Cloud Data Management Capabilities Framework
The one-paragraph answer
CDMC (Cloud Data Management Capabilities Framework) is the EDM Council's cloud-specific data management framework. It defines fourteen key controls covering how organizations should manage data in cloud environments. Because most AI runs in the cloud, CDMC is now a common reference for enterprises assessing whether their cloud data management is AI-ready.
Cloud data management is different from on-premises data management. Storage is elastic, access is API-driven, and data flows across boundaries in ways traditional frameworks did not anticipate. CDMC provides a cloud-native framework: fourteen controls covering ownership, classification, sensitivity, cataloging, sovereignty, security, quality, protection, retention, provenance, ethics, entitlements, cost, and lineage.
Data ownership; data classification; sensitivity and privacy; cataloging and metadata; sovereignty and cross-border; entitlements and access; data protection; data quality; data retention and archiving; data provenance and lineage; ethical data use; cost management; consumption purpose; and data lineage.
Each control is assessed against defined outcomes. Results feed enterprise cloud strategy and AI readiness.
Multi-cloud, hybrid, sovereignty, and vendor lock-in issues that traditional data management frameworks did not fully address.
Cloud is the default AI infrastructure. Enterprise buyers ask about CDMC in vendor diligence. Regulators reference cloud data management expectations that CDMC captures. AI programs running in the cloud without CDMC-style controls face specific risks around data sovereignty, entitlement management, and lineage that on-premises frameworks did not address.
The academic literature on CDMC is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“Effective data governance is important for minimizing data breach activity and mitigating bias”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“the performance of a machine learning model is upper bounded by the quality of the data”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about CDMC arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, CDMC becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No. Complementary. Use DMBOK for vocabulary, DCAM for enterprise maturity, CDMC for cloud-specific controls.
The framework is a reference; assessments and certifications are performed by qualified third parties.
The cloud AI deployment guidance in Volume III of The Operating Discipline for AI Library™ references CDMC controls where they apply.
On premises, data sat in known systems behind a known perimeter. In cloud, storage is elastic and effectively unlimited, access is API-driven rather than gated by a network boundary, data crosses jurisdictions by default, and a single misconfigured permission can expose everything at once. CDMC exists because the frameworks written for the previous architecture do not describe this one. Its fourteen controls are the cloud-native answer.
Four of the fourteen matter disproportionately for AI. Data classification and sensitivity, because you cannot decide what may be used for training until you know what you hold. Sovereignty and cross-border, because model training moves data and the movement may be unlawful. Entitlements and access, because a training pipeline typically reads far more broadly than any human user ever would. And provenance and lineage, because when someone asks what this model learned from, lineage is the only thing that can answer.
Unusually for a technical framework, CDMC names ethical data use as a control. That inclusion recognises something most cloud governance misses: lawful and appropriate are not the same test. Data a company is permitted to hold is not automatically data it should train a model on, and the fact that a consent form technically covers a use does not make the use one a customer would recognise or accept. Organisations that treat this control as decorative are the ones that end up explaining themselves publicly.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning CDMC that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including CDMC Cloud Data Management, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →