Government agencies are accelerating AI adoption and digital services, while public-data obligations remain demanding. Government data governance must support modernization under the Freedom of Information Act (FOIA), Criminal Justice Information Services (CJIS), the Federal Records Act, privacy, and interagency-sharing requirements. These obligations shape daily decisions about data access, retention, disclosure, and sharing.
According to Deloitte’s 2025 Federal Chief Data Officer Survey, 78% of federal organizations reported using AI, up from 67% in the previous survey.
The increase reinforces the need for stronger governance over the data supporting AI initiatives as adoption expands.
Government technology and data leaders need governance that supports new data uses and withstands legal scrutiny. Leaders building a formal program must translate statutory obligations into operating rules, ownership, and evidence. Agencies with informal governance need to identify gaps before policies, access decisions, or sharing practices fail under audit or public-records scrutiny.
The guide explains how agencies can formalize legally defensible controls, accountability, and compliant sharing as modernization expands. It also shows how to assess readiness and evaluate supporting software.
What is government data governance?
Government data governance is the system of policies, roles, standards, and controls governing how agencies classify, retain, access, audit, and share public data. Public sector data governance turns FOIA, CJIS, interagency-sharing requirements, and National Institute of Standards and Technology (NIST) standards into enforceable operating rules.
Five pillars form the operational foundation:

-
Classification (FOIA, Federal Information Processing Standard (FIPS) 199): Apply impact categories and identify information that may require protection or disclosure review.
-
Retention (Federal Records Act, Privacy Act): Apply authorized retention and disposition requirements to government records.
-
Access control (CJIS, Federal Information Security Modernization Act (FISMA), least privilege): Restrict access according to role, authorization, and data sensitivity.
-
Audit trails (FISMA, Federal Risk and Authorization Management Program (FedRAMP)): Record activity so agencies can demonstrate how controls operated.
-
Interagency data sharing: Use Memoranda of Understanding (MOUs), Data Use Agreements (DUAs), and statutory authority to define permitted sharing and applicable controls.
Public-sector vs. private-sector governance
The underlying data governance disciplines also apply in private organizations. Government agencies must implement them within statutory and regulatory boundaries.
Private companies can choose their classification and retention approaches. Federal agencies must also account for FIPS 199 and Federal Records Act requirements. The OPEN Government Data Act adds an open-data obligation for eligible, non-exempt government data.
Why formalize now: the maturity gap and what is at stake
Formal federal data governance gives agencies clear decision rights, accountable owners, and evidence for oversight. Federal Data Strategy actions direct agencies to use governance bodies and maturity assessments to identify gaps, set priorities, and guide investment. Together, these actions create a formal path from baseline assessment to remediation.
The maturity gap
Government leaders increasingly connect AI readiness with stronger data practices, yet operational readiness remains uneven. The National Association of State Chief Information Officers (NASCIO) and EY surveyed leaders from 46 states.
According to NASCIO and EY’s Data Quality Report 2024, 95% of surveyed state CIOs and CDOs said increased AI adoption affects data management, yet only 22% had a dedicated data-quality program. Another 57% rated their data-quality maturity as reactive, highlighting the gap between recognizing the need for better data practices and operationalizing them.
The findings measure data-quality readiness, so they serve only as a proxy for broader governance maturity. They still expose an operating gap between recognizing the need and establishing ownership, controls, and evidence.
OvalEdge expert insight: Recognition does not create governance maturity. Agencies close the gap when policies become repeatable workflows with named owners, documented controls, and reviewable evidence.
What happens without governance
Weak governance creates exposure when agencies must explain how they handled regulated or sensitive information:
-
FOIA responses slow down or become inconsistent when records officers cannot distinguish releasable information from material that may qualify for an exemption.
-
CJIS audits expose control gaps when agencies cannot show who accessed Criminal Justice Information (CJI), why access existed, or whether controls remained current.
-
Interagency sharing becomes harder to defend when agencies lack an agreement documenting legal authority, permitted use, safeguards, retention, and accountability.
The result is weaker evidence when auditors, records officers, or partner agencies ask how a decision was made.
Data classification under FOIA and public records law
A government data management framework needs classification rules for two purposes. Agencies must assess the impact of unauthorized disclosure or loss. Records teams also need enough context to identify information that may require protection or disclosure review.
