What is Product Data Governance?

Executive Summary

Most organisations approach Digital Product Passports as a technology problem. They evaluate platforms, design integrations and build publishing pipelines. Then, some months in, they discover that the difficulty was never the plumbing. It was that nobody could say who owned a material declaration, when a weight had last been verified, which of three recorded values was correct, or on whose authority a public claim had been made.

That is a governance problem, and no amount of technology solves it. A well-built pipeline publishes poor data faster and more consistently than a poor one. Governance decides what is true, who decides it, how quality is measured, what happens when a value changes, and how the organisation defends what it has published. Technology only moves the result.

This article sets out The Trusted Product Data Governance Framework, six layers in a deliberate order. Ownership establishes who is accountable. Quality makes the state of the data measurable. Policies turn expectations into rules. Stewardship provides the people who operate those rules daily. Lifecycle manages change over time. Compliance is the outcome, not the starting point. Each layer depends on the one above it, which is why programmes that begin at compliance and work upwards tend to stall.

Governance is also what makes a passport defensible rather than merely present. A published claim implicitly asserts that the organisation knows the value, knows where it came from, and knows that it is current. Governance is the mechanism that makes those three assertions true, and it is why passports built on governed data survive scrutiny while passports built on assembled spreadsheets do not.

Everything here is vendor neutral and organisation-size agnostic. A small manufacturer and a multinational need the same six layers. They differ in formality, not in substance.

FrameworkTBF-023
The Trusted Product Data Governance Framework

Sets out ownership, quality, policies, stewardship, lifecycle and compliance as the six working parts of governance.

Table of Contents

Definition

Definition
Product Data Governance

Product data governance is the set of accountabilities, policies, standards and routine practices through which an organisation decides what its product information means, who owns it, how its quality is measured, how it changes over time, and how published claims about products are authorised and evidenced. It is exercised by people and processes, supported by systems, and it determines whether product data can be trusted by parties outside the organisation.

Three clarifications, because the term is frequently misapplied.

Governance is not a system. A master data platform, a workflow tool or a passport product can enforce governance decisions. None of them can make those decisions. A tool configured without an owner, a definition and a rule simply automates whatever the organisation was already doing.

Governance is not a project. It has a start but no end. Products change, suppliers change, regulations change and the definitions the organisation agreed last year stop matching what it now sells. Governance is the standing capability that keeps those things aligned.

Governance is not bureaucracy, when it is done well. Its purpose is to reduce the number of decisions that must be made repeatedly. A defined owner and a written definition mean a question is answered once rather than relitigated in every project.

The one sentence version

Governance is the answer to a single question asked about every published attribute: who says so, on what basis, and how would we prove it?

Why Governance Matters

Digital Product Passports change the consequences of poor product data. Internally, a wrong value causes friction: a picking error, a re-work, an argument between functions. Published externally, under a Digital Product Passport regime, the same wrong value becomes a claim made to customers, retailers, recyclers and market surveillance authorities.

Five specific shifts explain why governance now outranks technology in importance.

Claims become externally verifiable. Once published against a persistent identifier, product information can be compared against packaging, against a competitor’s data, against a laboratory test and against previous versions. Inconsistencies that used to remain internal become visible.

Data becomes durable. A passport is a snapshot that persists. The organisation may be asked years later why it stated something, which means provenance and version history stop being technical niceties and become the substance of a defence.

Accountability becomes unavoidable. Regulation attaches responsibility to economic operators, not to systems. Somebody must be able to stand behind a figure, and organisations without defined ownership discover this at exactly the wrong moment.

Dependency on third parties increases. A substantial part of a passport, material composition, recycled content, certificates, origin, arrives from suppliers. Governing data the organisation did not create requires explicit rules about acceptance, validity and expiry.

Scale magnifies everything. A governance weakness that is tolerable across twenty products becomes unmanageable across twenty thousand. Manual verification does not scale; agreed definitions and automated rules do.

Example
The same weakness, before and after

A manufacturer holds three different net weights for one product: one in the design system, one in the planning system and one on the packaging artwork. For years this was a minor nuisance resolved by phone calls. When the product is published in a passport, one of those figures becomes a public claim. A retailer compares it to the delivered goods, a discrepancy is logged, and the organisation now needs to explain which figure is authoritative and why. Nothing about the data changed. The exposure did.

