Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation
Research Article  ·  Published: 21 July 2026
Issue cover
Journal of Reliable and Secure Computing
Volume 2, Issue 3, 2026: 164-178
Research Article Open Access

Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation

1 Department of Business Administration, Dongshin University, Jeollanam-do 58245, Republic of Korea
* Corresponding Author: Fang Sun, [email protected]
Volume 2, Issue 3

Article Information

Abstract

Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors.

Graphical Abstract

Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation

Keywords

secure data governance AI-driven corporate digital transformation trustworthy AI cybersecurity privacy-preserving computation compliance framework model security

Data Availability Statement

Data will be made available on request.

Funding

This work was supported without any funding.

Conflicts of Interest

The author declares no conflicts of interest.

AI Use Statement

The author declares that no generative AI was used in the preparation of this manuscript.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Verhoef, P. C., Broekhuizen, T., Bart, Y., Bhattacharya, A., Dong, J. Q., Fabian, N., & Haenlein, M. (2021). Digital transformation: A multidisciplinary reflection and research agenda. Journal of business research, 122, 889-901.
    [CrossRef] [Google Scholar]
  2. Bharadwaj, A., El Sawy, O. A., Pavlou, P. A., & Venkatraman, N. V. (2013). Digital business strategy: toward a next generation of insights. MIS quarterly, 37(2), 471-482.
    [CrossRef] [Google Scholar]
  3. Fitzgerald, M., Kruschwitz, N., Bonnet, D., & Welch, M. (2013). Embracing digital technology: A new strategic imperative. MIT sloan management review, 55(2), 1. https://sloanreview.mit.edu/projects/scholars/embracing-digital-technology/
    [Google Scholar]
  4. European Parliament and Council. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
    [Google Scholar]
  5. European Parliament and Council. (2022). Regulation (EU) 2022/868 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act). Official Journal of the European Union. http://data.europa.eu/eli/reg/2022/868/oj
    [Google Scholar]
  6. European Parliament and Council. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. http://data.europa.eu/eli/reg/2024/1689/oj
    [Google Scholar]
  7. Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology.
    [CrossRef] [Google Scholar]
  8. ISO/IEC. (2023). ISO/IEC 23894:2023 Information technology - Artificial intelligence - Guidance on risk management. International Organization for Standardization. https://www.iso.org/standard/77304.html
    [Google Scholar]
  9. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (No. NIST Special Publication (SP) 800-207). National Institute of Standards and Technology.
    [CrossRef] [Google Scholar]
  10. Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2(4), 603-609.
    [CrossRef] [Google Scholar]
  11. Cihon, P., Maas, M. M., & Kemp, L. (2020, February). Should artificial intelligence governance be centralised? Design lessons from history. In Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society (pp. 228-234).
    [CrossRef] [Google Scholar]
  12. Wirtz, B. W., Weyerer, J. C., & Geyer, C. (2019). Artificial intelligence and the public sector—applications and challenges. International journal of public administration, 42(7), 596-615.
    [CrossRef] [Google Scholar]
  13. Rubinstein, I. S. (2011). Regulating privacy by design. Berkeley Tech. LJ, 26, 1409.
    [Google Scholar]
  14. Boyes, H., Hallaq, B., Cunningham, J., & Watson, T. (2018). The industrial internet of things (IIoT): An analysis framework. Computers in industry, 101, 1-12.
    [CrossRef] [Google Scholar]
  15. Janssen, M., Brous, P., Estevez, E., Barbosa, L. S., & Janowski, T. (2020). Data governance: Organizing data for trustworthy Artificial Intelligence. Government information quarterly, 37(3), 101493.
    [CrossRef] [Google Scholar]
  16. Khatri, V., & Brown, C. V. (2010). Designing data governance. Communications of the ACM, 53(1), 148-152.
    [CrossRef] [Google Scholar]
  17. Weber, K., Otto, B., & Österle, H. (2009). One size does not fit all---a contingency approach to data governance. Journal of Data and Information Quality (JDIQ), 1(1), 1-27.
    [CrossRef] [Google Scholar]
  18. Abraham, R., Schneider, J., & Vom Brocke, J. (2019). Data governance: A conceptual framework, structured review, and research agenda. International journal of information management, 49, 424-438.
    [CrossRef] [Google Scholar]
  19. OECD. (2022). Going Digital to Advance Data Governance for Growth and Well-being. OECD Publishing.
    [CrossRef] [Google Scholar]
  20. Tene, O., & Polonetsky, J. (2011). Privacy in the age of big data: a time for big decisions. Stan. L. Rev. Online, 64, 63.
    [Google Scholar]
  21. Wieringa, J., Kannan, P. K., Ma, X., Reutterer, T., Risselada, H., & Skiera, B. (2021). Data analytics in a privacy-concerned world. Journal of Business Research, 122, 915-925.
    [CrossRef] [Google Scholar]
  22. Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572.
    [CrossRef] [Google Scholar]
  23. Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. P. (2018, April). Sok: Security and privacy in machine learning. In 2018 IEEE European symposium on security and privacy (EuroS&P) (pp. 399-414). IEEE.
    [CrossRef] [Google Scholar]
  24. Biggio, B., & Roli, F. (2018, October). Wild patterns: Ten years after the rise of adversarial machine learning. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security (pp. 2154-2156).
    [CrossRef] [Google Scholar]
  25. Mitchell, M., Wu, S., Zaldivar, A., Barnes, P., Vasserman, L., Hutchinson, B., ... & Gebru, T. (2019, January). Model cards for model reporting. In Proceedings of the conference on fairness, accountability, and transparency (pp. 220-229).
    [CrossRef] [Google Scholar]
  26. Gebru, T., Morgenstern, J., Vecchione, B., Vaughan, J. W., Wallach, H., Iii, H. D., & Crawford, K. (2021). Datasheets for datasets. Communications of the ACM, 64(12), 86-92. https://dx.doi.org/10.1145/3458723
    [Google Scholar]
  27. Raji, I. D., Smart, A., White, R. N., Mitchell, M., Gebru, T., Hutchinson, B., ... & Barnes, P. (2020, January). Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing. In Proceedings of the 2020 conference on fairness, accountability, and transparency (pp. 33-44).
    [CrossRef] [Google Scholar]
  28. Raisch, S., & Krakowski, S. (2021). Artificial intelligence and management: The automation–augmentation paradox. Academy of management review, 46(1), 192-210.
    [CrossRef] [Google Scholar]
  29. Mittelstadt, B. D., Allo, P., Taddeo, M., Wachter, S., & Floridi, L. (2016). The ethics of algorithms: Mapping the debate. Big data & society, 3(2), 2053951716679679.
    [CrossRef] [Google Scholar]
  30. Leslie, D. (2019). Understanding Artificial Intelligence Ethics and Safety: A Guide for the Responsible Design and Implementation of AI Systems in the Public Sector. The Alan Turing Institute.
    [CrossRef] [Google Scholar]
  31. Dwivedi, Y. K., Hughes, L., Ismagilova, E., Aarts, G., Coombs, C., Crick, T., ... & Williams, M. D. (2021). Artificial Intelligence (AI): Multidisciplinary perspectives on emerging challenges, opportunities, and agenda for research, practice and policy. International journal of information management, 57, 101994.
    [CrossRef] [Google Scholar]
  32. Dwork, C. (2008, April). Differential privacy: A survey of results. In International conference on theory and applications of models of computation (pp. 1-19). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  33. Kairouz, P., & McMahan, H. B. (2021). Advances and open problems in federated learning. Foundations and trends in machine learning, 14(1-2), 1-210.
    [CrossRef] [Google Scholar]
  34. Lindell, Y. (2020). Secure multiparty computation. Communications of the ACM, 64(1), 86-96.
    [CrossRef] [Google Scholar]
  35. UNESCO. (2021). Recommendation on the Ethics of Artificial Intelligence. United Nations Educational, Scientific and Cultural Organization. https://www.unesco.org/en/articles/recommendation-ethics-artificial-intelligence
    [Google Scholar]
  36. OECD. (2024). Recommendation of the Council on Artificial Intelligence. OECD Legal Instruments. https://legalinstruments.oecd.org/en/instruments/oecd-legal-0449
    [Google Scholar]
  37. OECD. (2020). Going Digital integrated policy framework. OECD Digital Economy Papers, No. 292. OECD Publishing.
    [CrossRef] [Google Scholar]
  38. Brous, P., Janssen, M., & Herder, P. (2020). The dual effects of the Internet of Things (IoT): A systematic review of the benefits and risks of IoT adoption by organizations. International Journal of Information Management, 51, 101952.
    [CrossRef] [Google Scholar]
  39. Brynjolfsson, E., Rock, D., & Syverson, C. (2018). Artificial intelligence and the modern productivity paradox: A clash of expectations and statistics. In The economics of artificial intelligence: An agenda (pp. 23-57). University of Chicago Press. https://www.nber.org/system/files/chapters/c14007/c14007.pdf
    [Google Scholar]
  40. Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., ... & Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and machines, 28(4), 689-707.
    [CrossRef] [Google Scholar]
  41. Brundage, M., Avin, S., Wang, J., Belfield, H., Krueger, G., Hadfield, G., ... & Anderljung, M. (2020). Toward trustworthy AI development: mechanisms for supporting verifiable claims. arXiv preprint arXiv:2004.07213.
    [CrossRef] [Google Scholar]
  42. Adner, R. (2017). Ecosystem as structure: An actionable construct for strategy. Journal of management, 43(1), 39-58.
    [CrossRef] [Google Scholar]
  43. Zuboff, S. (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. PublicAffairs. https://www.hbs.edu/faculty/Pages/item.aspx?num=56791
    [Google Scholar]

