Blog
Compliance
GDPR
ISO 27001
ISO 9001
August 24, 2026
Approx min read

Evidence owners and approvers: who signs off what

At twenty people, one person knows the whole compliance picture. They wrote the policies, they run the reviews, and if an auditor asks when access was last checked they can answer from memory.

At two hundred, that person still exists and their memory is now wrong. Access reviews sit with IT. Training records sit with HR. The record of processing sits with whoever inherited data protection. Supplier assessments sit with the team that signs the contracts. Each of those teams is doing the work. None of them is recording it in a way the others can see.

The controls usually keep operating. What goes is the ability to say when one last operated, and who confirmed it.

Why the record is the requirement

Under the UK GDPR, being compliant and being able to show it are separate obligations, and the second one is written down. Article 5(2) states that "the controller shall be responsible for, and be able to demonstrate compliance with" the data protection principles.

Article 24(1) goes further and puts maintenance in the text. The controller implements appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation, and "those measures shall be reviewed and updated where necessary".

The text puts a review duty on the controller where one is needed, and a measure implemented in 2024 and never revisited since is hard to defend against that wording. A review with no record of who did it or when has the same evidential weight as no review.

Management system certification works on the same principle. IAF MD 1:2023, which governs certification across several sites or entities, requires that all sites sit inside the internal audit programme, and that the central function is responsible for ensuring data is collected and analysed from every one of them, with demonstrable authority over internal audit planning, evaluation of corrective actions and management review. Demonstrable is the operative word in both regimes.

Owner and approver are two different jobs

The pattern that survives contact with a real organisation is simple, and it separates two things most compliance registers merge.

The owner does the work. They run the access review, update the supplier list, deliver the training. They are a named individual, and naming a team here is where most registers go wrong. "IT" cannot be asked when it last did something.

The approver confirms the work happened and was adequate. They sign it off, and their sign-off carries a date.

Keeping those separate matters for anything a buyer or an auditor will lean on. A control where the same person does the work and confirms it is a control with no second pair of eyes, and that is exactly the observation an experienced auditor makes without needing to see the evidence. It is also a practical protection for the owner, who otherwise carries sole responsibility for a judgement that belongs higher up.

Neither role belongs to the compliance function by default. The person who runs starters and leavers should own that control. The compliance owner's job is that every control has both roles filled and neither is vacant.

What a working evidence register holds

Four fields do most of the work. The control and what it requires. The owner, by name. The approver, by name. The date it is next due.

Add two more and the register becomes auditable. The date of the last review with the name of whoever confirmed it, and a record of what changed, showing the previous position alongside the new one.

That last field is the one organisations skip and the one that pays off. When a buyer asks why a policy says something different from what it said in their last review, the useful answer names the change, the date and the person who approved it. Rebuilding that from email is a bad day.

Where it breaks in a multi-team organisation

The same failures show up on every split register.

The owner who does not know they own it. Somebody assigned the control during a certification push and never told the person. It shows up as a review that has never happened against a control everyone assumed was running.

The approver who cannot assess it. A department head signing off a technical control they have no way to evaluate. The signature exists and it means nothing, which is worse than an open item because it stops anyone looking.

The handover with no record. Someone leaves, their controls are reassigned, and the new owner inherits a due date without the history. What a successor needs to inherit when the owner of a specific record leaves is its own procedure.

The common cause of all three is that ownership was recorded once, during a project, and has never been reviewed since. Ownership is itself something to review on a schedule.

Starting from where you are

Take the controls that a buyer or auditor has actually asked about in the last year. That is usually twenty to forty items out of a much longer register.

For each one, name the owner, name the approver, and set the next due date. Where the honest answer to "who owns this" is nobody, that is the finding, and writing "unassigned" is more useful than writing a team name.

Then run one cycle. A register that has been through a single complete round of reviews, with dates and names against each, tells you more about your position than any gap analysis.

Making the sign-off visible with Naq

The Naq platform automates GDPR, ISO 27001, ISO 9001, Cyber Essentials and the NHS DSPT in one system, with controls mapped across frameworks so a single piece of evidence satisfies requirements in several standards at the same time.

Policies and risks run an owner to approver workflow, with the review schedule set at the point of approval, so each one carries two named people and a date. Every control has a named owner, and its status is set by the evidence attached to it. Meaningful actions are written to the activity stream, and field edits show the previous and the new value. Records are archived instead of deleted, and approval snapshots are preserved as they were at sign-off. Each record has a human-readable identifier, which matters when somebody in another team needs to refer to one in an email.

The effect for an organisation whose evidence lives in four departments is that the current position is something you can look at, and the history behind it is something you can show.

For organisations with no full-time compliance hire, Naq's in-house Clinical Safety Officers and virtual Data Protection Officers are available alongside the platform.

The ISO 27001 and GDPR framework pages carry the requirement detail, and compliance across several entities covers the wider case. If your organisation spans more than one legal entity, certifying a group covers what changes.

If you want to see what your policies and controls look like with names and review dates against them, book a fifteen-minute demo.