Most public bodies already manage data. Staff maintain registers, process applications, generate reports, and share information with partner organisations every day. The challenge is that how data gets managed often depends on who you ask. One team has a naming convention; another doesn’t. A records management policy exists, but many staff haven’t read it. Someone built a workaround in Excel years ago and it quietly became the process.

A data maturity assessment makes these patterns visible. It gives an organisation a clear picture of how data is managed in practice and identifies where improvements would have the greatest impact.

Where the idea comes from

Capability maturity models have been around since the mid-1980s, when Carnegie Mellon’s Software Engineering Institute developed a framework to evaluate software development practices. The core idea was simple: organisations improve by understanding where they currently sit on a maturity scale and then working deliberately toward the next level. That concept has since been applied to fields well beyond software, including data management.
The DAMA-DMBoK framework (the Data Management Body of Knowledge, maintained by DAMA International) is the most widely adopted maturity model for data management. In Ireland, the OGCIO recommends it as the standard framework for public service bodies.

It covers eleven knowledge areas, including data governance, data quality, security, metadata, and data integration. It places the organisation on a five-level scale: from Level 1 (ad hoc, where success depends on individual staff) through to Level 5 (optimised, where processes are automated and continuously improved).

The levels describe process characteristics, and progression through them is sequential. Most public bodies sit somewhere in the Level 1 to 3 range across different knowledge areas, and different parts of the same organisation often sit at different levels.

What a good assessment actually looks at

A maturity assessment should draw evidence from several sources. Surveys alone can produce misleading scores, as staff often answer based on what policies say rather than what actually happens day to day.

A well-run assessment usually combines a structured survey with facilitated workshops or interviews and a review of existing documentation.

The DMBoK names a specific risk here: that “conversations on data quickly devolve into discussions about systems”. A well-run interview should steer past this.

The workshops are often the most valuable part. They surface the everyday realities people rarely have time to discuss: reports that take days because they require data from three systems, folder structures nobody understands, or processes that depend on one person’s knowledge. Giving staff a space to raise these issues, and having those issues documented and taken seriously, matters as much as the final report.

What we keep finding

Across organisations, the same patterns appear repeatedly:

  • Knowledge lives in people, not in processes. Staff know where to find things because they’ve always known. When someone leaves, that knowledge goes with them. The DMBoK flags this as a defining characteristic of Level 1 maturity, where “success depends on the competence of individuals.” It is the most common risk we encounter, and it is rarely on anyone’s radar until it causes a problem.

  • Data gets collected out of habit. Organisations gather information because they always have, without a clear picture of whether it still serves a purpose. Fields get added to forms but never removed. Nobody is quite sure what some of the data is for, but it keeps arriving.
  • Technology outpaces practice. Many public bodies now run standardised platforms (Microsoft 365, Dynamics 365, SharePoint) that offer governance and classification features out of the box. But the technology arrived as part of a broader IT programme, and the data management practices haven’t caught up. The capability exists; the habits haven’t followed. We regularly see data classification features available in an organisation’s systems that nobody has turned on.

  • Staff tend to be strong on security but less confident on governance, quality, and sharing. Data protection and cyber security get attention because they carry legal and reputational consequences. Data quality, metadata, classification, and sharing practices receive less focus because there is no equivalent forcing function.

  • Manual workarounds persist where automation could help. We see data shared between organisations by email attachment on a monthly schedule when the underlying systems could support an automated feed. These workarounds are invisible to management because they function well enough, until they don’t.

Where it leads

Data management exists to support the organisation’s real work

  • Making decisions with confidence

  • Sharing information efficiently

  • Reducing manual effort

A data maturity assessment gives management an evidence base for deciding what to improve and in what order. Some recommendations will be quick to act on: switching on a feature that’s already available, documenting a process that currently lives in someone’s head. Others will need investment and planning, and the assessment helps make the case in concrete terms.

The DMBoK describes this as an ongoing cycle: an initial assessment establishes a baseline, a roadmap defines the next steps, and periodic reassessment tracks progress over time. The assessment results sit within a broader programme of data governance and strategy, and the roadmap gives a sequence and pace for change.

For organisations considering whether to start, the OGCIO has published a self-assessment guide and advice note based on the DAMA-DMBoK framework. For those looking for external support, Derilinx has conducted data maturity assessments for over 40 public service bodies across Ireland (more information on our recent work in the OGP Framework Report).

The Impact of the OGP Technical Services Framework on Open Data & Data Management
Does Rain Affect Footfall in Dublin? What the Data Really Shows

Related Posts

  • September 2026
    What’s new in CKAN 2.11
  • June 2026
    Public Service API Standards: A Practical Guide Beyond the Checklist
  • March 2026
    Does Rain Affect Footfall in Dublin? What the Data Really Shows
Never Miss an Update!

Get the latest on open and shared data — news, events, and insights straight to your inbox.