Writing

The Governance Crisis: The Turning Point

The absence of those four pages had cost the company its reputation and would ultimately cost it $247 million in fines, settlements, and remediation.

The Governance Crisis, part 4 of 5

The Seven Pillars of Data Management, a novel in seven acts.

Chapter I, The Governance Crisis. Pillar I: Data Governance. Part 4 of 5.

The Night

After the board meeting, Nadia drove home through streets slick with November rain. The city felt foreign to her, as though the crisis had rearranged her perception of the physical world. The towers of Bay Street, which she had always found beautiful in their glass-and-steel ambition, now seemed to her like monuments to a kind of institutional arrogance, the belief that growth and profit and market share could substitute for the harder, quieter work of getting the foundations right.

She poured a glass of red wine she did not drink. She sat at her kitchen counter with a legal pad, she still used legal pads, a habit from her early days as an actuary, and began to write.

Not a remediation plan. Not a regulatory response. Not a stakeholder communication strategy. Those would come later, drafted by teams, reviewed by lawyers, approved by committees. What she wrote that night was something more personal: a diagnosis. A clear-eyed accounting of everything that had gone wrong and everything that would need to change if Northbridge was going to survive not just the investigation but the underlying disease that the investigation had exposed.

She wrote for four hours. When she finished, she had seven pages. Seven pages that would become the foundation of the largest data governance transformation in Canadian insurance history.

She called them the Seven Steps.


The Seven Steps

Step One: Secure Executive Sponsorship. Nadia wrote this first because it was the step that Northbridge had skipped, and the step without which everything else was theatre. She had been hired as Chief Data Officer, but the role had been created as an afterthought, a concession to a governance consulting report that the board had commissioned and then largely ignored. She reported to the Chief Technology Officer, who reported to the Chief Operating Officer, who reported to the CEO. Three layers of organizational hierarchy between the person responsible for data and the person with the authority to act. The board had never discussed data governance in a substantive way. The CEO had never publicly championed data as a strategic asset. The result was predictable: data governance was an initiative, not a discipline. A project, not a culture. A line item that could be deferred when quarterly earnings were tight.

What Nadia needed, what every organization that is serious about data governance needs, was a champion at the highest level of the organization. Not someone who approved a budget and then disappeared. Someone who stood up at town halls and said, “Our data is as important as our capital, and we will treat it with the same rigour.” Someone who held other executives accountable. Someone who made governance not just permissible but expected.

After the crisis, Douglas Firth became that champion. Not because he suddenly understood data management, but because he understood institutional survival. He had seen companies die: not from a single catastrophe but from the slow accumulation of deferred maintenance, unfixed foundations, and unasked questions. He would later tell Nadia, in a private conversation that she would remember for the rest of her career, “I spent forty years in public service believing that governance was bureaucracy. I was wrong. Governance is the immune system of an institution. Without it, any infection can become fatal.”

Step Two: Establish a Data Governance Council. Within two weeks of the crisis, Nadia convened Northbridge’s first Data Governance Council. The composition was deliberate: the Chief Data Officer as chair, the General Counsel, the Chief Risk Officer, the Chief Information Security Officer, the heads of each major business unit (Personal Lines, Commercial Lines, Health & Life, Reinsurance), the Chief Actuary, the VP of Customer Experience, and a representative from the Office of the Privacy Commissioner who served as an observer for the duration of the remediation period.

The council met every Monday at 8:00 AM. No exceptions. No delegates. No cancellations. Nadia was ruthless about this, because she understood that the single greatest threat to any governance program is the slow erosion of executive attention. The first meeting is full. The second meeting is missing two people. By the sixth meeting, it’s Nadia and three middle managers, and the initiative is dead.

She told the council at its first meeting: “If you are not in this room every Monday at eight, I will assume you do not consider the lawful management of our customers’ personal information to be a priority. I will document that assumption. And I will share it with the board.”

No one missed a meeting.

Step Three: Define Data Ownership and Stewardship. This was the step that exposed the deepest dysfunction at Northbridge. When Nadia asked each business unit head to identify the data they “owned,” the answers were revealing. The Head of Personal Lines said he owned “policy data.” The Head of Health & Life said she owned “health data.” The CTO said IT owned “all data.” The CFO said finance owned “financial data.” Nobody owned customer data. Nobody owned claims data that crossed business lines. Nobody owned the data that had been migrated from Commonwealth, it existed in an institutional no-man’s-land, belonging to everyone and therefore to no one.

Nadia spent three weeks conducting what she called a “data census”: a comprehensive inventory of every dataset in the organization, its source, its classification, its sensitivity level, and its regulatory obligations. For each dataset, she assigned a Business Data Owner (an executive accountable for the data’s integrity and compliance) and a Technical Data Steward (a senior analyst responsible for day-to-day quality and access management). She created a RACI matrix that mapped every data domain to its owner, its steward, the systems it resided in, and the regulations that governed it.

