Thinklytics

Governance · 8 min read · May 2026

Data governance consulting: what we actually do in the first 90 days

By Thinklytics Partners, Governance Practice

Past the policy-document theater and into the work that actually changes how data flows through your company. The 90-day plan, the deliverables, and the political conversations that determine whether governance sticks.

What does the first 90 days of a data governance engagement look like?

Week 1 to 3: certify the top 12 to 18 metrics with named owners. Week 4 to 8: build the metric layer in your existing tool (dbt, Looker, Power BI semantic model, Tableau). Week 9 to 12: turn off the legacy duplicate definitions and run an executive readout. Most clients see the metric arguments end in week 6.

Most data governance projects ship a policy document and a slide deck and call it done. Six months later the company is still arguing about what "active customer" means and the AI initiative is stalled because finance and sales report different revenue numbers.

This is what we do in the first 90 days that's different.

What this is

A specific 90-day plan for data governance. What gets shipped each week, who has to be in the room, and what changes about how decisions get made when the engagement ends.

What this is not

A maturity-model assessment. We don't score your governance on a 1-to-5 scale and tell you to move to 3.5. That's busywork. What changes outcomes is the work we describe below, not the rating.

The 90-day shape

Days 1 to 30: Setting the rules of the game

The first month is about establishing decision rights, not writing policy. Policy without decision rights is theater.

Week 1, Stakeholder map. We identify who actually makes data decisions today, which is rarely the same as who's supposed to. The CFO might be the de-facto authority on revenue definitions even if there's a "Data Council" on paper. Map the real authority before changing it.

Week 2, Critical data element inventory. We list the 30 to 50 metrics and master-data elements that appear in executive reporting, regulatory filings, and customer-facing surfaces. These are the elements that have to be governed first. Everything else can wait.

Week 3, Definition reconciliation, round one. For each critical data element, we pull every existing definition from documentation, source code comments, lineage tools, and stakeholder interviews. The number of distinct definitions per metric is usually 3 to 8. We document the variants without trying to resolve them yet.

Week 4, Decision-rights workshop. We bring the stakeholder map and the definition inventory to a 4-hour facilitated session with the executive team. The output is one decision: who has the final say on each critical data element. This is the political work. Without it, the rest of the engagement doesn't stick.

Days 31 to 60: Building the operational layer

Now we have decision rights. The second month is about plumbing the system that enforces them.

Week 5, Data dictionary v1. Every critical data element gets a single, signed-off definition. The owner from week 4 signs. The definition includes: what it means in plain English, how it's calculated, source-of-truth system, refresh cadence, known edge cases, and last review date. We use a lightweight tool (often the existing wiki or Confluence; we don't push you onto a new platform unless you already have one).

Week 6, Lineage capture for the critical elements. For each metric in the dictionary, we trace the lineage backwards through your warehouse. Source table → transformation → mart → BI tool. The lineage gets attached to the dictionary entry. This is when you discover that "monthly recurring revenue" is computed three different ways in three different dashboards.

Week 7, Quality SLAs. Each critical data element gets a quality SLA: completeness, freshness, accuracy thresholds. The SLA is the trigger for incident response. If MRR completeness drops below 99%, an alert fires and a named owner is paged. SLAs without paging are just hopes.

Week 8, Governance steering committee setup. The executives who signed the decision rights become the governance steering committee. They meet monthly to review changes to critical-element definitions, exception requests, and SLA breaches. We design the cadence and the escalation paths.

Days 61 to 90: Making it stick

The first two months are setup. The third month is the test of whether anything actually changed.

Week 9, Change-management ratchet. Every time someone wants to change the definition of a critical element, the change goes through the steering committee. We design the request form, the review cadence, and the publication path. Most organizations skip this step and the dictionary rots within 6 months.

Week 10, Incident response dry-run. We deliberately trigger an SLA breach (in a controlled way) and watch how the response runs. Who got paged? Did they know what to do? Did the steering committee get the post-mortem? This is the test of whether the operational layer works.

Week 11, Onboarding asset for new hires. Every new analyst, engineer, and PM has to learn how data is governed. We write the onboarding doc that gets them productive in week one without absorbing tribal knowledge through osmosis.

Week 12, Handover and 6-month plan. We document everything, transfer ownership of the dictionary and steering committee facilitation to your team, and write a 6-month plan for what to govern next (usually a wider definition coverage and the customer-data model).

