By Vilner Rasmussen
Capabilities rarely fail with a bang. There is no outage, no incident report, no moment where someone says “that stopped working”. They drift. A routine gets switched off during a busy month. A field stops being checked. The one person who knew why a rule existed moves to another job. Six months later, the ticket queue is back.
To understand where that drift starts, we mapped the method across 165 capabilities in 11 master-data domains — Customer, Vendor, Material, Finance, HR, Asset, Supply Chain, Project, Quality & Compliance, Governance & Enterprise Structure, and AI & Analytics. Fifteen capabilities per domain, five per component. Every one researched against official SAP documentation, with limits stated openly.
Three patterns stood out.
1. The People Component Is the One Nobody Governs
For each domain we asked how much of a component’s capabilities is actually governance work — the kind a score can track — versus operational work. Business Processes and Platforms & Tools vary by domain. People & Competencies sits at a flat 20% everywhere.
That is not a flaw in the data. It is the point. Tools come with validation, workflows and change logs. Processes come with approvals. Competence comes with nothing — unless you build it. No system will tell you that the only person who understands your pricing conditions is about to retire. That is where capabilities quietly fail, and it is why KEEP IT exists: knowledge held by the unit, tested against the score and certified, instead of carried by three people.
2. Shared Platforms Produce Shared Strengths — and Shared Blind Spots
Customer, Vendor, Material and Finance converge on exactly the same governance profile. Not four separate judgement calls — one consequence of the same platform mechanics applied to different objects. That is good news, because one proven routine travels to the next domain without a rebuild. It is also a warning: a weakness in the shared mechanics shows up in all four at once.
3. The Low Number Is the Useful One
Asset is the lowest-governance domain we mapped — genuinely operational, execution-heavy, with little native governance tooling behind it. It would have been easy to leave it out. We publish it anyway, because a method that only shows its best domain isn’t proof; it’s marketing. The low number tells you where a capability will need people and process to hold, because the system won’t do it for you.
What This Means If You Run a Domain
- Ask where the knowledge sits, not just where the data sits. If the honest answer is “with one person”, you have found your first risk.
- Treat a fixed score as a habit, not a report. A baseline is a photograph; the value is in reading it every month.
- Expect tooling-only fixes to drift. New tooling without the process to run it, or a process with no one trained to hold it, gives you a fragmented solution — more expensive to maintain, not less.
The most expensive failures in master data are not the visible ones. They are the ones that look fine until the person who held them leaves.
Related: The Governance Heatmap · KEEP IT · The Stakes

