GOV-02Governance and Accountability

Approved policy set

Policies covering the organization's obligations are approved, dated, owned and reviewed on a stated cycle.

Why it exists

An unapproved policy is a draft; an unreviewed one is a claim about the past.

What usually proves it

Policy register with owner, approval date, next review; approval record.

Smaller organizations

A dozen policies, approved once a year, with the founder as owner.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC5.3
  • Fully addressedISO/IEC 27001 Annex A · A.5.1
  • Fully addressedNIST Cybersecurity Framework · GV.PO-01
  • Fully addressedPCI DSS · 12.1
  • Fully addressedHIPAA Security Rule · 164.316(a)
  • Partially addressedGDPR · Art. 24(2) — Policies are required only where proportionate.
  • Deliberately absentEU AI Act — The Act imposes system-level obligations and quality management for providers; it does not require an organizational policy set.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 1.1