Skip to main content
Data governance tool

Build a controlled critical data element register

Document the definition, accountability, lineage, quality expectations, controls, and business impact of data elements that matter most to your organisation.

No external API is used. The submitted form is processed on the current server, while CSV and JSON exports are generated locally in the browser.

How it works

Capture the record, calculate a transparent criticality score, and export a structured register entry for review.

1

Describe the element

Record the business definition, ownership, process context, systems, consumers, classification, and lineage.

2

Assess criticality

Select impact factors and severity. The tool applies a fixed formula with visible weights and thresholds.

3

Strengthen governance

Review completeness, practical actions, thresholds, and controls, then export the record to CSV or JSON.

Critical data element register

Required fields are marked with an asterisk. Enter one controlled record at a time; imported CSV rows remain in your browser only.

Create or assess a register entry

Complete the fields below. Progress updates as you type.

1. Identity and accountability
Example: Customer legal name or Invoice due date.
State what the element means, the business concept represented, and any relevant inclusions or exclusions.
Use a role where possible, such as Head of Finance Operations.
Describe where the element is created, changed, approved, or used.
2. Systems, lineage, and use
Separate system names with commas or new lines. Duplicate names are rejected.
Name the authoritative system, table, application, or approved source.
Describe origin, major transformations, interfaces, storage points, and downstream destinations.
List reports, teams, processes, applications, models, regulators, or external recipients.
3. Criticality and business impact
Explain the consequence of incorrect, incomplete, unavailable, late, or unauthorised data.
Impact categories
Choose the highest credible impact, not the average impact.
4. Quality thresholds, controls, and lifecycle
Include validity, uniqueness, referential integrity, allowable values, reconciliation, or timeliness rules.
Describe preventive, detective, corrective, access, change, reconciliation, approval, and monitoring controls.
Optional. Record material defects, exceptions, workarounds, unresolved ownership, or evidence gaps.

Privacy note: no external transmission is performed by this page. Server-side submission uses the site’s own PHP runtime; browser exports and CSV import remain local unless the site separately implements secure storage.

Methodology, limitations, and responsible use

The tool is designed to support consistent governance conversations and a repeatable starting point for register management.

Methodology

Criticality combines selected impact categories, maximum credible severity, classification sensitivity, system dependencies, and consumer dependencies. The weights are fixed and shown in the result.

Limitations

The score does not test whether controls operate effectively, whether lineage is technically complete, or whether regulatory obligations have been correctly interpreted. It relies on user-supplied information.

How to use the result

Use the result to prioritise approval, monitoring, evidence, remediation, lineage validation, threshold review, and periodic reassessment. Keep the record aligned with the organisation’s approved governance framework.

Frequently asked questions

Practical guidance for establishing and maintaining a critical data element register.

What is a critical data element?

A critical data element is a data item whose accuracy, completeness, availability, timeliness, confidentiality, or integrity materially affects important business outcomes, obligations, decisions, customers, operations, or reporting.

How should we decide whether an element is critical?

Assess credible impact if the element is wrong, missing, late, unavailable, duplicated, or accessed inappropriately. Consider legal, financial, customer, operational, safety, security, strategic, and reputational consequences.

Should the owner be a person or a role?

A stable accountable role is usually preferable because responsibilities survive personnel changes. A named person may be recorded operationally, but the governance record should clearly identify the accountable role.

What is the difference between an owner and a steward?

The owner is accountable for decisions, risk acceptance, and approval. The steward typically coordinates definitions, rules, quality monitoring, issue management, metadata, and day-to-day governance activity.

How detailed should lineage be?

Lineage should be detailed enough to identify origin, material transformations, system interfaces, storage points, reconciliation controls, and major downstream uses. High-criticality elements generally need more technical evidence.

How are quality thresholds selected?

Thresholds should reflect business impact, consumer requirements, regulatory or contractual expectations, process capability, and the cost of failure. They should be measurable and linked to escalation and remediation.

What does the criticality score represent?

The score is a prioritisation aid from 0 to 100. It consistently combines selected impact factors, maximum severity, classification, system dependencies, and consumer dependencies using the published formula.

Does a high score mean the element is poorly controlled?

No. A high score indicates that the element may warrant stronger governance attention because of its impact and dependencies. Control effectiveness must be assessed separately using evidence.

How often should records be reviewed?

Review frequency should be proportionate to criticality and change. Quarterly review is a practical default, with additional event-driven review after system changes, incidents, regulatory changes, or material process redesign.

Can this tool replace legal or audit advice?

No. It is a structured governance aid and does not provide legal advice, regulatory interpretation, certification, audit assurance, or a technical control test.

Where is imported or exported data processed?

CSV import, duplicate detection, filtering, and CSV or JSON download are performed locally in the browser. Form submission is processed by the current site server and is not sent to an external API.

What CSV columns can be imported?

The importer accepts headers matching the form field names, including element_name, business_definition, domain, owner, steward, systems, source_of_truth, classification, impact_level, and related fields. The first valid row populates the form; duplicate element-name and domain combinations are reported.