Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Data governance and the DAMA-DMBOK framework

Data Governance and the DMBOK: What It Is, and Is Not

Data governance is the discipline organisations reach for after something has already gone wrong — a regulator asks where personal data lives, two departments report different revenue figures, or an AI project stalls because nobody can say whether the training data was permitted.

The reference framework for it is the DAMA-DMBOK, and the most useful thing to understand about that framework is how carefully DAMA defines what it is not.

What the DMBOK is

The DAMA Data Management Body of Knowledge, published by DAMA International, is the globally recognised framework for data management. It sets out the principles, practices and functions needed to build, scale and govern data programmes.

Its own description of itself is precise and worth quoting in substance: a curated and structured subset of knowledge forming the foundation of the discipline, reflecting a consensus view of generally accepted practice, defining the scope and boundaries of the profession while staying flexible enough to evolve.

The second edition expanded coverage of data ethics, updated the data governance content, added material on data integration and interoperability, and increased focus on emerging technologies.

What it deliberately is not

What the DAMA-DMBOK data governance framework is and is not

DAMA publishes an explicit list of boundaries, and every one of them corrects a common misunderstanding.

It is not a prescriptive standard. It names no tools, technologies or methodologies. Organisations adapt the guidance to their own environment — which means a consultant telling you the DMBOK requires a particular platform is describing something else.

It is not a regulation or compliance mandate. It aligns with governance and compliance principles but is not legally binding. You cannot be non-compliant with the DMBOK.

It is not a certification programme. It is the knowledge base behind CDMP certification, but the framework itself certifies nothing — and no organisation is “DMBOK certified”.

It is not exhaustive, and not one-size-fits-all. Organisations must interpret it against their own data challenges, industry and maturity level.

Read together, those boundaries explain why data governance programmes fail in a characteristic way: a team adopts the framework expecting a checklist, finds principles instead, and either invents a checklist of its own or stalls.

The version question

Two developments matter if you are building a programme now.

The DMBOK 2.0 Revision launched in 2024, updating the second edition rather than replacing it.

The DMBOK 3.0 project started in 2025. DAMA describes it as an evergreening initiative to modernise the body of knowledge for a rapidly changing landscape — incorporating emerging disciplines, refining existing knowledge areas, and improving accessibility, developed through global collaboration with practitioners, academics and organisations.

The practical read: build on principles, not on chapter numbers. The knowledge areas are being refined, so a programme whose documentation cross-references specific structure will need rework, while one built on the underlying disciplines will not.

What a data governance programme actually needs

Framework aside, the artefacts are consistent across every implementation that works:

  • A data inventory or catalogue — what data exists, where it lives, who owns it and what it is used for. Everything else depends on this, and its absence is the usual root cause.
  • Named ownership. Data owners and stewards with defined authority, not a RACI nobody has seen.
  • Agreed definitions. A business glossary that settles what “customer” and “active” mean before two reports disagree in public.
  • Data quality measures with thresholds and an owner for remediation.
  • Classification and handling rules, which is where governance meets privacy and security obligations.
  • Lifecycle and retention — creation through to defensible disposal.
  • A decision forum that meets and rules on things, rather than a committee that receives updates.

The last one separates functioning programmes from documented ones. Governance is the authority to decide; without a body that actually decides, you have documentation.

How data governance connects to compliance frameworks

Framework What it needs from you
GDPR Records of processing, purpose limitation, retention and subject rights all assume a maintained inventory. Most GDPR programmes are doing data governance under another name
DPDP Act India’s notice standard and Significant Data Fiduciary duties require knowing precisely what you hold and why
ISO 42001 AI management systems depend on knowing the provenance, permission and quality of training data. Ungoverned data is the most common blocker to an AI programme
ISO 27001 Classification and asset management overlap directly. One inventory should serve both rather than two diverging lists

That table is the strongest argument for doing this properly. Data governance is rarely funded on its own merits — it gets funded because four other programmes each need the same foundation and only one of them has to pay for it.

Where to start

  1. Build the inventory first, for a bounded domain rather than the whole enterprise.
  2. Name owners for that domain, with authority to decide.
  3. Write the glossary entries that are actually contested — not all of them.
  4. Stand up a decision forum and give it something real to rule on in its first meeting.
  5. Measure quality on a few fields that matter, and publish the numbers.
  6. Reuse the inventory for privacy, security and AI obligations rather than letting each build its own.

This guide reflects dama.org at 15 August 2026, on which the DMBOK 2.0 Revision (2024) is current and the DMBOK 3.0 evergreening project is under way.

The Data Governance Toolkit provides 85 DMBOK-aligned editable templates covering the data inventory and catalogue, ownership and stewardship records, the business glossary, data quality measures, classification and retention schedules, and the governance forum artefacts.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.