ASEAN Data Management Framework
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Controls
Implement preventive and detective controls commensurate with the potential impact of data being compromised, establishing risk tolerance and selecting controls to bring risk within the risk appetite.
- Control set mapped to dataset tiers
- Risk tolerance/appetite statement driving control selection
- Evidence controls are operating
- Uniform controls regardless of tier
- No link between control strength and impact
- Controls designed but not operating
Apply technical (IT controls), procedural (baseline and design) and physical safeguards to ensure confidentiality, integrity and availability of data at all stages of the data lifecycle.
- Inventory of technical, procedural and physical safeguards
- Mapping of safeguards to CIA objectives
- Evidence safeguards cover hardcopy and digital data
- Only technical controls considered
- Physical/hardcopy data unprotected
- Procedural safeguards undocumented
Apply protection appropriate to each data lifecycle stage, creation, distribution, storage and disposal, e.g. MFA and encryption at creation, encryption and DLP in transit, end-point encryption and DR for storage, and media sanitisation prior to disposal.
- Lifecycle-stage control mapping (creation/distribution/storage/disposal)
- Evidence of encryption, DLP, backup/DR and sanitisation as applicable
- Disposal/sanitisation records
- Controls only at rest, transit and disposal ignored
- No secure disposal/sanitisation
- Lifecycle stages not distinguished
Document a data protection control matrix that specifies the controls applied for each category/tier across the data lifecycle stages.
- Data protection control matrix (tier x lifecycle stage)
- Approval and version history of the matrix
- Evidence matrix is applied operationally
- No documented mapping of controls to tiers and stages
- Matrix not maintained
- Matrix exists but is not operationalised
Assess residual risk remaining after controls and have management formally assess and accept it through a risk acceptance process.
- Residual risk register
- Documented management risk-acceptance decisions
- Evidence residual risk is within risk appetite
- Residual risk not assessed
- No formal acceptance by management
- Accepted risks not tracked or reviewed
Use recognised international standards as reference when categorising and protecting data, e.g. NIST SP 800-60, FIPS 199, NIST CSF/RMF, ISO 9001, ISO/IEC 27001, 27018 and 27701.
- Documented references to standards used (e.g. ISO 27001, NIST CSF/RMF, FIPS 199)
- Mapping of internal categories to referenced standards
- Justification where standards are adapted
- No reference to external standards
- Standards cited but not actually applied
- Adaptations from standards undocumented
Data Inventory
Begin with identification of the data the organisation possesses by answering why data is collected/used/stored, who is responsible, what type of data, where it is located and how it is accessed; update understanding as new data types arise.
- Data identification questionnaire (why/who/what/where/how) completed
- Evidence of periodic re-identification of new data types
- Mapping of responsible owners to data
- Only known systems mapped, shadow data omitted
- Data ownership not assigned
- No trigger to capture newly collected data types
Capture in a data inventory, for each dataset, the purpose, data owner, data type (personal or business), data fields, dataset and location/system; keep the inventory updated as new data types are collected.
- Data inventory register with purpose, owner, type, fields, dataset and location
- Update log showing the inventory is maintained
- Coverage check across business units
- Inventory missing key attributes (owner, purpose, location)
- Personal vs business data not distinguished
- Inventory stale or partial
When categorising and protecting data consider nature and type of services provided, applicable regulation (e.g. PDPA, GDPR, sector rules), competitive landscape, cost of safeguards versus risk appetite (including data aggregation and volume), and customer expectations.
- Documented categorisation considerations applied per dataset
- Regulatory mapping (PDPA/GDPR/sector) influencing categories
- Rationale balancing safeguard cost against risk appetite
- Categories assigned without considering regulation
- Aggregation/volume effects ignored
- Over-protection that hinders legitimate data use
Governance and Oversight
Identify and determine roles and responsibilities across three functions, data management, business process and risk management, to ensure adoption, operation and compliance of the DMF in line with business needs.
- Org chart or RACI assigning data management, business process and risk management functions
- Documented mandate/terms of reference for each function
- Board or owner approval of the governance structure
- Functions defined on paper but not staffed or empowered
- No risk management function separate from operations
- Small-organisation roles undocumented and undelegated
The data management function owns and designs the processes supporting the six components, defines policies and procedures, determines implementation roles and skills, promotes awareness, reviews dataset categories, manages risk by establishing protection controls, and handles data protection queries and complaints.
- Documented process ownership for the six DMF components
- Awareness/training distribution records
- Log of data-protection queries and complaints with resolution
- No single accountable owner for the DMF processes
- Awareness activities not evidenced
- Category reviews not performed by the data management function
The business process function identifies data and completes the data inventory, implements protection controls and complies with defined policies and procedures, and reports any security incident or non-compliance.
- Completed data inventory attributable to business units
- Evidence controls are operated by process owners
- Incident/non-compliance reports raised by business functions
- Inventory completed centrally without business-unit input
- Controls defined but not operated by process owners
- Incidents not reported up to the risk function
The risk management function monitors implementation of effective data risk-management practices to keep risk within the organisation's risk appetite, evaluates control effectiveness, and reports findings to management with recommendations to improve policies.
