Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Showing posts with label CDMC. Show all posts
Showing posts with label CDMC. Show all posts

Tuesday, 23 June 2026

Scaling at Cloud Speed: Moving from Manual Checklists to CDMC Automation

For years, data governance has relied on a familiar model: committees, policies, spreadsheets, and periodic reviews. It worked when data moved slowly, systems were predictable, and change could be managed through human oversight but that world no longer exists.

Today, data is created, transformed, and consumed continuously across cloud platforms. AI models are trained on that data in near real time. Decisions happen in milliseconds. And yet, in many organizations, governance is still anchored in manual controls and retrospective checks. There’s an uncomfortable truth emerging: human-in-the-loop governance cannot scale to cloud speed. The question is no longer whether governance is important. It’s whether governance can keep up and this is where the industry has been quietly converging on a new answer.


The Missing Link: Why CDMC Exists

The EDM Council didn’t create the Cloud Data Management Capabilities (CDMC) framework to replace existing governance thinking. It created it because something was missing. Frameworks like DAMA-DMBOK remain foundational they define what good governance looks like across domains such as data quality, metadata, and security. But they were never designed for an environment where:

  • Data is distributed across cloud services
  • Access decisions are made dynamically via APIs
  • Policies must be enforced continuously not reviewed quarterly

CDMC fills that gap. It translates governance intent into 14 concrete, measurable controls, designed specifically for cloud environments, with a clear emphasis on automation and continuous enforcement

In other words, it moves governance from principle to execution.

From Policy to Enforcement: What Automation Really Means

The power of CDMC is not just that it defines controls, it defines controls that can be automated, monitored, and evidenced. This is a fundamental shift. Traditional governance asks: Do we have a policy? CDMC asks Is this control being executed automatically, right now, and can we prove it? Across its 14 controls spanning governance, classification, privacy, lifecycle, and architecture, CDMC embeds governance directly into the data pipeline itself. 

The impact of that shift becomes most visible when you look at a few critical controls.

Control #1: Governance Accountability in an AI World

One of the simplest, yet most powerful, requirements is this: every sensitive data asset must have a defined owner. This is not new in principle. DAMA has long emphasised stewardship and accountability but CDMC enforces it through automation ensuring that ownership fields are populated in data catalogs, monitored, and escalated when missing. In an AI-driven context, this becomes critical. If a model produces biased or incorrect outputs, the question is no longer abstract. It becomes operational:

Who owns the data that trained this model?

Without automated ownership tracking, accountability collapses. With it, organizations can trace responsibility back to the source.

Control #11: Data Privacy that doesn’t rely on Humans

Privacy has always been a governance priority. But manual processes, reviews, sign-offs, compliance checklists are no longer sufficient when data is constantly moving and being repurposed. CDMC embeds privacy into the flow of data itself. It requires automated triggers, such as data protection impact assessments for personal data, ensuring that privacy controls are activated consistently and at scale. This matters even more in AI scenarios, where training datasets can be assembled from multiple sources rapidly. You simply cannot rely on someone remembering to remove PII before it enters a pipeline. You need a system that ensures it never gets there in the first place.

Control #12: Stopping Data Swamps before they start

Data quality has always been a known challenge. What’s changed is the speed at which poor-quality data propagates. In traditional environments, issues might take weeks to surface. In AI pipelines, they surface instantly and at scale. CDMC addresses this by requiring data quality measurement as a built-in control, applied at ingestion and continuously monitored through metrics. This is a subtle but profound shift. Instead of discovering problems downstream, organizations prevent them upstream. Instead of cleaning data after the fact, they stop poor data from entering the ecosystem at all. This is how you avoid the modern equivalent of a data warehouse problem: the AI-era data swamp.



The joined-up Framework: DAMA as Constitution, CDMC as Enforcement

It’s tempting to position CDMC as a replacement for traditional frameworks but that misses the point. The real strength comes from how they work together.

  • DAMA-DMBOK defines the principles of governance, the constitution that outlines what good looks like
  • CDMC defines the execution, the enforcement layer that ensures those principles are actually applied

Where DAMA says:

Data must be secure.

CDMC operationalises it as:

Security controls must be enabled, monitored, and evidenced automatically for all sensitive data.

Where DAMA defines accountability, CDMC ensures accountability exists in the system. Where DAMA defines quality, CDMC ensures quality is measured continuously. This is the bridge many organizations have been missing.

From Governance Theatre to Operational Reality

There is a growing gap between organizations that talk about governance and those that have embedded it into their platforms.

