Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Showing posts with label DAMA. Show all posts
Showing posts with label DAMA. Show all posts

Tuesday, 23 June 2026

Scaling at Cloud Speed: Moving from Manual Checklists to CDMC Automation

For years, data governance has relied on a familiar model: committees, policies, spreadsheets, and periodic reviews. It worked when data moved slowly, systems were predictable, and change could be managed through human oversight but that world no longer exists.

Today, data is created, transformed, and consumed continuously across cloud platforms. AI models are trained on that data in near real time. Decisions happen in milliseconds. And yet, in many organizations, governance is still anchored in manual controls and retrospective checks. There’s an uncomfortable truth emerging: human-in-the-loop governance cannot scale to cloud speed. The question is no longer whether governance is important. It’s whether governance can keep up and this is where the industry has been quietly converging on a new answer.


The Missing Link: Why CDMC Exists

The EDM Council didn’t create the Cloud Data Management Capabilities (CDMC) framework to replace existing governance thinking. It created it because something was missing. Frameworks like DAMA-DMBOK remain foundational they define what good governance looks like across domains such as data quality, metadata, and security. But they were never designed for an environment where:

  • Data is distributed across cloud services
  • Access decisions are made dynamically via APIs
  • Policies must be enforced continuously not reviewed quarterly

CDMC fills that gap. It translates governance intent into 14 concrete, measurable controls, designed specifically for cloud environments, with a clear emphasis on automation and continuous enforcement

In other words, it moves governance from principle to execution.

From Policy to Enforcement: What Automation Really Means

The power of CDMC is not just that it defines controls, it defines controls that can be automated, monitored, and evidenced. This is a fundamental shift. Traditional governance asks: Do we have a policy? CDMC asks Is this control being executed automatically, right now, and can we prove it? Across its 14 controls spanning governance, classification, privacy, lifecycle, and architecture, CDMC embeds governance directly into the data pipeline itself. 

The impact of that shift becomes most visible when you look at a few critical controls.

Control #1: Governance Accountability in an AI World

One of the simplest, yet most powerful, requirements is this: every sensitive data asset must have a defined owner. This is not new in principle. DAMA has long emphasised stewardship and accountability but CDMC enforces it through automation ensuring that ownership fields are populated in data catalogs, monitored, and escalated when missing. In an AI-driven context, this becomes critical. If a model produces biased or incorrect outputs, the question is no longer abstract. It becomes operational:

Who owns the data that trained this model?

Without automated ownership tracking, accountability collapses. With it, organizations can trace responsibility back to the source.

Control #11: Data Privacy that doesn’t rely on Humans

Privacy has always been a governance priority. But manual processes, reviews, sign-offs, compliance checklists are no longer sufficient when data is constantly moving and being repurposed. CDMC embeds privacy into the flow of data itself. It requires automated triggers, such as data protection impact assessments for personal data, ensuring that privacy controls are activated consistently and at scale. This matters even more in AI scenarios, where training datasets can be assembled from multiple sources rapidly. You simply cannot rely on someone remembering to remove PII before it enters a pipeline. You need a system that ensures it never gets there in the first place.

Control #12: Stopping Data Swamps before they start

Data quality has always been a known challenge. What’s changed is the speed at which poor-quality data propagates. In traditional environments, issues might take weeks to surface. In AI pipelines, they surface instantly and at scale. CDMC addresses this by requiring data quality measurement as a built-in control, applied at ingestion and continuously monitored through metrics. This is a subtle but profound shift. Instead of discovering problems downstream, organizations prevent them upstream. Instead of cleaning data after the fact, they stop poor data from entering the ecosystem at all. This is how you avoid the modern equivalent of a data warehouse problem: the AI-era data swamp.



The joined-up Framework: DAMA as Constitution, CDMC as Enforcement

It’s tempting to position CDMC as a replacement for traditional frameworks but that misses the point. The real strength comes from how they work together.

  • DAMA-DMBOK defines the principles of governance, the constitution that outlines what good looks like
  • CDMC defines the execution, the enforcement layer that ensures those principles are actually applied

Where DAMA says:

Data must be secure.

CDMC operationalises it as:

Security controls must be enabled, monitored, and evidenced automatically for all sensitive data.

Where DAMA defines accountability, CDMC ensures accountability exists in the system. Where DAMA defines quality, CDMC ensures quality is measured continuously. This is the bridge many organizations have been missing.

From Governance Theatre to Operational Reality

There is a growing gap between organizations that talk about governance and those that have embedded it into their platforms.

Manual governance processes, however well designed, become governance theatre in cloud environments:

  • Policies exist, but are not enforced
  • Ownership is defined, but not maintained
  • Controls are documented, but not executed

CDMC changes the conversation. It forces organisations to move from:

  • Periodic assurance → continuous control
  • Documentation → instrumentation
  • Manual oversight → automated guardrails

And that’s what makes it so relevant in the age of AI.

AI doesn’t remove the need for governance, it increases it exponentially. But it also exposes the limits of traditional approaches. You cannot govern at cloud speed with spreadsheets, committees, and retrospective checks. You need governance that is:

  • Embedded
  • Automated
  • Measurable
  • Continuous

That’s the shift CDMC represents. Not a new theory of governance but a new way of making governance real.

