# Governance Starter Pack
Condensed data governance starter: systems register template fields, classification levels and first 30-day actions. Printable checklist, free with a quick email.
# Governance Starter Pack

     Rodan · First 30 days · guides.rodan.io

   Rodan · Resources · Governance

# Governance Starter Pack

   A condensed start: systems register fields, classification levels and the first thirty days of action. Enough to begin without boiling the ocean.

## What is inside

- Twenty register columns to copy into a sheet

- Public / Internal / Confidential / Restricted definitions

- Day 1–30 action sequence with owners

- Links to the full toolkit and self-assessment

     Email unlocks the full printable pack. Free to access, we just ask for an email.

     Print pack **
    [Score governance](/governance/assess)

## Principles for week one

- CFO or equivalent owns governance at mid-market. IT enables.

- Include spreadsheets, pixels and shadow systems in the register.

- Classification drives access. Do not invent a fifth level on day one.

- Perfect is the enemy. A living 80% register beats a perfect one that never ships.

## Systems register template fields

     Copy these twenty columns into a sheet. One row per system (including material spreadsheets).

          #  Field  Notes

          1  System name  Human-readable, unique

          2  Vendor / hosting location  SaaS vendor or self-host region

          3  Business owner  Named person, not a team alias

          4  Purpose  Why the system exists

          5  Data categories  Customer, finance, HR, product, etc.

          6  Personal data flag  Yes / No

          7  Special category flag  Yes / No

          8  Classification  Public / Internal / Confidential / Restricted

          9  Lawful basis  If personal data

          10  Volume (approx)  Records or scale band

          11  Source  Where data enters from

          12  Flows to  Downstream systems

          13  Access controls  SSO, MFA, role model

          14  DPA status  Signed / missing / N/A

          15  Transfer mechanism  If outside UK / EEA

          16  Retention rule  Policy or “unknown”

          17  Backup / recovery  Tested? RTO note

          18  Criticality  Trading / reporting / low

          19  Contract renewal  Date or N/A

          20  Notes / risks  Open issues

## Classification levels

          Level  Definition  Examples

          Public  No harm if disclosed  Published marketing, public price lists

          Internal  Minor harm  Process docs, org charts

          Confidential  Material harm  Customer lists, financials, contracts

          Restricted  Severe harm  Special category data, payment data, M&A material

     Access, sharing and AI connections follow the highest classification of data in the system.

## First 30-day actions

### Days 1–7

- Name a governance lead and a fortnightly 30-minute forum

- Draft the register sheet with the twenty columns above

- List the top 15 systems by criticality (include finance, CRM, warehouse, storefront, HR)

- Agree the four classification levels with leadership in one page

### Days 8–14

- Complete register rows for the top 15 (owners, personal data, DPA status)

- Flag shared admin logins and missing MFA on Confidential / Restricted systems

- Identify the three metrics that cause the most board argument; note source systems

### Days 15–21

- Classify every row in the top 15

- Chase missing DPAs for processors that touch personal data

- Write a one-page retention default for customer and prospect records

### Days 22–30

- Close or schedule the top five access and DPA gaps

- Publish the register location and review cadence (twice a year minimum)

- Run the [governance self-assessment](/governance/assess) and keep the score for the next forum

- Park AI / new analytics work that would touch unclassified personal data

## What not to do in month one

- Do not buy a governance platform before the register exists

- Do not write a 40-page policy nobody will read

- Do not invent custom classification labels

- Do not connect an LLM to Shopify, CRM or HR until classification and DPAs are honest

      [Full governance toolkit](/governance/toolkit)
      [Self-assessment](/governance/assess)
      [AI readiness checklist](/resources/ai-readiness-checklist)
HTML: https://rodan.io/resources/governance-starter-pack
