ISO/IEC 25012 Data Quality Model: Standard, Characteristics & Certification

What Is ISO/IEC 25012?
Published as part of the SQuaRE (Systems and Software Quality Requirements and Evaluation) series under ISO/IEC 25000, it provides a shared vocabulary and structured framework for specifying, evaluating and improving data quality across information systems.
The standard categorizes data quality into 15 distinct characteristics, classified across two perspectives, inherent data quality, which relates to properties of the data itself and system-dependent data quality, which relates to how quality is achieved and maintained within the technology environment where data is stored and used. Organizations across industries, from healthcare and finance to manufacturing and e-commerce, apply ISO/IEC 25012 to define what good data means within their specific operational context and to align data governance programs around measurable quality criteria.
Whether you are implementing a data governance framework, preparing for a regulatory audit, or building the data foundation for an AI or analytics program, ISO/IEC 25012 provides the structural model that makes data quality assessable, comparable and improvable.
ISO/IEC 25012 helps organizations define, measure and improve data quality through a structured model of 15 recognized characteristics - Pacific Certifications
Inherent vs System-Dependent Characteristics
Inherent data quality refers to properties that can be assessed from the data itself, independent of the system in which it resides. These characteristics relate to data domain values, business rules governing those values, relationships between data elements and metadata.
Inherent characteristics are intrinsic to the data and remain relevant regardless of which system processes or stores that data.
System-dependent data quality refers to properties that are achieved and preserved through the capabilities of the computer system environment, including hardware, software and infrastructure components.
These characteristics depend on how the system is designed, configured and maintained and they cannot be assessed from the data alone.
Some characteristics in ISO/IEC 25012 are classified as both inherent and system-dependent, meaning they have dimensions that relate to both the data itself and the system that manages it.
Compliance and confidentiality, for example, have inherent aspects, such as whether data values conform to a regulatory definition, as well as system-dependent aspects, such as whether the system enforces access controls that preserve those values.
Practical Tip: Separate data quality issues caused by the data itself from those caused by the system, because each requires a different control approach.
All 15 Data Quality Characteristics
Inherent Characteristics
Accuracy: The degree to which data correctly represents the true value of the intended attribute - both syntactically and semantically. Accurate data reflects real-world facts without distortion or error.
Completeness: The degree to which all expected attributes and related entity instances have populated values for a given subject in a specific context of use. This includes both record completeness and attribute completeness.
Consistency: The degree to which data is free from contradiction and coherent across records, sources and comparable entities. This covers referential integrity, semantic consistency and format consistency.
Credibility: The degree to which data is regarded as true and believable by users. This characteristic encompasses authenticity - the trustworthiness of data origins and attributions.
Currentness: The degree to which data is sufficiently up to date for the intended decision or process. Data that was accurate at the time of capture may no longer reflect the current state of the entity it describes.
System-Dependent Characteristics
Accessibility: The degree to which data can be retrieved by authorized users and applications in a specific context of use. System uptime, query performance and interface design all affect accessibility.
Compliance: The degree to which data adheres to applicable standards, regulations and organizational constraints, including both the data values themselves and the systems that process them.
Confidentiality: The degree to which data access and disclosure are controlled and restricted to authorized parties. This characteristic has direct relevance to GDPR, data privacy laws and ISO/IEC 27001 alignment.
Efficiency: The degree to which data processing delivers the required performance relative to the resources consumed, covering query response times and data processing throughput.
Precision: The degree to which data has the exact or required level of detail - expressed in terms of the number of significant digits, decimal places, or granularity required for the intended use.
Traceability: The degree to which data lineage, provenance and history can be audited and understood. Traceability is foundational for regulatory compliance, incident investigation and AI governance.
Understandability: The degree to which data is expressed in appropriate language, symbols and units - and accompanied by metadata that makes its meaning clear to intended users.
Availability: The degree to which data is accessible and usable when required by authorized users or processes, taking into account system uptime and recovery capabilities.
Portability: The degree to which data can be transferred from one system, format, or environment to another without loss of quality or meaning.
Recoverability: The degree to which data can be restored to a required quality state following a system failure, corruption event, or disaster scenario.
Both Inherent and System-Dependent
Compliance and confidentiality carry dimensions in both categories. Compliance relates inherently to whether data values meet regulatory definitions and system-dependently to whether the technology environment enforces those requirements. Confidentiality relates inherently to the sensitivity classification of data values and system-dependently to whether the system prevents unauthorized access to those values.
Use the 15 characteristics as a practical checklist for assessing whether data is accurate, complete, consistent, secure, usable and reliable.
ISO 25012 vs ISO 8000
Writer’s view: ISO/IEC 25012 explains what good data looks like, while ISO 8000 helps organizations verify and exchange quality data in practice.
Use Cases in ERP and Data Governance
In ERP implementations, whether SAP, Oracle, Microsoft Dynamics, or any comparable platform, data migration from legacy systems is one of the highest-risk phases of the project. ISO/IEC 25012 provides the quality measurement framework that defines acceptance criteria for migrated data.
Accuracy, completeness, consistency and currentness characteristics are used to define data quality rules that migrated records must satisfy before go-live. Organizations that apply ISO/IEC 25012 during ERP migrations report fewer post-go-live data issues, reduced rework costs and faster user adoption.
In data governance programs, ISO/IEC 25012 serves as the reference vocabulary that aligns business stakeholders, data stewards and IT teams around a shared understanding of data quality. Data quality dimensions in the standard map directly to governance policies, for example, credibility maps to authoritative source designation, traceability maps to data lineage requirements and compliance maps to regulatory data handling obligations.