NIST FIPS 199 impact levels in practice
FIPS 199 categorizes federal information and information systems by the potential impact of losing confidentiality, integrity, or availability. Agencies assign Low, Moderate, or High values based on potential harm to operations, assets, or individuals.
-
Low: A compromise could cause limited adverse effects.
-
Moderate: A compromise could cause serious adverse effects.
-
High: A compromise could cause severe or catastrophic adverse effects.
FIPS 199 applies those impact values to information types and systems. Agencies can carry the resulting categorization into datasets, records, and forms that contain the information.
A governed data catalog provides the inventory and metadata context behind that work. It can show what information exists, where it resides, who owns it, and how teams classify it. Legal and records-management teams still determine which statutory requirements apply to a record.
Disclosable vs. exempt data
FOIA disclosure review requires separate legal analysis from FIPS 199 security categorization. Records officers need metadata and context to identify information that may fall under a statutory exemption. The Department of Justice maintains guidance on the nine FOIA exemptions and the requirements agencies apply when withholding information.
The OPEN Government Data Act creates a parallel obligation. Agencies must publish eligible public data in open, machine-readable formats while preserving privacy, confidentiality, and security protections.
For records teams, classification must therefore support both protection and lawful disclosure. Weak metadata can make either task slower and harder to defend.
Did you know? A FOIA exemption alone does not always justify withholding. Agencies generally must also reasonably foresee harm to an interest the exemption protects, or identify a law that prohibits disclosure.
Retention and disposition under federal and state records law
Retention and disposition govern how long agencies keep records, when they transfer or destroy them, and how they document authorized actions. For data governance for government agencies, records controls connect legal obligations with ownership, schedules, and evidence across the record lifecycle.
State and local agencies follow their own records laws. Federal requirements can also apply to federally funded programs or regulated information, depending on the program and data involved.
Federal Records Act and Privacy Act requirements
Federal records include information agencies create or receive while conducting public business when that information documents government activity or has informational value. The National Archives and Records Administration (NARA) requires agencies to schedule federal records under approved disposition authorities.
NARA’s General Records Schedules cover common administrative records, while agency-specific schedules address unique program records. Agencies must follow the applicable authority when retaining, transferring, or disposing of records.
For Privacy Act systems of records, agencies must also follow rules for maintaining, using, and disclosing records about individuals. Effective lifecycle controls connect schedules, ownership, and disposition evidence to the broader pillars of data governance.
Disposition evidence should show which schedule applied, who authorized the action, and when the agency completed it. The evidence helps teams demonstrate that they followed the approved authority.
For example: A benefits application and a public-comment submission may belong to different record series. The agency must apply the correct schedule to each and document the resulting disposition.
Access remains governed throughout that lifecycle. The next control question is who can use the record and what activity the agency must document.
Access control and audit trails under CJIS, FISMA, and least-privilege requirements
Public sector data governance must control who can use protected data and preserve evidence of that activity. CJIS requirements govern access to CJI, while FISMA and NIST controls extend access governance, least privilege, and auditable activity across federal information systems.
CJIS authentication and access requirements
The Federal Bureau of Investigation (FBI) CJIS Security Policy requires agencies to identify and authenticate organizational users. Version 6.1 requires multi-factor authentication (MFA) for privileged and non-privileged accounts that access applicable systems.
Personnel controls matter as well. Agencies must complete required screening before granting qualifying access to unencrypted CJI. They must also review or revoke access when employment or responsibilities change.
A broader data access management practice connects these requirements to documented users, roles, assets, approvals, and review cycles.
Role-based access beyond CJIS
Agencies should extend the same discipline to non-CJIS systems through role-based access control and least-privilege principles. Each role should grant only the access required for assigned duties.
Effective role governance also needs a current inventory of assets, sensitivity classifications, accountable owners, and mappings between roles and permissible uses.
OvalEdge expert insight: Role-based access weakens when permissions lose their data context. A governed inventory helps reviewers connect access decisions with asset ownership, sensitivity, and intended use.
Periodic reviews should test whether each role still matches current duties. Teams should also remove stale permissions when staff transfer, leave, or change responsibilities.
What FISMA requires from audit logs
FISMA establishes federal security-management obligations, while NIST Special Publication 800-53 defines supporting controls. Audit records should capture the event, time, location, source, outcome, and associated identity.
