This webpage outlines the data governance standard operating procedures for Finance and Administration and University Human Resources (F&A/UHR).
On This Page
Purpose
Data-driven strategies are essential for effective operations and strategic decision-making. As outlined in the F&A/UHR Data Strategy Program Charter, the vision of the program is to:
Foster a data-centric culture that equips, enables, and empowers the F&A and UHR community to consistently use data-informed decisions to advance the university’s operational and strategic goals. Leverage this approach to drive impactful insights, enhance student success, support institutional security, and boost operational efficiency across all units.
Data governance is a comprehensive collection of processes, roles, policies, standards, and metrics designed to ensure the effective and efficient use of information in achieving organizational goals. For F&A and UHR, this means the discipline to maximize the value of data, manage its associated risks, and reduce management costs. The goal is to ensure data validity, organize it at scale, and deliver it to everyone who needs it, empowering personnel with the right tools to collectively curate and transform data, extract its value, and assemble and communicate data insights everyone can trust.
Scope
The data governance standard operating procedures apply to all F&A and UHR data and information systems and analytics programs at the F&A/UHR departmental, divisional or unit level. This includes any data generated or managed by, or on behalf of, F&A and UHR, as well as all data for which F&A and UHR have been granted stewardship by third parties.
F&A and UHR data encompasses facts, statistics, or information that is read, created, collected, used, updated, reported, shared, stored, transferred, or deleted by F&A and UHR units. This data can be in any form, including electronic or physical, and may reside in information systems hosted by the organization or a third party.
Information Systems covered include the technology, software, and services administered for the purpose of creating, storing, managing, using, and gathering F&A and UHR data. Examples may include financial enterprise resource planning (ERP) systems, human resources information systems (HRIS), Facilities planning and/or maintenance systems, operational systems, risk management systems, spreadsheets, surveys, and other data collection and storage tools and platforms.
These standard operating procedures apply to all data under the responsibility of F&A and UHR administration, planning, operations, and decision-making, recognizing it as a strategic asset to be used for analysis and to gain insights for both strategic and operational purposes.
Data Strategy and Governance
Data strategy is a dynamic process to support the acquisition, organization, analysis, and delivery of F&A/UHR data in support of strategic and operational objectives. This involves developing a data governance strategy that outlines guiding principles, values, and high-level directional goals for the usage and management of F&A/UHR data assets.
Data strategy is established on an annual basis by the F&A/UHR Data Strategy Council with input from senior leadership in F&A/UHR, the F&A Data Governance Committee, and the F&A/UHR Data Community of Practice. The annual data strategy roadmap outlines data priorities to be achieved within a 12-month period. Data priorities include analytics and dashboards relevant to F&A/UHR which provide new insights for:
- Improving access to reliable & integrated information,
- Improving university operations,
- Enhancing campus safety, and
- Improving student success and wellbeing.
Data priorities also include tasks and activities related to data integrity, collection of new data, and data education and literacy.
The F&A/UHR Data Strategy Program Charter outlines data strategy purpose, vision, and objectives and states the roles and responsibilities of the Data Strategy Council and the Data Governance Committee. The Charter should be used in connection with these standards.
Key Principles of F&A/UHR Data Governance
The F&A/UHR data governance standard operating procedures are designed to meet the following core principles for data:
- Trustworthiness and Reliability: Ensuring data assets are accurate, consistent, understandable, and that access rights and authority are clearly defined, applied, and understood. This enables effective decision-making and customer experiences.
- Strategic Value Maximization: Actively managing data resources to maximize their value and utility, supporting strategic planning and decision-making for F&A and UHR functions.
- Security and Privacy by Design: Protecting F&A/UHR information from unauthorized access, use, disclosure, disruption, modification, or destruction, and maintaining stringent controls over personally identifiable information (PII). The strictest control will take precedence when multiple controls exist.
- Consistent Compliance: Adhering to all applicable international, federal, state, University System of Georgia (USG), and University of Georgia (UGA) regulations, policies, procedures, standards and contractual obligations.
