Data Governance Framework for Federal Agencies
Federal agencies can now align data governance with evolving security and AI demands.

Federal data governance runs on four layers stacked like sediment: a statute at the bottom, then an implementation memo, then a ten-year strategy, then a follow-up memo that closes the loopholes nobody caught the first time. The Foundations for Evidence-Based Policymaking Act (the Evidence Act), P.L. 115-435, is the bedrock. Everything else described here, the Chief Data Officer role, the governance boards, the zero trust guidance, the AI readiness scramble, sits on top of it, and if you don't understand the stack order, you'll misread every layer above it.
That's the actual subject of this piece: how a law passed in 2019 turned into the operational scaffolding agencies now use to manage data, secure it, open it to the public, and, increasingly, feed it into AI systems that didn't exist when the statute was drafted. Let's take it layer by layer.
How the CDO role and the CDO Council translate statute into agency-level governance
The Evidence Act names a specific officer responsible for data governance in each CFO Act agency: the Chief Data Officer. Not the CIO. Not a working group. A person, with a title, whose job includes lifecycle data management as a core function, not a side project bolted onto someone's existing portfolio. That distinction matters more than it sounds like it should, because agencies love a good committee, and the statute deliberately avoided giving one all the authority.
The Act also created the CDO Council, a body meant to develop shared resources for federal CDOs, evaluate emerging technology, and coordinate with sister councils like the CIO Council. Here's where the story gets a little absurd, in the way federal governance stories often do: the CDO Council sunset in December 2024 because Congress didn't reauthorize it in time. Gone. One month later, on January 15, 2025, OMB administratively re-established it via M-25-06, the very same day it dropped M-25-05, the long-awaited open data implementation guidance. Two major governance documents landed on the same day, one of them resurrecting the body meant to interpret the other. That timing likely reflects how deadlines and lapses collide in an election-transition year rather than any deliberate design. The Council updated its Charter again in September 2025, presumably to reduce the odds of a repeat lapse.
The CIO Council runs parallel to all this, handling IT governance, and the two are supposed to coordinate rather than merge. Data governance and IT governance both need to reach the same destination, but they follow separate lanes rather than a single merged path.
The Data Foundation and Deloitte's 5th Annual CDO Survey gives a useful snapshot of where the role actually stands. Over 90% of CDOs report having an organizational data strategy in place, meaning the planning infrastructure is essentially built across government. But the same survey surfaces friction underneath that number: almost half of CDOs cite conflicting statutory or legal authorities as a barrier, up nearly 15 percentage points from 2023, and 60% say they need more OMB guidance to actually implement Evidence Act provisions. Another 72% say an updated Federal Data Strategy implementation plan would help them do their jobs, and over 80% point to budget constraints as a persistent obstacle, with leadership support cracking the top three barriers as well.
A companion 2025 CDO Council Member Survey, covering 29 CFO and Non-CFO Act agencies, found 80% of respondents have held the role more than a year, and 61% of agencies have maintained a CDO function for over five years. So the role is maturing. The guidance it depends on is still catching up. That gap, between a maturing office and an immature rulebook, is the throughline for most of what follows in this piece.
The four structural components every agency framework requires
Strip away the acronyms and every agency framework needs the same four load-bearing components. Skip one, and the whole structure wobbles.
The data governance body comes first, chaired by the CDO, meant to make strategic and tactical calls collaboratively rather than by decree. Agencies aren't required to invent this from scratch: Resources.data.gov offers a Data Governance Steering Committee Charter template and a Data Governance Advisory Group Charter template, giving agencies a standardized starting document rather than a blank page. GSA's version, the Evidence-Based Data Governance Executive Board (EDGE), oversees AI and data governance together and developed standard open data procurement language for contracts, which is a more concrete accomplishment than the acronym suggests. In April 2025, GSA went further and published Roles and Responsibilities for its Data Evidence Governance Board, pushing open data obligations down to Staff and Service Office-level boards. That's governance that actually reaches program offices instead of stopping at the CDO's desk.
Data stewardship is the connective tissue. OPM's Business Data Steward role is the model here: a program-level person who understands data in its business context and defines the terms, rules, and quality standards that make that data usable outside its home office. Without stewards, a governance body can issue strategy all day and nothing on the ground changes.
Data quality governance needs to be a standing function, not a once-a-year audit somebody remembers to run before the inspector general shows up. GSA assembled a Data Quality Working Group led by its Statistical Official, explicitly tasked with continuous improvement and, notably, readiness for AI and machine learning. That last part is worth sitting with, because it foreshadows the entire AI readiness discussion later in this piece: quality standards written for humans reading reports are not automatically good enough for models training on that same data.
Ethics and decision frameworks round out the set. The Data Ethics Framework, built to support the Federal Data Strategy, helps leaders make calls across the acquire-manage-use lifecycle, and the Data Governance Playbook supports maturity assessments so agencies can benchmark where they stand and prioritize what to fix next.