Best Practice
Test the programme with one question

Pick any attribute that will appear in a passport and ask who owns it, where the authoritative value lives, when it was last verified, and what happens when it changes. If the answer requires a meeting, the organisation has a governance gap that no platform selection will close.

The Trusted Product Data Governance Framework

Governance fails most often because it is attempted in the wrong order. Programmes commonly start with quality dashboards, or with a compliance deadline, and then discover that neither can be acted on because nobody is accountable for the underlying values.

The Trusted Product Data Governance Framework orders the six layers by dependency. Each layer requires the one above it. Ownership without quality measurement is a title without feedback. Quality without policies is opinion. Policies without stewardship are documents. Stewardship without lifecycle management degrades as products change. And compliance without all five is an assertion the organisation cannot evidence.

Six layers, top to bottomEach layer depends on the one aboveCompliance is an outcome, not a starting point
01
OwnershipAccountability

Every product attribute has one named accountable owner in a business function, and one authoritative source system. Ownership answers who decides the value and who is answerable when it is wrong.

Without it: disputes have no resolution path and defects have no route to a fix.

02
QualityMeasurement

The condition of the data is measured against agreed dimensions: completeness, accuracy, consistency, timeliness, validity and uniqueness. Measurement turns a general sense that data is poor into a specific, assignable defect.

Without it: improvement is anecdotal and progress cannot be demonstrated.

03
PoliciesRules

Definitions, standards, validation rules, approval paths, disclosure rules and retention expectations are written down and applied consistently. Policies convert quality expectations into enforceable constraints.

Without it: every team applies its own interpretation and the same attribute means different things in different places.

04
StewardshipOperation

Named people run the rules day to day: they resolve exceptions, chase suppliers, maintain reference lists, onboard new products and escalate what they cannot settle. Stewardship is where governance becomes a routine rather than an initiative.

Without it: policies exist on paper and the backlog of exceptions grows unowned.

05
LifecycleChange over time

Attributes are governed from creation through change, verification, expiry and retirement. Versions and effective dates are retained, certificate validity is tracked, and material change triggers re-publication of anything already public.

Without it: published information silently ages and becomes a historical document presented as current.

06
ComplianceOutcome

Regulatory obligations are met and, critically, evidenced: the organisation can show what it published, when, from which source, on whose authority, and how it responded when the underlying facts changed.

Without the five layers above: compliance is a claim rather than a demonstrable position.

Governance is built downward and read upward. When a published claim is challenged at layer six, the answer is reconstructed from layers one to five.

Read the framework in both directions. Built downward, it is an implementation sequence: assign ownership, measure quality, write policies, staff stewardship, manage lifecycle, and compliance follows. Read upward, it is an audit path: a challenged claim leads back through lifecycle to the steward, the policy, the measurement and finally the accountable owner. A programme that cannot walk that path upward does not yet have governance.

Roles

Governance requires named people, not committees in general. Five roles cover the work, and in smaller organisations one person may hold several of them. What matters is that each responsibility is explicitly assigned.

Data owner. A business leader accountable for a domain of product information, for example engineering specifications, commercial attributes or sustainability data. Approves definitions, resolves disputes, accepts quality targets and answers for published claims in their domain. This is an accountability, not a full-time job.

Data steward. The operational role. Maintains values, applies rules, resolves exceptions, manages reference lists, onboards new products and works directly with suppliers. Stewards are the single highest-leverage investment in a governance programme and the most frequently omitted.

Data custodian. Usually IT or a data platform function. Operates the systems, integrations, access controls and backups. Custodians ensure the data is available and secure; they do not decide what it means.

Governance lead. Runs the governance function itself: maintains the policy set, convenes decision forums, tracks quality reporting, and keeps the framework alive between projects. Without this role, governance decays into whatever the last project left behind.

Compliance and regulatory owner. Interprets obligations, determines what must be published for which markets, and defines the evidence standard. Works with data owners to translate regulation into attribute-level requirements rather than general intent.

Two supporting participants deserve mention. Suppliers are effectively external stewards for the data they provide, and should be treated as part of the governance model with defined expectations and accountability. Product and category teams are frequently the originators of new attributes and must be brought into the definition process rather than allowed to create parallel vocabularies.

