May 12, 2026

Workflow Management for Master Data: How to Make Approvals Fast, Verifiable, and Audit-Proof

Selina Trummer

By Selina Trummer

Product Marketing Manager

16 min read

Share this post

Master data workflow management determines whether a new supplier is added to the ERP system in two days or two weeks—and whether updated bank account information is verified or simply accepted. This article shows you how to design creation, change, and approval processes so that responsibilities are clearly defined, verification is automated, and every change is traceable. It includes a role model, risk classes, a set of KPIs, and a real-world case study.

Key Takeaways

  • Master data workflow management controls who requests, reviews, and approves changes to master data, as well as when those changes are transferred to target systems such as SAP.

  • Errors occur most frequently during creation: In an HBR study, 47% of newly created data records contained at least one critical error.

  • According to Gartner (2026), governance fails more often due to culture than to budget constraints. The recommendation: Embed governance directly into daily workflows.

  • Not every change requires the same level of approval. Risk classes defined per attribute distinguish routine changes from critical changes, such as bank details.

  • The dual-control principle for sensitive attributes serves as a direct safeguard against payment fraud.

  • The GoBD requires that master data changes be traceable and, where applicable, logged with validity information.

  • Success can be measured, for example, by turnaround time, first-time-right rate, return rate, and SLA compliance.

What is Master Data Workflow Management?

Master data workflow management is the rule-based control of all master data creation, modification, lock, and archiving processes through defined roles, validation steps, and approval levels—with comprehensive logging of every decision. It determines who is authorized to request which data, which rules are automatically checked, who provides business-side approval, and when a data record is distributed to the operational systems.

Master data is a company’s long-term core data: customers, suppliers, materials, products, companies, and organizational units. You can find a detailed classification in our Master Data Guide. Unlike transaction data, master data is used by many processes simultaneously. An error during creation therefore carries over into every purchase order, every invoice, and every report.

A master data workflow typically consists of five elements:

  • Trigger: an event such as “new supplier,” “change in bank account information,” or “material being phased out.”

  • Request: a structured form with required fields instead of a free-form email.

  • Automatic validation: validation rules, duplicate checks, and comparison with reference data.

  • Business approval: one or more levels, depending on the risk associated with the change.

  • Distribution and logging: transfer to the Golden Record, distribution to target systems, and an immutable audit trail.

Technically, such processes are often modeled using BPMN 2.0. This notation is an open standard developed by the Object Management Group and standardized as ISO/IEC 19510. The advantage is that both business units and IT teams are reading the same process model.

It is important to draw a distinction. Workflow management for master data is not the same as general workflow automation. A generic ticket system does not know the data record it is approving. A workflow integrated into master data management, on the other hand, sees the data model, the history, and all relationships of the object. It can therefore check whether a new supplier is a duplicate before anyone invests time in the approval process.

Why Workflow Management Is Relevant for Master Data

Master data processes seem unremarkable—until they fail. Five key metrics show why approval processes are not merely an administrative task, but a matter of quality, cost, and control.

KPI

Statement

Source

47 %

of the newly created data records, at least one contained a critical error; only 3% of the data quality scores were “acceptable”

Nagle, Redman, Sammon – HBR, 2017

$12.9 million

average annual cost of poor data quality per organization

Gartner, Research 2020

60 % vs. 40 %

cultural resistance outweighs lack of budget as the main reason for failed governance initiatives (survey of 223 D&A leaders, March 2026)

Gartner, 21.09.2026

$2.77 billion

reported losses from business email compromise in 2024, based on 21,442 complaints

FBI IC3 Annual Report 2024

more than 50 %

of the fraud cases investigated were attributed to missing or circumvented internal controls (1,921 cases)

ACFE, Occupational Fraud 2024

Quality begins at the point of entry.

The 47% figure from the HBR study refers to newly created data records. That is the moment when a workflow kicks in. Validation rules that only take effect in the monthly quality report come too late.

Fraud exploits process gaps.

Business Email Compromise often targets a simple change to master data: A purported supplier reports new bank account information. Without the dual-control principle and reconfirmation, the next payment is diverted. The ACFE data confirms this pattern: Missing or bypassed controls are the most common lever.

