Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
6. Technology and analytics
6.1 Information systems
6.2 Data governance
6.2.1 Technology-enabled finance transformation
6.2.2 Data policies and procedures
6.2.3 Life cycle of data
6.2.4 Data management
6.2.5 Controls against security breaches
6.3 Data analytics
Achievable logoAchievable logo
6.2.2 Data policies and procedures
Achievable CMA Part 1
6. Technology and analytics
6.2. Data governance
Our CMA Part 1 course is currently in development and is a work-in-progress.

Data policies and procedures

7 min read
Font
Discuss
Share
Feedback

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. define data governance
  2. demonstrate a general understanding of data governance frameworks, including COSO’s Internal Control—Integrated framework

Definition of data governance

Definitions
Data governance
The overall management of the availability, integrity, usability, and security of data within an organization.

The primary objectives of data governance are defined by:

Objectives of data governance
Objectives of data governance

Data availability

Ensuring that data is accessible when needed by authorized users. This involves implementing backup strategies, redundancy systems, and disaster recovery plans to minimize downtime and data loss.

Data integrity

Maintaining the accuracy and reliability of data throughout its lifecycle. This requires implementing validation processes, error detection mechanisms, and audit trails to prevent unauthorized modifications or corruption.

Data usability

Ensuring that data is structured, formatted, and stored in a manner that allows efficient retrieval and processing. This includes data standardization, normalization, and metadata management to enhance usability across various departments.

Data security

Protecting data from unauthorized access, breaches, and cyber threats. Security measures include encryption, access controls, multi-factor authentication, and regular security assessments to safeguard sensitive information. of data within an organization. It involves establishing policies, procedures, and responsibilities to ensure data is accurate, consistent, and compliant with regulatory requirements.

The COSO’s Internal Control-Integrated Framework

This has already been discussed in CMA Part 1 - Section E on Internal Control. Since this objective has appeared in separate learning outcome statements for each section, we have covered them here briefly in the context of data governance.

Organizations rely on structured data governance frameworks to ensure proper data oversight. Management typically selects which frameworks to adopt based on the organization’s regulatory requirements, industry standards, and business needs. These frameworks provide structured guidelines that help maintain compliance, security, and operational efficiency while ensuring that data governance aligns with the company’s strategic objectives.

One of the most widely recognized frameworks is COSO’s Internal Control—Integrated Framework, which provides a structured approach for risk management, internal controls, and data integrity.

Objectives

The COSO Internal Control—Integrated Framework categorizes internal control objectives into three main areas:

  • Operations: Ensuring the effectiveness and efficiency of business operations, including safeguarding assets and optimizing processes to support organizational goals.
  • Reporting: Supporting the reliability, timeliness, and transparency of financial and non-financial reporting to facilitate informed decision-making.
  • Compliance: Ensuring adherence to applicable laws, regulations, and internal policies to mitigate legal and financial risks.

These objectives provide a foundation for organizations to design and implement internal controls that enhance data governance, risk management, and overall business integrity.

Key components

The COSO framework is built upon five interrelated components, often referred to as the five pillars, which are further broken down into 17 guiding principles. These pillars serve as the foundation for implementing effective internal controls, including those applied to data governance.

By following these principles, organizations can create a robust data governance framework that enhances compliance, security, and operational efficiency.

Sidenote
Acronym to remember: CRIME

These components are often remembered using the acronym CRIME, which provides an easy way to recall the framework while preparing for the CMA exam.

COSO internal control integrated framework acronym
COSO internal control integrated framework acronym

Pillar 1: Control Environment

This pillar establishes the tone at the top, promoting ethical behavior, accountability, and a commitment to governance policies. A strong control environment is demonstrated when an organization enforces ethical codes of conduct, provides regular training on governance policies, and establishes clear lines of authority and responsibility. For example, a company with a well-defined control environment may have leadership regularly communicating ethical expectations, implementing a whistleblower policy, and incorporating internal audits to ensure compliance with governance standards.

