GOV-02Governance and Accountability
Approved policy set
Policies covering the organization's obligations are approved, dated, owned and reviewed on a stated cycle.
Why it exists
An unapproved policy is a draft; an unreviewed one is a claim about the past.
What usually proves it
Policy register with owner, approval date, next review; approval record.
Smaller organizations
A dozen policies, approved once a year, with the founder as owner.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC5.3
- Fully addressedISO/IEC 27001 Annex A · A.5.1
- Fully addressedNIST Cybersecurity Framework · GV.PO-01
- Fully addressedPCI DSS · 12.1
- Fully addressedHIPAA Security Rule · 164.316(a)
- Partially addressedGDPR · Art. 24(2) — Policies are required only where proportionate.
- Deliberately absentEU AI Act — The Act imposes system-level obligations and quality management for providers; it does not require an organizational policy set.
- Fully addressedNIST AI Risk Management Framework · GOVERN 1.1