Governance
The organizational structure every other module is scoped to.
Works with
What it does
Governance is where you describe your organization to TrustPoint once, so every other module inherits that shape. You build the org tree, define the perimeters that will be assessed, and publish the policies people are held to.
Because permissions and reporting are scoped along the same tree, a business unit head sees their unit and nothing else, and a group report rolls up without anyone reconciling spreadsheets.
Policies live here as versioned documents with review cycles and approval routing, and attestations close the loop by recording who actually read and accepted them.
Org tree and folders
A hierarchy of Root, Perimeter, Business Unit and Project, with an org-chart view of the whole structure.
Permissions and reporting are scoped along this tree, so the structure you draw once decides who sees what and how numbers roll up.
Org tree
Add perimeter- GroupORG-001
- Retail BankingPRM-004
- Core BankingPRM-011
- Digital ChannelsPRM-012
- TreasuryPRM-007
Perimeters
The assessable scopes: an entity, a system, a site. Frameworks and assessments attach to a perimeter rather than floating free.
Scoping is the difference between a compliance answer that means something and one an auditor rejects. A perimeter makes the boundary explicit.
PRM-004 · Retail Banking
Policies
Authoring in a rich editor, with versioning, scheduled review cycles, approval routing and controlled publication.
A policy nobody reviewed in three years is a finding waiting to happen. Review cycles surface the ones that have gone stale before an auditor does.
POL-0031 · v4 · review due 2026-11-30
Attestations
Push a published policy to a population and track who has read and accepted it, with automatic reminders to the people who have not.
Publishing a policy is not the control. Evidence that the people it binds have accepted it is the control.
Roles that live here
- Compliance Manager
- Policy Owner
- Business Unit Head
- Tenant Administrator
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Governance on your org structure.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.