Governance fails in day-to-day operations, not in concept.

Gartner explicitly recommends embedding data governance into business workflows and integrating it into day-to-day operations. This is exactly what a master data workflow does: it turns a policy into a process step that cannot be skipped.

Compliance requires traceability.

The GoBD requires that changes be made in such a way that “both the original content and the fact that changes were made remain recognizable.” For master data, it explicitly mentions version history with validity information. For personal master data, the GDPR also applies: Data must be factually accurate, and data controllers must be able to demonstrate compliance.

The Four Root Causes of Slow and Error-Prone Master Data Processes

When master data approvals take too long or incorrect data slips through, it’s rarely the fault of any one individual. Most often, the same four structural causes are at play.

Responsibility with No Ownership

In many companies, a supplier master record “belongs” to no one. Purchasing creates it, accounting adds payment terms, and quality management maintains certificates. Everyone is responsible for their own fields, but no one is responsible for the record as a whole. Without a designated data owner and data steward, every conflict ends up in an email loop.

Checking at the Wrong Stage

Many organizations check data quality downstream: via reports, spot checks, or data cleansing projects. This is costly because by that point, the error has already made its way into purchase orders and invoices. The check belongs at the point of entry—that is, in the request itself. Our guide to data quality describes how to systematically measure and resolve downstream quality issues.

Approval via Media Discontinuity

A request arrives via email, approval comes by phone, and the data is entered into the ERP system via copy-and-paste. Every media break costs time and creates errors. Above all, it leaves no verifiable record. Anyone who needs to prove during an audit who approved a bank account and when will then have to search through their inbox.

One workflow for everything

The opposite is just as harmful: Every change goes through the same three approval stages—whether it’s a phone number or an IBAN being changed. The result is overburdened approvers, backlogs, and people finding ways around the system. If you apply the same strict standards to everything, you end up not checking anything thoroughly.

It’s not a tool problem—it’s a responsibility problem

The obvious reaction to slow approvals is to look for a better tool. But a workflow tool only automates what has already been decided. If it’s unclear who approves a change, the tool simply automates that ambiguity.

A master data workflow is responsibility codified.
Each stage answers a question: Who is authorized to submit a request? Who performs the technical review? Who bears the risk? Who is authorized to override the decision in exceptional cases? Only once these questions are answered is technical modeling worthwhile.

The latest Gartner survey supports this view. Cultural resistance carries more weight than a lack of budget. Gartner also recommends establishing governance as a shared responsibility between business and technology—not as a purely IT task.

For Heads of Data and Governance Leads, this means: The first workshop should not focus on a tool demo, but on the role model. Our article on the role of data administration in organizational data management describes which roles in data management have proven effective.

Approach: Setting Up Master Data Workflows in Seven Steps

The following procedure has proven effective for master data workflow management. It starts with the events, not the software.

Step 1: Take Inventory of Events and Data Objects

For each data domain, list all events that trigger a workflow: creation, modification, extension to a new company or plant, lock, and archiving. Note how often each event occurs per month. This shows where automation has the greatest impact.

Step 2: Classify Attributes into Risk Categories

It is not the data record that determines approval, but the attribute that has been changed. A phone number is non-critical; bank account information is highly critical. The following table shows a typical pattern. The turnaround times are industry benchmarks for guidance, not standards.

Risk Class

Example Attributes

Approval

Estimated Processing Time

Low

Contact Person, Phone Number, Descriptive Text

Automatic verification, no manual approval

Immediate

Medium

Payment Terms, Purchasing Organization, Product Group

Data Steward

1 business day

High

Bank Account Information, Tax ID, VAT ID, Credit Limit

Dual-Control Principle: Steward plus Data Owner, confirmation from the partner

2 business days

Critical

Organizational structure, account determination, valuation classes

Data owner plus business approval (e.g., Controlling, Legal)

By agreement

Step 3: Define the Role Model

A streamlined role model is sufficient for most master data workflows:

  • The requester submits the change request and provides the supporting documents.

  • The data steward performs a business-related review, cleans up the data, and clarifies any questions.

