Most organisations don't wait for something to go wrong before deciding who can access their data. They have owners, permissions, policies and processes designed to control how information is stored, shared and used. The problem is that most of those decisions are made for normal working conditions. A crisis changes the conditions. 

Decisions need to happen faster. Information may be incomplete or changing by the hour. The person who normally approves access might not be available, while teams, partners or public bodies that don't usually exchange data may suddenly need to work together. 

This is where an organisation can discover that having data governance isn't quite the same as having data governance that works under pressure. Research from UNESCO and CODATA suggests there's already a gap between recognising this problem and preparing for it. In their 2026 global survey on data policies for times of crisis, 78 per cent of respondents said a crisis-data checklist would be beneficial. 

em360tech image

Only 22 per cent already had one. That gap is helping bring more attention to crisis-ready data governance, and to a fairly simple question. If normal operating conditions suddenly change, can people still get the data they need and use it safely?

What Is Crisis-Ready Data Governance?

Crisis-ready data governance is the preparation of data rules, responsibilities and processes so an organisation can continue to find, access, understand, trust and responsibly share important data during disruption. 

The term itself is still emerging rather than representing a universally defined enterprise discipline. However, the problem behind it is well established. UNESCO and CODATA have been developing it through their work on Data Policies for Times of Crisis (DPTC), including a toolkit published in June 2025. 

That work looks at data across crisis preparedness, response and recovery. The aim isn't simply to make more information available. Data also needs to be usable, trustworthy and managed responsibly, particularly when organisations are making important decisions quickly or sharing information beyond their usual boundaries. 

For an enterprise, the crisis itself could take many forms. A cyberattack, infrastructure outage, natural disaster or another major disruption could all change what information people need, how quickly they need it and who needs access. Crisis-ready governance prepares for those changes before people are trying to work them out while the disruption is already happening.

How Is Crisis-Ready Data Governance Different From Normal Data Governance?

Normal data governance creates order around information. It establishes who owns data, who can access it, how it should be classified, what quality standards apply and how organisations keep it secure and compliant. Those rules don't suddenly become irrelevant during a crisis. If anything, they're more important. 

What changes is the environment they're expected to work in. A process built around approval from one data owner becomes a problem if that person is unavailable. A carefully controlled dataset isn't very useful if the team making an urgent decision can't access it. 

And two organisations can both have excellent data management practices while using formats or definitions that make exchanging information surprisingly difficult. Crisis-ready data governance therefore asks another layer of questions:

  • What changes when the normal owner isn't available?
  • Who can authorise emergency access?
  • Which rules remain fixed, and which processes need a predefined alternative?
  • How will information be shared with organisations that don't normally receive it?

It's less about creating a separate governance system for emergencies and more about making sure the existing one doesn't depend entirely on normal conditions remaining normal.

Is crisis-ready data governance the same as disaster recovery?

Crisis-ready data governance naturally overlaps with disaster recovery and business continuity, but they solve different parts of the problem. Disaster recovery is primarily concerned with restoring technology, systems and data after disruption. Crisis-ready data governance is concerned with whether people can still use the right information appropriately while the organisation is responding. 

A database can be available without the people using it knowing whether its information is current. A restored system can contain several versions of the same dataset without making it obvious which one should guide a decision. Recovery keeps information available. Crisis-ready governance helps keep it useful.

Why Normal Data Governance Can Break Down During A Crisis

A crisis doesn't necessarily create new data governance weaknesses. Often, it reveals assumptions that were easy to live with when there was enough time to work around them. Consider something as ordinary as an approval process. Under normal conditions, a team requests access, the appropriate owner reviews it and permission is granted. 

If the request is unusual, people can have a meeting, ask legal or security for advice and work out what to do. Now compress that process into an hour. The same organisation may need information immediately, while the usual owner is unavailable and an external partner needs part of the dataset too. Nobody is necessarily doing anything wrong. 

The process simply wasn't designed for the situation it's now being asked to handle. The UNESCO/CODATA survey gives some indication of where organisations see these weaknesses. Respondents identified capacity building and training as the area most in need of attention at 43 per cent, followed by risk governance at 40 per cent. 

Interoperability and real-time systems were identified by 38 per cent, while 36 per cent pointed to both operationalisation and ethical data principles. These problems tend to meet each other during a crisis. People need information quickly, but the authoritative dataset isn't clear. The data exists, but another system can't interpret it. 

Sharing is technically possible, but nobody knows what they're permitted to disclose. Good policies can only help if people can actually use them under the conditions they're designed to govern.

What Makes Data Governance Crisis-Ready?

There isn't one technology or policy that makes data governance ready for disruption. Readiness comes from knowing how the organisation will preserve the things good governance already depends on when circumstances change. 