What's NOT in the 90-day plan (on purpose)

Things we deliberately don't do in the first 90 days, even though they're often in vendor proposals:

  • Master data management platform selection. Way too early. You don't know enough about what you're governing yet to pick a platform.
  • Full enterprise data dictionary. Boiling the ocean. The 30 to 50 critical elements move the needle.
  • Tool migration. We don't push you off Excel or Confluence onto an "MDM platform" in the first 90 days. The platform decision is downstream of the governance discipline.
  • Quality monitoring tool deployment. SLAs and pages first. Tools second. Tools without SLAs just produce dashboards nobody looks at.

The four conversations that determine success

Outside the deliverables, four conversations have to happen for governance to stick. We run all four in the first 30 days.

1. The "who owns" conversation. Most companies have ambiguous ownership for the most important data elements. The CFO, the COO, and the Chief Data Officer all think they own revenue. Pick one. We've seen this conversation derail entire engagements when leadership isn't ready to have it.

2. The "no exceptions" conversation. Once a definition is signed off, the same number has to appear everywhere. The first time finance and sales report different revenue numbers in the same board meeting, the steering committee has to investigate within 48 hours. No "we're using different definitions for different audiences." That's the failure mode.

3. The "we're going to write it down" conversation. Engineers and analysts have tribal knowledge of how things work. The dictionary captures it. Some of them will resist because their value is the tribal knowledge. The conversation is about making the company resilient to their absence, not about replacing them.

4. The "AI is downstream of this" conversation. If the company has AI initiatives running, governance has to be the floor under them. AI projects on top of ungoverned data fail. We make this connection explicit in the executive readout because it changes how seriously the steering committee takes the work.

What the engagement costs

The 90-day plan runs $90K to $180K depending on company size and the number of critical data elements in scope. Larger enterprises with more business units and more regulated environments come in higher because the stakeholder map is bigger and the steering committee has more representation.

After the 90 days, governance maintenance is typically 10 to 20 hours per month of internal team time. We don't sell ongoing governance as a service. The point is to give you the operating system, not be the operating system.

Common questions

Do we need a Chief Data Officer to run this?

No. We've run the 90-day plan with a CFO as governance sponsor, with a CTO as sponsor, and with a VP of Data as sponsor. The role matters less than the authority. The sponsor needs to be senior enough to settle definition disputes when they come up.

What if the steering committee doesn't have authority over data?

Then governance won't work and the engagement is the wrong fit. We'll tell you on the discovery call. The hardest version of this work is when nobody on the executive team actually owns data, in that case the right first move is to clarify ownership at the CEO level before starting the 90-day plan.

Can you run this remotely?

Mostly yes. The decision-rights workshop in week 4 works much better in person; we strongly recommend that one is on-site. The rest of the engagement runs fine remote.

What's the relationship between governance and AI readiness?

Governance is upstream of AI readiness. The AI readiness assessment finds where governance gaps will block AI projects. The governance engagement closes those gaps. Run them in that order, assessment first, governance second, AI third.

How does this differ from compliance work?

Compliance asks "are we following the rules?" Governance asks "what should the rules be, and how do we enforce them?" The two overlap (governance feeds compliance), but compliance teams are usually understaffed for the upstream definitional work. Governance is a separate function with separate skills.

What happens at month 6 or 12 if we don't extend?

The system runs on the steering committee + dictionary + SLA infrastructure we set up. About 40% of clients re-engage us at month 6 to 12 to expand scope (more elements, more business units). The other 60% run it themselves. Both are valid outcomes. The point is to give you the system.


If you've got the symptoms, finance and sales reporting different numbers, AI projects stalling because definitions don't match across systems, a Data Council that meets quarterly and changes nothing, that's the conversation we have on every Data Governance Consulting discovery. We'll map your stakeholders, scope the critical elements, and tell you whether the 90-day plan is the right shape for your environment or whether you need to settle ownership at the CEO level first.

The clearest example of this work in production is Kaiser Permanente's metric governance engagement, same 90-day shape, scaled across a regulated healthcare environment. The executive readout from that engagement is one of the most-cited references we have when explaining to new buyers why decision rights come before policy.

Frequently asked questions

What does the first 90 days of a data governance engagement look like?