- Collaboration and Federation: Recognizing that data governance is a “team effort,” requiring multiple data and analytics stakeholders to work together in a federated and collaborative approach across F&A, UHR, and other UGA and non-UGA entities as appropriate.
- Data Quality Integration: Understanding that data quality and governance go hand in hand, necessitating continuous checking and measuring of data quality throughout all data processes.
- Transparency and Accountability: Clearly defining who can access and utilize data, in which situations and using which methods, and ensuring that roles related to data are clearly defined with agreed-upon responsibility and accountability.
Data Ownership & Stewardship
F&A and UHR data roles align with USG and UGA definitions, roles, and responsibilities for data owner, trustee, steward and custodian. The sources for these definitions and requirements are as follows.
| Role | Primary Responsibility |
| Data Owner | Ultimate accountability for institutional data |
| Data Trustee | Oversees functional data domains; overall responsibility for the data processed in their data area(s) |
| Data Steward | Defines data as unrestricted, sensitive, or confidential; manages and ensures data quality |
| Data Custodian | Manages technical storage and access |
| Data User | An individual who has been authorized to access data |
Data Owner
Each USG organization is responsible for all data processed by offices of the organization. As the chief executive officer, the president of the USG institution, the Chancellor of the USG, or the head of other USG organizations is identified as the data owner. The USG organization data owner has ultimate responsibility for submission of organizational data to the USO.
Data owners have the responsibility for the identification, appointment, and accountability of data trustees. Data owners will inform the USG organization’s Data Governance Committee of their data trustee appointments including office, name, and contact information of the incumbent.
Data Trustee
Data trustees, designated by the data owner, are executives of the USG organizations who have overall responsibility for the data processed in their data area(s). USG organization data trustees have overall responsibility for accuracy and timeliness of submission of data to the USO. These positions/offices would normally be cabinet-level positions reporting directly to the entity data owner.
Responsibilities of the data trustees include, but are not necessarily limited to:
- Ensuring that data accessed and used by units reporting to them is done so in ways consistent with the mission of the office and USG organization;
- Appointing data stewards within each functional area for which they are responsible, and informing the USG organization’s Data Governance Committee of data steward appointments including office, name, and contact information of the incumbent;
- Participating as a member of the Data Governance Committee; and
- Communicating unresolved concerns about data (such as data quality, cybersecurity, data privacy, access, etc.) to the data owner.
Data Steward
Data stewards, designated by the data trustees, are personnel responsible for the data processed, and the technology used to do so if applicable, in their data area(s). Data stewards recommend policies to the data trustees and establish procedures and guidelines concerning the access to, completeness, accuracy, privacy, and integrity of the data for which they are responsible. Individually, data stewards act as advisors to the data trustees and have management responsibilities for data administration issues in their functional areas. Data stewards have responsibility for accuracy and timeliness of submission of data to the USG system office in their area. Depending on the size and complexity of a functional department/division, it may be necessary and beneficial for a designated data steward to identify associate data stewards to manage and implement the stewardship process.
Responsibilities of the data stewards include, but are not necessarily limited to:
- Developing standard definitions for data elements created and/or used within the functional unit, extending to include metadata definitions as well as the root data element definition;
- Ensuring data quality standards are in place and met;
- Inventorying and identifying the data as unrestricted, sensitive, or confidential for functional data within their area(s) of supervision/direction and communicating it to those responsible for ensuring data is handled according to its appropriate classification;
- Establishing authorization procedures with the USG organization’s Data Governance Committee and/or chief information officer (CIO) to facilitate appropriate data access as defined by institutional/office data policy, and ensuring security for that data — authorization documentation must be maintained;
- Working with the USG organization’s Data Governance Committee to identify and resolve issues related to stewardship of data elements, when used individually or collectively, that cross multiple units or divisions;
- Participating as a member of the Functional Data Governance Committee(s) as appointed by the data trustee; and
- Communicating concerns about data (such as data quality, security, access, etc.) to the data trustees.