It includes principles such as:

  1. Demonstrating commitment to integrity and ethical values.
  2. Exercising oversight responsibility for internal controls and governance.
  3. Establishing structures, authority, and responsibility for data management.
  4. Demonstrating commitment to attract, develop, and retain competent individuals.
  5. Holding individuals accountable for their responsibilities in governance frameworks.

Pillar 2: Risk Assessment

Identifies and evaluates risks that may impact data governance, ensuring organizations can anticipate and mitigate potential threats. A strong risk assessment pillar is demonstrated when an organization actively conducts regular risk evaluations, implements predictive analytics to anticipate data security threats, and establishes a formal risk response plan. For example, a company with a well-structured risk assessment approach may perform periodic audits, classify data based on sensitivity levels, and develop contingency measures to mitigate cybersecurity threats before they escalate.

This includes:

  1. Specifying suitable objectives related to data governance and management.
  2. Identifying and analyzing risks that could impact data integrity.
  3. Assessing fraud risks related to data security and compliance.
  4. Identifying and responding to changes that may affect data governance policies.

Pillar 3: Control Activities

Focuses on the implementation of measures that safeguard data governance processes. A good application of this pillar includes enforcing segregation of duties to prevent unauthorized access, implementing automated data validation checks to ensure accuracy, and deploying encryption techniques to protect sensitive information. For example, a financial institution may integrate access controls that restrict data modifications based on employee roles, ensuring that only authorized personnel can update critical financial records. Additionally, companies may conduct periodic compliance audits and training sessions to reinforce best practices in data handling and security.

Principles include:

  1. Selecting and developing control activities to mitigate data risks.
  2. Deploying technology controls to support data integrity and security.
  3. Establishing policies and procedures that define data handling and management practices.

Pillar 4: Information and Communication

Ensures that data policies and governance frameworks are well-documented and effectively communicated. A good example of this pillar in action is a multinational corporation implementing a centralized documentation repository where all data governance policies are stored and easily accessible. Additionally, organizations may conduct regular training sessions and workshops to ensure that employees at all levels understand their roles and responsibilities regarding data governance. Another example is a company that establishes a structured reporting mechanism, ensuring that internal control responsibilities and data management policies are consistently communicated across departments.

This includes:

  1. Utilizing relevant, quality information to support data governance.
  2. Communicating internal control responsibilities clearly.
  3. Ensuring external communication regarding data governance is transparent and consistent.

Pillar 5: Monitoring Activities

Involves continuous assessment and improvement of data governance policies and procedures. A strong application of this pillar is evident when an organization conducts regular internal audits, implements automated monitoring systems, and establishes feedback loops to address governance deficiencies. For example, a company may use key performance indicators (KPIs) to track data quality over time and adjust governance practices accordingly. Additionally, firms may employ independent external reviews to validate compliance with regulatory requirements and industry best practices.

Principles include:

  1. Conducting ongoing and periodic evaluations to maintain governance effectiveness.
  2. Implementing corrective actions to address deficiencies and improve data governance.

Data governance

  • Management of data availability, integrity, usability, and security
  • Objectives:
    • Data availability: accessible to authorized users when needed
    • Data integrity: accuracy and reliability throughout lifecycle
    • Data usability: structured, standardized, and easily retrievable
    • Data security: protection from unauthorized access and breaches

Data governance frameworks

  • Provide structured guidelines for compliance, security, and efficiency
  • Align data governance with strategic objectives
  • Selection based on regulatory, industry, and business needs

COSO’s Internal Control—Integrated Framework

  • Widely recognized framework for risk management and internal controls
  • Three main objectives:
    • Operations: effectiveness, efficiency, safeguarding assets
    • Reporting: reliability and transparency of information
    • Compliance: adherence to laws, regulations, policies

COSO’s five components (CRIME)

  • Control Environment
    • Ethical values, accountability, governance structure
    • Oversight, authority, responsibility, competence, accountability
  • Risk Assessment
    • Identify, analyze, and respond to risks
    • Specify objectives, assess fraud risk, adapt to changes
  • Control Activities
    • Implement measures to mitigate risks
    • Technology controls, policies, procedures, segregation of duties
  • Information and Communication
    • Quality information, clear communication of responsibilities
    • Internal and external transparency
  • Monitoring Activities
    • Ongoing evaluations and corrective actions
    • Continuous improvement of governance practices

Sign up for free to take 15 quiz questions on this topic

Previous
Next  | 6.2.3 Life cycle of data
All rights reserved ©2016 - 2026 Achievable, Inc.

