A method for simultaneously carrying out data management in a system when building a new business information system

By introducing data management and supervision standards in the early stages of building a new business information system, the source avoidance of data quality problems and seamless integration of enterprise-level data governance were solved, achieving unified and secure compliance of system data and improving data governance efficiency and resource reuse capabilities.

CN122132379APending Publication Date: 2026-06-02CHONGQING TSINGSHAN IND

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHONGQING TSINGSHAN IND
Filing Date
2025-12-10
Publication Date
2026-06-02

Smart Images

  • Figure CN122132379A_ABST
    Figure CN122132379A_ABST
Patent Text Reader

Abstract

This invention relates to the technical fields of data quality, data management, and data governance. Specifically, it relates to a method for simultaneously conducting data governance within a newly built business information system. This method establishes a general data management standard covering data specifications, database specifications, and process specifications; builds a supervisory standard that runs through the entire process of project requirements analysis, design, development, deployment, and operation and maintenance; and integrates these two types of standards into the technical requirements of the newly built business system project. Data governance is implemented step-by-step at each stage of the project, thus avoiding data quality problems from the source of business system construction. This avoids the additional costs and schedule risks of traditional post-event governance, ensures that the system data format is uniform, secure, and compliant, and can seamlessly integrate with the enterprise's existing data governance system, solving the problems of data silos, redundancy, and inconsistency in multi-system parallel scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical fields of data quality, data management, and data governance, and specifically to a method for simultaneously carrying out data governance within a newly established business information system. Background Technology

[0002] In the process of enterprise digital transformation, newly built business information systems have become the core carriers supporting business expansion and improving operational efficiency. The quality of data governance within these systems directly determines the efficiency of data asset value conversion. High-quality data governance not only ensures the consistency, accuracy, and security of business data but also provides crucial support for cross-system data integration, intelligent decision analysis, and business process optimization. Therefore, the data governance phase when building new business information systems has become a core prerequisite for enterprises to avoid data silos, reduce subsequent rectification costs, and realize the implementation of their digital strategies.

[0003] Traditional data governance technologies generally adopt a reactive approach: "business systems are built first, data governance follows." This means that after the business systems have been deployed and running for a period of time, the accumulated business data (such as customer information, transaction records, and production parameters) is cleaned, standardized, and integrated. However, those skilled in the art have found through long-term practice that this model has many unavoidable technical flaws, such as: ① Under the post-event governance mechanism, system data problems (such as inconsistent data formats, redundancy and duplication, missing key fields, etc.) have already actually affected the business execution process, which may lead to problems such as order processing errors, inventory statistics deviations, and inaccurate decision-making. Moreover, the scope and extent of the impact of the problems are difficult to predict in advance, and subsequent corrections require additional business adjustment costs. ② After the business system is built, the supplier (i.e. the project implementer) usually withdraws. The subsequent data governance requires the enterprise to invest manpower and funds to re-sort out the system architecture and data links. Not only is the rectification cycle long, but it also requires coordination with business departments to suspend some system functions, which can easily interfere with normal operations. ③ Traditional post-event governance only optimizes data from a single system or a local area, without connecting with the overall enterprise data governance system. This results in inconsistent data standards between newly built systems and existing systems. When integrating data across systems, format conversion and consistency verification still need to be repeated, creating new data barriers and making it impossible to achieve efficient reuse of enterprise-level data resources.

[0004] Those skilled in the art have attempted to improve governance effectiveness by optimizing data processing workflows or building dedicated platforms to address the shortcomings of traditional post-event governance. However, this has not yet resolved the core pain points of data governance in newly established business information systems, namely, "loss of control at the source, difficulty in implementation, and insufficient collaboration." For example: The publication CN114298550A, titled "A Method for Governing Cement Production and Operation Data," organizes business data in the cement production field through a full-process design encompassing data integration, standardization, development, and quality management. However, its technical shortcomings are as follows: (1) This method only processes the existing production and operation data and does not intervene in the source links of business system construction (such as system design and database planning stages). It cannot fundamentally avoid the source problems such as inconsistent data standards and unreasonable data models. The governance only stays at the level of "compromise to correct existing data" and cannot completely solve the root cause of poor data quality. (2) The governance results can only support data-related applications (such as production data analysis and cost accounting), and are not deeply integrated with business management processes. They cannot optimize the core links of business system operation logic and approval nodes through data governance, and have limited actual effects on improving business management efficiency and simplifying operation processes. (3) This method is designed for cement production scenarios. The data model and standard specifications are strongly tied to the industry and lack universality. It is difficult to directly adapt to the governance needs of newly built business information systems in other industries (such as manufacturing, finance, and retail), and its scope of application is narrow.

[0005] The patent application CN112396404A, titled "A Data Platform System," provides enterprises with tools to support data integration and sharing by constructing a modular architecture for data aggregation, fusion, governance, service, and asset management. Its technical shortcomings are as follows: (1) The system only provides data governance tool modules (such as metadata management, data lineage analysis, and quality verification tools), without formulating a governance method for the entire life cycle of the newly built business system (such as data standard embedding in the requirements analysis stage and compliance review process in the development stage), and without clarifying data development specifications (such as table structure design rules and field naming standards). As a result, enterprises can only use tools to perform fragmented data processing, and cannot form a complete governance closed loop of "standardization-execution-supervision-optimization", making it difficult to complete the implementation of governance independently. (2) The system focuses on centralized management and sharing of data, but does not design an adaptation mechanism for the "synchronous governance" requirements of newly built business systems. It cannot embed governance requirements in real time during the system construction process. Data import and governance still need to be carried out through the middle platform after the system is built. In essence, it is still "post-event supplementary governance" and cannot solve the source data quality problem. (3) The system lacks connection with the project management process of the newly built business system. It does not set up governance checkpoints at key nodes such as project design, development, deployment and acceptance, which leads to the disconnect between data governance and system construction progress. It is easy to have the situation of "the system has been launched but governance has not been completed", which cannot guarantee the timeliness of governance work.