These four pieces are interdependent in a way that's easy to state and easy to underestimate. A governance body without stewards has strategy but no operational reach. Quality standards without a governance body have no authority behind them. Ethics frameworks without either are just nicely formatted PDFs. You need all four, functioning together, or you have the appearance of governance without the substance.
How FISMA, NIST SP 800-53, and zero trust fit into the data governance structure
FISMA is the security counterpart to the Evidence Act: the foundational statute requiring agencies to build, document, and run agency-wide information security programs. It applies to every federal agency, and it extends outward to contractors and third parties handling federal information, which matters more than it used to now that vendor-held data counts as an agency data asset (more on that loophole closure shortly). FISMA requires regular risk assessments, continuous monitoring, and controls tied to NIST guidance, which is where NIST Special Publication 800-53 comes in as the operational backbone.
NIST SP 800-53 organizes controls into twenty families, covering access management, incident response, encryption, and auditing, among others, and totals more than 1,000 individual controls. No agency applies all of them; instead, every information system gets categorized as Low, Moderate, or High impact based on the potential harm to confidentiality, integrity, or availability if something goes wrong, and that categorization determines which subset of controls actually applies. Not every system guarding cafeteria menu data needs the same lockdown as one holding veterans' medical records.
OMB M-25-04, issued January 2025, pushes agencies to focus cybersecurity resources on maturing zero trust architectures, framing it as critical to mitigating current risk. And this is where data governance and cybersecurity, historically separate conversations held in separate meetings by separate people, actually merge into one document: the Federal Zero Trust Data Security Guide, released by the CDO Council and CISO Council in May 2025, with an earlier version published in October 2024.
More than 30 federal agencies contributed to authoring it, reflecting a notably broad level of cross-agency collaboration for a technical guide. It's a key deliverable of OMB M-22-09, and its central idea is deceptively simple: secure the data itself, not just the perimeter around it. Perimeter security assumes a defended boundary keeps threats out; zero trust assumes that boundary has already been crossed and asks, continuously, whether the person or system touching this specific piece of data should be touching it right now. The guide is built to meet agencies where they are, accounting for differences in mission, risk tolerance, resources, and existing cybersecurity maturity, rather than demanding every agency hit the same bar on the same timeline.
The governance implication is the part worth sitting with. Zero trust reframes data security as a data governance question: who has access, under what conditions, verified continuously, not once at login and then forgotten. That means CDOs and CISOs need to work from one shared framework rather than two parallel ones that happen to reference each other in footnotes. The Zero Trust Data Security Guide is the first document that actually forces that marriage on paper.
What open data requirements actually demand from agencies operationally
The OPEN Government Data Act didn't just give agencies permission to share data if they felt like it; it created affirmative legal obligations to publish, catalog, and plan. Agencies must maintain comprehensive data inventories, disseminate data assets through the Federal Data Catalog, keep open data plans current, and actually engage the public rather than treating "public engagement" as a box on a form.
The Federal Data Catalog itself is a discovery layer, not a hosting service. OMB describes it as a central point of entry where the public and other agencies can find data assets, including ones that haven't been directly published yet and may never be. That's a subtle but important distinction: the catalog's job is to tell you a dataset exists and who to ask for it, not necessarily to hand it to you on the spot.
OMB M-25-05, issued January 15, 2025, is the document that finally operationalizes all of this, six years after the OPEN Government Data Act became law. Six years is a long time to wait for implementation guidance. M-25-05 rescinds and replaces the older M-13-13, requires an open-by-default posture, and mandates the comprehensive inventories, catalog participation, open data plans, and public engagement listed above. But the detail with the sharpest teeth is the redefinition of "data assets" to include data procured through private contracts and maintained on behalf of an agency. That closes a loophole vendors have been quietly living in for years: if a contractor holds your agency's data, that data is now within scope, full stop, not exempt because it technically sits on someone else's server.
GSA's procurement language is the clearest example of what compliance looks like in practice: standard contract terms that mandate open formats at the point of data acquisition from external vendors. Governance gets built into the purchase order itself, rather than retrofitted after the vendor relationship is three years old and nobody wants to renegotiate the contract.
There's also a quieter, more technical project underway: a cross-governmental effort to modernize the Federal Data Catalog and align it with FAIR standards, meaning data that's Findable, Accessible, Interoperable, and Reusable. The infrastructure itself is being rebuilt to actually support the legal requirements M-25-05 just formalized, which raises a fair question: was the catalog ever fully capable of doing what the statute asked of it? The honest answer looks like "not quite, but it's catching up."
All of which creates a real tension agencies have to live inside. Data needs to be open by default under the OPEN Government Data Act, and simultaneously locked down under FISMA and zero trust principles. Those two mandates don't cancel each other out; they get reconciled inside the governance framework itself, through classification, access controls, and the judgment calls stewards and governance boards make every day. Openness and security are best understood as two settings on the same dial, with governance deciding where the dial sits for any given piece of data.
