ISO/IEC 25012 Data Quality Model: Standard, Characteristics & Certification

ISO/IEC 25012 Data Quality Model: Standard, Characteristics & Certification

What Is ISO/IEC 25012?

Published as part of the SQuaRE (Systems and Software Quality Requirements and Evaluation) series under ISO/IEC 25000, it provides a shared vocabulary and structured framework for specifying, evaluating and improving data quality across information systems.

The standard categorizes data quality into 15 distinct characteristics, classified across two perspectives, inherent data quality, which relates to properties of the data itself and system-dependent data quality, which relates to how quality is achieved and maintained within the technology environment where data is stored and used. Organizations across industries, from healthcare and finance to manufacturing and e-commerce, apply ISO/IEC 25012 to define what good data means within their specific operational context and to align data governance programs around measurable quality criteria.

Whether you are implementing a data governance framework, preparing for a regulatory audit, or building the data foundation for an AI or analytics program, ISO/IEC 25012 provides the structural model that makes data quality assessable, comparable and improvable.

ISO/IEC 25012 helps organizations define, measure and improve data quality through a structured model of 15 recognized characteristics - Pacific Certifications


Inherent vs System-Dependent Characteristics

Inherent data quality refers to properties that can be assessed from the data itself, independent of the system in which it resides. These characteristics relate to data domain values, business rules governing those values, relationships between data elements and metadata.

Inherent characteristics are intrinsic to the data and remain relevant regardless of which system processes or stores that data.

System-dependent data quality refers to properties that are achieved and preserved through the capabilities of the computer system environment, including hardware, software and infrastructure components.

These characteristics depend on how the system is designed, configured and maintained and they cannot be assessed from the data alone.

Some characteristics in ISO/IEC 25012 are classified as both inherent and system-dependent, meaning they have dimensions that relate to both the data itself and the system that manages it.

Compliance and confidentiality, for example, have inherent aspects, such as whether data values conform to a regulatory definition, as well as system-dependent aspects, such as whether the system enforces access controls that preserve those values.

Practical Tip: Separate data quality issues caused by the data itself from those caused by the system, because each requires a different control approach.


All 15 Data Quality Characteristics

Inherent Characteristics

  • Accuracy: The degree to which data correctly represents the true value of the intended attribute - both syntactically and semantically. Accurate data reflects real-world facts without distortion or error.

  • Completeness: The degree to which all expected attributes and related entity instances have populated values for a given subject in a specific context of use. This includes both record completeness and attribute completeness.

  • Consistency: The degree to which data is free from contradiction and coherent across records, sources and comparable entities. This covers referential integrity, semantic consistency and format consistency.

  • Credibility: The degree to which data is regarded as true and believable by users. This characteristic encompasses authenticity - the trustworthiness of data origins and attributions.

  • Currentness: The degree to which data is sufficiently up to date for the intended decision or process. Data that was accurate at the time of capture may no longer reflect the current state of the entity it describes.

System-Dependent Characteristics

  • Accessibility: The degree to which data can be retrieved by authorized users and applications in a specific context of use. System uptime, query performance and interface design all affect accessibility.

  • Compliance: The degree to which data adheres to applicable standards, regulations and organizational constraints, including both the data values themselves and the systems that process them.

  • Confidentiality: The degree to which data access and disclosure are controlled and restricted to authorized parties. This characteristic has direct relevance to GDPR, data privacy laws and ISO/IEC 27001 alignment.

  • Efficiency: The degree to which data processing delivers the required performance relative to the resources consumed, covering query response times and data processing throughput.

  • Precision: The degree to which data has the exact or required level of detail - expressed in terms of the number of significant digits, decimal places, or granularity required for the intended use.

  • Traceability: The degree to which data lineage, provenance and history can be audited and understood. Traceability is foundational for regulatory compliance, incident investigation and AI governance.

  • Understandability: The degree to which data is expressed in appropriate language, symbols and units - and accompanied by metadata that makes its meaning clear to intended users.

  • Availability: The degree to which data is accessible and usable when required by authorized users or processes, taking into account system uptime and recovery capabilities.

  • Portability: The degree to which data can be transferred from one system, format, or environment to another without loss of quality or meaning.

  • Recoverability: The degree to which data can be restored to a required quality state following a system failure, corruption event, or disaster scenario.

Both Inherent and System-Dependent

Compliance and confidentiality carry dimensions in both categories. Compliance relates inherently to whether data values meet regulatory definitions and system-dependently to whether the technology environment enforces those requirements. Confidentiality relates inherently to the sensitivity classification of data values and system-dependently to whether the system prevents unauthorized access to those values.

