How UK CIOs Should Fix Data Governance Before Scaling AI
UK CIOs should fix data governance before scaling AI: ungoverned, poor-quality data is the most common reason enterprise AI stalls after pilot. Under UK GDPR and ICO guidance on AI and data protection, ownership, lineage and quality controls are a compliance requirement, not a technical nicety.
Most boards have approved an AI strategy. Far fewer have approved the data foundation underneath it. Organisations move fast on model selection and use cases, then discover mid-rollout that the underlying data is duplicated, undocumented, inconsistently owned, or simply not trusted by the business units meant to act on its outputs. The fix is not a new AI policy layered on top — it is the foundational work of data governance, done properly, before the next scaling decision.
Why does data governance decide whether AI projects survive contact with production?
According to Gartner, through 2026 a majority of organisations will abandon or stall AI projects that were not built on AI-ready data — a failure traced to the same causes repeatedly: unclear data ownership, inconsistent definitions across systems, and no audit trail for how a figure was derived. Model quality gets the attention in board papers; data quality determines whether the output can be trusted at all.
According to McKinsey’s global AI survey work, data-related challenges — availability, quality and integration — remain among the most cited barriers to capturing value from AI at scale, ahead of talent shortages and cost. For CIOs, that reframes the sequencing question: the constraint on AI value isn’t which model you choose, it’s whether the data feeding it is governed well enough to be relied on.
Executive Action:
- Commission an AI-readiness data audit before approving the next AI use case, not after.
- Require every AI business case to name its data owner and data quality score.
- Track data-related AI project delays as a standing board metric, not a project footnote.
What does good data governance for AI actually look like?
Good data governance for AI rests on four disciplines the DAMA-DMBOK framework has long formalised, now applied to AI use cases: ownership (a named accountable owner per data domain), quality (measured against defined standards, not assumed), lineage (a traceable path from source to AI output), and access control (mapped to UK GDPR’s purpose-limitation principle). Few organisations run all four consistently. Most run one or two, informally, and call it governance.
The practical test is simple: can your organisation explain, on request, which data fed a given AI output, who owns it, and how quality was verified? If the honest answer is “not reliably,” the governance gap is the actual blocker to further scaling.
Executive Action:
- Map critical data domains against the four DAMA disciplines and score each red/amber/green.
- Mandate lineage documentation for any data feeding a customer-facing or regulated AI use case.
- Align access controls to UK GDPR purpose limitation before, not after, an ICO inquiry.
Who should own data governance — the CIO, a CDO, or the business?
Ownership ambiguity is itself a governance failure. Where a Chief Data Officer role exists, governance should sit with them, with the CIO owning the platforms and controls that enforce it. Where no CDO exists — still the majority of mid-market UK organisations — the CIO inherits the accountability by default, formally assigned or not. Business unit leaders must own data quality within their domain; IT cannot be accountable for data it did not create. This shared model needs writing down and board ratification.
Our earlier briefing on technical debt and AI readiness covered the platform side of this problem; data governance is its counterpart on the information side. A CIO who has resolved technical debt but not data ownership has only solved the easier half.
Executive Action:
- Formally assign data governance accountability — CDO, CIO or shared model — and ratify it at board level.
- Give business unit leaders explicit data quality KPIs tied to their domain.
How should UK CIOs sequence this work in 2026?
Sequencing matters more than ambition. Start with data domains feeding your highest-risk or highest-value AI use cases — not a full enterprise-wide catalogue, which stalls momentum. Pair each domain audit with a lightweight governance charter: owner, quality standard, lineage requirement, access rule. Build incrementally, use case by use case, and the enterprise picture assembles within a year rather than waiting on a two-year data programme competing for the same budget as the AI work it should enable.
Where UK-specific standards apply — ISO 8000 for data quality, or FCA and PRA expectations for regulated financial services firms — build to those from the outset rather than retrofitting compliance later. It is cheaper to govern data correctly the first time than to remediate it under regulatory pressure.
Executive Action:
- Sequence governance by AI use-case risk and value, not by data domain size.
- Build to ISO 8000 and relevant sector standards from the start of each domain charter.
- Review progress quarterly against a red/amber/green domain scorecard, not a single annual audit.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Use INFORMD’s AI governance test to benchmark data readiness, or start from our technology strategy review template when writing your charter. Questions on sequencing this — get in touch.
Frequently Asked Questions
Data governance for AI means a named owner, a measured quality standard, traceable lineage from source to output, and defined access rules for every data domain feeding an AI system. Without these, AI outputs cannot be reliably trusted or audited.
AI projects typically stall in production, not pilot, because ungoverned data produces inconsistent outputs at scale. Gartner and McKinsey both cite data readiness — not model choice — as the leading barrier to scaling AI beyond initial pilots.
Where a Chief Data Officer exists, they should own data governance, with the CIO owning enforcing platforms and controls. Where no CDO exists, the CIO inherits this accountability by default and should have it formally ratified at board level.
UK GDPR’s purpose-limitation and accountability principles require documenting what data is used for AI, why, and under what access controls. The ICO expects this before deployment, making governance a compliance requirement as well as a performance one.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
