web analytics
Data Management Frameworks

CDMC Cloud Data Management

Cloud Data Management Capabilities Framework

The one-paragraph answer

CDMC (Cloud Data Management Capabilities Framework) is the EDM Council's cloud-specific data management framework. It defines fourteen key controls covering how organizations should manage data in cloud environments. Because most AI runs in the cloud, CDMC is now a common reference for enterprises assessing whether their cloud data management is AI-ready.

The pain CDMC is solving for our customers

Cloud data management is different from on-premises data management. Storage is elastic, access is API-driven, and data flows across boundaries in ways traditional frameworks did not anticipate. CDMC provides a cloud-native framework: fourteen controls covering ownership, classification, sensitivity, cataloging, sovereignty, security, quality, protection, retention, provenance, ethics, entitlements, cost, and lineage.

What CDMC covers

Fourteen key controls

Data ownership; data classification; sensitivity and privacy; cataloging and metadata; sovereignty and cross-border; entitlements and access; data protection; data quality; data retention and archiving; data provenance and lineage; ethical data use; cost management; consumption purpose; and data lineage.

Assessment approach

Each control is assessed against defined outcomes. Results feed enterprise cloud strategy and AI readiness.

Cloud-specific considerations

Multi-cloud, hybrid, sovereignty, and vendor lock-in issues that traditional data management frameworks did not fully address.

Why CDMC matters to you

Cloud is the default AI infrastructure. Enterprise buyers ask about CDMC in vendor diligence. Regulators reference cloud data management expectations that CDMC captures. AI programs running in the cloud without CDMC-style controls face specific risks around data sovereignty, entitlement management, and lineage that on-premises frameworks did not address.

What the research says about CDMC

The academic literature on CDMC is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“Effective data governance is important for minimizing data breach activity and mitigating bias”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“the performance of a machine learning model is upper bounded by the quality of the data”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about CDMC arrives from the board, the buyer, or the regulator.

How to get compliant with CDMC Cloud Data Management: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under CDMC. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities CDMC reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation CDMC expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, CDMC becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about CDMC

Does CDMC replace DAMA-DMBOK or DCAM?

No. Complementary. Use DMBOK for vocabulary, DCAM for enterprise maturity, CDMC for cloud-specific controls.

Is CDMC a certification?

The framework is a reference; assessments and certifications are performed by qualified third parties.

Where does CDMC fit in SRJ's work?

The cloud AI deployment guidance in Volume III of The Operating Discipline for AI Library™ references CDMC controls where they apply.

Why cloud changes the data control problem

On premises, data sat in known systems behind a known perimeter. In cloud, storage is elastic and effectively unlimited, access is API-driven rather than gated by a network boundary, data crosses jurisdictions by default, and a single misconfigured permission can expose everything at once. CDMC exists because the frameworks written for the previous architecture do not describe this one. Its fourteen controls are the cloud-native answer.

The controls that most directly gate AI

Four of the fourteen matter disproportionately for AI. Data classification and sensitivity, because you cannot decide what may be used for training until you know what you hold. Sovereignty and cross-border, because model training moves data and the movement may be unlawful. Entitlements and access, because a training pipeline typically reads far more broadly than any human user ever would. And provenance and lineage, because when someone asks what this model learned from, lineage is the only thing that can answer.

Ethical data use is in the framework for a reason

Unusually for a technical framework, CDMC names ethical data use as a control. That inclusion recognises something most cloud governance misses: lawful and appropriate are not the same test. Data a company is permitted to hold is not automatically data it should train a model on, and the fact that a consent form technically covers a use does not make the use one a customer would recognise or accept. Organisations that treat this control as decorative are the ones that end up explaining themselves publicly.

Primary sources on CDMC

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning CDMC that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including CDMC Cloud Data Management, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation