Information Security Docs
Breadcrumbs

Data Governance Roles Definitions

This document provides a reference for key data governance roles and related system concepts used to assign accountability, clarify responsibilities, and support consistent decision-making across institutional systems and data domains. It distinguishes between ownership, stewardship, custodianship, data use, and authoritative sources of truth so that systems and data can be governed, protected, maintained, and used in alignment with institutional policy, compliance obligations, and operational needs.

Roles Definitions

Data Owner

A Data Owner is accountable for the data within their domain and is responsible for defining policies for classification, access, protection, acceptable risk, and quality; ensuring compliance with institutional and regulatory requirements; and providing strategic direction for data use and lifecycle management.

System Owner

A System Owner is accountable for an information system throughout its lifecycle and is responsible for ensuring the system meets business requirements, operates securely, complies with organizational policies and regulatory obligations, and aligns with risk management practices. The System Owner is also responsible for accepting operational and technical risks associated with the system and ensuring appropriate resources are allocated for its secure operation and maintenance.

System Owner vs. Data Owner

A System Owner is accountable for the platform or application, while a Data Owner is accountable for the information stored, processed, or governed within that system.

Data Steward

A Data Steward acts as the operational representative of the Data Owner and serves as the subject matter expert for data quality and governance. The Data Steward monitors compliance with data policies and standards, maintains data definitions and metadata, supports Data Owners by implementing governance practices, and helps resolve data quality issues throughout the data lifecycle.

Data Custodian

A Data Custodian is responsible for the technical and operational management of institutional data on behalf of the Data Owner. The Data Custodian implements and maintains the security controls, access mechanisms, backup processes, monitoring, storage, transmission, and recovery procedures necessary to protect data confidentiality, integrity, and availability throughout the data lifecycle.

IT Custodian

An IT Custodian is responsible for implementing, operating, and maintaining the technical infrastructure, platforms, services, and controls that support institutional systems and data. The IT Custodian manages day-to-day technical administration, including system configuration, patching, monitoring, backups, access provisioning, security control implementation, and operational support, in accordance with requirements established by the System Owner, Data Owner, and applicable institutional policies.

Data User

A Data User is any individual who handles institutional data and is responsible for using data ethically and in compliance with policies, safeguarding data in their possession, reporting issues promptly, and completing required training on data handling and privacy.

System Custodian (or System Administrator / Technical Custodian)

A System Custodian is the individual or group responsible for the day-to-day operational management of an information system. They implement the controls and practices required to keep the system running securely and reliably, but they do so on behalf of the System Owner, who retains overall accountability.

Role

Primary Accountability

Key Responsibilities

System Owner

Accountable for the system as a whole (can also be the Data Owner)

  • Approves budgets, resources, and funding

  • Accepts risk on behalf of the organization

  • Approves major changes, upgrades, integrations, or architectural shifts

System Custodian

Responsible for operating and supporting the system

  • Performs day‑to‑day technical administration

  • Implements security and configuration controls approved by the System Owner

  • Manages patching, access provisioning, monitoring, backups, and maintenance

Data Owner 

Accountable for the data within the system (Can also be the System Owner)

  • Defines data classification and sensitivity

  • Establishes access rules, retention schedules, and data quality requirements

  • Ensures compliance with applicable policies, laws, and data governance standards

Data Steward

Responsible for supporting the Data Owner in implementing data governance practices and maintaining data quality, consistency, and documentation.

 

  • Maintains data definitions, metadata, and data quality rules

  • Monitors adherence to data standards and governance requirements

  • Supports access reviews, classification decisions, and issue resolution

  • Escalates policy, quality, or compliance concerns to the Data Owner

 

Data Custodian

Responsible for the technical and operational management of institutional data on behalf of the Data Owner.

  • Implements and maintains data protection controls

  • Manages access mechanisms, storage, transmission, backups, monitoring, and recovery processes

  • Supports confidentiality, integrity, and availability of institutional data throughout the data lifecycle

  • Operates in accordance with requirements established by the Data Owner and applicable policies

IT Custodian

Responsible for implementing, operating, and maintaining the technical infrastructure, platforms, services, and controls that support institutional systems and data.

  • Performs day-to-day technical administration and operational support

  • Manages system configuration, patching, monitoring, backups, and maintenance

  • Implements approved security controls and access provisioning processes

  • Operates in accordance with requirements established by the System Owner, Data Owner, and applicable institutional policies

System of Record (SOR)

A System of Record is the designated authoritative source for a defined data domain or data element within the organization. It is the official source used to establish the most accurate, complete, and current version of that data. Other systems that consume, display, replicate, or report on the same data should reference, synchronize with, or reconcile back to the System of Record unless another authoritative source has been formally designated.

Governance Responsibilities: Each System of Record should have an assigned System Owner, Data Owner, and appropriate custodians or stewards responsible for ensuring the data remains accurate, protected, auditable, and aligned with institutional policy and regulatory requirements. The designation of a System of Record should be documented, reviewed periodically, and communicated to downstream system owners, data users, and reporting teams to prevent conflicting sources of truth.

Key Characteristics of a System of Record

A system should be designated as a System of Record when it meets the following characteristics:

  • Is the authoritative, trusted source for a defined data domain

    • Example: The HR system may be the authoritative source for employee status, job title, department, and employment dates.

  • Maintains the master copy of the data, including history and audit trails

    • Example: The student information system maintains the official academic record, including enrollment history, grades, degree progress, and effective-dated changes.

  • Has assigned ownership and governance

    • Has an assigned System Owner, Data Owner, and appropriate custodians or stewards responsible for data accuracy, protection, quality, lifecycle management, and policy compliance.

    • Example: An ERP financial module may have a Finance Data Owner, an application System Owner, and IT Custodians responsible for access, configuration, integrations, backups, and monitoring.

  • Controls data quality and integrity

    • Ensures validations, approvals, and governance are enforced.

    • Example: A payroll or HR system may require approved workflow changes before employee pay group, supervisor, or employment status fields can be updated.

  • Supports regulatory, audit, or compliance requirements

    • Maintains records in a manner that supports institutional policy, legal obligations, auditability, and retention requirements.

    • Example: Student academic records may need to support FERPA requirements, transcript accuracy, retention obligations, and institutional audit reviews.

  • Feeds downstream systems

    • Used as the reference point for integrations, analytics, dashboards, reporting, identity systems, and other consuming applications.

    • Example: An identity governance system may consume employee status from HR and student enrollment status from the student information system to determine account eligibility and access rules.

A system that stores, displays, processes, or reports data is not automatically a System of Record. Operational systems, dashboards, reporting tools, spreadsheets, integrations, and downstream applications may support business processes, but they should not be treated as authoritative unless they have been formally designated and governed as the System of Record for a defined data domain or data element.

Term

Purpose

System of Record

The authoritative source of truth for specific data.

System of Reference

Secondary system that consumes data from one or more SORs.

System of Engagement

User-facing interfaces where people interact with the data (e.g., portals, apps), but not the authoritative store.

Example: Higher Education / Enterprise

  • HRIS (e.g., Workday) → System of Record for employee data

  • SIS (e.g., Banner, PeopleSoft Campus Solutions) → SOR for student academic records

  • ERP (e.g., Oracle Financials) → SOR for financial transactions

  • CRM (e.g., Salesforce) → Usually a system of reference fed by the SOR

A System of Record establishes the authoritative source for a defined data domain or data element and provides the reference point for governance, compliance, reporting, integration, and reconciliation. To be effective, each System of Record should have clearly assigned ownership, documented scope, appropriate stewardship and custodianship, and controls that preserve data accuracy, security, auditability, and consistency across downstream systems.