| Current-state assessment | Capabilities, gaps, risks, dependencies and priorities | Assessment report and findings register | Assess | Policies, evidence, interviews and system information | Data governance lead |
| Customer-data domain model | Scope, subdomains, critical elements and authoritative-source decisions | Domain map and data register | Design | Product, process and architecture knowledge | Business data owner |
| Accountability framework | Owner, steward, custodian, control and forum responsibilities | RACI and operating model | Design | Role nominations and executive decisions | Executive sponsor |
| Quality control catalogue | Rules, thresholds, monitoring, severity and remediation workflow | Control catalogue and rule specification | Design / implement | Business expectations and technical profiling | Data owner and technology |
| Metadata and lineage requirements | Glossary, source-to-use traceability, evidence and platform requirements | Standards and implementation backlog | Design / implement | System mappings and platform access | Metadata owner |
| Privacy and access control map | Purpose, consent, retention, sharing, access and review requirements | Control matrix | Design | Legal, privacy and security interpretations | Privacy and security functions |
| Governance metrics pack | KPIs, thresholds, reporting cadence and escalation | Dashboard specification and reporting pack | Operate | Data sources and agreed targets | Governance office |
| Training and transition pack | Role guidance, procedures, workshops and operating calendar | Training materials and runbook | Transition | Named participants and operational owners | Governance office |