3 Capability Assessment
For each capability, review the definition, ask the sample questions, score 1–5, check observed risks, and capture supporting notes.
Formal governance bodies, charter, council cadence, RACI, named data owners and stewards.
Sample Questions
- Is there a formal Data Governance charter?
- Does a governance council meet on a regular cadence?
- Are data owners and stewards named and active?
Risk Indicators Observed
Privacy Impact Assessments (PIAs), NIST alignment, incident response, FERPA operationalization.
Sample Questions
- Are PIAs embedded in project intake?
- Is FERPA training current and tracked?
- Is there a documented incident response plan?
Risk Indicators Observed
Data Privacy Agreements (DPAs), Data Sharing Agreements (DSAs), centralized EdTech approval workflows.
Sample Questions
- Is there a centralized vendor inventory?
- Are DPAs standardized and current?
- Who approves new EdTech tools?
Risk Indicators Observed
Defined DQ rules, monitoring, and issue-management processes.
Sample Questions
- Are DQ rules defined for critical data domains?
- Is there a formal issue-management process?
Risk Indicators Observed
Business glossary, enterprise data catalog, shared definitions.
Sample Questions
- Is there an enterprise data catalog?
- Are definitions shared and authoritative?
Risk Indicators Observed
Capture and traceability of data flows from source to report.
Sample Questions
- Can data flows be traced from source to report?
- Are PII flows documented?
Risk Indicators Observed
Standards adoption, versioning, extension governance.
Sample Questions
- Is Ed-Fi adopted and governed?
- Is CEDS used beyond federal reporting?
Risk Indicators Observed
DSA process, research access, open data posture.
Sample Questions
- How long does a typical DSA take to execute?
- Is there a research access model?
- Is there an open data posture or portal?
Risk Indicators Observed
AI use policy, use-case intake, model risk review.
Sample Questions
- Is there an AI use policy?
- Is there an AI use-case intake process?
Risk Indicators Observed
Governance, privacy, and security gates embedded in SDLC and procurement.
Sample Questions
- Are governance gates embedded in SDLC?
- Are governance checkpoints embedded in procurement?
Risk Indicators Observed