[0006] In summary, while existing data governance technologies attempt to address the shortcomings of traditional post-event governance by optimizing data processing workflows or building tool platforms, they have still failed to fully overcome the core technical bottlenecks in data governance for newly built business information systems. In terms of timing, it is impossible to achieve "synchronization of system construction and governance"; in terms of depth, it is impossible to avoid data quality problems from the source; in terms of implementation capability, there is a lack of supporting methodologies and execution mechanisms; and in terms of collaboration, it is impossible to effectively connect with the enterprise's overall data governance system and business management processes.

[0007] These shortcomings lead to inefficient and unstable data governance in newly built business systems, which not only restricts the release of data asset value but may also become an obstacle to enterprise digital transformation.

[0008] Therefore, how to develop a new data governance solution that can simultaneously embed governance requirements in the early stages of building a new business information system, ensure data quality from the source, provide complete implementation methods and standards, and seamlessly integrate with the enterprise's existing governance system has always been a problem that those skilled in the art urgently need to solve. Summary of the Invention

[0009] The purpose of this invention is to address the shortcomings of existing technologies by providing a method for simultaneously conducting data governance within a newly built business information system. This method establishes a universal data management standard covering data specifications, database specifications, and process specifications; builds a supervisory standard that runs through the entire process of project requirements analysis, design, development, deployment, and operation and maintenance; and integrates these two types of standards into the technical requirements of the newly built business system project. Data governance is implemented step-by-step at each stage of the project, avoiding data quality issues from the source of business system construction. This avoids the additional costs and schedule risks of traditional post-event governance, ensures unified system data format, security and compliance, and seamless integration with the enterprise's existing data governance system, resolving data silos, redundancy, and inconsistency issues in multi-system parallel scenarios.

[0010] The objective of this invention is achieved through the following approach: A method for simultaneously conducting data governance within a newly established business information system includes the following steps: 1) Determine the business system to be built, as well as its data management needs, data governance processes, and technical requirements; 2) Based on the data management needs of the business systems, establish data control standards to regulate the data management of the business systems; 3) Based on the data governance process of the business system, establish supervision standards to regulate the data governance process; 4) In accordance with the technical data management and supervision standards, complete the data governance within the business system during the business system construction process.

[0011] This invention establishes a general data management standard covering data specifications, database specifications, and process specifications. It builds a supervisory standard that runs through the entire process of project requirements analysis, design, development, deployment, and operation and maintenance. It integrates the two types of standards into the technical requirements of new business system projects, and implements data governance step by step at each stage of the project. This avoids data quality problems from the source of business system construction, avoids the additional costs and schedule risks of traditional post-event governance, ensures that the system data format is uniform, secure and compliant, and can be seamlessly integrated into the enterprise's existing data governance system. It solves the problems of data silos, redundancy and inconsistency in multi-system parallel scenarios.

[0012] Preferably, in step 2), the data management and control specifications include data specifications, database specifications, and process specifications, wherein, The data specifications include data quality specifications, data standard specifications, master data specifications, reference data specifications, indicator specifications, and data security specifications. The database specifications include the specifications for comments on tables, attributes, functions, and stored procedures, as well as the specifications for ER diagrams between tables; The process specifications include business flow specifications and data flow specifications.

[0013] This invention precisely categorizes data governance standards into three core types: data standards, database standards, and process standards. This directly defines the scope of standards that must be followed during the construction of business systems, eliminating the need for additional interpretation or supplementation and preventing execution deviations and confusion caused by "vague boundaries of governance standards" from the outset. Furthermore, this classification and sub-item setup comprehensively covers the key stages of the entire data lifecycle, from generation (data standards ensure source quality), storage (database standards ensure technical compliance), to circulation (process standards clarify the logical flow). These three aspects are interconnected to form a governance closed loop, effectively preventing loopholes in data governance caused by the absence of standards in any stage and ensuring the integrity of the governance work.

[0014] Preferably, the data quality specifications include data quality indicators, key data domains, data quality standards, data cleaning rules, data quality monitoring mechanisms, data quality problem rectification procedures, and data processing compliance requirements. The data standards and specifications include data status, data naming conventions, data formats and standard values, and data lifecycle management specifications; The master data specification includes the scope of master data, data usage, master data standards, master data model, and master data governance framework; The reference data specifications include the reference data scope, data usage, and reference data architecture; The indicator specifications include indicator specification objectives, indicator system, indicator naming and definition, indicator calculation methods, indicator dictionary, and hierarchical and classified management; The data security specifications include formulating data security policies and access strategies, controlling data access, classifying and labeling data, performing data backup and recovery, and auditing and monitoring data operations.

[0015] Preferably, in step 3), the specific content of the supervision specification is as follows: 3-1) The project requester determines the detailed design document of the business system, and based on the detailed design document, divides the entire process of the business system project construction into key nodes such as technical agreement signing, detailed design, development and deployment and final acceptance, and sets up node supervision at each key node. 3-2) During the technical agreement phase, the project requester shall incorporate data management specifications into the project technical requirements and technical agreement documents, and shall be responsible for reviewing the data management specifications. If the specifications are not met, the technical agreement phase node review shall not be approved. 3-3) During the detailed design phase, the project implementer shall carry out design work in accordance with the data management and control specifications, build the business system, and have the project requester review whether the business system meets the specification requirements. If the requirements are not met, the detailed design phase node review will not be passed. 3-4) During the development and deployment phase, the project implementer needs to deploy the business system, and the project requester needs to verify the consistency between the deployed business system and the business system in the detailed design document. If there are discrepancies between the two and they do not meet the standard specifications, the node review of the development and deployment phase will not be passed. 3-5) During the final acceptance review stage, the project requester shall conduct a comprehensive review of whether the entire process of implementing the business system complies with the data specification requirements. If the requirements are not fully met, the final acceptance review shall not be passed.