Week 1 to 3: certify the top 12 to 18 metrics with named owners. Week 4 to 8: build the metric layer in your existing tool (dbt, Looker, Power BI semantic model, Tableau). Week 9 to 12: turn off the legacy duplicate definitions and run an executive readout. Most clients see the metric arguments end in week 6.

Why focus on metric definitions before policies in the first 90 days?

Policies without certified metrics are paper. The reason governance projects stall is they start by writing a policy nobody can apply. Once a metric has a definition and an owner, the policies write themselves because the source of truth already exists to point at.

Who needs to be involved in the first 90 days of data governance?

One executive sponsor (typically CFO or COO), one metric owner per top metric (finance lead for revenue, RevOps for pipeline, etc.), and one technical lead. Six people total in most engagements. More than that and the project becomes a committee.

How is this different from a 12-month data governance roadmap?

A 12-month roadmap covers data classification, access policies, catalog, lineage, retention, privacy. The first 90 days only covers metric certification because that is the failure mode killing 80 percent of governance projects. The rest of the roadmap works once metrics are settled.

What is the typical fee for a 90-day data governance engagement?

$180,000 to $320,000 depending on the number of metrics in scope and the source-system mess. Senior-led delivery, fixed scope, fixed fee. Read our Kaiser Permanente metric governance case study for what the deliverable looks like on a Fortune 100 health system.

What is the most common pushback in the first 90 days?

Different teams claim ownership of the same metric. The resolution is always the same: name the executive sponsor and have them pick. Governance fails when there is no escalation path. With one, the metric arguments resolve in days, not quarters.

What happens after the first 90 days?

Three options. One: hand the certified metric layer to the internal team and exit. Two: extend into a 6-month build of the governance plane (policies, catalog, lineage on top of the metric layer). Three: convert to an ongoing managed model where Thinklytics co-runs governance. We don't require option two or three.

Does this work for international organizations?

Yes, with one nuance. Multi-region governance has to handle data residency rules per region, which adds 2 to 4 weeks to the foundation work. The metric certification process is otherwise identical; the governance plane gets a region-aware policy layer on top.

Frequently asked questions

What does the first 90 days of a data governance engagement look like?

Week 1 to 3: certify the top 12 to 18 metrics with named owners. Week 4 to 8: build the metric layer in your existing tool (dbt, Looker, Power BI semantic model, Tableau). Week 9 to 12: turn off the legacy duplicate definitions and run an executive readout. Most clients see the metric arguments end in week 6.

Why focus on metric definitions before policies in the first 90 days?

Policies without certified metrics are paper. The reason governance projects stall is they start by writing a policy nobody can apply. Once a metric has a definition and an owner, the policies write themselves because the source of truth already exists to point at.

Who needs to be involved in the first 90 days of data governance?

One executive sponsor (typically CFO or COO), one metric owner per top metric (finance lead for revenue, RevOps for pipeline, etc.), and one technical lead. Six people total in most engagements. More than that and the project becomes a committee.

How is this different from a 12-month data governance roadmap?

A 12-month roadmap covers data classification, access policies, catalog, lineage, retention, privacy. The first 90 days only covers metric certification because that is the failure mode killing 80 percent of governance projects. The rest of the roadmap works once metrics are settled.

What is the typical fee for a 90-day data governance engagement?

$180,000 to $320,000 depending on the number of metrics in scope and the source-system mess. Senior-led delivery, fixed scope, fixed fee. Read our Kaiser Permanente metric governance case study for what the deliverable looks like on a Fortune 100 health system.

What is the most common pushback in the first 90 days?

Different teams claim ownership of the same metric. The resolution is always the same: name the executive sponsor and have them pick. Governance fails when there is no escalation path. With one, the metric arguments resolve in days, not quarters.

What happens after the first 90 days?

Three options. One: hand the certified metric layer to the internal team and exit. Two: extend into a 6-month build of the governance plane (policies, catalog, lineage on top of the metric layer). Three: convert to an ongoing managed model where Thinklytics co-runs governance. We don't require option two or three.

Does this work for international organizations?

Yes, with one nuance. Multi-region governance has to handle data residency rules per region, which adds 2 to 4 weeks to the foundation work. The metric certification process is otherwise identical; the governance plane gets a region-aware policy layer on top.

Related reading

Thinklytics

Data and AI consulting for Fortune 500s, health systems, and growth-stage companies. Clean data, governed metrics, analytics ready for AI.

Austin, TX · United States

[email protected]