DAMA CDMP Data Governance Specialist Cheat Sheet

Cheat sheet: exam-prep reference for DAMA International CDMP Governance data governance concepts, roles, controls, artifacts, and decision points.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context
ItemDetail
Vendor/providerDAMA International
Official exam titleDAMA CDMP Data Governance Specialist
Official exam codeCDMP Governance
Page purposeIndependent Cheat Sheet for focused review and practice support

Data governance questions often test whether you can distinguish decision rights, accountability, policy, stewardship, control, and value delivery from the operational work of managing data. Expect scenario-based questions where several answers sound reasonable, but only one best aligns with governance principles.

Core Data Governance Definition

Data governance is the exercise of authority, control, and shared decision-making over data assets. It defines who can make which decisions about data, under what rules, using which processes, with what accountability.

ConceptExam-useful meaning
Data governanceDecision rights, accountability, policy, oversight, and control for data assets
Data managementExecution of practices that plan, build, operate, protect, and improve data assets
Data stewardshipFormal accountability for data definition, quality, usage, and issue resolution
Data ownershipBusiness accountability for data meaning, value, risk, and authorized use
Data custodianshipTechnical responsibility for storage, processing, backup, access enablement, and operations
Data policyHigh-level statement of required behavior or control
Data standardSpecific rule or convention that supports a policy
Data procedureStep-by-step method for performing governance or management work
Data controlMechanism used to prevent, detect, or correct noncompliance, risk, or poor quality

High-Yield Distinctions

DistinctionRemember this
Governance vs managementGovernance decides, directs, prioritizes, and monitors; management executes and operates.
Owner vs stewardOwner has business accountability and decision authority; steward performs ongoing coordination, definition, quality, and issue work.
Policy vs standardPolicy says what must be true; standard says how it must be implemented or measured.
Accountability vs responsibilityAccountability is answerability for outcomes; responsibility is performing assigned work.
Data governance vs data qualityGovernance defines accountability, rules, and escalation; data quality applies profiling, monitoring, remediation, and prevention.
Data governance vs metadata managementGovernance requires trusted definitions and lineage; metadata management captures, manages, and publishes that knowledge.
Data governance vs securityGovernance sets rules for acceptable data use and access accountability; security enforces confidentiality, integrity, and availability controls.
Centralized vs federated governanceCentralized maximizes consistency; federated balances enterprise standards with domain-level ownership.
Compliance vs valueCompliance is one driver; governance also improves trust, reuse, efficiency, analytics, and decision quality.
Committee vs stewardshipCommittees make decisions and resolve escalations; stewards do working-level coordination and control execution.

Data Governance Purpose and Drivers

DriverGovernance response
Regulatory or contractual riskPolicies, controls, accountability, evidence, retention, privacy, auditability
Poor data qualityStewardship, definitions, quality rules, issue workflow, root-cause remediation
Conflicting definitionsBusiness glossary, authoritative definitions, data ownership, metadata standards
Siloed dataEnterprise principles, shared standards, master/reference data governance
Analytics inconsistencyCertified data sources, lineage, semantic consistency, quality thresholds
Digital transformationData product accountability, domain stewardship, platform standards
Mergers or reorganizationData inventory, harmonized definitions, ownership reassignment, migration controls
Security and privacy exposureClassification, access governance, acceptable use, data handling standards

Governance Operating Model Choices

ModelBest fitStrengthsRisks / traps
CentralizedHighly regulated, enterprise-wide standardization neededConsistency, strong policy control, clear escalationCan become slow or disconnected from local business needs
DecentralizedIndependent business units with limited data sharingLocal agility, domain knowledgeInconsistent definitions, duplicate controls, weak enterprise reuse
FederatedMost large enterprises with shared and domain-specific dataBalances enterprise rules with domain ownershipRequires clear decision rights and escalation paths
HybridTransition state or varied maturity across domainsFlexible adoptionCan be ambiguous if roles are not documented
Data-domain alignedCustomer, product, supplier, finance, employee, etc.Assigns accountability by meaning and usageDomains must be defined carefully to avoid overlap
Data-product alignedAnalytics, platform, or mesh-style operating modelsStrong ownership of published data outputsNeeds explicit quality, metadata, and lifecycle obligations
Notes and examples

Governance operating model

A data governance operating model defines how governance work is organized and performed.

Common components

ComponentPurpose
SponsorshipProvides authority, funding, priority, and executive support
Governance council or boardMakes cross-functional decisions, resolves escalations, approves policies and priorities
Data ownersHold business accountability for data domains or critical data elements
Data stewardsSupport definition, quality, metadata, issue management, and policy adoption
Data custodiansImplement and operate technical controls and platforms
Working groupsAddress domain-specific issues, standards, definitions, and improvement plans
Policies and standardsDefine required behavior and consistent expectations
ProcessesProvide repeatable workflows for issues, changes, access, definitions, and exceptions
MetricsTrack adoption, performance, quality, compliance, and value

Centralized, decentralized, and federated models

ModelDescriptionStrengthWeakness
CentralizedA central team owns most governance decisions and standardsConsistency and controlMay be slow or disconnected from business context
DecentralizedBusiness units govern data independentlyLocal responsivenessInconsistent definitions, controls, and priorities
FederatedEnterprise standards with domain-level participation and accountabilityBalances consistency and local expertiseRequires clear roles, escalation, and coordination

For many enterprise scenarios, a federated model is often the best-fit concept because it recognizes that data is used across the enterprise but understood deeply by business domains.

Common operating model trap

A governance council should not be treated as the team that personally fixes every data problem. Its role is to prioritize, decide, assign accountability, remove barriers, and monitor outcomes.

