The Data Management Body of Knowledge
The one-paragraph answer
DAMA-DMBOK (Data Management Body of Knowledge) is the reference framework for the data management discipline, published by the Data Management Association (DAMA International). Now in its second edition (DMBOK2), it organizes data management into eleven knowledge areas surrounding data governance at the center. Every AI governance program depends on the disciplines DAMA-DMBOK defines.
Companies deploying AI often discover that their data management is inadequate: data quality is unknown, metadata is missing, master data is inconsistent, and data governance responsibilities are unclear. DAMA-DMBOK provides the vocabulary and structure to fix these problems systematically, rather than one AI project at a time.
The central function. Policies, roles, decision rights, standards, and issue resolution.
Data Architecture, Data Modeling and Design, Data Storage and Operations, Data Security, Data Integration and Interoperability, Documents and Content, Reference and Master Data, Data Warehousing and Business Intelligence, Metadata, Data Quality, and Data Management Environment.
How data is planned, developed, maintained, and retired.
Data steward, data custodian, data owner, data architect, and other roles that need explicit definition.
Because AI governance without underlying data governance is unstable. Data quality problems become AI quality problems. Metadata gaps become AI explainability problems. Master data inconsistencies become AI decision inconsistencies. Starting with DAMA-DMBOK saves months of remediation later.
The academic literature on DAMA-DMBOK is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“the performance of a machine learning model is upper bounded by the quality of the data”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“Data quality issues trace back their origin to the early days of computing.”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about DAMA-DMBOK arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, DAMA-DMBOK becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
DAMA offers CDMP (Certified Data Management Professional) certification based on DMBOK content. The framework itself is a body of knowledge, not a certifiable standard.
Complementary. DMBOK provides data management. ISO/IEC 42001 adds AI-specific management on top.
SRJ maps every AI governance artifact to the DMBOK knowledge area it depends on, in Appendix L of Volume III of The Operating Discipline for AI Library™.
Three, consistently. Data quality, because a model trained on data nobody profiled inherits every defect in it and amplifies them at scale. Metadata, because a model whose inputs are undocumented cannot be explained to a regulator, an auditor, or a customer who was denied something. And reference and master data, because a model that sees the same customer under three identities will make three different decisions about the same person and no one will be able to say which was right.
DAMA-DMBOK places data governance in the middle of the wheel and arranges the other knowledge areas around it. This is not a diagramming choice. Without decision rights, ownership, standards, and an escalation path, the other ten areas have no mechanism to be enforced. Every AI governance program that fails for want of a data foundation fails here first: nobody owned the data, so nobody could be asked to fix it.
Do not attempt all eleven knowledge areas. Start with the data that feeds your highest-risk AI use case, and for that data only, establish ownership, profile the quality, capture the metadata, and resolve the master data. Then extend. Organisations that try to boil the DAMA-DMBOK ocean produce a two-year program that delivers nothing; organisations that follow one AI use case down to its data and fix what they find deliver in a quarter and build the muscle to repeat it.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning DAMA-DMBOK that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including DAMA-DMBOK, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →