Skip to main content

AI data readiness is now a board- and executive-level mandate for CDAOs

Boards and executive teams expect explainable, governed AI—making trusted, contextual, AI-ready data a mandate for CDAOs responsible for scaling enterprise AI.

Why AI data readiness has expanded the CDAO’s mandate

For CDAOs, the expansion of data responsibilities creates both new authority and new accountability. Leaders read headlines about competitors launching AI systems and want to know how the organization can move faster. Boards, for example, must evaluate the risks.

Board oversight responsibility leads to questions such as:

  • Can we trust AI outputs to be accurate, reliable, and trustworthy?
  • Are governance controls and policies in place?
  • What safeguards protect AI systems and enterprise data?

Leaders increasingly treat data in the same category as financial controls and cybersecurity. If enterprise data is inconsistent, poorly governed, or difficult to explain, then AI becomes a liability, the kind that fails audits, exposes sensitive data, or drives decisions the company cannot defend.

As a result, CDAOs are expected to demonstrate leadership that the organization’s data architecture, governance processes, and operating model can support AI safely and reliably.

What an AI data readiness framework must include for boards to sign off

When boards ask whether the organization is AI ready, the answer cannot be a list of data initiatives. CDAOs need a clear AI data readiness framework that demonstrates how trusted, governed, contextual data will support AI safely, reliably, and at scale.

A board-ready framework has three components:

01
Operating model

Clear ownership, decision rights, and accountability across data, risk, technology, and business so AI readiness does not stall in ambiguity.

02
Governance

Governance covers enforceable standards, certified data pipelines, lineage, and policy-based permissions applied consistently across structured and unstructured data, enabling explainable and defensible AI outcomes.

03
Architecture

Modernized, context-rich, machine-readable data products support retrieval, reasoning, and safe scaling across AI use cases.

Defining this framework gives boards clarity on governance and accountability. The next challenge is operationalizing that framework by producing the trusted, governed, contextual data that AI systems require to perform reliably.

What AI data readiness means

AI data readiness reflects the conditions that allow AI systems to use enterprise data safely, consistently, and at scale. This occurs through trusted, governed, contextual data supported by clear lineage and permissions.

In practice, this means data is:

Trusted

Definitions and sources are consistent across systems

Governed

Permissions and policies control how data is used

Contextual

Relationships and business meaning are encoded in the data

Traceable

Lineage shows how data and AI outputs were generated

Without these conditions present, AI may retrieve information successfully but still struggle to generate outputs that are explainable, defensible, or safe to operationalize.

Why trusted, governed, contextual data is becoming a strategic differentiator for AI

As organizations operationalize AI data readiness, the next priority becomes ensuring that AI systems function within clearly defined governance boundaries. Once an AI data readiness framework is defined, the focus shifts from planning to execution. The goal is to turn governance principles into trusted, governed, contextual data that can be deployed enterprise-wide, as well survive risk review and audit scrutiny.

Leadership increasingly recognizes that modern data foundations determine whether AI initiatives scale successfully or not. Gartner predicts that through 2026, organizations will abandon 60 percent of AI projects unsupported by AI-ready data.1

Research prediction is one reason why boards now view AI data readiness not as technical detail but as a governance requirement.

Producing AI-ready data often requires CDAOs to move beyond traditional data management disciplines. AI-ready data reflects definitions, relationships, and rules, so AI systems can interpret enterprise data consistently across the organization. When enterprise data is made machine-readable, it shifts from static records stored in tables to context-rich knowledge networks that AI agents can reason over.

1 Gartner, “Lack of AI-Ready Data Puts AI Projects at Risk,” references to “abandon 60% of AI projects through 2026,” February 2025. 

Why data readiness requires transitioning from RBAC to ABAC

AI access introduces new patterns that place pressure on role-based access control (RBAC) across both structured and unstructured data. A practical AI data readiness step is evolving toward attribute-based access control (ABAC). Compare RBAC to preferred ABAC.

Feature

Role-based access control (RBAC)

Attribute-based access control (ABAC)

Access logic

Access is granted based on predefined user roles

Access is granted based on policies that evaluate attributes

Granularity

Tightly coupled to applications and static roles

Evaluates attributes of the data (e.g., classification, sensitivity), the user (e.g., context, purpose), and the environment (e.g., geography)

Data handling

Less effective when access spans both structured and unstructured data simultaneously

Applies uniformly and consistently across structured tables, fields, records, and unstructured documents

Adaptability

Struggles to adapt to new regulatory and data-sensitivity constraints without creating complex role matrices

Highly adaptable; policies can be updated to reflect new rules without re-architecting roles

Scalability for AI

Does not scale well as AI systems require broader, more dynamic access across diverse data types

Enables organizations to scale AI access while maintaining consistent policy enforcement

Risk management

Increased risk of overentitlement as roles broaden to accommodate new access patterns

Reduces overentitlement risk by enforcing the principle of least privilege at a granular level

Audit and compliance

Access decisions can be opaque and difficult to audit as role complexity grows

Produces auditable and repeatable access decisions, ensuring governance

How AI data readiness enables defensible AI governance

Defensible AI governance is not defined by a single policy. It is the ability to demonstrate through lineage, policy-enforced permissions, and traceability as to how AI systems use both structured and unstructured data, what controls apply, and how decisions can be explained. This is especially important when AI is leveraged for regulated reporting workflows such as sustainability/environmental, social, and governance disclosures under the Corporate Sustainability Reporting Directive (CSRD) where auditability, traceability, and evidence of controls are essential. For boards, this level of transparency transforms AI from a promising technology into a controllable enterprise capability.

When data is trusted, governed, and contextual, governance becomes operational rather than theoretical. AI systems can operate within guardrails, allowing organizations to scale AI initiatives enterprise-wide while managing risk.

The next step for CDAOs: From data management to unified, agentic data ecosystem

Data that was once fragmented is unified in a data catalog. A data fabric integrates data across both modern and legacy systems. With a stable base, the organization progresses to engineering context, creating a semantic layer, ontology, and knowledge graph to allow AI to reason, not just retrieve. This newly contextualized data facilitates intelligent process automation, using AI agents and learning loops to streamline core business workflows.

How KPMG helps CDAOs operationalize AI data readiness and perform defensible governance

KPMG helps organizations translate AI data readiness from aspiration into an operating model that boards can evaluate and leadership teams can execute. This includes helping CDAOs define governance frameworks, ownership models, and modern data architectures capable of producing trusted, governed, and contextual data for AI systems.

By connecting data modernization, governance design, and context-rich architecture, KPMG helps organizations move from fragmented data environments to AI initiatives that are explainable, defensible, and capable of delivering enterprise-scale value.

Meet our team

Image of Matteo Colombo
Matteo Colombo
Principal, KPMG Global Leader for Cloud, Data, AI , KPMG US
Image of Garrett P Flynn
Garrett P Flynn
Principal, Advisory, KPMG US

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline