Data governance policy
Who owns each data set, the quality it must meet, where it comes from and how it may be used, including as training data.
How the register reads it
| Also called | data management policy, data stewardship |
|---|---|
| Family | Assets, data and classification |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The AI governance lead (CTO, CDO or head of data science). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 42001 is ticked and no line resolves to it (ISO 27001 requires it too, inside a parent document, so it does not list it separately). |
| Template | Data governance policy. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.9 Inventory of information and other associated assetsMaintain a current asset inventory with owners.
What the ISO 27002 guidance expects the document to say: Requires an inventory of information and of the other assets associated with it to be developed and kept current, and requires that inventory to record ownership of each entry.
Common gap: Outdated entries in inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.12 Classification of informationClassify information by confidentiality, integrity, availability and interested-party requirements.
What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 42001:2023
ISO 42001 A.7.2 Data for development and enhancement of AI systemsThe organization shall define, document, and implement processes to determine data requirements and ensure data quality for AI system development and enhancement.
Common gap: Is data quality measured or assumed?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.4 Quality of data for AI systemsThe organization shall define and document quality requirements for data and ensure they are met.
Common gap: Is representativeness and bias assessed for training data?
Source: ISO/IEC 42001:2023
ISO 42001 A.7.5 Data provenanceThe organization shall document the provenance of data used in AI systems to enable evaluation and traceability.
Common gap: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerAsset management policy · Information classification and handling policy