
Meet Florian, your lecturer for data governance and AI governance, with over a decade in business intelligence, BI architectures, data modeling, and process mining, plus hands-on exercises.
Define the data governance core and AI governance framework, covering policies, metadata, data quality, privacy, and lifecycle, with practical templates and case-based exercises.
Explore the EasyCar case study to apply data governance and BI analytics for one-way rentals, fleet utilization, branch performance, and dynamic pricing in a practical exercise.
Learn how data governance serves as the decision layer—defining meaning, access, quality, risk, and accountability—to enable faster, compliant, auditable data use and stronger AI governance.
Drive governance to accelerate data value while reducing risk by standardizing definitions, making assets discoverable, clarifying ownership, and monitoring quality amid AI-driven complexity.
Learn how data governance sustains itself through four outcomes—reliable KPIs, controlled access, fewer incidents, and faster delivery—expressed in operational terms; beware anti-patterns like governance as police, shelfware, and gold plating.
Master governance vocabulary by linking policy, standards, and controls to risk, learning how issues and safe exceptions drive measurable, compliant operations.
Set clear scope boundaries for data governance and AI governance, establish module 1 foundations: shared vocabulary, value and risk framing, metadata, data quality, and outline forthcoming modules.
Map governance to the data lifecycle by placing control points at ingest, store and transform, surf time, and archive; enforce metadata, quality, lineage, access, and retention obligations.
Explore metadata as the translation layer that turns datasets into trustworthy assets for discovery, understanding, and governance; leverage data catalog, business glossaries, and lineage for AI explainability and audit readiness.
Define data quality as fitness for purpose by applying accuracy, completeness, timeliness, consistency, and validity through rules across use cases; AI amplifies issues, underscoring trust and privacy in governance.
Explore how data governance links business use to privacy and security obligations, classify sensitive data, and enforce access, encryption, retention, and evidence-driven controls for Genai.
Explore common data governance frameworks, from DAMA-DMBOK to ISO standards and GDPR basics, and learn to tailor a minimum viable set of policies, controls, and evidence for your organization.
Explain how AI raises opacity, amplification, drift, and hallucinations, requiring artifacts like model versions, prompts, and sources, and govern with data quality, lineage, and controls.
Explore AI governance as an extension of governance thinking, with NIST AI Risk Management Framework, EU AI Act, and ISO frames, and artifacts like registers, inventories, evaluations, and monitoring dashboards.
Contrast data governance and AI governance artifacts, showing how AI introduces model registries, AI impact risk assessments, prompt logging, and red team evidence while reinforcing accountability, controls, and auditability.
Ground EZCAR's customer support chatbot in approved sources and access boundaries to reduce wrong policy guidance. Use a retriever to source context and monitor incidents to ensure safe, up-to-date responses.
Define a set of key performance indicators for data governance and AI governance. Track glossary definitions, catalog metadata, adoption indicators, quality outcomes, risk indications, and time to resolve with scorecards.
Define a governance charter to align governance activities, covering purpose, scope, decision rights, engagement and escalation, and measurement, serving as a living reference and base for an AI governance addendum.
Practice data governance foundations by building a minimum viable governance starter set for the EasyCar reservations domain, including glossary terms, data quality rules, classifications, and ownership roles.
Explore a walk-through of data governance exercises, detailing assets, glossary terms, data quality rules, data classification, and ownership placeholders for rental data assets.
Explore a practical governance charter template for data governance and AI governance addendum, detailing mandate, scope, roles, policies, workflows, and KPIs for a data governance program.
Explore how governance runs, decision rights, roles, and escalation shape policies, standards, and controls, then navigate metadata, data quality, security, AI risk, and AI lifecycle gates.
Produce module deliverables for data governance and ai governance, including a racy chart for key workflows, roles, council terms of reference, and a one-page governance scorecard with an implementation roadmap.
Explore the centralized, federated, and hub-and-spoke operating model patterns in governance. Implement cross-domain standards and decision making with domain councils, balancing consistency, speed, and accountability in data and AI workflows.
Explore trade-off dimensions for operating models: decision speed, consistency, cost, and scalability; contrast centralization and federation, and highlight anti-patterns such as shadow committees and unclear mandates with practical fixes.
Define decision rights as the heart of data governance, building a practical decision catalog for access, data quality, glossary terms, and tier classification with time-bound exceptions and audit-ready evidence.
Define governance roles using six dimensions—accountability, decision rights, responsibilities, artifacts and evidence, KPIs, and cadence—and map them to data owner, steward, custodian, product owner.
Apply raci by scenario to govern data access, quality, and glossary workflows, defining one accountable owner, a responsible Stuart, and consulted security or privacy, with practical evidence artifacts.
Explore how data councils, domain councils, and the AI governance forum coordinate cross-domain decisions, establish terms of reference, and plug into a single decision system to avoid governance noise.