Governance Role Reference

RolePrimary accountabilityCommon exam clues
Executive sponsorAuthority, funding, strategic alignment, issue escalationRemoves barriers; connects governance to business objectives
Data governance council / boardApproves policies, priorities, standards, and escalated decisionsCross-functional decision-making body
Chief data officer / data leaderEnterprise data strategy, governance program leadership, value realizationAligns governance with data management capabilities
Data ownerBusiness accountability for a data domain or critical data elementApproves definitions, quality expectations, and access rules
Data stewardOperational coordination of definitions, quality, issues, metadata, and standardsMaintains glossary entries, raises issues, supports controls
Data custodianTechnical operations and control implementationDatabase/platform/file/storage administration
Data architectData models, integration patterns, standards alignmentEnsures structure supports enterprise principles
Data quality analystProfiling, rules, monitoring, defect analysisMeasures and reports data quality
Security/privacy officerClassification, access, privacy, risk controlsEnsures protection and compliant handling
Business process ownerProcess-level data creation and usage accountabilityImportant when root cause is process behavior
Project/product teamImplements governance requirements in change deliveryMust follow standards, metadata, and control requirements
Notes and examples

Role review table

RoleMain responsibilityStrong exam clue
Executive sponsorProvides mandate, funding, visibility, and authorityLack of adoption or cross-functional support
Chief Data Officer or equivalent leadership roleLeads enterprise data strategy and governance capabilityNeed for enterprise coordination and value realization
Data governance councilApproves policies, resolves conflicts, sets prioritiesCross-domain decision or escalation
Data ownerBusiness accountability for data domain, definition, quality expectations, and use“Who is accountable?”
Data stewardDay-to-day support for data definitions, quality issues, metadata, and standards“Who coordinates definitions or monitors quality?”
Data custodianTechnical implementation and care of data assetsStorage, backup, security configuration, system operation
Data user/consumerUses data appropriately according to policy and business needReporting, analytics, operational usage
Data producerCreates or captures dataUpstream quality defects and process controls
Risk, legal, privacy, complianceInterprets obligations and controlsRegulatory, retention, privacy, audit issues
IT/securityImplements platforms, access controls, and technical safeguardsTechnical enablement and control enforcement

RACI thinking

Questions may describe a governance activity and ask who should be responsible or accountable. Use this logic:

ActivityUsually accountableUsually responsible/supporting
Approving enterprise data policyGovernance council/executive authorityData governance team, legal, compliance, security
Defining business meaning of a critical data elementData ownerData steward, subject matter experts
Maintaining metadata in a repositoryStewardship/data management functionCustodians, data architects, tool administrators
Implementing access control in a systemIT/security custodianData owner approves, security advises
Resolving conflict between business unitsGovernance council or escalation authorityData owners, stewards, governance office
Monitoring data quality metricsData steward/data quality teamData owner accountable for outcomes
Approving exception to policyDefined governance authorityRisk, compliance, legal, business owner

RACI Pattern for Common Governance Activities

ActivityExecutive sponsorGovernance councilData ownerData stewardCustodian / ITSecurity / privacy
Approve enterprise data policyARCCCC
Define critical data elementCCARCC
Approve business definitionCCARCC
Implement access controlCCA/CCRA/R
Resolve cross-domain definition conflictCA/RRRCC
Monitor data quality ruleIIARR/CC
Remediate root cause in business processCCA/RR/CCC
Maintain technical metadataIICCA/RC
Approve retention requirementCCA/CCR/CA/R
Report governance metricsIAR/CRCC
Notes and examples

Legend: A = accountable, R = responsible, C = consulted, I = informed. Exact assignments vary by organization; exam questions usually test accountability logic, not one fixed chart.

Key Governance Artifacts

ArtifactPurposeCommon contents
Data governance charterEstablishes mandate, scope, authority, and objectivesVision, goals, principles, roles, decision rights, governance bodies
Data policyDefines required behavior for data handling or managementOwnership, quality, access, classification, retention, metadata, usage
Data standardsTranslate policy into implementable rulesNaming, modeling, quality thresholds, metadata fields, code sets
Data governance roadmapSequences capability buildoutInitiatives, dependencies, milestones, maturity targets
Data domain modelDefines major subject areas of accountabilityCustomer, product, supplier, employee, location, financial data
Data ownership matrixAssigns accountable owners and stewardsDomain, owner, steward, systems, critical elements
Business glossaryShared business terms and definitionsTerm, definition, owner, steward, synonyms, usage notes
Data catalogInventory and searchable metadata repositoryDatasets, lineage, classification, quality indicators, owners
Critical data element listFocuses control on high-value or high-risk dataName, definition, source, owner, quality rules, controls
Data quality rulesDefines measurable expectationsCompleteness, validity, consistency, accuracy, timeliness, uniqueness
Issue logTracks defects, decisions, and remediationIssue, severity, owner, root cause, action, status
Decision logPreserves governance decisions and rationaleDecision, date, participants, impact, policy reference
Data lineage mapShows origin, movement, transformation, and usageSource-to-target flows, transformations, reports, controls
Data classification schemeCategorizes sensitivity, risk, and handling needsPublic/internal/confidential/restricted or equivalent levels
Control evidenceDemonstrates that governance controls operateApprovals, reviews, audit logs, attestations, metrics

Data Governance Process Reference

PhaseKey actionsOutputs
InitiateIdentify drivers, sponsorship, scope, pain points, stakeholdersCharter, business case, initial scope
AssessEvaluate maturity, risks, data issues, existing controlsCurrent-state assessment, gap analysis
DesignDefine operating model, roles, policies, decision rightsGovernance framework, role model, policy set
PrioritizeSelect domains, critical data, initiatives, and metricsRoadmap, backlog, domain priorities
ImplementEstablish stewardship, standards, catalog/glossary, workflowsWorking committees, artifacts, tools, controls
OperateRun issue management, approvals, monitoring, escalationDecisions, issue resolution, metrics
MonitorMeasure adoption, quality, compliance, and valueDashboards, control evidence, maturity updates
ImproveRefine policies, automate controls, expand coverageLessons learned, enhanced standards, new capabilities

