EDM Council CDMC - Cloud Data Management Capability Framework
Evidence request list. 14 controls, 14 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CDMC Component 1: Governance and Accountability
The data control compliance of cloud and migrated data is monitored, with compliance to the CDMC Key Controls measured and reported (and the controls automated where possible).
- Evidence that compliance with the data controls is monitored and reported
- Automation of control monitoring
- No monitoring of data-control compliance in the cloud
Ownership is established and an ownership field is populated for all migrated and cloud-generated sensitive data, or the data is automatically flagged for review.
- An ownership field populated for sensitive data assets
- Process to flag data lacking an owner
- Sensitive data without an assigned owner
Sources of authoritative data and the authorised provisioning points are governed and recorded for sensitive data.
- Register of authoritative data sources and provisioning points
- No governance of authoritative sources / provisioning points
Data sovereignty and cross-border movement of sensitive data are recorded, auditable and controlled in accordance with defined policy.
- Records of data location and cross-border movement
- Controls enforcing sovereignty policy
- Uncontrolled cross-border movement of sensitive data
CDMC Component 2: Cataloguing and Classification
Cataloguing of sensitive data is automated and the catalogue is maintained as new data is created or ingested in the cloud.
- A data catalogue covering sensitive data, kept current (preferably automated)
- Sensitive data not catalogued
Classification of sensitive data is defined and applied (automatically where possible) using a consistent classification scheme covering categories such as PII, regulatory and confidentiality.
- Applied data classification using a defined scheme
- Automated classification where feasible
- Unclassified sensitive data
CDMC Component 3: Accessibility and Usage
Entitlements and access for sensitive data are managed by default and tracked, ensuring access is granted on a controlled, least-privilege basis.
- Entitlement/access records for sensitive data
- Default-deny / least-privilege access
- Uncontrolled access to sensitive data
The purpose for which data is consumed is defined and tracked for sensitive data, ensuring use is consistent with the permitted purpose.
- Recorded data consumption purposes for sensitive data
- Data used beyond its permitted purpose
CDMC Component 4: Protection and Privacy
Data Protection Impact Assessments are automatically triggered/performed for personal data in accordance with privacy requirements.
- DPIAs for personal-data processing
- Triggering mechanism for DPIAs
- Personal data processed without a DPIA where required
Appropriate security controls (including encryption, key management and monitoring) are enabled and evidence of their operation is recorded for sensitive data in the cloud.
- Security controls (encryption, key management, monitoring) applied to sensitive data
- Evidence of control operation
- Sensitive cloud data without adequate security controls
CDMC Component 5: Data Lifecycle
Data retention, archiving and purging are managed in accordance with a defined retention schedule for sensitive data.
- Retention schedule and evidence of archiving/purging
- Automated lifecycle enforcement
- Indefinite retention / no purging of sensitive data
Data quality is measured for sensitive data using defined data-quality metrics and the results are monitored.
- Data-quality metrics and measurement results for sensitive data
- No data-quality measurement
CDMC Component 6: Data and Technical Architecture
Cost metrics directly associated with data use, storage and movement are defined and monitored.
- Cost metrics for cloud data use/storage/movement
- No visibility of data-related cloud cost
Data lineage information is available, and the provenance and movement of sensitive data can be traced across the cloud environment.
- Data lineage/provenance records for sensitive data
- No lineage/provenance tracking for sensitive data
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EDM Council CDMC - Cloud Data Management Capability Framework framework page.