Organizations subject to GDPR, DPDP, CCPA, or sector-specific data regulations use ISO/IEC 25012 to structure their data quality requirements in terms that satisfy both technical and legal audit expectations.
Practical Tip: Apply ISO/IEC 25012 during ERP migration and governance projects to set clear acceptance rules for accuracy, completeness, consistency and traceability.
Implementation Examples
Healthcare: A hospital system applies the accuracy, completeness and currentness characteristics to patient records, ensuring that diagnoses, medications and allergy data are correct, fully populated and up to date before clinical decisions are made.
Financial services: A bank uses the consistency and traceability characteristics to manage customer identity data across core banking, CRM and compliance systems, ensuring that customer records do not contradict each other and that all data changes are logged with full lineage.
Manufacturing: A manufacturer applies portability and compliance characteristics during a system migration, verifying that product master data transferred between ERP platforms retains its structure, meaning and regulatory conformance.
E-commerce: A retail platform uses the completeness and understandability characteristics to evaluate product catalog data ensuring that all required attributes are populated and that product descriptions are clear to end consumers across all markets.
AI and machine learning: A data science team uses the accuracy, credibility and currentness characteristics to define training data quality requirements ensuring that models are built on data that is factually correct, from trusted sources and current enough to reflect the environment the model will operate in.
Final Remark: ISO/IEC 25012 becomes easier to apply when examples show how data quality controls support healthcare, finance, manufacturing, e-commerce and AI systems.
Audit Readiness
A documented data quality policy that references ISO/IEC 25012 as the applied model
A data quality scope definition identifying which data domains and systems are covered
Defined quality rules and thresholds for each applicable ISO/IEC 25012 characteristic
A data quality measurement program with documented metrics and reporting cycles
Evidence of data profiling, cleansing and quality improvement activities
Data lineage documentation covering key data flows across systems
Roles and responsibilities defined for data ownership and stewardship
A corrective action process for resolving data quality non-conformances
Records of management review of data quality performance trends
Audit readiness is not achieved by documentation alone, auditors expect to see objective evidence of sustained implementation, including measurement records, trend data and records of corrective actions taken in response to quality issues identified through the organization's own monitoring activities.
Audit readiness improves when data quality policies, rules, metrics, lineage records, stewardship roles and corrective actions are supported by real evidence.
ISO/IEC 25012 Certification Cost
For a small technology company or data services provider pursuing ISO/IEC 27001 as the primary certification covering data quality and security, the certification body audit cost is relatively modest. For larger enterprises with complex data environments across multiple business units, geographies, or platforms, audit days and therefore certification cost will be proportionally higher.
Organizations pursuing integrated certification across ISO/IEC 27001, ISO 9001 and ISO/IEC 27701 simultaneously will find integrated audits significantly more cost-efficient than pursuing each certification independently, as overlapping system requirements reduce duplication in audit effort and documentation.
The primary cost variable is audit days, which Pacific Certifications calculates based on employee count, site count and system scope. Any consultancy costs for system development or gap analysis are entirely separate from certification body fees. Pacific Certifications provides transparent, fixed-fee proposals so your organization has full visibility of audit costs before the process begins.
Cost planning should consider data scope, system complexity, employee count, site count, audit scope and whether ISO/IEC 27001, ISO 9001 or ISO/IEC 27701 is included.
ISO 25012 Certification Timeline
This includes 1 to 2 months for gap analysis and documentation development, 2 to 3 months for full system implementation and evidence generation and 2 to 4 weeks for Stage 1 and Stage 2 audits. Certificate issuance follows within 1 to 2 weeks of a successful Stage 2 audit.
For organizations with more complex data environments, multiple platforms, large data volumes, cross-border processing, or regulatory overlaps requiring ISO/IEC 27701 alongside ISO/IEC 27001, the timeline extends to 6 to 9 months. For organizations with significant data quality gaps, where foundational data governance infrastructure needs to be built from the ground up before an audit is viable, the preparation phase alone may take 3 to 4 months.
Starting with a thorough gap analysis, prioritizing the highest-risk data domains and assigning dedicated data stewardship responsibilities from the outset are the most effective ways to keep the certification timeline on track.
A Practical Tip from Pacific Certifications: Organizations can avoid delays by completing gap analysis, data quality rules, stewardship responsibilities and measurement evidence early.
How Pacific Certifications Can Help?
Accredited by ABIS, Pacific Certifications conducts impartial, evidence-based audits against applicable ISO standards in full conformance with ISO/IEC 17021.
Our services for organizations implementing ISO/IEC 25012-aligned programs include:
Independent certification audits for ISO/IEC 27001, ISO 9001, ISO/IEC 27701 and ISO/IEC 20000-1
Stage 1 and Stage 2 audit execution across single and multi-site data operations
Clear, transparent audit reports with conformity findings and certification decisions
Issuance of internationally recognized ISO certificates upon successful audit completion
Annual surveillance and triennial recertification audits to maintain certificate validity
Pacific Certifications does not provide consultancy, our role is strictly that of an independent auditor, ensuring your certificate carries full credibility with clients, regulators and trade partners in every market you operate in.
Contact Us
To get started with your data quality certification program or initiate your audit, contact us at support@pacificcert.com or +91-8595603096.
For training programs, contact us at trainings@pacificcert.com.
Also read: ISO 8000 and ISO/IEC 25012 data quality standard for digital transformation
