Skip to content

Evidence request lists

DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)

Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Data Architecture

DMBOK-DA-01
Enterprise Data Architecture

Maintain an enterprise data architecture including conceptual models, data flows, and reference architecture aligned to business capabilities.

Artefacts an auditor will ask for
  • conceptual model
  • data flow diagrams
  • reference architecture
Where this commonly fails
  • no maintained CDM
  • drift between architecture and reality
DMBOK-DA-02
Data Architecture Governance

Architecture changes follow review processes that assess impact on integration, quality, and compliance.

Artefacts an auditor will ask for
  • ARB minutes
  • architecture decisions
  • impact assessments
Where this commonly fails
  • ARB bypassed for tactical projects

Data Architecture and Modeling

DA-1
Enterprise Data Architecture

Define the overall structure of data and data-related resources as an integral part of the enterprise architecture.

Artefacts an auditor will ask for
  • enterprise data architecture diagram
  • reference architecture
  • architecture review board
Where this commonly fails
  • fragmented architecture
  • no ARB
  • stale diagrams
DA-2
Data Modeling and Design

Analyze, design, build, test, and maintain data models representing business requirements and system structures.

Artefacts an auditor will ask for
  • conceptual model
  • logical model
  • physical model
  • modeling standards
Where this commonly fails
  • incomplete models
  • weak standards
  • stale documentation
DA-3
Data Architecture Standards

Maintain architectural standards and guidelines that direct data integration, data flow, and technology platform decisions.

Artefacts an auditor will ask for
  • data architecture standards
  • naming conventions
  • pattern library
Where this commonly fails
  • weak standards adoption
  • inconsistent naming
  • no pattern library

Data Ethics and Maturity

DEM-1
Data Ethics

Establish ethical guidelines for data collection, usage, sharing, and monetization that respect individual rights.

Artefacts an auditor will ask for
  • data ethics framework
  • ethics review board
  • case register
Where this commonly fails
  • no framework
  • weak review
  • no register
DEM-2
Data Management Maturity Assessment

Assess organizational data management maturity levels and establish improvement roadmaps for each knowledge area.

Artefacts an auditor will ask for
  • DM maturity assessment
  • improvement roadmap
  • KPI tracker
Where this commonly fails
  • no assessment
  • weak roadmap
  • no tracker
DEM-3
Big Data and Data Science

Manage the unique requirements of big data environments including volume, velocity, variety, and veracity considerations.

Artefacts an auditor will ask for
  • big data architecture
  • data science governance
  • model registry
Where this commonly fails
  • weak governance
  • no model registry
  • stale architecture

Data Governance

DG-1
Data Governance Strategy

Establish policies, decision rights, and accountabilities for the proper management of data assets across the organization.

Artefacts an auditor will ask for
  • DG strategy
  • DG operating model
  • council charter
Where this commonly fails
  • no strategy
  • weak operating model
  • unclear council mandate
DG-2
Data Stewardship

Define data stewardship roles and responsibilities for oversight and accountability of data quality and usage.

Artefacts an auditor will ask for
  • steward role description
  • steward register
  • data domain map
Where this commonly fails
  • no stewards
  • weak mandate
  • unclear domains
DG-3
Data Policies and Standards

Develop and enforce organization-wide data policies, standards, and procedures for data management activities.

Artefacts an auditor will ask for
  • data policy catalog
  • standards register
  • policy lifecycle
Where this commonly fails
  • stale policies
  • weak standards
  • no lifecycle
DMBOK-DG-01
Data Governance Strategy and Operating Model

Establish a governance operating model with steering committee, data council, stewards, and clear decision rights aligned to business strategy.

Artefacts an auditor will ask for
  • Charter
  • RACI
  • council minutes
  • org chart
Where this commonly fails
  • no accountable executive sponsor
  • stewards undefined
DMBOK-DG-02
Data Policies and Standards

Define, publish, and enforce data policies, standards, and procedures covering classification, retention, sharing, and quality.

Artefacts an auditor will ask for
  • policy library
  • standards catalog
  • exception register
Where this commonly fails
  • policies unpublished
  • no exception process
DMBOK-DG-03
Data Stewardship Network

Appoint business and technical stewards with documented responsibilities and engagement cadence.

Artefacts an auditor will ask for
  • steward roster
  • responsibility matrix
  • meeting cadence
Where this commonly fails
  • stewardship in name only
DMBOK-DG-04
Data Management Maturity Assessment

Periodically assess maturity across knowledge areas and prioritise improvements.

Artefacts an auditor will ask for
  • maturity assessment
  • improvement roadmap
  • investment plan
Where this commonly fails
  • no rebaseline after 2 years

Data Integration and Interoperability

DMBOK-DI-01
Data Integration Architecture

Design and govern integration patterns (ETL, ELT, streaming, replication, APIs) consistently across the enterprise.