Common Mistake
Appointing owners without authority or time

Naming an owner who cannot change a process, cannot prioritise a fix and has no allocated capacity produces the appearance of governance and none of its effect. Ownership must come with the authority to decide and the time to exercise it.

Ownership

Ownership is the first layer because everything downstream resolves to it. Three questions define it for any attribute.

Who is accountable for the value? A named business role, not a department and not a system. When a figure is challenged, this is the person who answers.

Where does the authoritative value live? One system of record per attribute. Copies may exist elsewhere for performance or convenience, but only one location is authoritative, and that fact must be documented rather than assumed.

What is the value’s definition? A written statement of what the attribute means, its unit, permitted values, granularity, and any calculation rule. Two organisations can hold different figures for the same attribute name and both be right, because they defined it differently. A passport makes that ambiguity public.

An attribute register is the practical artefact. For each attribute that will appear in a passport, or that feeds one, it records the definition, the owner, the source of record, the granularity, the quality expectation, the disclosure rule and any regulatory driver. It is unglamorous and it is the single most useful document a passport programme can produce, because every subsequent argument is resolved by reference to it.

Ownership also needs an escalation route. Some attributes are genuinely contested between functions, typically where engineering, commercial and sustainability interests intersect. A standing decision forum with the authority to settle definitional disputes prevents those attributes from remaining permanently unowned, which is the usual outcome.

Policies

Policies convert governance intent into rules that apply the same way every time. A workable policy set for product data covers six areas, and it should be short enough that stewards actually read it.

Definition standards. How attributes are named, defined, versioned and retired, and how new attributes are proposed and approved. This is what prevents the organisation from accumulating four similar fields with slightly different meanings.

Reference data control. Units of measure, country codes, material taxonomies, certificate types and status values come from controlled lists with an owner. Free text where a controlled list should exist is the most common cause of downstream inconsistency.

Validation rules. What must be present, in what format, within what range, and which cross-field consistencies must hold before an attribute is publishable. Rules should be enforced automatically wherever possible, because manual checking silently stops happening under pressure.

Approval and authorisation. Which changes require review, who approves publication, and what constitutes sufficient evidence for a claim. Sustainability and safety claims typically warrant a higher bar than descriptive content.

Supplier data acceptance. What the organisation requires from suppliers, in what format, with what evidence and what validity period, and what happens when a declaration expires or is superseded. Without this, supplier data ages invisibly.

Disclosure and retention. Which attributes may be shown to which audiences, which must never leave the organisation, how long published versions are retained, and how supersession is recorded.

Best Practice
Enforce policies where the data is created

A rule applied at publication time rejects work that has already been done. The same rule applied at the point of entry prevents the defect. Governance that only inspects at the end trains the organisation to treat it as an obstacle rather than a standard.

Quality

Quality is the layer that makes governance visible. Without measurement, the organisation cannot tell whether it is improving, and the conversation stays subjective.

Six dimensions are sufficient for product data, and each should be measured per attribute rather than in aggregate.

Completeness. Is the value present where it is required, for the products where the requirement applies? Aggregate completeness across all attributes hides the fact that the few regulated ones are the gaps.

Accuracy. Does the value correspond to physical or documented reality? Accuracy cannot be inferred from within the data and requires verification against a source, a measurement or a document.

Consistency. Do the copies of this value agree across systems, and does it agree with related attributes? Contradictions between systems are the defects most likely to become public through a passport.

Timeliness. Is the value current, and when was it last verified? A verification date is more useful than an update timestamp, because many values are correct and simply unchanged.

Validity. Does the value conform to its definition, format, unit and permitted range? This is the dimension most readily automated and should be enforced at entry.

Uniqueness. Does the product appear once, or has it been duplicated across systems and catalogues? Duplication produces divergent values that are individually plausible.

Measurement should produce assignable defects, not dashboards. A quality report that tells an executive the estate is at eighty-three per cent changes nothing. A report that gives a named steward a list of forty products missing a regulated attribute, with a due date, changes the number.

Targets should also be differentiated. Attributes that will be published under regulatory obligation warrant near-total completeness and periodic verification. Internal descriptive attributes do not. Applying one standard to everything guarantees either an unachievable programme or a meaninglessly low bar.