  • The data owner is responsible for the domain and approves critical changes.

  • An approver from the business unit (e.g., Controlling, Compliance) is involved only for defined attributes.

The key is the separation of duties: The person who submits a request must not be the one to approve that same change. The system must technically enforce this, not merely recommend it.

Step 4: Move Validation to the Point of Entry

Any rule that can be checked automatically belongs in the request: required fields, format checks (e.g., IBAN check digit), duplicate checks against the golden record, and comparisons with reference lists. The data steward should only check what a machine cannot determine.

Step 5: Define Routing, SLAs, and Escalation

Set a service-level time for each approval stage. If it expires, the workflow automatically escalates to a substitute or the next level. Parallel approvals—such as purchasing and accounting simultaneously—significantly shorten turnaround time compared to sequential chains.

Step 6: Ensure an audit trail and historical data retention

Every action is logged: who, when, what, old value, new value, and reason. Master data is versioned with validity periods, ensuring that reports based on specific cut-off dates remain possible. This meets the historical data retention requirements of the GoBD and answers any audit question in minutes rather than days.

Step 7: Measure and Refine Workflow KPIs

Without key performance indicators, workflow optimization remains a matter of gut feeling. The following KPIs form a robust foundation:

KPI

Definition

Was sie verrät

Durchlaufzeit

Zeit von Antrag bis Verteilung ins Zielsystem

Engpässe im Routing

First-Time-Right-Quote

Anteil der Anträge ohne Rückfrage

Qualität der Antragsmasken und Pflichtfelder

Rückläuferquote

Anteil der Anträge, die zurück an den Requester gehen

Unklare Regeln oder Schulungsbedarf

SLA-Einhaltung

Anteil der Freigaben innerhalb der Zielzeit

Überlastete Rollen, fehlende Vertretungen

Automatisierungsgrad

Anteil der Änderungen ohne manuelle Freigabe

Wirkung der Risikoklassen

Stop Guessing. Start Governing.

Use this self-assessment to find out how robust your data foundation really is. With 10 targeted questions, this checklist shows you where you stand today—and where your greatest leverage for sound data governance lies.

  • 10-Question Checklist to Assess Your Governance Maturity

  • A field-tested 90-day plan you can start using right away

  • 100% free and independent

Best Practices für Stammdaten-Workflows

Mit einem hochfrequenten Prozess starten.
Lieferanten- oder Materialanlage kommen in den meisten Unternehmen täglich vor. Hier zeigt sich der Nutzen schnell, und die Organisation lernt das neue Vorgehen an einem vertrauten Fall.

Den Antrag so gut machen, dass Rückfragen überflüssig werden.
Die meisten Verzögerungen entstehen nicht bei der Freigabe, sondern bei der Klärung unvollständiger Anträge. Kontextabhängige Pflichtfelder und Vorbelegungen aus dem Golden Record senken die Rückläuferquote.

Bankdaten immer außerhalb des Kanals bestätigen.
Kommt eine Änderungsmeldung per E-Mail, erfolgt die Rückbestätigung über eine bereits hinterlegte Telefonnummer – nie über die Kontaktdaten in derselben Nachricht. Der Workflow dokumentiert diesen Schritt als Pflichtaufgabe.

Vertretungen verbindlich hinterlegen.
Ein Workflow, der im Urlaub des Data Owners stehen bleibt, verliert schnell die Akzeptanz. Vertretungsregeln gehören in die Workflow-Konfiguration, nicht in die Abwesenheitsnotiz.

Fachbereiche modellieren lassen.
Wenn Prozessverantwortliche Workflows selbst anpassen können, bleibt das Modell nah an der Realität.

Workflows versionieren.
Auch der Prozess selbst ändert sich. Dokumentieren Sie, welche Workflow-Version zu welchem Zeitpunkt galt. Im Audit zählt nicht nur, was freigegeben wurde, sondern nach welcher Regel.

Vier Ansätze für Stammdaten-Workflows

Unternehmen steuern Stammdatenfreigaben heute meist auf eine von vier Arten. Die Tabelle vergleicht sie entlang der Kriterien, die für Governance Leads zählen.