Artefacts an auditor will ask for
  • integration catalog
  • pattern guide
  • interface contracts
Where this commonly fails
  • point-to-point sprawl
DMBOK-DI-02
Data Lineage and Movement

Document end-to-end data lineage from sources through transformations to consumers.

Artefacts an auditor will ask for
  • lineage diagrams
  • metadata tool output
  • transformation rules
Where this commonly fails
  • manual lineage missing fields

Data Integration, Quality and Metadata

DIQ-1
Data Integration and Interoperability

Manage data acquisition, extraction, transformation, movement, delivery, replication, federation, and virtualization.

Artefacts an auditor will ask for
  • integration architecture
  • API catalog
  • ETL inventory
Where this commonly fails
  • point-to-point sprawl
  • weak catalog
  • stale ETL
DIQ-2
Data Quality Management

Define, monitor, and maintain data integrity through profiling, cleansing, matching, and continuous improvement.

Artefacts an auditor will ask for
  • DQ rules catalog
  • DQ dashboard
  • DQ improvement plan
Where this commonly fails
  • weak DQ rules
  • no dashboard
  • no improvement plan
DIQ-3
Metadata Management

Collect, categorize, maintain, integrate, and deliver metadata to support data management and governance.

Artefacts an auditor will ask for
  • metadata catalog
  • business glossary
  • lineage diagrams
Where this commonly fails
  • weak metadata
  • no lineage
  • stale glossary

Data Modeling and Design

DMBOK-DM-01
Conceptual, Logical, and Physical Data Models

Develop layered data models with traceability from business concepts to physical implementation.

Artefacts an auditor will ask for
  • CDM
  • LDM
  • PDM
  • model versioning
Where this commonly fails
  • physical drift from logical model
DMBOK-DM-02
Modeling Standards and Naming Conventions

Apply consistent naming, abbreviation, and modeling notation standards across the enterprise.

Artefacts an auditor will ask for
  • naming standard
  • abbreviation list
  • style guide
Where this commonly fails
  • inconsistent table prefixes

Data Quality

DMBOK-DQ-01
Data Quality Management Program

Establish a DQ program with dimensions (accuracy, completeness, consistency, timeliness, validity, uniqueness), KPIs, and remediation.

Artefacts an auditor will ask for
  • DQ framework
  • KPI dashboards
  • issue log
Where this commonly fails
  • DQ owned only by IT, not business
DMBOK-DQ-02
Data Profiling and Monitoring

Profile critical data elements regularly and monitor quality against thresholds with alerts.

Artefacts an auditor will ask for
  • profiling output
  • DQ rules
  • monitoring dashboards
Where this commonly fails
  • thresholds not defined
DMBOK-DQ-03
Data Quality Issue Resolution

Track quality issues to root cause and implement preventive controls.

Artefacts an auditor will ask for
  • issue tickets
  • RCA reports
  • preventive control register
Where this commonly fails
  • recurring issues without RCA

Data Security

DMBOK-DSec-01
Data Security Classification

Classify data by sensitivity and apply controls commensurate with classification levels.

Artefacts an auditor will ask for
  • classification policy
  • data inventory with classes
  • labeling tools
Where this commonly fails
  • unclassified PII in shared drives
DMBOK-DSec-02
Access Controls and Privileged Access

Implement role-based access, least privilege, and review privileged accounts regularly.

Artefacts an auditor will ask for
  • RBAC matrix
  • access review reports
  • privileged account inventory
Where this commonly fails
  • no quarterly access reviews
DMBOK-DSec-03
Data Masking and Encryption

Protect data at rest and in transit using encryption, masking, or tokenisation appropriate to risk.

Artefacts an auditor will ask for
  • encryption inventory
  • key management procedures
  • masking config
Where this commonly fails
  • prod data in non-prod without masking

Data Storage and Operations

DMBOK-DS-01
Database Design and Operations

Design databases for performance, availability, and recoverability with documented operations.

Artefacts an auditor will ask for
  • design docs
  • backup schedules
  • recovery test results
Where this commonly fails
  • DR tests not performed
  • no documented runbooks
DMBOK-DS-02
Database Performance and Capacity Management

Monitor performance, plan capacity, and tune database environments proactively.

Artefacts an auditor will ask for
  • capacity plans
  • performance baselines
  • tuning reports
Where this commonly fails
  • no capacity forecasting

Data Storage, Operations and Security

DSO-1
Data Storage and Operations

Manage structured physical data assets through storage deployment, maintenance, and operations support.

