A governance report written for practitioners and a governance report written for a board are different documents with the same facts in them. The first can list controls. The second has to answer why the organisation should spend money on something that produces no revenue, and it has about two pages to do it before the audience decides this is an IT matter.
This was the second. The supplied case was a fictional healthcare provider, Neoteric, established in Australia and New Zealand and expanding into the UK, India and the US, carrying legacy systems, a consumer wearable app and a governance model built when it operated in one regulatory regime.
The organisation was not badly governed, and the assessment says so first. It had a Data Governance Council, a Non-Invasive Data Governance framework already adopted, autonomous regional management, and a genuine culture of medical leadership. Assessments that open by declaring everything broken tend to be wrong and are always dismissed.
The problem was that a governance model built for one jurisdiction had stopped matching a business that was no longer single-jurisdiction. Three specific things stop working at the border. Regional autonomy, a strength when it lets local teams respond to local conditions, becomes inconsistency when the same patient data is handled to different standards in four countries. Legacy systems, tolerable when the alternative is disruption, become a compliance liability when they cannot demonstrate what they do with data. And a wearable app collecting health metrics turns a clinical provider into a consumer data business, which is a materially different regulatory question that nobody had asked.
The finding that mattered came out of scoring exposure by activity and by region rather than by regulation. Read across any row and the same activity carries different risk in different places. Read down any column and no two jurisdictions want the same thing first. The UK and EU peak on consent, cross-border transfer and wearable monetisation. India’s binding constraint is data localisation. The US peaks on retention. Australia, the home market, is the lowest-risk column across the board, which is exactly why the existing model had never been stress-tested. That rules out the response most organisations reach for, which is to pick the strictest regime and apply it everywhere.
The recommendation was federation rather than centralisation, on the grounds that regional autonomy is an operating strength rather than a defect, and that pure autonomy is what produced the inconsistency in the first place. Federation is the only shape that survives contact with four regulators at once.
In brief
- Governance assessment across four jurisdictions (Australia, UK and EU, India, US) for a healthcare provider mid-expansion, delivered as an architecture report, a board report and a board presentation
- Compliance exposure scored 1 to 5 across five activities and four regions, showing no two jurisdictions share a top constraint: UK and EU peak at 5 on consent, cross-border transfer and wearable monetisation; India at 5 on data localisation; the US at 5 on retention
- Existing strengths documented before gaps, including an operating Data Governance Council and an adopted Non-Invasive Data Governance framework
- Governance maturity assessed at 2.5 out of 5 overall, with cross-border accountability and metadata management at the floor
- Risks evidenced against real incidents (WannaCry, the British Airways £183 million GDPR penalty, the Target third-party breach) rather than described abstractly
- Federated governance recommended over centralisation, on the finding that regional autonomy is a genuine operating strength rather than a defect to be removed
- Phased cloud migration recommended with a single-region pilot ahead of broader rollout, sequenced over an 18 month roadmap with governance on the critical path
- Stakeholder communication plan included in the recommendation, on the basis that adoption resistance is the most probable failure mode
The report as submitted
The work ran as three connected deliverables: an assessment of the current architecture, security posture and data ethics; a report to the board; and a board presentation with the supporting visuals.
Part one, the architecture and ethics assessment
Current storage and security
The estate was fragmented across legacy content management, cloud billing, CRM, electronic health records, identity management and web analytics. Systems of that spread present integration and security problems in combination that none of them presents alone (Dennis 2019), and moving health records to the cloud introduces data sovereignty and compliance questions that have to be managed rather than assumed away. Optimising the layout of data in cloud data lakes improves both performance and security (Shrivastava & Chandrasekaran 2019), which makes the migration decision an architecture decision rather than a hosting decision.
An effective data classification strategy is the precondition for everything else (Digital Guardian 2017): patient records, wearable data and monetisation initiatives are three different sensitivity classes and cannot be governed by one policy. Compliance with healthcare data law in Australia, the UK, the US and India then determines what may cross which border and how long it may be retained (Department of Home Affairs 2019). The specific risks are unauthorised access, data sovereignty exposure, and vulnerabilities inherited from third-party systems (Lord 2019), and the specific mitigations are complete audit trails and strong encryption for international transfers.
