Extending Traditional Data Governance Frameworks to Address Large Language…

Extending Traditional Data Governance Frameworks to Address Large Language Model (LLM) Non-Determinism and Uncertainty About Deployed Behavior

2026-05-09 · governance-policy security-risk agentic-ai organisational-design · medium · source → · wiki →
key claims
  1. DAMA-DMBOK, ISO/IEC 38505, and COBIT remain usable baseline frameworks for deployed Large Language Model governance because they already define stewardship, accountability, metadata, quality, security, and monitoring domains, but they require explicit reinterpretation for generative-system control surfacesDAMA (n.d.)Iso (n.d.)ISACA (2025)
  2. Metadata and lineage governance must expand from business-data catalogs and pipeline lineage to versioned prompt templates, system instructions, model identifiers, evaluation sets, transparency artifacts, impact assessments, and generation provenance if organizations want auditable Large Language Model operationsDAMA (n.d.)Google (n.d.)Google (n.d.)Microsoft (2022)NIST (2024)
  3. Classical data-quality governance is insufficient on its own, because deployed generative systems also require behavioral evaluation, confabulation tracking, red teaming, and release criteria that measure whether outputs remain fit for purpose under realistic and adversarial conditionsMicrosoft (2022)Google (n.d.)NIST (2024)
  4. Governance of prompt templates is a first-class extension point for traditional governance frameworks, because system-level policies, prompt templates, safeguard thresholds, and tool-use constraints materially change model behavior and therefore need documented ownership, review, and revision historyGoogle (n.d.)Google (n.d.)Google (n.d.)Google (n.d.)
  5. Accountability and oversight domains must be extended so that Large Language Models operate as bounded proposal or interpretation layers while deterministic policy, approval, rollback, and human-override mechanisms retain final authority for consequential governance actionsNIST (n.d.)Microsoft (2022)Governance Policy Application (n.d.)Hybrid Architecture Design (n.d.)Compliance (n.d.)
  6. The currently lower-friction extension strategy is a mapped control stack in which traditional governance domains absorb generative-AI-specific practices such as content provenance, transparency notes, incident disclosure, safeguards, and ongoing assurance review, even though a separate framework could still offer clearer clause-level guidance in some sectorsDAMA (n.d.)Iso (n.d.)ISACA (2025)NIST (2024)Microsoft (2022)Google (n.d.)

Research Question

How can traditional data governance frameworks be extended or mapped to address the inherent non-determinism and uncertainty about whether deployed behavior remains aligned with intended use in modern Large Language Models (LLMs) and multi-step agent systems?

Findings

Executive Summary

Traditional data governance frameworks can be extended for Large Language Model systems by treating prompt templates, model versions, evaluation evidence, and inference provenance as governed assets and by keeping final consequential authority outside stochastic model output. The accessible public material for DAMA-DMBOK, ISO/IEC 38505, and COBIT already covers accountability, stewardship, metadata, quality, security, and monitoring, but it does not specify how to govern probabilistic outputs, prompt changes, or model-version drift in deployed generative systems. NIST's generative profile plus Microsoft's and Google's responsible-AI frameworks supply the missing operational extensions: impact assessments, intended-use restrictions, content provenance, transparency artifacts, safeguards, red teaming, ongoing evaluation, and incident handling. Alignment uncertainty should be governed as a continuous assurance and change-control problem rather than folded into classical data quality alone, because behavior can shift through prompt interaction, safeguard tuning, and model or backend changes even when business data remain stable.

Key Findings

  1. DAMA-DMBOK, ISO/IEC 38505, and COBIT remain usable baseline frameworks for deployed Large Language Model governance because they already define stewardship, accountability, metadata, quality, security, and monitoring domains, but they require explicit reinterpretation for generative-system control surfaces.
  2. Metadata and lineage governance must expand from business-data catalogs and pipeline lineage to versioned prompt templates, system instructions, model identifiers, evaluation sets, transparency artifacts, impact assessments, and generation provenance if organizations want auditable Large Language Model operations.
  3. Classical data-quality governance is insufficient on its own, because deployed generative systems also require behavioral evaluation, confabulation tracking, red teaming, and release criteria that measure whether outputs remain fit for purpose under realistic and adversarial conditions.
  4. Governance of prompt templates is a first-class extension point for traditional governance frameworks, because system-level policies, prompt templates, safeguard thresholds, and tool-use constraints materially change model behavior and therefore need documented ownership, review, and revision history.
  5. Accountability and oversight domains must be extended so that Large Language Models operate as bounded proposal or interpretation layers while deterministic policy, approval, rollback, and human-override mechanisms retain final authority for consequential governance actions.
  6. The currently lower-friction extension strategy is a mapped control stack in which traditional governance domains absorb generative-AI-specific practices such as content provenance, transparency notes, incident disclosure, safeguards, and ongoing assurance review, even though a separate framework could still offer clearer clause-level guidance in some sectors.

Assumptions

Analysis

The evidence favors extension by mapping rather than replacement because the older frameworks still describe the right governance categories, but newer sources add the operational evidence required for deployed generative systems. The strongest cross-source convergence sits around four extensions: provenance, evaluation, safeguards, and accountability, because NIST, Microsoft, and Google each publish controls in those areas even though they differ in terminology. The practical mapping is therefore: governance and accountability to impact assessment and role separation; metadata and lineage to prompts, models, and generation provenance; quality to behavioral evaluation and confabulation thresholds; security to safeguards and prompt-injection defenses; and audit to transparency notes, release evidence, and incident disclosure. An alternative interpretation is that generative-AI governance now needs a separate framework because legacy standards are summary-level and partly paywalled, and NIST's generative profile already behaves like a specialized companion framework. The evidence still favors mapped extension as the lower-friction adoption path, because DAMA-DMBOK, ISO/IEC 38505, and COBIT continue to provide the organizational ownership and governance categories while NIST and vendor frameworks supply the missing operational detail. Prior repository items sharpen the final control recommendation by adding empirical and governance-specific evidence that current Large Language Model systems remain only partially reproducible, which makes deterministic external authority the safer interpretation of traditional accountability obligations.

Risks, Gaps, and Uncertainties

Open Questions


sources

cites
cites Data Governance Standards and Regulations Applied to Artificial Intelligence (AI) Systems and Multi-Step Autonomous AI Deployments
cites Governance Policy Application: Deterministic Requirements vs Stochastic Large Language Model (LLM) Elements
cites Hybrid Architecture Design: Probabilistic Large Language Models (LLMs) for Interpretation, Deterministic Layers for Governance Enforcement
cites Implementation Patterns for Regulatory Compliance in Artificial Intelligence-Driven Data Governance: Policy-as-Code, Guardrails, and Output Validation
cites Practical Limits of Large Language Model (LLM) Determinism: Temperature Zero, Fixed Seeds, and Constrained Prompts
cites Compliance Risks of Relying on Stochastic Large Language Model (LLM) Outputs for Governance, Privacy, and Regulatory Decisions
related (frontmatter)
related Automated governance assurance and change control verification patterns for AI-assisted delivery
related Explainable Artificial Intelligence (XAI): current research state, leading institutions, and regulatory intersection in heavily regulated industries
related When and how should human intervention be incorporated into Artificial Intelligence (AI)-driven and automated workflows?
version history
versiondatecommitsummary
1.02026-05-11d2cdfc2Initial completion

Connected items

Loading…

View full knowledge graph →