That includes availability, clear authority, data quality, provenance, timely access, interoperability and responsible sharing. Together, those capabilities answer three practical questions.

Can people find and trust the right data?

Having access to data isn't enough if people can't tell whether they're looking at the right version. Teams need to know which sources are authoritative, who owns them and how recently they've been updated. Data provenance, which records where information came from and what has happened to it, can also help people judge whether it remains suitable for the decision they're making. 

UNESCO and CODATA's approach draws partly on the FAIR principles, which call for data to be Findable, Accessible, Interoperable and Reusable. Those qualities become particularly useful when people have less time to hunt for information or resolve uncertainty manually.

Can the data move where it's needed?

Two systems having access to the same information doesn't mean they can automatically use it together. Different formats, definitions and technical standards can turn data exchange into a manual translation exercise. During ordinary operations, that's inefficient. During a fast-moving crisis, it can delay the decisions the data was supposed to support. 

This helps explain why common standards were the leading priority in the UNESCO/CODATA survey, selected by 48 per cent of respondents. Data interoperability gives systems and organisations a shared way to exchange and understand information rather than simply moving files between them.

Can people access and share it responsibly?

Speed doesn't remove an organisation's responsibility to protect sensitive information. Emergency access may need to be broader or work differently, but those decisions still need boundaries. Organisations need to know what can be shared, with whom, under what circumstances and who has the authority to approve an exception. 

There are already practical examples of this approach in humanitarian response. OCHA's Data Responsibility Guidelines cover the safe, ethical and effective management of operational data, including privacy and information-sharing requirements. Its work also uses Information Sharing Protocols to establish how data should be exchanged during a response. 

The lesson for enterprises isn't to copy a humanitarian framework. It's that responsible sharing becomes much easier when the difficult decisions have been considered before someone urgently needs an answer.

How Can Organisations Prepare Data Governance For A Crisis?

No organisation can predict every crisis or know exactly what information people will need. It can still remove many of the avoidable questions that slow a response down. A useful starting point is identifying which datasets would become critical if important services, suppliers, locations or systems were disrupted. 

Are you enjoying the content so far?

From there, organisations can establish the authoritative source, map who owns it and identify the systems and people it depends on. Emergency access and sharing arrangements can then be considered before they're needed. 

That includes fallback authority if the normal owner isn't available, rules for external sharing and practical checks that another team or organisation can actually use the information it receives. For leaders reviewing their current data governance, a few questions can reveal where more preparation may be needed:

  • Which data would become critical first?
  • Where is the authoritative version, and who owns it?
  • Who can authorise access if the normal owner isn't available?
  • Which teams or external organisations might suddenly need it?
  • Can their systems understand and use the data?
  • What information can and can't be shared?
  • What happens if the usual system or data pathway is unavailable?
  • Have these arrangements ever been tested?

The aim isn't to build a process for every disaster anyone can imagine. It's to identify decisions that are predictable enough to make now, rather than leaving people to improvise them later.

Why Testing May Matter More Than Having A Policy

A crisis plan can look perfectly reasonable when everyone reviewing it has time, access to the usual systems and all the right people sitting around the table. Testing changes the question from whether the plan makes sense to whether it actually works. 

An exercise might reveal that an approval route takes too long, a backup owner doesn't have the permissions they thought they had or information from one system can't be used by another. These are much cheaper discoveries during a simulation than during a real incident. There's already evidence of the difference preparation can make. 

Deloitte's assessment of the UK's 2026 Dynamic General Insurance Stress Test found that firms that had rehearsed governance routes, assigned responsibilities and established data pathways were better able to turn analysis into decisions during the simulated shocks. UNESCO and CODATA are moving in a similar direction. 

Their next phase is expected to use case studies and pilots to test the DPTC checklist in practice, gather feedback and refine the toolkit rather than treating published guidance as the finished product. That's where crisis-ready data governance stops being a policy exercise. 

The real test isn't whether the organisation has documented what people are supposed to do. It's whether those arrangements still produce trustworthy, usable information when people have to work differently.

Final Thoughts: Good Data Governance Has To Work When Normal Operations Don't

Most data governance is created during periods when people have time to follow established processes. A crisis removes some of that certainty. People change roles, information changes quickly, normal systems may not be available and decisions that usually take days can suddenly need answers within hours. 

Crisis-ready data governance doesn't replace the policies, ownership structures or controls organisations already have. It asks whether they remain useful when the assumptions behind them change. The emerging work from UNESCO and CODATA suggests organisations already recognise the gap. The harder part is turning that recognition into processes people can actually use, then testing those processes before they're needed. 

As the planned pilots and case studies begin providing more evidence about what works in practice, crisis-ready data governance is likely to become a more concrete part of the wider data resilience conversation. EM360Tech will continue following that shift as organisations move from knowing they need to prepare towards understanding what good preparation actually looks like.