Independent reporting on data, AI and digital regulation in Luxembourg

Data governance · Explainer

How to assess data governance maturity: models, scoring and a light-weight method for Luxembourg

A data governance maturity assessment scores capabilities on a 0–5 scale against evidence. Here is what to measure, whom to interview and how to build a roadmap.

Key takeaways

  • Most data management maturity models use a five- or six-step scale; the DAMA-DMBOK2 assessment runs from level 0 (absence of capability) to level 5 (optimised).
  • DAMA-DMBOK2 groups data management into 11 knowledge areas, with data governance at the centre of the 'DAMA wheel'.
  • Scores should be based on four criteria per area: activities, tools, standards, and people and resources.
  • A light-weight assessment combines a short survey, structured interviews and a review of documents such as policies, role descriptions and the GDPR record of processing activities.
  • The result is only useful when turned into target levels per area, a prioritised roadmap and a scheduled re-assessment.

A data governance maturity assessment scores how consistently an organisation manages its data, area by area, on a scale that typically runs from 0 (no capability) to 5 (optimised), and it backs each score with evidence. For a Luxembourg organisation, a light-weight version needs three ingredients: a recognised framework such as DAMA-DMBOK2, a small set of interviews and documents, and a roadmap that turns the scores into decisions.

What maturity models measure

Maturity models describe how predictable and repeatable a practice is, not how much technology an organisation owns. The DAMA-DMBOK2 assessment uses six levels, as presented at DAMA Sydney in September 2019:

Level DAMA-DMBOK2 name What it looks like
0 Absence of capability The practice does not exist
1 Initial / ad hoc Success depends on the competence of individuals
2 Repeatable Minimum process discipline is in place
3 Defined Standards are set and used
4 Managed Processes are quantified and controlled
5 Optimised Process improvement goals are quantified

Other frameworks follow similar logic. The CMMI Data Management Maturity (DMM) model uses five levels (performed, managed, defined, measured, optimising) across six categories, among them data management strategy, data governance and data quality. The EDM Council’s DCAM, popular in financial services, is organised in eight components, from data strategy and business case to data operations and the control environment, as summarised in a CDMP study guide.

The dimensions to score

DAMA-DMBOK2, published in 2017 and revised in 2024, divides data management into 11 knowledge areas, with data governance at the centre of the “DAMA wheel”:

  • Data governance
  • Data architecture
  • Data modelling and design
  • Data storage and operations
  • Data security
  • Data integration and interoperability
  • Documents and content
  • Reference and master data
  • Data warehousing and business intelligence
  • Metadata
  • Data quality

Within each area, DAMA-DMBOK2 proposes four assessment criteria: activities (is the process performed?), tools (is it supported by technology?), standards (is it documented?), and people and resources (are roles, skills and budget assigned?). Scoring each criterion separately avoids a common illusion: a data catalogue licence is a tool, not proof that metadata is managed.

Running a light-weight assessment

A full assessment of all 11 areas is rarely needed for a first pass. A pragmatic scope is data governance plus the three to five areas that matter most to the business, for example reference and master data, data quality, metadata and data security.

1. Plan. Agree the scope, the scale and the sponsor. DAMA-DMBOK2 describes five activities: plan the assessment, perform it, interpret the results, create a targeted improvement programme and re-assess.

2. Survey. A short questionnaire captures how staff perceive current practice. In Luxembourg, the administrative languages are Luxembourgish, French and German under the law of 24 February 1984, and English is common in business, so the questionnaire should be available in the languages respondents actually work in. Organisations that do not want to design their own questionnaire can start from a structured maturity assessment survey and adapt it to their scope.

3. Interview. Survey results are perceptions. Structured interviews test them. Typical interviewees are:

  • the executive sponsor or management committee member responsible for data;
  • the data protection officer, where one has been appointed under the GDPR;
  • business data owners for the key domains (customer, product, finance);
  • IT, architecture and data platform leads;
  • compliance, risk and internal audit.

4. Ask for evidence. Each score should point to something that can be inspected. Useful evidence includes data policies and standards, a list of named data owners and stewards, governance committee minutes, a business glossary or data catalogue, data quality rules and reports, issue logs, and the record of processing activities required by Article 30 GDPR. Where no evidence exists, the score should not be higher than level 1.

5. Score and calibrate. Score each area on the four criteria, then hold a short calibration workshop where interviewees can challenge the scores. Disagreement between business and IT is itself a finding.

Turning the result into a roadmap

A score is a baseline, not a plan. Three steps make it actionable:

  1. Set a target level per area. Not every area needs level 4. A target follows business value and regulatory exposure: an organisation that must answer data access requests or regulatory reporting will need defined processes for the data concerned.
  2. Prioritise the gaps. A value-versus-feasibility matrix separates quick wins (high value, high feasibility) from strategic initiatives (high value, low feasibility) and tasks that can wait.
  3. Schedule the re-assessment. Re-assessing with the same scale and method shows whether the programme moves the scores. Changing the method between rounds makes the comparison meaningless.

The roadmap should name owners and dates for each initiative, and it should start with governance foundations (roles, decision rights, policies), because most other areas depend on them.

Common pitfalls

  • Averaging everything into one number. As Data Crossroads notes, neither DAMA-DMBOK2 nor DCAM clearly defines how to aggregate scores into one overall level. A single average hides the weak area that causes the incidents.
  • Self-assessment without evidence. A survey captures perception; only interviews and document review show whether a practice is actually performed.
  • Treating maturity as the goal. Higher levels cost money; the right level is the one the business and its regulators need.
  • Assessing everything at once. A broad first pass with thin evidence is less useful than a focused one with solid evidence.
  • No follow-up. Without a re-assessment date, the exercise becomes a one-off report.

What to do now

  1. Choose a framework and scale (for example the DAMA knowledge areas and the 0–5 scale) and document the choice.
  2. Limit the first assessment to data governance and three to five priority areas.
  3. Name an executive sponsor and the interviewees, including the DPO where one exists.
  4. Prepare an evidence checklist before the interviews start.
  5. Agree target levels and a re-assessment date in the same meeting where the results are presented.

Questions & answers

What is a data governance maturity assessment?

It is a structured evaluation of how consistently an organisation manages its data, scored per capability on a maturity scale (for example 0 to 5) and backed by evidence rather than opinion.

Which maturity model should a Luxembourg organisation use?

Common references are DAMA-DMBOK2, the CMMI Data Management Maturity (DMM) model and the EDM Council's DCAM. A smaller organisation can borrow the DAMA knowledge areas and a 0–5 scale without adopting a full framework.

How long does a light-weight assessment take?

There is no standard duration. The effort depends on the number of knowledge areas in scope, the number of interviews and how quickly documentary evidence can be collected.

Should the target be level 5 everywhere?

No. Target levels should follow business and regulatory need; many areas only need to be repeatable or defined.

Sources

  1. DAMA-DMBOK: Data Management Body of Knowledge · DAMA International
  2. Regulation (EU) 2016/679 (General Data Protection Regulation) · EUR-Lex
  3. Loi du 24 février 1984 sur le régime des langues · Legilux
  4. Data Management Maturity Assessment (DMMA), DAMA Sydney, September 2019 · Firas Hamdan / SlideShare
  5. What is the Data Management Body of Knowledge (DMBOK)? · DATAVERSITY
  6. DAMA-DMBOK2 vs DCAM 2.2: maturity assessment · Data Crossroads
  7. Maturity assessment frameworks (CDMP study guide) · Open Exam Prep

Written and fact-checked against primary sources.