A metric owner is the person accountable for a metric. The word hides an ambiguity that causes real damage, because there are two distinct things to be accountable for and they belong to different people.
The definition owner is accountable for what the metric means. They approve changes to the formula, decide on scope and exclusions, and answer when someone asks how the number was produced. This usually sits with the measurement or governance function.
The value owner is accountable for where the number sits. They respond when it crosses a threshold and they hold the levers that move it. This sits with whoever runs the operation being measured.
Combining them creates an obvious problem. The person judged on the number also controls how it is calculated.
Not usually fraud. Something subtler and harder to catch.
Under pressure, a value owner who also controls the definition will find genuinely defensible reasons to adjust scope. A newly acquired estate is not comparable yet, so exclude it. Systems pending decommission are not really in production. This class of finding is being reclassified.
Every one of those may be correct. The pattern of them is the problem, and it is invisible unless someone outside the reporting line owns the definition.
Definition owner: named in the metric catalog, approves formula changes, signs off restatements.
Value owner: named on the reporting line, responds at threshold breach, presents the explanation.
Neither can change the other’s domain unilaterally. A value owner who believes the definition is wrong raises it as a change request, which gets recorded with a date and a reason.
That record is most of the value. It converts a quiet adjustment into a visible decision.
A metric with no value owner at all. It appears in the pack, gets discussed, and nobody is accountable for moving it because the person receiving it has no lever. See actionable metric.
Fix it by moving value ownership to whoever holds the lever, even when that person sits outside security. A metric the security function cannot move should be reported by the function that can.
From the blog