GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-003 Management Commitment and Accountability

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A named executive owns the information security programme, security objectives appear in organisational goals and management review of programme status is recorded at defined intervals. A board or an equivalent body independent of management oversees the development and performance of internal control, receives the security programme's status at defined intervals and records what it reviewed and what it decided.

Rationale

Information security requires resource allocation and decision authority that only executive sponsorship can provide; without it the programme has no mandate across business units. Independent oversight is a separate requirement rather than a stronger version of the same one: an executive owner reports on the programme and a board or equivalent body forms a view on it from outside the management line. In a company with no board, the equivalent body is whatever group holds the owners' interest, and its independence from the executives running the programme is the property that matters.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

Art. 20(1) of the Directive makes the management body approve the cybersecurity risk-management measures rather than only oversee them, and makes it liable for infringements of Art. 21. Annex point 1.1.1(k) turns the approval into a dated field on the policy, so the evidence is a date and a minute, not a status report.

Framework Mappings (10)

HIPAA-164.308.a.2Assigned Security Responsibilityinformative
5.4Management responsibilitiesfull
NIS2-Art.20.1Management Body Approval and Oversight of Cybersecurity Measurespartial
NIS2-CIR-1.2Roles, Responsibilities and Authoritiesinformative
NIS2-CIR-2.2Compliance Monitoringinformative
PM-1Information Security Program Planpartial
MG-3.2-007Pre-Trained Model Monitoring | MG-3.2-007informative
GOVERN 2.3Executive Leadership Accountabilityinformative
CC1.2COSO Principle 2: Exercises Oversight Responsibilityfull
CC1.5COSO Principle 5: Enforces Accountabilitypartial

Evidence (3)

recorddocumentmanual

Management review meeting minutes or board/executive committee agenda showing security programme status was reviewed by senior management at defined intervals.

Example: Board or executive team meeting minutes (Google Drive / board portal) from the most recent review cycle, with an agenda item for information security, attendance list including a C-level or equivalent, and documented outcomes.

Test: Request the last two management review meeting minutes that include a security agenda item. Verify: (1) a named executive-level attendee is recorded, (2) security programme status or metrics were presented, (3) the review occurred within the defined interval (typically 12 months), (4) action items or decisions are documented.

policydocumentmanual

Documented security objectives aligned to organisational goals, approved by senior management, with the progress recorded against them.

Example: Annual security objectives document (Confluence / OKR tool such as Lattice or Notion), showing named executive sponsor, approval date, and security goals mapped to organisational priorities.

Test: Request the current security objectives and the progress records kept against them. Verify: (1) the objectives are stated with a named executive owner, (2) each objective carries a measure and a target, (3) a progress record exists for at least one objective within the last review cycle, stating the current value against the target, (4) an objective missed at the last review carries a recorded decision to continue, revise or drop it, (5) the objectives are dated within the current review cycle.

recorddocumentmanual

Minutes of the board or equivalent independent body recording its review of the information security programme and of the internal control system.

Example: Board minutes, 2026-06-18, agenda item 6, information security programme review

Test: Request the last two sets of minutes carrying a security agenda item. Verify: (1) the body's members are identified and those independent of executive management are distinguishable, (2) security programme status reached the body at the interval the charter or terms of reference set, (3) the minutes record what the body reviewed and what it decided rather than noting the item was tabled, (4) actions the body set are tracked to closure, (5) the body received the material in advance rather than only at the meeting.

Questions (3)

boolean

Is your information security programme sponsored by a named executive who is accountable for its direction and resources?

The sponsor should be a C-level executive or equivalent who is named in the security programme documents and receives regular programme status updates.

select

How frequently does senior management formally review the status of the information security programme?

Quarterly or more frequentlySemi-annuallyAnnuallyOnly when a significant incident occursNo formal management review takes place

Management review meetings should produce documented minutes with security agenda items, attendance records, and action items. Annual is the typical minimum.

boolean

Does a board or an equivalent body independent of management review the information security programme at a defined interval?

Independence means the body sits outside the management line that runs the programme. Where there is no board, the equivalent body is the group holding the owners' interest, such as an investor committee or an audit committee. Minutes recording what was reviewed and decided are the evidence; an agenda listing the item is not.