The NDMO Framework Explained: 15 Domains in One Map
9 min read · June 8, 2026
Ask any data leader in the Kingdom what "data management" means in practice, and the conversation quickly arrives at one document: the national data management and personal data protection standards issued by the National Data Management Office (NDMO), operating under the Saudi Data and AI Authority (SDAIA). The framework spans 15 domains, 77 controls, and 191 specifications, and it has become the shared language of data work in Saudi Arabia. This guide maps all 15 domains in one place: what each covers, who must comply, how the rollout actually happens, and how the domains depend on each other.
What the framework is — and why it exists
The NDMO framework is the Kingdom's national reference for how organizations govern, manage, and protect data. It was built to do three things:
- Standardize practice. Every government entity describes ownership, classification, quality, and protection the same way, using the same controls.
- Make compliance measurable. Each domain breaks into controls, and each control into specifications — concrete, auditable requirements rather than abstract principles.
- Support the national agenda. Reliable, well-governed data underpins digital government, AI adoption, and the data economy ambitions of Vision 2030.
The structure is hierarchical: 15 domains group 77 controls, which expand into 191 specifications. When an entity is assessed, it is scored at the specification level — which is why teams that read only the domain names are usually surprised by how operational the requirements get.
Who must comply
- Government entities: mandatory. The framework applies to public bodies, and compliance is formally measured.
- Entities handling government data: in scope through contracts. Service providers and partners that process government data inherit obligations through agreements and data-sharing arrangements.
- Large private organizations: increasingly aligned by choice. Banks, telecoms, healthcare groups, and contractors adopt the framework because government procurement rewards it, sector regulators echo it, and — frankly — it is a well-structured map that saves them designing one from scratch.
The practical takeaway: even if you are not formally obligated today, the framework is becoming the default standard your partners, auditors, and customers will use to evaluate you.
The 15 domains in one map
Fifteen domains are hard to hold in your head as a flat list. Grouped by purpose, they form five clusters.
1. Steering: setting direction
- Data Governance. The anchor domain: establishing a data management office, strategy, policies, roles such as data owners and stewards, and maturity measurement. Every other domain assumes this one exists — it defines who decides.
2. Knowing your data
- Data Catalog & Metadata. A living inventory of data assets enriched with business and technical metadata, so the organization knows what data it has and where it lives.
- Data Architecture & Modelling. Standards for how data is structured, modelled, and integrated across systems.
- Data Classification. Labelling data by sensitivity (public, restricted, confidential, top secret) so every downstream decision — access, sharing, publication — has a basis.
3. Trusting your data
- Data Quality. Measuring and improving accuracy, completeness, timeliness, and consistency against defined rules.
- Reference & Master Data. Single agreed versions of shared entities (customers, organizations, locations) and code lists.
- Data Operations. The operational lifecycle: storage, retention, backup, archiving, and disposal.
- Document & Content Management. Governing unstructured content — documents, records, media — with the same discipline applied to structured data.
4. Putting data to work
- Business Intelligence & Analytics. Governed reporting and analytics, so decisions rest on trusted, consistent figures.
- Data Sharing & Interoperability. Controlled exchange of data between entities through agreements, standards, and platforms.
- Data Value Realization. Treating data as an asset: identifying use cases, measuring benefits, and tying data work to outcomes.
- Open Data. Proactively publishing eligible datasets for public reuse.
- Freedom of Information. Handling public requests for access to government information within defined rules and timelines.
5. Protecting data
- Personal Data Protection. Aligning with the Personal Data Protection Law (PDPL) — fully enforced since September 2024, with SDAIA as the enforcement authority and penalties reaching SAR 5 million, rising to SAR 10 million for repeat violations.
- Data Security & Protection. Technical and organizational safeguards: access control, encryption, monitoring, and incident handling.
Notice that the last cluster cannot work without the second: you cannot protect personal data you have not found, and you cannot apply security controls proportionally without classification.
The rollout reality: priority tiers
On paper the framework applies broadly; in practice it has arrived in waves. Government entities are grouped into priority tiers, with the largest and most data-intensive bodies assessed first. Compliance is measured through periodic assessments that combine self-assessment with evidence review, producing scores per domain that entities are expected to improve year over year.
Three practical consequences follow:
- Your turn is coming, not optional. Entities in later tiers sometimes treat the framework as distant. The assessment cycle keeps expanding, and the entities that started early consistently find audits easier.
- Evidence matters as much as activity. Assessors look for artifacts: registers, policies, classification labels, quality reports. Doing the work without documenting it scores poorly.
- Scores reward systems, not heroics. A spreadsheet inventory maintained by one employee decays between assessments. Sustainable scores come from processes and platforms that keep evidence current by default.
How the domains interlock
The framework reads like a list but behaves like a system:
- Governance feeds everything. Without named owners and stewards, classification stalls, quality issues have no escalation path, and sharing agreements have no signatory.
- The catalog is the backbone. Classification labels, quality scores, ownership, and retention rules all attach to data assets, and the data catalog is where those assets are registered. Most domains effectively write their evidence into it.
- Classification drives protection and sharing. Security controls, PDPL safeguards, open data eligibility, and sharing decisions all key off classification labels.
- Quality depends on ownership and lineage. A quality rule without an owner is a dashboard nobody acts on, and data lineage tells you where an error entered and what it contaminated.
- Value realization sits on top. BI, analytics, sharing, and open data only deliver value once the foundational domains have made data findable, trusted, and safe.
This is why "one domain per quarter" plans struggle: the domains were designed to reinforce each other, and assessments expose the gaps where they don't.
Where to start
For most organizations, the practical sequence is:
- Stand up governance — a data management office (even a small one), named owners, and a policy baseline.
- Build the catalog and classify — inventory data assets, attach metadata, and apply classification labels.
- Switch on quality and protection — quality rules on critical datasets, and PDPL-aligned controls on personal data.
- Then scale outward — sharing, open data, analytics, and value measurement on top of the foundation.
Teams that follow this order find the later domains get cheaper: the catalog built in step 2 becomes the evidence base for almost every assessment that follows.
If you are mapping your own organization against the 15 domains, our NDMO compliance overview shows how Goava covers the catalog, classification, quality, and governance domains from a single platform — and where to begin if your assessment date is already on the calendar.
Monthly digest
Monthly data governance insights for organizations operating in Saudi Arabia.