Someone outside of day-to-day operations is providing governance oversight over the security program. For a startup or small company, this might be an advisory board, external advisors, or even a board with an independent director. Auditors do not expect a Fortune 500 governance structure, but they do want to see that leadership accountability exists outside of the people running operations.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Board or equivalent governance body with documented security oversight
Implementation Steps
Document the governance structure in an organizational policy: identify who comprises the board or equivalent oversight body, confirm at least one member is independent from operations
Hold quarterly governance or security review meetings with documented agendas and meeting minutes, this is the primary evidence for this criterion
Include security metrics, significant incidents, and risk posture in board or management review meetings, security must be a standing agenda item
If the company is too small for a formal board, designate an advisory board or document that senior leadership plus an external security advisor form the oversight function
Tools / Systems
Confluence / Google Docs (meeting minutes)Email (meeting invites as proof of cadence)Board management software (if applicable)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Board or equivalent governance body with documented security oversight
Evidence Artifacts
Organizational chart or governance document showing the board or oversight body composition and indicating independent members
Meeting minutes from at least one governance meeting during the audit period showing security topics were discussed
Board or leadership review agenda template showing security as a standing item
📅Quarterly meetings minimum; minutes retained for the full audit period
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Board or equivalent governance body with documented security oversight
Implementation steps
Document the governance structure in writing: who is on the oversight body, their role (employee vs. independent), and how often they meet
Maintain formal meeting minutes that note attendees, agenda items discussed, and any decisions or action items, even informal advisory meetings need minutes
Security topics at governance meetings should include incident summary, control status, risk register updates, and any material changes to the environment
Tools / systems
Meeting minutes (Word / Google Docs)
Email records (meeting cadence documentation)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Governance structure document identifying oversight body members and their independence
Meeting minutes showing security review occurred at least quarterly
Action items or follow-ups from governance meetings, demonstrating the oversight is substantive
Evidence frequency: Quarterly; minutes uploaded to your GRC platform at each meeting