Example
From dashboard to fix

An organisation reports overall product data quality at eighty-nine per cent for two years without improvement. It then re-cuts the same measurement by attribute and owner. Two attributes, recycled content and country of origin, account for most of the shortfall, and both belong to one team that had never been told they owned them. Ownership is assigned, a steward is given the backlog, and the regulated subset reaches full completeness within a quarter. The data did not become easier. It became someone’s job.

Benefits

Defensible published claims. Ownership, provenance and version history mean a challenge is answered by retrieval rather than investigation.

Faster passport delivery. Most passport programmes are delayed by data collection, not by technology. Governed data shortens the longest task in the plan.

Lower cost of change. When definitions and owners are documented, a new regulation, market or product category is an extension rather than a rediscovery exercise.

Fewer external corrections. Consistent data across passports, retailer feeds, marketplaces and packaging removes the contradictions that third parties otherwise find and report.

Reduced key-person risk. Undocumented knowledge held by long-serving individuals becomes an institutional asset that survives their departure.

Better supplier performance. Explicit expectations, formats and validity requirements measurably improve what suppliers return, because most supplier data problems are specification problems.

Reuse across the business. Governed product data serves commerce, service, sustainability reporting and compliance simultaneously, so the investment is not attributable to one obligation.

Common Mistakes

Common Mistake
Buying a platform before assigning ownership

Tooling implements decisions. Purchased before the decisions exist, it becomes a configuration project that ends with the same unresolved questions, now encoded.

Common Mistake
Governance by committee with no stewards

A steering group that meets monthly cannot resolve the thousands of small exceptions that constitute real data work. Without stewards, decisions are made but never operationalised.

Common Mistake
Measuring quality without assigning defects

Dashboards without named owners and due dates produce awareness rather than improvement. The organisation learns to discuss the number instead of changing it.

Common Mistake
One quality standard for every attribute

Treating a marketing description with the same rigour as a regulated substance declaration either exhausts the programme or dilutes the standard where it matters. Differentiate by consequence.

Common Mistake
Governing only what is published today

Scope defined by the current obligation leaves the organisation repeating the exercise for every new delegated act and market. Govern the attributes the product genuinely has, publish the subset required.

Common Mistake
Excluding suppliers from the governance model

A large share of passport content originates outside the organisation. Treating supplier data as a procurement attachment rather than governed data leaves the weakest link ungoverned.

Common Mistake
No verification date

An attribute with an update timestamp but no record of when it was last checked cannot support a timeliness claim. Values that are correct and unchanged look identical to values nobody has looked at in six years.

Common Mistake
Treating governance as a one-off project

Governance established for a launch and then unstaffed decays quietly. The first visible symptom is usually an external correction, by which point trust has already been affected.

Frequently Asked Questions

Is governance really more important than technology?
Yes, in the sense that technology cannot compensate for its absence. A good platform makes governed data cheaper to manage and publishes ungoverned data more efficiently. The determinant of trust is governance.

Where should a small organisation start?
With an attribute register for the attributes that will actually be published, a named owner for each, and one steward with allocated time. That is a genuine governance capability and it can be built in weeks.

Do we need a formal data governance function?
Not necessarily a department, but the roles must exist and be named. In smaller organisations one person may be owner, steward and governance lead for a domain, which is legitimate provided the responsibilities are explicit.

How does governance relate to master data management?
Master data management is largely the technical and operational discipline for maintaining authoritative records. Governance sets the accountabilities, definitions and rules those records implement. Governance decides, master data management executes.

Who owns sustainability data, which spans several functions?
Typically a sustainability or compliance owner for the definition and evidence standard, with engineering and procurement owning the underlying inputs. The key is one accountable owner per attribute, with named contributors, rather than shared ownership.

How do we govern data we receive from suppliers?
By specifying it: required attributes, format, evidence, validity period and an accountable sender. Then by tracking validity and treating expiry as a defect, not as background noise.

How often should product data be verified?
By consequence and volatility. Regulated and safety-relevant attributes warrant a defined verification cycle and re-verification on change. Stable descriptive attributes can be verified far less often.

How do we know governance is working?
Four signals: every published attribute has a named owner, quality defects are assigned and closing, material upstream changes trigger re-publication, and a challenged claim can be evidenced within a day. If those hold, the framework is operating.

Key Takeaways

Key Takeaways

Definitions of record for the terms used above live in the glossary.

References

About This Article

tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.