Data policies and procedures

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. define data governance
  2. demonstrate a general understanding of data governance frameworks, including COSO’s Internal Control—Integrated framework

Definition of data governance

Definitions
Data governance
The overall management of the availability, integrity, usability, and security of data within an organization.

The primary objectives of data governance are defined by:

Data availability

Ensuring that data is accessible when needed by authorized users. This involves implementing backup strategies, redundancy systems, and disaster recovery plans to minimize downtime and data loss.

Data integrity

Maintaining the accuracy and reliability of data throughout its lifecycle. This requires implementing validation processes, error detection mechanisms, and audit trails to prevent unauthorized modifications or corruption.

Data usability

Ensuring that data is structured, formatted, and stored in a manner that allows efficient retrieval and processing. This includes data standardization, normalization, and metadata management to enhance usability across various departments.

Data security

Protecting data from unauthorized access, breaches, and cyber threats. Security measures include encryption, access controls, multi-factor authentication, and regular security assessments to safeguard sensitive information. of data within an organization. It involves establishing policies, procedures, and responsibilities to ensure data is accurate, consistent, and compliant with regulatory requirements.

The COSO’s Internal Control-Integrated Framework

This has already been discussed in CMA Part 1 - Section E on Internal Control. Since this objective has appeared in separate learning outcome statements for each section, we have covered them here briefly in the context of data governance.

Organizations rely on structured data governance frameworks to ensure proper data oversight. Management typically selects which frameworks to adopt based on the organization’s regulatory requirements, industry standards, and business needs. These frameworks provide structured guidelines that help maintain compliance, security, and operational efficiency while ensuring that data governance aligns with the company’s strategic objectives.

One of the most widely recognized frameworks is COSO’s Internal Control—Integrated Framework, which provides a structured approach for risk management, internal controls, and data integrity.

Objectives

The COSO Internal Control—Integrated Framework categorizes internal control objectives into three main areas:

  • Operations: Ensuring the effectiveness and efficiency of business operations, including safeguarding assets and optimizing processes to support organizational goals.
  • Reporting: Supporting the reliability, timeliness, and transparency of financial and non-financial reporting to facilitate informed decision-making.
  • Compliance: Ensuring adherence to applicable laws, regulations, and internal policies to mitigate legal and financial risks.

These objectives provide a foundation for organizations to design and implement internal controls that enhance data governance, risk management, and overall business integrity.

Key components

The COSO framework is built upon five interrelated components, often referred to as the five pillars, which are further broken down into 17 guiding principles. These pillars serve as the foundation for implementing effective internal controls, including those applied to data governance.

By following these principles, organizations can create a robust data governance framework that enhances compliance, security, and operational efficiency.

Sidenote
Acronym to remember: CRIME

These components are often remembered using the acronym CRIME, which provides an easy way to recall the framework while preparing for the CMA exam.

Pillar 1: Control Environment

This pillar establishes the tone at the top, promoting ethical behavior, accountability, and a commitment to governance policies. A strong control environment is demonstrated when an organization enforces ethical codes of conduct, provides regular training on governance policies, and establishes clear lines of authority and responsibility. For example, a company with a well-defined control environment may have leadership regularly communicating ethical expectations, implementing a whistleblower policy, and incorporating internal audits to ensure compliance with governance standards.

It includes principles such as:

  1. Demonstrating commitment to integrity and ethical values.
  2. Exercising oversight responsibility for internal controls and governance.
  3. Establishing structures, authority, and responsibility for data management.
  4. Demonstrating commitment to attract, develop, and retain competent individuals.
  5. Holding individuals accountable for their responsibilities in governance frameworks.

