A Board Data Policy That Reaches the Stockroom
Most board data policies cover email, laptops and the HR drive, and stop there. The system that holds supplier bank details, payroll and the asset register is rarely named. Seven clauses that close the gap, and where your own system fits.
Boards adopt data policies after an incident somewhere else, and the policy reflects what the incident was about: a lost laptop, a leaked spreadsheet, a phishing email. The operations system, where the supplier master, the payroll and the asset register actually live, is usually missing from the text, because it was bought by a department and nobody thought of it as a data store.
To the board
A data policy that does not name the operations system does not govern most of the organization’s operational records. Add seven clauses: classify systems, approve hosting arrangements, set an isolation rule where it matters, approve sub-processors, review access, guarantee an exit, and attest each year.
Seven clauses to adopt
-
Classify every system that holds organizational data
List each one, the categories of data it holds, and an owner by role. The operations system belongs on the list, with payroll, staff files and supplier bank details named.
-
Approve hosting arrangements by class
State which arrangements are acceptable for each class of data: shared cloud, a dedicated instance, or on-premise. Management then chooses within that rule.
-
Set an isolation rule where it is needed
For the classes that warrant it, require that records do not share a database with any other organization. This is the clause a dedicated instance exists to satisfy.
-
Approve sub-processors
Require a published list of every provider that touches the data, with its region, and a review whenever it changes.
-
Review access each quarter
Require the owner to confirm, by role, who can see and change the data, and to report changes to the committee.
-
Guarantee an exit
Require that every system can return the organization’s records in a usable form, and remove them afterwards, without depending on the supplier’s goodwill.
-
Attest annually
Have each system owner sign a one-page statement against these clauses, filed with the committee papers.
A policy that names the laptops and not the ledger governs the wrong thing.
Where a dedicated instance fits
Clause three is the only one that a hosting arrangement satisfies on its own. Once a board has decided that certain records may not share a database with another organization, management needs a system that meets that rule without becoming an infrastructure project. A dedicated instance does: its own database, its own encryption key, its own storage and backups, run by the vendor and kept on the current release.
The other six clauses are about the organization’s own discipline, and the system’s job is to make them easy to evidence. Roles make clause five a report rather than an investigation. An audit trail shows who changed what. A published sub-processor list answers clause four. An export answers clause six.
If the board is deciding whether clause three should apply at all, is a dedicated instance worth it sets out when it earns its cost and when shared is enough.
To match your policy
Where the board’s policy goes further than the standard instance, these are the additions we build.
Region in the contract
Hosting set in the country or region your policy names.
A trimmed provider list
Optional services switched off so the sub-processor list matches what the board approved.
Your history, moved across
An existing shared workspace moved to a dedicated instance with its records intact, when a new policy takes effect.
How it works: send us the clause, and we return a written scope and cost.
See the dedicated instanceFor the next committee meeting
Which systems hold supplier bank details?
Ask management for
A named list with owners.
Which clause
Clause one.
Do any of them share a database with other organizations?
Ask management for
A yes or no for each.
Which clause
Clause three.
Who can change payroll records?
Ask management for
Roles, reviewed this quarter.
Which clause
Clause five.
Could we leave each system next month?
Ask management for
A tested export.
Which clause
Clause six.
What AWRA OpsHub does today
- A dedicated instance with its own database, encryption key, storage and backups, for records the board rules may not share a system.
- Roles and an audit trail that turn an access review into a report.
- A published sub-processor list with each provider’s region.
- An export of your records, followed by removal, on request.
More we can add to your workspace
- A hosting region of your choosing, set in the contract.
- A sub-processor list trimmed to what your board approved.
- Your current workspace moved to a dedicated instance with its full history.
Where we point you to a specialist
- We do not write your data policy. The clauses here are a starting point for your board and its advisers, not legal advice.
Each of these can be scoped into a dedicated-instance quote.
A system that meets clause three
Your own AWRA, used by your organization alone, run by us. Available to set up now.
See the dedicated instanceFrequently asked questions
Should a board data policy cover the ERP?
Yes. The ERP usually holds supplier bank details, payroll, staff files and the asset register, which are among the most sensitive operational records an organization keeps.
What clauses should a board data policy include for business systems?
Classify systems, approve hosting arrangements, set an isolation rule where needed, approve sub-processors, review access each quarter, guarantee an exit, and attest annually.
How does a dedicated instance help with a board data policy?
It satisfies a rule that certain records may not share a database with another organization, without the organization having to run its own servers.
Is this legal advice?
No. The clauses are a starting point for a board and its advisers to adapt.