Skip to content

Advanced Performance Management · Data science and analytics

Data Governance, Quality and Ethical Issues in ACCA APM

Updated 11 October 2026 · Fact-checked

Data governance is the set of rules, roles and controls that keep an organisation's data accurate, secure, lawful and used fairly. In APM you identify the risks (poor quality, security, privacy, bias, cost), link each to the scenario, and recommend controls and ethical safeguards. Always weigh benefits against limitations.

Understand Data Governance, Quality and Ethical Issues

Big data and analytics can improve performance measurement. They give faster, richer and more detailed insight than traditional reports. But insight is only as good as the data behind it. APM tests whether you can see the risks and recommend sensible controls.

Data governance is the framework that decides who owns data, who may access it, how it is stored, how long it is kept, and how its quality is checked. Good governance gives clear ownership, written policies, and monitoring. Without it, different departments hold different versions of the same figure.

Data quality is about whether data is fit for its purpose. Common dimensions are accuracy, completeness, timeliness, consistency, validity and relevance. Big data is often high in volume and velocity but varied and uncertain in veracity. Data from social media, sensors or third parties may be incomplete, duplicated, out of date or unrepresentative. Analysing poor data gives poor decisions, quickly and at scale. This is often called garbage in, garbage out.

Security and privacy risks arise because large stores of data attract hackers and because staff can misuse them. Risks include breaches, ransomware, insider misuse and loss of customer trust. Privacy concerns cover collecting data without clear consent, using it for a purpose other than the one stated, keeping it too long, and sharing it with third parties. Laws on data protection apply, so non-compliance can bring fines and reputational damage. Do not quote specific legal penalties unless the question gives them.

Ethical issues and limitations include bias, lack of transparency and over-reliance on metrics. Algorithms trained on biased historical data can discriminate, for example in hiring, pricing or credit. Complex models may be a black box, so managers cannot explain decisions. Staff may feel monitored, which hurts morale, and may game the measures. Correlation is not causation, so patterns can mislead. There are also costs: software, skilled data scientists, storage, security and compliance. These can outweigh the benefits for a small firm, and the cost of failure can be large.

How to solve Data Governance, Quality and Ethical Issues questions

Use this method for any question on risks, limitations or ethics of data and analytics. It keeps your answer structured and tied to the scenario.

  1. 1Read the requirement. Note the verb (identify, evaluate, advise, recommend) and who you are writing for.
  2. 2Underline the scenario facts: type of data, source, who uses it, the decision it supports, and any hints of weakness.
  3. 3Group issues under headings: data quality, security, privacy and legal, bias and ethics, cost and practical limits.
  4. 4For each issue, state the risk, then link it to a specific fact in the scenario. Say what could go wrong for the business.
  5. 5Recommend a control for each major risk, such as data ownership, validation checks, access controls, consent, audit of algorithms and training.
  6. 6Balance the answer. Say where benefits of analytics justify the risk, and give a conclusion or recommendation.
  7. 7Show professional skills: be sceptical about data claims, be commercial about cost versus benefit, and communicate clearly in the format asked.

Quickest way: Five-heading sweep

When to use it: Use when time is short and you need a fast structure for a 10 to 25 mark requirement.

  1. Jot five headings: Quality, Security, Privacy, Bias and ethics, Cost.
  2. Pick the two or three that fit the scenario best and spend most time there.
  3. For each, write one risk sentence with a scenario fact, then one control sentence.
  4. Finish with a one-line judgement on whether benefits outweigh the risks.
  5. Check you have enough distinct points for the marks available, roughly one developed point per mark or two.

Common mistakes in Data Governance, Quality and Ethical Issues

  • Listing generic risks without using the scenario.

    Students memorise a list and write it out.

    Fix: Tie every point to a named fact, such as the data source or the decision affected.

  • Only describing problems and giving no controls.

    The word 'issues' makes students stop at identification.

    Fix: Pair each risk with a practical safeguard and who is responsible for it.

  • Confusing data quality with data security.

    Both sound like 'data problems'.

    Fix: Quality asks if data is fit to use. Security asks if it is protected from unauthorised access or loss.

  • Ignoring cost and the limits of analytics.

    Students assume big data is always beneficial.

