DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Data Architecture
Maintain an enterprise data architecture including conceptual models, data flows, and reference architecture aligned to business capabilities.
- conceptual model
- data flow diagrams
- reference architecture
- no maintained CDM
- drift between architecture and reality
Architecture changes follow review processes that assess impact on integration, quality, and compliance.
- ARB minutes
- architecture decisions
- impact assessments
- ARB bypassed for tactical projects
Data Architecture and Modeling
Define the overall structure of data and data-related resources as an integral part of the enterprise architecture.
- enterprise data architecture diagram
- reference architecture
- architecture review board
- fragmented architecture
- no ARB
- stale diagrams
Analyze, design, build, test, and maintain data models representing business requirements and system structures.
- conceptual model
- logical model
- physical model
- modeling standards
- incomplete models
- weak standards
- stale documentation
Maintain architectural standards and guidelines that direct data integration, data flow, and technology platform decisions.
- data architecture standards
- naming conventions
- pattern library
- weak standards adoption
- inconsistent naming
- no pattern library
Data Ethics and Maturity
Establish ethical guidelines for data collection, usage, sharing, and monetization that respect individual rights.
- data ethics framework
- ethics review board
- case register
- no framework
- weak review
- no register
Assess organizational data management maturity levels and establish improvement roadmaps for each knowledge area.
- DM maturity assessment
- improvement roadmap
- KPI tracker
- no assessment
- weak roadmap
- no tracker
Manage the unique requirements of big data environments including volume, velocity, variety, and veracity considerations.
- big data architecture
- data science governance
- model registry
- weak governance
- no model registry
- stale architecture
Data Governance
Establish policies, decision rights, and accountabilities for the proper management of data assets across the organization.
- DG strategy
- DG operating model
- council charter
- no strategy
- weak operating model
- unclear council mandate
Define data stewardship roles and responsibilities for oversight and accountability of data quality and usage.
- steward role description
- steward register
- data domain map
- no stewards
- weak mandate
- unclear domains
Develop and enforce organization-wide data policies, standards, and procedures for data management activities.
- data policy catalog
- standards register
- policy lifecycle
- stale policies
- weak standards
- no lifecycle
Establish a governance operating model with steering committee, data council, stewards, and clear decision rights aligned to business strategy.
- Charter
- RACI
- council minutes
- org chart
- no accountable executive sponsor
- stewards undefined
Define, publish, and enforce data policies, standards, and procedures covering classification, retention, sharing, and quality.
- policy library
- standards catalog
- exception register
- policies unpublished
- no exception process
Appoint business and technical stewards with documented responsibilities and engagement cadence.
- steward roster
- responsibility matrix
- meeting cadence
- stewardship in name only
Periodically assess maturity across knowledge areas and prioritise improvements.
- maturity assessment
- improvement roadmap
- investment plan
- no rebaseline after 2 years
Data Integration and Interoperability
Design and govern integration patterns (ETL, ELT, streaming, replication, APIs) consistently across the enterprise.
- integration catalog
- pattern guide
- interface contracts
- point-to-point sprawl
Document end-to-end data lineage from sources through transformations to consumers.
- lineage diagrams
- metadata tool output
- transformation rules
- manual lineage missing fields
Data Integration, Quality and Metadata
Manage data acquisition, extraction, transformation, movement, delivery, replication, federation, and virtualization.
- integration architecture
- API catalog
- ETL inventory
- point-to-point sprawl
- weak catalog
- stale ETL
Define, monitor, and maintain data integrity through profiling, cleansing, matching, and continuous improvement.
- DQ rules catalog
- DQ dashboard
- DQ improvement plan
- weak DQ rules
- no dashboard
- no improvement plan
Collect, categorize, maintain, integrate, and deliver metadata to support data management and governance.
- metadata catalog
- business glossary
- lineage diagrams
- weak metadata
- no lineage
- stale glossary
Data Modeling and Design
Develop layered data models with traceability from business concepts to physical implementation.
- CDM
- LDM
- PDM
- model versioning
- physical drift from logical model
Apply consistent naming, abbreviation, and modeling notation standards across the enterprise.
- naming standard
- abbreviation list
- style guide
- inconsistent table prefixes
Data Quality
Establish a DQ program with dimensions (accuracy, completeness, consistency, timeliness, validity, uniqueness), KPIs, and remediation.