The exercise took three months. It was, by every account, the most painful process the organization had ever undertaken. It required executives to take personal responsibility for data they had spent years ignoring. It required IT to relinquish the fiction that “data is a technology problem.” It required the legal team to translate regulation into operational policy, not just memoranda. It required everyone to confront the truth that Margaret Whitfield’s health data had been accessible to a junior analyst because nobody had ever asked the question: who is supposed to prevent that?

Step Four: Create a Policy Framework. Northbridge had policies. Folders of them. Beautifully formatted documents that had been drafted by consultants, approved by committees, and filed in SharePoint folders that nobody opened. The Data Classification Policy. The Information Security Policy. The Privacy Compliance Policy. The Records Retention Policy. Each one a masterwork of corporate prose. Each one entirely disconnected from how data actually moved through the organization.

Nadia did not write new policies. She burned the old ones, metaphorically, and started from a single principle: every policy must be enforceable, measurable, and tied to a named individual who is accountable for its implementation. She reduced the policy library from forty-seven documents to twelve. Each policy was no longer than five pages. Each policy included specific technical controls, audit procedures, and escalation paths. Each policy named its owner, its review cycle, and the consequences of non-compliance.

The most important policy, the one that would have prevented the entire crisis, was the Data Classification and Access Control Policy. Four pages. It required every dataset entering Northbridge’s environment to be classified by sensitivity level (public, internal, confidential, restricted) within thirty days of creation or acquisition. It required access controls to match the classification level. It required quarterly access reviews. It required that any dataset containing sensitive personal information as defined by PIPEDA, Law 25, UK GDPR, or CPRA be flagged, isolated, and subject to enhanced consent verification before any processing.

Four pages. The absence of those four pages had cost the company its reputation and would ultimately cost it $247 million in fines, settlements, and remediation.

Step Five: Implement Decision Rights. This step addressed what Nadia considered the silent killer of data governance: ambiguity about who has the authority to make decisions about data. Before the crisis, anyone at Northbridge with a business justification, real or imagined, could request access to virtually any dataset, and the IT team, which processed access requests, had no framework for evaluating whether the request was appropriate. The IT team was not trained in privacy law. They were not trained in data classification. They were order-takers, and the orders they received were often wrong.

Nadia implemented a decision rights framework based on the DAMA-DMBOK model. Data owners had the authority to approve or deny access to their domains. Data stewards had the authority to set quality standards and enforce them. The governance council had the authority to resolve disputes between domains, set enterprise-wide standards, and escalate non-compliance to the board. No individual, not the CEO, not the CTO, not the head of any business unit, had the authority to override a data classification or access control without the documented approval of the governance council.

It was, in Douglas Firth’s words, “the first time in this company’s history that the rules about data had teeth.”

Step Six: Measure with KPIs. Nadia knew that governance without measurement is aspiration without accountability. She established a dashboard of twelve key performance indicators that were reported to the board quarterly:

Percentage of datasets with assigned owners. Percentage of datasets classified by sensitivity level. Time to resolve data access requests. Number of policy violations detected. Number of policy violations remediated. Data quality scores by domain. Audit findings closed within thirty days. Regulatory inquiry response time. Training completion rate. Consent compliance rate by jurisdiction. Data breach incidents. Governance council attendance.

The dashboard was not a vanity exercise. It was the mechanism by which the board, for the first time, could evaluate whether the organization was actually governing its data or merely claiming to. The numbers, in the first quarter, were devastating. Fewer than twenty percent of datasets had assigned owners. Fewer than ten percent had been classified. The average time to resolve a data access request was forty-three days. The consent compliance rate for the former Commonwealth portfolio was zero.

But the numbers improved. Quarter by quarter, meeting by meeting, policy by policy, the numbers improved. And as they improved, something else improved too, something that could not be measured on a dashboard but that everyone in the organization could feel: trust. Trust that the company was taking this seriously. Trust that the data was being protected. Trust that Margaret Whitfield’s experience would never be repeated.

Step Seven: Iterate Quarterly. The final step was not a step at all but a commitment: that data governance at Northbridge would never again be treated as a project with a start date and an end date. It would be treated as a permanent operational discipline, like financial auditing or regulatory compliance: something that the organization does every day, reviews every quarter, and improves every year, not because a regulator demands it but because it is the right thing to do.

Every ninety days, the governance council reviewed the KPIs, updated the policies based on audit findings and regulatory changes, and assessed whether the organizational structure was still adequate. New regulations were mapped to existing controls within thirty days of enactment. New acquisitions were subject to a governance readiness assessment before integration could begin. New systems were required to demonstrate compliance with the classification and access control framework before deployment.

Governance became, in Nadia’s phrase, “the operating system of the institution.” Not the most glamorous system. Not the system that generated headlines or impressed analysts on earnings calls. But the system without which every other system, every analytics platform, every AI model, every customer-facing application, every regulatory filing, was built on a foundation of sand.

Papa S. Nguer

Papa S. Nguer is a keynote speaker, presales leader, and author of Winning the Moments That Matter. 25 years in enterprise data and technical sales, $93M+ influenced, 300+ proving engagements.

Book him to speak  ·  Work with him  ·  LinkedIn

← All writing