Cite This Article

APA Style
Sun, F. (2026). Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation. Journal of Reliable and Secure Computing, 2(3), 164-178. https://doi.org/10.62762/JRSC.2026.326448
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Sun, Fang
PY  - 2026
DA  - 2026/07/21
TI  - Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation
JO  - Journal of Reliable and Secure Computing
T2  - Journal of Reliable and Secure Computing
JF  - Journal of Reliable and Secure Computing
VL  - 2
IS  - 3
SP  - 164
EP  - 178
DO  - 10.62762/JRSC.2026.326448
UR  - https://www.icck.org/article/abs/JRSC.2026.326448
KW  - secure data governance
KW  - AI-driven corporate digital transformation
KW  - trustworthy AI
KW  - cybersecurity
KW  - privacy-preserving computation
KW  - compliance framework
KW  - model security
AB  - Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors.
SN  - 3070-6424
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Sun2026Data,
  author = {Fang Sun},
  title = {Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation},
  journal = {Journal of Reliable and Secure Computing},
  year = {2026},
  volume = {2},
  number = {3},
  pages = {164-178},
  doi = {10.62762/JRSC.2026.326448},
  url = {https://www.icck.org/article/abs/JRSC.2026.326448},
  abstract = {Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors.},
  keywords = {secure data governance, AI-driven corporate digital transformation, trustworthy AI, cybersecurity, privacy-preserving computation, compliance framework, model security},
  issn = {3070-6424},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
0
Scopus
0
Views
11
PDF Downloads
1

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

CC BY Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Journal of Reliable and Secure Computing
Journal of Reliable and Secure Computing
ISSN: 3070-6424 (Online)
Portico
Preserved at
Portico