[0016] This invention divides the entire business system construction process into four key nodes: technical agreement signing, detailed design, development and deployment, and final acceptance. It directly transforms abstract supervision requirements into concrete tasks focusing on core aspects, avoiding oversights or a scattered focus of supervision. Furthermore, it forms a progressive supervision logic around these key nodes (data management standards are embedded into core requirements during the technical agreement stage, avoiding the rectification costs of supplementing standards later; during the detailed design and development and deployment stages, the responsibilities of the implementer to execute the standards and the client to verify compliance are clearly defined, ensuring that the process is not compromised; and during the final acceptance stage, the implementation of standards throughout the entire process is comprehensively verified, achieving comprehensive supervision). This mandates that project implementers attach importance to and implement data governance requirements, completely avoiding the problem of supervision becoming a mere formality.

[0017] Preferably, in step 3-1), the entire project construction process includes the stages of requirements analysis, system design, system development, system testing, system deployment, and system operation and maintenance, and the supervision process of node supervision includes regular data quality audits, code reviews, security testing, and compliance checks.

[0018] Preferably, in step 4), the data governance within the business system is completed in the following manner: 4-1) Technical data management and supervision standards shall be used as technical requirements in the business system construction process, and data management checkpoints shall be set up at the detailed design, development and deployment and final acceptance nodes of the business system. 4-2) At the detailed design stage, the project implementer conducts a detailed design of the business system in accordance with the data management and control specifications, and the project requester reviews it. If the review is passed, the next step of work is carried out. If the review is not passed, the project implementer re-rectifies it until it meets the requirements. 4-3) At the development and deployment stage, the project implementer shall develop and deploy the business system in accordance with the data management and control specifications, and the project requester shall review the deployed business system. If the review is passed, the next step shall be carried out. If the review is not passed, the project implementer shall make corrections until the requirements are met. 4-4) During the final acceptance phase, data documents are organized and delivered in accordance with the data management and control specifications. The project requester reviews the business system in accordance with the data management and control specifications. If the review is passed, the project requester accepts the business system. If the review is not passed, the project implementer reorganizes and improves the system until it meets the specifications and can complete the data governance of the business system construction process.

[0019] Preferably, in step 4-4), the data type documents include data standard documents, master data documents, reference data documents, data dictionaries, ER diagrams, business flows, and data flow documents.

[0020] The beneficial effects of this invention include the following: ① This invention adopts a proactive governance model that synchronizes business system construction and data governance. At the source of system construction (requirements analysis, system design, development deployment, etc.), data specifications (data, database, process specifications) and a full-process supervision mechanism are clearly defined. This avoids problems such as inconsistent data formats, redundancy, and unreasonable models from the source, preventing data issues from affecting business execution and causing order errors, inaccurate decisions, etc. Furthermore, this invention, through node reviews in the supervision specifications, compels project implementers to execute according to the specifications, eliminating the need for additional manpower and funds for rectification after system development is completed, and also avoiding the need to suspend business system functions, thus avoiding disruption to operations. ② This invention directly breaks down data silos between different business systems by constructing a universal data management and control standard. This allows previously fragmented data, adhering to different standards, to circulate and interact according to a unified standard, significantly reducing problems such as redundant processing and interpretation errors caused by data inconsistency, and achieving efficient reuse of enterprise-level data resources. Furthermore, this invention deeply integrates the data management and control standard with business management processes, ensuring that data management rules are closely aligned with the operational logic and workflow of actual business operations, guaranteeing that the data management and control standard can be truly implemented and effective. ③ This invention not only establishes data management and control standards but also formulates supporting supervision standards for the entire lifecycle of business systems. By clarifying governance checkpoints and review processes for key nodes such as technical protocols, detailed design, development and deployment, and final acceptance, a complete governance closed loop of "standard formulation - implementation - supervision and review - acceptance confirmation" is formed. Furthermore, this invention incorporates data management and control standards and supervision standards as project technical requirements, ensuring deep integration of various standards with project management processes. This guarantees that data governance and system construction progress are synchronized, ensuring the timeliness and feasibility of governance.

[0021] Definitions: Project implementer: refers to the entity that undertakes project requirements, is responsible for implementing the project plan and ensuring delivery. It is usually a company, team or individual with technical, human or execution capabilities, and is often referred to as "Party B" or "contractor". Its core responsibility is to promote project implementation, including resource allocation, progress control and quality assurance.

