Houghton Consulting v3.3 www.houghton.consulting

Data Governance & Ethics — Revision Trainer

D4B Joint Professional Master's, University of Bologna · built from all twelve session decks · shared with the class
days to go
17:00IST start (18:00 CET)
90minutes
30 + 5MCQs + written

Start here

Everything here comes from the twelve session decks and the Week 4 DGI (Data Governance Institute) companion guide. Where the slides differ from the published standard, the slides win — that is what is being marked.

Time budget

35 minutes on the 30 MCQs — about 70 seconds each. Two passes: answer what you know, flag the rest, come back. Never leave a blank.

45 minutes on the five written answers — about 9 minutes each. Eight marks each, so aim for five to seven substantive points, one named framework and one concrete example.

10 minutes to review and submit manually. Do not rely on auto-submit.

Before the day

The Safe Exam Browser may be required — that is not confirmed for this exam yet. Mark's "more details to follow" email should settle it, along with the exam link, the scope and any open-book rules. Installing and testing it in advance costs little, and the day of the exam is the worst possible time to find out it is needed.

Either way, have your D4B login details to hand on paper. They do not autofill in the Bologna exam browser, which has caught people out before.

A group call the evening before is worth organising — it helped before the April Cybersecurity exam.

PDF The full revision brief — 26 pages Everything here plus the definitions, the framework tables, the General Data Protection Regulation summary and the five short-response scaffolds, laid out to read or print. Version 2.0. Read as PDF 397 KB Word copy 110 KB
Used version 1? Here is what has changedv1 → v3.3

The practice questions are the substantial change. Version 1 gave you the same fixed 20 questions every time, in the same order, with a one-line note on why the right answer was right. Working through it twice taught you the answer positions rather than the material.

There is now a pool of 100. Twenty are drawn at random each time you load the page or press "New set of 20", and the four options are shuffled independently, so the correct answer is not sitting in the same place twice. You will get a different mix on every attempt.

The questions themselves were rewritten. Version 1 asked a lot of questions about where something appeared — which week defined a term, which wording a slide used, how many items a list held. Those tested whether you remembered the deck, not whether you understood the subject. Every question now puts you in a situation and asks you to diagnose it, tell two related concepts apart, reason about a consequence, or apply a framework to a dilemma. The answers are still drawn from the taught material.

Get one wrong and you now get taught. A second panel opens naming the misconception, explaining why the option you picked is tempting and where it breaks down, and pointing at what to revise. Roughly 130 words rather than the single line version 1 gave you.

Smaller changes: every acronym is written out on first use; the Safe Exam Browser guidance was softened because its use is not yet confirmed; the author name in the footer is now a contact link; and each question carries the week it comes from, so a run of wrong answers tells you which session to go back to.

Unchanged: the twelve-session map, the counts flip cards, the traps table, the topic panels and the five short-response scaffolds. If you had those working for you, they are where you left them.

The twelve sessions

WkTitleMost examinable content
1Introduction to Data GovernanceTechTarget definition; governance-as-government analogy; the 7 named DG (data governance) frameworks; "data exhaust"
2Principles of Data Management and GovernanceGovernance vs management; DMBOK (Data Management Body of Knowledge)'s 8-element scope; 4 data management principles; provenance vs lineage; MDM (master data management)
3Data Risks, Integrity and Security5-step risk process; 4 register headings; 12 identification methods; 5 challenges; 6 general + 3 application controls
4Data Governance FrameworksPrinciples → Policies → Processes → Standards; 4 GAIP (Generally Accepted Information Principles) principles; CDO (Chief Data Officer)'s 6 functions; 6 steward types; DGI's 10 components
5Operating Model 2, Architecture and MetadataThe 4 execution scenarios; escalation path; Ladley on architecture and metadata; data fabric
6Data Regulatory Compliance and Data ProtectionGDPR (General Data Protection Regulation): 7 principles, 6 lawful bases, consent, controller vs processor, Arts. 28–32, Art. 9, Art. 25, Chapter V
7Implementing Data GovernanceLadley's 8 phases; RACI (Responsible, Accountable, Consult, Inform); 3 maturity levels; 4 challenge quadrants; 4 objections; monetisation
8Ethical Concepts and Frameworks3 branches; 4 normative families; Kant's imperatives; Rawls; Asimov; the 7 information-age values
9Ethics and AI (artificial intelligence)3 direct + 5 broader concerns; historical bias and feedback loops; interpretability; the case studies
10Privacy, Analytics and EthicsUDHR (Universal Declaration of Human Rights) Art. 12, ECHR (European Convention on Human Rights) Art. 8, Charter Art. 8; 4 causes of bias; fairness; privacy-preserving AI; AIF360 (AI Fairness 360)
11Governance of AI and Advanced AnalyticsAI Act tiers and timeline; Recital 71 and Arts. 13/15/22/35; FAT/ML (Fairness, Accountability and Transparency in Machine Learning); direct vs indirect auditing
12Future Trends4 trends; UN (United Nations) advisory group's 3 objectives; CRISP-DM (Cross-Industry Standard Process for Data Mining) adaptation; expanded CDO role

