Data & AI Governance

Data Classification & Governance Readiness

Turn classification from a label into a practical control decision.

A practical, risk-based approach to classifying data and connecting classification to ownership, access, sharing, retention, security, lineage and AI-use decisions.

Classification lifecycle

IdentifyAsset / purpose
owner / source
Assess ImpactDisclosure / integrity
availability / misuse
ClassifyPublic / Internal
Confidential / Restricted
Apply ControlsAccess / sharing
retention / monitoring
PropagateFollow downstream
copies and consumers
ReviewChange / AI / third party
migration / incident

Start with impact, not the label

  • Consider confidentiality, integrity, availability, privacy and misuse impact.
  • Include legal, contractual and regulatory obligations.
  • Consider business criticality, external distribution and analytics or AI use.

Classification establishes a minimum control baseline

The label should influence access, sharing, storage, encryption, retention, disposal, monitoring, third-party use and AI review. Context may require stronger controls than the baseline.

Classification inheritance

Downstream data should normally inherit the source classification unless there is a documented and approved basis to change it, such as verified aggregation, masking, tokenisation or de-identification.

Key relationship

Classification tells us the control requirement. Lineage tells us everywhere that requirement has to follow.