TrustPoint

Governance

The organizational structure every other module is scoped to.

What it does

Governance is where you describe your organization to TrustPoint once, so every other module inherits that shape. You build the org tree, define the perimeters that will be assessed, and publish the policies people are held to.

Because permissions and reporting are scoped along the same tree, a business unit head sees their unit and nothing else, and a group report rolls up without anyone reconciling spreadsheets.

Policies live here as versioned documents with review cycles and approval routing, and attestations close the loop by recording who actually read and accepted them.

Org tree and folders

A hierarchy of Root, Perimeter, Business Unit and Project, with an org-chart view of the whole structure.

Permissions and reporting are scoped along this tree, so the structure you draw once decides who sees what and how numbers roll up.

Illustrative interface. Not customer data.

Perimeters

The assessable scopes: an entity, a system, a site. Frameworks and assessments attach to a perimeter rather than floating free.

Scoping is the difference between a compliance answer that means something and one an auditor rejects. A perimeter makes the boundary explicit.

PRM-004 · Retail Banking

Policies

Authoring in a rich editor, with versioning, scheduled review cycles, approval routing and controlled publication.

A policy nobody reviewed in three years is a finding waiting to happen. Review cycles surface the ones that have gone stale before an auditor does.

POL-0031 · v4 · review due 2026-11-30

Attestations

Push a published policy to a population and track who has read and accepted it, with automatic reminders to the people who have not.

Publishing a policy is not the control. Evidence that the people it binds have accepted it is the control.

Roles that live here

  • Compliance Manager
  • Policy Owner
  • Business Unit Head
  • Tenant Administrator

Drawn from sixteen built-in roles, each scoped along the org tree. Access control

Related frameworks

See Governance on your org structure.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.