A data governance maturity model places an organisation on a five-level scale from ad-hoc to optimised, and its only real purpose is to tell you which single thing to fix next. Most organisations that commission an assessment sit at level 1 or 2: documented intent, no operating cadence, and no named owner for any given table.
That gap between the policy document and the operating reality is the subject of this article. A maturity model is worth reading only if it changes what you do on Monday.
What is a maturity model actually for?
Maturity models come from process engineering — the five-stage shape originates in CMMI and was carried into data management by DAMA International's DMBOK and by the EDM Council's DCAM framework. The stages are a vocabulary, not a scoreboard.
The failure mode is using the model as a report card. An executive hears "we are at 2.3" and asks how to get to 4, which is the wrong question and produces a programme designed to move a number rather than to fix anything.
The useful use is diagnostic. Maturity is not one score — it is a profile across capabilities, and organisations are routinely level 4 in one dimension and level 1 in another. A bank with an excellent regulatory reporting process and no idea which of its four thousand tables contain personal data is exactly that shape. The profile tells you where the imbalance is, and the imbalance is where the risk lives.
The dimensions worth scoring separately are: ownership and accountability, metadata and discovery, data quality, policy and standards, privacy and access control, and the operating cadence that keeps all of it alive.
What do the five levels look like in practice?
Levels are easiest to recognise by behaviour, not by definition. Here is what each one sounds like inside a real organisation.
Level 1 — Ad hoc
Nobody owns anything. Knowledge about the data lives in people, and the same figure has three values depending on who produced it. Finding a table means asking a specific engineer who has been there seven years, and the risk everyone quietly acknowledges is that this person will leave.
There is no governance function, or there is one on the org chart that convenes when there is an incident.
Recognition test: ask three departments for the number of active customers. If you get three numbers and each one is defensible, you are at level 1.
Level 2 — Aware
A policy document exists. It was written for a regulator or in response to an audit finding, it is accurate, and it is not what happens. Someone has the words "data governance" in their title, usually alongside four other responsibilities.
There may be a catalog, populated once during a project and now drifting. Stewards were nominated in a slide deck and never told what the role involves week to week.
Recognition test: open the governance policy and check the date of the last substantive edit. If it is the date it was approved, you are at level 2. Most organisations are here, and level 2 is more dangerous than level 1 because it looks solved.
Level 3 — Defined
Ownership is real. Every significant data asset has a named steward who knows they are the steward. Definitions live in a business glossary and are used in reports rather than re-derived inside each one. Changes to source systems trigger an impact review, because column-level lineage in a working data catalog makes the downstream effect visible before the change ships.
Governance has a cadence — a working group that meets, decides, and records decisions — and access requests follow a defined path rather than a favour.
This is the level at which governance starts paying for itself, and it is the correct target for most enterprises.
Level 4 — Managed
Governance is measured. There are metrics with owners: share of critical assets carrying a named steward, glossary coverage of the terms used in regulatory reports, mean time to fulfil an access request, count of quality rules currently failing.
Quality is monitored continuously rather than discovered during reconciliation. Policies are enforced by systems rather than by memoranda — a masking rule applies because the column is classified, not because an engineer remembered.
Level 5 — Optimised
Governance is part of how the platform works. Classification and quality checks run in the deployment pipeline, new data products are governed at creation because the path of least resistance is the governed one, and the programme improves itself from its own metrics.
Very few organisations reach level 5 across every dimension, and fewer need to.
How do you assess your own level honestly?
Self-assessments inflate. The reliable technique is to score against evidence rather than intent, and the evidence is behavioural.
Four questions produce a more accurate score than a workshop, and each one leaves an artefact behind:
Pick a number in a board report and trace it. Ask for the definition, the source columns and the transformation. Count how many people you had to ask and how long it took. Under an hour with a written answer is level 3 or above. A week of archaeology is level 1.
Ask who owns a specific table. Not "who owns customer data" — name a table. If the answer is a team rather than a person, or simply "IT", ownership is nominal.
Take a real access request and time it end to end. The duration matters less than whether the path was the same as the last one.
Ask what happens when a source column changes type. If the answer is that downstream reports break and someone investigates afterwards, lineage is not operational regardless of what the catalog contains.
These four take an afternoon and are harder to game than a questionnaire.
Which level should you actually target?
Level 3, deliberately and completely, before anything else.
The argument for stopping there for a while is that levels 1 to 3 remove risk and levels 4 to 5 add efficiency. An organisation that cannot say who owns a table is exposed; an organisation that owns everything but has no quality dashboard is merely working harder than it needs to.
