Unstructured data doesn't respect organizational boundaries. Rocket Software CIO Darlene Williams argues for building shared accountability before AI forces the issue.
Ask who owns unstructured data security at most enterprises, and you'll get a pause, followed by a complicated answer. Usually, something like “That's probably a security question” or “IT handles our data infrastructure," followed by a conversation that makes clear neither team feels they fully own it. The honest answer is often that it lives in the space between functions, which means it isn't really owned by anyone.
That's not a failure of leadership. It's a reflection of reality.
Unstructured data—emails, documents, recordings, collaboration threads—doesn't sit cleanly within any single function. IT understands the infrastructure and where data physically lives. Security owns the controls that guard against unauthorized access, data breaches, and compliance violations: access management, encryption standards, and monitoring for anomalous behavior. But those controls only work if someone has already decided what the data is, how sensitive it is, and who should be able to reach it. Data classification is determined by legal and data privacy governance and is supported by IT and security controls. The responsibility is shared with business functions that use unstructured data at the edge of their business processes. All stakeholders must work in concert to be good stewards of unstructured data. Legal teams and data governance groups own the policies that guide our classification, retention, and appropriate use of data. No single team has full visibility or complete authority.
The instinct is to solve this absence by forcing ownership of the responsibility for unstructured data governance into one function. That usually creates gaps rather than closing them. The most common gap is accountability without authority—one team responsible for a policy they didn't set, or another team setting rules they can't enforce technically. You also see coverage gaps, where data that moves between systems falls outside the scope of whoever owns each individual environment.
Unstructured data moves across every function—sales, finance, operations, legal—so the governance model shouldn't stop at departmental boundaries. For organizations with complex, distributed environments—cloud platforms, collaboration tools, AI systems—shared accountability among IT, security, and governance teams often works better than trying to centralize control.
The Moment to Get Ahead of It
At Rocket Software, the trigger to change our governance approach to unstructured data wasn't a single incident. It was recognizing where the software industry was heading before it became a problem.
As our AI adoption accelerated and the use of collaboration platforms grew, it became clear that governing data by system or environment wasn't going to hold. The volume of unstructured data moving across platforms—documents, emails, recordings, AI-assisted workflows—was growing faster than any single team could manage in isolation.
We looked at where other organizations had stumbled. We saw organizations where AI tools trained on or surfaced internal content—documents, emails, recorded meetings—that hadn't been properly classified or scoped. The common thread was that governance hadn't kept pace with deployment.
We decided to formalize shared accountability before an incident forced us to, not after. The goal was to build a model that could scale with AI adoption rather than one constantly trying to catch up.
We started by mapping where our unstructured data actually lived and how it moved—not just within systems, but across them. From there, we established a cross-functional working group with IT, security, legal, and data governance that meets regularly and operates from shared visibility into the data estate. We aligned on a common classification framework so that policies travel with the data rather than stopping at a system boundary. And we defined clear escalation paths so that when something falls in a gray area, there's an agreed process for resolving it rather than each team waiting for another to act. We also aligned our data classification policies with our AI and Data Analytics framework so that, as we build autonomous agents, they have the same guardrails when using unstructured data.
Why Aligning IT, Security, and Governance Takes Time
Building a shared accountability model sounds straightforward. In practice, it's not. Unstructured data has always existed at the edges of traditional governance; it never fit as neatly into frameworks as structured data has. As environments have expanded to include cloud platforms, collaboration tools, and AI systems, data began moving across more systems and touching more teams than ever before. Aligning IT, security, and governance around a shared model while the landscape is actively shifting is genuinely difficult.
The growing focus by regulators, boards, and customers on data sovereignty and privacy adds another layer of complexity. Organizations now need visibility not only into where data resides, but also how it's accessed, shared, and governed across environments.
Map the Data Where It Lives, How It Moves
The instinct is to start with tools: software that locks down data, monitors access, and flags leaks. But tools can't enforce agreements that don't exist. Before investing in security technology, organizations need to know where their data lives and agree on who's accountable for it.
Mapping where the data lived and how it moved was what unlocked the conversation for us. Once teams could see the same picture, the accountability discussion became much more straightforward.
Governance is tested in the gray areas as customer information, internal documents, and collaboration data constantly move across platforms. Ownership can't depend on where data happens to live at a given moment. What works better is governance that follows the data itself: consistent policies around access, classification, and retention that apply across systems, not just within them. As volume grows, automation helps enforce those policies more consistently than manual oversight ever could.
Accountability is tracked on multiple levels. In addition to data protection tools and data owners, we use education and automation as part of a systemic approach. We educate end users about data privacy laws and the importance of proper handling and records retention to comply with customer contracts and regulations. We also apply role-based access control (RBAC) to segment data and restrict read and write permissions. And we create a privacy-first pipeline by automating the anonymization and aggregation of sensitive data.
What's Working—and What's Still Evolving
The shared accountability model has given us something we didn't have before: a common language across IT, security, and data governance teams, as well as with our Enterprise Risk Management council.
Before, when a question came up about a particular data set—say, recordings from a customer call that also contained internal discussion—IT would defer to security, security would defer to governance, and legal would want to know what classification had been applied before weighing in. Everyone was waiting for someone else to frame the problem. Now we have a shared classification framework and a shared visibility layer, so when that question comes up, everyone is looking at the same information, and we can get to a decision in one conversation instead of three. We also codify those classifications in written policies available to all employees.
When everyone is working from the same visibility layer and the same classification framework, conversations about ownership that used to stall move much faster.
Where we've seen additional momentum is in applying AI to the governance challenge itself. The same capabilities that create risk—AI's ability to pull from documents, emails, and collaboration platforms in real time—can also help manage it. Tools that provide continuous monitoring and real-time visibility across complex environments are changing what's possible. Rather than relying on periodic audits or manual reviews, AI can surface anomalies, flag policy gaps, and support faster remediation across the data estate.
What's still evolving is governance's ability to keep pace with AI adoption. As new tools get introduced across the business, there's always a window between deployment and full governance coverage that requires active management. That’s ongoing work, not a solved problem.
For peers still trying to figure out who owns unstructured data security, it’s okay to land on the fact that no one does. What matters most is that the teams that touch the data—IT, security, governance, legal—are working from the same information and the same set of accountabilities.
Written by Darlene Williams
Darlene Williams is Chief Information Officer at Rocket Software, where she leads the company’s global IT strategy, overseeing data modernization, digital transformation, hybrid cloud strategy, AI-enabled operations, and enterprise security. With more than 20 years of experience, she specializes in optimizing business processes, spearheading digital innovation projects, and boosting financial outcomes across multiple verticals.