Governance Decision Rights

Decision typeTypical decision ownerExample
Policy decisionGovernance council or executive authorityApprove enterprise data classification policy
Domain decisionData owner with steward supportDefine “active customer” for the customer domain
Standards decisionGovernance function, architecture, or councilAdopt naming standard for data elements
Quality decisionData owner, steward, quality leadSet acceptable completeness threshold for a critical field
Access decisionData owner with security/privacy inputApprove access to confidential customer data
Architecture decisionData architecture / architecture boardSelect authoritative source pattern
Exception decisionGovernance council or delegated authorityTemporarily allow nonstandard interface with compensating control
Escalation decisionHigher governance bodyResolve conflicting definitions across business units

Policy, Standard, Procedure, and Guideline

Document typeAuthority levelExampleExam trap
PolicyMandatory, high-level“Customer personal data must be classified and protected.”Do not confuse with step-by-step instructions.
StandardMandatory, specific“Customer ID must be numeric and unique across source systems.”More precise than policy.
ProcedureMandatory process steps“To request access, submit request, obtain owner approval, log ticket.”Operationalizes policy/standard.
GuidelineRecommended practice“Use plain-language business definitions where possible.”Usually advisory unless adopted as required.
PrincipleStable design belief“Data is an enterprise asset.”Guides decisions but may need policies to enforce.
Notes and examples

Policies, standards, procedures, and guidelines

The exam may test whether you understand the hierarchy of governance artifacts.

ArtifactMeaningExample
PolicyMandatory high-level ruleCustomer personal data must be protected according to approved privacy and security requirements
StandardSpecific mandatory requirement supporting policyCustomer identifiers must follow an approved format and naming standard
ProcedureStep-by-step processSteps to request access to restricted customer data
GuidelineRecommended practicePreferred naming convention examples for analytics datasets
ControlMechanism to enforce or monitor requirementsApproval workflow, access review, quality threshold, audit log

Decision rule

If the scenario involves a broad requirement that applies across the organization, choose policy. If it involves detailed uniform implementation requirements, choose standard. If it involves how to perform a task, choose procedure.

Governance Domains and What to Control

AreaGovernance focusTypical controls
Data architectureAlignment of data structures with business needsArchitecture review, modeling standards, authoritative source rules
Data modeling and designConsistent representation of business conceptsNaming conventions, model review, definition approval
Data storage and operationsReliable, secure, recoverable data platformsBackup, recovery, access, retention, operational controls
Data securityAuthorized and appropriate accessClassification, role-based access, least privilege, monitoring
Data integrationControlled data movement and transformationInterface standards, lineage, reconciliation, transformation rules
Document and content managementGovernance of unstructured/semi-structured dataRetention, classification, versioning, legal hold support
Reference and master dataShared, consistent core entities and code setsGolden record rules, survivorship, stewardship workflows
Data warehousing and BITrusted reporting and analyticsCertified metrics, semantic standards, report lineage
MetadataMeaning, context, lineage, and usage knowledgeGlossary, catalog, required metadata fields, ownership
Data qualityFitness for purposeQuality rules, profiling, scorecards, remediation workflow
Data ethicsAppropriate and responsible useUsage review, fairness considerations, transparency, accountability

Critical Data Elements

Critical data elements are data elements important enough to require explicit governance because they affect business decisions, risk, operations, reporting, compliance, or customer outcomes.

Selection criterionExample question
Regulatory or audit impactIs this element used in required reporting or evidence?
Financial impactDoes an error affect revenue, cost, reserves, or valuation?
Customer or stakeholder impactCould poor data harm customers or service delivery?
Operational dependencyDo key processes fail if this data is wrong or late?
Cross-system reuseIs this element shared across many systems or reports?
Executive reportingDoes leadership use this value for decisions?
Privacy/security sensitivityDoes it identify, classify, or expose a person, account, or asset?
Notes and examples

Critical data elements

A critical data element is a data element important enough to require special governance attention because it affects business operations, reporting, risk, regulatory obligations, customer experience, or strategic decisions.

What governance does for critical data elements

Governance actionPurpose
Identify and prioritizeFocus effort where risk or value is highest
Assign ownership and stewardshipEnsure accountability
Define business meaningReduce ambiguity
Document lineageUnderstand origin, transformation, and downstream use
Set quality rulesEstablish measurable expectations
Monitor qualityDetect and trend issues
Manage changesPrevent unintended downstream impact
Control access and useProtect sensitive or regulated data

Common trap

Not all data should receive the same governance intensity. Effective governance is risk-based and value-based. Applying heavy controls to every data element can create unnecessary cost and resistance.

Data Stewardship Reference

Stewardship typeFocusTypical responsibilities
Business data stewardMeaning and business useDefinitions, quality expectations, issue triage, business rules
Technical data stewardTechnical metadata and implementation supportSource mappings, lineage, data structures, transformation details
Domain stewardA subject area such as customer or productCross-application consistency and domain issue resolution
Project stewardGovernance compliance in a projectEnsures new/change work follows standards
Operational stewardDay-to-day data process supportMonitors queues, validates corrections, supports remediation
Enterprise stewardCross-domain alignmentHarmonizes definitions and escalates conflicts
Notes and examples

Data stewardship

Data stewardship is a key enabling function within governance. Stewards help ensure data is defined, understood, controlled, and improved.

Stewardship activities

  • Develop and maintain business definitions
  • Support data classification
  • Identify critical data elements
  • Document metadata and lineage
  • Monitor data quality rules and metrics
  • Coordinate issue investigation and remediation
  • Support data access and usage decisions
  • Facilitate alignment across business and technical teams
  • Promote policy and standard adoption

Types of stewards

Steward typeFocus
Business data stewardBusiness meaning, usage, rules, and quality expectations
Technical data stewardTechnical metadata, lineage, data structures, and system implementation
Domain data stewardData within a business domain, such as customer, product, supplier, or finance
Enterprise data stewardCross-domain consistency, enterprise standards, and coordination
Data quality stewardQuality rules, monitoring, issue tracking, and remediation support

Stewardship trap

Stewardship is not just documentation. It is an accountability-support role that connects business meaning, operational processes, quality control, and governance decisions.