Why data governance has become the prerequisite for AI deployment in federal agencies
Scale first: Federal reporting identified roughly 3,600 AI use cases across federal agencies, a nearly 70% year-over-year increase, with especially sharp increases at NASA, HHS, Veterans Affairs, Justice, and Energy. That's not a pilot program anymore. That's a wave.
Almost three-quarters of CDOs report direct involvement in shaping their agency's AI strategy, and roughly 90% say they're already using AI or actively planning to in the near term. The CDO job description, quietly and without much fanfare, now includes de facto AI readiness officer, whether or not that line appears anywhere in the position description.
Here's the problem, though, and it's a big one: over 80% of federal leaders, according to ICF research, say their data isn't AI-ready. Poor data quality is the single most cited barrier to scaling AI initiatives, and it's not a minor speed bump. Estimates suggest enterprises spend as much as 80% of AI implementation timelines on data-related tasks, ingestion, cleansing, curation, format conversion, before a model ever runs a single prediction. That's roughly the equivalent of spending four-fifths of a construction budget just leveling the ground before building begins.
It gets more specific and more uncomfortable: a large share of CDOs cite a lack of AI-specific guidance as a primary barrier. The governance frameworks walked through in the earlier sections, the CDO Council, the data quality working groups, the stewardship models, were built for data management as a discipline in its own right. They weren't designed with model training pipelines in mind, and the guidance is still catching up to the technology it's supposed to govern.
The 2025 CDO Council survey frames the synthesis point about as directly as a government survey ever does: sustained investment in data governance and coordination is critical to unlocking AI value while maintaining public trust and accountability. In plain terms: bad data put into a good model doesn't produce a good answer. Garbage in, garbage out was a saying long before anyone called it AI readiness.
Structurally, this means the quality working groups, the stewardship roles, the governance bodies, and the zero trust data security work covered earlier aren't just compliance overhead anymore. They're the precondition for AI to function at any meaningful scale. Agencies treating data governance as a checkbox are going to hit the AI readiness wall; agencies that actually built the layered structure this piece has walked through are the ones positioned to move faster, and more safely, once the AI use cases start multiplying again next year.
Where the framework still breaks down and what agencies are doing about it
Numbers don't lie, even when the systems generating them clearly have some issues: GAO estimated the federal government lost roughly $186 billion to improper payments in fiscal year 2025. Thirteen programs across seven agencies reported improper payment rates of 10% or higher in two consecutive years, and Medicare and Medicaid together account for a substantial share of that total. This is the least abstract evidence available that governance gaps have real fiscal consequences, not theoretical ones.
Role ambiguity inside agencies compounds the problem. CDOs report declining clarity around their own responsibilities even as the role itself matures, a contradiction worth sitting with: the job is becoming more established even as the job description grows blurrier. Almost half cite conflicting statutory or legal authorities as a barrier, up sharply from 2023, suggesting that as more mandates stack on top of each other (Evidence Act, OPEN Government Data Act, Paperwork Reduction Act, FISMA, zero trust guidance), the seams between them are fraying rather than tightening.
The CDO Council's own recent history is basically a case study in how fragile this coordination infrastructure really is. The Council sunset in December 2024 when Congress didn't reauthorize it, and OMB had to administratively rebuild it a month later. Coordination mechanisms, it turns out, can vanish overnight without sustained institutional commitment behind them; they don't run on autopilot just because they've existed for a few years.
Budget and leadership support remain the most cited obstacles across every survey referenced in this piece. A governance framework that looks complete on paper but has no funding and no executive sponsorship behind it isn't a functioning system at all.
So what are agencies actually doing about all this? A few concrete moves stand out. GSA's Data Evidence Governance Board Roles and Responsibilities, published April 2025, pushes open data accountability down below the CDO into Staff and Service Office boards, meaning governance reaches program-level staff instead of stopping at the top. The Federal Zero Trust Data Security Guide has more than 30 agencies co-authoring one shared playbook instead of each building its own from scratch, which at minimum saves everyone from reinventing the same wheel 30 separate times. The FAIR data catalog modernization project is rebuilding the infrastructure the open data mandates actually depend on to function. And the CDO Council's updated 2025 Charter is an attempt to re-anchor coordination after the December lapse, hopefully with enough institutional memory built in this time that reauthorization doesn't become a recurring cliffhanger.
The honest read, after walking through all four layers of this framework, is that the statutory and structural scaffolding is more complete now than it's ever been. But implementation maturity still varies sharply from agency to agency, and that variance is the real story here, more than any single memo or statute. The CDOs succeeding aren't the ones with the most polished strategy document. They're the ones treating this entire layered structure, statute, memo, strategy, phase-two guidance, as an actual management system they run every day, not a checklist they clear once and file away.


