Information Ownership and Stewardship
In CGEIT (Certified in the Governance of Enterprise IT, an ISACA certification) and the broader discipline of Governance of Enterprise IT (GEIT), information ownership and stewardship ensure that information is treated as a strategic enterprise asset with clear accountability. Information ownershi… In CGEIT (Certified in the Governance of Enterprise IT, an ISACA certification) and the broader discipline of Governance of Enterprise IT (GEIT), information ownership and stewardship ensure that information is treated as a strategic enterprise asset with clear accountability. Information ownership assigns accountability for a specific information asset to a business executive, not to IT. This is usually a senior manager whose function creates the data or depends on it most. The owner is responsible for: - Classifying the information, for example as public, internal, confidential or restricted. - Deciding who may access it and what uses are acceptable. - Setting retention and disposal periods. - Defining risk tolerance and required protection levels. - Ensuring compliance with legal, regulatory and contractual obligations such as privacy laws. This reflects a core GEIT principle: the business is accountable for the value and risk of IT-enabled assets. Information stewardship is the operational responsibility for managing information on the owner's behalf. Data stewards define and maintain data quality standards, metadata, business definitions and data lineage. They also monitor integrity, resolve data issues and coordinate between business and technical teams. Custodians, often IT staff, implement technical controls as directed by owners, including backups, access provisioning, encryption and secure storage. COBIT supports these roles in several ways: - APO14 (Managed Data) addresses data management practices. - APO01 (Managed I&T Management Framework) covers the definition of roles and responsibilities. - EDM03 (Ensured Risk Optimization) links data protection to enterprise risk. - RACI charts distinguish who is accountable from who is responsible. The board and executive management set information governance policy, often establish a data governance council, and monitor performance through metrics such as data quality indices and access review completion rates. Clear ownership and stewardship support the central GEIT objectives: - Value realization, from trusted and accurate information. - Risk optimization, through appropriate protection. - Resource optimization, by eliminating duplicate or orphaned data. - Transparency for stakeholders. Without defined owners, data becomes unmanaged, which leads to security gaps, poor decisions and regulatory exposure. For CGEIT purposes, the key distinction is that ownership is a governance accountability, while stewardship and custodianship are delegated management and operational responsibilities.
Information Ownership and Stewardship (CGEIT – Governance of Enterprise IT)
Information Ownership and Stewardship: A Complete CGEIT Guide
1. Why Information Ownership and Stewardship Is Important
Information is one of the most valuable assets an enterprise has. Unlike hardware or software, its value depends on how accurately, securely and appropriately it is created, used, shared and retired. Without clearly assigned ownership and stewardship, information becomes an orphan asset. Nobody is accountable for its quality, classification, protection, retention or lawful use.
The consequences of poor or missing ownership include:
• Regulatory and legal exposure. Privacy laws (e.g., GDPR, HIPAA), financial reporting rules (e.g., SOX) and data retention mandates all require demonstrable accountability for data.
• Poor data quality. Inconsistent definitions, duplicated records and unreliable reports undermine decision-making and value delivery.
• Security failures. If no one classifies data or approves access, controls are either excessive and costly, or inadequate and risky.
• Conflict and inefficiency. Business units argue over the definition of a customer or revenue, and IT is wrongly blamed for business data problems.
• Failure to realize value. Analytics, AI and digital initiatives depend on trusted, well-governed data.
From a CGEIT perspective, information ownership is a core element of the governance framework. It ensures that accountability for enterprise assets sits with the business, that decision rights are clear, and that IT-related risk and value are managed in line with stakeholder needs.
2. What It Is: Key Concepts and Definitions
Information (Data) Owner
The information owner is a senior business executive or manager who is accountable for a specific set of information assets. Examples include the CFO for financial data, the HR Director for employee data and the Head of Sales for customer data. The owner is usually the person whose business function creates or primarily depends on the information. Typical responsibilities:
• Determining the classification of the information (e.g., public, internal, confidential, restricted)
• Approving access rights and periodically reviewing who has access
• Defining acceptable use, quality requirements and business rules
• Setting retention and disposal requirements in line with legal and business needs
• Accepting or escalating residual risk related to the information
• Ensuring compliance with laws and policies relevant to that data
Information (Data) Steward
The data steward is usually a business-side subject matter expert who acts on behalf of the owner. The steward manages the day-to-day quality, definitions, metadata and proper use of data. Stewards are responsible for executing the owner's decisions; they are not the ultimate decision-makers. Responsibilities include:
• Maintaining data definitions, business glossaries and metadata
• Monitoring and remediating data quality issues
• Coordinating between business users and IT
• Applying data standards and policies consistently
Information (Data) Custodian
The custodian is typically IT or an operations function, sometimes a third-party service provider. The custodian is responsible for implementing and operating the controls the owner specifies. Examples include backups, storage, access provisioning, encryption, patching and technical security. The custodian does not own the data and does not decide classification or who gets access.
Information User
Users access and use information in line with the policies and permissions granted by the owner. They are responsible for appropriate use and for reporting incidents.
Other Governance Roles
• Board / Executive Management: Ultimately accountable for the governance of enterprise information. They set direction and risk appetite.
• Chief Data Officer (CDO) / Data Governance Council: Develops the data governance framework, policies and standards, and resolves cross-functional ownership disputes.
• CISO / Information Security Manager: Defines the security policy framework, advises owners and monitors compliance. This role does not own business data.
• CIO: Accountable for IT services and the custodial environment, not for business data content.
• Privacy Officer / DPO: Oversees compliance with privacy requirements.
3. How It Works: Implementing Ownership and Stewardship
Step 1 – Establish policy and governance structure
Executive management approves an information governance or data governance policy. The policy defines roles, decision rights and escalation paths. A data governance council or steering committee provides oversight.