    Fix: Mention set-up and running costs, skills shortages, and that correlation is not causation. Give a balanced view.

  • Treating ethics as only a legal matter.

    Privacy law is easy to recall, so ethics stops there.

    Fix: Add fairness, transparency, consent beyond legal minimum, and trust of customers and staff.

  • Inventing laws or penalties.

    Students try to sound precise.

    Fix: Refer to data protection law in general terms unless the question names a law.

Worked examples

Example 1

A retail chain plans to use customer loyalty-card data and social media data to set store-level performance targets. Data comes from several regional systems and a third-party supplier. Evaluate the data quality and privacy risks and recommend controls. (10 marks)

Show the solution
  1. Quality risk: regional systems may record sales and customer details differently, so figures are inconsistent and not comparable across stores. Targets based on them could be unfair.
  2. Quality risk: third-party social media data may be unrepresentative, since only some customers post, and may be out of date or unverified. Conclusions on demand could be wrong.
  3. Privacy risk: loyalty-card holders may not have consented to their data being combined with social media data or shared with a supplier. This could breach data protection law and damage trust.
  4. Control for quality: appoint a data owner, set common definitions, run validation and reconciliation checks, and test supplier data for reliability before use.
  5. Control for privacy: obtain clear consent, state the purposes, anonymise data where possible, limit access, and agree contract terms with the supplier on use and security.
  6. Judgement: the analysis can improve target setting, but only if data is reliable and lawful. Pilot in a few stores first to limit cost and risk.

Answer: The main risks are inconsistent and unrepresentative data leading to unfair targets, and use of personal data without proper consent. Recommend common data definitions, data ownership, validation, supplier checks, consent, anonymisation and restricted access, and pilot before full roll-out.

Example 2

A bank uses an algorithm trained on past lending decisions to approve small business loans. Managers say it is objective. Discuss the ethical issues and limitations. (8 marks)

Show the solution
  1. Bias: past decisions may reflect human bias, for example against certain areas or groups. The algorithm learns this and repeats it at scale, so it is not automatically objective.
  2. Transparency: a complex model may be a black box. Staff cannot explain a rejection to a customer, which harms fairness and may breach regulatory expectations.
  3. Data limits: historic data may not predict future conditions, and may omit new businesses with no track record. Correlations found may not be causal.
  4. Accountability: over-reliance on the model may let managers avoid responsibility. Someone must own decisions and handle appeals.
  5. Controls: test outputs for discriminatory patterns, document the model, keep human review for borderline or rejected cases, and audit regularly.
  6. Conclusion: the model can speed decisions and cut cost, but the bank should not call it objective without testing and oversight.

Answer: The algorithm may embed past bias, lacks transparency, relies on historic correlations, and can blur accountability. The bank should test for bias, explain decisions, keep human review and audit the model regularly, rather than assume objectivity.

Exam tips

  • Always anchor each risk to a scenario fact. Generic lists earn few marks.
  • Pair every risk with a control. Many requirements ask you to 'recommend' or 'advise'.
  • Use the professional skills marks: show scepticism about data claims and weigh cost against benefit.
  • If the question gives a role such as adviser to the board, write in that format and tone, briefly and clearly.
  • Link this topic to performance measures: poor data can distort KPIs and encourage gaming.

Practice questions from Data science and analytics

Data Governance, Quality and Ethical Issues in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Data Governance, Quality and Ethical Issues: frequently asked questions

What is data governance in ACCA APM?

It is the framework of policies, roles and controls that keeps data accurate, secure, lawful and properly used. You should name ownership, access control, quality checks and compliance. Apply these to the scenario given.

What are the main limitations of big data for performance measurement?

Data may be poor quality, unrepresentative or hard to interpret. Analysis can find correlations that are not causal, and set-up and running costs can be high. Managers may also over-rely on what is easy to measure.

How do I discuss ethical issues of analytics in the exam?

Cover privacy and consent, bias in algorithms, transparency and the effect on staff and customers. Link each to the scenario and suggest a safeguard. Go beyond legal compliance to fairness and trust.

Is data quality the same as data security?

No. Data quality is about whether data is accurate, complete, timely and fit for use. Data security is about protecting data from unauthorised access, loss or damage. Exam answers should keep them separate.