Data quality and ethics
Collecting wearable data raises privacy questions that consent forms written for clinical care do not answer. Patient consent for international data sharing has to align with cultural as well as legal norms, and AI-driven health recommendations need transparent data usage policies if patients are to make informed decisions about them (Floridi & Taddeo 2016). Algorithm bias and privacy impact have to be addressed together rather than sequentially (Leonelli 2016), because a model that is fair on average can still be unfair to the population a regional expansion has just acquired.
Monetisation ethics is the harder question, and it comes down to balancing commercial interest against privacy and distributing value fairly, with explicit protection for vulnerable populations. On quality, accuracy has to hold across three different things at once: clinical records, wearable measurements and cross-border consistency (Chisholm 2017). Automated monitoring and international standardisation are the practical mechanisms (McGilvray 2008), supported by identity verification, standardised terminology and demonstrable regulatory compliance (Dennis 2018). Transparency, quality governance and patient rights protection are the three elements that make the framework auditable rather than aspirational (Crawford & Paglen 2019).
Towards a solution
The proposed architecture is regional data lakes for analytics with a global data warehouse for reporting, which allows secure cross-border integration under role-based access control. Around it sits a governance structure with regional councils operating under global policy (Knight 2023), standardised data ownership and cross-border sharing protocols, and metadata management built on a centralised catalogue and business glossary with automated lineage tracking for compliance (DBHIDS 2016).
For the healthcare-specific layer: privacy-by-design with consent management and data minimisation (Therriault 2017), end-to-end encryption and multi-factor authentication with audit logging and breach detection (Seiner 2019), and automated data validation against international standards with real-time monitoring (Ginsburg, Phillips & Van Riper 2018). Operationally this is a DataOps model with automated testing, monitoring and compliance checks (Newman 2019) on a cloud-native architecture that can scale by region (Shrivastava & Chandrasekaran 2019). None of it works without executive sponsorship and sustained stakeholder engagement (Paolini 2016), which is the finding the board report was then built around.
Part two, the report to the board
Executive summary
Neoteric is expanding into international markets and needs to modernise infrastructure, handle data ethically, and build an architecture that will still work after the next regulatory change. The report sets out the case for a data governance function capable of supporting that expansion, since the regulatory landscape differs materially in each target market. The core recommendations are to align data analytics with corporate strategy, move privacy considerations into the design phase, and build compliance with global standards into the operating model rather than the audit cycle (Noonan 2019).
Strengths
The organisation has a strong market position in Australia and New Zealand and an operating philosophy centred on medical leadership, which keeps governance decisions anchored to clinical purpose. Local management teams are autonomous and accountable for their own regions. The Non-Invasive Data Governance framework is already adopted, which matters because its emphasis on minimal disruption to existing process means governance can be extended without a change programme that clinical staff will resist (Seiner 2019). And the Data Governance Council gives the organisation a forum where governance decisions already get made with stakeholders in the room (OAIC 2021). These are the foundations the expansion has to build on, not replace.
Opportunities
Modernising the technology estate is the obvious one, and most of the others depend on it. Expansion into three new markets is a rare chance to standardise governance practice while the regional operations are still being designed, rather than retrofitting it later. The wearable app creates a direct channel to patients and a basis for personalised health insight, provided the consent model is built first (Dennis 2019). And raising data literacy across the organisation through training makes every other initiative cheaper to deliver (OAIC 2021).
Gaps
Reliance on legacy systems and third-party solutions produces data silos, inconsistent quality, and decisions that are not aligned to strategy because the people making them cannot see across the organisation. Coordination becomes harder as the business becomes international, and there is no framework that would keep four regions consistent (OAIC 2021). There are no clear roles or responsibilities for data stewardship, so accountability for data quality sits nowhere in particular (Seiner 2019). And there is no metadata management strategy, which limits both data quality and the ability to demonstrate what the organisation holds and why (Dennis 2018). The decentralised structure that produces the autonomy is the same structure that produces the inconsistency if it is not aligned globally.
Risks
Unauthorised access to patient data is the first risk, made worse by outdated systems and third-party components whose security cannot be attested (Dennis 2019). The 2017 WannaCry outbreak is the precedent: it disabled healthcare organisations worldwide specifically through unpatched legacy systems.