Manual governance processes, however well designed, become governance theatre in cloud environments:

  • Policies exist, but are not enforced
  • Ownership is defined, but not maintained
  • Controls are documented, but not executed

CDMC changes the conversation. It forces organisations to move from:

  • Periodic assurance → continuous control
  • Documentation → instrumentation
  • Manual oversight → automated guardrails

And that’s what makes it so relevant in the age of AI.

AI doesn’t remove the need for governance, it increases it exponentially. But it also exposes the limits of traditional approaches. You cannot govern at cloud speed with spreadsheets, committees, and retrospective checks. You need governance that is:

  • Embedded
  • Automated
  • Measurable
  • Continuous

That’s the shift CDMC represents. Not a new theory of governance but a new way of making governance real.

References

Thursday, 5 May 2022

CDO and Data Leaders Global Summit

Today was the CDO and data leaders global summit hosted by the EDM Council and CDO Magazine designed specifically for senior and C-level data and analytics executives. 
 

One of the sessions was about the EDM. 


There were discussion about the Cloud Data Management Capabilities (CDMC) 14 key controls and Automations. These should help build trust and confidence in the industry. 













The EDM Councils areas of Advocacy 

  • Best Practice - DCAM & Cloud CDMC, Data ROI, ESG Data (environmental, social & corporate governance)
  • Driving Standards - Knowledge Graph, Industry Ontologies, shared lab
  • Training and Certification - virtual & elearning and webinars and events
  • Research and Benchmarking - Global Industry Study, Life Sciences, Data Sharing
  • Regulatory Engagement - Regulators participation
  • Networking - Data Visions, CDO Summit, workgroups and forums

Learn more about the CDMC, and download with a free license for internal use, at: https://edmcouncil.org/page/CDMC

For  those who have been very DAMA Book of Knowledge focused the DCAM (Data Management Capability Assessment Model) is closely aligned. CDMC took the DCAM framework and focused on managing data in Cloud.  It contains a number of best practices specific to the challenges (and opportunities) of Cloud. The council has been in regular communication with global regulators about CDMC, on what controls may be needed in ensuring safe and effective Cloud environments.

Controls that will be used in Snowflake to satisfy the EDMC's CDMC framework can be found at the GIT link is: https://github.com/Snowflake-Labs/EDMC-CDMC-v1-14-Control_Mapping . On the Microsoft side in Microsoft Purview Compliance Manager there are templates for CDMC key controls.

The keynote was interesting talking about how the CDMC - Cloud Data Management Capabilities Framework - will have a global impact as the best practice standard for cloud Data.  The session labelled as global industry standard for accelerating trusted cloud adoption created through global industry workgroup between May 2020 to September 2021.  There were 100+ companies and 300+ participants. The panel was made up of 


 

Two reports to read
EDM Council ESG Corporate Reporting Entities report 
EDM Council ESG Rating Providers and Data Aggregators report


Sunday, 1 May 2022

Different data models and frameworks

 There are 3 different models that can help when thinking about data governance and data management.

The revised DAMA Wheel has data governance at the top

The core components to think about for data governance and data management are: Policy; Stewardship & Ownership; Culture Change; Strategy; Principles and Ethics; Data Valuation; Data Maturity Assessment; Data Classification.

When getting started I look at the fundamentals as a starting place.
1. Data Governance
2. Meta Data Management
3. Data Quality
4. Reference/Master Data

DAMA-DMBOK | Data Management Body of Knowledge




DCAM (Data Management Capability Assessment Model) was first published in 2014 following the Socratic method of question and debate. . CDMC (Cloud Data Management Capabilities Framework) is a playbook of best practice for managing data in the cloud. Version 1.1.1 was released in September 2021 , created by a cross industry workgroup of 100+ firms. It is a framework for best data management practices to accelerate trusted cloud adoption.  It can be downloaded here. The holistic list of capabilities highlighted in the CDMC from the EDM Council is:

Data Cataloguing and Discovery 
Data Classification 
Data Ownership 
Data Security 
Data Sovereignty and Cross-Border Data Sharing 
Data Quality
Data Lifecycle Management 
Data Entitlements and Access Tracking  
Data Lineage  
Data Privacy 
Trusted Source Management and Data Contracts 
Ethical Use and Purpose 
Master Data Management

The Data Management Maturity (DMM)  program from the CMMI Institute has best practices for providing support for the implementation of process for these five categories: strategy; governance; data quality; operations; and platform and architecture. 

Best practice for ensuring broad participation in the practice and senior oversight of the effectiveness of data management. 


Capability Maturity Model Integration  (CMMI) Six themes  The CMMI models are described as collections of effective practices and process improvement goals that organisations can use to evaluate and improve their processes.