Policy Register

Data governance policy

Who owns each data set, the quality it must meet, where it comes from and how it may be used, including as training data.

How the register reads it

Also calleddata management policy, data stewardship
FamilyAssets, data and classification
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe AI governance lead (CTO, CDO or head of data science).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 42001 is ticked and no line resolves to it (ISO 27001 requires it too, inside a parent document, so it does not list it separately).
TemplateData governance policy.

Which standards require it, and what each expects it to contain

5 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.9 Inventory of information and other associated assets

Maintain a current asset inventory with owners.

What the ISO 27002 guidance expects the document to say: Requires an inventory of information and of the other assets associated with it to be developed and kept current, and requires that inventory to record ownership of each entry.

Evidence an auditor accepts: The inventory of information and associated assets, showing scope across hardware, software, services, information stores and cloud tenancies; the recorded owner for each entry, and evidence owners have accepted the role; the process and cadence for keeping the inventory current, including additions and retirements
Common gap: Outdated entries in inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.12 Classification of information

Classify information by confidentiality, integrity, availability and interested-party requirements.

What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.

Evidence an auditor accepts: The classification scheme, defining the levels and the criteria for each against confidentiality, integrity and availability; evidence the criteria account for the requirements of relevant interested parties, such as customers, regulators and contracts; classification applied to actual information assets in the inventory, not only defined in policy
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 42001:2023

ISO 42001 A.7.2 Data for development and enhancement of AI systems

The organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.

Evidence an auditor accepts: Data requirements specification; data quality procedure; defined data requirements per AI system
Common gap: Is data quality measured or assumed?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.4 Quality of data for AI systems

The organization shall define and document quality requirements for data and ensure they are met.

Evidence an auditor accepts: Data quality standards; quality assessment reports; quality dimensions defined (accuracy, completeness, representativeness, bias)
Common gap: Is representativeness and bias assessed for training data?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.5 Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

Evidence an auditor accepts: Provenance records; lineage diagrams; end-to-end data lineage from source to model
Common gap: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Asset management policy · Information classification and handling policy