The counts MCQs test

Tap a card to reveal the answer. This module runs on numbered lists and multiple-choice questions feed on them.

Traps

Each of these is a place where being well-read can talk you into the wrong answer. Answer to the slides.

TopicWhat the slides sayWhat you might wrongly assume
Third leg of CIA (confidentiality, integrity, availability)Week 3 says confidentiality, integrity and accessibility — twiceAvailability. It appears only in the Art. 32 GDPR (General Data Protection Regulation) list
Integrity and security"Data integrity is a desired result of data security"The reverse. Distractors flip the direction
DGI (Data Governance Institute) componentsThe value-driven v2.0 set: Mission and Value, Beneficiaries, Data Products…The classic 2006 set: Mission and Vision, Data Rules and Definitions, Data Stakeholders, DGO (Data Governance Office), Data Stewards. Only Decision Rights, Accountabilities and Controls appear in both
Data OwnerA type of Business Data Steward, with approval authorityA separate top-level role alongside steward and custodian
Maturity levelsThree: reactive, preemptive, proactiveA five-level CMMI (Capability Maturity Model Integration)-style model. Do not import one
Rawls"Social justice based ethics"Contractarianism. That word never appears in the module
Asimov's lawsNumbered 1–4, humanity-level law placed fourthThe Zeroth Law taking precedence over the first
Data quality dimensionsFive, including relevanceThe DAMA (Data Management Association) UK six, including validity and uniqueness
GDPR fine tiersOne figure: up to €20m or 4% of global turnoverThe two-tier structure. The €10m/2% tier is never taught
Data meshNever taught — Dehghani is not cited anywhereThat it is examinable. The only architecture pattern named is data fabric
DIKW (data, information, knowledge, wisdom)The letters never appear in the slide textThat it is a named framework here. It survives only as an unlabelled graphic

Not in the slides at all — do not spend revision time here

Data mesh and Dehghani. Data warehouse, lake, lakehouse. Federated governance as a named term.

GDPR breach notification and the 72-hour rule (Arts. 33–34). DPO (Data Protection Officer) designation and tasks (Arts. 37–39). The enumerated data subject rights — that slide is an image.

ISO/IEC (International Organization for Standardization / International Electrotechnical Commission) 42001 and 23894, IEEE (Institute of Electrical and Electronics Engineers) 7000, the NIST (National Institute of Standards and Technology) AI (artificial intelligence) RMF (Risk Management Framework), COBIT (Control Objectives for Information and Related Technologies). Floridi and AI4People. The trolley problem. k-anonymity and pseudonymisation as techniques.

Topic detail

Expand whichever topics you are shaky on. Everything here is quoted or closely paraphrased from the decks.

Practice questions

Twenty questions drawn at random from a pool of 100, with the answer order shuffled each time. Draw a new set as often as you like — you will get a different mix. Get one wrong and a fuller explanation opens beneath it.

Score 0 / 20

Five short responses with answer scaffolds

Eight marks each, nine minutes each. Write your own answer first, then open the scaffold — the shape of a full-mark answer is define, apply a named framework, give a concrete example, then evaluate.