PM-23: Data Governance Body

PM-23 requires your organization to establish a formal data governance body with defined roles and responsibilities for overseeing how data

Quick-reference card

FieldValue
Control IDPM-23
Control NameData Governance Body
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
Baselines
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PM-23 requires your organization to establish a formal data governance body with defined roles and responsibilities for overseeing how data is managed, protected, and shared throughout its lifecycle. This isn’t a suggestion to “think about” data governance. It’s a mandate to create a standing group of senior leaders who own the policies, procedures, and standards that govern how your organization handles data, including personally identifiable information (PII).

In practice, this governance body must include senior officials such as the chief information officer, the senior agency information security officer, and the senior agency official for privacy. These aren’t advisory roles. The body is responsible for developing guidelines that support data modeling, quality, integrity, and de-identification needs across every stage of the information lifecycle.

The governance body also serves as the decision point for data release. It reviews and approves applications to release data outside your organization, archives those applications and the released data, and performs post-release monitoring to verify that the original assumptions behind the release remain valid. For federal agencies, this requirement is anchored in the Foundations for Evidence-Based Policymaking Act (EVIDACT) and OMB M-19-23, which set specific structural expectations for how the body operates.

Why it matters

Most organizations treat data governance as a distributed responsibility, meaning everyone owns it and no one actually does. Without a formal body to set and enforce policy, you end up with inconsistent data handling practices across departments, conflicting interpretations of privacy requirements, and no clear authority to resolve disputes about data access or release.

Failure to maintain PM-23 introduces audit risk and may result in certification withdrawal or regulatory findings. Federal agencies without a documented data governance body face noncompliance with EVIDACT requirements, which auditors flag as a structural gap rather than a technical one. This type of finding is difficult to remediate quickly because it requires organizational change, not a patch or configuration update.

The consequences extend beyond audit. When no single body owns data policy, decisions about PII handling, de-identification, and external data sharing happen in isolation. This fragmentation creates conditions where sensitive data is released without proper review, quality controls degrade over time, and post-release monitoring doesn’t happen at all. Regulatory bodies increasingly scrutinize whether governance structures exist on paper only or function in practice.

Without centralized governance, your organization also loses the ability to balance data utility against security and privacy requirements in a consistent way. Individual teams optimize for their own objectives, which often means underweighting privacy protections or overrestricting access in ways that undermine legitimate analytical use.

What attackers exploit:

  • Inconsistent data classification and handling practices that leave PII exposed in systems without appropriate controls
  • Absence of post-release monitoring, allowing released datasets to be misused without detection
  • Fragmented authority over data access decisions, enabling insiders to obtain sensitive data without centralized review
  • Lack of de-identification standards, resulting in re-identifiable data being treated as anonymized
  • Missing governance documentation, which delays incident response when teams can’t determine who owns data decisions

How to implement

For your organization

The most common failure mode with PM-23 is treating the governance body as a compliance checkbox rather than an operational function. Organizations stand up a committee, document it in a charter, and never convene it with enough regularity or authority to influence actual data handling practices.

Start by formally establishing the governance body through a charter document. The charter should define membership, meeting cadence, decision-making authority, and escalation paths. At minimum, your membership must include the chief information officer, the senior agency information security officer, and the senior agency official for privacy. Depending on your organization’s structure, you should also include data stewards from major business units and legal counsel with privacy expertise.

Develop the body’s core policy portfolio next. This portfolio should cover data classification standards, PII handling procedures, de-identification requirements, data quality and integrity standards, and the process for reviewing and approving external data releases. Each policy needs an owner, a review cycle, and a defined scope. Don’t try to cover every data type in a single policy. Segment by data sensitivity and regulatory applicability.

Build the data release review process as a distinct workflow. Every request to share data outside your organization should flow through a documented application process. The governance body reviews the application, assesses risks to privacy and security, and issues a formal approval or denial. Approved releases must be archived alongside the application, and you should define post-release monitoring checkpoints to validate that the conditions of release remain appropriate.