Data sovereignty is the second. Failure to comply with international data protection law brings substantial fines and reputational damage (OAIC 2021). British Airways’ £183 million GDPR penalty in 2019 is the precedent a board will already know.
Third-party systems and cross-border transfers are the third, and the 2013 Target breach, which originated with a vendor, is the precedent (Seiner 2019).
The fourth risk is internal, and it is the one most likely to actually happen: staff resistance to new governance practice. It is also the only risk in the register the board can address directly, through the change management and data literacy work it chooses to fund.
The fifth is cumulative reputational damage. Beyond regulatory fines, failure to hold a defensible line on data ethics erodes public trust and damages clinical reputation, which for a healthcare provider is the asset the business runs on (OAIC 2021).
Recommendations
Invest in scalable cloud storage and modern data architecture to replace the legacy estate, improving accessibility, security and compliance (Dennis 2019). Phase it, starting with a pilot in one region, so that the first rollout produces evidence rather than a very expensive lesson.
Build a governance structure with regional councils operating under global policy, which addresses data sovereignty without stripping regions of the autonomy that makes them effective (OAIC 2021). Establish the regional councils within the first six months.
Implement a metadata management strategy with a dedicated team and a target of completion inside the first year (Dennis 2018).
Define data stewardship roles with named accountability and put best practice for data management and security behind them, with the first compliance audit scheduled within 18 months of implementation (Seiner 2019). Neither stewardship nor metadata is a system purchase, which makes them easy to defer indefinitely and cheap to actually do.
Stakeholder management strategy
Governance fails on adoption far more often than on design, so the communications plan is part of the recommendation rather than an appendix to it. Each group has to be persuaded of something different.
| Stakeholder group | Risk or opportunity | Motivation | Message focus | Channel |
|---|---|---|---|---|
| Executives | Reputational risk, global inconsistency | Strategic growth, compliance | Governance enables trusted global expansion | Board presentation |
| Tech leads | Legacy systems, data access gaps | Efficiency, system stability | Cloud and metadata mean scalable, secure architecture | Internal tech roadmap |
| Marketing | Customer engagement, data-driven insight | Brand reputation, customer loyalty | Personalised health insight through the wearable app | Marketing strategy meetings |
| Operations | Data governance consistency | Operational efficiency | Standardised practice across regions | Operations workshops |
| Staff | Data literacy, role clarity | Clarity, daily usability | Clear roles mean less friction | Intranet updates, training |
Part three, the board presentation
Current data infrastructure

The diagram is the argument for the migration in one picture. Seven discrete systems feed three new regions, several of the paths are unencrypted, and the two systems flagged as carrying security vulnerabilities are the legacy content management platform and the wearable app, which are respectively the oldest and the newest thing in the estate. The assessment put 63% of regional security measures below international standard, 48% of cross-border transfers without proper encryption, and 72% of wearable app user data reachable through unsecured interfaces.
Governance maturity
Overall maturity was assessed at 2.5 out of 5, with a target of 4.2 within twelve months. The per-dimension picture is more useful than the aggregate, because the two dimensions at the floor are the two that international expansion depends on.
| Dimension | Current stage | Target stage |
|---|---|---|
| Governance framework | Defined | Quantitative |
| Regional representation | Managed | Optimising |
| Cross-border accountability | Initial | Quantitative |
| Metadata management | Initial | Quantitative |
| Data quality | Managed | Quantitative |
Metadata gaps affect 78% of cross-border analytics and contribute to a 23% error rate. Regional representation is the only dimension targeted at the top of the scale, because it is the one the federated model depends on entirely.
Global regulatory constraints

The grid does the argument’s work. The UK and EU carry the highest exposure on patient consent, cross-border transfer and wearable monetisation, all at 5. India’s binding constraint is entirely different: data localisation at 5, with consent and transfer materially lower. The US peaks on data retention. Australia, the home market, is the lowest-risk column across the board.
Three regimes, three different first problems. In the UK and EU the binding instrument is GDPR; in India it is a localisation requirement; in the US it is HIPAA, where penalties attach per violation rather than as a proportion of turnover. The wearable app’s monetisation model is the single most exposed process in the organisation, and it is exposed on consent rather than on security, which means it cannot be fixed with encryption.