[0022] Project requester: refers to the entity that proposes project goals, clarifies business requirements, and ultimately receives and accepts project deliverables. It is usually the project initiator or beneficiary, often referred to as "Party A", "owner", or "client". Attached Figure Description

[0023] Figure 1 This is a flowchart illustrating the method for simultaneously implementing data quality management within a newly established business system according to the present invention. Figure 2 This is an example of the "Data Quality Specification Document Delivery Template" in this invention; Figure 3 This is an example of the "Basic Data Standard Template" in this invention. Figure 3 (a) is the first part of the example of the "Basic Data Standard Template" Figure 3 (b) is the second part of the example horizontal row of the "Basic Data Standard Template". Figure 3 (c) is the third part of the example horizontal row of the Basic Data Standard Template; Figure 4 This is an example of the "Data Hierarchical Classification Catalog Template" in this invention; Figure 5This is an example of the "Indicator Standard Definition Template" in this invention. Figure 5 (a) is the first half of the example of the "Indicator Standard Definition Template" Figure 5 (b) is the latter half of the example of the "Indicator Standard Definition Template"; Figure 6 Here is an example of a table annotation and explanatory document template; Figure 7 This is an example of a field description document template. Figure 7 (a) is the first half of the example paragraph description document template. Figure 7 (b) is the second half of the example paragraph description document template; Figure 8 This is a sample code template for a stored procedure. Figure 9 This is an example of the "Data Inventory Template" in this invention. Figure 9 (a) is the first half of the "Data Inventory Template" example. Figure 9 (b) is the latter half of the "Data Inventory Template" example; Figure 10 Example of a flowchart for implementing a business system project. Detailed Implementation

[0024] like Figures 1 to 10 As shown, a method for simultaneously carrying out data governance within a newly established business information system includes the following steps: 1) Determine the business system to be built, as well as its data management needs, data governance processes, and technical requirements; 2) Based on the data management needs of the business systems, establish data control standards to regulate the data management of the business systems; 3) Based on the data governance process of the business system, establish supervision standards to regulate the data governance process; 4) In accordance with the technical data management and supervision standards, complete the data governance within the business system during the business system construction process.

[0025] Based on the above method, the following is an example: 1) Determine the business system to be built, as well as its data management needs, data governance processes, and technical requirements; 2) Based on the data management needs of the business system, establish data control standards as unified rules for data standards, database design, and data flow processes to regulate data management in the business system; In this embodiment, the data management and control specifications include data specifications, database specifications, and process specifications, wherein, The data specifications include data quality specifications, data standard specifications, master data specifications, reference data specifications, indicator specifications, and data security specifications. They primarily define standard data formats, naming rules, encoding methods, and data types to ensure data consistency and understandability throughout the organization. For example, they stipulate that date formats should be uniformly YYYY-MM-DD, text data should be despaced, and there are precision requirements for numerical data. Data specifications help improve data quality and reduce data interpretation errors. The specific construction process is as follows: (1) Establish data quality standards: (1-1) Clearly define the supporting value of data quality to business objectives, such as improving customer satisfaction and reducing the cost of incorrect decisions. Simultaneously set specific and quantifiable data quality indicators (including accuracy, completeness, consistency, timeliness, effectiveness, etc.) to ensure that the direction of data quality control is consistent with business objectives.

[0026] (1-2) Identify data elements that have a critical impact on business operations. Such data are usually core data in decision-making and business process operation. Based on the degree of impact of the data on the business, prioritize key data domains and identify the objects that need to be monitored and managed at the highest level.

[0027] (1-3) Establish clear quality standards for each key data domain, covering dimensions such as data format, value range, and allowed values; simultaneously develop data cleaning rules to standardize data that does not meet quality standards and ensure that the data meets business usage requirements.

[0028] (1-4) Use automated tools to conduct data quality checks regularly. The checks include data verification, data cleaning, and data comparison. At the same time, deploy a real-time monitoring mechanism to ensure that data quality problems are detected and resolved in a timely manner, and to avoid the accumulation of problematic data from affecting business operations.

[0029] (1-5) When data quality issues are detected, a clear processing flow should be established, and the issues should be recorded, reported, and analyzed in sequence. Corrective measures should be implemented, including data repair, root cause analysis, and preventive measures, forming a closed-loop management of "discovery-processing-prevention".

[0030] (1-6) Ensure that the data processing process complies with industry standards, laws and regulations and the company’s internal security policies. By implementing access control, data encryption and other technical and management measures, a sensitive data protection mechanism is built to prevent the risk of data leakage or misuse.

[0031] Based on the above steps, a "Data Quality Specification Document Delivery Template" (e.g., for newly established business systems) is proposed. Figure 2 (As shown).

[0032] (2) Establish data standards and specifications: (2-1) Assess the data status of the new business system, including data storage location, data type, existing data quality level, etc. Through systematic review, accurately identify data redundancy, data inconsistency and potential data quality problems, so as to provide objective basis and basic support for the subsequent formulation of data standards.

[0033] (2-2) Establish data naming standards. For core data objects such as data elements, database tables, and fields, establish unified naming rules to ensure the clarity, consistency, and comprehensibility of the names. The naming rules may include specific requirements such as prefixes, suffixes, and case uniformity to ensure that the names accurately reflect the business meaning and actual use of the data, and facilitate data understanding and reuse across departments and processes.

[0034] (2-3) Establish a data format and standard value system. Define a unified standard format for different types of data such as date, time, numerical, and text. Clarify the list of allowed values ​​or range of values ​​for each data type. In particular, for enumerated data, the boundaries and optional values ​​must be strictly defined to ensure the standardization of data input from the source and avoid data chaos caused by inconsistent formats or values.

[0035] (2-4) Formulate data lifecycle management specifications to clarify the management rules and operating standards for each stage of the data lifecycle, including creation, updating, archiving, and destruction. This includes the responsible parties, operating procedures, and audit requirements for each stage, ensuring that the data always meets the enterprise's compliance requirements and business needs throughout the entire lifecycle, while avoiding invalid data occupying storage resources or the loss of critical data.

[0036] Based on the above steps, a "Basic Data Standard Template" for newly established business systems will be created, such as... Figure 3 As shown, where Figure 3 (a) Figure 3 (b) Figure 3 (c) By combining the data, you can obtain the complete example table of the "Basic Data Standard Template".