The USG Business Procedures Manual, Section 12, refers to the “USG organization’s Data Governance Committee.” UGA’s Office of Institutional Research provides information about UGA’s Data Governance Committee Framework, which currently includes committees for core academic (student) and administrative and financial data (human resources, finance, and some facilities data), functioning at the “institution” level.
UGA Data Management & Governance Framework — Office of Institutional Research
Data Custodian
Custodians are designated by and typically report to data stewards. The data custodian is responsible for the technical management, security, and maintenance of an organization’s data assets. Their role focuses on the operational side of data governance, ensuring that data is stored safely, backed up regularly, protected with appropriate access controls, and handled in compliance with security policies and regulatory requirements. Custodians are authorized to grant access to elements within the data domain for which the steward is accountable.
Data User
An individual who has been authorized to access data.
For F&A/UHR Data Governance Standard Operating Procedure purposes, a System Administrator is defined as:
An individual designated by the corresponding data steward who is responsible for physically provisioning access or modifying or removing access to the data/system based on the directions of the data custodian.
To mitigate the risk that one individual can grant approval for data access (data custodian) and physically provision that access within a system and/or platform (system administrator), custodians and system administrators should be separate individuals. The custodian is responsible to ensure a process, approved by the data steward, exists such that custodians document decisions to grant/modify/remove data access and share that information with the system administrator so the actions can take effect in the system and/or platform.
Exceptions to the segregation of duties between the data custodian and system administrator must be approved by the data steward, and processes should be implemented that independently monitor system access provisioned solely by the data custodian.
The roles and responsibilities of each data role will be provided to the individual when they are named to the role. Additionally, these individuals are responsible to complete F&A/UHR data governance training to ensure their awareness and understanding of these roles and responsibilities.
Data Policies & Standards
To ensure the key principles of data governance, F&A/UHR standard operating procedures are built on the following policies, standards and guidelines:
- Data Use, Access, and Classification: UGA Data Access Policy and Data Classification and Protection Standard
- For the purposes of the F&A/UHR Data Strategy Program and the analytics created for publication to the F&A/UHR Data Website Portal, no sensitive data (that which requires confidentiality by law, policy, or contractual obligation) and no personally identifiable information (for example, student or employee name or MyID) will be uniquely identified. Aggregated data that is not linkable to individuals or other sensitive or confidential data is allowable.
- Analytics requiring sensitive data or that is linkable to individuals must be approved by the applicable Data Steward prior to publication to the F&A/UHR Data Website Portal. Access controls to restrict these analytics to a limited set of users is required.
- Data Security and Privacy: Minimum Security Standards Policy
- Compliance Standards: F&A/UHR data practices will conform to these regulatory requirements: University Cybersecurity Program & GLBA Compliance Policy, European Union General Data Protection Regulation Compliance Policy, Privacy Policy and EU GDPR Privacy Notice
- Data Definitions: UGA uses the Data Cookbook (uga.datacookbook.com) application as its data dictionary. The Data Cookbook is a resource for end users to learn about the data elements used by the institution. In conjunction with the development of the UGA Data Warehouse, new data definitions are added to the Data Cookbook to reflect the information available for reports and analytics.
- F&A/UHR data stewards are responsible for ensuring these minimum standards are met with respect to the Data Cookbook. Data Stewards may assign this responsibility to associate data stewards.
- Appendix A provides an overview of the Data Cookbook and minimum requirements of the F&A/UHR Data Strategy Program when documenting data definitions for data used in reports and analytics.
- Data Access Control: Access to the F&A/UHR Data Analytics Infrastructure and Data Website Portal will follow the procedures established by the F&A/UHR Data Governance Committee in consultation with Data Stewards and Custodians.
- Access will use UGA Single-Sign On protocols.
- Access to ETL/ELT pipelines and to the SQL server will be limited to authorized users identified by Data Custodians by data source.
- Access to analytics tools will be limited to authorized users identified by Data Custodians or Data Stewards.
- Access to formally “publish” analytics and dashboards to the F&A/UHR Data Website Portal will be limited to authorized users identified by Data Custodians or Data Stewards.
