Most entities can write a policy. Very few can run governance.
That gap is showing up across the Gulf right now. MTCIT’s National Data Governance and Management Framework sets mandatory requirements across 14 domains of data governance for every government unit in Oman. The framework is thorough. It covers policy, office setup, and a compliance assessment model. What it can’t do, because no framework can, is run itself.
That’s the real question entities are working through now. Not “do we have a policy,” but “can governance actually function, week after week, across every department that touches data.”
Why governance programmes lose momentum
The pattern is familiar to anyone who’s sat through a post-launch review a year on.
Governance gets treated as an IT initiative. The policy lives with the technology team, business units stay disconnected, and nobody outside IT feels ownership of it.
Policies exist. Ownership doesn’t. A document can name “data owners” without anyone actually holding the role day to day, a gap we cover in more detail in How to set up a Data Governance and Management Office in Oman.
Technology arrives before governance is defined. Catalogues get deployed without metadata standards behind them. Quality tools get switched on without anyone owning the fixes. Lineage gets mapped without the business context that makes it useful.
And governance becomes a one-time project instead of an operating capability. The rollout happens, the deck gets archived, and six months later nobody can say whether anything actually changed.
The NDGF anticipates some of this by requiring a dedicated governance office and a formal compliance assessment. But structure on paper and structure in practice are two different projects. Closing that gap is where most of the real work happens.
An operating model, not a checklist
Rather than treat NDGF as a compliance exercise, it helps to think in terms of five pillars that together form an operating model.
Governance strategy, the objectives, policies, and operating principles that tie everything together.
Organisational structure, a governance office, a governance council, named data owners and stewards, and the working groups that keep decisions moving. This is where the DGMO itself lives.
Data management capabilities, the business glossary, metadata, data catalogue, classification scheme, master data, quality rules, and lineage that make governance usable rather than theoretical.
Governance processes, issue management, approvals, stewardship routines, policy enforcement, and ongoing monitoring.
Measurement and continuous improvement, KPIs, compliance reporting, maturity assessments, and automation where it earns its place.
Each pillar maps closely to what the NDGF already asks for. The difference is that a framework describes the destination. An operating model describes how you get there, and how you stay there.
The five phases
Phase 1: Discovery and assessment. Establish the current state, run a gap analysis against the 14 domains, map stakeholders, and set priorities. This is where the honest conversations happen, and where they should happen, before scope and cost surprises show up later.
Phase 2: Strategy and design. Turn the gap analysis into policy, an operating model, defined roles, and a governance framework that fits how the entity actually works, not a generic template.
Phase 3: Implementation. Build out metadata, the data catalogue, stewardship routines, quality processes, and the technology that supports all of it. Technology comes after the model is defined, not before, entities that buy the platform first usually end up governing the platform instead of the data.
Phase 4: Enablement. Train the people who will run this day to day, drive adoption, and build a governance culture business teams engage with rather than tolerate. This is where most programmes are won or lost, and it deserves the same rigour as any technical workstream.
Phase 5: Validation and continuous monitoring. Track KPIs, report on compliance against the Compliance Assessment Model, assess maturity, and treat improvement as ongoing rather than a box ticked once.
What this looks like when it’s actually running
In practice, delivery work maps directly onto the NDGF’s domains rather than treating governance and compliance as separate tracks.
Strategy and roadmap work feeds directly into the data management strategy a governance office is mandated to own. Policy development translates national-level policy into entity-specific rules people can actually follow. Data catalogue and glossary work is where the technology layer earns its keep, whichever platform underpins it. Data quality and classification becomes concrete rules and remediation workflows rather than a static policy paragraph. Master data, sharing, and analytics governance gets built around the entity’s actual critical data elements, not a generic template. Compliance reporting becomes a running self-assessment and KPI process rather than an annual scramble. And training and awareness gets the same investment as any other workstream, because that’s where adoption is actually won or lost.
Measuring success beyond the compliance floor
Compliance with the NDGF is the floor, not the goal, a point covered from a different angle in Oman’s National Data Governance Framework, explained. Entities that operationalise governance well tend to see it show up as improved trust in data across departments, faster decision-making, less duplicated effort, better interoperability between systems, stronger AI readiness, and lower compliance risk as a byproduct rather than the headline.
This isn’t Oman’s first version of this mandate
Saudi Arabia’s National Data Management Office, operating under SDAIA, set out a similar model years earlier: a national regulator defining policy and maturity requirements, with each entity responsible for standing up its own governance function and reporting against it. Much of that methodology, gap assessment, policy localisation, office charter, training rollout, automated compliance dashboards, transfers directly to what MTCIT is now asking of Omani entities. Not because the two frameworks are identical, but because the operating discipline behind them is the same.
Building governance that lasts
Governance isn’t a one-time deliverable. Policies evolve, data volumes grow, technology changes, and the operating model has to move with all three. Entities that treat their governance office as a permanent function, not a project team that disbands after go-live, are the ones still compliant, and still functional, two years in.
Edgematics is an all-in-data consultancy working with government and regulated entities across the GCC to turn frameworks like the NDGF into operating reality: structures, policies, staffing models, and the platforms to run them. Our team has directly supported organisations through NDMO Phase 2 readiness in Saudi Arabia and governance programmes for entities including Bank Muscat, the UAE Ministry of Environment & Water, and the Abu Dhabi Urban Planning Council.
Book a Discovery Call to compare notes on what this looks like for your entity.
FAQ
What is a data governance operating model? The structure, people, processes, and technology that let governance run continuously, rather than a policy document that sits on a shelf. See How to set up a Data Governance and Management Office in Oman for how the organisational piece of this gets built.
How long does implementation typically take? It varies by entity size and current maturity, but a phased rollout, from discovery through validation, typically spans several quarters rather than weeks.
What should entities prioritise first? Metadata, a business glossary, and clear data ownership. They’re the foundation everything else, including data quality and lineage, depends on.
Is technology enough on its own? No. Technology supports governance once the operating model, roles, and processes are defined. Deployed on its own, it tends to formalise the gaps rather than close them.
How do entities measure governance success? Through a mix of compliance reporting against the NDGF’s Compliance Assessment Model and business outcomes: data trust, decision speed, reduced duplication, and AI readiness. The full compliance mechanics are covered in Oman’s National Data Governance Framework, explained.