GOV-03Governance and Accountability

Roles and responsibilities defined

Security, privacy and compliance responsibilities are assigned and communicated to the people who hold them.

Why it exists

People perform duties they know they hold.

What usually proves it

Role descriptions, RACI, acknowledgement records.

Smaller organizations

A one-page list of who does what, acknowledged by each person.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC1.4
  • Fully addressedISO/IEC 27001 Annex A · A.5.3
  • Fully addressedNIST Cybersecurity Framework · GV.RR-02
  • Fully addressedPCI DSS · 12.4
  • Fully addressedHIPAA Security Rule · 164.308(a)(3)
  • Partially addressedGDPR · Art. 32 — Implied through appropriate measures rather than stated.
  • Partially addressedEU AI Act · Art. 26(2) — Human oversight must be assigned to competent persons.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 2.2