Data governance is easy to point to on paper. Frameworks exist. Policies are in place. Committees run. Roles have been assigned. But if the same issues keep resurfacing, data quality problems, mistrust in reporting, spreadsheet dependency, manual reconciliation, there’s usually an underlying problem. In our recent webinar with Owen Greenwood (Dufrain) Tim Bowes (Dufrain) and Navin Ahuja (Industry Specialist) we discuss what it takes to really have governance underpinned for the insurance sector.
That was the thread running through our recent webinar. As Owen Greenwood put it right at the start: “The question is rarely, do we have governance? It’s why isn’t it working?”
Governance has moved from “important” to unavoidable, not just because of regulation, but because AI adoption, fragmented data estates (often shaped by M&A), and increasingly complex third‑party ecosystems make weaker foundations harder to live with.
We’ve pulled out the most recognisable patterns that came through in our recent session, so you can quickly pressure‑test whether you’re seeing the same failure modes, and why they tend to persist even when governance “exists”.
1. AI is forcing a different standard of confidence
Governance has always underpinned insurance decision-making, reporting and service delivery.
What’s changed is how that data is now being used. It’s no longer just feeding reporting cycles, it’s being relied on in real-time decisions, operational processes and AI-driven outcomes.
That shift quietly raises the bar.
Data that was “good enough” for reporting starts to fall short when it’s being used to automate decisions or scale processes. Gaps that were previously absorbed through manual checks or domain knowledge become harder to contain.
As Tim Bowes put it: “AI doesn’t just remove governance problems. It actually industrialises them and exacerbates them.”
And this is where it starts to show up in practice.
AI use cases move forward, but stall when:
- stakeholders don’t have confidence in the data underpinning them
- assumptions that held at small scale don’t hold when applied more broadly
- questions about quality, lineage or ownership emerge too late in the process
At the same time, there is more scrutiny, not just of what the model is doing, but whether the data feeding it can be trusted, explained and evidenced as fit for purpose.
This is why governance is showing up more visibly in senior conversations. Not because it’s new, but because it now sits directly in the path of delivery.
2. The gap between proof of concept and production is where many organisations stall
One of the strongest themes was that many organisations confuse governance with the artefacts around it.
Navin Ahuja described people equating governance with “the wrapping… the frameworks, the policies, the committee meetings and artefacts and say, look, we’ve got data governance.”
But the test of governance isn’t whether it exists. It’s whether it produces data that is “trusted”, “well controlled”, and “fit for purpose”.
When that outcome isn’t there, the business defaults to familiar behaviours: reconciling reports, building alternative spreadsheets, debating whose number is right, all of which quietly eats time and confidence.
This is where insurers tend to get stuck: a governance programme can “go live” without becoming the thing people actually rely on.
3. The early warning signs are surprisingly consistent
Tim Bowes outlined patterns that many insurers will recognise immediately when governance isn’t landing in practice.
You’ll typically see some combination of:
- data quality tooling generating a large backlog of issues, with no clarity on which ones matter most to fix
- data owners and stewards named, but engagement dropping off over time (owners stop turning up; it becomes “data people” talking to themselves)
- teams spending time disagreeing about which report is correct, creating spreadsheets and manual reconciliations to compensate
These symptoms matter because they don’t just create inefficiency, they create hesitation. Decisions slow down, confidence drops, and operational teams build their own “truth” to keep moving.
4. “Shadow processes” are usually governance telling you where it doesn’t reach
Navin described manual workarounds, “shadow processes”, as a huge issue, because they reveal the gap between the operational reality and the governance model on paper.
His example will feel familiar: an underwriter frustrated with turnaround times creates an Excel quotation workaround. The key point wasn’t judgement, it was realism:
“They’re not bad actors… they are business people faced with a real problem.” – Navin Ahuja
This is often where governance fails most quietly: the business routes around friction, the workaround becomes normal, and the governance controls don’t cover what is actually happening day‑to‑day. Tim reinforced this from a process angle, governance analysis often doesn’t capture the manual workarounds that have evolved over time.
If you want a fast diagnostic: where are spreadsheets doing “critical path” work that your formal processes assume sits somewhere else?
5. Ownership breaks when it’s assigned as a title rather than lived as accountability
Ownership came through as the hinge point. Tim described how data ownership is frequently a side‑of‑desk responsibility for busy people, without enough education or operational connection to carry the accountability.
Navin added an important nuance: even when roles exist, the wrong people are often named owners. Effective ownership sits with people who are actually impacted by the data, “They feel the pain.”
When ownership isn’t close to impact, three things tend to follow:
- issues are logged, but not prioritised or resolved with urgency
- governance forums lose energy because accountability isn’t real
- the business sees governance as bureaucracy “pushed down” rather than something that helps them deliver
6. Controls often grow reactively and that’s how gaps (and duplication) happen
Navin’s controls point is one insurers should take seriously. Rather than designing controls from first principles (risk → control), many data control environments evolve reactively, issue happens, add a control; audit finding, add a control; regulatory pressure, add a control.
The outcome is uneven: some areas over‑controlled, some under‑controlled, and in worst cases, gaps remain. He also called out the irony: insurers are excellent at systematic risk management, but data controls can be surprisingly reactive in practice.
The practical improvement discussed was to treat controls as an integrated system:
- don’t rely only on detective indicators (DQ metrics), build preventative controls too (mandatory fields, system logic, reference data processes)
- assume controls fail and build safety nets, with an intentional mix of preventative and detective coverage
That’s when governance starts to behave like the kind of risk discipline insurers are already good at.
7. Change is where governance gets undone and change teams are the blind spot
Even when governance is well implemented, it can be undone during transformation if delivery teams can’t see or use the governance information they need (lineage, quality rules, current quality of critical data).
Tim Bowes was explicit: “Change teams are often the blind spot… they can undo months or years of good data governance work without even realising it.”
This is why the session repeatedly returned to governance being embedded into delivery, “governance by design” rather than governance as a repair job after the fact.
It also explains why some insurers feel like they are constantly rebuilding governance rather than steadily improving confidence.
Watch the full discussion
Owen closed with a question that cuts through:
“Do your data owners genuinely own the data… or have they simply inherited the responsibility and they don’t have the time or the authority or even the incentive necessarily to improve it?”
If the honest answer is “inherited”, it usually explains why the same patterns keep resurfacing, even after governance programmes have “completed”.
If you or your teams are facing any of these challenges in our blog above, we’re offering a Governance Power Hour to get your AI on track, if you would like to book a session please contact: enquiries@dufrain.co.uk, for more information.
These highlights capture the strongest themes, but the full discussion goes deeper into the examples and nuance, including where to start pragmatically (use change as leverage, anchor to high‑value use cases, take a risk‑based approach where data quality cannot be wrong).