Step 2 – Inventory and categorize information assets
Identify key information domains, such as customer, product, financial, employee and supplier data. Map them to business processes and systems.
Step 3 – Assign owners
Assign each information asset or domain to a named business owner at an appropriate level of seniority. Ownership should be documented, for example in a data catalog or RACI matrix. Shared data, such as master data, may need a designated primary owner, with the governance council resolving conflicts.
Step 4 – Appoint stewards and confirm custodians
Owners delegate operational responsibilities to stewards. IT and service providers are formally designated as custodians, with obligations defined in SLAs and contracts.
Step 5 – Classify information
Owners classify data according to the enterprise classification scheme. Classification drives the protection controls custodians must implement. This makes control investment proportionate to value and risk.
Step 6 – Define access, quality, retention and usage rules
• Owners approve access requests based on least privilege and need-to-know.
• Stewards define data quality metrics.
• Retention schedules reflect legal and business needs.
Step 7 – Monitor, review and report
• Owners conduct periodic access recertification.
• Data quality KPIs are reported.
• Internal audit provides independent assurance.
• Metrics feed into governance reporting to the board.
Step 8 – Embed in the lifecycle
Ownership applies across the full information lifecycle: plan, create/acquire, store, use, share, archive and destroy. It also applies when data is moved to the cloud or shared with third parties. Outsourcing transfers custody, never accountability.
RACI Illustration
Example activity: classifying customer data.
• Owner (Head of Sales): Accountable
• Steward: Responsible (prepares the proposal)
• CISO: Consulted
• IT Custodian: Informed, then implements the controls
Link to Frameworks
• COBIT 2019: APO14 (Managed Data) addresses data management, including ownership, quality and lifecycle. EDM01 (Ensured Governance Framework Setting and Maintenance) covers decision rights. APO01 covers the organizational structures and roles that define accountability. DSS05/DSS06 cover security and business process controls.
• COBIT principle: Separate governance from management, and recognize that the business owns information while IT enables it.
• DAMA-DMBOK: Positions data stewardship as a central data governance function.
• ISO/IEC 27001: Requires that information assets have identified owners (asset management controls).
4. Common Challenges
• Business managers believe IT owns the data because it sits in IT systems.
• Shared or enterprise-wide data has no clear single owner.
• Owners are assigned in name only and lack time, training or authority.
• Ownership is not updated after reorganizations, mergers or system changes.
• Shadow IT and cloud services create unmanaged data stores.
• Owners and custodians are confused with each other, which weakens segregation of duties.
5. Exam Tips: Answering Questions on Information Ownership and Stewardship
Tip 1 – The business owns the data, not IT. If a question asks who is accountable for classification, access approval or data quality, the answer is almost always the business/data owner. It is not the CIO, IT manager, database administrator or security manager.
Tip 2 – Distinguish accountable vs. responsible. The owner is accountable for decisions. The steward or custodian is responsible for carrying them out. CGEIT favours answers that place accountability at the right governance level.
Tip 3 – The custodian implements; it does not decide. Options such as "IT should determine who has access to payroll data" are traps. IT provisions access only after the owner approves it.
Tip 4 – The CISO advises and monitors. Security management sets the framework and standards. It does not own business information or accept business risk on the owner's behalf.
Tip 5 – Look for the governance-level answer. CGEIT is a governance exam. When asked for the best or first action, prefer the option that does one of the following:
• Establishes a policy
• Defines roles and accountability
• Assigns ownership
• Aligns with business objectives
Avoid jumping to a technical fix such as encryption or a DLP tool.
Tip 6 – Ownership comes before classification, and classification comes before controls. If data is not classified or protected properly, the root cause is often that ownership was never assigned. The best answer is frequently to assign or clarify ownership.
Tip 7 – Outsourcing and cloud do not transfer accountability. The enterprise and its data owners remain accountable even when a provider acts as custodian. Look for answers covering contracts, SLAs, right-to-audit clauses and monitoring.
Tip 8 – Disputes go to governance bodies. When business units disagree over definitions or ownership of shared data, the best answer is usually a data governance council/committee or executive sponsor. A unilateral IT decision is not the right answer.
Tip 9 – Access reviews belong to owners. Periodic user access recertification should be performed or approved by the data owner. IT may supply the reports.
Tip 10 – Ultimate accountability rests with the board and executive management. If the question concerns overall accountability for enterprise information governance, choose the board or executive leadership. Choose individual data owners only for specific assets.
Tip 11 – Watch keywords.
• "Accountable", "approve", "classify" and "accept risk" point to the owner.
• "Day-to-day quality", "definitions" and "metadata" point to the steward.
• "Backup", "implement", "maintain" and "provision" point to the custodian.
Tip 12 – Eliminate extreme or operational distractors. Remove answer choices that are purely technical, that place business accountability on IT, or that bypass policy and governance structures.
Sample Question
A data breach revealed that sensitive customer data was stored without encryption, and no one could say who had approved its protection level. What should the IT governance function recommend FIRST?
A. Encrypt all customer databases immediately
B. Assign a business owner for customer data and require classification
C. Have the CISO take ownership of all sensitive data
D. Purchase a data loss prevention solution
Answer: B. The root cause is missing ownership and accountability. Encryption (A) and DLP (D) are tactical controls. The CISO (C) should not own business data.
6. Key Takeaways
• Information is a business asset. Ownership must sit with accountable business leaders.
• Owners decide, stewards manage quality and meaning, custodians implement controls, and users comply.
• Clear ownership enables proper classification, proportionate protection, quality and compliance. This supports value delivery and risk optimization.
• In the exam, choose answers that establish accountability, policy and governance structures over technical or IT-centric fixes.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!