Artefacts an auditor will ask for
  • storage architecture
  • capacity plan
  • backup policy
Where this commonly fails
  • weak capacity planning
  • stale architecture
  • unverified backups
DSO-2
Data Security

Ensure privacy, confidentiality, and appropriate access controls for personal, health, and private data.

Artefacts an auditor will ask for
  • data security policy
  • controls catalog
  • monitoring evidence
Where this commonly fails
  • weak controls
  • no monitoring
  • stale policy
DSO-3
Data Access Management

Control and monitor access to data assets through authentication, authorization, and audit mechanisms.

Artefacts an auditor will ask for
  • access management policy
  • access reviews
  • privilege catalog
Where this commonly fails
  • stale access
  • no reviews
  • weak privilege catalog

Data Warehousing and BI

DMBOK-DW-01
Data Warehouse and BI Architecture

Provide integrated analytical data via warehouse, marts, or lakehouse aligned to reporting needs.

Artefacts an auditor will ask for
  • DW architecture
  • semantic layer
  • BI catalog
Where this commonly fails
  • multiple conflicting marts
DMBOK-DW-02
Analytical Data Quality and Reconciliation

Reconcile analytical outputs against sources and certify reports for trust.

Artefacts an auditor will ask for
  • recon reports
  • certified report register
  • balancing controls
Where this commonly fails
  • BI numbers diverge from source

Documents and Content

DMBOK-DOC-01
Document and Content Management

Manage unstructured documents and records with classification, retention, and search capability.

Artefacts an auditor will ask for
  • ECM inventory
  • retention schedule
  • records policy
Where this commonly fails
  • legacy fileshares unmanaged

Documents, Content and Business Intelligence

DCB-1
Document and Content Management

Store, protect, index, and enable access to data found in unstructured sources including electronic files and physical records.

Artefacts an auditor will ask for
  • DMS configuration
  • content lifecycle policy
  • retention schedule
Where this commonly fails
  • uncontrolled documents
  • weak lifecycle
  • stale retention
DCB-2
Data Warehousing

Manage analytical data processing through data warehouse design, ETL processes, and dimensional modeling.

Artefacts an auditor will ask for
  • DW architecture
  • ETL design
  • data marts inventory
Where this commonly fails
  • weak data marts
  • poor lineage
  • stale ETL
DCB-3
Business Intelligence and Analytics

Enable access to decision support data for reporting, analysis, and data-driven decision making.

Artefacts an auditor will ask for
  • BI tooling inventory
  • analytics catalog
  • KPI dictionary
Where this commonly fails
  • report proliferation
  • weak KPI definitions
  • no analytics catalog

Metadata

DMBOK-META-01
Metadata Management Strategy

Capture business, technical, and operational metadata in a managed metadata repository.

Artefacts an auditor will ask for
  • metadata strategy
  • catalog tool
  • glossary entries
Where this commonly fails
  • business glossary stale
DMBOK-META-02
Business Glossary and Data Dictionary

Maintain shared business definitions and link them to physical implementations.

Artefacts an auditor will ask for
  • Glossary
  • approval workflow
  • term-to-column linkage
Where this commonly fails
  • terms approved but unlinked

Reference Data and Master Data

RMD-1
Reference Data Management

Manage shared reference data sets to reduce redundancy and ensure standardized definition and use of data values.

Artefacts an auditor will ask for
  • reference data inventory
  • governance procedures
  • change log
Where this commonly fails
  • fragmented reference data
  • no governance
  • weak change log
RMD-2
Master Data Management

Establish authoritative sources for master data entities and implement processes to maintain data consistency.

Artefacts an auditor will ask for
  • MDM architecture
  • golden record policy
  • stewardship plan
Where this commonly fails
  • weak golden record
  • stewardship gaps
  • stale architecture
RMD-3
Data Matching and Linking

Implement matching algorithms and linking processes to resolve duplicates and maintain a single view of entities.

Artefacts an auditor will ask for
  • matching rules
  • entity resolution platform
  • review queue
Where this commonly fails
  • weak matching rules
  • no review queue
  • poor resolution accuracy

Reference and Master Data

DMBOK-RMD-01
Reference Data Management

Govern reference data (codes, lookups, taxonomies) with authoritative sources and change control.

Artefacts an auditor will ask for
  • reference data catalog
  • change log
  • authoritative source list
Where this commonly fails
  • multiple country code lists
DMBOK-RMD-02
Master Data Management

Implement MDM for critical entities (customer, product, employee) with matching, survivorship, and stewardship.

Artefacts an auditor will ask for
  • MDM hub design
  • match rules
  • survivorship rules
  • steward workflow
Where this commonly fails
  • customer duplicates across systems
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition) framework page.