Corrective action: fixing the cause rather than the symptom
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
Data governance sounds like something only large organisations do. The three parts that matter — ownership, definitions and access — are worth having at fifteen people.
Data governance is the set of decisions about who owns which data, what the numbers mean, who may see them, and how quality is maintained. In large organisations it becomes a function with a committee. In a company of fifteen it is three or four decisions, written down once — and skipping them is why two people present different revenue figures in the same meeting.
The trigger is usually a specific embarrassment rather than a principle: a report contradicted by another report, a customer list that turned out to exist in four versions, an ex-employee who still had access to everything, or a question from a customer about their data that nobody could answer.
Definitions are the cheapest win and the one most often skipped. Two teams counting customers differently produces two truths, an argument in every review, and eventually a decision made on the wrong number. Writing down what a customer is takes twenty minutes and settles that permanently — and unlike most governance, it needs no tooling at all.
Small companies waste time on the parts of governance designed for scale: a formal council, a full data catalogue, quality scorecards, a lineage diagram of every field. None of these earn their cost below a certain size, and starting there is the reliable way to abandon the whole effort. Owners, definitions, access and retention are the parts that pay at any size. Everything else can wait until someone can name the specific problem it would solve.
Ettex Records is a reasonable home for the registers this produces: custom tables with typed fields for a dataset inventory — name, owner, source of truth, location, personal data yes or no, retention reference — plus relations between tables so owners and systems are references, saved views to see everything one role owns, revision history where every cell change is tracked, and CSV import to start from a spreadsheet. The definitions document and the access rules belong in Ettex Docs with version history, so "what did we mean by active customer last year" is answerable. Access to the workspace itself is managed in Ettex Teams, and the numbers everyone argues about usually live in Ettex Sheets.
The boundary: Ettex is not a data governance platform. There is no data catalogue that discovers your systems, no lineage, no quality scoring, no classification or PII detection, and no access-review workflow. What you get is a place to keep the registers and documents, plus workspace-level permissions. The decisions — who owns what, what the terms mean — are not a software problem anyway.
The decisions about who owns each dataset, what key terms and numbers mean, who may access and export data, how quality is maintained, and how long data is kept.
They need the useful parts — owners, definitions, access rules and retention. The committees, catalogues and scorecards designed for large organisations rarely pay for themselves below a few hundred people.
With definitions of the five numbers your reports argue about, and an owner per dataset. Both take hours rather than weeks and remove the most common source of confusion.
The one place a dataset is authoritative, named explicitly, so that when copies disagree there is a rule for which wins. Unnamed sources of truth are how four versions of a customer list appear.
Knowing what personal data you hold, why, where and who can see it is both good governance and the foundation of most data-protection obligations. The specific legal requirements depend on your jurisdiction — check them locally.
Annually against the current staff list, plus removal at the point someone leaves. Access that accumulates and never contracts is the most common finding in any first review.
Data governance in a small company is four things written down: who owns each dataset, what the key numbers mean, who can read and export them, and how long you keep them. Everything else is scale you do not have yet.
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
A conflict of interest policy is mostly a register and a habit. The point is not to forbid overlapping interests but to have them written down before anyone has reason to ask.
A record of processing activities lists what personal data you hold, why, where it goes and how long you keep it. It is dull to build and it answers half the questions anyone will ever ask you.