Establish a disciplined escalation path from steward to data owner to council and executive sponsor, with a controlled exception lifecycle, service level agreements, risk reviews, and compensating controls.
Anchor governance in domains and data products with clear ownership, stewardship, service level agreements, and shared definitions to enable cross-domain interoperability across reservations, customers, fleet, and pricing.
Define cadence and artifacts as the backbone of data governance, with weekly synchronization, monthly council, quarterly reviews, and artifacts like decision lock, issue lock, exception register, KPI scorecard.
Drive enablement and change by onboarding, training, and running governance workflows, ensuring tier-1 assets have metadata, owners, classifications, quality checks, and automated evidence capture with clear transition plans.
Measure the data governance operating model with KPIs that reveal enablement or blocking, starting with decision-lead time, coverage, MTTR, repeat issue rate, and attendance and quorum.
Design a governance scorecard linking KPIs, targets, trends, and actions to drive timely decisions, with owners, due dates, risks, issues, exception status, and a lightweight maturity snapshot on one page.
Identify priority domains in the discover phase, baseline pain points, and measure success to guide a phased governance roadmap; pilot one domain, create artifacts, then scale and optimize with kpis.
Explore how AI governance ties into the data governance operating model, applying decision rights, forums, escalations, and evidence to AI artifacts such as model cards, data cards, and monitoring dashboards.
Lead a 90-day governance pilot for EasyCar by drafting a governance operating model, justifying the chosen model, and building a race chart, escalation ladder, and initial scorecard.
Choose the domain and adopt a federated with central standards operating model for data governance, then map RACI roles, data access processes, SLAs, and governance council terms of reference.
Set module 3 scope for data governance to keep governance practical, focusing on policy mechanics, testable controls with evidence, and an exception workflow that yields runnable policies.
Discover a three-layer governance model—policy, standards, and procedures—and learn how traceability links policy intent to controls and evidence to ensure consistent audits and operation.
Develop clear, testable data policies with defined scope and auditable evidence, including tier one data sets with documented owners and freshness, while avoiding vague anti-patterns.
Translate policy into concrete standards and runnable procedures by defining scope, requirements, test methods, evidence, owners, and frequency, with versioning and reuse to prevent policy sprawl.
Apply preventive, detective, and corrective controls to manage risk. Balance manual and automated controls with a hybrid approach; tie control statements to failure modes and evidence.
Link every control to its evidence location with a stable, timestamped proof. Demonstrate control execution, approval, and freshness through artifacts like dashboard URLs, ticket queries, and logs.
Understand how an explicit risk acceptance, time-bound exception maintains governance under legacy constraints, with explicit approvals, compensating controls, a risk register, defined expiry, and regular reviews.
Frame policies as a translation layer to align internal controls with external standards like GDPR and ISO. Use a lightweight mapping for traceability and evidence.
Apply data governance and AI governance to EZCAR reservations analytics by translating policies into standards and controls, implementing automated freshness checks, and using time-bound exceptions with compensating controls and evidence.
Define policy, control, and exception templates to run governance as a workflow. Practice with a small scope on EasyCar reservations, drafting 1 policy and 5–8 controls with evidence locations.
Apply policy standards and controls in a practical exercise by drafting a policy for reservation analytics data, building a control catalog, creating an exception register, and reflecting on policy-to-evidence chain.
Walks through building a data access policy for reservations analytics, detailing metadata, scope, role-based controls, approvals, and an exception register within a data governance framework.
Set boundaries for catalog operations and onboarding assets to ensure discoverability and accountability, defining minimal metadata, published status, and metadata ownership with glossary life cycle.
Metadata drives search, understanding, and trust by providing clear names, ownership, and descriptions; it guides AI safety and retrieval accuracy.
Bridge business and technical metadata to enable meaningful data governance and decision rights. Map owners, definitions, classifications, and lineage to ensure data freshness, handling, and accountability.
Explore the glossary life cycle as a governed workflow that links terms to data assets, with five phases—propose, review, approve, publish, retire. Include ownership and version history.
Develop a trustworthy data catalog by applying a repeatable onboarding playbook that captures ownership, business context, and sensitivity, links governance evidence, and scales through automation.
Establish naming conventions that encode domain, product, and entity with a meaningful version. Use a controlled vocabulary of tags with a steward for consistency and classification from public to restricted.
Integrate data quality and data lineage using a single source of truth, linking the catalog to rules, lineage, approvals, issue backlog, and glossary for reliable cross-tool discovery.
Develop artifacts by drafting glossary terms and minimum metadata for a real data set; define owner, description, domain, classification, and onboarding deliverables to establish a shared quality bar.
Draft three business glossary terms—booking, cancellation, no show—and define minimum metadata for a data asset, then articulate a definition of done to standardize onboarding in a data catalog prototype.