[0037] (3) Establish master data specifications: (3-1) First, define the scope of master data in the new business system. It is clear that master data must be basic data that supports business operations and is shared across systems. It usually covers core data types such as customer information, product information, supplier information, and organizational information to ensure that the boundaries of master data are clear and highly matched with business needs.

[0038] (3-2) Conduct a systematic survey of the master data usage scenarios and flow paths of the newly established business system, accurately identify the inconsistencies and underlying causes of the current data; at the same time, combine business process nodes and system functional requirements to comprehensively analyze the specific requirements of the business side and the system side for master data, and provide a realistic basis for the subsequent master data specification formulation.

[0039] (3-3) Establish core control rules for master data elements, including unified naming rules, standard data formats, clear value ranges and standardized coding rules, so as to ensure the uniqueness, integrity, consistency and accuracy of master data; when classifying master data, it is necessary to achieve "no duplication and no omission" in data classification, and the level of detail should take into account both the needs of statistical analysis and the convenience of daily management, so as to avoid inconvenience caused by being too coarse or too fine.

[0040] (3-4) Build a structured master data model, covering core contents such as entity relationship diagram (ER diagram), data attribute definition, and standardized data dictionary, clearly defining the relationship and attribute constraints between master data entities, and providing a clear blueprint for subsequent structured data storage, processing and sharing.

[0041] (3-5) Develop supporting data governance strategies, specifically covering data ownership allocation (clarifying the responsible entities for each master data domain), approval process standardization (setting approval nodes for adding / changing / deleting master data), change management mechanism (establishing full-process control over the application, review, and implementation of master data changes), data quality monitoring plan (regularly checking the master data quality compliance status), and daily maintenance mechanism (ensuring continuous updates and optimization of master data), forming a closed-loop master data governance system.

[0042] Based on the above steps, a "Data Hierarchical Classification Directory Template" for newly established business systems will be created, such as... Figure 4 As shown.

[0043] (4) Establish reference data standards: (4-1) Define the specific dataset scope of reference data, and clarify the typical reference data types such as industry standard codes (e.g., national unified product classification codes, industry compliance codes) and enterprise internal classification systems (e.g., material classification systems and customer classification directories customized by business departments); at the same time, in conjunction with business process nodes, evaluate the actual role and importance of various reference data in business flow, decision support and system interaction, so as to provide a basis for subsequent priority management.

[0044] (4-2) The system reviews the actual application scenarios, usage frequency and related business modules of existing reference data. Through data comparison, process tracing and other methods, it accurately identifies problems such as data inconsistency (such as the same code corresponding to different business meanings), data redundancy (such as repeatedly storing the same type of reference data) and data missing (such as key business scenarios lacking corresponding reference data). Simultaneously, it assesses the compatibility between external general reference data standards (such as industry association standards and relevant national regulations) and the company's internal business needs, and determines whether it is necessary to make localization adjustments to external standards.

[0045] (4-3) Design the storage and management architecture of the reference data, and give priority to adopting a centralized management model (such as building a unified reference data management platform) to ensure the authority, uniqueness and consistency of the reference data when sharing across systems; clearly define the core components of the reference data model, including data entities (such as industry code entities, material classification entities), entity attributes (such as entity codes, names, and effective times) and relationships between entities (such as the mapping relationship between industry codes and product classifications), to lay the foundation for the structured management and system integration of reference data.

[0046] Based on the above steps, supplement the relevant information of the reference data in the "Data Hierarchical Classification Directory Template" of the newly built business system.

[0047] (5) Establish indicator standards: (5-1) Determine the core purpose of the indicator specifications (e.g., improve data quality, promote data collaboration between departments, support the achievement of specific business objectives, assist strategic decision-making, etc.) to ensure that the direction of indicator specification construction is consistent with the overall needs of the enterprise; systematically identify the stakeholders related to the indicator specifications (e.g., business departments, technical departments, decision-making level, data management team, etc.) to gain an in-depth understanding of the information acquisition needs and actual decision-making scenarios of each party (e.g., daily operation monitoring, monthly business analysis, annual strategic review, etc.) to provide accurate basis for subsequent indicator design.

[0048] (5-2) Based on the company's business needs and strategic goals, identify the key areas that need to be measured (such as financial health, operational efficiency, customer satisfaction, data quality level, business growth scale, etc.); divide the indicators into a structured "theme domain-level" structure—the theme domain can be divided into financial domain, operational domain, customer domain, data governance domain, etc., and the level can be divided into key performance indicators (KPI), operational indicators (OI), and support indicators (SI), forming a logically clear and comprehensive indicator system framework to ensure that the indicators are deeply adapted to the business scenarios.

[0049] (5-3) Establish a unified naming rule for indicators (it is recommended to adopt a structured format of "subject area - indicator type - measurement object - statistical dimension", such as "operation area - efficiency category - order processing - average daily duration") to ensure that the indicator name accurately reflects its measurement content and avoids semantic ambiguity; prepare a detailed definition document for each indicator to clarify the core elements: including the calculation formula (including parameter meaning and calculation logic), data source (specific business system or data table), statistical unit (such as 10,000 yuan, times, days), and statistical period (such as daily, monthly, quarterly) to completely eliminate cross-departmental misunderstanding of indicators.

[0050] (5-4) Establish standardized specifications for indicator calculation, clarify the calculation methods, statistical scope (such as time range of natural month, fiscal year, business scope of the whole company, specific business unit), data filtering rules (such as excluding test data, including valid orders), and outlier handling methods (such as null value filling rules, extreme value truncation standards) for various indicators; ensure that the calculation logic and statistical scope of the same indicator are completely consistent regardless of which department (such as finance department, operations department) or system (such as business system, reporting system), and eliminate data interpretation contradictions caused by differences in scope.

