You built the dashboard. Most of the numbers are green. And leadership still doesn't quite trust it. If that's familiar, the dashboard is probably measuring the wrong things — effort instead of outcomes, volume instead of risk. A scorecard earns trust when every number answers a question someone actually cares about. Here's how to build one that does.
Measure outcomes, not activity
“12,000 assets catalogued” sounds like progress, but it doesn't tell anyone whether the data that matters is under control. Activity metrics reward motion; outcome metrics reward results. The question leadership is really asking is “are we exposed?” — not “how busy is the team?”
Try this: for every metric on your dashboard, ask “what decision would change if this number moved?” If the answer is “none,” cut it.
Report a few measures, not fifty
A scorecard with forty metrics is a spreadsheet, and nobody reads it. Leadership can hold three to five numbers in their head; give them more and they'll trust none of them. Being disciplined about what you leave off is what makes the rest credible.
Try this: force yourself to pick the five measures you'd keep if you could show only five. That short list is your scorecard; everything else is supporting detail one click down.
Every number needs an owner and a source
A metric someone typed into a slide by hand is an opinion. A metric derived from the system of record is evidence. Trust collapses the first time a number can't be explained or reproduced, so each measure should have a clear definition, a named owner, and a source anyone can trace.
Try this: next to each measure, write one sentence — how it's calculated and where the data comes from. If you can't, that measure isn't ready to report.
Show movement, with a one-line “so what”
A single snapshot can't tell you whether things are getting better or worse. Leadership wants the trend and the takeaway: what changed since last time, and why. A number with a short explanation is worth ten without one.
Try this: pair each measure with its prior value and a sentence — “classification of tier-1 data rose from 78% to 91% after the billing domain was reviewed.” That's the part people remember.
Tie each measure to a target and an action
A measure with no target is trivia — you can't tell good from bad. And a red number with no owner or next step just creates anxiety. Every measure should have a threshold that defines “acceptable,” and every miss should map to a specific action and a person.
Try this: for each measure, write the target and what happens when it's missed — “tier-1 coverage below 95% → steward review scheduled within a week.”
A starter scorecard
If you're building from scratch, a small, outcome-focused set covers most of what leadership needs:
- Coverage of critical data — the share of your highest-tier assets that have an owner, a classification, and a policy.
- Classification of sensitive data — how much of your regulated or sensitive data is actually labeled.
- Ownership — the share of key domains and assets with a named, current owner.
- Open issues — unresolved governance issues, and how long they've been open.
- Exceptions — approved policy exceptions, and how many are past their review date.
Five numbers, each tied to a target, a source, and an owner, will tell a truer story than a wall of charts.
The takeaway
A good governance scorecard isn't a report card for the team — it's a decision tool for leadership. Measure outcomes, keep the list short, make every number traceable, and tie each one to a target and an action. Do that, and the scorecard stops being something you defend and becomes something people use.