Use the 15 characteristics as a practical checklist for assessing whether data is accurate, complete, consistent, secure, usable and reliable.


ISO 25012 vs ISO 8000

Dimension

ISO/IEC 25012

ISO 8000

Purpose

Defines what data quality characteristics exist

Defines how to verify and exchange quality data

Scope

Structured data in computer systems- all industries

Master data quality and data exchange- industrial and supply chain focus

Output

A classification model for quality characteristics

Requirements for data quality verification and portability

Application

Data governance, ERP evaluation, software quality

Supply chain data, product data management, master data governance

Relationship

Defines the characteristics that ISO 8000 verifies

Provides operational requirements to achieve ISO/IEC 25012 characteristics

Writer’s view: ISO/IEC 25012 explains what good data looks like, while ISO 8000 helps organizations verify and exchange quality data in practice.


Use Cases in ERP and Data Governance

In ERP implementations, whether SAP, Oracle, Microsoft Dynamics, or any comparable platform, data migration from legacy systems is one of the highest-risk phases of the project. ISO/IEC 25012 provides the quality measurement framework that defines acceptance criteria for migrated data.

Accuracy, completeness, consistency and currentness characteristics are used to define data quality rules that migrated records must satisfy before go-live. Organizations that apply ISO/IEC 25012 during ERP migrations report fewer post-go-live data issues, reduced rework costs and faster user adoption.

In data governance programs, ISO/IEC 25012 serves as the reference vocabulary that aligns business stakeholders, data stewards and IT teams around a shared understanding of data quality. Data quality dimensions in the standard map directly to governance policies, for example, credibility maps to authoritative source designation, traceability maps to data lineage requirements and compliance maps to regulatory data handling obligations.

Organizations subject to GDPR, DPDP, CCPA, or sector-specific data regulations use ISO/IEC 25012 to structure their data quality requirements in terms that satisfy both technical and legal audit expectations.

Practical Tip: Apply ISO/IEC 25012 during ERP migration and governance projects to set clear acceptance rules for accuracy, completeness, consistency and traceability.


Implementation Examples

  • Healthcare: A hospital system applies the accuracy, completeness and currentness characteristics to patient records, ensuring that diagnoses, medications and allergy data are correct, fully populated and up to date before clinical decisions are made.

  • Financial services: A bank uses the consistency and traceability characteristics to manage customer identity data across core banking, CRM and compliance systems, ensuring that customer records do not contradict each other and that all data changes are logged with full lineage.

  • Manufacturing: A manufacturer applies portability and compliance characteristics during a system migration, verifying that product master data transferred between ERP platforms retains its structure, meaning and regulatory conformance.

  • E-commerce: A retail platform uses the completeness and understandability characteristics to evaluate product catalog data ensuring that all required attributes are populated and that product descriptions are clear to end consumers across all markets.

  • AI and machine learning: A data science team uses the accuracy, credibility and currentness characteristics to define training data quality requirements ensuring that models are built on data that is factually correct, from trusted sources and current enough to reflect the environment the model will operate in.

Final Remark: ISO/IEC 25012 becomes easier to apply when examples show how data quality controls support healthcare, finance, manufacturing, e-commerce and AI systems.


Audit Readiness

  • A documented data quality policy that references ISO/IEC 25012 as the applied model

  • A data quality scope definition identifying which data domains and systems are covered

  • Defined quality rules and thresholds for each applicable ISO/IEC 25012 characteristic

  • A data quality measurement program with documented metrics and reporting cycles

  • Evidence of data profiling, cleansing and quality improvement activities

  • Data lineage documentation covering key data flows across systems

  • Roles and responsibilities defined for data ownership and stewardship

  • A corrective action process for resolving data quality non-conformances

  • Records of management review of data quality performance trends

Audit readiness is not achieved by documentation alone, auditors expect to see objective evidence of sustained implementation, including measurement records, trend data and records of corrective actions taken in response to quality issues identified through the organization's own monitoring activities.

Audit readiness improves when data quality policies, rules, metrics, lineage records, stewardship roles and corrective actions are supported by real evidence.


ISO/IEC 25012 Certification Cost

For a small technology company or data services provider pursuing ISO/IEC 27001 as the primary certification covering data quality and security, the certification body audit cost is relatively modest. For larger enterprises with complex data environments across multiple business units, geographies, or platforms, audit days and therefore certification cost will be proportionally higher.

Organizations pursuing integrated certification across ISO/IEC 27001, ISO 9001 and ISO/IEC 27701 simultaneously will find integrated audits significantly more cost-efficient than pursuing each certification independently, as overlapping system requirements reduce duplication in audit effort and documentation.

