Capability Type: Enabling / Cross-Cutting
Capability Owner: CIO or CDO
Related Capabilities: Decision Management, Risk & Compliance, Enterprise Architecture, Analytics & Insight, IT Infrastructure
Definition
Information & Data Management is the business capability responsible for treating data as a managed asset — acquiring it, storing it, protecting it, transforming it, and converting it into decision-ready information — with the same discipline an organization applies to any other input of production.
The core premise of this capability: data is a raw material. Like capital, labor, or physical inventory, it has to be sourced, held, safeguarded, and processed before it produces value. It does not become useful on its own — it becomes useful when it is transformed into a data product that a person or system can use to make a decision.

Why This Is a Business Capability (Not Just an IT Function)
Data management is frequently mis-classified as a purely technical concern — something that lives inside IT alongside databases and servers. Framing it as a business capability instead means:
- It has owners, outcomes, and value metrics, not just systems and uptime targets.
- It has a cost structure that should be visible to the business, the same way cost of goods sold is visible.
- It has maturity levels the organization can be assessed against.
- It can be assured — audited, tested, and reported on — like any other capability that carries operational or regulatory risk.
- It is shared infrastructure for decision-making across every other business capability (finance, operations, marketing, risk, etc. all consume it).
The Economics of Data: Cost as a Raw Material
Because data behaves like a raw material, it carries real, attributable costs at every stage of its lifecycle. Treating these as invisible or "free" is one of the most common failure modes in data management — it leads to unmanaged sprawl, shadow data stores, and untrusted reporting.
| Cost Category | What It Covers | Typical Cost Drivers |
|---|---|---|
| Acquisition | Sourcing data — internally generated or externally purchased/licensed | System instrumentation, third-party data licensing, integration effort, consent/legal review |
| Storage | Holding data in a retrievable state | Database/warehouse/lake infrastructure, redundancy, backup, retention duration |
| Protection | Keeping data safe, compliant, and access-controlled | Security tooling, encryption, access management, privacy compliance, audit logging |
| Transformation / Processing | Cleaning, structuring, integrating, and modeling raw data | Pipeline engineering, data quality remediation, ETL/ELT compute, master data reconciliation |
| Productization | Packaging processed data into a decisionable form (report, dashboard, model, API) | Analytics engineering, BI tooling, model development, delivery/UX design |
| Decay / Carrying Cost | The ongoing cost of holding data that is stale, duplicated, or no longer accurate | Re-validation effort, cost of decisions made on bad data, storage of unused data ("data debt") |
Implication: every dataset the business holds is a standing liability until it is converted into something decisionable. A mature capability actively manages this — deciding deliberately what data is worth acquiring, how long it's worth keeping, and when it should be retired — rather than defaulting to "keep everything, forever, just in case."
Capability Components (Sub-Capabilities)
| Sub-Capability | Purpose |
|---|---|
| Data Governance | Defines ownership, decision rights, policy, and standards for how data is managed across the organization |
| Data Architecture | Designs how data is structured, stored, and moved — the "plumbing" the other sub-capabilities depend on |
| Data Quality Management | Ensures data is accurate, complete, consistent, and fit for its intended use |
| Master & Reference Data Management | Maintains a single, trusted version of core business entities (customer, product, vendor, location, etc.) |
| Data Integration & Pipelines | Moves and transforms data between systems reliably and at the needed frequency |
| Data Security & Privacy | Protects data from unauthorized access, loss, or misuse; manages regulatory and contractual obligations |
| Data Lifecycle Management | Governs data from creation through archival and deletion, including retention policy |
| Metadata & Data Cataloging | Makes data discoverable and understandable — what it means, where it came from, who owns it |
| Analytics & Decision Enablement | Converts governed data into the final "decisionable data product" — reports, dashboards, models, alerts |
| Data Literacy | Builds the organizational skill to correctly interpret and use data products in decisions |
Each of these can be independently assessed, resourced, and matured — which is what makes this a capability rather than a single project or system.
Capability Assurance: What "Good" Looks Like
Assurance is how the organization gets confidence that this capability is actually working — not just that systems exist, but that they produce trustworthy outcomes.
Typical assurance mechanisms:
- Data quality scorecards — measurable thresholds (accuracy, completeness, timeliness) tracked over time
- Governance controls — documented data ownership (stewards/trustees), approval workflows for new data sources, policy exceptions logged and reviewed
- Security & privacy audits — access reviews, encryption standards, regulatory compliance checks (e.g., data residency, consent management)
- Lineage & traceability — ability to trace any decisionable data product back to its raw source
- Cost transparency — visibility into what each dataset or pipeline actually costs to acquire, store, and maintain, reviewed periodically like any other budget line
- Maturity assessment — periodic scoring of each sub-capability (e.g., Initial → Managed → Defined → Optimized) against a maturity model
Common assurance failure signals:
- Multiple conflicting "versions of the truth" for the same business entity
- Data stores with no identifiable owner
- Growing storage costs with no corresponding growth in decision value
- Decisions being made on data no one can trace back to a trusted source
- Security/privacy incidents traced to unmanaged or "shadow" data

Value Realization
The capability's value is not the data itself — it's the quality and speed of the decisions the data enables. Value is realized when:
- Decisions are made faster because trusted data products are readily available rather than manually reconciled each time
- Decisions are made better because the underlying data is accurate, complete, and well-understood
- Risk is reduced because data is protected, compliant, and traceable
- Cost is controlled because the organization only acquires, stores, and processes the data that actually earns its keep
A useful test for any data initiative: what decision does this ultimately enable, and is that decision worth what this data costs to acquire, store, protect, and process?