GOV-01Governance and Accountability

Accountable owner for digital trust

A named individual is accountable for the digital trust programme, with the authority and budget to direct it.

Why it exists

Programmes without a name attached become everybody's intention and nobody's work.

What usually proves it

Appointment record, role description, board or leadership minute naming the owner.

Smaller organizations

One founder or manager, named in writing, is enough.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC1.3
  • Fully addressedISO/IEC 27001 Annex A · A.5.2
  • Fully addressedNIST Cybersecurity Framework · GV.RR-02
  • Partially addressedPCI DSS · 12.1.3 — Scoped to cardholder data responsibilities only.
  • Fully addressedHIPAA Security Rule · 164.308(a)(2)
  • Partially addressedGDPR · Art. 24 — Accountability sits with the controller as an entity; no named individual is required except where Art. 37 applies.
  • Partially addressedEU AI Act · Art. 26 — Deployer duties imply an accountable person without naming the role.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 2.1