Skip to main content

Framework

The Analytics Governance Control Model

Published 7th September 2026.

This is our framework for what governing a measurement layer takes. It has five layers, from the pressure that creates the problem down to the accountability that keeps the answer funded. It is an opinion, dated, and it is the shape every review and every retained month here follows.

The five layers

Evidence moves up the stack and pressure moves down it. Where a layer is missing, the layers above it work from assumptions and the layers below it work without direction.

  1. Layer 1. AI-Driven Change Velocity

    Where measurement changes come from and how fast they arrive: internal releases, agencies, vendor scripts that update themselves, and code assistants that treat a tracking tag as an implementation detail.

    Governance capacity gets designed for the rate of change somebody assumed, rather than the rate the organisation has.

    It is the pressure the four layers under it absorb, and it is what a review measures first.

  2. Layer 2. Measurement Infrastructure

    A current inventory of what is deployed: tag containers, hard-coded scripts, pixels and SDKs, the consent configuration, and where each collection endpoint sends what it collects.

    Governance operates on what somebody remembers. Most inventories we are handed are between six and eighteen months old, cover the tag manager only, and stop at the container rather than following the request to its destination.

    ConsentMark measures this layer: a scan reads what the browser did on the day it ran.

  3. Layer 3. Technical Control

    Automated checks that compare what the site does against what was approved: tag behaviour under each consent state, changes between one release and the next, personal data in tag parameters, and a gate in front of publishing.

    Governance depends on somebody reading a diff, which does not scale to the rate of change in Layer 1.

    ConsentMark measures this layer too. Monitor runs the comparison on a schedule and keeps each run as signed evidence.

  4. Layer 4. Operational Governance

    The people and the process: who requests a change, who approves it, what the standard is, what gets documented, and who owns the answer when marketing, engineering, legal and compliance each hold part of it.

    Controls report and nobody acts, because a finding with no owner has nobody to close it.

    An Obscurity Governance Retainer operates this layer with the client, under one named contact.

  5. Layer 5. Executive Oversight

    What the board and the data protection officer see: the governance posture, what moved since the last report, and whether the organisation could show a regulator how it keeps control of what its sites measure.

    Process loses rigour when no one senior reads its output, and automation loses its budget when nobody connects it to a risk the board recognises.

    The retainer's monthly report is written for this layer, and the person who ran the month answers questions on it.

Reading your own posture

A grade from a free scan reads Layers 2 and 3 on one property, on one date, under the published methodology. Layers 1, 4 and 5 are about how your organisation works and no browser can see them. They come up in the Governance Posture Call.

Book a Governance Posture Call