Advanced Performance Management · Technology and information systems
Data Quality, Governance and Cyber Risks in ACCA APM
Updated 11 October 2026 · Fact-checked
Data quality means information is accurate, complete, timely and fit for decisions. Governance sets who owns data and how it is protected and used. Cyber risks threaten its confidentiality, integrity and availability. In APM, you identify the risk in the scenario, assess its impact, then recommend controls and weigh costs against benefits.
Understand Data Quality, Governance and Cyber Risks
Performance management relies on data. If the data is wrong, the measures, reports and decisions built on it are wrong too. Data quality is about whether data is fit for its purpose. Good data is accurate, complete, consistent, timely, relevant and valid. Poor data leads to bad pricing, wrong targets and misleading KPIs.
Data governance is the set of policies, roles and processes that control how data is collected, stored, used and shared. It answers simple questions. Who owns this data? Who may change it? How long is it kept? Who can see it? Good governance gives the board confidence in the numbers and helps the company meet privacy law.
Security is often explained with three aims, the CIA triad. Confidentiality means only authorised people see data. Integrity means data is not altered improperly or by mistake. Availability means data and systems are there when needed. Cyber risks include hacking, malware, ransomware, phishing, insider misuse and denial-of-service attacks. Weak passwords, unpatched software, poor staff training and unsecured third-party suppliers make these worse.
Privacy and ethics matter when firms use personal data or big data. Issues include consent, collecting more than is needed, using data for a purpose people did not agree to, bias in algorithms, lack of transparency, and profiling customers or staff unfairly. Laws on data protection differ by country, so a global business must manage several regimes. In the exam, refer to the principles rather than quoting specific laws unless the scenario gives them.
New information systems bring their own risks and costs. Costs include hardware, software, licences, implementation, data migration, training, disruption and ongoing support. Risks include overruns, delays, staff resistance, poor fit with needs, data lost in migration and new security gaps. Benefits include faster and better information, lower processing costs and better decisions. Some benefits are hard to quantify, so you must judge them and not ignore them.
Key rules to remember
- CIA triad
- Security = Confidentiality + Integrity + Availability
- Use it as a checklist when a scenario describes a data breach or system failure. Say which element is hit.
- Data quality attributes
- Accurate, Complete, Consistent, Timely, Relevant, Valid
- Use these to assess whether information is fit for purpose. Name the attribute that fails in the scenario.
- Net benefit of a new system
- Net benefit = Total benefits − Total costs (compare on a discounted basis where cash flows span several years)
- Include one-off costs such as migration and training plus running costs. Add qualitative benefits and risks separately.
- Risk exposure
- Risk exposure = Likelihood × Impact
- A qualitative guide for ranking risks. Use numbers only if the question gives them.
How to solve Data Quality, Governance and Cyber Risks questions
Use this method for any question on data quality, governance, cyber risk or system implementation.
- 1Read the requirement and note the verb (identify, assess, recommend, evaluate). It sets the depth you need.
- 2Pick out the facts in the scenario: type of data, who uses it, systems, weaknesses, and any breach or complaint.
- 3Name the issue using a theory label, such as a failed data quality attribute, a CIA element, or a privacy or ethics principle.
- 4Explain the impact on the business in the scenario: decisions, cost, reputation, regulation, customers or performance measures.
- 5Recommend specific controls or actions, such as access controls, encryption, training, data ownership roles, audits, or phased implementation.
- 6Weigh costs against benefits, including non-financial factors, and point out the limits of the evidence.
- 7Finish with a clear conclusion or recommendation that answers the requirement, in the style asked (report, email, memo).
Quickest way: Issue, impact, action
When to use it: Use this when time is short, or for a 5 to 10 mark part of a longer question.
- List the issues the scenario shows in a few words each.
- For each issue, write one sentence of impact tied to the company.
- For each impact, write one practical action.
- Add one line on cost versus benefit or on ethics if the requirement mentions it.
- Check you have one point per mark available.
Common mistakes in Data Quality, Governance and Cyber Risks
Writing a generic list of cyber threats with no link to the scenario.
Students recall a memorised list and write it out to fill space.
Fix: Choose only the threats the scenario supports, quote the facts, and explain the effect on that business.
Treating data quality and data security as the same thing.
Both sound like 'data problems'.
Fix: Quality is about fitness for use. Security is about protection. Name which one you are discussing and use the right framework.
Ignoring ethics and privacy when the scenario mentions customer or staff data.
Students focus on technical controls and forget professional judgement.
Fix: Mention consent, purpose, transparency, fairness and bias. Say what the firm should do to act responsibly.
Evaluating a new system using only purchase cost.
It is the easiest figure to find.
Fix: Include migration, training, disruption, support and risks. Add benefits that are hard to measure and comment on them.
Recommending controls without saying what they cost or how they help.
Students think any security measure is automatically good.
Fix: Link each control to a risk and consider whether the cost is proportionate to the risk reduced.
Giving a one-sided answer that says the new system is simply good or bad.
Students fear sitting on the fence.
