AI Readiness: Why Data Governance Comes Before AI

August 29, 2026 Mark O'Malley

AI Readiness: Why Data Governance Comes Before AI

Organisations often begin an AI program by choosing a model, buying licences or identifying a productivity use case. In practice, one of the biggest determinants of whether AI delivers value is much less glamorous: the quality, ownership and accessibility of the organisation’s data.

For Family Offices, this matters even more. Information is frequently distributed across Microsoft 365, investment platforms, finance systems, board portals, document stores, adviser systems, personal devices and historical repositories. The data may be highly sensitive, duplicated, inconsistently classified or accessible to more people than intended.

Before AI is connected to that environment, the Family Office should know what information exists, where it resides, who owns it and who should be allowed to use it.

Key takeaways

  • AI can amplify poor data governance as easily as it can improve productivity.
  • Trusted data, clear ownership and appropriate access are prerequisites for reliable AI.
  • Agentic AI increases the importance of process and data readiness because agents can act across multiple systems.
  • Family Offices should improve information governance before granting AI broad access to sensitive repositories.
  • AI readiness is an organisational capability, not a software-purchasing decision.

The AI problem may actually be a data problem

If an AI system is asked to summarise, compare, retrieve or act on organisational information, it depends on the underlying data being sufficiently accurate, current and governed.

Common problems include:

  • multiple versions of the same document;
  • outdated information remaining accessible;
  • unclear ownership of records;
  • poorly structured file shares;
  • excessive Microsoft 365 permissions;
  • duplicate records across business applications;
  • sensitive data mixed with ordinary operational content;
  • critical information stored in personal accounts or devices.

An AI system connected to this environment does not automatically resolve those weaknesses. It may simply make them easier to search, summarise and redistribute.

Family Office data has a different sensitivity profile

Family Office information can combine business, investment and deeply personal data in the same environment. Examples include:

  • investment portfolios and transactions;
  • trust and entity structures;
  • tax and legal information;
  • family correspondence;
  • board or family council papers;
  • estate and succession planning;
  • health and personal information;
  • property and lifestyle assets;
  • travel and security arrangements;
  • communications with advisers.

This means ordinary enterprise information-governance assumptions do not always fit. The Family Office needs a model that reflects discretion, privacy, family relationships and a very low tolerance for inappropriate disclosure.

AI readiness starts with five data questions

1. What data do we have?

Build an inventory of the major information repositories and business systems. The objective is not to catalogue every file; it is to understand where material information is held and which systems are authoritative.

2. Who owns it?

Every important data domain should have an accountable owner who can decide how information is classified, retained, corrected and accessed.

3. Who can access it today?

Before AI receives access, organisations should review existing human permissions. AI should not inherit an access-control problem that already exists.

4. Is the information trustworthy?

AI output will be less reliable if the source environment contains duplicate, contradictory or obsolete information. High-value use cases may require specific trusted repositories rather than unrestricted access to everything.

5. What should AI never access?

Some information should remain outside particular AI use cases entirely. This should be determined by risk, privacy, confidentiality, legal obligations and the sensitivity of the information.

Data ownership matters more as agents arrive

The arrival of agentic AI raises the stakes. An agent may not only retrieve information but use it to make recommendations, update systems or trigger actions.

Deloitte research reported in August 2026 found a significant readiness gap: only a minority of surveyed leaders considered their business processes prepared for agentic AI, while most expected large-scale process redesign over the coming years. The implication is that organisations cannot simply bolt agents onto existing processes and expect transformation.

The same applies to data. If ownership, quality and permissions are unclear, agents will automate uncertainty rather than remove it.

Govern the retrieval layer

Modern AI solutions increasingly use retrieval systems to bring organisational information into the model’s context. This can be powerful, but it introduces governance questions:

  • Which repositories are indexed?
  • How often is information updated?
  • Are permissions preserved?
  • Can deleted or superseded information still appear?
  • Are sensitive documents excluded where appropriate?
  • Can the organisation trace an AI answer back to its source?

For higher-risk use cases, traceability and source attribution are essential.

Retention and deletion need to work before AI

Many organisations retain information indefinitely because storage is inexpensive. AI changes the risk equation because old information that was previously difficult to find may become instantly discoverable.

Family Offices should therefore review:

  • retention periods;
  • duplicate and obsolete data;
  • personal information that no longer needs to be held;
  • former employee and adviser access;
  • legacy archives and shared mailboxes;
  • unstructured data in collaboration platforms.

Data minimisation is not simply a storage-management exercise. It reduces the information available to be exposed, misused or incorrectly surfaced by AI.

A practical AI-readiness sequence

  1. Identify the business outcome. Start with a real use case, not the technology.
  2. Map the required information. Determine what data the use case genuinely needs.
  3. Confirm ownership and authority. Identify who is accountable for that data.
  4. Review access. Correct excessive human permissions before adding AI.
  5. Improve quality. Remove obvious duplication and stale information.
  6. Define exclusions. Identify information the AI should not access.
  7. Test with a controlled dataset. Start narrowly before expanding scope.
  8. Measure reliability and risk. Evaluate whether the AI produces sufficiently accurate and appropriate results.
  9. Expand deliberately. Add data or automation only when controls are proven.

Data governance is part of Secure AI Governance

AI governance cannot be separated from data governance. Policies about approved tools are useful, but they are incomplete if the organisation does not understand the information those tools can reach.

DSC helps Family Offices establish practical Secure AI Governance that brings together data, identity, privacy, vendor assessment and technical controls. Our broader Family Office technology model is designed around the same principle: technology should provide confidence without creating unmanaged complexity.

Sources and further reading