Skip to content

Evidence request lists

EDM Council CDMC - Cloud Data Management Capability Framework

Evidence request list. 14 controls, 14 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CDMC Component 1: Governance and Accountability

CDMC-KC1
Data Control Compliance

The data control compliance of cloud and migrated data is monitored, with compliance to the CDMC Key Controls measured and reported (and the controls automated where possible).

Artefacts an auditor will ask for
  • Evidence that compliance with the data controls is monitored and reported
  • Automation of control monitoring
Where this commonly fails
  • No monitoring of data-control compliance in the cloud
CDMC-KC2
Ownership Field

Ownership is established and an ownership field is populated for all migrated and cloud-generated sensitive data, or the data is automatically flagged for review.

Artefacts an auditor will ask for
  • An ownership field populated for sensitive data assets
  • Process to flag data lacking an owner
Where this commonly fails
  • Sensitive data without an assigned owner
CDMC-KC3
Authoritative Data Sources and Provisioning Points

Sources of authoritative data and the authorised provisioning points are governed and recorded for sensitive data.

Artefacts an auditor will ask for
  • Register of authoritative data sources and provisioning points
Where this commonly fails
  • No governance of authoritative sources / provisioning points
CDMC-KC4
Data Sovereignty and Cross-Border Movement

Data sovereignty and cross-border movement of sensitive data are recorded, auditable and controlled in accordance with defined policy.

Artefacts an auditor will ask for
  • Records of data location and cross-border movement
  • Controls enforcing sovereignty policy
Where this commonly fails
  • Uncontrolled cross-border movement of sensitive data

CDMC Component 2: Cataloguing and Classification

CDMC-KC5
Cataloguing

Cataloguing of sensitive data is automated and the catalogue is maintained as new data is created or ingested in the cloud.

Artefacts an auditor will ask for
  • A data catalogue covering sensitive data, kept current (preferably automated)
Where this commonly fails
  • Sensitive data not catalogued
CDMC-KC6
Classification

Classification of sensitive data is defined and applied (automatically where possible) using a consistent classification scheme covering categories such as PII, regulatory and confidentiality.

Artefacts an auditor will ask for
  • Applied data classification using a defined scheme
  • Automated classification where feasible
Where this commonly fails
  • Unclassified sensitive data

CDMC Component 3: Accessibility and Usage

CDMC-KC7
Entitlements and Access for Sensitive Data

Entitlements and access for sensitive data are managed by default and tracked, ensuring access is granted on a controlled, least-privilege basis.

Artefacts an auditor will ask for
  • Entitlement/access records for sensitive data
  • Default-deny / least-privilege access
Where this commonly fails
  • Uncontrolled access to sensitive data
CDMC-KC8
Data Consumption Purpose

The purpose for which data is consumed is defined and tracked for sensitive data, ensuring use is consistent with the permitted purpose.

Artefacts an auditor will ask for
  • Recorded data consumption purposes for sensitive data
Where this commonly fails
  • Data used beyond its permitted purpose

CDMC Component 4: Protection and Privacy

CDMC-KC10
Data Protection Impact Assessments

Data Protection Impact Assessments are automatically triggered/performed for personal data in accordance with privacy requirements.

Artefacts an auditor will ask for
  • DPIAs for personal-data processing
  • Triggering mechanism for DPIAs
Where this commonly fails
  • Personal data processed without a DPIA where required
CDMC-KC9
Security Controls

Appropriate security controls (including encryption, key management and monitoring) are enabled and evidence of their operation is recorded for sensitive data in the cloud.

Artefacts an auditor will ask for
  • Security controls (encryption, key management, monitoring) applied to sensitive data
  • Evidence of control operation
Where this commonly fails
  • Sensitive cloud data without adequate security controls

CDMC Component 5: Data Lifecycle

CDMC-KC11
Data Retention, Archiving and Purging

Data retention, archiving and purging are managed in accordance with a defined retention schedule for sensitive data.

Artefacts an auditor will ask for
  • Retention schedule and evidence of archiving/purging
  • Automated lifecycle enforcement
Where this commonly fails
  • Indefinite retention / no purging of sensitive data
CDMC-KC12
Data Quality Measurement

Data quality is measured for sensitive data using defined data-quality metrics and the results are monitored.

Artefacts an auditor will ask for
  • Data-quality metrics and measurement results for sensitive data
Where this commonly fails
  • No data-quality measurement

CDMC Component 6: Data and Technical Architecture

CDMC-KC13
Cost Metrics

Cost metrics directly associated with data use, storage and movement are defined and monitored.

Artefacts an auditor will ask for
  • Cost metrics for cloud data use/storage/movement
Where this commonly fails
  • No visibility of data-related cloud cost
CDMC-KC14
Data Lineage

Data lineage information is available, and the provenance and movement of sensitive data can be traced across the cloud environment.

Artefacts an auditor will ask for
  • Data lineage/provenance records for sensitive data
Where this commonly fails
  • No lineage/provenance tracking for sensitive data
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EDM Council CDMC - Cloud Data Management Capability Framework framework page.