Devensa Advisory
Get started

Five Data Findings That Repeat in Every Audit

Poor data quality costs the average company $12.9M a year. See the five data findings that repeat in audit after audit and what actually fixes them.

Devensa Advisory 6 min read
Two lines for the finance ledger and product analytics converge on one reported number once governance is applied.

Ask finance and sales for the same number, active customers this quarter, and there's a real chance you get two different answers, both pulled from real systems by people who aren't lying to you. Poor data quality costs the average organization $12.9 million1 a year. Audit after audit, it's the same five findings behind that number, regardless of the company or the industry.

The Five Findings, Every Time

No Single Source of Truth

Finance counts anyone with an active subscription. Sales counts anyone who's ever signed a contract. Neither team is wrong on their own terms, and nobody in the building has forced those two definitions into agreement, so both numbers show up in different decks in the same quarter.

Ownership Stops the Moment Data Lands in Storage

IT owns the warehouse and the pipeline, but ask who's accountable for whether the data flowing through it is actually correct, and the room usually points at someone else. Data quality was never written into anyone's job description, so it became everyone's ambient responsibility and nobody's actual job.

Access Accumulates and Is Never Revoked

Every new hire, project, and integration adds another layer of permissions, and almost nobody ever builds a process to remove it, only to grant it. A database with hundreds of accounts holding read access, most of which haven't touched the data in a year, is closer to the norm than the exception.

Quality Checks Happen After the Damage

A number turns out wrong in a board deck, a decision gets made on it, and only then does anyone open the pipeline to see what broke. The fix that gets built afterward usually patches the one report that broke, without anyone asking how many other reports are quietly running on the same broken assumption right now.

Retention Policies Exist Without Automation to Enforce Them

A retention policy can specify exactly what should be purged and when, in language precise enough to survive legal review, while nothing in the actual infrastructure enforces a single word of it. The company ends up holding data it wrote down, in an official document, that it said it wouldn't hold.

Why It Costs More Than It Looks Like It Should

72% of leaders say bad data has already cost their organization $500,000 or more, and 37% put the damage above $1 million.2 61% say they personally second-guess their own company's data at least once a month. Data quality and governance issues are cited by nearly half of business leaders, 45%, as a top barrier to scaling AI.3 AI models inherit and amplify whatever quality problems already exist in the data feeding them, which makes every one of these five findings a live risk to every AI initiative built on top of it.

The Framework Behind a Real Fix

Most formal data governance programs are built on some version of the DAMA-DMBOK framework, organized here around six core pillars.

  • Data ownership and stewardship: a named business owner accountable for each critical data domain, not an IT default.
  • Data quality management: standards for accuracy and completeness, measured continuously rather than discovered after a bad decision.
  • Master data management: one official definition for core metrics, replacing the version each department built on its own.
  • Metadata and data cataloging: a record of what data exists and what it means, instead of relying on institutional memory.
  • Access governance: permissions reviewed in both directions, who has access and who's actually used it.
  • Data lifecycle and retention: enforced rules for how long data is kept, backed by automation rather than a policy alone.
$12.9 million, the average annual cost of poor data quality to an organization, Gartner.

Getting Departments to One Number

  • Force a single definition for your most-cited metrics: in writing, with one named owner per metric, before building another dashboard on top of it.
  • Run access reports in both directions: who has access, and separately, who's actually used it in the past twelve months.
  • Attach automation to every retention rule: a policy that specifies a purge date and enforces nothing is a description, not a control.
  • Fix the pattern, not just the incident: when a number breaks a board deck, check how many other reports share the same broken assumption.
  • Treat data quality as a named business accountability: not a byproduct of whoever happens to own the infrastructure underneath it.

Frequently asked questions

What's the difference between data governance and data management?

Data management is the operational work: pipelines, databases, infrastructure. Data governance is the policy and accountability layer above it: who owns a dataset, what quality standard it must meet, and who answers when it doesn't. Strong data management with no governance still produces disagreeing departments.

Should IT or the business own data governance?

The business. IT typically owns the infrastructure, but data quality is a business outcome. The strongest programs assign a named business owner to each critical data domain, with IT as a partner on the underlying systems rather than the sole accountable party.

What is master data management, in plain terms?

It's the practice of establishing one official definition for core metrics, active customer, closed deal, so every department works from the same number instead of a version it built independently. Without it, two departments can both be technically right and still disagree.

How do I know if my organization has a real data governance gap right now?

Ask two departments for the same metric and see if the numbers match. If they don't, and nobody can immediately explain why in a way that resolves it, that's the gap. What would happen if you asked that question in your next leadership meeting?

If you asked two departments for the same number right now, are you confident they'd match?

Sources

  1. Gartner, cited in IBM, “The True Cost of Poor Data Quality.” https://www.ibm.com/think/insights/cost-of-poor-data-quality
  2. OneStream 2026 survey, cited via Accounting Today. https://www.accountingtoday.com/news/poor-data-governance-not-just-embarrassing-its-expensive
  3. IBM, “The True Cost of Poor Data Quality,” citing IBM Institute for Business Value research. https://www.ibm.com/think/insights/cost-of-poor-data-quality

Originally published on the Devensa blog.

Keep reading

All insights →
Data Governance

Who Actually Owns the Data?

Poor data quality costs the average organization $12.9 million a year, according to Gartner. See why the owner-versus-custodian confusion is usually to blame.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Put a name next to every gap.

A Current State Assessment scores where you are across the six domains and sequences what comes next, with owners attached.

Get started Explore Data Governance