- Access to use analytics and dashboards available on the F&A/UHR Data Website Portal is limited to authorized F&A/UHR staff.
- Separation of Duties: F&A/UHR units must ensure organizational structure, job duties, and business processes include an adequate system of separation of duties to reduce the risk of loss of confidentiality, integrity, and availability of data.
- Metadata Management Policies: Guidelines for managing descriptive information about F&A/UHR data.
How to Use F&A/UHR Data Governance SOPs for Analytics Enablement
F&A/UHR furthers analytics enablement through the following institutional, divisional, and unit or departmental structures. The F&A/UHR Data Governance Standard Operating Procedures apply to all of these structures.
Institutional Analytics
Through the UGA Data Warehouse, maintained by the Office of Institutional Research, certain F&A/UHR data sets are available for institutional analytics and reporting. F&A/UHR data trustees, stewards, and custodians have the same roles and responsibilities with respect to the institutional analytics as they do to divisional (F&A or UHR) and unit and/or departmental structures.
Unit/Department-Based Analytics
The individual F&A and UHR units and/or departments utilize and maintain their own internal analytics processes and structures, which are primarily using data within their unit’s data domain(s). The analytics and insights produced at this level are typically used for internal purposes and decision-making; however, they can also be pertinent to F&A and/or UHR collectively and, when relevant, can be made available through the F&A/UHR Data Website Portal as described below. Internal analytics programs must, at a minimum, follow the F&A/UHR Data Governance Standard Operating Procedures.
F&A/UHR Online Data Hub
This hub fulfills the purpose of the F&A/UHR Data Strategy Program vision. The hub delivers data visualizations, dashboards, models, and other analytical content suitable for F&A/UHR business users across all F&A and UHR units, for the purpose of planning, management, decision-making, and accountability. It is designed to be a single point of access where F&A/UHR users find and utilize pertinent analytics — those developed at the institutional level by OIR, those developed at the unit or departmental level, and those which are developed with cross-domain data, at the request of F&A/UHR leadership and/or management and which align with the priorities of the F&A/UHR data roadmap.
Analytics on this portal include descriptive analytics (what happened?), diagnostic analytics (why did it happen?), predictive analytics (what will happen?), and prescriptive analytics (how can it be made to happen?).
The following diagram outlines the relationship of the F&A/UHR Online Data Hub to the data sources housed within F&A/UHR units and those in the UGA Data Warehouse. Data Governance and the application of these standard operating procedures supports these relationships and ensures data integrity for users of the analytics.

Making Unit/Department Data or Analytics Available on the Portal
When cross-domain data is needed to create analytics or when existing unit/departmental analytics are ready to be added to the Portal, data stewards (or associate stewards) are responsible to complete the following data governance checklist. This checklist ensures the data stored on the SQL server and/or the associated analytic/dashboard meets the required data standards.
- Data definitions have been entered or confirmed in the Data Cookbook.
- The analytic or dashboard has been tested to ensure data validity, completeness, and accuracy vis-à-vis the data source.
- The unit/department has a methodology and practice in place to ensure that data changes are adequately reflected in the analytic/dashboard, ensuring the user has access to timely data.
- The data in the analytic/dashboard complies with applicable USG and UGA policies and any data regulations. See Data Policies and Standards for a list.
- No personally identifiable data is available in the analytic/dashboard.
- If personally identifiable data is required, the Data Steward must approve the data/analytic and confirm access restrictions with the Portal Administrator.
- The analytic or dashboard uses the established formatting standards which create consistency in the look/feel and navigation of the item.
Data custodians are responsible for communicating access requirements for the analytic/dashboard to the Portal administrator. The Portal administrator will look to the data custodian for directions when provisioning access to the analytic/dashboard.
All users requesting access will attest to business use of the Portal and confirm data usage compliance.
Making Cross-Domain Analytics Available on the Portal
Note: This section is under development. Specific process guidance for cross-domain analytics will be added as pilot data sets are completed.