Data Quality Dimensions

DimensionMeaningExample control
AccuracyCorrectly represents real-world valueValidate address against trusted source
CompletenessRequired values are presentRequired fields populated for critical records
ConsistencySame value agrees across systems or contextsCustomer status matches master data
TimelinessAvailable and current when neededDaily feed received before reporting cutoff
ValidityConforms to format, domain, or ruleDate is valid; code exists in reference table
UniquenessNo inappropriate duplicationOne active customer master record per entity
IntegrityRelationships are valid and preservedOrder references existing customer
ReasonablenessValue is plausible in contextBirth date is not in the future
ConformityFollows required representationCountry code uses approved standard
Notes and examples

Data quality governance

Data quality is a frequent data governance topic because governance defines who is accountable for quality, what “fit for purpose” means, and how quality issues are escalated.

Common data quality dimensions

DimensionQuestion it answers
AccuracyDoes the data correctly represent the real-world object or event?
CompletenessAre required values present?
ConsistencyDoes data agree across systems or records?
TimelinessIs data available and current when needed?
ValidityDoes data conform to rules, formats, or allowed values?
UniquenessAre duplicates controlled?
IntegrityAre relationships valid and preserved?
ConformityDoes data follow approved standards?
ReasonablenessAre values plausible within business expectations?

Quality governance workflow

  1. Identify critical data and business impact.
  2. Define quality rules and thresholds.
  3. Assign owner and steward accountability.
  4. Profile and measure data.
  5. Record issues and root causes.
  6. Prioritize remediation by risk and value.
  7. Implement process or system controls.
  8. Monitor trends and report to governance bodies.

Quality trap

Fixing bad data downstream is usually less effective than addressing root causes at creation, capture, integration, or process handoff. In scenario questions, prefer answers that prevent recurrence rather than merely cleansing symptoms.

Data Quality Governance Workflow

    flowchart TD
	    A[Profile or monitor data] --> B{Issue detected?}
	    B -- No --> C[Continue monitoring]
	    B -- Yes --> D[Log issue and assign steward]
	    D --> E[Assess severity and business impact]
	    E --> F[Identify root cause]
	    F --> G{Root cause type}
	    G --> H[Source process correction]
	    G --> I[System or integration fix]
	    G --> J[Definition or rule clarification]
	    H --> K[Implement remediation]
	    I --> K
	    J --> K
	    K --> L[Validate fix]
	    L --> M[Update metadata, rules, controls]
	    M --> N[Report metric and close]

Data Quality Issue Triage

If the issue is…Likely response
Isolated bad recordCorrect record, log cause if material
Recurring defectRoot-cause analysis and process/system remediation
Conflicting definitionsEscalate to owner/council for semantic decision
Missing ownershipAssign owner/steward before defining remediation
Unclear business ruleDocument and approve rule before implementing validation
Technical mapping errorFix transformation, update lineage and mapping metadata
Source process errorChange process, training, input controls, or upstream validation
Access-related correction delayReview permissions and workflow accountability

Metadata and Glossary Governance

AssetGovernance purposeKey exam clues
Business glossaryShared business languageTerms, definitions, owners, synonyms, policies
Technical metadataPhysical implementation detailsTables, columns, data types, jobs, schemas
Operational metadataProcessing and runtime informationLoad times, job status, volumes, errors
Lineage metadataMovement and transformation visibilitySource-to-target path, transformations, downstream usage
Usage metadataHow data is consumedReports, queries, users, frequency
Classification metadataRisk and handling requirementsSensitivity level, privacy category, retention class
Quality metadataTrust indicatorsQuality rules, scores, exceptions, thresholds
Notes and examples

Metadata governance

Metadata is data about data. Governance uses metadata to create shared understanding, traceability, and control.

Metadata types

Metadata typeExamplesGovernance value
Business metadataDefinitions, business rules, owners, classificationsCommon meaning and accountability
Technical metadataTable names, columns, data types, mappings, interfacesImplementation transparency
Operational metadataBatch runs, job status, usage, refresh time, error logsMonitoring and service management
Process metadataWorkflow steps, approvals, lifecycle statusGovernance process control
Lineage metadataSource-to-target flow, transformations, dependenciesImpact analysis and trust

High-yield metadata concepts

  • A business glossary supports shared meaning.
  • A data catalog helps users discover and understand data assets.
  • Lineage supports impact analysis, auditability, quality investigation, and trust.
  • Metadata quality matters; a stale catalog can reduce confidence.
  • Governance defines metadata standards, ownership, required fields, and maintenance processes.

Metadata trap

A tool does not create governance by itself. A catalog or glossary only works when roles, processes, standards, and accountability are in place.

Master and Reference Data Governance

ConceptGovernance focusCommon decision points
Master dataCore business entities shared across processesCustomer, product, supplier, employee, location
Reference dataPermitted values or code setsCountry codes, status codes, product categories
Golden recordBest representation of an entitySurvivorship rules, matching, stewardship approval
System of recordAuthoritative system for a data element or processOwnership, integration, lineage
System of referenceTrusted source for lookup or reporting usePublication and synchronization rules
Match/mergeIdentifies duplicates and combines recordsThresholds, false positives, manual review
SurvivorshipSelects winning values from sourcesSource priority, recency, completeness
Hierarchy governanceManages parent-child relationshipsApproval, versioning, effective dating
Notes and examples

Reference data and master data governance

Reference data and master data frequently require strong governance because they are reused across systems and business processes.

Reference data

Reference data consists of permissible values used to classify or categorize other data.