Kriterium

E-Mail und Excel

ERP-Standard-Workflow

Generische BPM- oder Ticket-Lösung

MDM-integrierter Workflow

Kenntnis des Datenmodells

keine

nur für das eigene System

keine, nur Formulardaten

vollständig, domänenübergreifend

Validierung beim Antrag

manuell

systemspezifische Prüfungen

eingeschränkt, aufwendig zu pflegen

Regeln, Dubletten- und Referenzprüfung am Golden Record

Risikobasierte Freigabe pro Attribut

nicht möglich

teilweise, oft mit Customizing

möglich, aber ohne Datenkontext

konfigurierbar pro Attribut

Audit-Trail

verstreut in Postfächern

für das eigene System

Prozessprotokoll, getrennt von den Daten

Prozess- und Datenhistorie in einem

Historisierung mit Gültigkeiten

nicht vorhanden

eingeschränkt

nicht vorhanden

stichtagsgenau

Verteilung an mehrere Zielsysteme

manuell

nur eigenes System

über zusätzliche Integration

zentral über Schnittstellen

Geeignet für

Kleinstvolumen

Ein-System-Landschaften

allgemeine Genehmigungen

heterogene Landschaften mit mehreren Domänen

Die Tabelle zeigt ein klares Muster: Je heterogener die Systemlandschaft, desto wichtiger wird es, dass Workflow und Datenmodell an einem Ort liegen. Genau diesen Ansatz verfolgt der Goldright Agile Data Manager.

So setzt der Goldright Agile Data Manager Stammdaten-Workflows um

Der Agile Data Manager ist die Multi-Domain-MDM-Plattform der Goldright Enterprise Suite. Er führt Stammdaten aus isolierten Quellen zu einem validierten Golden Record zusammen – und steuert auf genau diesem Datenbestand auch die Pflege- und Freigabeprozesse. Workflow und Daten liegen damit nicht in zwei Systemen, sondern in einem.

Business Process Engine in BPMN.
Die Business Process Engine des Agile Data Manager steuert und automatisiert Datenpflege- und Freigabe-Workflows auf Basis von BPMN. Der Workflow, den Fachbereich und IT im Workshop entwerfen, wird damit direkt ausführbar – ohne Übersetzung in ein separates Ticketsystem.

Mehrstufige Freigaben und Vier-Augen-Prinzip.
Freigabestufen lassen sich nach Risiko staffeln. Routineänderungen durchlaufen eine schlanke Prüfung, sensible Attribute wie Bankverbindungen oder Steuernummern das Vier-Augen-Prinzip. So wird das Risikoklassen-Modell aus Schritt 2 zur technisch durchgesetzten Regel.

Integrierte Governance.
Ownership und Verantwortlichkeiten werden zentral in der Plattform geregelt. Das Berechtigungsmodell der Enterprise Suite greift bis auf die Ebene einzelner Datenobjekte und Attribute. Wer beantragen, prüfen oder freigeben darf, ist damit keine Absprache mehr, sondern Konfiguration.

Freigaben mit vollem Datenkontext.
Weil der Workflow auf dem Golden Record läuft, sehen Data Steward und Data Owner nicht nur ein Formular, sondern den Datensatz mit seinen Beziehungen und seiner Herkunft. Datenbereinigung und Abgleich werden automatisiert, die Data Lineage bleibt lückenlos nachvollziehbar.

Zeitstempel-Historie und Audit-Sicherheit.
Jede Änderung wird dokumentiert und historisiert. Die Zeitstempel-Historie ermöglicht stichtagsbezogene Auswertungen – die technische Antwort auf die GoBD-Anforderung, Stammdaten mit Gültigkeitsangaben zu historisieren.

Verteilung über konfigurierbare APIs.
Freigegebene Daten fließen über bidirektionale Schnittstellen in ERP-, CRM- und BI-Systeme. Die Enterprise Suite ist auch im SAP Store verfügbar. Das Abtippen freigegebener Daten ins Zielsystem entfällt.