Ethical analytics framework
The framework embeds privacy-by-design across the development lifecycle rather than reviewing for privacy at the end, gives patients granular consent control instead of a single accept-or-leave decision, and addresses algorithm bias through training data diversity. It runs in four phases over six months, with consent architecture first because everything else depends on what the organisation is permitted to do, then bias prevention, then privacy-by-design in the build process, then the monetisation ethics framework.
Communication and the action plan

Four recommendations to the board: implement regional data lakes with standardised security protocols, establish regional governance councils with clear accountability, deploy privacy-by-design for the wearable app, and launch the phased communication strategy. UK operations serve as the initial pilot.
The sequencing on the chart is the part that matters. Stakeholder communication runs for the entire 18 months rather than being an event at the start, and governance councils are on the critical path: the compliance framework cannot begin until council formation completes, and privacy-by-design work depends on the compliance framework. Resourcing is four to six full-time staff in development and two to three per region in governance, at £2.2 million over 18 months, against a projected return of £4.5 million in avoided risk and £2.8 million in operational efficiency. Those return figures are projections built on the exposure model above rather than measured outcomes, and should be read as the case for approval rather than as a result.
References
Chisholm, M. (2017). Fundamental Concepts of Data Quality. In Data Quality for the Information Age (pp. 23-57). Morgan Kaufmann.
Crawford, K., & Paglen, T. (2019). Excavating AI: The Politics of Images in Machine Learning Training Sets. AI Now Institute.
DBHIDS. (2016). Data Governance Framework: Best Practices for Healthcare Organizations. Department of Behavioral Health and Intellectual disAbility Services.
Dennis, B. (2018). Using Data Quality and Data Management to Improve Patient Care. Journal of Healthcare Information Management, 32(2), 52-58.
Dennis, R. (2019). The Data Warehouse, the Data Lake, and the Future of Analytics. Data Management Review, 15(3), 28-35.
Department of Home Affairs. (2019). Data Retention Guidelines for Healthcare Providers. Australian Government Publishing Service.
Digital Guardian. (2017). Data Classification for Healthcare Organizations. Security Management Quarterly, 24(4), 78-92.
Floridi, L., & Taddeo, M. (2016). What is Data Ethics? Philosophical Transactions of the Royal Society A, 374(2083).
Ginsburg, G. S., Phillips, K. A., & Van Riper, M. (2018). Opportunities and Challenges of Data Analytics in Healthcare. New England Journal of Medicine, 378(25), 2368-2370.
Knight, R. (2023). Data Catalog Essentials: Building a Foundation for Enterprise Data Management. Data Management Review, 19(2), 45-52.
Leonelli, S. (2016). Locating Ethics in Data Science: Responsibility and Accountability in Global and Distributed Knowledge Production Systems. Philosophical Transactions of the Royal Society A, 374(2083).
Lord, N. (2019). Data Protection: Data In Transit vs. Data at Rest. Digital Guardian White Paper Series.
McGilvray, D. (2008). Executing Data Quality Projects: Ten Steps to Quality Data and Trusted Information. Morgan Kaufmann.
Newman, P. (2019). Security Think Tank: Data Architecture and Security Must Evolve in Parallel. Computer Weekly.
Noonan, H. (2019). Why a Data Governance Team Needs to Be the Start of Any Enterprise Digital Transformation. Tealium.
OAIC. (2021). Data Governance Council: What is it and Why is it Important? Office of the Australian Information Commissioner.
Paolini, J. (2016). Data Governance Implementation: A Content Analysis and Best Practice Recommendations. Information Management, 50(1), 35-42.
Seiner, R. (2019). The Non-Invasive Data Governance Framework, The Levels and Components. TDAN.com.
Shrivastava, S., & Chandrasekaran, K. (2019). Getting Cloud Data Lakes Right: Implementation Strategies for Healthcare. Journal of Healthcare Information Management, 33(4), 82-96.
Therriault, D. (2017). Data Security Practices for Healthcare Organizations. Journal of AHIMA, 88(11), 46-50.