Examples:

  • Country codes
  • Currency codes
  • Product categories
  • Status codes
  • Business unit codes

Governance focus:

  • Approved value lists
  • Change control
  • Authoritative sources
  • Versioning
  • Consistency across systems

Master data

Master data represents core business entities shared across processes.

  • Customer

  • Product

  • Supplier

  • Employee

  • Location

  • Account

  • Authoritative source or system of record

  • Survivorship rules

  • Duplicate management

  • Identity resolution

  • Business definitions

  • Cross-functional ownership

  • Data quality monitoring

Exam trap

A master data program is not just a technology implementation. Master data success depends on governance: ownership, standards, definitions, matching rules, stewardship, change management, and issue resolution.

Data Classification and Handling

Classification concernGovernance action
SensitivityDefine classification levels and required handling
PrivacyIdentify personal, confidential, or restricted attributes
AccessRequire owner approval and role-appropriate permissions
RetentionDefine how long data is kept and when disposed
UsageSpecify approved and prohibited uses
SharingControl internal/external transfer conditions
Masking or de-identificationApply when lower-risk use is needed
AuditabilityRetain evidence of approvals and access changes
Third-party useDefine contractual and control expectations

Risk, Compliance, and Control Reference

Governance riskPreventive controlDetective controlCorrective control
Unauthorized accessClassification, approval workflow, least privilegeAccess review, audit logsRevoke access, remediate exposure
Inconsistent reportingCertified metrics, glossary, semantic layer standardsReconciliation, report inventory reviewRetire duplicate reports, align definitions
Poor data qualityInput validation, stewardship, source controlsProfiling, scorecards, exception reportsRoot-cause remediation, data correction
Uncontrolled data changeChange management, model reviewLineage impact analysis, change auditRollback, update mappings, communicate changes
Unknown data ownershipOwnership matrix, domain modelOwnership gap assessmentAssign owner/steward and document accountability
Excessive retentionRetention schedule, lifecycle controlsStorage review, aging reportsDispose/archive according to policy
Unapproved data sharingSharing standards, contract reviewData transfer monitoringStop transfer, remediate, update controls
Metadata decayRequired metadata workflowCatalog completeness metricsSteward review and metadata refresh

Governance Metrics

Metric categoryExample measuresWhat it indicates
AdoptionNumber of governed domains, assigned owners, trained stewardsProgram rollout and coverage
Policy compliancePercentage of datasets with classification, access review completionControl effectiveness
Metadata completenessRequired catalog fields populated, glossary approval statusDiscoverability and accountability
Data qualityDefect rate, rule pass rate, issue aging, recurrence rateFitness for purpose and remediation success
Issue managementOpen issues, severity, time to resolution, escalation countOperational governance performance
ValueReduced rework, improved reporting cycle time, fewer reconciliationsBusiness benefit
Risk reductionFewer unauthorized access exceptions, improved audit findingsControl and compliance impact
Stewardship effectivenessSteward participation, decisions completed, backlog trendOperating model health
Notes and examples

Data governance metrics

Metrics show whether governance is adopted, effective, and valuable. Avoid relying only on activity metrics; include outcome and value measures.

Metric categories

CategoryExamplesWhat it tells you
AdoptionNumber of governed domains, steward participation, policy acknowledgmentWhether governance is being used
Data qualityDefect rates, completeness, duplicate rate, rule pass rateWhether data is improving
Issue managementOpen issues, aging, resolution time, recurrenceWhether problems are being controlled
MetadataCatalog coverage, glossary completeness, lineage availabilityWhether data is understandable
Access and complianceAccess review completion, exceptions, audit findingsWhether controls are working
Business valueReduced rework, faster reporting, fewer reconciliations, improved decision confidenceWhether governance supports outcomes
MaturityCapability assessment results over timeWhether the program is improving

Metric trap

Counting meetings, policies, or stewards does not prove governance effectiveness. Prefer metrics linked to reduced risk, improved quality, better decisions, adoption, and measurable business outcomes.

Maturity Model Thinking

Maturity levelCharacteristicsGovernance priority
Ad hocInformal ownership, inconsistent definitions, reactive fixesEstablish sponsorship, scope, basic ownership
RepeatableSome policies and stewards, inconsistent executionStandardize processes and decision rights
DefinedDocumented framework, domains, policies, workflowsExpand coverage and integrate with projects
ManagedMetrics, controls, monitoring, formal escalationImprove effectiveness and automate evidence
OptimizedContinuous improvement, embedded governance, measurable valueOptimize value, reduce friction, adapt to change

Do not assume maturity is only about tools. Higher maturity means governance is embedded in decisions, processes, controls, and culture.

Implementation Roadmap Pattern

StepPractical focusAvoid this trap
1. Confirm business driversTie governance to risk, value, quality, or strategyStarting with a tool selection
2. Secure sponsorshipObtain authority for decisions and conflict resolutionTreating governance as a data team-only activity
3. Define scopeChoose domains, data elements, and use casesTrying to govern all data equally on day one
4. Assign rolesName owners, stewards, councils, custodiansAssigning responsibility without authority
5. Establish policiesCreate clear, enforceable expectationsWriting policies that no process can execute
6. Build artifactsGlossary, catalog, quality rules, issue logCreating documentation with no owner
7. Embed in processesProjects, access, change, quality, reportingRunning governance as a separate meeting-only function
8. Measure and improveUse metrics and feedback loopsMeasuring activity only, not outcomes

Decision Matrix: What Governance Mechanism Fits?

