A working AI governance framework starts with data, not policy. Sharma Vedula of Data Society explains what enterprise leaders must audit before they build.

Data Before Models: How to Build an AI Governance Framework Your Enterprise Will Actually Use

Most conversations about AI governance start with policy: acceptable use guidelines, ethical principles, model risk frameworks. These matter. But they tend to arrive before the harder, more foundational work of understanding what the organization’s data actually looks like, who owns it, who can access it, and whether any of it can be trusted.

Sharma Vedula, Head of Solutions at Data Society, has a principle he returns to with every enterprise client before an AI model goes anywhere near production.

“You can’t really bolt AI onto a broken foundation and expect it to hold.”

That broken foundation is almost always a data problem before it is a governance problem. And the governance frameworks that actually work in practice are the ones built from the data layer up, not from a policy document down.

WHY MOST AI GOVERNANCE FRAMEWORKS FAIL BEFORE THEY START

AI governance frameworks fail for two predictable reasons. The first is that they are built as compliance artifacts, documents that satisfy a legal or regulatory requirement, rather than operational guides that change how people work. The second is that they assume the underlying data is in better shape than it is.

When Data Society runs a data readiness audit, the finding is consistent across industries and organization sizes. Vedula describes what the team typically encounters:

“Most organizations have more data than they realize, but it’s fragmented, duplicated, or siloed in ways that make it effectively unusable.”

A governance framework layered on top of unusable data does not fix the data. It creates a false sense of security while the actual risk remains. For enterprises looking to build an AI governance framework that functions in practice rather than on paper, the sequence matters: audit the data first, then build the governance around what actually exists.

Learn more about Data Society’s AI advisory services: https://datasociety.com/data-and-ai-advisory-services/

THE FOUR-PART DATA READINESS AUDIT

When Vedula’s team evaluates an enterprise for AI readiness, they look at four things at once. Understanding these four dimensions is the practical starting point for building a governance framework that holds.

The first dimension is quality. Is the data accurate, complete, and consistent across systems? This seems basic, but it is where most audits surface the most problems. Data that is technically present is often inconsistently labeled, missing key fields, or stored in formats that were never designed to be queried at scale.

The second is ownership. Who is responsible for each data set? This question gets urgent fast when automated AI systems enter the picture. When a model makes a decision based on a data set that no one technically owns, accountability gaps emerge quickly.


The third is access controls. Who can see the data, who can modify it, and is there an audit trail? Vedula is direct about the stakes here:

“AI amplifies what’s already there. If your data foundation is solid, AI makes you faster. But if it’s not, AI can make your problems bigger and faster.”

The fourth is security. AI pipelines often touch sensitive data at scale: PII, financial records, proprietary business information. If access controls are not properly scoped, the pipeline becomes an efficient exposure mechanism. Vedula’s team looks at encryption in transit and at rest, how access is scoped by role, and whether monitoring systems would catch an anomaly in real time, not after the fact.

See the full landscape of enterprise AI readiness: https://datasociety.com/the-2025-ai-readiness-report-insights-to-build-your-2026-strategy/

GOVERNANCE IN PRACTICE: WHAT CITY OF DALLAS AND THE IDB SHOW US

Two Data Society engagements illustrate how governance frameworks have to flex to fit operational reality.

The City of Dallas needed to modernize how 42 city departments worked with data across teams that had very different systems, different maturity levels, and different user needs. A single top-down governance structure applied uniformly across all 42 departments would have created more friction than it resolved. The answer was to build toward a shared data vocabulary and capability baseline that could flex as each department evolved. The governance framework had to meet each department where it was, not force everyone into a single model.

The Inter-American Development Bank engagement required building machine learning tools to assess infrastructure risk and protect major investment portfolios. As Vedula puts it:

“You cannot build a reliable risk model on top of messy ungoverned data. Before any model gets built, you need to know where the data comes from, who owns it, how current is it, and whether you can actually trust it. That audit isn’t optional. It’s the foundation everything else sits on.”

In both cases, the governance framework was not a document that preceded the work. It was built incrementally as the teams developed a clearer picture of what the data actually looked like and what the operational requirements actually demanded.

See Data Society case studies: https://datasociety.com/resources/#case-studies

THE SECURITY LAYER MOST GOVERNANCE FRAMEWORKS MISS

AI introduces a category of security risk that traditional IT governance frameworks were not designed to handle. Classic software systems fail in predictable ways: a database either returns a result or it does not. AI models can return output that appears confident and is completely wrong, or that accurately reflects a data set that was never supposed to be accessible.

Vedula identifies the specific vulnerabilities his team looks for most closely. Encryption across the full pipeline, both in transit and at rest, is table stakes. Access scoping, ensuring that a model only touches the data it actually needs to touch, is where most enterprises have gaps. Real-time monitoring that would catch an anomaly before it becomes a breach is where almost everyone is underinvested.

Building these controls into an AI governance framework is not optional for organizations handling sensitive data at scale. It is the difference between a governance framework that manages risk and one that creates a false sense of security while leaving material vulnerabilities unaddressed.

Learn more about Data Society’s AI advisory and implementation services: https://datasociety.com/data-and-ai-advisory-services/

Frequently Asked Questions

At minimum: data quality standards, data ownership and access controls, an audit trail for how models use data, model monitoring for drift and failure modes, fallback procedures for when models behave unexpectedly, and clear accountability for who owns each piece of the system. Security controls, including encryption and anomaly detection, are also essential for any system handling sensitive data.

How do you start building an AI governance framework?

Start with a data readiness audit. Before writing a single policy document, understand what data exists, who owns it, how current it is, and whether it can be trusted. The governance framework should be built around what actually exists, not what is assumed to exist. Most organizations find more gaps in this phase than they expected.

The highest-stakes vulnerabilities are access control failures that expose sensitive data through AI pipelines, model drift that goes undetected until it causes downstream errors, and accountability gaps when no one technically owns the data a model is using. AI amplifies whatever is already in the data, which means governance failures at the data layer propagate at scale.

Traditional IT governance assumes systems fail in predictable ways. AI systems fail differently: a model can return confident, plausible output that is wrong, which requires a different kind of monitoring and a different accountability structure. AI governance also has to account for data quality in ways that traditional IT governance often does not, since model performance is directly tied to the quality of the training and inference data.

BUILD A GOVERNANCE FRAMEWORK THAT HOLDS UNDER PRESSURE

If your organization is building or scaling AI systems and does not have a data readiness audit as the foundation, the governance framework is sitting on uncertain ground. Data Society works with enterprise and government clients to run that audit and build governance structures that are built from the data layer up.

Talk to Data Society’s advisory team about your AI governance needs:
https://datasociety.com/contact/

Don’t wanna miss any Data Society Resources?

Stay informed with Data Society Resources—get the latest news, blogs, press releases, thought leadership, and case studies delivered straight to your inbox.

Data: Resources

Get the latest updates on AI, data science, and our industry insights. From expert press releases, Blogs, News & Thought leadership. Find everything in one place.

View All Resources
  • Data Before Models: How to Build an AI Governance Framework Your Enterprise Will Actually Use

    July 20, 2026

    Read more

  • Your AI Skills Gap May Not Be A Gap At All

    July 13, 2026

    Read more