This document provides a reference for key data governance roles and related system concepts used to assign accountability, clarify responsibilities, and support consistent decision-making across institutional systems and data domains. It distinguishes between ownership, stewardship, custodianship, data use, and authoritative sources of truth so that systems and data can be governed, protected, maintained, and used in alignment with institutional policy, compliance obligations, and operational needs.
Roles Definitions
Data Owner
A Data Owner is accountable for the data within their domain and is responsible for defining policies for classification, access, protection, acceptable risk, and quality; ensuring compliance with institutional and regulatory requirements; and providing strategic direction for data use and lifecycle management.
System Owner
A System Owner is accountable for an information system throughout its lifecycle and is responsible for ensuring the system meets business requirements, operates securely, complies with organizational policies and regulatory obligations, and aligns with risk management practices. The System Owner is also responsible for accepting operational and technical risks associated with the system and ensuring appropriate resources are allocated for its secure operation and maintenance.
System Owner vs. Data Owner
A System Owner is accountable for the platform or application, while a Data Owner is accountable for the information stored, processed, or governed within that system.
Data Steward
A Data Steward acts as the operational representative of the Data Owner and serves as the subject matter expert for data quality and governance. The Data Steward monitors compliance with data policies and standards, maintains data definitions and metadata, supports Data Owners by implementing governance practices, and helps resolve data quality issues throughout the data lifecycle.
Data Custodian
A Data Custodian is responsible for the technical and operational management of institutional data on behalf of the Data Owner. The Data Custodian implements and maintains the security controls, access mechanisms, backup processes, monitoring, storage, transmission, and recovery procedures necessary to protect data confidentiality, integrity, and availability throughout the data lifecycle.
IT Custodian
An IT Custodian is responsible for implementing, operating, and maintaining the technical infrastructure, platforms, services, and controls that support institutional systems and data. The IT Custodian manages day-to-day technical administration, including system configuration, patching, monitoring, backups, access provisioning, security control implementation, and operational support, in accordance with requirements established by the System Owner, Data Owner, and applicable institutional policies.
Data User
A Data User is any individual who handles institutional data and is responsible for using data ethically and in compliance with policies, safeguarding data in their possession, reporting issues promptly, and completing required training on data handling and privacy.
System Custodian (or System Administrator / Technical Custodian)
A System Custodian is the individual or group responsible for the day-to-day operational management of an information system. They implement the controls and practices required to keep the system running securely and reliably, but they do so on behalf of the System Owner, who retains overall accountability.
|
Role |
Primary Accountability |
Key Responsibilities |
|
System Owner |
Accountable for the system as a whole (can also be the Data Owner) |
|
|
System Custodian |
Responsible for operating and supporting the system |
|
|
Data Owner |
Accountable for the data within the system (Can also be the System Owner) |
|
|
Data Steward |
Responsible for supporting the Data Owner in implementing data governance practices and maintaining data quality, consistency, and documentation.
|
|
|
Data Custodian |
Responsible for the technical and operational management of institutional data on behalf of the Data Owner. |
|
|
IT Custodian |
Responsible for implementing, operating, and maintaining the technical infrastructure, platforms, services, and controls that support institutional systems and data. |
|
System of Record (SOR)
A System of Record is the designated authoritative source for a defined data domain or data element within the organization. It is the official source used to establish the most accurate, complete, and current version of that data. Other systems that consume, display, replicate, or report on the same data should reference, synchronize with, or reconcile back to the System of Record unless another authoritative source has been formally designated.
Governance Responsibilities: Each System of Record should have an assigned System Owner, Data Owner, and appropriate custodians or stewards responsible for ensuring the data remains accurate, protected, auditable, and aligned with institutional policy and regulatory requirements. The designation of a System of Record should be documented, reviewed periodically, and communicated to downstream system owners, data users, and reporting teams to prevent conflicting sources of truth.
Key Characteristics of a System of Record
A system should be designated as a System of Record when it meets the following characteristics:
-
Is the authoritative, trusted source for a defined data domain
-
Example: The HR system may be the authoritative source for employee status, job title, department, and employment dates.
-
-
Maintains the master copy of the data, including history and audit trails
-
Example: The student information system maintains the official academic record, including enrollment history, grades, degree progress, and effective-dated changes.
-
-
Has assigned ownership and governance
-
Has an assigned System Owner, Data Owner, and appropriate custodians or stewards responsible for data accuracy, protection, quality, lifecycle management, and policy compliance.
-
Example: An ERP financial module may have a Finance Data Owner, an application System Owner, and IT Custodians responsible for access, configuration, integrations, backups, and monitoring.
-
-
Controls data quality and integrity
-
Ensures validations, approvals, and governance are enforced.
-
Example: A payroll or HR system may require approved workflow changes before employee pay group, supervisor, or employment status fields can be updated.
-
-
Supports regulatory, audit, or compliance requirements
-
Maintains records in a manner that supports institutional policy, legal obligations, auditability, and retention requirements.
-
Example: Student academic records may need to support FERPA requirements, transcript accuracy, retention obligations, and institutional audit reviews.
-
-
Feeds downstream systems
-
Used as the reference point for integrations, analytics, dashboards, reporting, identity systems, and other consuming applications.
-
Example: An identity governance system may consume employee status from HR and student enrollment status from the student information system to determine account eligibility and access rules.
-
A system that stores, displays, processes, or reports data is not automatically a System of Record. Operational systems, dashboards, reporting tools, spreadsheets, integrations, and downstream applications may support business processes, but they should not be treated as authoritative unless they have been formally designated and governed as the System of Record for a defined data domain or data element.
|
Term |
Purpose |
|
System of Record |
The authoritative source of truth for specific data. |
|
System of Reference |
Secondary system that consumes data from one or more SORs. |
|
System of Engagement |
User-facing interfaces where people interact with the data (e.g., portals, apps), but not the authoritative store. |
Example: Higher Education / Enterprise
-
HRIS (e.g., Workday) → System of Record for employee data
-
SIS (e.g., Banner, PeopleSoft Campus Solutions) → SOR for student academic records
-
ERP (e.g., Oracle Financials) → SOR for financial transactions
-
CRM (e.g., Salesforce) → Usually a system of reference fed by the SOR
A System of Record establishes the authoritative source for a defined data domain or data element and provides the reference point for governance, compliance, reporting, integration, and reconciliation. To be effective, each System of Record should have clearly assigned ownership, documented scope, appropriate stewardship and custodianship, and controls that preserve data accuracy, security, auditability, and consistency across downstream systems.