Fix: Balance both sides, then make a clear recommendation with conditions, such as a pilot or phased roll-out.
Worked examples
Example 1
A retail chain collects customer purchase and location data through its loyalty app. Reports show inconsistent customer records across regions, and a supplier with access to the data was recently hacked. The finance director asks you to explain the data quality and governance problems and recommend actions. (10 marks)
Show the solution
- Issues: customer records are inconsistent, so the data fails the consistency attribute and probably accuracy. A supplier breach threatens confidentiality.
- Impact of poor quality: marketing and sales analysis by region will be unreliable, so targets and KPIs built on it may mislead managers.
- Impact of the breach: customer personal and location data may be exposed. This risks regulatory action, loss of trust and compensation costs.
- Governance gap: nobody seems to own the customer data or set common standards across regions. Supplier access appears poorly controlled.
- Action on quality: appoint data owners, set one common data standard, run cleansing and validation checks at entry, and audit regularly.
- Action on security: limit supplier access to what is needed, require security standards in contracts, encrypt data, monitor access and test an incident response plan.
- Ethics: collect only data needed, tell customers how it is used, and get clear consent for location tracking.
- Cost and benefit: these steps cost money and staff time, but they are small compared with the possible losses from a major breach and from poor decisions.
Answer: The firm has a data quality problem (inconsistent, possibly inaccurate records) and a governance and security problem (unclear ownership, weak supplier control). Fix them with data owners, common standards, validation, tighter supplier access, encryption, monitoring and transparent, consent-based use of personal data. The cost is justified by the reduced risk and better decisions.
Example 2
A manufacturer plans a new integrated information system. Estimated one-off costs are $900,000 and annual running costs are $150,000. It expects annual savings and extra contribution of $400,000 for each of 4 years. Ignoring discounting, evaluate the financial case and comment on other factors. (8 marks)
Show the solution
- Total benefits over 4 years = $400,000 × 4 = $1,600,000.
- Total running costs over 4 years = $150,000 × 4 = $600,000.
- Total costs = $900,000 + $600,000 = $1,500,000.
- Net benefit = $1,600,000 − $1,500,000 = $100,000, undiscounted.
- Comment: the margin is thin. Discounting would cut the value of later benefits and the one-off cost falls up front, so the net present value could be negative. Calculate it with the company's cost of capital before deciding.
- Risks: overruns, delays, data migration errors, staff resistance and new security gaps could easily erase a $100,000 margin.
- Non-financial benefits: better information quality, faster reporting and better decisions, but these are hard to quantify and may be overstated.
- Recommendation: do not approve yet. Test the estimates, run a discounted appraisal and sensitivity analysis, and consider a phased implementation or pilot.
Answer: Undiscounted net benefit is $100,000 ($1,600,000 − $1,500,000). That is marginal, and discounting could make it negative. Given implementation risks and uncertain qualitative benefits, do a discounted appraisal with sensitivity analysis and consider a phased roll-out before approving.
Exam tips
- Tie every point to a fact in the scenario. Generic security lists earn few marks.
- Use a framework label (CIA, data quality attributes) to structure your answer, then apply it. It also helps the markers follow you.
- When the question mentions personal data or big data, add an ethics point. It often separates good answers from average ones.
- For system evaluation, show both numbers and judgement. Calculate what you can, then discuss risks and qualitative factors.
- Earn professional skills marks by using the requested format, giving a clear recommendation, and showing commercial awareness of cost versus risk.
Practice questions from Technology and information systems
- Marlow Telecom analyses its customer database to explain why 12% of customers cancelled their contracts last quarter, by examining usage pat…
- Halden Logistics is considering using a permissioned blockchain shared with its suppliers, customers and customs agents to record shipment e…
- Harbour Foods analyses scanner data and finds that sales of barbecue charcoal and a particular lager are strongly correlated across stores, …
- Brightwell Bank uses a machine learning model to score loan applicants, and the score feeds into a sales team's bonus scheme. An internal re…
- Castellan Pharma plans to use a data lake for performance analytics drawing on sales, R&D and HR data. The CFO wants clear ownership of each…
Data Quality, Governance and Cyber Risks in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Data Quality, Governance and Cyber Risks: frequently asked questions
What is the difference between data quality and data governance?
Data quality describes how good the data is, for example whether it is accurate and timely. Data governance is the framework of policies, roles and controls that keeps it that way. Good governance is a main way of achieving good quality.
How should I answer a cyber security question in APM?
Identify the threats the scenario shows, say which part of the CIA triad is affected, and explain the business impact. Then recommend specific controls and comment on their cost and practicality.
What ethical issues come up with big data?
Typical issues are consent, privacy, using data for a purpose people did not agree to, bias in algorithms, lack of transparency and unfair profiling. State the issue, who is harmed, and what the firm should do about it.
How do I evaluate the costs and benefits of a new information system?
List the one-off and running costs, then the quantifiable benefits, and compare them, discounting if cash flows span several years. Add risks and qualitative benefits, then give a reasoned recommendation.