Rodan · Resources · Governance

Governance Starter Pack

A condensed start: systems register fields, classification levels and the first thirty days of action. Enough to begin without boiling the ocean.

What is inside

  • Twenty register columns to copy into a sheet
  • Public / Internal / Confidential / Restricted definitions
  • Day 1–30 action sequence with owners
  • Links to the full toolkit and self-assessment

Email unlocks the full printable pack. Free to access, we just ask for an email.

Principles for week one

  • CFO or equivalent owns governance at mid-market. IT enables.
  • Include spreadsheets, pixels and shadow systems in the register.
  • Classification drives access. Do not invent a fifth level on day one.
  • Perfect is the enemy. A living 80% register beats a perfect one that never ships.

Systems register template fields

Copy these twenty columns into a sheet. One row per system (including material spreadsheets).

#FieldNotes
1System nameHuman-readable, unique
2Vendor / hosting locationSaaS vendor or self-host region
3Business ownerNamed person, not a team alias
4PurposeWhy the system exists
5Data categoriesCustomer, finance, HR, product, etc.
6Personal data flagYes / No
7Special category flagYes / No
8ClassificationPublic / Internal / Confidential / Restricted
9Lawful basisIf personal data
10Volume (approx)Records or scale band
11SourceWhere data enters from
12Flows toDownstream systems
13Access controlsSSO, MFA, role model
14DPA statusSigned / missing / N/A
15Transfer mechanismIf outside UK / EEA
16Retention rulePolicy or “unknown”
17Backup / recoveryTested? RTO note
18CriticalityTrading / reporting / low
19Contract renewalDate or N/A
20Notes / risksOpen issues

Classification levels

LevelDefinitionExamples
PublicNo harm if disclosedPublished marketing, public price lists
InternalMinor harmProcess docs, org charts
ConfidentialMaterial harmCustomer lists, financials, contracts
RestrictedSevere harmSpecial category data, payment data, M&A material

Access, sharing and AI connections follow the highest classification of data in the system.

First 30-day actions

Days 1–7

  • Name a governance lead and a fortnightly 30-minute forum
  • Draft the register sheet with the twenty columns above
  • List the top 15 systems by criticality (include finance, CRM, warehouse, storefront, HR)
  • Agree the four classification levels with leadership in one page

Days 8–14

  • Complete register rows for the top 15 (owners, personal data, DPA status)
  • Flag shared admin logins and missing MFA on Confidential / Restricted systems
  • Identify the three metrics that cause the most board argument; note source systems

Days 15–21

  • Classify every row in the top 15
  • Chase missing DPAs for processors that touch personal data
  • Write a one-page retention default for customer and prospect records

Days 22–30

  • Close or schedule the top five access and DPA gaps
  • Publish the register location and review cadence (twice a year minimum)
  • Run the governance self-assessment and keep the score for the next forum
  • Park AI / new analytics work that would touch unclassified personal data

What not to do in month one

  • Do not buy a governance platform before the register exists
  • Do not write a 40-page policy nobody will read
  • Do not invent custom classification labels
  • Do not connect an LLM to Shopify, CRM or HR until classification and DPAs are honest