KI unter denselben Regeln.
Über den AI Assistant und die native MCP-Integration greifen KI-Anwendungen auf den Golden Record zu – berechtigungsgeprüft und im Audit-Trail dokumentiert. KI wird so Teil des kontrollierten Prozesses statt eines Umwegs daran vorbei.

Die folgende Übersicht ordnet die Anforderungen aus dem Lösungsansatz den Funktionen des Agile Data Manager zu:

Anforderung aus dem Lösungsansatz

Funktion im Agile Data Manager

Wirkung im Workflow

Ereignisse und Datenobjekte inventarisieren

Multi-Domain-Datenmodell

Alle Domänen und Auslöser auf einer Plattform

Attribute in Risikoklassen einteilen

Mehrstufige Freigaben, Vier-Augen-Prinzip

Strenge Prüfung nur dort, wo das Risiko liegt

Rollenmodell festlegen

Integrierte Governance, Berechtigungen bis auf Attributebene

Funktionstrennung wird technisch durchgesetzt

Validierung an den Point of Entry verlegen

Golden Record, automatisierte Bereinigung und Abgleich

Freigeber entscheiden mit vollem Datenkontext

Routing festlegen

Business Process Engine (BPMN)

Prozessmodell ist direkt ausführbar

Audit-Trail und Historisierung sicherstellen

Zeitstempel-Historie, Data Lineage

Jede Änderung stichtagsgenau nachvollziehbar

Verteilung an Zielsysteme

Konfigurierbare, bidirektionale APIs

Keine manuelle Übertragung ins ERP

Praxis-Case: Materialanlage in einem Maschinenbau-Unternehmen

Anonymisiertes Projektmuster aus der MDM-Praxis.

Ausgangslage

Ein mittelständischer Maschinenbauer mit mehreren Werken legt jede Woche neue Materialstammsätze an. Die Konstruktion startet den Prozess per Excel-Vorlage. Einkauf, Arbeitsvorbereitung, Controlling und Vertrieb ergänzen nacheinander ihre Sichten. Jede Abteilung wartet auf die vorherige. Unvollständige Vorlagen gehen per E-Mail zurück, Dubletten fallen erst beim Bestellen auf.

Diagnose

Alle vier Wurzelursachen sind sichtbar. Niemand ist für den Materialstamm als Ganzes verantwortlich. Die Prüfung erfolgt nachgelagert. Jede Übergabe ist ein Medienbruch. Und jedes Material durchläuft dieselbe Kette, egal ob Normteil oder sicherheitsrelevante Baugruppe. Inkonsistente Materialstammdaten sind in der Fertigungsindustrie ein typischer Engpass für Bedarfsplanung und Produktion.

Umsetzung mit dem Agile Data Manager

Das Projektteam definiert zuerst das Rollenmodell: ein Data Owner für die Domäne Material, ein Data Steward je Werk. Rollen und Berechtigungen werden in der integrierten Governance des Agile Data Manager hinterlegt. Die Excel-Vorlage wird durch einen Workflow ersetzt, der in der Business Process Engine als BPMN-Prozess modelliert ist. Alle Fachbereiche ergänzen ihre Sichten im selben Workflow direkt am Golden Record, statt Dateien weiterzureichen. Die Freigabe ist nach Risiko gestaffelt: Normteile durchlaufen eine Stufe, sicherheitsrelevante Baugruppen das Vier-Augen-Prinzip mit zusätzlicher Freigabe durch die Qualitätssicherung. Freigegebene Materialien werden über die konfigurierbaren APIs an das ERP-System übergeben.

Ergebnis

Jede Freigabe ist in der Zeitstempel-Historie nachvollziehbar dokumentiert. Rückfragen werden im Workflow statt im Postfach geklärt. Dubletten werden am Golden Record sichtbar, bevor ein Material bestellt wird. Und der Materialstamm liegt als Single Source of Truth für alle Werke vor. Wichtiger als jede Einzelzahl: Das Unternehmen misst nun Durchlaufzeit und First-Time-Right-Quote und kann gezielt nachschärfen.