SituationBest mechanism
Business units disagree on a termData owner/steward analysis, council decision, glossary update
A dataset has unknown sensitivityClassification standard and owner review
Report numbers do not matchCertified metric definition, lineage, reconciliation, quality rules
New project creates a shared data fieldArchitecture/model review, definition approval, metadata capture
Analysts cannot find trusted dataData catalog, glossary, certified sources, ownership metadata
Access requests are inconsistentAccess policy, owner approval workflow, periodic access review
Duplicate customer records occurMaster data governance, match/merge rules, stewardship queue
Code values differ across systemsReference data governance and synchronization process
Data quality fixes do not lastRoot-cause remediation and source process controls
Data governance has low engagementLink scope to business pain, clarify authority, show metrics

Governance in Change Delivery

Delivery activityGovernance requirement
Business requirementsIdentify data owners, critical data, definitions, quality needs
Solution designApply architecture, integration, metadata, and security standards
Data modelingReview naming, definitions, relationships, and authoritative sources
Data migrationDefine mapping, profiling, cleansing, reconciliation, and signoff
IntegrationDocument lineage, transformation rules, controls, and monitoring
TestingInclude data quality, access, privacy, and reconciliation tests
DeploymentEnsure catalog/glossary updates and operational ownership
Post-implementationMonitor quality, issues, adoption, and control effectiveness

Common Governance Anti-Patterns

Anti-patternWhy it failsBetter approach
“Buy a catalog and call it governance”Tools do not create authority or accountabilityDefine operating model, roles, policies, and workflows first
Govern everything equallyResources are dilutedPrioritize critical data and high-value domains
IT-only ownershipBusiness meaning and accountability are missingAssign business owners and stewards
Committee with no decision rightsMeetings produce discussion, not controlDocument authority, escalation, and decision scope
Policy without enforcementBehavior does not changeAttach controls, procedures, metrics, and consequences
Stewardship as a side job onlyWork is under-resourcedDefine expectations, time allocation, and management support
Metrics only on activityBusy work may not create valueInclude quality, risk, cycle time, adoption, and business impact
Ignoring cultureUsers bypass controlsCommunicate value and embed governance into normal work

High-Yield Scenario Cues

Scenario wordingLikely exam direction
“Who is accountable for the meaning of the data?”Data owner, supported by steward
“Who maintains definitions and coordinates issue resolution?”Data steward
“Who implements database access controls?”Custodian / technical team, under policy and approval rules
“Conflicting definitions across business units”Governance council or cross-domain decision process
“Need trusted reporting metrics”Glossary, certified definitions, lineage, quality controls
“Repeated downstream defects”Root-cause analysis at source process, not only downstream cleansing
“No one knows where data comes from”Metadata and lineage management
“Sensitive data used for analytics”Classification, access control, privacy review, approved use
“Duplicate master records”Master data governance and stewardship workflow
“Governance program lacks authority”Executive sponsorship and charter

Data Governance Principles

PrinciplePractical implication
Data is an enterprise assetManage data for shared value, not only local application needs
Accountability must be explicitAssign named owners/stewards and decision rights
Governance should be risk- and value-basedFocus strongest controls on critical, shared, sensitive, or high-impact data
Business and IT share responsibilitiesBusiness owns meaning and value; IT enables technical management and controls
Definitions should be standardized where sharedAvoid conflicting metrics and semantic ambiguity
Quality must be measured against useFitness for purpose depends on business context
Metadata is a governance enablerYou cannot govern what you cannot find, define, or trace
Governance must be embeddedControls should fit projects, operations, analytics, and access processes
Exceptions must be managedTemporary deviations need approval, rationale, risk acceptance, and review
Continuous improvement mattersGovernance matures through feedback, metrics, and adaptation

Cheat Sheet Checklist

Before exam practice, make sure you can answer:

  • Who makes data decisions, who executes them, and who is accountable for outcomes?
  • How do policy, standard, procedure, control, and metric differ?
  • When should a governance council be used instead of a steward or owner?
  • How do data quality, metadata, master data, security, and architecture connect to governance?
  • What artifacts prove that governance is operating, not just documented?
  • How should governance prioritize domains, data elements, and issues?
  • What does a federated model solve, and what ambiguity can it create?
  • Why is root-cause remediation better than repeated downstream correction?
  • How do classification, access approval, retention, and usage rules reduce risk?
  • Which metrics show adoption, effectiveness, value, and control performance?
Notes and examples

Rapid review checklist

Before taking a practice set, confirm that you can explain:

  • What data governance is and why it matters
  • How governance differs from data management
  • How owners, stewards, custodians, sponsors, and councils interact
  • Why executive sponsorship is important
  • How policies, standards, procedures, guidelines, and controls differ
  • How critical data elements are identified and governed
  • How governance supports data quality improvement
  • Why metadata, glossary, catalog, and lineage matter
  • How classification influences access, privacy, security, retention, and use
  • How governance applies to master and reference data
  • How issue management and escalation should work
  • How governance metrics should show adoption, risk reduction, quality improvement, and value
  • Why change management and communication are essential
  • How to choose proportionate governance based on risk and value

Final Exam-Prep Next Step

Use this Cheat Sheet to build scenario drills: for each practice question, identify the data asset, decision right, accountable role, governing artifact, control, and escalation path before selecting an answer. Then continue with targeted CDMP Governance practice questions focused on roles, operating models, stewardship, data quality, metadata, policy, and risk scenarios.

Core idea: what data governance is

Data governance is the system of authority, accountability, policies, decision rights, controls, and oversight that enables an organization to manage data as an asset.

It answers questions such as:

  • Who has authority to define, approve, change, or retire data rules?
  • Who is accountable for data quality, meaning, access, retention, and use?
  • Which policies and standards apply across business units?
  • How are conflicts resolved when stakeholders disagree?
  • How is compliance, risk reduction, and business value measured?
  • How do data management practices align with organizational strategy?
Notes and examples

Governance versus management

ConceptPrimary focusTypical activitiesExam trap
Data governanceDecision rights, accountability, oversightApproving policies, assigning stewardship, resolving cross-functional issues, setting standardsConfusing governance with hands-on technical data work
Data managementExecution and operationProfiling data, building data models, maintaining metadata repositories, configuring toolsTreating operational tasks as the governance body’s main job
Data stewardshipAccountable care of data on behalf of the organizationDefining terms, reviewing quality issues, supporting policy adoptionAssuming stewards “own” all data or replace business accountability
Data ownership/accountabilityBusiness responsibility for data meaning, use, and riskApproving definitions, access rules, quality expectationsAssuming IT is the default owner because it stores data
Data custodianshipTechnical care and safeguardingStorage, backups, access implementation, platform operationsConfusing custody with business ownership

A useful exam decision rule:

If the question is about who decides, who is accountable, what policy applies, or how conflicts are escalated, think data governance. If the question is about how work is technically performed, think data management execution.