[0051] (5-5) Establish a centralized indicator dictionary management platform (such as a digital document library, professional indicator management tools, or data governance platform modules) to fully record all information of each indicator, including the indicator's unique identifier, standard name, detailed definition, calculation formula, data source, statistical unit, statistical period, responsible department, person in charge, update records, etc.; position the indicator dictionary as a unified indicator knowledge sharing platform within the organization, open to all relevant parties for querying, referencing, and tracing, so as to achieve transparency and reusability of indicator information.

[0052] (5-6) Implement multi-dimensional hierarchical and categorized management of indicators: classify indicators by importance (e.g., core indicators, important indicators, general indicators) for priority resource allocation; classify indicators by data sensitivity (e.g., high-sensitivity indicators, medium-sensitivity indicators, low-sensitivity indicators) to match differentiated access control strategies; classify indicators by business domain (e.g., financial indicators, operational indicators, customer indicators, data governance indicators) to facilitate departmental management and maintenance; achieve refined management of indicators through hierarchical classification to improve management efficiency and application relevance.

[0053] Based on the above steps, a "Metric Standard Definition Template" for newly established business systems will be created, such as... Figure 5 As shown, where Figure 5 (a) Figure 5 (b) By combining the data, you can obtain the complete example table of the "Indicator Standard Definition Template".

[0054] (6) Establish data security standards: (6-1) Develop an enterprise-level data security policy, clarify the core principles of data classification and grading (such as classifying levels based on data sensitivity and business impact), and formulate differentiated protection requirements for different levels of data (such as high-sensitivity data requiring full lifecycle encryption and low-sensitivity data requiring basic access control); simultaneously set specific control strategies for data access, use, sharing and processing, strictly adhere to the principle of least privilege (only granting users the minimum data permissions required to complete business) and the principle of business needs (data operations must match the actual business scenario), and prevent abuse of permissions or access to irrelevant data.

[0055] (6-2) Implement a strict access control mechanism. Through permission verification, identity authentication and other means, ensure that only authorized users can access data of the corresponding sensitive level. Deploy an identity and access management system (IAM) and implement role-based access control (RBAC) mode. Data access permissions are preset according to business roles. Users obtain permissions through role association to avoid fragmented permission management. At the same time, it supports dynamic adjustment of permissions and lifecycle management (such as timely revocation of permissions when employees leave the company).

[0056] (6-3) Classify the data according to its sensitivity and importance (e.g., into four levels: high sensitivity, medium sensitivity, low sensitivity, and public), and uniformly mark the data carriers (e.g., data tables, files, and interface data) (e.g., through metadata tags, field identifiers, etc.). This marking needs to be embedded in the entire data management process to support the automated execution of security policies, such as restricting the cross-system transmission of highly sensitive marked data and prohibiting unauthorized sharing of files marked with sensitive information.

[0057] (6-4) Develop a specific data backup strategy, specifying the backup frequency (e.g., real-time backup of highly sensitive data, daily incremental backup of ordinary data + weekly full backup), backup method (e.g., local backup + off-site disaster recovery), and storage medium (e.g., encrypted storage server, cloud disaster recovery space). Regularly conduct integrity verification and availability verification of backup data to ensure that backup data can be recovered normally. Establish a comprehensive disaster recovery plan, specifying recovery objectives (RTO, recovery time objective; RPO, recovery point objective), and formulate emergency recovery procedures for scenarios such as data loss and system failure to ensure that data can be quickly recovered and available after business interruption.

[0058] (6-5) Deploy a logging and auditing mechanism to fully cover data access (such as who accesses and when), data operations (such as adding, modifying, and deleting), and permission changes (such as granting and revoking permissions) to form a traceable audit log; introduce a Security Information and Event Management System (SIEM) to monitor, correlate, and alert on audit logs and system security events in real time, identify high-risk behaviors (such as high-frequency access to sensitive data and unauthorized IP attempts to log in) in a timely manner, and trigger emergency response procedures to prevent data leakage or damage risks.

[0059] (7) Establish database standards, including standards for comments on tables, attributes, functions, and stored procedures, as well as standards for ER diagrams between tables; In this embodiment, the database specifications focus on best practices for database design and management, including database table structure design, indexing strategies, storage optimization, backup and recovery strategies, and access control. For example, they require a clear entity-relationship model, avoidance of data redundancy, reasonable index design to improve query efficiency, and the development of regular maintenance plans. These specifications help improve database performance and data security, as detailed below: In this embodiment, the database specification is established in the following manner: 1. Establish annotation standards: You are required to provide comments related to all tables and stored procedures in the system you have created. a. Table comment requirements: Table names must include Chinese name comments and detailed descriptions (e.g., ...). Figure 6 (as shown) b. Table technical specifications: These must include whether the table is master data, the table change mechanism, the table change frequency, the table latency, and the external systems it depends on. c. Field Requirements: All fields must have Chinese name comments, field business meaning comments, and must be in the correct English case (e.g., ...). Figure 7 As shown, Figure 7 (a) Figure 7 (b) Example of a field description document template obtained by concatenation). d. Enumeration field requirements: All enumeration fields must have comments explaining the business meaning of the enumeration values; e. Stored procedure requirements: All stored procedures must have a Chinese name comment and a detailed description; f. Required comments for stored procedure internal code: Include the stored procedure name, the business module it belongs to, a functional description, a general description of the calculation logic, the developer's name, the date, and detailed comments explaining why associations and filtering are needed (e.g., ...). Figure 8 (as shown) 2. Establish ER diagram standards: The requirement is to provide an ER diagram related to the newly built business system, including all tables in the system, table relationships, and data correspondences. The process specifications, including business flow specifications and data flow specifications, require the streamlining of the business flow of the established business system, which must reflect the various business entities within the business flow; they also require the categorization of all business entities in the established system according to the "Data Hierarchical Classification Catalog Template" and the supplementation of relevant data hierarchical classification content, and require adherence to the "Data Inventory Template" (such as...). Figure 9 As shown, where, Figure 9 (a) Figure 9(b) By combining the data, you can obtain the complete example table of the "Data Inventory Template". This establishes the mapping relationship between business entities and business data tables, and supplements the relevant data inventory content. In this embodiment, the process specification covers the entire lifecycle management of data, from data collection, cleaning, storage, processing, analysis to archiving or destruction. It includes processes for checking the accuracy of data entry, managing data changes, approving data permissions, and handling data quality issues. By clearly defining the responsible parties, operational steps, and review requirements for each stage, it ensures the orderly conduct of data processing activities and reduces errors and omissions.