Agencies must also protect audit information from unauthorized alteration or deletion and retain it according to defined requirements. These controls preserve the evidentiary value of access records.
For FedRAMP-aligned cloud environments, current monitoring requirements emphasize centralized analysis and tamper-resistant logging through a Security Information and Event Management (SIEM) capability or equivalent.
The Federal Zero Trust Data Security Guide further connects governance and security through data inventory, categorization, protection, and access controls. The Federal Chief Data Officer Council and Chief Information Security Officer Council jointly developed the guide.
Audit evidence becomes especially important when data crosses agency boundaries. Agencies need records showing what they shared, who accessed it, and which controls applied.
Interagency data sharing: MOUs, data use agreements, and legal authority
A government data management framework must govern interagency sharing before data moves between organizations. Agencies need legal authority, a defined purpose, agreed controls, and accountability for recipient use. MOUs, DUAs, and other information-exchange agreements turn those requirements into operating terms.
What can legally be shared?
Technical access does not establish legal authority to share data. The arrangement should identify the statute, regulation, routine use, program authority, or other basis permitting disclosure. It should also define what the recipient may receive and use.
A well-structured agreement should specify:
-
Purpose, scope, and permitted uses.
-
Data elements and systems covered.
-
Access, security, and incident responsibilities.
-
Retention, disposition, and redisclosure limits.
-
Legal authority supporting the exchange.
-
Ownership, review, termination, and accountability requirements.
Without an executed agreement, agencies may struggle to prove the recipient’s authority, safeguards, permitted use, and compliant disposition.
Agencies should also maintain enough metadata to identify which governed assets fall under each agreement. The mapping makes later reviews and renewals more precise.
CJIS interagency connection agreements
CJIS requires formal information-exchange agreements before agencies exchange CJI. Those agreements define responsibilities, data ownership, and applicable security controls for the participating parties.
The correct agreement depends on the relationship. A Management Control Agreement (MCA) applies when a noncriminal-justice agency performs criminal-justice functions for a Criminal Justice Agency (CJA). The MCA preserves the CJA’s management authority over that function.
When agencies disseminate Criminal History Record Information (CHRI) beyond the primary agreement, the releasing agency must log the disclosure. The log creates an auditable record of secondary sharing.
Governance structure: who owns these decisions
Government data governance needs explicit decision rights across enterprise and program levels. For data governance for government agencies, the CDO coordinates enterprise governance. Governance bodies set shared policies, while owners and stewards apply those standards to specific data within their authority.
The CDO's role under the Evidence Act and Federal Data Strategy
The Foundations for Evidence-Based Policymaking Act established agency CDO responsibilities for data lifecycle management and governance. Office of Management and Budget (OMB) Memorandum M-19-23 directs agencies to maintain Data Governance Bodies chaired by their CDOs.
Federal Data Strategy practices give that structure an operating direction. They cover stewardship, protection, sharing, inventory, maturity assessment, and appropriate data use.
Under the OPEN Government Data Act, agencies also carry responsibility for cataloging and publishing eligible data in open, machine-readable formats. Privacy and security protections still apply.
Centralized vs. federated governance
A centralized model places most governance decisions with an enterprise body. A federated model sets common standards centrally while program offices retain data ownership and stewardship.
The Department of Labor provides a public example of federation. Its model gives component agencies data ownership while department-wide governance bodies coordinate shared standards and stewardship.
Federation works when local teams have defined authority and enterprise leaders retain clear escalation paths. Teams should document which decisions require central review and which remain local.
Pro Tip: Document decision rights across enterprise policy, domain ownership, and steward execution. Use a Responsible, Accountable, Consulted, and Informed (RACI) matrix, then track escalation volume and decision turnaround time.
