Data management presents risk, opportunity: Governance Institute

The original source of this piece comes from The Sustainability Report written entirely by Rachel Alembakis. Cite the source of the document as follows: Rachel Alembakis, 7 August 2020, “Data management presents risk, opportunity: Governance Institute”, The Sustainability Report, http://www.thesustainabilityreport.com.au/data-management-presents-risk-opportunity-governance-institute/. The Sustainability Report’s Twitter handle can be found here. Consider following, the reports are always groundbreaking and allow one to go beyond typical definitions of #Sustainability.


There is a disconnect between IT and business leaders regarding the risk and opportunity of consumer data, according to new research from the Governance Institute of Australia and CSIRO.

The report – Digital Trust – Corporate awareness and attitudes to consumer data – also identifies risks to brand and reputation from mishandling data and difficulty in putting a value on data have been identified as key data governance concerns for corporate Australia.

The report, authored by CSIRO’s Data61, the digital specialist arm of the national science agency, found that the majority of respondents placed “damage to brand or reputation as the highest potential
impact of four consumer data risks,” which also included legislative and regulatory change, disruption or failure to innovate, and cybercrime.

The report noted that the challenge is to connect the governance of data and the governance of reputation with a chain of responsibility.

“Data protection and cyber security is not a project, it’s not a set and forget,” said Megan Motto, Governance Institute of Australia CEO. “It’s a process and organisations need to be continually upgrading and looking out for security risks, the contextualisation of the risk, the value of data, how to turn the data into insights that give a competitive advantage in business.”

Data governance is complex and is a higher stake issue than ever before, Motto noted.

“This is no longer the purview of IT departments alone,” she said. “It’s about the leadership of organisations. Who should own it? The board ultimately owns it, albeit that they delegate it to different actors in the C-suite and in particular the chief information officer, or the chief data officers, as they’re often called. It depends on the size and maturity of organisations, and how many staff and layers of staff you have available.”

The report found that respondents are more concerned about the risks of damage to brand and reputation than cybercrime or disruptions when it comes to innovating and legislative or regulatory change.

“Like all risk management processes, it’s owned by the board, so the board has to say to the management team, what is the process, how are you updating this process on a regular basis, what are the risk management strategies,” Motto said. “All of the normal risk conversations that a board would have would apply to data governance.”

Board members should also have a “deep reasonable understanding” of the data a company holds, not only for risk management purposes, but for strategic purposes as well, Motto added.

Data presents not only risk management concerns, but strategic value as well. Participants most often assessed consumer data as very valuable, with over 87% claiming consumer data ranged between valuable and extremely valuable.

The report by the Governance Institute and Data61 was based on a survey invitation sent in September and October 2019 to the Governance Institute’s message list, with 117 participants completing the survey

The report also identified that there is uncertainty over who is responsible and accountable for the data governance strategy and that companies find it difficult to place a value on data. However, organisations that value consumer data are more likely to consider it in their strategies and business models, and organisations with a data governance strategy are “more likely to be aware of the risks in handling consumer data and they are significantly more likely to recognise that mishandling consumer data presents a high risk to brand and reputation.”

Having data governance strategies are strategic conversations as well as risk management conversations, Motto said.

“Those are the strategic conversations for the board to have,” she said. “Governance and risk management frameworks are frameworks for decision-making that help organisations not only comply with the law and regulatory requirements, but help you perform as a business.”

Maintaining trust with stakeholders is an essential part of social license to operate.

“Organisations should look at this through a business sustainability lens and say, it’s in our best interests to have our supply chains trust us, our employees trust us, and our customers trust us, and to that end, we need to think about how we use data ethically,” Motto said. “That’s the other side of the trust compact if you like – an organisation is expected to use data ethically in order to have that trust. Building the tech is the easy part – it’s the ethical frameworks around them to achieve the goal – that’s the challenge.”

When considering this aspect of trust, organisations should also consider the power dynamic that comes with demands for data, said Katina Michael, a professor at the Arizona State University and director of the Society Policy Engineering Collective.

“Before you have a trust scenario, you have to recognise there’s a power imbalance- the end user is supposed to give the data over to access the service,” Michael said. “I as the organisation am taking your data because you need this service, there’s no other way about it. You want this service, you hand over your data.”

“The underlying element is that the organisation has control because you’re seeking a service of care, leisure, entertainment or convenience,” Michael said. “But the underlying dimension is control. The minute you give over data, it’s an exchange, but it’s not a fair exchange.”


“Every organisation requires ethical principles and objectives and they have to live and die by those principles and entrench them in their workforce,” she said. “It’s just not about the standards and policies – its’ about the enforcement of those principles and objectives.”

COVID-19 has added additional complexity and urgency, said Rob Hanson, lead author of the report and senior research consultant at CSIRO’s Data61.

“COVID-19 has forced a more rapid adoption of digital services,” Hanson said. “Consequently, confidence, trust and privacy are all critical for consumers to have in the businesses that they interact with. Trust enhancing technologies, including cyber security and privacy enhancing services, are a key enabler of good governance and mitigating risks while maintaining a competitive advantage.”

Previous
Previous

Lessons from COVIDSafe: Toward Public Interest Technologies of the Future

Next
Next

Πόσο χρήσιμο είναι τελικά το COVIDSafe;