Public Consulting Group (PCG)Data Governance Modernization
CONFIDENTIAL — DRAFT
Situation Analysis — Assessment FormInterview & Workshop Instrument
Capabilities scored0 / 10
Avg maturity
Autosave ready
Assessment progress
0%

1 Instructions

Use this form during interviews and workshops to capture current-state evidence and apply a 1–5 maturity score per capability area. Your work is automatically saved in this browser as you go.

Maturity Scale Legend

ScoreLabelDescription
1Ad hocNot present or informal only; no documentation.
2EmergingInconsistent; pockets of practice without enterprise alignment.
3DefinedDocumented but not consistently enforced or measured.
4ManagedEnforced and measured with clear ownership.
5OptimizedContinuously improved, benchmarked, and embedded in operations.

2 Organization Profile

Capture identifying information about the organization being assessed.

3 Capability Assessment

For each capability, review the definition, ask the sample questions, score 1–5, check observed risks, and capture supporting notes.

Operating Model & Decision Rights

Not scored

Formal governance bodies, charter, council cadence, RACI, named data owners and stewards.

Sample Questions
  • Is there a formal Data Governance charter?
  • Does a governance council meet on a regular cadence?
  • Are data owners and stewards named and active?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Privacy, Security & Compliance (FERPA / State Laws)

Not scored

Privacy Impact Assessments (PIAs), NIST alignment, incident response, FERPA operationalization.

Sample Questions
  • Are PIAs embedded in project intake?
  • Is FERPA training current and tracked?
  • Is there a documented incident response plan?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Vendor & EdTech Governance

Not scored

Data Privacy Agreements (DPAs), Data Sharing Agreements (DSAs), centralized EdTech approval workflows.

Sample Questions
  • Is there a centralized vendor inventory?
  • Are DPAs standardized and current?
  • Who approves new EdTech tools?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Data Quality

Not scored

Defined DQ rules, monitoring, and issue-management processes.

Sample Questions
  • Are DQ rules defined for critical data domains?
  • Is there a formal issue-management process?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Metadata & Catalog

Not scored

Business glossary, enterprise data catalog, shared definitions.

Sample Questions
  • Is there an enterprise data catalog?
  • Are definitions shared and authoritative?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Lineage

Not scored

Capture and traceability of data flows from source to report.

Sample Questions
  • Can data flows be traced from source to report?
  • Are PII flows documented?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Interoperability & Standards (Ed-Fi / CEDS)

Not scored

Standards adoption, versioning, extension governance.

Sample Questions
  • Is Ed-Fi adopted and governed?
  • Is CEDS used beyond federal reporting?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

Data Use, Sharing & Transparency

Not scored

DSA process, research access, open data posture.

Sample Questions
  • How long does a typical DSA take to execute?
  • Is there a research access model?
  • Is there an open data posture or portal?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

AI & Advanced Analytics Governance

Not scored

AI use policy, use-case intake, model risk review.

Sample Questions
  • Is there an AI use policy?
  • Is there an AI use-case intake process?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

SDLC & Procurement Governance

Not scored

Governance, privacy, and security gates embedded in SDLC and procurement.

Sample Questions
  • Are governance gates embedded in SDLC?
  • Are governance checkpoints embedded in procurement?
Maturity Score (1–5)
Hover a number to see its scale label.
Risk Indicators Observed

4 Cross-Cutting Risk Summary

Synthesize observations across capabilities.

Top 5 Risks Observed

1
2
3
4
5

Immediate Quick Wins

1
2
3
4
5

5 Overall Maturity Snapshot

Auto-updates as scores are selected above.

CapabilityScore (1–5)
1. Operating Model & Decision Rights
2. Privacy, Security & Compliance (FERPA / State Laws)
3. Vendor & EdTech Governance
4. Data Quality
5. Metadata & Catalog
6. Lineage
7. Interoperability & Standards (Ed-Fi / CEDS)
8. Data Use, Sharing & Transparency
9. AI & Advanced Analytics Governance
10. SDLC & Procurement Governance
Overall Average

6 Recommended Next Steps

0–30 Days

30–60 Days

60–90 Days

7 Sign-off