High-yield governance objectives

Data governance exists to improve business outcomes, not to create bureaucracy. Common objectives include:

ObjectiveWhat it means in exam scenarios
Strategic alignmentData priorities support business strategy, regulatory obligations, and enterprise goals
AccountabilityNamed roles are responsible for definitions, quality, access, compliance, and issue resolution
ConsistencyShared policies, standards, definitions, and decision processes reduce local variation
Risk managementData risks are identified, controlled, monitored, and escalated
Data quality improvementQuality expectations are defined, measured, and acted on
Regulatory and policy complianceData handling supports privacy, security, retention, audit, and legal obligations
Value realizationGovernance enables better analytics, operations, customer experience, and decision-making
TransparencyStakeholders can understand data meaning, lineage, quality, and permitted use

Data governance and the DAMA knowledge areas

Data governance interacts with every major data management discipline. A specialist-level candidate should understand the relationships.

Data management areaGovernance connection
Data architectureGovernance sets principles and standards for data structures, integration, and enterprise alignment
Data modeling and designGovernance supports naming, definitions, relationships, and modeling standards
Data storage and operationsGovernance defines retention, protection, availability, and operational expectations
Data securityGovernance defines access accountability, classification, acceptable use, and control expectations
Data integration and interoperabilityGovernance promotes shared definitions, lineage, interface standards, and data movement controls
Documents and contentGovernance addresses unstructured data, records, retention, classification, and ownership
Reference and master dataGovernance defines authoritative sources, stewardship, quality, and change control
Data warehousing and business intelligenceGovernance supports trusted metrics, semantic consistency, lineage, and report certification
MetadataGovernance requires business, technical, and operational metadata for transparency
Data qualityGovernance defines dimensions, thresholds, accountability, measurement, and remediation
Big data and analyticsGovernance addresses ethical use, model risk, lineage, privacy, quality, and reproducibility

Data classification, access, privacy, and security

Data governance and data security are closely connected. Governance defines expectations and accountability; security implements and monitors technical controls.

Classification review

Classification conceptGovernance purpose
Public, internal, confidential, restricted, or similar levelsMatch protection to sensitivity and risk
Personal data or sensitive personal dataTrigger privacy, consent, access, and minimization considerations
Financial, health, legal, or regulated dataIdentify special handling and audit needs
Intellectual propertyProtect business value and competitive advantage
Retention categoryControl how long data is kept and when it is disposed
Notes and examples

Access governance principles

PrincipleMeaning
Least privilegeUsers receive only the access needed for approved work
Need to knowAccess is tied to legitimate business purpose
Segregation of dutiesAvoid conflicting access that increases fraud or misuse risk
Approval accountabilityBusiness owners approve access based on data sensitivity and use
Periodic reviewAccess rights are reviewed and recertified
AuditabilityAccess decisions and activity can be traced

Privacy and ethical use

Governance should address:

  • Purpose limitation
  • Appropriate access
  • Data minimization
  • Consent or permitted use where applicable
  • Retention and disposal
  • Transparency
  • Protection of sensitive data
  • Ethical analytics and responsible data use

Security trap

Do not choose an answer that makes IT solely responsible for data access decisions. IT often implements access, but business accountability and governance-approved policies determine who should have access and why.

Data lifecycle governance

Data governance should cover the full data lifecycle.

Lifecycle stageGovernance concerns
PlanBusiness purpose, accountability, standards, risk assessment
Create/captureQuality at source, validation, metadata, consent or permitted use
StoreSecurity, classification, retention, backup, availability
Use/shareAccess, usage rights, interpretation, quality, lineage
Integrate/transformMapping, reconciliation, lineage, control checks
ArchiveRetention, retrieval, legal hold, cost management
DisposeSecure deletion, defensible disposal, audit evidence

Lifecycle trap

Retention and disposal are governance issues, not merely storage issues. Keeping data indefinitely can increase cost, risk, and compliance exposure.

Governance processes candidates should recognize

Common processes

ProcessPurposeKey outputs
Policy managementCreate, approve, communicate, and maintain policiesApproved policies, standards, exception rules
Data issue managementCapture, prioritize, assign, resolve, and monitor issuesIssue log, root cause, remediation plan
Data definition managementEstablish and maintain approved business termsGlossary entries, definitions, synonyms
Data quality managementDefine, measure, monitor, and improve qualityRules, scorecards, thresholds, trends
Data access managementApprove and review data accessAccess approvals, recertification evidence
Data classificationIdentify sensitivity and handling needsClassification labels, protection requirements
Metadata managementCapture and maintain metadataCatalog, lineage, ownership, technical mappings
Change managementAssess and control changes to data, definitions, systems, or reportsImpact assessment, approvals, communication
Exception managementAllow controlled deviation from policyRisk acceptance, expiration, approval record
Maturity assessmentEvaluate governance capability and improvement roadmapMaturity scores, gaps, action plan
Notes and examples

Issue escalation path

    flowchart TD
	    A[Data issue identified] --> B[Log issue with impact and evidence]
	    B --> C{Can domain steward resolve?}
	    C -- Yes --> D[Assign fix and monitor outcome]
	    C -- No --> E[Escalate to data owner]
	    E --> F{Cross-domain conflict or policy decision?}
	    F -- No --> D
	    F -- Yes --> G[Governance council decision]
	    G --> H[Implement remediation or policy change]
	    H --> I[Measure and report results]

Maturity and implementation

Data governance programs usually evolve over time. A maturity assessment helps identify current capability, target state, gaps, and roadmap priorities.

