Purpose
This guidance provides a reference for key data-governance roles and related system concepts used to establish accountability, clarify responsibility, and support consistent decisions across institutional systems and data domains. It distinguishes ownership, stewardship, custodianship, data use, and authoritative sources so systems and data can be governed, protected, maintained, and used consistently with institutional policy, compliance obligations, and operational needs.
Scope and Audience
This guidance is intended for people who assign, perform, or depend on data and system governance roles, including Data Owners, System Owners, Data Stewards, Data Custodians, IT Custodians, System Custodians/Administrators, and Data Users. It also supports teams that designate or consume Systems of Record.
Related Requirements
This guidance supports consistent interpretation of governance responsibilities appearing throughout UTRGV policies and standards. In particular, related documents in this package assign responsibilities to Data Owners, System Owners, technical support roles, and users.
Terms and Concepts
Role Comparison
|
Role |
Primary accountability |
Key responsibilities |
|---|---|---|
|
System Owner |
The system as a whole; may also be the Data Owner |
Approves budgets/resources/funding; accepts organizational risk; approves major changes, upgrades, integrations, and architectural changes. |
|
System Custodian |
Operating and supporting the system |
Day-to-day technical administration; implements approved security/configuration controls; manages patching, access provisioning, monitoring, backups, and maintenance. |
|
Data Owner |
Data within the system; may also be the System Owner |
Defines classification/sensitivity; establishes access, retention, and quality requirements; ensures compliance with policy, law, and data-governance requirements. |
|
Data Steward |
Operational support for the Data Owner's governance responsibilities |
Maintains definitions, metadata, and quality rules; monitors data standards; supports access reviews/classification/issue resolution; escalates policy, quality, or compliance concerns. |
|
Data Custodian |
Technical/operational management of institutional data for the Data Owner |
Implements data-protection controls; manages access mechanisms, storage, transmission, backups, monitoring, and recovery; supports confidentiality, integrity, and availability. |
|
IT Custodian |
Technical infrastructure, platforms, services, and supporting controls |
Performs technical administration/support; manages configuration, patching, monitoring, backups, and maintenance; implements approved security/access controls according to owner and policy requirements. |
Guidance
Characteristics of a System of Record
A system should be designated as an SOR when it has the following characteristics.
-
It is the authoritative, trusted source for a defined data domain.
-
Example: an HR system may be authoritative for employee status, job title, department, and employment dates.
-
-
It maintains the master copy, including history and audit trails.
-
Example: a student information system may hold the official academic record, enrollment history, grades, degree progress, and effective-dated changes.
-
-
It has assigned ownership and governance.
-
An SOR should have an assigned System Owner, Data Owner, and suitable custodians/stewards responsible for accuracy, protection, quality, lifecycle management, and compliance.
-
Example: an ERP financial module may have a Finance Data Owner, application System Owner, and IT Custodians handling access, configuration, integrations, backups, and monitoring.
-
-
It controls data quality and integrity.
-
Validations, approvals, and governance should be enforced.
-
Example: an HR/payroll system may require approved workflows before pay group, supervisor, or employment-status values are changed.
-
-
It supports regulatory, audit, and compliance requirements.
-
Records should support institutional policy, legal obligations, auditability, and retention.
-
Example: student records may need to support FERPA, transcript accuracy, retention obligations, and institutional audits.
-
-
It feeds downstream systems.
-
The SOR becomes a reference for integrations, analytics, dashboards, reporting, identity systems, and consuming applications.
-
Example: identity governance may consume employee status from HR and enrollment status from the student information system to determine account eligibility/access.
-
A system is not automatically an SOR merely because it stores, displays, processes, or reports data. Dashboards, spreadsheets, integrations, reporting tools, operational applications, and other downstream systems should not be treated as authoritative unless formally designated and governed as the SOR for a defined data domain or element.
Related System Types
|
Term |
Purpose |
|---|---|
|
System of Record |
Authoritative source of truth for specific data. |
|
System of Reference |
Secondary system that consumes data from one or more Systems of Record. |
|
System of Engagement |
User-facing interface through which people interact with data, such as a portal or application, without necessarily being the authoritative store. |
Examples
Higher-education / enterprise examples from the source include:
-
HRIS, such as Workday: SOR for employee data.
-
SIS, such as Banner or PeopleSoft Campus Solutions: SOR for student academic records.
-
ERP, such as Oracle Financials: SOR for financial transactions.
-
CRM, such as Salesforce: usually a System of Reference populated by an SOR.
A well-governed System of Record provides the authoritative reference for governance, compliance, reporting, integration, and reconciliation. Each SOR should have clear ownership, documented scope, suitable stewardship/custodianship, and controls that preserve accuracy, security, auditability, and downstream consistency.
Related UTRGV Documents
External References
Review and Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823