Pillar 2: Risk Assessment

Identifies and evaluates risks that may impact data governance, ensuring organizations can anticipate and mitigate potential threats. A strong risk assessment pillar is demonstrated when an organization actively conducts regular risk evaluations, implements predictive analytics to anticipate data security threats, and establishes a formal risk response plan. For example, a company with a well-structured risk assessment approach may perform periodic audits, classify data based on sensitivity levels, and develop contingency measures to mitigate cybersecurity threats before they escalate.

This includes:

  1. Specifying suitable objectives related to data governance and management.
  2. Identifying and analyzing risks that could impact data integrity.
  3. Assessing fraud risks related to data security and compliance.
  4. Identifying and responding to changes that may affect data governance policies.

Pillar 3: Control Activities

Focuses on the implementation of measures that safeguard data governance processes. A good application of this pillar includes enforcing segregation of duties to prevent unauthorized access, implementing automated data validation checks to ensure accuracy, and deploying encryption techniques to protect sensitive information. For example, a financial institution may integrate access controls that restrict data modifications based on employee roles, ensuring that only authorized personnel can update critical financial records. Additionally, companies may conduct periodic compliance audits and training sessions to reinforce best practices in data handling and security.

Principles include:

  1. Selecting and developing control activities to mitigate data risks.
  2. Deploying technology controls to support data integrity and security.
  3. Establishing policies and procedures that define data handling and management practices.

Pillar 4: Information and Communication

Ensures that data policies and governance frameworks are well-documented and effectively communicated. A good example of this pillar in action is a multinational corporation implementing a centralized documentation repository where all data governance policies are stored and easily accessible. Additionally, organizations may conduct regular training sessions and workshops to ensure that employees at all levels understand their roles and responsibilities regarding data governance. Another example is a company that establishes a structured reporting mechanism, ensuring that internal control responsibilities and data management policies are consistently communicated across departments.

This includes:

  1. Utilizing relevant, quality information to support data governance.
  2. Communicating internal control responsibilities clearly.
  3. Ensuring external communication regarding data governance is transparent and consistent.

Pillar 5: Monitoring Activities

Involves continuous assessment and improvement of data governance policies and procedures. A strong application of this pillar is evident when an organization conducts regular internal audits, implements automated monitoring systems, and establishes feedback loops to address governance deficiencies. For example, a company may use key performance indicators (KPIs) to track data quality over time and adjust governance practices accordingly. Additionally, firms may employ independent external reviews to validate compliance with regulatory requirements and industry best practices.

Principles include:

  1. Conducting ongoing and periodic evaluations to maintain governance effectiveness.
  2. Implementing corrective actions to address deficiencies and improve data governance.
Key points

Data governance

  • Management of data availability, integrity, usability, and security
  • Objectives:
    • Data availability: accessible to authorized users when needed
    • Data integrity: accuracy and reliability throughout lifecycle
    • Data usability: structured, standardized, and easily retrievable
    • Data security: protection from unauthorized access and breaches

Data governance frameworks

  • Provide structured guidelines for compliance, security, and efficiency
  • Align data governance with strategic objectives
  • Selection based on regulatory, industry, and business needs

COSO’s Internal Control—Integrated Framework

  • Widely recognized framework for risk management and internal controls
  • Three main objectives:
    • Operations: effectiveness, efficiency, safeguarding assets
    • Reporting: reliability and transparency of information
    • Compliance: adherence to laws, regulations, policies

COSO’s five components (CRIME)

  • Control Environment
    • Ethical values, accountability, governance structure
    • Oversight, authority, responsibility, competence, accountability
  • Risk Assessment
    • Identify, analyze, and respond to risks
    • Specify objectives, assess fraud risk, adapt to changes
  • Control Activities
    • Implement measures to mitigate risks
    • Technology controls, policies, procedures, segregation of duties
  • Information and Communication
    • Quality information, clear communication of responsibilities
    • Internal and external transparency
  • Monitoring Activities
    • Ongoing evaluations and corrective actions
    • Continuous improvement of governance practices

More from Data governance

  • Life cycle of data
  • Data management
  • Controls against security breaches