time of first deployment) so the trajectory of self-assessment-versus-observed gap is trackable across years. |
| **Data Sensitivity** | Confidential. The dashboard surfaces governance-program data (capability scores, gaps, recommendations) but not the underlying data assets themselves. Data-classification signals include summary counts of classified assets per BU; the dashboard displays counts, never asset content. Row-level security scopes each BU steward to their own BU plus enterprise aggregates; CDO, chief of staff, and CFO's office see all twelve BUs. |
| **Known Quality Issues** | (a) Systematic self-assessment bias — stewarded BUs over-rate by +0.3 to +1.0 on the 1–5 scale; IT-director substitutes are honest or slightly under-rate. This bias is the reason the dashboard exists (see Section 2) and is handled by the operational-signal-weighted aggregate per Success Criterion 2, not by trying to correct the survey itself. (b) The four non-stewarded BUs (~33% of the portfolio) have a structurally different data-completeness profile — catalog coverage is ~42% (versus ~78% for stewarded BUs). The dashboard reports catalog-coverage rate as an operational signal in its own right rather than assuming clean coverage; the coverage differential is part of the roadmap conversation. (c) The annual self-assessment survey is a snapshot, not a trailing measure — using it to evaluate quarterly trajectory would be misleading. The dashboard restricts self-assessment to annual comparisons and uses only operational signals for trajectory panels. |

### 7. Deliverables

| Item | Detail |
| --- | --- |
| **Format** | Power BI workspace with four reports: (1) *Roadmap Overview* (CDO-facing; the annual roadmap-drafting surface, twelve-BU comparison, gap-to-target ranking, weighted-versus-self-assessment overlay); (2) *Quarterly Review* (curated for the 90-minute quarterly meeting; six panels in review order); (3) *Business-Unit Deep-Dive* (per-BU drill, one page per BU, filter-persistent for each steward); (4) *Audit Trail* (CFO-facing; the drill-through source for every recommendation, per Success Criterion 5). Each report has row-level security scoped to the user's role. |
| **Access Method** | Power BI Service, deployed to the Enterprise Data Office workspace. CDO, chief of staff, and Data Office team access via direct workspace membership. Twelve BU stewards access via a published app scoped to their BU. CFO's office and Chief Compliance Officer access via separate published apps scoped to the enterprise-view surfaces they need. Mobile access is not required — usage happens at desk or in review meetings. |
| **Mobile Required** | No. |
| **Target Go-Live** | 2026-10-05 (a Monday, three months before the annual roadmap-drafting window opens in January 2027). The intervening months (Oct–Dec 2026) run the quarterly review in trial mode; the January 2027 roadmap draft is the first roadmap produced from the dashboard as the primary artifact. |
| **Review Cadence** | Monthly cadence review during the first two quarters post-deployment (with the CDO and chief of staff). Quarterly thereafter, aligned to the governance investment review meeting. Annual review at the roadmap-drafting window each January. |

### 8. Constraints & Assumptions

- **Constraint**: The operational-signal-versus-self-assessment weighting rule (Success Criterion 2) must be agreed and communicated *before* the dashboard produces any ranking that lands in a budget conversation. If the CDO cannot secure agreement, the dashboard ships in dual-view mode (weighted and self-assessment-only side by side) rather than in single-ranking mode. Shipping a single ranking that a steward has not been shown before the budget meeting is not an acceptable fallback.
- **Constraint**: The gap-visibility symmetry criterion (Success Criterion 3) is a bidirectional requirement. The dashboard cannot surface only the gaps that reduce noisy stewards' allocations and hide the gaps that reduce quiet substitutes' allocations. If a UI simplification proposal would violate the symmetry, reject it; the symmetry is the ethical core of the roadmap-bias correction, not a cosmetic detail.
- **Constraint**: Data-classification signals surface as summary counts only. Any drill-through that would expose a specific classified asset's identity is out of scope; the dashboard reports "12 classified assets in this BU without documented lineage" rather than "asset AST-01234 is a classified asset without documented lineage." Classified-asset review happens in the classification tool itself, not in this dashboard.
- **Constraint**: The quarterly review's 90-minute timebox is a hard constraint. Report load time on the *Quarterly Review* view must be under 5 seconds per panel; slow panels compress decisions past the meeting boundary and force the review to reconvene, which invalidates the "sole visual artifact" success criterion.
- **Assumption**: The CDO will continue to sponsor operational-signal-primary ranking through at least the first full annual cycle. If executive turnover changes the sponsorship posture toward self-assessment-primary, the dashboard's primary job (bias correction) is invalidated and the design needs revisiting; the dashboard is not neutral on the sponsorship question.
- **Assumption**: The four operational-signal source systems (catalog, DQ monitoring, IAM, classification tool) remain available and produce comparable-quality signals across the twelve business units. If a source system's coverage becomes uneven across BUs (say, IAM is only fully deployed in eight of the twelve), the dashboard's cross-BU comparisons become unreliable on that dimension and must be flagged with a visible caveat rather than shipped as a clean ranking.
- **Assumption**: The twelve-business-unit portfolio is stable through at least the FY2027 roadmap cycle. Mergers, divestitures, or reorganizations that add or remove business units would trigger a data-model rework, not a maintenance update. The dashboard versions itself against the business-unit master file; a schema change is a scope change.
- **Assumption**: The annual self-assessment survey continues to run in May of each year. If the survey is discontinued or the timing shifts, the dashboard's self-assessment overlay becomes stale; the CDO's office is on the hook for either running the survey on schedule or communicating the deprecation and updating the dashboard's overlay policy.