There is also a sequencing reason. Level 4 is measurement, and measuring an operating model that does not exist produces metrics nobody acts on. Governance dashboards built at level 2 are routinely abandoned within two quarters — not because the numbers were wrong, but because nobody holding them had the authority to change anything.
The exception is the dimension your regulator asks about directly. If supervisory reporting requires demonstrable lineage for specific figures, that dimension goes to level 4 on its own schedule regardless of the rest of the profile.
What actually moves an organisation from level 2 to level 3?
This is the only transition most organisations need to plan, and it is an operating-model change rather than a technology one.
Scope down to critical data elements. The instinct is to govern everything, which guarantees failure. Identify the 100 to 200 data elements that appear in regulatory reports, board reporting and customer-facing processes. Govern those completely. The rest can wait, and much of it will never need governing at all.
Give stewardship a definition and a time budget. A steward with no allocated hours is a name on a list. Two to four hours a week, written into objectives, with a defined set of tasks — approve definitions, resolve quality exceptions, review access — is the difference between a role and a title. The mechanics are set out in data stewardship roles and a working RACI.
Make the catalog the path of least resistance. Adoption is not a training problem. If finding a table is faster through the catalog than through a colleague, engineers use the catalog. If it is slower, no mandate will fix it and the catalog becomes another level 2 artefact.
Put a decision cadence in place. A monthly forum with the authority to settle a contested definition, minuted. Most governance programmes fail not because decisions are wrong but because there is no venue in which a decision becomes final.
Instrument one visible win in the first quarter. A reconciliation that used to take three days and now takes an afternoon buys the political capital for the rest of the programme. The obstacles that tend to appear at this point are catalogued in common data governance challenges.
Where does tooling fit?
Tooling does not create maturity, and buying a catalog at level 1 produces an empty catalog. But past level 2 the operating model cannot be sustained manually — nobody maintains lineage for four thousand tables in a spreadsheet.
The practical sequence is to establish ownership and critical data elements first, then deploy a catalog to carry them. OvalEdge fits this pattern because its crawlers build the technical layer — schemas, column-level lineage, usage statistics — automatically, so stewards spend their allocated hours on business meaning rather than on data entry. The comparison against the alternatives is in OvalEdge vs Collibra vs Alation.
Where tooling genuinely accelerates maturity is measurement. Level 4 requires coverage metrics that are expensive to compute by hand and nearly free once the metadata sits in one place. Analyst coverage of the category has consolidated around exactly this capability set, with governance platforms now evaluated on active metadata and automation rather than on documentation features.
What does this look like in a supervised institution here?
The profile in Azerbaijani banks and state institutions is consistently uneven, and in a specific way.
Regulatory reporting processes are mature — often level 3 or 4 — because supervision forced them there. CBAR's Regulation on Information Security Management in Banks, in force since April 2022 and built on the ISO/IEC 27000 series, has the same effect on classification and access control: the controls exist because they are examined.
The same institution is frequently at level 1 for anything outside that perimeter — departmental databases nobody catalogued, an analytics estate with no ownership, and increasingly, data being fed into AI pilots without a classification step.
That last one matters more than it used to. When a customer table becomes retrieval context for an assistant, its governance status becomes an AI governance question, and the ungoverned side of the estate is exactly where those projects source their data. What an auditor will then ask for is described in what the ISO/IEC 42001 audit actually requires.
The trilingual dimension adds a real complication: definitions maintained in Azerbaijani, English and Russian drift apart, and a glossary that is level 3 in one language is level 1 in the others. That problem is specific enough to have its own treatment of AZ/EN/RU metadata.
The practical consequence for the assessment: score the AI-adjacent estate separately. It is usually the lowest number on the page and the fastest-growing.
Key points
- Maturity is a profile across capabilities, not a single score. Score ownership, metadata, quality, policy, access and cadence separately.
- Level 2 — a correct policy that describes nothing that happens — is where most organisations sit, and is more dangerous than level 1 because it looks resolved.
- Assess against behaviour: trace a board number, name the owner of a specific table, time an access request, ask what happens when a column changes type.
- Target level 3 completely before pursuing level 4. Measurement without an operating model produces abandoned dashboards.
- The level 2 to 3 transition is scope reduction, funded stewardship, a decision cadence and one visible win — not a tool purchase.
- Score the AI-adjacent estate separately. It is where governance is weakest and demand is growing fastest.
If you want an outside read on the profile rather than a self-assessment, Yukon Labs runs a structured data and AI readiness assessment and implements OvalEdge where the operating model needs a catalog underneath it. For the regional context, start with data governance in Azerbaijan.