Establish a regular meeting cadence, at minimum quarterly, with documented agendas and meeting minutes. These records serve as primary evidence during audits. Between formal meetings, the body should maintain a decision log that captures ad hoc approvals, policy exceptions, and emerging issues escalated by data stewards.

Common mistakes include failing to document the body’s decisions in a way that auditors can trace, limiting membership to IT without privacy or legal representation, and neglecting the post-release monitoring requirement. The governance body should also coordinate with your vendor risk management program when third parties handle or receive your organization’s data, ensuring that external data sharing aligns with your governance policies.

Evidence examples

Evidence TypeExample Artifact
Governance body charterCharter document defining membership roles, decision authority, meeting cadence, and escalation procedures for the data governance body
Privacy program planPrivacy program plan documenting how the governance body integrates with broader privacy and security program objectives
Data governance policies and standardsPolicies covering data classification, PII handling, de-identification standards, data quality requirements, and data sharing procedures
Meeting recordsAgendas, minutes, and attendance logs from governance body meetings, including documented decisions and action items
Data release review recordsApplications submitted for external data release, approval or denial decisions, and associated risk assessments
Post-release monitoring reportsDocumentation of monitoring activities performed after data releases, including validation that release assumptions remain current

Cross-framework mapping

No applicable cross-framework mappings have been configured for this control.

  • AT-02 — Literacy Training and Awareness: ensures that personnel understand the data governance policies and procedures established by the governance body
  • AT-03 — Role-based Training: provides specialized training for governance body members and data stewards on their specific responsibilities
  • PM-19 — Privacy Program Leadership Role: establishes the senior agency official for privacy, who serves as a required member of the data governance body
  • PM-22 — Personally Identifiable Information Quality Management: addresses the data quality and integrity standards that the governance body is responsible for developing and enforcing
  • PM-24 — Data Integrity Board: serves a complementary function focused specifically on data integrity, often working alongside the data governance body
  • PT-07 — Specific Categories of Personally Identifiable Information: defines handling requirements for sensitive PII categories that the governance body must account for in its policies
  • SI-04 — System Monitoring: supports the governance body’s post-release monitoring responsibilities by providing technical monitoring capabilities
  • SI-19 — De-identification: implements the de-identification standards and guidelines that the governance body establishes for PII protection

Frequently asked questions

What is NIST SP 800-53 PM-23

PM-23 requires your organization to establish a data governance body consisting of designated senior roles with defined responsibilities for overseeing data management, privacy, and security across the information lifecycle. The body must include, at minimum, the chief information officer, the senior agency information security officer, and the senior agency official for privacy. Its responsibilities extend beyond policy creation to include reviewing data release applications, archiving released data, and conducting post-release monitoring.

What happens if PM-23 is not implemented

Without a formally established data governance body, your organization lacks centralized authority over data handling decisions, creating inconsistent PII management practices and unmonitored external data releases. Auditors will flag the absence as a structural governance gap, which is more difficult to remediate than a technical finding because it requires organizational change. For federal agencies, noncompliance also represents a violation of EVIDACT requirements and OMB M-19-23 directives.

How do you audit PM-23

Auditors verify that a data governance body charter exists and names specific roles, that meeting records demonstrate regular convening and documented decisions, and that data release review records show an active approval workflow with post-release monitoring. You should be prepared to produce the charter of operations, board meeting minutes, archived data release applications, and the policies and standards the body has issued. The assessment objective requires demonstrating that the body consists of defined roles with defined responsibilities, not just that it exists on paper.

Who should be on a data governance body

The governance body should include, at minimum, your chief information officer, senior agency information security officer, and senior agency official for privacy, as specified in the NIST SP 800-53 framework. Beyond these required roles, effective governance bodies also include data stewards from major business units, legal counsel with privacy expertise, and representatives from any function that handles significant volumes of PII. Membership should reflect decision-making authority over data classification, de-identification standards, and external data sharing.


UpGuard helps organizations manage cybersecurity risk across their attack surface, vendor ecosystem, and workforce. If you’re building governance programs that depend on continuous visibility into your security posture, explore how the UpGuard platform supports compliance readiness.

Experience superior visibility and a simpler approach to cyber risk management