[0060] 3) Based on the data governance process of the business system, establish oversight standards to ensure the implementation of data management guidelines. The entire process includes stages such as requirements analysis, system design, system development, system testing, system deployment, and system maintenance. Each stage has corresponding data management oversight nodes. For example, in the requirements analysis stage, it is necessary to ensure the clarity of data requirements and their consistency with data governance policies. The oversight process includes regular data quality audits, code reviews, security testing, and compliance checks, specifically including: (1) The technical agreement, detailed design, development deployment, and final acceptance milestones of the business system project must be reviewed by the client or the client must participate in the review to ensure that they have been implemented in accordance with the specifications; (2) During the technical agreement phase, Party A shall include the established data management and control specifications in the technical requirements and technical agreement documents. During the node review, Party A shall be responsible for reviewing and checking this content. If the requirements are not met, the node shall not be approved. (3) During the detailed design phase, the implementer needs to implement the design in accordance with the data management and control specifications and produce corresponding deliverables. During the node review, the client is responsible for reviewing whether the deliverables meet the requirements; if they do not meet the requirements, the node cannot be approved. (4) During the review of the development and deployment node, the client shall be responsible for reviewing whether the system implementation is consistent with the deliverables in the detailed design document. If the requirements are not met, the node shall not be approved. (5) During the final acceptance review, the client shall take the lead in reconfirming whether the project implementation meets the data specifications. If the requirements are not met, the project cannot pass the review. It is worth noting that the design phase of the oversight specification needs to focus on the compliance of the data model to ensure that the data architecture follows the established specifications. This embodiment ensures the compliance of the data model in the following ways: ① Establish standardized oversight processes covering regular data quality audits, code reviews, security testing, and compliance checks. These processes must comprehensively cover all stages of data processing (including data collection, cleaning, storage, processing, transmission, and application) to ensure the rationality of data processing logic, the rigor of data access control, and the effectiveness of data security measures, all in accordance with pre-defined control and management standards.

[0061] ② Establish a dynamic monitoring mechanism, employing a combination of continuous monitoring and random checks to conduct full-cycle supervision of data processing activities during project execution. The scope of supervision covers key dimensions such as data entry accuracy (e.g., data format compliance, content authenticity verification results), data flow compliance (e.g., data transmission paths complying with security standards, complete flow permission approvals), and data storage security (e.g., sensitive data encryption status, storage media access control), ensuring that the entire data processing process consistently meets control requirements.

[0062] 4) In accordance with technical data management and supervision standards, complete data governance within the business system during the business system construction process: Generally, new business systems are built through projects, with procurement contracts signed with specific suppliers (i.e., project implementers), who then complete the construction and delivery. Therefore, established data management and monitoring standards must be incorporated into the project's technical requirements, which the supplier will then implement accordingly.

[0063] In this embodiment, the specific process of incorporating data management and supervision specifications into the technical requirements of the business system is as follows: At the project's inception, data management standards, including data classification, data security levels, and compliance requirements, are incorporated into the requirements document. This clarifies data sensitivity classifications and specifies standards for data storage, processing, and transmission. During database design and architecture planning, ensure the design conforms to data standards, such as employing appropriate data encryption technologies and designing reasonable data models to support data lifecycle management. Simultaneously, plan data auditing and monitoring mechanisms, such as logging and anomaly detection. Establish detailed coding standards, requiring developers to follow best practices in data processing, such as avoiding hardcoding sensitive information and implementing data access control. Ensure the standards are followed through code review mechanisms. Develop data backup and recovery strategies, and implement regular data security audits and performance monitoring to ensure continuous compliance and security of data during system operation. Establish a data issue response mechanism to ensure rapid action in the event of data breaches or anomalies.

[0064] In this embodiment, the specific process of data governance according to technical requirements is as follows: (1) Establish data control checkpoints at the detailed design, development deployment, and final acceptance stages of the project; (2) At the detailed design stage, the supplier shall conduct the detailed design of the system in accordance with the data control specifications. The client shall review the detailed design results in accordance with the data control specifications. If the design meets the requirements, the review shall be approved and the next step of work shall be carried out. If the design does not meet the requirements, the supplier shall make corrections until the design meets the requirements. (3) At the development and deployment stage, the supplier shall develop and deploy the system in accordance with the data management and control specifications. The client shall review the system development and deployment results in accordance with the data management and control specifications. If the review meets the requirements, the next step can be carried out. If the supplier does not meet the requirements, the supplier shall make corrections until the requirements are met. (4) At the final acceptance point, the supplier shall organize and deliver data documents such as data standard documents, master data documents, reference data documents, data dictionary, ER diagram, business flow, and data flow documents in accordance with the data management and control specifications. The client shall review the deliverables in accordance with the data management and control specifications. If the deliverables meet the requirements, they shall be accepted. If the deliverables do not meet the requirements, the supplier shall reorganize them until they meet the requirements, thus completing the closed loop of data governance in the newly built business system.

