Accountable owner for digital trust
A named individual is accountable for the digital trust programme, with the authority and budget to direct it.
DTCF normalises what an organization must achieve into 7 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.
DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution
A named individual is accountable for the digital trust programme, with the authority and budget to direct it.
Expected conduct is published and affirmed by staff on joining and annually.
Risks are recorded with inherent and residual judgement, an owner, a treatment decision and a review date.
Accepted risks and control exceptions carry an accountable executive, a compensating control and an expiry date.
Legal, regulatory and contractual obligations that apply are identified, owned and kept current.
Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.
Backups exist, are protected from the same failure as production, and restoration is tested.
First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.
Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.