Walks through defining glossary terms like booking, cancellation, and no show within a data catalog context, outlining minimum metadata, data lineage, and governance for reservations data.
Explore data quality and master data boundaries, turning quality into a measurable, repeatable workflow with measurement, enforcement, SLAs, and governance across analytics and AI readiness.
Explore five data quality dimensions—accuracy, completeness, timeliness, consistency, and validity—and learn to measure with metrics, define targets, and publish scorecards to govern quality across pipelines.
Design specific rules with patterns like null checks, non-negative ranges, reference sets, duplicates, and cross-field consistency, aligned to p1–p3 priority levels.
Define clear ownership and workflows to ensure data quality as an operational service, with explicit roles, handoffs, and service level agreements guiding rule logic, data product outcomes, triage, and fixes.
Follow the detect-to-validate remediation lifecycle for data quality, emphasizing evidence and decision rights. Learn to triage, assign owner, define due dates, and implement preventive changes.
Establishes the distinction between master data and reference data, and shows how governance, survivorship rules, golden record hub, and code lists governance prevent duplicates and misaligned analytics.
Monitor and report data quality by linking dashboards to prioritization and accountability, tracking breach rate, meantime to response, and open P1 and P2 backlogs to drive improvements.
Turn vague expectations into an operational data quality agreement for a single data set by defining three rules with thresholds and SLAs, delivering a rulebook entry and an SLA template.
Draft a data quality rulebook with completeness, validity, and uniqueness; define severity models, SLAs/OLAs, escalation paths, and a data quality dashboard for EasyCars reservation analytics.
Define scope boundaries for data and ai governance by prioritizing safe use of sensitive data through classification, labeling, access governance, retention, DPIA, and ROPA.
Data classification drives governance by defining four levels—public, internal, confidential, and restricted—with examples and minimum controls. Labels and tags in catalogs, storage, and BI ensure ownership, onboarding, and measurable compliance.
Learn how handling standards translate sensitive data into safe behaviors across storage, sharing, and analytics, with encryption, clear key ownership, and logging for audits.
Master access governance through a five-step lifecycle—request, approve, provision, review, and revoke—emphasizing time-bound access, role-based controls, and auditable evidence to ensure only the right people see data.
Master DPIA and PIA using a structured record to reveal risks, document purpose and data categories, identify data subjects and recipients and lawful basis, then apply mitigations like masking identifiers.
Align retention and deletion with data categories across systems using explicit schedules and automation; use clear deletion patterns—hard delete, soft delete, anonymization—and ensure defensible deletion with audits.
Link evidence and audits by weaving standards, decisions, and assessments with operational proof. Maintain a controlled repository with catalog discovery, DPI-A records, Ropa entries, and quarterly checks to prevent drift.
Apply privacy and security guardrails to a dataset by drafting a 10-field classification, defining five handling rules, and outlining an access workflow with roles and retention to enable catalog discoverability.
Develop field level classifications and handling rules for the reservations analytics data set, design access workflow, set retention and deletion intents, and assemble an evidence map for a privacy audit.
Explore data classification templates, handling rules, and access workflow designs to implement rigorous data governance. The walkthrough covers roles, separation of duties, review cadences, evidence map, and retention practices.
Define lifecycle stages and gate-based transitions, capture lineage and evidence, and enable impact analysis, incident response, and explainability to establish the governance foundation.
Explore the data governance lifecycle from ingest to delete, through ingest, curate, surf, serving, archive, and delete stages. Emphasizes owner, evidence, and controls for schema, exposure, retention, and deletion.
Map governance gates to asset life cycle stages, defining pass criteria and evidence for ingest, current, surf, archive, and delete gates to enforce durable, auditable controls.
Explore lineage fundamentals across processed, table, and column lineage, and how governance defines a minimum standard by risk tier to balance granularity, cost, and explainability for audits and root-cause analysis.
Capture lineage as a delivery practice by building multi-layer maturity with coverage, automation, and standards, using templates, instrumentation, and reconciliation to ensure discoverable, versioned lineage for data products.
Discover how data lineage turns investigation into a repeatable workflow, enabling impact analysis before changes and after-incident tracing, with ownership and monitoring to reduce risk and support explainability.
Discover how data lineage becomes governance evidence by linking it to catalogs, quality checks, and code releases, enabling traceability, explainability, and auditable outcomes.
Create a data product lifecycle and lineage package that supports change safety, audits, and incident response by detailing sources to consumers, five critical columns, derivation logic, and an evidence checklist.
Demonstrate building a complete data lineage package for the fact reservations table, covering table and column level lineage, blast radius analysis, lifecycle gates, impact paths, and evidence packaging.
Explore end-to-end data lineage from sources to consumers using a reservations dataset, detailing staging to mart flows, derivation notes, lifecycle stages, and top three impact paths.