- Risk monitoring reports against risk appetite
- Control effectiveness evaluations
- Findings and improvement recommendations to management
- No independent evaluation of control effectiveness
- Risk appetite not used as a monitoring threshold
- Findings not reported to management
Leadership (business owner or executive management) establishes risk appetite and strategy, approves the content of the six foundational components, and oversees the function to confirm it operates as designed.
- Documented risk appetite and data strategy approved by leadership
- Sign-off of the six DMF components
- Oversight/management review records
- Risk appetite undefined or not approved at leadership level
- Components implemented without executive sign-off
- No oversight to confirm the function operates as designed
Impact / Risk Assessment
Define a categorisation matrix with impact categories, thresholds and tiers that provides clear guidance on assigning datasets by risk impact level; the number of tiers depends on business needs (non-prescriptive).
- Documented categorisation matrix with tiers and thresholds
- Guidance on assigning datasets to tiers
- Approval of the matrix by the data management function
- No defined tiers or thresholds
- Matrix not applied consistently
- Tier definitions ambiguous
Assess the impact if a dataset is compromised across confidentiality (unauthorised disclosure), integrity (quality/corruption) and availability (not available to intended users).
- Impact assessment recording C, I and A impact per dataset
- Definitions of confidentiality, integrity and availability impact
- Linkage of CIA impact to assigned tier
- Only confidentiality considered, integrity/availability omitted
- CIA impact not recorded per dataset
- Assessment not repeated when data changes
Assess impact across the primary impact categories, financial, strategic, operational and compliance (and reputational/legal), to inform the tier assigned to each dataset.
- Impact assessment across financial, strategic, operational and compliance categories
- Evidence categories feed the tier assignment
- Stakeholder input into impact ratings
- Impact assessed on a single dimension
- Compliance/legal impact not considered
- No traceability from impact to tier
Assign each dataset to a tier (e.g. Tier 1 significant, Tier 2 moderate, Tier 3 limited harm) based on the assessed impact, avoiding over-protection that hinders business use of data.
- Register of datasets with assigned tiers
- Rationale for each tier assignment
- Review evidence that tiers remain appropriate
- Datasets unassigned or default-tiered
- Tiers assigned without documented rationale
- Over-classification across the board
Monitoring and Continuous Improvement
Determine what needs to be monitored and measured, the methods of monitoring/measurement/analysis/evaluation, when monitoring and measurement are performed and by whom, and when results are analysed and evaluated.
- Documented monitoring plan (what/how/when/who)
- Defined metrics and evaluation cadence
- Assigned monitoring responsibilities
- Monitoring undefined or ad hoc
- No metrics or evaluation schedule
- Responsibility for monitoring unassigned
Periodically review the design of the process for assigning categories and the data protection controls matrix, taking into account security audits, incidents, effectiveness measurements and business feedback.
- Periodic review records of categorisation process and control matrix
- Inputs from audits, incidents and effectiveness measures
- Resulting design changes
- Control matrix never reviewed
- Audit/incident learnings not fed back
- Reviews not evidenced
Periodically review the categories assigned to datasets and the current lifecycle stage for each, adjusting tiers as data, use or context changes.
- Periodic re-categorisation review records
- Evidence tiers updated when data/use changes
- Lifecycle status tracked per dataset
- Categories set once and never revisited
- Lifecycle stage not tracked
- Re-categorisation not triggered by change
Test the operating effectiveness of data protection controls and measure effectiveness to verify that security requirements have been met.
- Control effectiveness test results
- Defined effectiveness measures/requirements
- Remediation of failed tests
- Controls assumed effective without testing
- No defined effectiveness criteria
- Test failures not remediated
Incorporate findings from monitoring and review activities into updated policies, procedures and processes to drive continuous improvement of data management.
- Change log showing updates driven by monitoring findings
- Updated policies/procedures with version history
- Evidence of communication of changes
- Findings not translated into updates
- Policies static despite review findings
- Updates not communicated
Policies and Procedures
Management provides documented commitment to the establishment, implementation, operation, monitoring, review, maintenance and improvement of data management initiatives.
- Approved data management policy with leadership endorsement
- Statement of management commitment
- Review/version history of the policy
- Policy lacks leadership endorsement
- Commitment stated once and never reviewed
- No named policy owner
The objectives, scope of application and considerations of the DMF are defined, documented and maintained to enable a clear understanding of the implementation parameters specific to the organisation.
- Documented DMF objectives and scope
- Defined considerations specific to the organisation
- Maintenance/review evidence of scope statements
- Scope undocumented or generic
- Objectives not tied to the organisation's data context
- Scope never revisited as the business changes
Adopt an effective data management approach to define, establish, monitor and maintain data management, including formalising the activities that categorise and protect datasets and provide for their continued improvement.
- Documented data management approach/methodology
- Formalised categorisation and protection procedures
- Continuous improvement mechanism in procedure
- Approach implied but not formalised
- Categorisation and protection steps not described procedurally
- No improvement loop in procedures
Include data management policies as part of corporate governance to ensure a clear mandate and accountability, and reflect the subsequent foundational components as content within the policies and procedures.
- Data management policy referenced within corporate governance framework
- Policies reflecting inventory, assessment, controls and monitoring components
- Distribution to internal and external stakeholders
- Policy isolated from corporate governance
- Components 3-6 not reflected in policy content
- Policies not communicated to suppliers/employees
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASEAN Data Management Framework framework page.