Public-sector data governance readiness checklist
A readiness review should test whether governance requirements exist as working controls with ownership and evidence. Agencies building a program can use the checklist as an implementation sequence. Agencies with informal governance can use it to identify controls that lack consistent execution.
|
Constraint |
Verify |
Primary owner |
|
FOIA and public records classification |
Records carry enough context to support disclosure and exemption review. |
Records Officer / Data Steward |
|
FIPS 199 security categorization |
Information types and systems have documented Low, Moderate, or High impact categorizations. |
Chief Information Security Officer / System Owner |
|
Retention and disposition |
Records map to approved schedules, and teams can produce disposition evidence. |
Records Officer |
|
Access control and auditability |
Roles follow least privilege, access reviews occur, and activity logs remain reviewable. |
Chief Information Security Officer / Data Owner |
|
Interagency data sharing |
Each exchange has legal authority, permitted use, controls, retention terms, and accountable parties. |
Legal / Privacy / Program Owner |
|
Governance accountability |
CDOs, governance bodies, owners, and stewards have documented decision rights and escalation paths. |
CDO / Data Governance Body |
For each row, mark the control as met, partial, or gap. Link supporting evidence, assign an owner, set a due date, and review unresolved gaps through the governance body.
Common mistakes that break governance under these constraints
The most damaging mistakes disconnect classification, sharing, access, and logging from their legal context, accountable owners, or review requirements. Weak federal data governance often fails when teams cannot produce evidence behind a decision.
-
Using sensitivity labels as FOIA decisions: Security categories can flag risk, but they do not establish the statutory basis for withholding a record.
-
Enabling sharing before finalizing agreements: Agencies lose documented authority, permitted-use boundaries, and accountability when technical access precedes the governing agreement.
-
Treating access as a technology-only function: Governance also requires business justification, accountable ownership, and periodic review of permissions.
-
Keeping logs without integrity or retention controls: Audit evidence weakens when agencies cannot prove that records remained intact and available for the required period.
Each failure leaves weaker evidence that teams followed the required control. Ask whether the agency can produce the governing rule, current owner, and execution evidence. A missing element signals a remediation priority.
What to look for in government data governance software

Government data governance software should help agencies classify sensitive data, control access, document governance decisions, support interagency-sharing requirements, and preserve audit-ready evidence. The strongest platforms connect these controls to shared metadata, ownership, policies, and workflows so teams can apply requirements consistently across systems.
Those capabilities also provide a practical evaluation test. Agencies should assess whether a platform can move governance requirements from written policy into repeatable, reviewable processes without separating classification, access, sharing, and audit activity into disconnected tools.
Look for capabilities that support:
-
Sensitive-data classification: Detect personally identifiable information (PII), protected health information (PHI), CJI, and agency-defined categories. Preserve relevant FIPS 199 context where agencies use it.
-
Auditable activity: Preserve protected, searchable, and exportable records of access and approvals. Confirm integrity controls and SIEM integration where agency requirements call for them.
-
Role-based access workflows: Connect access requests to sensitivity, ownership, approval rules, periodic reviews, and least-privilege requirements.
-
Interagency-sharing oversight: Catalog shared assets and associate them with owners, classifications, approved uses, and relevant agreements or legal authority.
-
Government-appropriate deployment and security: Confirm that the deployment model meets agency requirements. For cloud services subject to FedRAMP, verify the offering’s current status through the official FedRAMP Marketplace.
Evaluation should focus on whether reviewers can trace a governance decision from the underlying asset to its owner, applicable policy, approval, and supporting evidence.
A data governance platform should give stewards and owners a shared environment for applying policies, reviewing exceptions, and maintaining governance evidence as data changes.
Platforms like OvalEdge can connect cataloging, classification, lineage, ownership, and access workflows across a unified governance environment. This gives teams the context needed to keep controls visible and reviewable as data changes.
Conclusion
Formal government data governance builds classification, retention, access, audit, and sharing practices that can withstand FOIA, CJIS, FISMA, and interagency review. Effective data governance for government agencies gives teams a defensible way to apply those requirements across programs and systems.
The next step is to assess which controls still depend on informal decisions. Agencies should verify decision ownership, applicable authority, retained evidence, and the path for reviewing exceptions. Prioritize gaps affecting sensitive data, external sharing, or high-volume public requests. The Evidence Act and Federal Data Strategy provide the structural backbone through CDO leadership, governance bodies, maturity assessment, and open-data responsibilities.
OvalEdge helps agencies operationalize this work through its unified data governance platform. It connects governed metadata, ownership, classification, lineage, and policy-driven access workflows. Stewards and decision-makers gain clearer context for applying and reviewing controls.
Book a demo with OvalEdge to see how governed metadata, lineage, ownership, and access workflows can support your agency’s FOIA, CJIS, and interagency review processes.