- DQ framework
- KPI dashboards
- issue log
- DQ owned only by IT, not business
Profile critical data elements regularly and monitor quality against thresholds with alerts.
- profiling output
- DQ rules
- monitoring dashboards
- thresholds not defined
Track quality issues to root cause and implement preventive controls.
- issue tickets
- RCA reports
- preventive control register
- recurring issues without RCA
Data Security
Classify data by sensitivity and apply controls commensurate with classification levels.
- classification policy
- data inventory with classes
- labeling tools
- unclassified PII in shared drives
Implement role-based access, least privilege, and review privileged accounts regularly.
- RBAC matrix
- access review reports
- privileged account inventory
- no quarterly access reviews
Protect data at rest and in transit using encryption, masking, or tokenisation appropriate to risk.
- encryption inventory
- key management procedures
- masking config
- prod data in non-prod without masking
Data Storage and Operations
Design databases for performance, availability, and recoverability with documented operations.
- design docs
- backup schedules
- recovery test results
- DR tests not performed
- no documented runbooks
Monitor performance, plan capacity, and tune database environments proactively.
- capacity plans
- performance baselines
- tuning reports
- no capacity forecasting
Data Storage, Operations and Security
Manage structured physical data assets through storage deployment, maintenance, and operations support.
- storage architecture
- capacity plan
- backup policy
- weak capacity planning
- stale architecture
- unverified backups
Ensure privacy, confidentiality, and appropriate access controls for personal, health, and private data.
- data security policy
- controls catalog
- monitoring evidence
- weak controls
- no monitoring
- stale policy
Control and monitor access to data assets through authentication, authorization, and audit mechanisms.
- access management policy
- access reviews
- privilege catalog
- stale access
- no reviews
- weak privilege catalog
Data Warehousing and BI
Provide integrated analytical data via warehouse, marts, or lakehouse aligned to reporting needs.
- DW architecture
- semantic layer
- BI catalog
- multiple conflicting marts
Reconcile analytical outputs against sources and certify reports for trust.
- recon reports
- certified report register
- balancing controls
- BI numbers diverge from source
Documents and Content
Manage unstructured documents and records with classification, retention, and search capability.
- ECM inventory
- retention schedule
- records policy
- legacy fileshares unmanaged
Documents, Content and Business Intelligence
Store, protect, index, and enable access to data found in unstructured sources including electronic files and physical records.
- DMS configuration
- content lifecycle policy
- retention schedule
- uncontrolled documents
- weak lifecycle
- stale retention
Manage analytical data processing through data warehouse design, ETL processes, and dimensional modeling.
- DW architecture
- ETL design
- data marts inventory
- weak data marts
- poor lineage
- stale ETL
Enable access to decision support data for reporting, analysis, and data-driven decision making.
- BI tooling inventory
- analytics catalog
- KPI dictionary
- report proliferation
- weak KPI definitions
- no analytics catalog
Metadata
Capture business, technical, and operational metadata in a managed metadata repository.
- metadata strategy
- catalog tool
- glossary entries
- business glossary stale
Maintain shared business definitions and link them to physical implementations.
- Glossary
- approval workflow
- term-to-column linkage
- terms approved but unlinked
Reference Data and Master Data
Manage shared reference data sets to reduce redundancy and ensure standardized definition and use of data values.
- reference data inventory
- governance procedures
- change log
- fragmented reference data
- no governance
- weak change log
Establish authoritative sources for master data entities and implement processes to maintain data consistency.
- MDM architecture
- golden record policy
- stewardship plan
- weak golden record
- stewardship gaps
- stale architecture
Implement matching algorithms and linking processes to resolve duplicates and maintain a single view of entities.
- matching rules
- entity resolution platform
- review queue
- weak matching rules
- no review queue
- poor resolution accuracy
Reference and Master Data
Govern reference data (codes, lookups, taxonomies) with authoritative sources and change control.
- reference data catalog
- change log
- authoritative source list
- multiple country code lists
Implement MDM for critical entities (customer, product, employee) with matching, survivorship, and stewardship.
- MDM hub design
- match rules
- survivorship rules
- steward workflow
- customer duplicates across systems
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition) framework page.