Appendix A — UGA Data Cookbook Overview & Minimum Standards per the F&A/UHR Data Strategy Program
Assigning Access
Permissions in the Data Cookbook should be determined by the structure of your Data Stewards and Data Custodians:
- Moderators
- Moderator roles in the Data Cookbook should be held by the Data Steward and any designee of their choosing.
- Moderators have editing and approval access across their entire functional area.
- Managers
- Manager roles should be held by your Data Custodians and any designee that has been approved by your Data Steward.
- Managers have approval access for their specific functional area with edit access across the wider functional area.
- Editors
- Editors should be appointed by your Data Steward or Data Custodians as necessary.
- Editors only have edit access within their specific functional area.
User roles are assigned by EITS and can be requested here.
- Anyone with a UGA MyID may be granted viewer access in the Data Cookbook.
- Advanced permissions will require approval from an existing moderator, a Data Custodian, or the Data Steward for your functional area.
Creating Definitions
To begin, it is best to remember that the collaborative definition process is built into the workstream of the Data Cookbook.
Establishing a Rough Draft
All the roles noted above can begin the definition process. Establish the field that you are attempting to define as well as a base definition. Additionally, determine the following for your data field:
Definition Source
- This should be the group/institution that is the originator of the definition.
- For definitions created by your unit, the source will be the name of your unit.
- For definitions taken from other sources (USG, Department of Labor, Oracle, etc.), the source will be the name of that entity.
Privacy Classification
- The Cookbook currently has privacy classifications of Public, Internal, Sensitive, and Restricted.
- Guidelines to determine the Privacy Standards to apply to your data field can be found here under the UGA Policy library.
- A quick guideline:
- Public — can be disclosed without restriction
- Internal — restriction is preferred, but can be subject to open records request
- Sensitive — restricted by law, policy, or contractual obligation
- Restricted — subset of sensitive data that pertains to Personal Identifying Information and Financial Information
Data System
- The data systems are the authoritative source in which the defined term is housed combined with any other system in which the field is used.
- Examples of data systems currently used at UGA include: UGAJobs/PeopleAdmin, OneUSGConnect/PeopleSoft HCM, AiM, Banner, GAIL, PeopleSoft Financials, etc.
- Data systems are currently fixed values within the Cookbook, but more can be added via a request to EITS if you are unable to find the system in which the field is housed.
Functional Area
- Depending on the role of the user creating the definition, the functional area may be restricted at this point in the process.
- You will only be able to assign a functional area for which you have editing access, so fields that fall under multiple areas will need those areas added by Managers and Moderators further on in the definition process.
- The current list of Functional Areas can be found here in the Data Cookbook; however, it is possible to add more via a request to EITS.
Revision, Refining, and Approval
Once a rough draft has been created, the definition can be saved for collaboration or submitted for approval.
Save
By selecting Save, you leave the definition in the drafting stage while unlocking collaboration from others in your functional area as well as additional properties:
- Synonyms — This section can be used to add any other names used to refer to the field you are defining. Used mostly for unofficial names, abbreviations, and alternate spellings/spacings. Examples:
- FLSA Status → Salaried/Hourly
- Multiple Components of Pay → MCOP
- Paygroup → Pay Group
- Tags — This section can be used to add terms that relate to your definition while not necessarily being a part of the definition. Used for search optimization as well as grouping terminology. Users can search by tag to return all definitions that share that tag.
- Attachments — This section gives you the ability to link supporting documents to your definition. Good examples include related policies, additional resources, and related communications.
- Related Definitions — This section is similar to the Synonyms section but is used to add other defined terms within the Data Cookbook. Best practice is that once you have added synonyms and tags, search for them in the related definitions section as well.
- If any synonyms are found in related definitions, they should be removed from the synonyms section. This is not true for tags.
After all supporting fields and collaboration steps have occurred, the definition may be submitted for approval.
Submit
Once submitted, a definition is locked from editing, and an approval notification is sent to all users with approval access for the included functional areas. Managers or Moderators for the included functional areas may then either approve or reject the definition for the field in question.


