Everything here comes from the twelve session decks and the Week 4 DGI (Data Governance Institute) companion guide. Where the slides differ from the published standard, the slides win — that is what is being marked.
35 minutes on the 30 MCQs — about 70 seconds each. Two passes: answer what you know, flag the rest, come back. Never leave a blank.
45 minutes on the five written answers — about 9 minutes each. Eight marks each, so aim for five to seven substantive points, one named framework and one concrete example.
10 minutes to review and submit manually. Do not rely on auto-submit.
The Safe Exam Browser may be required — that is not confirmed for this exam yet. Mark's "more details to follow" email should settle it, along with the exam link, the scope and any open-book rules. Installing and testing it in advance costs little, and the day of the exam is the worst possible time to find out it is needed.
Either way, have your D4B login details to hand on paper. They do not autofill in the Bologna exam browser, which has caught people out before.
A group call the evening before is worth organising — it helped before the April Cybersecurity exam.
The practice questions are the substantial change. Version 1 gave you the same fixed 20 questions every time, in the same order, with a one-line note on why the right answer was right. Working through it twice taught you the answer positions rather than the material.
There is now a pool of 100. Twenty are drawn at random each time you load the page or press "New set of 20", and the four options are shuffled independently, so the correct answer is not sitting in the same place twice. You will get a different mix on every attempt.
The questions themselves were rewritten. Version 1 asked a lot of questions about where something appeared — which week defined a term, which wording a slide used, how many items a list held. Those tested whether you remembered the deck, not whether you understood the subject. Every question now puts you in a situation and asks you to diagnose it, tell two related concepts apart, reason about a consequence, or apply a framework to a dilemma. The answers are still drawn from the taught material.
Get one wrong and you now get taught. A second panel opens naming the misconception, explaining why the option you picked is tempting and where it breaks down, and pointing at what to revise. Roughly 130 words rather than the single line version 1 gave you.
Smaller changes: every acronym is written out on first use; the Safe Exam Browser guidance was softened because its use is not yet confirmed; the author name in the footer is now a contact link; and each question carries the week it comes from, so a run of wrong answers tells you which session to go back to.
Unchanged: the twelve-session map, the counts flip cards, the traps table, the topic panels and the five short-response scaffolds. If you had those working for you, they are where you left them.
| Wk | Title | Most examinable content |
|---|---|---|
| 1 | Introduction to Data Governance | TechTarget definition; governance-as-government analogy; the 7 named DG (data governance) frameworks; "data exhaust" |
| 2 | Principles of Data Management and Governance | Governance vs management; DMBOK (Data Management Body of Knowledge)'s 8-element scope; 4 data management principles; provenance vs lineage; MDM (master data management) |
| 3 | Data Risks, Integrity and Security | 5-step risk process; 4 register headings; 12 identification methods; 5 challenges; 6 general + 3 application controls |
| 4 | Data Governance Frameworks | Principles → Policies → Processes → Standards; 4 GAIP (Generally Accepted Information Principles) principles; CDO (Chief Data Officer)'s 6 functions; 6 steward types; DGI's 10 components |
| 5 | Operating Model 2, Architecture and Metadata | The 4 execution scenarios; escalation path; Ladley on architecture and metadata; data fabric |
| 6 | Data Regulatory Compliance and Data Protection | GDPR (General Data Protection Regulation): 7 principles, 6 lawful bases, consent, controller vs processor, Arts. 28–32, Art. 9, Art. 25, Chapter V |
| 7 | Implementing Data Governance | Ladley's 8 phases; RACI (Responsible, Accountable, Consult, Inform); 3 maturity levels; 4 challenge quadrants; 4 objections; monetisation |
| 8 | Ethical Concepts and Frameworks | 3 branches; 4 normative families; Kant's imperatives; Rawls; Asimov; the 7 information-age values |
| 9 | Ethics and AI (artificial intelligence) | 3 direct + 5 broader concerns; historical bias and feedback loops; interpretability; the case studies |
| 10 | Privacy, Analytics and Ethics | UDHR (Universal Declaration of Human Rights) Art. 12, ECHR (European Convention on Human Rights) Art. 8, Charter Art. 8; 4 causes of bias; fairness; privacy-preserving AI; AIF360 (AI Fairness 360) |
| 11 | Governance of AI and Advanced Analytics | AI Act tiers and timeline; Recital 71 and Arts. 13/15/22/35; FAT/ML (Fairness, Accountability and Transparency in Machine Learning); direct vs indirect auditing |
| 12 | Future Trends | 4 trends; UN (United Nations) advisory group's 3 objectives; CRISP-DM (Cross-Industry Standard Process for Data Mining) adaptation; expanded CDO role |
Tap a card to reveal the answer. This module runs on numbered lists and multiple-choice questions feed on them.
Each of these is a place where being well-read can talk you into the wrong answer. Answer to the slides.
| Topic | What the slides say | What you might wrongly assume |
|---|---|---|
| Third leg of CIA (confidentiality, integrity, availability) | Week 3 says confidentiality, integrity and accessibility — twice | Availability. It appears only in the Art. 32 GDPR (General Data Protection Regulation) list |
| Integrity and security | "Data integrity is a desired result of data security" | The reverse. Distractors flip the direction |
| DGI (Data Governance Institute) components | The value-driven v2.0 set: Mission and Value, Beneficiaries, Data Products… | The classic 2006 set: Mission and Vision, Data Rules and Definitions, Data Stakeholders, DGO (Data Governance Office), Data Stewards. Only Decision Rights, Accountabilities and Controls appear in both |
| Data Owner | A type of Business Data Steward, with approval authority | A separate top-level role alongside steward and custodian |
| Maturity levels | Three: reactive, preemptive, proactive | A five-level CMMI (Capability Maturity Model Integration)-style model. Do not import one |
| Rawls | "Social justice based ethics" | Contractarianism. That word never appears in the module |
| Asimov's laws | Numbered 1–4, humanity-level law placed fourth | The Zeroth Law taking precedence over the first |
| Data quality dimensions | Five, including relevance | The DAMA (Data Management Association) UK six, including validity and uniqueness |
| GDPR fine tiers | One figure: up to €20m or 4% of global turnover | The two-tier structure. The €10m/2% tier is never taught |
| Data mesh | Never taught — Dehghani is not cited anywhere | That it is examinable. The only architecture pattern named is data fabric |
| DIKW (data, information, knowledge, wisdom) | The letters never appear in the slide text | That it is a named framework here. It survives only as an unlabelled graphic |
Data mesh and Dehghani. Data warehouse, lake, lakehouse. Federated governance as a named term.
GDPR breach notification and the 72-hour rule (Arts. 33–34). DPO (Data Protection Officer) designation and tasks (Arts. 37–39). The enumerated data subject rights — that slide is an image.
ISO/IEC (International Organization for Standardization / International Electrotechnical Commission) 42001 and 23894, IEEE (Institute of Electrical and Electronics Engineers) 7000, the NIST (National Institute of Standards and Technology) AI (artificial intelligence) RMF (Risk Management Framework), COBIT (Control Objectives for Information and Related Technologies). Floridi and AI4People. The trolley problem. k-anonymity and pseudonymisation as techniques.
Expand whichever topics you are shaky on. Everything here is quoted or closely paraphrased from the decks.
Twenty questions drawn at random from a pool of 100, with the answer order shuffled each time. Draw a new set as often as you like — you will get a different mix. Get one wrong and a fuller explanation opens beneath it.
Eight marks each, nine minutes each. Write your own answer first, then open the scaffold — the shape of a full-mark answer is define, apply a named framework, give a concrete example, then evaluate.