Typical maturity progression

StageCharacteristics
Ad hocInconsistent definitions, unclear ownership, reactive issue handling
RepeatableSome local processes and stewards exist, but enterprise alignment is limited
DefinedPolicies, roles, standards, and processes are documented and communicated
ManagedMetrics, controls, escalation, and monitoring are active
OptimizedContinuous improvement, automation, enterprise adoption, measurable value
Notes and examples

Do not assume every organization should immediately pursue maximum maturity in every area. A better answer usually aligns maturity goals with business strategy, risk, regulatory needs, and value.

Implementation success factors

  • Executive sponsorship
  • Clear business case
  • Prioritized scope
  • Defined decision rights
  • Practical policies and standards
  • Business participation
  • Stewardship network
  • Communication and training
  • Tooling that supports—not replaces—process
  • Metrics and continuous improvement
  • Change management and adoption planning

Implementation trap

A “big bang” enterprise rollout without prioritization, sponsorship, and adoption planning is usually risky. Exam scenarios often favor starting with high-value or high-risk domains, demonstrating results, and scaling.

Governance decision rules for exam scenarios

Use these rules when answer choices are close.

Scenario clueStrong answer direction
Multiple departments define the same term differentlyEstablish approved business definition through governance/stewardship
Data quality defects recurIdentify root cause and assign accountable owner; improve process controls
Users cannot trust reportsAddress lineage, definitions, quality rules, certification, and ownership
Sensitive data is broadly accessibleClassify data, enforce access governance, approve by owner, review access
New analytics project wants all available dataApply purpose, classification, privacy, minimization, and approved use
System change may affect reportsPerform lineage and impact analysis before implementation
Business units disagree on standard valuesEscalate through governance decision rights and approved standards
Glossary exists but is not usedImprove adoption, ownership, integration into processes, and communication
Governance is viewed as bureaucracyConnect governance to business outcomes, risk reduction, and measurable value
IT is asked to define business meaningBusiness owner/steward should define meaning; IT supports implementation

Common candidate mistakes

Mistake 1: Treating data governance as a technology project

Tools can support catalogs, workflow, lineage, quality monitoring, and access reviews. But governance requires authority, accountability, policies, roles, and decisions.

Better framing: people, process, policy, accountability, and technology together.

Mistake 2: Assuming the data governance team owns all data

The governance function coordinates and enables governance. Business data owners retain accountability for data meaning, quality expectations, and acceptable use.

Mistake 3: Choosing the fastest fix instead of the governed fix

A quick technical correction may not solve root cause, ownership, policy, or control gaps. In exam scenarios, choose sustainable remediation.

Mistake 4: Confusing “data owner” with “system owner”

A system owner may manage an application. A data owner is accountable for data as a business asset, especially meaning, quality, risk, and use.

Mistake 5: Ignoring change management

Governance fails when stakeholders do not understand roles, incentives, workflows, or benefits. Communication, training, and adoption are often the best answer.

Mistake 6: Over-governing low-risk data

Governance should be proportionate. Prioritize critical data, sensitive data, regulatory data, high-value analytics, and enterprise-shared data.

Mistake 7: Focusing only on compliance

Compliance is important, but governance also supports value creation, decision quality, operational efficiency, and strategic alignment.

Quick concept comparisons

Data owner versus data steward

QuestionData ownerData steward
Main roleAccountable decision-makerOperational governance support
FocusBusiness accountability and authorityDefinition, quality, metadata, coordination
Approves key decisions?Usually yesUsually recommends or prepares
Handles daily governance tasks?Not usuallyOften yes
Replaces IT?NoNo
Notes and examples

Policy versus standard versus procedure

If the question asks…Think…
“What rule must everyone follow?”Policy
“What exact requirement supports the rule?”Standard
“What steps do we take?”Procedure
“What is recommended?”Guideline
“How do we enforce or test it?”Control

Data governance versus data quality

Data governanceData quality
Defines accountability, rules, priorities, and oversightMeasures and improves fitness for use
Establishes ownership and escalationIdentifies defects and root causes
Approves policies and standardsApplies rules, profiling, monitoring, remediation
Ensures quality is managed as a business issueProvides evidence and improvement actions

Scenario mini-drills

Use these quick drills to test whether you are applying governance logic rather than memorizing definitions.

Drill 1

A finance report and a sales dashboard use different definitions of “active customer.” Executives are debating which number is correct.

Best governance response:

  • Assign business ownership for the term.
  • Use stewardship to document candidate definitions and usage.
  • Approve an enterprise or context-specific definition through the appropriate governance body.
  • Update glossary, lineage, reporting standards, and affected reports.
Notes and examples

Avoid: asking IT to choose the definition based only on current system logic.

Drill 2

A customer dataset has repeated address defects. Analysts clean the file every month before reporting.

  • Measure the defect pattern.
  • Determine root cause at capture, integration, or source process.
  • Assign accountable data owner and steward.
  • Implement validation or process controls upstream.
  • Monitor quality metrics and recurrence.

Avoid: continuing manual cleansing as the primary control.

Drill 3

A new analytics team requests unrestricted access to detailed personal data “in case it becomes useful.”

  • Confirm business purpose and approved use.
  • Apply classification and privacy/security requirements.
  • Use least privilege and minimization.
  • Approve access through accountable data owner and security process.
  • Monitor and review access.

Avoid: broad access without purpose, classification, or approval.

Drill 4

A data catalog has been purchased, but business users still do not trust the data.

  • Assign ownership and stewardship for catalog content.
  • Define required metadata and quality standards.
  • Link glossary terms, lineage, quality indicators, and certified assets.
  • Integrate catalog use into reporting, analytics, and change processes.
  • Measure adoption and usefulness.

Avoid: assuming tool deployment alone solves trust.

Put the review into practice