Building Your Data Management Office: A 90-Day Roadmap
10 min read · June 4, 2026
Most data governance programs in Saudi Arabia do not stall because of technology. They stall because no one truly owns them. The national data management framework issued by the National Data Management Office (NDMO) spans 15 domains, 77 controls, and 191 specifications — and it assumes that a specific function inside your organization is accountable for data. The Personal Data Protection Law (PDPL), fully enforced since September 2024 under SDAIA's supervision, raises the stakes further, with penalties of up to SAR 5 million, doubling to SAR 10 million for repeat violations. That accountable function is the Data Management Office (DMO).
The good news: a credible DMO does not take years to stand up. With a clear mandate and a disciplined sequence, the first 90 days are enough to move from zero to an operating function with visible results. Here is a roadmap you can actually run.
What a Data Management Office Actually Does
Before day zero, be clear about what you are building. A DMO is not an IT project with an end date. It is a permanent organizational function that:
- Sets data policies and standards aligned with NDMO controls and PDPL obligations
- Assigns ownership and stewardship across business domains and keeps them current
- Operates the data catalog, data classification, and data quality programs
- Coordinates between business units, IT, legal, and compliance — and reports to executive leadership
Organizational position matters. A DMO buried three levels deep inside IT will struggle to direct business units. The strongest placements report to a Chief Data Officer, a transformation office, or the executive committee directly.
Days 0–30: Mandate, People, and Inventory
Get a written mandate
Nothing else on this roadmap works without it. Ask for a short charter — two pages is enough — signed by the CEO or executive committee, stating: the DMO's scope and authority, its power to name data owners in business units, the escalation path when disputes arise, and its budget. If leadership will not sign, you do not have a DMO; you have a working group.
Define the three core roles
- Data owner — a senior business leader accountable for an entire data domain. Owners approve access and classification decisions and accept risk. Ownership is a business role, never a purely technical one.
- Data steward — the day-to-day operational arm. Stewards define business terms, monitor quality, and act as the first escalation point for data issues. Their natural home is inside the business unit.
- Data custodian — the technical role. Custodians implement controls, manage storage and backups, and enforce access. Their home is IT.
A simple test keeps the boundaries clean: owners decide, stewards manage, custodians implement.
Build a realistically sized team
- Smaller organizations: 2–3 dedicated people — a DMO lead, a governance specialist, and a data analyst — supported by part-time stewards in business units
- Mid-sized organizations: 4–6, adding a data quality lead and a metadata and catalog specialist
- Large or heavily regulated organizations: a core team of 8–12 plus a federated steward network across domains
The federated model matters more than headcount. A small central team with named stewards in every domain consistently outperforms a large central team trying to do stewardship on the business's behalf. And stewards need formally allocated time in their job plans — a title on a slide is not a steward.
Start the data inventory — systems first, fields later
Do not attempt to catalog every column in month one. List your systems and major datasets: name, owning unit, business purpose, and whether each holds personal data. A spreadsheet is acceptable at this stage; the goal is a complete map of the landscape, not a perfect one.
Days 31–60: Catalog, Classification, and Quick Wins
Stand up the data catalog
Move the inventory out of spreadsheets and into a real data catalog. Connect your priority systems, harvest technical metadata automatically, and attach the owners and stewards you named in month one. The catalog becomes the DMO's operating surface: every later activity — classification, quality, lineage — hangs off it.
Apply data classification
Saudi Arabia's national data classification scheme defines four levels: Top Secret, Secret, Restricted, and Public. Classify the datasets you inventoried — at dataset level first, not field by field — and explicitly flag everything containing personal data, since that drives your PDPL obligations. Classification decisions belong to data owners; the DMO facilitates and records them.
Deliver visible quick wins
Pick two or three deliverables the business will notice:
- A business glossary covering roughly 50 of the most contested terms — 'customer', 'active account', 'revenue' — with owner-approved definitions
- A personal data register listing where personal data lives, groundwork that PDPL compliance requires anyway
- One end-to-end data lineage map for a critical executive report, showing exactly where its numbers come from
Quick wins are not vanity. They buy the political capital you will need for the harder months ahead.
Days 61–90: Quality Baselines, KPIs, and Reporting Cadence
Establish data quality baselines
Select the critical data elements in each priority domain — the fields that decisions, regulatory reports, and customer interactions actually depend on. Measure them against core data quality dimensions: completeness, validity, uniqueness, and timeliness. Record the baseline before fixing anything; you cannot demonstrate progress without a starting line.
Define KPIs the DMO will live by
- Percentage of priority systems represented in the catalog
- Percentage of inventoried datasets classified
- Number of domains with a named owner and an active steward
- Quality score trend on critical data elements
- Data issues raised versus resolved, with aging
Set a reporting cadence and keep it
- Weekly: a short internal DMO stand-up on progress and blockers
- Monthly: a steering meeting with data owners to take decisions — classification disputes, access policies, quality priorities
- Quarterly: an executive report linking DMO progress to NDMO compliance posture and PDPL risk exposure
The cadence is the product. A DMO that reports predictably, with the same KPIs each cycle, becomes part of how the organization runs rather than a side initiative.
Common Failure Modes
- No real mandate. The DMO launches as an IT initiative; business units politely ignore it.
- Boiling the ocean. Trying to inventory and classify everything before delivering anything anyone can use.
- Tools before roles. A catalog with no owners or stewards behind it is an empty shelf.
- Part-time everything. Stewards are named but given no allocated time, so stewardship never happens.
- Policy without operations. A beautiful policy library with no enforcement, measurement, or follow-up.
- Compliance theater. Reporting built solely for the regulator; the business sees no benefit and support quietly evaporates.
After Day 90
Day 90 is a starting line, not a finish line. From here the work compounds: expand the catalog domain by domain, automate lineage capture, deepen quality rules from baselines into enforced thresholds, and prepare for formal NDMO compliance assessment with evidence the DMO already generates as a by-product of normal operations.
If you would rather not assemble that operating surface from separate tools, Goava brings the catalog, classification, lineage, and quality workflows in this roadmap together in one platform built for Saudi organizations — explore the product or talk to our team.
Monthly digest
Monthly data governance insights for organizations operating in Saudi Arabia.