Übertragbarkeit

Dasselbe Muster funktioniert für Lieferantenanlage, Kundenstammdaten oder die Pflege von Organisationsstrukturen. Wie wichtig saubere Materialdaten für den operativen Betrieb sind, zeigt unser Beitrag zu Produktstammdaten.

Fallstricke: Was bei Stammdaten-Workflows schiefgeht

Den Ist-Prozess eins zu eins digitalisieren.
Wer die bestehende E-Mail-Kette in ein Workflow-Tool überträgt, erhält eine schnellere Version eines schlechten Prozesses. Hinterfragen Sie jede Stufe: Welches Risiko deckt sie ab?

Zu viele Freigabestufen.
Jede zusätzliche Stufe verlängert die Durchlaufzeit und verteilt Verantwortung. Drei Freigaben bedeuten oft, dass sich jeder auf die anderen beiden verlässt.

Notfall-Bypass ohne Kontrolle.
Eilige Fälle gibt es immer. Wenn der Bypass aber nicht protokolliert und nachträglich geprüft wird, wird er zur Hintertür. Die ACFE-Zahlen zeigen, wie oft umgangene Kontrollen der Auslöser von Schäden sind.

Workflow ohne Datenkontext.
Ein Freigeber, der nur ein Formular sieht, kann nicht beurteilen, ob der „neue” Lieferant schon unter anderem Namen existiert. Zeigen Sie im Freigabeschritt die Historie und verwandte Datensätze an.

Fehlende Zielsysteme im Blick.
Ein perfekt freigegebener Datensatz nützt wenig, wenn er manuell ins ERP übertragen wird. Die Verteilung gehört zum Workflow.

KI ohne Governance.
Gartner erwartet, dass GenAI die Time-to-Value von Governance- und MDM-Programmen bis 2027 um 40 % beschleunigt. KI-Vorschläge für Klassifizierung oder Dublettenerkennung sind wertvoll – sie gehören aber als Prüfschritt in den Workflow, nicht als ungeprüfte Direktänderung. Für Hochrisiko-KI verlangt der EU AI Act ohnehin dokumentierte Datenaufbereitungsschritte wie Bereinigung, Aktualisierung und Anreicherung.

Stop Guessing. Start Governing.

Use this self-assessment to find out how robust your data foundation really is. With 10 targeted questions, this checklist shows you where you stand today—and where your greatest leverage for sound data governance lies.

  • 10-Question Checklist to Assess Your Governance Maturity

  • A field-tested 90-day plan you can start using right away

  • 100% free and independent

Fazit: Workflow Management für Stammdaten ist gelebte Governance

Workflow Management für Stammdaten ist kein Verwaltungsthema. Es ist der Ort, an dem Governance-Richtlinien zum ersten Mal auf den Arbeitsalltag treffen. Hier entscheidet sich, ob Qualitätsregeln greifen, bevor ein Fehler entsteht, ob kritische Änderungen wie Bankdaten wirksam kontrolliert werden und ob jede Entscheidung im Audit belegbar ist.

Die Datenlage ist eindeutig. Fast die Hälfte neu erstellter Datensätze enthält kritische Fehler. Betrug nutzt fehlende oder umgangene Kontrollen. Und Governance scheitert häufiger an Kultur als an Budget – weshalb Gartner empfiehlt, sie direkt in die Workflows einzubetten.

Der Weg dorthin beginnt nicht mit einem Tool, sondern mit Verantwortung. Wer Rollen klärt, Attribute nach Risiko einteilt, die Prüfung an den Point of Entry verlegt und die richtigen KPIs misst, macht Freigaben gleichzeitig schneller und sicherer. Ein Workflow, der direkt auf dem Golden Record arbeitet, schließt die Lücke zwischen Prozess und Daten: Jede Freigabe sieht den vollständigen Kontext, jede Änderung wird historisiert, jede Verteilung erfolgt zentral.

Unternehmen, die ihre Stammdaten-Workflows so aufsetzen, schaffen mehr als Effizienz. Sie schaffen ein belastbares Fundament für Compliance, für Automatisierung und für KI-Anwendungen, die auf verlässliche Daten angewiesen sind.