References

Sunday, 2 April 2023

In a Nutshell Concept Map

There is lots of talk about DAMA-DMBOK2 and DCAM and this can be confusing for people who are new to data governance and data management. There are many definitions describing what data governance is. For example Wikipedia states

'Data governance is a term used on both a macro and a micro level. The former is a political concept and forms part of international relations and Internet governance; the latter is a data management concept and forms part of corporate data governance.'

I came across this article  Data Management and Data Governance in a Nutshell which has a useful concept map of data management and data governance definitions. DAMA and  DCAM are fairly well aligned now.


Monday, 15 August 2022

DAMA-DMBOK2, DCAM and TOGAF methodologies

 














I came across this article giving a comparison between what is included in DAMA-DMBOK2, DCAM and TOGAF methodologies. I mentioned the core framework elements here. The most used data models by the industry are DAMA-DMBOK2 by the DAMA International and DCAM® 2.2 by the EDM Council.

No one model covers all areas and no one company is the same and it is very common that different bits are used as and when required. It is worth reading the discussion in the blog. 

Sunday, 1 May 2022

Different data models and frameworks

 There are 3 different models that can help when thinking about data governance and data management.

The revised DAMA Wheel has data governance at the top

The core components to think about for data governance and data management are: Policy; Stewardship & Ownership; Culture Change; Strategy; Principles and Ethics; Data Valuation; Data Maturity Assessment; Data Classification.

When getting started I look at the fundamentals as a starting place.
1. Data Governance
2. Meta Data Management
3. Data Quality
4. Reference/Master Data

DAMA-DMBOK | Data Management Body of Knowledge




DCAM (Data Management Capability Assessment Model) was first published in 2014 following the Socratic method of question and debate. . CDMC (Cloud Data Management Capabilities Framework) is a playbook of best practice for managing data in the cloud. Version 1.1.1 was released in September 2021 , created by a cross industry workgroup of 100+ firms. It is a framework for best data management practices to accelerate trusted cloud adoption.  It can be downloaded here. The holistic list of capabilities highlighted in the CDMC from the EDM Council is:

Data Cataloguing and Discovery 
Data Classification 
Data Ownership 
Data Security 
Data Sovereignty and Cross-Border Data Sharing 
Data Quality
Data Lifecycle Management 
Data Entitlements and Access Tracking  
Data Lineage  
Data Privacy 
Trusted Source Management and Data Contracts 
Ethical Use and Purpose 
Master Data Management

The Data Management Maturity (DMM)  program from the CMMI Institute has best practices for providing support for the implementation of process for these five categories: strategy; governance; data quality; operations; and platform and architecture. 

Best practice for ensuring broad participation in the practice and senior oversight of the effectiveness of data management. 


Capability Maturity Model Integration  (CMMI) Six themes  The CMMI models are described as collections of effective practices and process improvement goals that organisations can use to evaluate and improve their processes. 

Wednesday, 28 July 2021

Data Governance: An Introduction

Initially published on the Coeo blog.  

Data Governance is a core area that businesses need to adopt in the data-driven world. Data has been around since the earliest of times, from the first libraries in the ancient world that started to collect and store information.

The collection of scientific research information, from census information about human populations, weather and spatial data to DNA genetic data, have all been contributing to the need to store data for analysis. The breadth of the information that is available for analysis covers our entire planet and beyond, and the population as well as different species. With our life and environment becoming documented to the finest degree the need for categorisation, data labelling and data management has become engrained into our society. Where research led the way for documentation of classification for data, business is now at a crucial time of growth and expansion to enable innovation.

With all data there becomes a continual need for its management and a core starting place is data governance. The DAMA Dictionary of Data Management defines Data Governance as “The exercise of authority, control and shared decision making (planning, monitoring and enforcement) over the management of data assets".

The goal of data governance is to help an organisation to manage data as an asset efficiently and effectively. It provides the principles, policy, processes, framework, metrics and oversight that are required to drive the most business value. Data governance programs have a goal of creating sustainable data management, good data quality that is measured and defining policies and practices. A much-needed area that needs to be considered is that of culture and embedding that culture of data management into the business.

We start with understanding what data assets a business has from the core known data and dark data; data that is collected but not used. The proliferation of duplicate data around a business is key to document. Often the first thing that comes to mind with data governance these days is compliance with all the data breaches that keep occurring. The areas one thinks of here are:  

  • Policies
  • Transparency
  • Governance
  • Regulations, such as GDPR
  • Standards
  • Rules
  • Law

These require data inventories and audits to understand what personal data your organisation collects, where it is stored, how it is protected and who may have access to it.​ This is part of the picture that needs to be considered.

DAMA-DMBOK is an international guiding framework for the management of data. The framework includes areas such as:

  • Data Strategy – defining, communicating and driving execution​.
  • Policy – metadata management, access, usage, security, quality
  • Standards and quality – data architecture and data quality standards
  • Oversight/audit/stewardship
  • Compliance
  • Data issue management – compliance, ownership, policy, terminology, data quality, data access
  • Data management improvement projects 
  • Data asset valuation constantly define business value of data assets.

Consideration for the allocation of roles and responsibilities within an operating model helps guide the adoption of best practices.

In conclusion, managing data assets within a business requires it to be embedded in the culture of an organisation. Having high quality data leads to better business decisions. Having a core oversight function that is provided by a Chief Data Officer helps with keeping the day to day running of data in the fore front of everyone’s minds and you never know where the next innovation will come from.

More Information