Information Security Docs
Breadcrumbs

Data Governance Roles Definitions

Purpose

This guidance provides a reference for key data-governance roles and related system concepts used to establish accountability, clarify responsibility, and support consistent decisions across institutional systems and data domains. It distinguishes ownership, stewardship, custodianship, data use, and authoritative sources so systems and data can be governed, protected, maintained, and used consistently with institutional policy, compliance obligations, and operational needs.

Scope and Audience

This guidance is intended for people who assign, perform, or depend on data and system governance roles, including Data Owners, System Owners, Data Stewards, Data Custodians, IT Custodians, System Custodians/Administrators, and Data Users. It also supports teams that designate or consume Systems of Record.

This guidance supports consistent interpretation of governance responsibilities appearing throughout UTRGV policies and standards. In particular, related documents in this package assign responsibilities to Data Owners, System Owners, technical support roles, and users.

Terms and Concepts

Click to expand...

Data Owner

A Data Owner is accountable for data within a defined domain. Responsibilities include setting expectations for classification, access, protection, acceptable risk, and quality; ensuring institutional and regulatory compliance; and providing strategic direction for data use and lifecycle management.

System Owner

A System Owner is accountable for an information system throughout its lifecycle. The role ensures the system supports business requirements, operates securely, complies with organizational and regulatory obligations, and aligns with risk-management practices. The System Owner accepts operational and technical risk associated with the system and ensures appropriate resources are available for secure operation and maintenance.

System Owner vs. Data Owner

The System Owner is accountable for the platform or application. The Data Owner is accountable for the information stored, processed, or governed through that platform. One person may hold both roles, but the accountabilities are distinct.

Data Steward

A Data Steward is the operational representative of the Data Owner and subject-matter expert for data quality and governance. The Data Steward monitors adherence to data requirements, maintains definitions and metadata, implements governance practices on behalf of the Data Owner, and helps resolve data-quality issues throughout the data lifecycle.

Data Custodian

A Data Custodian performs technical and operational management of institutional data on behalf of the Data Owner. The role implements and maintains controls for access, backup, monitoring, storage, transmission, recovery, and other protections needed to preserve data confidentiality, integrity, and availability.

IT Custodian

An IT Custodian implements, operates, and maintains technical infrastructure, platforms, services, and controls that support institutional systems and data. Typical duties include system configuration, patching, monitoring, backups, access provisioning, implementation of security controls, and operational support under requirements established by System Owners, Data Owners, and institutional policy.

Data User

A Data User is anyone who handles institutional data. Data Users are responsible for ethical and policy-compliant use, safeguarding data in their possession, promptly reporting issues, and completing required data-handling and privacy training.

System Custodian / System Administrator / Technical Custodian

A System Custodian is the person or group responsible for day-to-day operation of an information system. The role implements controls and operating practices needed for reliable and secure service on behalf of the System Owner, who retains overall accountability.

System of Record (SOR)

A System of Record is the formally designated authoritative source for a defined data domain or data element. It establishes the version of data treated as the most accurate, complete, and current. Systems that consume, display, replicate, or report the same data should reference, synchronize with, or reconcile to the SOR unless another authoritative source has been formally designated.

Each SOR should have a System Owner, Data Owner, and appropriate custodians or stewards so data remains accurate, protected, auditable, and aligned with institutional and regulatory requirements. SOR designation should be documented, reviewed periodically, and communicated to downstream system owners, data users, and reporting teams to avoid conflicting sources of truth.

Role Comparison

Role

Primary accountability

Key responsibilities

System Owner

The system as a whole; may also be the Data Owner

Approves budgets/resources/funding; accepts organizational risk; approves major changes, upgrades, integrations, and architectural changes.

System Custodian

Operating and supporting the system

Day-to-day technical administration; implements approved security/configuration controls; manages patching, access provisioning, monitoring, backups, and maintenance.

Data Owner

Data within the system; may also be the System Owner

Defines classification/sensitivity; establishes access, retention, and quality requirements; ensures compliance with policy, law, and data-governance requirements.

Data Steward

Operational support for the Data Owner's governance responsibilities

Maintains definitions, metadata, and quality rules; monitors data standards; supports access reviews/classification/issue resolution; escalates policy, quality, or compliance concerns.

Data Custodian

Technical/operational management of institutional data for the Data Owner

Implements data-protection controls; manages access mechanisms, storage, transmission, backups, monitoring, and recovery; supports confidentiality, integrity, and availability.

IT Custodian

Technical infrastructure, platforms, services, and supporting controls

Performs technical administration/support; manages configuration, patching, monitoring, backups, and maintenance; implements approved security/access controls according to owner and policy requirements.

Guidance

Characteristics of a System of Record

A system should be designated as an SOR when it has the following characteristics.

  1. It is the authoritative, trusted source for a defined data domain.

    • Example: an HR system may be authoritative for employee status, job title, department, and employment dates.

  2. It maintains the master copy, including history and audit trails.

    • Example: a student information system may hold the official academic record, enrollment history, grades, degree progress, and effective-dated changes.

  3. It has assigned ownership and governance.

    • An SOR should have an assigned System Owner, Data Owner, and suitable custodians/stewards responsible for accuracy, protection, quality, lifecycle management, and compliance.

    • Example: an ERP financial module may have a Finance Data Owner, application System Owner, and IT Custodians handling access, configuration, integrations, backups, and monitoring.

  4. It controls data quality and integrity.

    • Validations, approvals, and governance should be enforced.

    • Example: an HR/payroll system may require approved workflows before pay group, supervisor, or employment-status values are changed.

  5. It supports regulatory, audit, and compliance requirements.

    • Records should support institutional policy, legal obligations, auditability, and retention.

    • Example: student records may need to support FERPA, transcript accuracy, retention obligations, and institutional audits.

  6. It feeds downstream systems.

    • The SOR becomes a reference for integrations, analytics, dashboards, reporting, identity systems, and consuming applications.

    • Example: identity governance may consume employee status from HR and enrollment status from the student information system to determine account eligibility/access.

A system is not automatically an SOR merely because it stores, displays, processes, or reports data. Dashboards, spreadsheets, integrations, reporting tools, operational applications, and other downstream systems should not be treated as authoritative unless formally designated and governed as the SOR for a defined data domain or element.

Term

Purpose

System of Record

Authoritative source of truth for specific data.

System of Reference

Secondary system that consumes data from one or more Systems of Record.

System of Engagement

User-facing interface through which people interact with data, such as a portal or application, without necessarily being the authoritative store.

Examples

Higher-education / enterprise examples from the source include:

  • HRIS, such as Workday: SOR for employee data.

  • SIS, such as Banner or PeopleSoft Campus Solutions: SOR for student academic records.

  • ERP, such as Oracle Financials: SOR for financial transactions.

  • CRM, such as Salesforce: usually a System of Reference populated by an SOR.

A well-governed System of Record provides the authoritative reference for governance, compliance, reporting, integration, and reconciliation. Each SOR should have clear ownership, documented scope, suitable stewardship/custodianship, and controls that preserve accuracy, security, auditability, and downstream consistency.

External References

Review and Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823