The primary cost variable is audit days, which Pacific Certifications calculates based on employee count, site count and system scope. Any consultancy costs for system development or gap analysis are entirely separate from certification body fees. Pacific Certifications provides transparent, fixed-fee proposals so your organization has full visibility of audit costs before the process begins.

Cost planning should consider data scope, system complexity, employee count, site count, audit scope and whether ISO/IEC 27001, ISO 9001 or ISO/IEC 27701 is included.


ISO 25012 Certification Timeline

This includes 1 to 2 months for gap analysis and documentation development, 2 to 3 months for full system implementation and evidence generation and 2 to 4 weeks for Stage 1 and Stage 2 audits. Certificate issuance follows within 1 to 2 weeks of a successful Stage 2 audit.

For organizations with more complex data environments, multiple platforms, large data volumes, cross-border processing, or regulatory overlaps requiring ISO/IEC 27701 alongside ISO/IEC 27001, the timeline extends to 6 to 9 months. For organizations with significant data quality gaps, where foundational data governance infrastructure needs to be built from the ground up before an audit is viable, the preparation phase alone may take 3 to 4 months.

Starting with a thorough gap analysis, prioritizing the highest-risk data domains and assigning dedicated data stewardship responsibilities from the outset are the most effective ways to keep the certification timeline on track.

A Practical Tip from Pacific Certifications: Organizations can avoid delays by completing gap analysis, data quality rules, stewardship responsibilities and measurement evidence early.


How Pacific Certifications Can Help?

Accredited by ABIS, Pacific Certifications conducts impartial, evidence-based audits against applicable ISO standards in full conformance with ISO/IEC 17021.

Our services for organizations implementing ISO/IEC 25012-aligned programs include:

  • Independent certification audits for ISO/IEC 27001, ISO 9001, ISO/IEC 27701 and ISO/IEC 20000-1

  • Stage 1 and Stage 2 audit execution across single and multi-site data operations

  • Clear, transparent audit reports with conformity findings and certification decisions

  • Issuance of internationally recognized ISO certificates upon successful audit completion

  • Annual surveillance and triennial recertification audits to maintain certificate validity

Pacific Certifications does not provide consultancy, our role is strictly that of an independent auditor, ensuring your certificate carries full credibility with clients, regulators and trade partners in every market you operate in.


Contact Us

To get started with your data quality certification program or initiate your audit, contact us at support@pacificcert.com or +91-8595603096.

For training programs, contact us at trainings@pacificcert.com.

Apply for ISO/IEC 25012 Data Quality Certification
Strengthen data accuracy, consistency and reliability by aligning your data quality practices with ISO/IEC 25012 characteristics for better governance and digital decision-making.

Also read: ISO 8000 and ISO/IEC 25012 data quality standard for digital transformation

Pacific Certifications
ISO/IEC 25012 Data Quality Model

Frequently Asked Questions

What is ISO/IEC 25012?
ISO/IEC 25012 is an international standard that defines a general data quality model for structured data in computer systems. It classifies 15 data quality characteristics across inherent and system-dependent categories, providing a framework for specifying, measuring and improving data quality.
Does ISO/IEC 25012 have its own certification?
ISO/IEC 25012 is a reference model standard and does not carry a standalone third-party certification. Organizations apply it as the data quality framework within certifications such as ISO/IEC 27001, ISO 9001 and ISO/IEC 27701.
What is the difference between inherent and system-dependent data quality?
Inherent data quality refers to properties that can be assessed from the data itself, accuracy, completeness, consistency, credibility and currentness. System-dependent quality refers to properties that depend on the technology environment- accessibility, availability, efficiency, portability and recoverability.
How does ISO/IEC 25012 differ from ISO 8000?
ISO/IEC 25012 defines what data quality characteristics exist and what they mean. ISO 8000 defines how to verify and exchange data that meets those characteristics. The two standards are complementary and are frequently applied together.
Which industries benefit most from ISO/IEC 25012?
ISO/IEC 25012 applies across all industries where structured data is used in decision-making or regulatory compliance including healthcare, financial services, manufacturing, retail, logistics and technology.
Can Pacific Certifications help with ISO/IEC 27001 certification for a data-intensive organization?
Yes. Pacific Certifications conducts ISO/IEC 27001 certification audits for organizations of all sizes and industries, including data service providers, technology companies and enterprises managing complex data environments.
Pacific Certifications

Pacific Certifications

Looking for ISO Certification? Get in touch now!

Pacific Certifications

Pacific Certifications is an independent, internationally recognized certification body providing third-party audit and certification services for management system standards such as ISO 9001, ISO 14001, ISO/IEC 27001, ISO 45001, and other ISO standards. We also provide product certification services and training and personnel certification programs designed to support organizational and professional competence.