Define clear scope boundaries for ai governance with a shared vocabulary, guiding principles, and anchor frameworks that clarify roles and decision points across risk, legal, engineering, and product teams.
Explore why ai governance adds a distinct layer to data governance, addressing opacity, drift, misuse, and fairness through documentation, monitoring, thresholds, and shared responsibility across product, data, and legal teams.
Translate governance principles into concrete design requirements, review questions, and audit evidence with named owners for use cases, models, and controls, while ensuring transparency, fairness, safety, privacy, and human oversight.
Assign clear owners for use case, data, and model responsibilities. Establish a governance forum to review evidence, approve with conditions, and escalate risk within risk, legal, privacy, and security constraints.
Frameworks anchor ai governance by standardizing risk, documentation, and approval across projects. Translate framework language into local risk-tier requirements, map to controls, and unify policies and evidence.
Establish operational governance by producing a standard artifact package from design through operation, including ai impact assessment, risk register, model and data cards, and an approval record, for risk-aligned reviews.
Build a linked, searchable, versioned evidence trail that spans design, build, deploy, and monitor to ensure accountability for model decisions.
Turn governance ideas into a one-page AI governance charter addendum for a use case, detailing scope and non-use. Align three to five principles with testing, illustrated by EasyCar examples.
Draft an AI data governance addendum for a use case, outlining scope, four governance principles with tests, oversight, evidence, and specific risks using the AI governance charter addendum template.
Outline data governance for a customer support triage ai use case with classification, routing, confidence scores, and human review, supported by governance principles and minimum evidence.
Define governance mechanics for ai systems across algorithms and maturity; enable a lightweight yet disciplined responsible ai process with risk taxonomy, review via Aia process, and model and data cards.
Use a three-lens AI risk taxonomy: data, model, and use case—to identify precise mitigations for governance, addressing data risks (coverage, privacy, bias), model risks (instability, overfitting), and use-case risk.
Use a severity and likelihood scoring model to prioritize risks and connect scores to governance obligations, thresholds, and AIA or forum approval, with risk-based review cadences and dynamic pricing.
The AI impact assessment turns responsible AI into a documented decision for new models, major changes, or use contexts, including data sources, evaluation results, risk mitigations, monitoring plans, and auditability.
Explore model cards and data cards as essential, versioned documentation for AI systems. Describe purpose, limitations, monitoring, data provenance, privacy considerations, and evidence links while avoiding stale or conflated documents.
Design explicit human oversight with clear intervention points, logging, disclosures, and human in the loop and human on the loop patterns for accountable decision-making.
The risk register drives ongoing governance for responsible AI by assigning owners, due dates, and evidence links to track mitigation and residual risk decisions.
Draft a lightweight AIA outline, model card skeleton, data card skeleton, oversight plan, and evidence list to demonstrate whether the operating discipline is understandable and repeatable.
Explore responsible AI with an exercise introducing AI impact assessment, model card, data card, human oversight plan, and AI risk register for a production fraud-detection model.
Explore a sample walkthrough of a booking fraud detection model within data governance and AI governance, detailing the AI impact assessment, model cart, oversight plan, and risk register.
Your organization is deploying AI. Data teams are growing. Regulations are tightening. And someone has to make sure the data can be trusted and the models can be explained. That's what this course is about.
Data Governance has expanded well beyond traditional data management and this course reflects that reality.
The course is built in two halves. The first builds your core governance program: operating model, policies and controls, business glossary, data quality, privacy, and lineage. The second covers AI governance: assessing and documenting AI risk, governing ML pipelines, and writing GenAI-specific policies for RAG ingestion, prompt safety, and response governance.
The labs are real governance work. Every module has a hands-on assignment built on EasyCar, a realistic car rental case study that runs through the entire course. You'll draft business glossary terms with ownership and exclusions, write testable data quality rules with severity levels, produce an AI Impact Assessment, fill in a model card and data card, design a human oversight plan for a fraud detection model, and define GenAI prompt logging standards.
What makes this course different:
End-to-end scope: From writing your first governance charter to governing ML pipelines, RAG corpora, and LLM prompt safety
14 hands-on lab assignments: One per module, all built on the same EasyCar case study that runs continuously from Module 1 to Module 14, so context and decisions compound as you progress rather than starting over each time
15+ ready-to-use templates included: charters, RACI matrices, policy catalogs, model cards, AI risk registers, data cards, incident runbooks, and more — ready to adapt and deploy
Regulatory alignment: Modules map to EU AI Act, NIST AI RMF, ISO/IEC 42001, and GDPR so you know where your controls map to real obligations
Vendor-agnostic: All principles and templates work regardless of your tooling stack
You'll finish with a governance charter, a policy catalog, a data quality rulebook, an AI risk register, a model card, a data card, and a GenAI policy; artifacts you can put in front of your organization immediately.