A data governance function has been formally set up and is working: the governance approach and plan are defined, approved and aligned with the data and data management strategies; data across its life cycle is governed through structures, authority lines, roles and responsibilities, escalation paths, policies, standards and routines, covering (requirements, architecture, ownership and stewardship, quality, privacy, security, access and use, ethics, retention and disposal, regulatory compliance); and adherence is evaluated with accountable owners. The v2.2 model (as the Federal Reserve Board's OIG report of January 2023 quotes it) expects senior management to give the governance function formal authority and expects its roles to be made known to every stakeholder. Covers ground held in v2.2 by capabilities 6.1 (function established), 6.2 (policy and standards written and approved), 6.4 (govern the data structure), 6.5 (govern fitness for purpose, including access, sharing agreements and contractual use) and 6.6 (govern data ethics); the v3 sub-capability split is not held.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.