Ihr nächster Schritt: Prüfen Sie mit dem Governance-Reifegrad-Check, wie weit Ihre Rollen, Freigaben und Kontrollen heute reichen. Oder sprechen Sie mit uns darüber, wie der Agile Data Manager Ihre Stammdaten-Workflows abbildet.

Frequently Asked Questions

A master data workflow is a defined, system-supported process for creating, modifying, locking, or archiving master data. It specifies who initiates the process, which rules are automatically checked, who approves the data, and when the data record is distributed to target systems. Every step is logged.
Master data maintenance refers to the ongoing process of entering, updating, and cleaning up data. Workflow management is the framework that governs this process: It defines the roles, sequence, approvals, and documentation for these activities.
Start with a high-frequency process, such as supplier or material creation. First, define roles and risk classes, then set up the request with automated checks. Measure turnaround time and the first-time-right rate from the very beginning.
At least three: a requester who submits the request, a data steward who performs a business-side review, and a data owner who is responsible for the data domain and approves critical changes. For certain attributes, additional business approvers—such as those from Controlling or Compliance—are also involved.
The Agile Data Manager controls maintenance and approval workflows via a BPMN-based business process engine—directly on the Golden Record. Approvals can be configured in multiple stages and according to the dual-control principle; roles and permissions are managed through the integrated governance system; and the timestamp history documents every change with precise effective dates. Approved data is transferred to ERP, CRM, and BI systems.
The GoBD requires that the original content and the fact that a change has been made remain identifiable. When master data is changed, the unambiguous meaning must be preserved in the transaction data; if necessary, master data must be archived with validity information. Furthermore, the change history must not be alterable retroactively (Rz. 111).
In a single-system environment, the answer is often yes. However, as soon as master data is used across multiple systems—ERP, CRM, PLM, HR—the ERP workflow lacks a cross-domain perspective. A workflow integrated with MDM validates data against the golden record and distributes it centrally to all target systems.
That depends on the risk class. The following are generally accepted industry guidelines: non-critical changes should be approved immediately and automatically; moderate changes within one business day; and critical changes within two business days. It is essential that SLAs be defined and measured.
Whenever a change has direct financial or legal implications—such as with bank account information, tax ID numbers, credit limits, or corporate structures. For bank account information, additional confirmation should be obtained through an independent channel.
Common metrics include the duplicate rate, the completeness of critical data fields, timeliness (the time between a change and system synchronization), the number of manual corrections, and business-impact metrics such as reporting time or the order error rate. It is crucial to collect these metrics as a baseline in Step 1 of the framework. This is the only way to demonstrate the impact of subsequent measures—an issue described in Chapter 14 as a common weakness.
AI can suggest classifications, detect duplicates, and flag anomalies. However, it does not replace the approval process. It makes sense to include AI suggestions as a separate verification step in the workflow so that every data entry remains traceable.

Quellenverzeichnis

ACFE – Association of Certified Fraud Examiners: Occupational Fraud 2024: A Report to the Nations - acfe.com

Bundesministerium der Finanzen: GoBD – BMF-Schreiben vom 28.11.2019, Rz. 58 und 111 - PDF

Europäische Union: Verordnung (EU) 2016/679 (DSGVO), Art. 5. - eur-lex.europa.eu

Europäische Union: Verordnung (EU) 2024/1689 (AI Act), Art. 10. - artificialintelligenceact.eu

FBI Internet Crime Complaint Center: 2024 IC3 Annual Report, 2025. - ic3.gov

Gartner: Gartner Predicts 60% of Organizations That Ignore Data Governance Culture Challenges Will Fail to Govern AI Successfully by 2027, Pressemitteilung - gartner.com

Gartner: Gartner Predicts 80% of D&A Governance Initiatives Will Fail by 2027 - gartner.com

Gartner: Data Quality: Why It Matters and How to Achieve It (Research 2020) - gartner.com

Nagle, T.; Redman, T. C.; Sammon, D.: Only 3% of Companies’ Data Meets Basic Quality Standards, Harvard Business Review - hbr.org

Object Management Group: Business Process Model and Notation (BPMN) 2.0.2, ISO/IEC 19510. - omg.org