[0065] In summary, this embodiment, through data governance, implements data cleaning, standardization, and normalization operations to eliminate redundant data and correct errors, ensuring consistency in format, definition, and value range across all data. This directly improves the accuracy of data analysis and the effectiveness of business decisions, reducing decision-making errors caused by data inconsistencies. Simultaneously, by establishing a strict data access control mechanism and implementing data encryption and anonymization, the security of sensitive data can be ensured. Furthermore, relevant business personnel (IT personnel) can identify and eliminate bottlenecks by streamlining data flows, optimizing data processing workflows, and improving the responsiveness and processing capabilities of business systems, supporting rapid business iteration and development. By establishing a unified data dictionary and metadata management, enterprises can enable different departments and systems to share data resources based on a common language and understanding. This not only promotes cross-departmental collaboration but also increases data reuse, reduces redundant work, and accelerates the data-driven decision-making process.

[0066] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications made to the present invention by those skilled in the art without departing from the spirit of the present invention shall fall within the protection scope of the present invention.

Claims

1. A method for simultaneously conducting data governance within a newly established business information system, characterized in that, Includes the following steps: 1) Determine the business system to be built, as well as its data management needs, data governance processes, and technical requirements; 2) Based on the data management needs of the business systems, establish data control standards to regulate the data management of the business systems; 3) Based on the data governance process of the business system, establish supervision standards to regulate the data governance process; 4) In accordance with the technical data management and supervision standards, complete the data governance within the business system during the business system construction process.

2. The method according to claim 1, characterized in that: In step 2), the data management and control specifications include data specifications, database specifications, and process specifications, wherein, The data specifications include data quality specifications, data standard specifications, master data specifications, reference data specifications, indicator specifications, and data security specifications. The database specifications include the specifications for comments on tables, attributes, functions, and stored procedures, as well as the specifications for ER diagrams between tables; The process specifications include business flow specifications and data flow specifications.

3. The method according to claim 2, characterized in that: The data quality specifications include data quality indicators, key data domains, data quality standards, data cleaning rules, data quality monitoring mechanisms, data quality problem rectification procedures, and data processing compliance requirements. The data standards and specifications include data status, data naming conventions, data formats and standard values, and data lifecycle management specifications; The master data specification includes the scope of master data, data usage, master data standards, master data model, and master data governance framework; The reference data specifications include the reference data scope, data usage, and reference data architecture; The indicator specifications include indicator specification objectives, indicator system, indicator naming and definition, indicator calculation methods, indicator dictionary, and hierarchical and classified management; The data security specifications include formulating data security policies and access strategies, controlling data access, classifying and labeling data, performing data backup and recovery, and auditing and monitoring data operations.

4. The method according to claim 1, characterized in that: In step 3), the specific content of the supervision specification is as follows: 3-1) The project requester determines the detailed design document of the business system, and based on the detailed design document, divides the entire process of the business system project construction into key nodes such as technical agreement signing, detailed design, development and deployment and final acceptance, and sets up node supervision at each key node. 3-2) During the technical agreement phase, the project requester shall incorporate data management specifications into the project technical requirements and technical agreement documents, and shall be responsible for reviewing the data management specifications. If the specifications are not met, the technical agreement phase node review shall not be approved. 3-3) During the detailed design phase, the project implementer shall carry out design work in accordance with the data management and control specifications, build the business system, and have the project requester review whether the business system meets the specification requirements. If the requirements are not met, the detailed design phase node review will not be passed. 3-4) During the development and deployment phase, the project implementer needs to deploy the business system, and the project requester needs to verify the consistency between the deployed business system and the business system in the detailed design document. If there are discrepancies between the two and they do not meet the standard specifications, the node review of the development and deployment phase will not be passed. 3-5) During the final acceptance review stage, the project requester shall conduct a comprehensive review of whether the entire process of implementing the business system complies with the data specification requirements. If the requirements are not fully met, the final acceptance review shall not be passed.

5. The method according to claim 4, characterized in that: In step 3-1), the entire project construction process includes the stages of requirements analysis, system design, system development, system testing, system deployment, and system operation and maintenance. The supervision process for node monitoring includes regular data quality audits, code reviews, security testing, and compliance checks.

6. The method according to claim 1, characterized in that: In step 4), the data governance within the business system is completed in the following manner: 4-1) Technical data management and supervision standards shall be used as technical requirements in the business system construction process, and data management checkpoints shall be set up at the detailed design, development and deployment and final acceptance nodes of the business system. 4-2) At the detailed design stage, the project implementer conducts a detailed design of the business system in accordance with the data management and control specifications, and the project requester reviews it. If the review is passed, the next step of work is carried out. If the review is not passed, the project implementer re-rectifies it until it meets the requirements. 4-3) At the development and deployment stage, the project implementer shall develop and deploy the business system in accordance with the data management and control specifications, and the project requester shall review the deployed business system. If the review is passed, the next step shall be carried out. If the review is not passed, the project implementer shall make corrections until the requirements are met. 4-4) During the final acceptance phase, data documents are organized and delivered in accordance with the data management and control specifications. The project requester reviews the business system in accordance with the data management and control specifications. If the review is passed, the project requester accepts the business system. If the review is not passed, the project implementer reorganizes and improves the system until it meets the specifications and can complete the data governance of the business system construction process.

7. The method according to claim 6, characterized in that: In step 4-4), the data documents include data standard documents, master data documents, reference data documents, data dictionaries, ER diagrams, business flows, and data flow documents.