### 9. Governance Maturity Model (domain-specific extension)

The dashboard scores each business unit against the eight enterprise governance capabilities on a 1–5 maturity scale. The capability list and level definitions below are the current enterprise governance framework as ratified by the CDO's office in 2025-Q4; changes to the framework itself flow through the CDO's governance-framework revision process, not through dashboard maintenance.

**The eight capabilities**:

| Capability | What it measures | Primary operational signal |
| --- | --- | --- |
| **Catalog** | Are the BU's data assets discoverable in the enterprise catalog? | Catalog coverage rate (% of BU assets registered) |
| **Lineage** | Is upstream and downstream lineage documented for the BU's critical assets? | Lineage-documented rate (% of catalog-registered assets with lineage) |
| **Quality** | Are the BU's critical data domains monitored, with SLAs and incident-tracking? | DQ monitoring uptime; DQ incident rate per critical domain |
| **Access** | Are access controls reviewed on schedule, and are review completion rates tracked? | Access-review completion rate (% of reviews closed within SLA) |
| **Retention** | Are the BU's data-retention policies documented and enforced technically? | Retention-policy coverage rate; retention-enforcement automation coverage |
| **Classification** | Are the BU's assets classified per the enterprise classification schema? | Classification coverage rate (% of BU assets with a classification tag) |
| **Stewardship** | Is stewardship in place for the BU, and are stewardship activities tracked? | Steward-assignment coverage; stewardship-activity completion rate |
| **Data Literacy** | Are the BU's data consumers trained to interpret the data they use? | Enrolled-training completion rate per BU |

**The five levels**:

| Level | Name | Definition |
| --- | --- | --- |
| **1** | Initial | Ad-hoc; capability exists only where individual initiative produced it. No enterprise standard adopted. |
| **2** | Managed | Enterprise standard adopted but coverage is spotty; capability applied to a subset of assets or domains with documented gaps. |
| **3** | Defined | Enterprise standard applied consistently across the BU's critical assets and domains. Documented processes for maintaining the capability as new assets or domains are added. |
| **4** | Quantitatively Managed | Capability quality is measured with metrics; SLAs are in place; deviations trigger documented remediation. |
| **5** | Optimizing | Capability metrics are used to drive continuous improvement; the BU contributes back to the enterprise standard based on operational learning. |

The dashboard's operational-signal-to-level mapping (e.g., "catalog coverage of 78% + lineage rate of 62% + documented process = Level 3") is documented in the *Audit Trail* report's methodology appendix and is version-controlled alongside this BRD. Changes to the mapping are treated as changes to the dashboard's semantic model, subject to CDO sign-off and communication to all twelve BU stewards before taking effect.

### Approval

| Role | Name | Date | Signature |
| --- | --- | --- | --- |
| Stakeholder (Chief Data Officer) | | 2026-06-24 | |
| Data Owner (Enterprise Data Office) | | 2026-06-24 | |
| Chief of Staff (day-to-day operator) | | 2026-06-24 | |
| Chief Financial Officer's representative (audit-trail scope) | | 2026-06-24 | |
| Analyst (author) | | 2026-06-24 | |

Business-unit steward sign-off on the operational-signal-versus-self-assessment weighting (Success Criterion 2) is logged as a separate appendix; sign-off date for the weighting round is 2026-09-14.

---

**Pattern notes.** This BRD's Section 5 explicitly names a stakeholder base with legitimate, structural disagreement built into the dashboard's very reason for existing. Compare against the AIRS exemplar, where the stakeholder base agrees on the science and disagrees only on interpretation; or the CloudRevenue exemplar, where the stakeholder base agrees on the objective and disagrees only on definitions. EnterpriseGovernance is the case where the stakeholders' *interests* diverge — the noisy stewards benefit from the current bias, the quiet substitutes are hurt by it, and the CDO has to run the dashboard against both audiences at once. Section 5 handles that by giving both groups identical dashboard access while making the bias itself visible per Success Criterion 3. This is the domain where the BRD's *disagreement check* validity test (Chapter 2) does the most work — a BRD that produced no disagreement from the twelve stewards would be either miraculously well-crafted or dangerously vague, and dangerously vague is the more likely explanation.
